NERL Postdoc
I. Data in the System
-
Describe what data/information will be collected in the system.
NERL Postdoc database contains contains:
Branch, Division
Employee Name
Job Title
Series, Grade
Appointment type and year
OMIS data elements
Type of work
Appt/separation/conversion date
Status of postdoc (on board, converted, terminated)
Education info (discipline and date of degree)
Research area where working
For those who've left NERL (identify whether took another federal job, at university or private firm - no address or phone number
Change of name after marriage
Location of advertisement
If converted ot terminated, how long on board as post doc -
What are the sources and types of the data/information in the system?
Get it from HR, OMIS, or from application
-
How will the data be used by the Agency?
It is used to answer ORMA postdoc data calls and answer questions asked by management about the post doc program
-
Why is the information being collected? (Purpose)
It is used to answer ORMA postdoc data calls and answer questions asked by management about the post doc program
II. Access to the Data
Who will have access to the data/information in the system (internal and external parties)? If contractors, are the Federal Acquisition Regulations (FAR) clauses included in the contract (24.104 Contract clauses; 52.224-1 Privacy Act Notification; and 52.224-2 Privacy Act)?
Kathy Kuntz, owner of the system and a SEE employee, Marjorie McKenzie
-
What controls are in place to prevent the misuse of data by those having authorized access?
None
Do other systems share or have access to data/information in this system? If yes, explain who will be responsible for protecting the privacy rights of the individuals affected by the interface? (i.e., System Administrators, System Developers, System Managers)
No. But some of this data is downloaded from OMIS.
-
Will other agencies, state or local governments share/information or have access to data in this system (includes any entity external to EPA.)?
No
Do individuals have the opportunity to decline to provide information or to consent to particular uses of the requested information? If yes, how is notice given to the individual? (Privacy policies must clearly explain where the collection or sharing of certain information may be optional and provide users a mechanism to assert any preference to withhold information or prohibit secondary use.)
No
III. Attributes of the Data
Explain how the use of the data is both relevant and necessary to the purpose for which the system is being designed.
To answer the questions asked by the management.
-
If data are being consolidated, what controls are in place to protect the data from unauthorized access or use? Explain.
No one except the two mentioned above have access the data.
-
If processes are being consolidated, are the proper controls remaining in place to protect the data from unauthorized access? Explain.
No one except the two mentioned above have access the data.
How will data be retrieved? Can it be retrieved by personal identifier? If yes, explain. (A personal identifier is a name, Social Security Number, or other identifying symbol assigned to an individual, i.e. any identifier unique to an individual.)
Mostly retrieved by division, or type of post doc or status
- Is the web policy machine readable? Where is the policy stated? (Machine readable policy enables visitors to easily identify privacy policies and make an informed choice about whether to conduct business with that site.)
N/A
IV. Maintenance of Administrative Controls
-
Has a record control schedule been issued for the records in the system? If so, provide the schedule number. What are the retention periods for records in the system? What are the procedures for eliminating the records at the end of the retention period? (You may check with the record liaison officer (RLO) for your AA-ship or Tammy Boulware (Headquarters Records Officer) or Judy Hutt, Agency Privacy Officer, to determine if there is a retention schedule for the subject records.)
Data in database is added/updated on continual basis to conduct trend analyses in response to management queries. So, data has not been discarded.
While the data are retained in the system, what are the requirements for determining if the data are still sufficiently accurate, relevant, timely, and complete to ensure fairness in making determinations?
Much of the data retained has no need to be updated. Divisions are queried occasionally to see if there is any change in the research area the postdoc is working, and if so, we update the database. Other than that, much of the data doesn't change and thus, there's no need to update it. The analyses is based on the position and division but not on the person.
Will this system provide the capability to identify, locate, or monitor individuals? If yes, explain.
No.
Does the system use any persistent tracking technologies?
No.
- Under which System of Records (SOR) notice does the system operate? Provide the name of the system and its SOR number if applicable. A list of Agency SORs are posted at http://www.epa.gov/privacy/notice/. (A SOR is any collection of records under the control of the Agency in which the data is retrieved by a personal identifier. The Privacy Act Officer will determine if a SOR is necessary for your system.)
N/A.
![[logo] US EPA](http://www.epa.gov/epafiles/images/logo_epaseal.gif)