Global Privacy and Information Quality Working Group
Product II Privacy Policy Development Guide
Message From the Chair “The foundations for privacy policy exist in our current laws and customs. Constitutions, statutes, regulations, policies, procedures, and common law requirements still control the obligations of the justice entities to collect and share information within legal limits.”
The Change “Clear articulation of rules that control justice information sharing in a manner that translates into systems requirements for systems developers and information managers.”
The Audience The guidebook has been developed to assist the individual who is assigned the task of writing a privacy policy.
The Process “A step-by-step guide on team effort to develop and articulate privacy policy.”
Section 3 Privacy Policy Overview 3.1What Is a Privacy Policy? 3.2The Intersection Between Privacy and Information Quality 3.2.1What Is Information Quality? 3.2.2Impact of Data Quality on Privacy and Public Access 3.2.3What Generates Data Quality Issues? 3.2.4Future Guidance Statement
Section 4 Governance 4.1Identifying the Champion 4.2Resource Justification 4.3Identifying the Project Leader 4.4Building the Project Team and Stakeholder Contacts
Section 5 Planning 5.1Developing a Vision, Mission, Values Statement, and Goals and Objectives 5.1.1Vision Statement 5.1.2Mission Statement 5.1.3Values Statement 5.1.4Goals and Objectives 5.2Writing the Charter
Section 6 Process 6.1Understanding Information Exchanges 6.1.1Tools to Assist With Understanding the Flow of Information 6.2Analyzing the Legal Requirements 6.2.1Introduction 6.2.2Approach to the Legal Analysis 6.2.3Focusing the Legal Analysis 6.2.4Performing the Legal Analysis Checklist 6.2.6Resources
Section 6 Process (continued) 6.3Using FIPs as a Starting Point ( law enforcement exception discussion ) 6.4Identifying Critical Issues and Policy Gaps
Section 7 Product (Developing the Elements of the Privacy Policy) 7.1Vision and Scope for the Privacy Policy 7.2Outline and Organizational Structure 7.2.1Introduction 7.2.2Definitions 7.2.3Applicability 7.2.4Legal Requirements and Policy Guidance 7.2.5Accountability (responsibility for implementation/ compliance monitor) 7.2.6Process for Revisions and Amendments
Section 7 Product (continued) 7.3Writing the Privacy Policy 7.3.1Making the Policy Choices—Filling in the Gaps 7.4Vetting the Privacy Policy 7.5Resources 7.5.1Some Common Elements of Current Policies 7.5.2Policy Example(s)
Section 8 Implementation 8.1Formal Adoption of the Policy 8.2Publication 8.3Outreach 8.4Training
Appendices Appendix A – Case Study –Illinois Criminal Justice Information Authority and Illinois Integrated Justice Information System (IIJIS) Appendix B – Definitions Appendix C – Acknowledgements Appendix D – Compendium
Next Steps on Privacy GAC input on the Privacy Policy Development Guide Compendium of state and privacy laws and available Attorney General opinions Examples of privacy policies GAC input on next steps on information quality
Next Steps on Information Quality Goals and objectives Identification of subject-matter experts Guidance on information quality issues Guidance on developing information quality policies