GCN Home > 08/30/05 web stories
GAO: Privacy issues remain in data mining programs
By Patience Wait, GCN Staff
A sampling of data mining programs in several federal agencies has found that implementing privacy and security measures is haphazard, according to a report from the Government Accountability Office.

Of five data mining programs at five different agencies, none followed all key procedures for privacy and security measures, GAO said.

The report, titled Data Mining: Agencies Have Taken Key Steps to Protect Privacy in Selected Efforts, but Significant Compliance Issues Remain, examined programs at the Small Business Administration, the Agriculture Departments Risk Management Agency, the IRS, the State Department and the FBI.

Most agencies notified the general public that they were collecting and using personal information and provided opportunities for individuals to review that information, GAO found, but agencies are also required to tell the public why the information is being gathered.

Only the State Department and the SBA did so; RMA did not give notice consistently, while the IRS and FBI claimed an allowed exemption because the systems are used in law enforcement.

Three of the agencies have prepared privacy impact assessments, but none of the assessments complied with guidance provided by the Office of Management and Budget.

The watchdog agency submitted recommendations for improvement tailored to each agencys needs and requirements. The agencies subject to review generally agreed with the majority of GAOs recommendations. However, the General Services Administration, which provides a database to State, disagreed, claiming the Privacy Act doesnt apply to its system and that it has taken adequate security measures.

However, in our view, GSAs system is subject to the Privacy Act, the GAO concluded. Additionally, while we acknowledge GSAs efforts to secure its system, it is nonetheless required to comply with the specific requirements of the Federal Information Security Management Act of 2002
and related guidance, GAO said.

More news on related topics: Knowledge Management, Management, IT Management, IT Security
GCN.com
The latest technology news from GCN.com
FCW.com
The latest policy and management news from FCW.com