Intelligence Community Legal Restrictions

(c) Data quality. Any element of the intelligence community that processes personal information collected through signals intelligence shall include such personal information in intelligence products only if it is consistent with the applicable intelligence community standards for accuracy and objectivity, with a focus on the application of standards for the quality and reliability of information, review of other sources of information and interpretation of data. and objectivity in conducting analyses. 1. Background and applicability. a. Background. Section 1016(d) of the Intelligence Reform and Prevention of Terrorism Act 2004 (IRTPA) requires the publication of guidelines on privacy and civil liberties in the development and use of the Information Sharing Environment (ISE). Section 1 of Executive Order 13388, Strengthening Further the Exchange of Terrorism Information to Protect Americans, provides that «[t]he authorities shall, to the fullest extent consistent with applicable law. Enter the . The exchange of information on terrorism between authorities. [and] protect the liberty, privacy, and other legal rights of Americans in the conduct of [these] activities. These guidelines implement IRTPA and EO 13388 requirements to protect privacy rights and provide other legal protections regarding civil liberties and legal rights of Americans in the development and use of ISE.

b. Applicability. This policy applies to information about U.S. citizens and lawful permanent residents that is subject to privacy or other legal protections under the U.S. Constitution and federal laws («Protected Information»). For the intelligence community, protected information includes information about «persons of the United States» as defined in Executive Order 12333. Protected information may also include other information that the U.S. Government expressly determines by executive order, international treaty, or similar instrument that should be covered by these guidelines. 2. Compliance with Laws. a. General.

When developing and using ISE, all agencies without exception must comply with the Constitution and all applicable laws and regulations regarding protected information. b. Evaluation of rules. Each agency implements an ongoing process to identify and assess the laws, implementing regulations, policies and procedures that apply to proprietary information that it provides or will have access to through the EIS. Each authority must identify, document and comply with all legal restrictions applicable to such information. Each organization shall adopt internal policies and procedures requiring it: (i) to obtain or retain only proprietary information that is legally permitted to it under applicable laws, regulations, directives and regulations; and (ii) ensure that proprietary information provided by the Agency through the ISE has been lawfully obtained from the Agency and can lawfully be made available through the ISE. c. Modifications. The Attorney General and the DNI will review these restrictions and jointly submit recommendations for changes to these restrictions to the Assistant to the President for Homeland Security and Counterterrorism, the Assistant to the President for National Security Affairs, and the Director of the Office of Management and Budget for further consideration. 3. Purpose.

Protected information should only be shared via ISE if it is terrorist information, homeland security information, or law enforcement information (as defined in Section 13 below). Each agency shall adopt internal policies and procedures to ensure that the Agency`s access to and use of protected information available through the ISE is consistent with the approved purpose of the EIA. 4. Identification of protected information to be shared through the HIA. One. Identification and due diligence. In order to facilitate compliance with these guidelines, in particular section 2 (Compliance with laws) and section 3 (purpose specification), each authority shall identify its data assets containing proprietary information to be shared through the ISE and establish reasonably practicable mechanisms to ensure that protected information has been verified in accordance with these guidelines before being placed on the provision of the ISE. b. Reporting mechanisms. In accordance with the guidelines and standards to be published for the ISE, each Agency shall establish a mechanism for ISE participants to determine the type of protected information that the Agency provides to the ISE so that those participants can process the information in accordance with applicable legal requirements.

In particular, such a mechanism, where reasonably possible and consistent with the Agency`s legal authorities and mission requirements, will enable ISE participants to determine whether: (i) the information relates to a U.S. citizen or lawful permanent resident; (ii) the information is subject to specific data protection restrictions or other similar restrictions on access, use or disclosure and, if so, the nature of those restrictions; and (iii) there are limits to the reliability or accuracy of the information.