Privacy Act of 1974

5 U.S.C. § 552a

Privacy Act of 1974

In force since September 27, 1975

Who it applies to

  • Federal executive-branch agencies maintaining systems of records retrieved by an individual identifier

Consumer rights

  • Access / know — grantedObtain the personal data held about you, and the categories, sources and purposes behind it.
  • Correction — grantedRequire inaccurate personal data to be fixed.
  • Deletion / erasure — not granted
  • Portability — not granted
  • Opt out of sale / sharing — not granted
  • Opt out of targeted advertising — not granted
  • Opt out of profiling — not granted
  • Limit sensitive data use — not granted
  • Human review of automated decisions — not granted
  • Non-discrimination — not granted
  • Appeal a refusal — not granted
  • Private right of action — grantedSue directly, rather than relying on a regulator to enforce on your behalf.

Obligations

Consent model
Opt-in
Universal opt-out signal
Not required
Risk assessments
Not required
Data protection officer
Not required
Records of processing
Required
Processor contract
Not required
Right to cure
None — enforcement may follow immediately
Data broker registration
Not required

Breach notification

To individuals
Set by OMB policy rather than by the Act
To the regulator
Agencies report to CISA and OMB under federal incident policy
What triggers it
Set by OMB policy rather than by the Act

Penalties

Headline
Actual damages of at least $1,000, plus fees; criminal misdemeanour for wilful disclosure
Private right of action
Yes — individuals can sue directly
Notes
Agencies must publish a System of Records Notice in the Federal Register before operating a covered system — the oldest public processing register in US law, and a close cousin of the GDPR's records of processing.

Exemptions

Entities

  • The entire private sector — this Act governs the government, not businesses
  • State and local government

Data

  • Records exempted by an agency rule, such as certain law-enforcement systems

Sources