Privacy Impact Assessments

A Privacy Impact Assessment (PIA) is a privacy risk assessment and public transparency document that explains how a DOI system, project, application, service, or electronic collection handles personally identifiable information (PII). A PIA describes what information is collected, why it is collected, how it is used, how it is shared, how it is protected, and how privacy risks are mitigated. 

The E-Government Act of 2002 requires federal agencies to conduct PIAs before developing or procuring information technology that collects, maintains, or disseminates information in identifiable form from or about members of the public, and to make PIAs publicly available when practicable. DOI also conducts PIAs and Adapted PIAs consistent with Office of Management and Budget guidance, the Privacy Act of 1974, DOI regulations and policy, and applicable National Institute of Standards and Technology privacy and security requirements. 

DOI uses PIAs for Department-owned or operated systems and Adapted PIAs for third-party websites, applications, platforms, or services used for public engagement, outreach, communication, or information collection. DOI also evaluates artificial intelligence, machine learning, automated analytics, and other emerging technologies through the Department’s privacy risk assessment process to determine whether a PIA, Adapted PIA, System of Records Notice (SORN) review, or other privacy compliance action is required. 

The DOI Privacy Office, within the Office of the Chief Information Officer, manages and coordinates the Department’s PIA process under the oversight of the Senior Agency Official for Privacy. System owners, program managers, Information System Security Officers, records officials, and other responsible officials coordinate with Privacy Officers and Privacy Analysts to ensure privacy risks are identified and addressed before systems or services are deployed or significantly modified. 

PIA Guidance and Review Process 

For information on how PIAs are conducted at DOI, see the DOI PIA Guide. If you need an accessible version of a document posted on this page, please contact the DOI Privacy Office at DOI_Privacy@ios.doi.gov

A Privacy Threshold Analysis (PTA) is generally used to determine whether a PIA, Adapted PIA, SORN review, or other privacy compliance action is required. PIAs should be completed or updated before a system, service, or project begins collecting, maintaining, using, sharing, or disseminating PII, and whenever a significant change creates new or changed privacy risks. 

Examples of changes that may require a new or updated PIA include new or expanded PII collection, new data sharing, migration to a cloud or third-party service, implementation of artificial intelligence or automated analytics, new public-facing services, new authentication or identity proofing capabilities, changes in retention or access controls, or integration with another system. 

PIAs and Adapted PIAs should be written in plain language so the public can understand what information DOI collects, how DOI uses it, and how DOI protects it. 

Published DOI PIAs 

The links below provide access to published PIAs and Adapted PIAs by Department-wide system, Bureau, or Office. These public postings support transparency and help individuals understand how DOI systems and services handle PII. 

Department-wide 

Adapted PIAs

Decommissioning PIAs

Office of the Secretary and Interior Business Center 

Decommissioning PIAs

Bureau of Indian Affairs 

Decommissioning PIAs

Bureau of Indian Education 
Bureau of Land Management 

Adapted PIAs

Decommissioning PIAs

Bureau of Ocean Energy Management 

Adapted PIAs

Decommissioning PIAs

Bureau of Reclamation 
Bureau of Safety and Environmental Enforcement 

Adapted PIAs

Decommissioning PIAs

Bureau of Trust Funds Administration 

Decommissioning PIAs

National Park Service 

Adapted PIAs

Decommissioning PIAs

Office of Inspector General 
Office of Natural Resources Revenue 
Office of Surface Mining Reclamation and Enforcement 
Office of the Solicitor 
U.S. Fish and Wildlife Service 

Decommissioning PIAs

U.S. Geological Survey 

Questions about PIAs 

For questions about DOI PIAs or the Department’s privacy risk assessment process, contact the DOI Privacy Office. The DOI Privacy Office will route inquiries to the appropriate Privacy Officer, Privacy Analyst, system owner, or program office as needed. 

If you are seeking access to records about yourself or want to authorize disclosure of Privacy Act records to another person or entity, visit the Privacy Act Requests page. Where available, individuals may submit Privacy Act requests electronically through FOIAXpress PAL. A Login.gov account is required to access the electronic submission process and complete remote identity proofing and authentication, where required. 

Related Privacy Resources