﻿<?xml version="1.0" encoding="UTF-8"?>


<pai>
<agency toc="yes">
<name>National Credit Union Administration</name>
<abbrev>
NCUA
</abbrev>
    <previousPubs id="systems" toc="yes">
        <title>Systems of Records Published Between January 3, 2022 and December 29, 2023</title>
    </previousPubs>
    <previouslyPublished>
        <url>https://www.govinfo.gov/content/pkg/FR-2022-05-02/pdf/2022-09338.pdf</url>
        <title> Reasonable Accommodations Records System, NCUA-25</title>
        <date year="2022" month="5" day="2" />
    </previouslyPublished>
    <previouslyPublished>
        <url>https://www.govinfo.gov/content/pkg/FR-2022-10-20/pdf/2022-22802.pdf</url>
        <title> Examination and Supervision System (ESS) – NCUA-22</title>
        <date year="2022" month="10" day="20" />
    </previouslyPublished>
    <previouslyPublished>
        <url>https://www.govinfo.gov/content/pkg/FR-2023-04-13/pdf/2023-07846.pdf</url>
        <title>NCUA-26, Prospective Official Application Records.</title>
        <date year="2023" month="4" day="13" />
    </previouslyPublished>
    <previouslyPublished>
        <url>  </url>
        <title>NCUA-27, NCUA General Support System Records.</title>
        <date year="2023" month="4" day="13" />
    </previouslyPublished>
    <previouslyPublished>
        <url>https://www.govinfo.gov/content/pkg/FR-2023-06-08/pdf/2023-12246.pdf</url>
        <title>Anti-Harassment Case Tracking and Records, NCUA-28.</title>
        <date year="2023" month="6" day="8" />
    </previouslyPublished>
    <previouslyPublished>
        <url>https://www.govinfo.gov/content/pkg/FR-2023-07-06/pdf/2023-14274.pdf</url>
        <title>NCUA-11, Office of Inspector General (OIG) Investigative Records</title>
        <date year="2023" month="7" day="6" />
    </previouslyPublished>
    <previouslyPublished>
        <url>https://www.govinfo.gov/content/pkg/FR-2023-07-25/pdf/2023-15737.pdf</url>
        <title>Non-Payroll Employee Administrative Records, NCUA-29</title>
        <date year="2023" month="7" day="25" />
    </previouslyPublished>

    <section id="ncua1" toc="yes">
        <systemNumber>-1</systemNumber>
        <subsection type="systemName">Personnel Access and Security System (PASS)</subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>Office of Continuity and Security Management, National Credit Union Administration, 1775 Duke Street, Alexandria, VA. 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>Government Organization and Employees (5 U.S.C. 301); 5 U.S.C. Chapter 73 (Suitability, Security, and Conduct); 5 U.S.C. 7531-33 (National Security); Federal Information Security Management Act of 2002 (44 U.S.C. 3541); E-Government Act of 2002 (44 U.S.C. 101); Paperwork Reduction Act of 1995 (44 U.S.C. 3501); Executive Order 10450 (Security requirements for government employment); Executive Order 13526 and its predecessor orders (National Security Information); Executive Order 12968 (Access to Classified Information); Executive Order 13857 (Security of Classified Networks and Information); Homeland Security Presidential Directive 12 (HSPD-12), August 27, 2004); 12 U.S.C § 1785 and NCUA Rules and Regulations 701.14; Section 212 of the Federal Credit Union Act (12 U.S.C § 1790a).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>The collected information enables NCUA OCSM to identify and review allegations of misconduct or negligence in employment and other security information relevant to making HSPD-12 PIV card issuance determinations, and personnel suitability, fitness, and/or national security determinations. It also improves the handling of sensitive personal information and facilitates NCUA’s ability to identify potential insider threats or potential systemic security concerns.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p>The system will collect and maintain information on individuals who require short- or long-term access as required by their position to NCUA-controlled facilities and information technology systems, including NCUA employees, appointees, interns, contractors, students, volunteers, and other non-federal employees either presently or formerly in any of these positions; applicants for NCUA employment or for work on NCUA contracts; applicants, appointees, employees, interns or contractors for whom an Office of Personnel Management (OPM) suitability, fitness or national security clearance investigation has been initiated and/or conducted; officials from troubled or newly chartered credit unions; visitors to NCUA facilities and their security clearance information; foreign national visitors.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>Incident and investigative material relating to any category of individual described above, including case files containing information such as full name, date of birth, gender, photograph, social security number, place of birth, citizenship; work and home telephone numbers and addresses; identification documentation (such as passports, work visas, driver’s licenses); security screening information (such as resume, employer address, applications for employment, fingerprints, credit checks); legal case pleadings and files; employment information (NCUA employment status, former employment letters of reference, former employment letters of termination or resignation); information obtained during security inquires (such as letters of inquiry; other agency database checks and reports; suspicious activity reports and notifications from other agencies and employees; network audit records, email, chat conversations, text messages sent using NCUA devices; social media account findings for individuals undergoing security investigations); self-reported security-related information (such as foreign travel notifications, changes in financial status, changes in marital status, arrests); security violation files; security evaluations and clearances; NCUA security screening status (permanent or provisional); personnel identity verification (PIV) information (such as card status, PIV card number, PIN number).</p>
                <p>For visitors, information collected can include names, date of birth, citizenship, identification type, temporary pass number, host name, office symbol, room number, telephone number.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>Information is provided by the individual to whom the record pertains; references supplied by the individual such as current and/or former employers and associates; public records such as court documents, news media, social media and other publications; intra-agency records; and investigative and other record material compiled in the course of investigation or furnished by other government agencies.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p>NCUA OCSM uses these records to document the outcome of adjudicative determinations for the issuance of the HSPD-12 PIV card or the local agency access badge, and to document the outcome of adjudicative determinations for suitability, fitness, and/or national security clearances.  Contact information is used for communication and authentication purposes.  In addition with those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, all or a portion of records in this system may be disclosed to authorized federal or state entities as it is determined to be relevant and necessary. </p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Records are stored electronically and physically.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Records are retrieved by individual identifiers such as name, social security number, or an individual identifier with non-individually identifiable information.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>Records are maintained until they become inactive.  Records become inactive when they are no longer useful for their collected purpose.  Records are disposed in accordance with NCUA record retention schedules and consistent with destruction methods appropriate to the type of information.</p>
                <p>Physical, Procedural, And Administrative Safeguards:  Information in the system is safeguarded in accordance with the applicable laws, rules and policies governing the operation of federal information systems.  Access to privacy-related information within the system is password protected and restricted to authorized personnel.  Physical records in paper format are safeguarded in accordance with the applicable laws, rules and policies governing privacy-related information.  All records in paper format are stored under the requisite double-lock.  Access to privacy-related information in paper format is restricted to authorized personnel.   </p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Deputy Director, Office of Continuity and Security Management, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p>Upon verification that an individual has a record in the system, as determined by the notification procedure below, the system manager will provide the procedure for gaining access to available records.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>Requests to amend or correct a record should be submitted in writing to the system manager listed above in accordance with NCUA regulations at 12 CFR Part 792, Subpart E. Requesters must reasonably identify the record, specify the information being contested, state the corrective action sought and the reasons for the correction along with supporting justification showing why the record is not accurate, timely, relevant, or complete.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>An individual can determine if this system contains a record pertaining to the individual by addressing a request in writing to the system manager listed above in accordance with NCUA regulations at 12 CFR Part 792, Subpart E. The individual must provide his/her full name and identify the date he/she was associated with NCUA as well as contact information for a response. If there is no record on the individual, the individual will be so advised.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>In addition to any exemption to which this system is subject by Notices published by or regulations promulgated by OPM or the Director of National Intelligence, the system is subject to a specific exemption pursuant to 5 U.S.C. 552a (k)(5) to the extent that disclosures would reveal a source who furnished information under an express promise of confidentiality, or prior to September 27, 1975, under an express or implied promise of confidentiality.</p>
            </xhtmlContent>
        </subsection>
    </section>

    <section id="ncua2" toc="yes">
<systemNumber>-2</systemNumber>
<subsection type="systemName">Grievance Records.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Current or former Federal employees who have submitted grievances with NCUA in accordance with part 771 of the OPM's regulations. These case files contain all documents related to the grievance, including statements of witnesses, reports of interviews and hearings, examiners' findings and recommendations, a copy of the original and final decision with related correspondence and exhibits.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>5 U.S.C. 1302, 3301, and 3302, E.O. 10577, 3 CFR 1954-1958 Comp., p. 218; E.O. 10987; 3 CFR 1959-1963 Comp., p. 519.
</p><p>Purpose:</p>
<p>The information in this system is used in the Agency's formal grievance process.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) Information is used by the appropriate Federal, State, or local agency responsible for investigating, prosecuting, enforcing, or implementing a statute, rule, regulation, or order where the disclosing agency becomes aware of an indication of a violation or potential violation of civil or criminal law or regulations. (2) Information is used by any source from which additional information is requested in the course of processing a grievance to the extent necessary to identify the individual, inform the source of the purpose(s) of the request, and identify the type of information requested. (3) Information is used by a Federal agency in response to its request in connection with the hiring or retention of an employee, the issuance of a security clearance, the conducting of a security or suitability investigation of an individual, the classifying of jobs, the letting of a contract, or the issuance of a license, grant, or other benefit by the requesting agency, to the extent that the information is relevant and necessary to the requesting agency's decision on the matter. (4) Information is used by the congressional office from the record of an individual in response to an inquiry from that congressional office made at the request of that individual. (5) Information is used by another Federal agency or by a court when the government is party to a judicial proceeding before the court. (6) Information is used by the National Archives and Records Administration (General Services Administration) in records management inspections conducted under authority of 44 U.S.C. 2904 and 2906. (7) Information is used by NCUA in the production of summary descriptive statistics and analytical studies in support of the function for which the records are collected and maintained, or for related work force studies. While published statistics and studies do not contain individual identifiers, in some instances, the selection of elements of data included in the study may be structured in such a way as to make the data individually identifiable by inference. (8) Information is used by officials of the Office of Personnel Management, the Merit Systems Protection Board, including the Office of the Special Counsel, the Federal Labor Relations Authority and its General Counsel, or the Equal Employment Opportunity Commission when requested in performance of their authorized duties. (9) Information (that is relevant to the subject matter involved in a pending judicial or administrative proceeding) is used to respond to a request for discovery or for appearance of a witness. (10) Information is used by officials of labor organizations reorganized under the Civil Service Reform Act when relevant and necessary to their duties of exclusive representation concerning personnel policies, practices, and matters affecting work conditions. (11) Standard routine uses as set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are maintained in file folders.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records are retrievable by the names of the individuals on whom they are maintained.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Records are maintained in lockable metal filing cabinets to which only authorized personnel have access.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are disposed of three (3) years after closing of the case. Disposal is by shredding or burning.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>Director, Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Request to amend or correct a record should be directed to the system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Individual on whom the record is maintained; testimony of witness; agency officials; related correspondence from organization or persons.
</p></xhtmlContent></subsection></section>
<section id="ncua3" toc="yes">
<systemNumber>-3</systemNumber>
<subsection type="systemName">Payroll Records System.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of the Chief Financial Officer, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428. NCUA also has an interagency agreement with the General Services Administration, Region VI, Kansas City, Missouri to provide and maintain payroll and related services and systems involving NCUA employees. For administrative purposes, supporting documents in hard copy form may exist within NCUA at the duty station of each employee.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Employees of NCUA.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Salary and related payroll data, including time and attendance information.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>5 U.S.C. 703; 44 U.S.C. 3301.
</p><p>Purpose:</p>
<p>This system documents time and attendance and ensures that employees receive proper compensation and that NCUA's financial reports properly reflect employee salary and benefit payments. It is also used to allow the agency to budget employee pay and benefits.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) Information is used to ensure proper compensation to all NCUA employees and to formulate financial reports and plans used within the agency, or is sent to the General Services Administration (GSA). (2) Information is used to document time worked and provide a record of attendance to support payment of salaries and use of annual, sick, and nonpaid leave. (3) Users of the time and attendance information include the employee's supervisor, the office's timekeeper, the payroll officer, staff involved in the budget process, accountants responsible for the proper recording of payroll results, and the GSA National Payroll Center in Kansas City, Missouri. (4) Further information in this system is used to make reports to state and local taxing authorities. (5) The names, social security numbers, home addresses, dates of birth, dates of hire, quarterly earnings, employer identifying information, and State of hire of employees may be disclosed to the Office of Child Support Enforcement, Administration for Children and Families, Department of Health and Human Services for the purpose of locating individuals to establish paternity, establish or modify orders of child support, identify sources of income and for other child support enforcement actions as required by the Personal Responsibility and Work Opportunity Reconciliation Act (Welfare Reform Law, Pub. L. 104-193). (6) Standard routine uses as set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are maintained in electronic media or in paper format.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records are retrieved by name or social security number.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Records are maintained in secured offices, accessible by written authorization only.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are retained and disposed of in accordance with GSA policy.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>Primary:
</p><p>Payroll Officer, Office of the Chief Financial Officer, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p><p>Secondary:
</p><p>Office Timekeepers, National Credit Union Administration, Central Office (1775 Duke Street, Alexandria, Virginia 22314-3428) and Regional Offices (see appendix B for Regional Offices' addresses).
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Information is primarily obtained from the individual whom the record concerns, the Office of Personnel Management, and the GSA. Also, time and attendance information is prepared and submitted by the timekeeper in a given employee's office.
</p></xhtmlContent></subsection></section>
<section id="ncua4" toc="yes">
<systemNumber>-4</systemNumber>
<subsection type="systemName">Travel Advance and Voucher Information System.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of the Chief Financial Officer, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>All NCUA employees who have traveled or relocated in the course of performing their duty and who have been reimbursed for the expense of such travel.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>This system contains information from the following forms: Travel Vouchers (NCUA 1012), Relocation Travel Order (NCUA 1617) Application for Travel Advance (NCUA 1371), and Travel Voucher Cover Sheet (NCUA 1364), Agreement to Remain in Federal Service (NCUA 1030), Statement of Difference (NCUA 1310), Repayment of Travel Advance (NCUA 1372), Direct Deposit Form (SF-1199A).
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>5 U.S.C. 5701-5752; Executive Order 11609 (July 22, 1971); Executive Order 11012 (March 27, 1962); 5 U.S.C. 4101-4118; Federal Travel Regulations, FPMR 101-7, Chapter 2, Section 6.3.
</p><p>Purpose:</p>
<p>The purpose of this system is to allow for the management and storage of employee-related master data, properly account for employee-related reimbursements and provide documentary support for reimbursements to employees.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) Records are used to provide documentary support for reimbursements to employees for on-the-job and relocation travel expenses. (2) Users of the information include first and second line supervisors, NCUA accounting staff, and budgeting staff. (3) Standard routine uses as set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are stored in paper hard copy form and in a computer system.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records are retrievable by social security number and name.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>The paper hard copy records are maintained in secured offices. The computer disc and accounting system is located in a secured office and its access is limited to only those employees who need the information to process travel-related transactions.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are maintained in the Division of Financial Control until the annual financial audit is completed. After the audit, the paper records are stored in a Federal Records Center for a minimum of three years and the computer disc is purged. The accounting system is archived as necessary.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>Director, Division of Financial Control, Office of the Chief Financial Officer, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Records are prepared by the individual whom the record concerns.
</p></xhtmlContent></subsection></section>
    <section id="ncua5" toc="yes">
        <systemNumber>-5</systemNumber>
        <subsection type="systemName">
            Unofficial Personnel and Employee Development/Correspondence Records.
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>
                    The NCUA originally published NCUA-5 on January 21, 2001 (65 FR 3486).  The NCUA republished NCUA-5 on December 27, 2006 (71 FR 77807), and July 16, 2010 (75 FR 41539).  Both of the publications were of full republications of the NCUA’s SORNs, neither of which included substantive changes to NCUA-5.
                </p>
            </xhtmlContent>
        </subsection>
    </section>

    <section id="ncua6" toc="yes">
<systemNumber>-6</systemNumber>
<subsection type="systemName">Emergency Information (Employee) File.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>For employees of a regional office, the system is located at the regional office where the employee is assigned, National Credit Union Administration, (<i>See</i> appendix B for addresses of Regional Offices). For employees of the central office, the system is located at the assigned office, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>NCUA employees; individuals designated by employees as emergency contacts; family members of employees.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>This system contains personal information about NCUA employees, such as height, weight, hair color, eye color, current address, and telephone number, and in some locations may also have a personal cell telephone number and personal email address. Also, this system identifies the individual to contact in case of an emergency involving the employee.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>5 U.S.C. 301.
</p><p>Purpose:</p>
<p>The information in this system is used to maintain employee identification information in case of emergency.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) The information on the individual to contact in cases of emergency may be disclosed in case of emergency to any federal, state or local authority responding to the emergency. (2) In the event of an emergency, the information may be disclosed to the individual listed as a contact in case of emergency, or other person identified as a family member of the employee. This list is updated as necessary. The listed information is used to contact the employee if there is a national emergency. (3) Standard routine uses as set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are stored on paper hard copy and may also be stored electronically.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records are indexed alphabetically by name and, where stored electronically as part of a computer system, are subject to electronic safeguards.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Records are maintained in locked file drawers or stored electronically as part of a computer database.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are disposed of after an employee is separated from the agency.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>(1) For employees of an NCUA regional office, the system manager is the regional director of the regional office where the employee is assigned (See appendix B for addresses of Regional Offices). For employees of the central office, the system manager is the Office Director of the assigned office, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the appropriate system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the appropriate system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Individual on whom the record is maintained.
</p></xhtmlContent></subsection></section>
<section id="ncua7" toc="yes">
<systemNumber>-7</systemNumber>
<subsection type="systemName">Employee Injury File.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Any employee who has sustained a job-related injury or disease.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Copies of reports submitted by an individual who has sustained a job-related injury or disease. Copies of any further claims made regarding the same injury or disease or any other material required for documenting and adjudicating the claim.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>Occupational Safety and Health Act of 1970, 29 CFR part 1960.
</p><p>Purpose:</p>
<p>This information is maintained to provide data to the Department of Labor, when needed, for adjudication of a claim, and to prepare reports as required by the Department of Labor.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) Information is disclosed to the Department of Labor. (2) Standard routine use as set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are stored on paper in file cabinets.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records are retrieved by date of injury and employee name.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Records are maintained in a locked file drawer.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are disposed five years after the year to which they relate.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>Director, Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Individual on whom the record is maintained; superiors of individual; individual's physician; hospital attending individual; Department of Labor.
</p></xhtmlContent></subsection></section>
<section id="ncua8" toc="yes">
<systemNumber>-8</systemNumber>
<subsection type="systemName">Investigative Reports Involving Any Crime, Suspected Crime or Suspicious Activity Against a Credit Union.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428. Computerized records of Suspicious Activity Reports (SAR), with status updates, are managed by the Financial Crimes Enforcement Network (FinCEN), Department of the Treasury, pursuant to a contractual agreement, and are stored in Detroit, Michigan. Authorized personnel at NCUA's Central Office and regional offices have on-line access to the computerized database managed by FinCEN through individual work stations linked to the database central computer.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Directors, officers, committee members, employees, agents, and persons participating in the conduct of the affairs of federally insured credit unions who are reported to be involved in suspected criminal activity or suspicious financial transactions and are referred to law enforcement officials; and other individuals who have been involved in irregularities, violations of law, or unsafe or unsound practices referenced in documents received by the NCUA in the course of exercising its supervisory functions.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Inter- and intra-agency correspondence, memoranda, and reports. The SAR contains information identifying the credit union involved, the suspected person, the type of suspicious activity involved, and any witnesses.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>12 U.S.C. 1786 and 1789.
</p></xhtmlContent></subsection>
<subsection type="purpose"><xhtmlContent><p>The overall system serves as an NCUA repository for investigatory or enforcement information related to its responsibility to examine and supervise federally insured credit unions. The system maintained by FinCEN serves as the database for the cooperative storage, retrieval, analysis, and use of information relating to Suspicious Activity Reports made to or by the NCUA Board, the Federal Reserve Board, the Office of the Comptroller of the Currency, the Federal Deposit Insurance Corporation, the Office of Thrift Supervision, (collectively, the Federal financial regulatory agencies), and FinCEN to various law enforcement agencies for possible criminal, civil, or administrative proceedings based on known or suspected violations affecting or involving persons, financial institutions, or other entities under the supervision or jurisdiction of such Federal financial regulatory agencies.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>Information in these records may be used to: (1) Determine if any further agency action should be taken. (2) Provide the federal financial regulatory agencies and FinCEN with information relevant to their operations; (3) Disclose information to third parties during the course of an investigation to the extent necessary to obtain information pertinent to the investigation; (4) With regard to formal or informal enforcement actions; release information pursuant to 12 U.S.C. 1786(s), which requires the NCUA Board to publish and make available to the public final orders and written agreements, and modifications thereto; and (5) Standard routine uses as set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>The records will be maintained in electronic data processing systems and paper files.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Computer output and file folders are retrievable by indexes of data fields, including name of the credit union, NCUA Region, and individuals' names.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Paper records and word processing discs are stored at the NCUA in lockable metal file cabinets. The database maintained by FinCEN complies with applicable security requirements of the Department of the Treasury. On-line access to the information in the database is limited to authorized individuals who have been designated by each federal financial regulatory agency and FinCEN, and each such individual has been issued a nontransferable identifier or password.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are maintained indefinitely.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>General Counsel, NCUA, 1775 Duke Street, Alexandria, VA 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>Inquiries should be sent to the System Manager as noted above.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Same as "Notification procedure" above.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Same as "Notification procedure" above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Information received by the NCUA Board from various sources, including, but not limited to law enforcement and other agency personnel involved in sending inquiries to the NCUA Board, NCUA examiners, credit union officials, employees, and members. The information maintained by FinCEN is compiled from SAR and related historical and updating forms compiled by financial institutions, the NCUA Board, and the other federal financial regulatory agencies for law enforcement purposes.
</p></xhtmlContent></subsection>
<subsection type="systemsExempted"><xhtmlContent><p>This system is exempt from 5 U.S.C. 552a(c)(3), (d)(1), (d)(2), (d)(3), (d)(4), (e)(1), (e)(4)(G), (H) and (I), and (f) of the Privacy Act pursuant to 5 U.S.C. 552a(k)(2).
</p></xhtmlContent></subsection></section>
<section id="ncua9" toc="yes">
<systemNumber>-9</systemNumber>
<subsection type="systemName">Freedom of Information and Privacy Act Requests and Invoices.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>(1) Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428. (2) Office of Inspector General National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428. (3) For requests prior to 2006 processed by a regional office, the system is located at the regional office (see appendix B for a list of addresses of the regional offices). (4) For requests prior to 2006 processed by the Asset Management and Assistance Center, the system is located at AMAC, 4807 Spicewood Springs Road, Suite 5100, Austin, Texas 78759-8490.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>This system of records includes information pertaining to any Freedom of Information Act (FOIA) or Privacy Act requester.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>The system may contain the requester's name, company name or organization, address, date of request, invoice number, amount due, phone number, social security or tax identification number, description of information requested and documents located or result of search for documents.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>12 U.S.C. 1789, 5 U.S.C. 552, 5 U.S.C. 552a.
</p><p>Purpose:</p>
<p>Records in this system are used to process requests received. These records may be used by the NCUA for collection of the amount due, as well as to identify subsequent requests made by the same individuals.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) The information may be disclosed to a consumer reporting agency. The information disclosed to a consumer reporting agency is limited to: (a) Information necessary to establish the identity of the individual, including name, address, and social security or taxpayer identification number; (b) the amount, status, and history of the claim; and (c) the agency or program under which the claim arose.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are maintained in paper and electronic form.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records in this system are retrievable by requester's name, company name or organization, date of request, category of requester, request number, invoice number, or key words.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Physical security consists of storing records on a password protected computer database and a hard copy secured in a metal file cabinet which is accessible only to those individuals responsible for processing requests and collecting outstanding payments.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are retained for various periods depending on the determination made on the request, but normally no greater than six years following the year in which the request was processed.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>(1) Freedom of Information Act Officer, Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428. (2) For requests processed by the Office of Inspector General, Inspector General, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>The sources of records for this system of records are the FOIA and Privacy Act request files.
</p></xhtmlContent></subsection></section>
<section id="ncua10" toc="yes">
<systemNumber>-10</systemNumber>
<subsection type="systemName">Liquidating Credit Union Records System.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Information within this system of records is located at the Asset and Management Assistance Center (AMAC) 4807 Spicewood Springs Road, Suite 5100, Austin, Texas 78759.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Members, employees and creditors of liquidating federally-insured credit unions.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Share and account records; personal data regarding income and debts; payment or employment history; accounts payable records.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>12 U.S.C. 1787.
</p><p>Purpose:</p>
<p>The information in this system is used to determine insurance, collect loan amounts due and for all purposes necessary to close out the affairs of the liquidated credit union.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) Information is used for payment of insurance claims to shareholders in liquidating federally-insured credit unions. (2) Information is used in the collection of outstanding loans, which may include referral of information to third party service providers or potential purchasers of the loans. (3) Information is used for all purposes necessary to close out the affairs of the liquidated credit union and carry out all appropriate liquidation-related functions of NCUA. (4) Information may be disclosed to address locators or a surety company in pursuit of a fidelity bond claim. (5) Information on unclaimed insured shares is included in a database on the NCUA Web site after other efforts to locate account holders have failed. (6) Information may be disclosed to the appropriate federal, state or local government agency, such as the Internal Revenue Service, if required by law or regulation or upon appropriate request. (7) Standard routine uses as set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>This information is maintained on computer databases and hard copy. Copies of share and loan documents, incoming payments, and loan portfolios may also be maintained on microfilm copy.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Information is indexed by name of individual and by name of closed insured credit union.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Information is maintained in secured offices and in password protected computer databases.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Information is maintained for six years following the appointment of the NCUA Board as liquidating agent of an insured credit union unless the NCUA's Record Management Policy requires a different time period or does not require the information to be maintained. After the retention period is completed, the system manager may destroy any records that the system manager determines are unnecessary unless directed not to do so by a court of competent jurisdiction or governmental agency or prohibited by law.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>President, AMAC, 4807 Spicewood Springs Road, Suite 5100, Austin, Texas 78759-8490.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains information pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no information on the individual, the individual will be so advised. Written inquiries should include name of inquirer, name of closed insured credit union of which inquirer was a member, and share and loan account numbers, if known.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available information.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Information is obtained from outside address locators; share and loan account files of the liquidating credit union of which the individual was a member; third party service providers; and credit bureaus.
</p></xhtmlContent></subsection></section>
<section id="ncua11" toc="yes">
<systemNumber>-11</systemNumber>
    <subsection type="systemName">
        <p>  NCUA-11, Office of Inspector General (OIG) Investigative Records.</p>
    </subsection>
    <subsection type="securityClassification">
        <xhtmlContent>
            <p>Unclassified.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="systemLocation">
        <xhtmlContent>
            <p>Office of Inspector General, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="systemManager">
        <xhtmlContent>
            <p> Counsel to the Inspector General/Assistant Inspector General for Investigations, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="authorityForMaintenance">
        <xhtmlContent>
            <p>Federal Credit Union Act, 12 U.S.C. 1751, et seq., and the Inspector General Act of 1978, 5 U.S.C. 401, et seq.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="purpose">
        <xhtmlContent>
            <p> This system is maintained for the purposes of:</p>
            1.	<p>1. Conducting and documenting investigations by the OIG or other investigative agencies regarding NCUA programs, operations, personnel, and contractors, and reporting the results of investigations to NCUA management, other Federal agencies, and other public authorities or professional organizations that have the authority to bring criminal prosecutions or civil or administrative actions, or to impose disciplinary sanctions;</p>
            2.	<p>2. Documenting the outcome of OIG investigations;</p>
            3.	<p>3. Maintaining a record of the activities that were the subject of investigations;</p>
            4.	<p>4. Reporting investigative findings for use in operating and evaluating NCUA programs or operations and in the imposition of sanctions;</p>
            5.	<p>5. Maintaining a record of complaints and allegations received regarding NCUA programs, operations, and personnel, and documenting the outcome of OIG reviews and disposition of those complaints and allegations;</p>
            6.	<p>6. Coordinating relationships with other Federal agencies, State and local governmental agencies, and nongovernmental entities in matters relating to the statutory responsibilities of the OIG and reporting to such entities on government-wide efforts pursuant to the oversight of Federal funds;</p>
            7.	<p>7. Acting as a repository and source for information necessary to fulfill the reporting requirements of the Inspector General Act, 5 U.S.C. 401-424;</p>
            8.	<p>8. Reporting on OIG activities to the Council of Inspectors General for Integrity and Efficiency (CIGIE); and</p>
            9.	<p>9. Participating in CIGIE’s investigative qualitative assessment review process.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="categoriesOfIndividuals">
        <xhtmlContent>
            <p>Subjects of investigation, complainants, and witnesses referred to in complaints or investigative cases, reports, accompanying documents, and correspondence prepared by, compiled by, or referred to the OIG.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="categoriesOfRecords">
        <xhtmlContent>
            <p> The system is comprised of OIG investigation files and complaint files. These files include reports of investigations with related exhibits, statements, affidavits, or other pertinent documents. Files may contain memoranda; computer-generated background information; location information; payroll, time sheets, and travel records; correspondence, including call, text, and email records; and reports from or to other law enforcement bodies pertaining to violations or potential violations of criminal laws, fraud, or abuse with respect to administration of NCUA programs and operations, and violations of employee and contractor standards of conduct. Records in this system may contain personally identifiable information such as names, Social Security numbers, dates of birth, and addresses. This system may also contain such information as employment history, bank account information, driver’s licenses, vehicle registration, educational records, criminal history, photographs, voice recordings, and other information of a personal nature provided or obtained in connection with an investigation.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="routineUsesOfRecords">
        <xhtmlContent>
            <p>In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside the NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:</p>
            <p>1. If a record in a system of records indicates a violation or potential violation of civil or criminal law or a regulation, and whether arising by general statute or particular program statute, or by regulation, rule, or order, the relevant records in the system of records may be disclosed as a routine use to the appropriate agency, whether Federal, State, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto;</p>
            <p>2. A record in a system of records may be disclosed as a routine use to a member of Congress or to a congressional staff member in response to an inquiry from the congressional office made at the request of the individual about whom the record is maintained;</p>
            <p>3. A record in a system of records may be disclosed as a routine use to the Department of Justice, when: (a) NCUA, or any of its components or employees acting in their official capacities, is a party to litigation; or (b) Any employee of NCUA in his or her individual capacity is a party to litigation and where the Department of Justice has agreed to represent the employee; or (c) The United States is a party in litigation, where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation;</p>
            <p>4. A record in a system of records may be disclosed as a routine use in a proceeding before a court or adjudicative body before which NCUA is authorized to appear (a) when NCUA or any of its components or employees are acting in their official capacities; (b) where NCUA or any employee of NCUA in his or her individual capacity has agreed to represent the employee; or (c) where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation;</p>
            <p>5. A record from a system of records may be disclosed as a routine use to contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for NCUA when necessary to accomplish an agency function or administer an employee benefit program. Individuals provided information under this routine use are subject to the same Privacy Act requirements and limitations on disclosure as are applicable to NCUA employees;</p>
            <p> 6. A record from a system of records may be disclosed as a routine use to the Department of Justice, including its U.S. Attorney’s Offices, and State and local prosecutors, to the extent necessary to obtain legal advice on any matter relevant to an OIG investigation, audit, inspection, or other inquiry related to the responsibilities of the OIG;</p>
            <p>7. A record from a system of records may be disclosed as a routine use to any Federal agency, entity, or board responsible for coordinating and conducting oversight of Federal funds, in order to prevent fraud, waste, and abuse related to Federal funds, or for assisting in the enforcement, investigation, prosecution, or oversight of violations of administrative, civil, or criminal law or regulation, if that information is relevant to any enforcement, regulatory, investigative, prosecutorial, or oversight responsibility of the NCUA or of the receiving entity;</p>
            <p>8. A record from a system of records may be disclosed as a routine use to another Federal agency considering suspension or debarment action if the information is relevant to the suspension or debarment action. The OIG also may disclose information to another agency to gain information in support of the NCUA’s own debarment and suspension actions;</p>
            <p>9. A record from a system of records may be disclosed as a routine use to the Council of the Inspectors General on Integrity and Efficiency (CIGIE) to assist in its preparation of reports, analysis, surveys, coordination of investigations, and other CIGIE activities;</p>
            <p>10. A record from a system of records may be disclosed as a routine use to other Federal entities, such as other Offices of Inspector General, to the Government Accountability Office, or to a private party with which the OIG or the NCUA has contracted or with which it contemplates contracting, for the purpose of auditing or reviewing the performance or internal management of the OIG’s audit or investigative programs.</p>
            <p>11. A record from a system of records may be disclosed as a routine use to a complainant alleging whistleblower reprisal and the complainant’s employer (current or former) that at the time of the alleged reprisal was a grantee, subgrantee, contractor, or subcontractor of the NCUA, to fulfill the whistleblower reprisal investigation reporting requirements of 41 U.S.C. 4712(b)(1) or any other whistleblower reprisal law requiring a disclosure to a complainant or an entity that employs or employed the complainant;</p>
            <p>12. A record from a system of records may be disclosed to appropriate agencies, entities, and persons when (1) NCUA suspects or has confirmed that the security or confidentiality of information in the system of records has been compromised; (2) NCUA has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by NCUA or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with NCUA’s efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm; and</p>
            <p>13. A record from a system of records may be disclosed to another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in (1) responding to a suspected or confirmed breach or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="policiesAndPractices">
        <xhtmlContent>
            <p>  Electronic records and backups are stored on secure servers, approved by NCUA’s Office of the Chief Information Officer (OCIO), within a FedRAMP-authorized commercial Cloud Service Provider’s (CSP) Software-as-a-Service solution hosting environment and accessed only by authorized personnel.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="retrievability">
        <xhtmlContent>
            <p> Information is retrieved by case number, general subject matter, or name of the subject of investigation.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="retentionAndDisposal">
        <xhtmlContent>
            <p> Records are maintained and disposed in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or an NCUA records disposition schedule approved by NARA.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="safeguards">
        <xhtmlContent>
            <p>NCUA and the Cloud Service Provider have implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub. L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures. The records are maintained behind a layered defensive posture consistent with all applicable Federal laws and regulations, including OMB Circular A-130 and NIST Special Publication 800-37.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="recordAccessProcedures">
        <xhtmlContent>
            <p>Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
            <p>1. Full name.</p>
            <p>2. Any available information regarding the type of record involved.</p>
            <p>3. The address to which the record information should be sent.</p>
            <p>4. You must sign your request.</p>
            <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf. Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
        </xhtmlContent>
    </subsection>
    <subsection type="contestingRecordProcedures">
        <xhtmlContent>
            <p>  Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
            <p>1. Full name.</p>
            <p>2. Any available information regarding the type of record involved.</p>
            <p>3. A statement specifying the changes to be made in the records and the justification therefore.</p>
            <p>4. The address to which the response should be sent.</p>
            <p>5. You must sign your request.</p>
            <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="notificationProcedure">
        <xhtmlContent>
            <p> Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
            <p>1. Full name.</p>
            <p>2. Any available information regarding the type of record involved.</p>
            <p>3. The address to which the record information should be sent.</p>
            <p>4. You must sign your request.</p>
            <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf. Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
        </xhtmlContent>
    </subsection>
    <subsection type="exemptionsClaimed">
        <xhtmlContent>
            <p>Pursuant to 5 U.S.C. 552a(j)(2), this system of records is exempt from subsections (c)(3) and (4), (d), (e)(1), (e)(2), (e)(3), (e)(4)(G), (e)(4)(H), (e)(4)(I), (e)(5), (e)(8), (f) and (g) of the Act. This exemption applies to information in the system that relates to criminal law enforcement and meets the criteria of the (j)(2) exemption. Pursuant to 5 U.S.C. 552a(k)(2), to the extent that the system contains investigative material compiled for law enforcement purposes, other than material within the scope of subsection (j)(2), this system of records is exempt from 5 U.S.C. 552a(c)(3), (d), (e)(1), (e)(4)(G), (H), and (I), and (f). The exemption rule is contained in 12 CFR 792.66 of the NCUA regulations.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="history">
        <xhtmlContent>
            <p> This SORN was published originally as NCUA-20, "Investigation Files," at 53 FR 37372 (Sept. 26, 1988); renamed to "Office of Inspector General Investigative Records" at 60 FR 18149 (April 10, 1995); and renumbered as NCUA-11 at 65 FR 3486 (Feb. 20, 2000). Subsequent modifications were published at 71 FR 77807 (Dec. 27, 2006) and 75 FR 41539 (July 16, 2010).</p>
        </xhtmlContent></subsection></section>
<section id="ncua12" toc="yes">
<systemNumber>-12</systemNumber>
    <subsection type="systemName">
        Consumer Complaints Against Federal Credit Unions – NCUA-12
    </subsection>
    <subsection type="securityClassification">
        <xhtmlContent>
            <p> None.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="systemLocation">
        <xhtmlContent>
            <p>NCUA Consumer Assistance Center, Office of Consumer Financial Protection,  National Credit Union Administration, 1775 Duke Street, Alexandria, VA. 22314-3428. Third party service provider, Salesforce.com, Inc. The Landmark at One Market, Suite 300, San Francisco, CA 94105.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="systemManager">
        <xhtmlContent>
            <p> Division of Consumer Affairs Director, Office of Consumer Financial Protection, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="authorityForMaintenance">
        <xhtmlContent>
            <p>12 U.S.C. 1752a, 12 U.S.C. 1766, 12 U.S.C. 1784(a), and 12 U.S.C. 1789.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="purpose">
        <xhtmlContent>
            <p> The system supports the NCUA’s supervisory oversight and enforcement responsibilities to intake and respond to consumer inquiries, complaints and other communications from the general public, credit unions and other state and federal government banking and law enforcement agencies regarding federal consumer financial protection laws, regulations and credit union activity.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="categoriesOfIndividuals">
        <xhtmlContent>
            <p>Individuals who are members of the public that contact the NCUA’s Consumer Assistance Center by telephone, written correspondence and web search, including both general inquiries and complaints concerning federal financial consumer protection matters within credit unions.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="categoriesOfRecords">
        <xhtmlContent>
            <p>This system contains correspondence and records of other communications between the NCUA and the individual submitting a complaint or making an inquiry, including copies of supporting documents and contact information supplied by the individual. This system may also contain regulatory and supervisory communications between the NCUA and the NCUA-insured credit union in question and/or intra-agency or inter-agency memoranda or correspondence relevant to the complaint or inquiry.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="recordSourceCategories">
        <xhtmlContent>
            <p> Information is provided by the individual complainant, and his or her representative such as, a member of Congress or an attorney.  Information is also provided by federal credit union officials and employees.  Information is provided by the individual to whom the record pertains, internal agency records, and investigative and other record material compiled in the course of an investigation, or furnished by other state and federal financial regulatory and law enforcement government agencies.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="routineUsesOfRecords">
        <xhtmlContent>
            <p>  The NCUA’s Consumer Assistance Center uses these records to document the submission of and responses to consumer inquiries, complaints and other communications from the general public regarding federal consumer financial protection laws, regulations and credit union activity.</p>
            <p>In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, all or a portion of the records or information contained in this system may be disclosed outside the NCUA as a routine use as follows:</p>
            <p>(1) Information may be disclosed to officials of federal credit unions and other persons mentioned in a complaint or identified during an investigation.</p>
            <p>(2) Disclosures may be made to the Federal Reserve Board, other federal financial regulatory agencies, the Federal Financial Institutions Examination Council, the White House Office of Consumer Affairs, and the Congress, or any of its authorized committees in fulfilling reporting requirements or assessing implementation of applicable laws and regulations. (Such disclosures will be made in a non-identifiable manner when feasible and appropriate.)</p>
            <p>(3) Referrals may also be made to other federal and nonfederal supervisory or regulatory authorities when the subject matter is a complaint or inquiry which is more properly within such agency's jurisdiction.</p>
            <p> (4)  NCUA’s Standard Routine Uses apply to this system of records.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="policiesAndPractices">
        <xhtmlContent>
            <p>Records are stored electronically and physically.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="retrievability">
        <xhtmlContent>
            <p>Records are retrieved by individual identifiers such as individual complainant’s name.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="retentionAndDisposal">
        <xhtmlContent>
            <p> All records, including audio records, are retained in a secure and encrypted cloud-based storage system for a period of seven years consistent with the National Archives and Records Administration records retention schedule.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="safeguards">
        <xhtmlContent>
            <p>Information in the system is safeguarded in accordance with the applicable laws, rules and policies governing the operation of federal information systems.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="recordAccessProcedures">
        <xhtmlContent>
            <p>Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
            <p>1. Full name.</p>
            <p>2. Any available information regarding the type of record involved.</p>
            <p>3. The address to which the record information should be sent.</p>
            <p>4. You must sign your request.</p>
            <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
        </xhtmlContent>
    </subsection>
    <subsection type="contestingRecordProcedures">
        <xhtmlContent>
            <p> Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
            <p>1. Full name.</p>
            <p>2. Any available information regarding the type of record involved.</p>
            <p>3. A statement specifying the changes to be made in the records and the justification therefore.</p>
            <p>4. The address to which the response should be sent.</p>
            <p>5. You must sign your request.</p>
            <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
        </xhtmlContent>
    </subsection>
    <subsection type="notificationProcedure">
        <xhtmlContent>
            <p> Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
            <p>1. Full name.</p>
            <p>2. Any available information regarding the type of record involved.</p>
            <p>3. The address to which the record information should be sent.</p>
            <p>4. You must sign your request.</p>
            <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
        </xhtmlContent>
    </subsection>
    <subsection type="history">
        <xhtmlContent>
            <p> This system of records notice was originally published in 65 FR 3486 (January 21, 2000). It was republished (but not substantively changed in 75 FR 41539 (July 16, 2010), and 71 FR 77807 (December 27, 2006).</p>

        </xhtmlContent>
            </subsection>
        </section>

<section id="ncua13" toc="yes">
<systemNumber>-13</systemNumber>
<subsection type="systemName">Litigation Case Files.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Records are maintained in files by the case name of individuals who are: the subject of NCUA investigations made in contemplation of legal action; involved in civil litigation with NCUA or involved in administrative proceedings; involved in litigation of interest to NCUA; or pursuing tort claims.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Records in case files include: Investigative reports relating to possible felonies or violations of the Federal Credit Union Act; transcripts of testimony or affidavits; documents and other evidentiary matters, pleadings and other documents filed in court; orders filed or issued in civil, administrative or criminal proceedings; correspondence relating to investigatory or litigation matters; information provided by the individual under investigation or from a Federal credit union; and other memoranda gathered and prepared by staff in performance of their duties.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>12 U.S.C. 1766, 1786, 1787, and 1789; 28 U.S.C. 2671-2680.
</p><p>Purpose:</p>
<p>This system documents the preparation and progress of legal proceedings and investigations conducted by the Office of General Counsel.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) The staff of the Office of General Counsel may use such records to render legal advice concerning investigations or courses of legal action; to represent NCUA in all judicial and administrative proceedings in which NCUA or any of its employees who, within the scope of employment and in an official capacity, is a party; or to intervene as an amicus curiae. (2) The information in this system may be disclosed to federal, state, local or professional licensing boards or Boards of Medical Examiners, when such records reflect on the qualifications or fitness of a licensed individual or an individual seeking to be licensed. (3) Standard routine uses set forth in appendix A.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the system manager listed above.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Record source categories vary depending upon the legal issue but generally are obtained from the following: NCUA staff and internal agency memoranda; federal employees and private parties involved in torts; contracts; federal credit union files or officials; general law texts and sources; law enforcement officers; witnesses and others; administrative and court pleadings, transcripts or judicial orders/decisions; evidence gathered in connection with the matter involved; and from individuals to whom the records relate.
</p></xhtmlContent></subsection>
<subsection type="systemsExempted"><xhtmlContent><p>This system is subject to the specific exemption provided by 5 U.S.C. 552a(k)(2), as the system of records is investigatory material compiled for law enforcement purposes.
</p></xhtmlContent></subsection></section>
<section id="ncua14" toc="yes">
<systemNumber>-14</systemNumber>
<subsection type="systemName">PaymentNet J.P.Morgan Chase Bank PaymentNet.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>J.P.Morgan Chase Bank, N.A. Commercial Card Solutions (Elgin, IL).
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Employees of NCUA with individually billed government travel cards and/or centrally billed government travel cards.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>NCUA employee credit card data, including name and address, and past and present charges to account.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>Federal Travel Regulations, Travel and Transportation Reform Act of 1998 (Pub. L. 105-264).
</p><p>Purpose:</p>
<p>The purpose of this system is for the Office of the Chief Financial Officer (OCFO) to monitor the usage of the government travel card by NCUA employees and to assure timely payments of accounts.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>The system can be used by individual cardholders to access their own account information to monitor charges, payments, change their address, etc. It is also used by OCFO to provide oversight of the travel card program by monitoring card usage in order to reduce card misuse, abuse, and delinquencies.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are maintained in a database that is accessible by Internet over a 128-bit encryption secure connection.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records are retrieved by name or account number.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Records are maintained in a secure database that can only be accessed with a username and password provided by Bank of America after receipt of an application submitted by the OCFO. Only authorized staff in OCFO can access multiple employee records, all other employees can only access their own account information within the PaymentNet system.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>All account activity (charges, payments, credits, <i>etc.</i>) is retained in the PaymentNet system for 36 months. All information on closed accounts (name, address, activity) is retained for 36 months before it is permanently removed from the PaymentNet system.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>Deputy Financial Officer, Office of the Chief Financial Officer, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire about his/her personal account information by accessing the PaymentNet system with a username and password provided to them by Bank of America or by written request to OCFO.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon approval of the cardholder application and issuance of the government travel card by BOA, a username and password is also submitted to the cardholder for access to their account information in PaymentNet.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be submitted online through the PaymentNet system or submitted in writing to OCFO.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Records are prepared by the individual whom the record concerns by submission of an application to J.P.Morgan Chase Bank and by the subsequent activity to the individual's account.
</p></xhtmlContent></subsection></section>
<section id="ncua15" toc="yes">
<systemNumber>-15</systemNumber>
<subsection type="systemName">Contract Employee Pay and Leave Records.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Information within this system of records is located at the Asset Management and Assistance Center (AMAC) 4807 Spicewood Springs Road, Suite 5100, Austin TX 78759-8490, and the payroll processor, Paychex of San Antonio, Texas.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Contract employees hired by the Agent for the Liquidating Agent for work on liquidation cases.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Wages and related payroll data, including leave records.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>Fair Labor Standards Act.
</p><p>Purpose:</p>
<p>This system documents employee information and ensures that employees receive proper compensation.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>Information is used to document time worked and provide a record of attendance to support payment of wages and use of leave. Users of the system include the payroll officer (financial analyst), the employee's supervisor, and Paychex.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are maintained in file folders.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Records are retrieved by name.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>Records are maintained in a secured file cabinet, accessible only to the payroll officer and division manager.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are retained and disposed of in accordance with the Fair Labor Standards Act.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p><i>Primary:</i> Financial Analyst, Asset Management and Assistance Center (4807 Spicewood Springs Road, Suite 5100, Austin TX 78759-8490).
</p><p><i>Secondary:</i> Division of Accounting Service Director, Asset Management and Assistance Center (4807 Spicewood Springs Road, Suite 5100, Austin TX 78759-8490).
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection></section>
<section id="ncua16" toc="yes">
<systemNumber>-16</systemNumber>
<subsection type="systemName">Leave Transfer Program Case Files.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of Human Resources, 1775 Duke Street, Alexandria, VA 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>NCUA employees who submitted applications to become leave recipients under the provisions of the Leave Transfer program.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Leave transfer program applications, leave requests, and medical documentation.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>5 CFR 630.913.
</p><p>Purpose:</p>
<p>To administer the NCUA leave transfer program.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>These records are used to administer the NCUA leave transfer program.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>These records are maintained in file folders and filed in metal file cabinets.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>The records are retrieved by the names of the employee.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p>These files are kept in a locked room and are available only to authorized personnel whose duties require access.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>These records are maintained in accordance with NARA General Records Schedules 1 (Civilian Personnel Records). Disposal of manual records is by shredding.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>Director, Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual or an individual's authorized representative may inquire as to whether the system contains a record pertaining to the individual by addressing a request in person or by mail to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p></xhtmlContent></subsection></section>
<section id="ncua17" toc="yes">
<systemNumber>-17</systemNumber>
<subsection type="systemName">Personal Identity Verification Files.
</subsection>
<subsection type="systemLocation"><xhtmlContent><p>Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent><p>Individuals who require regular, ongoing access to federal facilities, information technology systems, or information classified in the interest of national security, including applicants for employment or contracts, federal employees, contractors, students, interns, volunteers, affiliates, individuals authorized to perform or use services provided in NCUA facilities and individuals formerly in any of these positions. The system also includes individuals accused of security violations or found in violation.
</p></xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent><p>Name, former names, birth date, birth place, Social Security number, home address, phone numbers, employment history, residential history, education and degrees earned, names of associates and references and their contact information, citizenship, names of relatives, birthdates and places of relatives, citizenship of relatives, names of relatives who work for the federal government, criminal history, mental health history, drug use, financial information, fingerprints, summary report of investigation, results of suitability decisions, level of security clearance, date of issuance of security clearance, requests for appeal, witness statements, investigator's notes, tax return information, credit reports, security violations, circumstances of violation, and agency action taken. Copies of background investigation forms such as the SF-85, SF-85P, SF-86, or SF-87 may also be included in this file.
</p></xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent><p>Executive orders 10450, 10865, 12333, and 12356; sections 3301 and 9101 of title 5, U.S. Code; sections 2165 and 2201 of title 42, U.S. Code; sections 781 to 887 of title 50, U.S. Code; parts 5, 732, and 736 of title 5, Code of Federal Regulations; and Homeland Security Presidential Directive (HSPD) 12, Policy for a Common Identification Standard for Federal Employees and Contractors, August 27, 2004.
</p></xhtmlContent></subsection>
<subsection type="purpose"><xhtmlContent><p>The records in this system of records are used to document and support decisions regarding clearance for access to classified information, the suitability, eligibility, and fitness for service of applicants for Federal employment and contract positions, including students, interns, or volunteers to the extent their duties require access to federal facilities, information, systems, or applications. The records may be used to document security violations, employee access and attendance, and supervisory actions taken.
</p></xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent><p>(1) The information maintained in this system is collected from PIV Applicants, the individuals to whom a PIV card is issued. The PIV Applicant may be a current or prospective Federal hire, a Federal employee or a contractor. The information is used in each step of the PIV Process for example, conducting a background investigation, completing the identity proofing and registration process, creating an employee record in the Comprehensive Human Resources Integrated System (CHRIS), issuing a PIV card and the determination of physical and logical access. Additionally, the information such as card expiration date, PIV Registrar Approval, etc. is maintained in this file and is used to assist in the production of the PIV card. (2) The information in this system may be disclosed to the United States Office of Personnel Management, the Merit Systems Protection Board, the Office of Special Counsel, the Equal Employment Opportunity Commission, the Federal Labor Relations Authority, the General Services Administration or an arbitrator or agent to the extent the disclosure is needed to carry out the government-wide personnel management, investigatory, adjudicatory and appellate functions within their respective jurisdictions, or to obtain information. (3) The information in this system may be disclosed to federal, state, local or professional licensing boards or boards of Medical Examiners, when such records reflect on the qualifications of a licensed individual or individual seeking to be licensed. (4) Standard routine uses as set forth in Appendix A.
</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent><p>Storage:</p>
<p>Records are stored on paper and electronically in a secure location.
</p></xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent><p>Files are retrieved by name or Social Security number (SSN), employee name, and employee identification number.
</p></xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent><p><i>For paper records:</i> Comprehensive paper records are kept in a secure room at NCUA Central Office, Office of Human Resources. Limited paper records may be kept at NCUA regional offices in locked file cabinets in locked rooms. Access to the records is limited to those employees who have a need for them in the performance of their official duties.
</p><p><i>For electronic records:</i> Comprehensive electronic records are kept at the NCUA Central Office, Office of Human Resources. Access to the records is restricted to those with a specific role in the PIV process that requires access to information to perform their duties, and who have been given a password to access that part of the system. Controls are in place to identify unauthorized access. Persons given roles in the PIV process must complete training specific to their roles to ensure they are knowledgeable about how to protect individually identifiable information. Electronic records of security badge and parking pass usage for access to the Central Office and access to parking are accessible by selected staff in the Division of Procurement and Facilities Management.
</p></xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent><p>Records are destroyed upon notification of death or not later than five years after separation or transfer of employee to another agency, whichever is applicable.
</p></xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent><p>Security Officer, Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.
</p></xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent><p>An individual can determine if this system contains a record pertaining to the individual by addressing a request in writing to the system manager listed above. If there is no record on the individual, the individual will be so advised.
</p><p>When requesting notification of or access to records covered by this system, an individual should provide at a minimum his/her full name, date of birth, office and duty location in order to establish identity.
</p></xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent><p>Upon request, the system manager will set forth the procedures for gaining access to available records.
</p></xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent><p>Requests to amend or correct a record should be directed to the system manager listed above. Requesters should also reasonably identify the record, specify the information they are contesting, state the corrective action sought and the reasons for the correction along with supporting justification showing why the record is not accurate, timely, relevant, or complete.
</p></xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent><p>Information is obtained from a variety of sources including the employee, contractor, or applicant via use of the SF-85, SF-85P, or SF-86 and personal interviews; employers' and former employers' records; FBI criminal history records and other databases; financial institutions and credit reports; medical records and health care providers; educational institutions; interviews of witnesses such as neighbors, friends, co-workers, business associates, teachers, landlords, or family members; tax records; and other public records. Security violation information is obtained from a variety of sources, such as witnesses or supervisor's reports. Electronic records are created based on use of security badges and parking passes at readers at entrances and exits to parking at the Central Office, building entrances, and building elevators.
</p></xhtmlContent></subsection></section>
<section id="ncua18" toc="yes">
<systemNumber>-18</systemNumber>
<subsection type="systemName">Credit Union Service Organization (CUSO) Registry System.</subsection>
<subsection type="securityClassification"><xhtmlContent>
<p>Unclassified.</p>
</xhtmlContent></subsection>
<subsection type="systemLocation"><xhtmlContent>
<p>Office of Examination and Insurance, National Credit Union Administration, 1775 Duke Street, Alexandria, VA. 22314-3428.</p>
</xhtmlContent></subsection>
<subsection type="categoriesOfIndividuals"><xhtmlContent>
<p>Individuals responsible for the content and submission of information to the CUSO Registry System and individuals with an ownership interest in the CUSO.</p>
</xhtmlContent></subsection>
<subsection type="categoriesOfRecords"><xhtmlContent>
<p>Information used to identify and contact individuals covered by the system including name, address, and telephone number.</p>
</xhtmlContent></subsection>
<subsection type="authorityForMaintenance"><xhtmlContent>
<p>12 U.S.C. 1756, 1757(5)(D) and (7)(I), 1766, 1781(b)(9), 1782, 1784, 1785, 1786 and 1789(11).; 12  CFR Parts 712 and 741.</p>
</xhtmlContent></subsection>
<subsection type="purpose"><xhtmlContent>
<p>The collected information enables NCUA to identify concentrations and interdependencies between CUSOs and across supervised credit unions.  It also improves the consistency and transparency of CUSO information and facilitates NCUA’s ability to identify any potential systemic safety and soundness concerns stemming from relationships between credit unions and CUSOs.  </p>
<p>Disclosure to consumer reporting agencies:  </p>
<p>None.</p>
</xhtmlContent></subsection>
<subsection type="routineUsesOfRecords"><xhtmlContent>
<p>NCUA may share information in this system with appropriate federal or state financial supervision authorities.  Contact information is used for communication and authentication purposes.  A registered CUSO may authorize other users, such as owner credit unions or affiliated CUSOs or individuals, to access its record.</p></xhtmlContent></subsection>
<subsection type="policiesAndPractices"><xhtmlContent>
<p>Storage:  </p>
<p>Records are stored electronically.</p>
</xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent>
<p>Records are retrieved by individual business identifiers such as business name, system-assigned registry number, unique user identification, or by an individual identifier with non-individually identifiable information.</p>
</xhtmlContent></subsection>
<subsection type="safeguards"><xhtmlContent>
<p>Information in the system is safeguarded in accordance with the applicable laws, rules and policies governing the operation of federal information systems.  Information in the system that is available to the general public does not include any privacy-related information.  Access to privacy-related information is password protected and restricted to authorized personnel.  </p>
</xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent>
<p>Records are maintained until they become inactive.  Records are disposed in accordance with NCUA record retention schedules and consistent with destruction methods appropriate to the type of information.  </p>
</xhtmlContent></subsection>
<subsection type="systemManager"><xhtmlContent>
<p>CUSO Program Officer, Office of Examination and Insurance, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.</p>
</xhtmlContent></subsection>
<subsection type="notificationProcedure"><xhtmlContent>
<p>An individual can determine if this system contains a record pertaining to the individual by addressing a request in writing to the system manager listed above. If there is no record on the individual, the individual will be so advised.  The individual must provide his/her full name and identify the CUSO he/she is associated with as well as contact information for a response.</p>
</xhtmlContent></subsection>
<subsection type="recordAccessProcedures"><xhtmlContent>
<p>Upon verification that an individual has a record in the system, as determined by the notification procedure above, the system manager will provide the procedure for gaining access to available records.</p>
</xhtmlContent></subsection>
<subsection type="contestingRecordProcedures"><xhtmlContent>
<p>Requests to amend or correct a record should be directed to the system manager listed above. Requesters should also reasonably identify the record, specify the information they are contesting, state the corrective action sought and the reasons for the correction along with supporting justification showing why the record is not accurate, timely, relevant, or complete.</p>
</xhtmlContent></subsection>
<subsection type="recordSourceCategories"><xhtmlContent>
<p>Information is provided by the individual to whom the record pertains or by a representative of the associated CUSO.</p></xhtmlContent></subsection>
<subsection type="exemptionsClaimed"><xhtmlContent>
<p>None.</p></xhtmlContent></subsection></section>

    <section id="ncua19" toc="yes">
        <systemNumber>-19</systemNumber>
        <subsection type="systemName">
            NCUA Financial and Acquisition Management System
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>None.</p>
            </xhtmlContent> </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>Enterprise Services Center,  6500 South MacArthur Blvd., Oklahoma City, OK 73169;  NCUA, 1775 Duke Street, Alexandria, VA 22314.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Chief Financial Officer, Office of the Chief Financial Officer, NCUA, 1775 Duke Street, Alexandria, VA 22314.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>12 USC 1751; 31 U.S.C. 3501, et seq. and 31 U.S.C. 7701(c).  Where the employee identification number is the social security number, collection of this information is authorized by Executive Order 9397.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>This system serves as the core financial and acquisition system and integrates program, financial, and budgetary information.  Records are collected to ensure that all obligations and expenditures (other than those in the pay and leave system) are in conformance with laws, existing rules and regulations, and good business practices, and to maintain subsidiary records at the proper account and/or organizational level where responsibility for control of costs exists.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p>NCUA employees, contractors, suppliers, vendors, interns, and customers.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>Employee personnel information:  Limited to current and former NCUA employees, and includes name, address, Social Security number (SSN).  Business-related information:  Limited to contractors/vendors, customers, and credit unions (but not their members), and includes name of the company/agency, point of contact, telephone number, mailing address, email address, contract number, vendor number (system unique identifier), DUNS number, and TIN, which could be a SSN in the case of individuals set up as sole proprietors, and total assets and insured shares.  Financial information:  Includes financial institution name, lockbox number, routing transit number, deposit account number, account type, debts (e.g., unpaid bills/invoices, overpayments, etc.), and remittance address.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>The information maintained in Department of Transportation, (DOT)/Enterprise Service Center (ESC) systems including:  Purchase orders, contracts, vouchers, invoices, contracts, disbursements, receipts/collections, Pay.Gov transactions, and related records; U.S. General Services Administration (GSA) Federal personnel payroll system (for payroll disbursement postings): Concur (for travel disbursements); JPMorgan Chase (for charge card payments; travel advance applications; other records submitted by  individuals, employees, vendors, and other sources.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p>In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:</p>
                <p>1. NCUA’s Standard Routine Uses apply to this system of records (see below).</p>
                <p>2. Records may be shared with a vendor that NCUA is doing business with if a dispute about payments or amounts due arises. In such a situation, only the minimum amount of information need to resolve the dispute will be shared with the vendor.</p>
                              </xhtmlContent>
    </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Records are maintained in paper and/or electronic form.  Records are also maintained on NCUA’s network back-up tapes.  Electronic records are stored in computerized databases.  Records are stored in locked file rooms and/or file cabinets.</p>
               
                </xhtmlContent></subsection>
<subsection type="retrievability"><xhtmlContent>

                <p>Records are retrieved by any one or more of the following:  Records may be retrieved by a name of employee, employee ID, employee NCUA email address, social security number (SSN) for employees, SSN/Tax Identification Number (TIN) for vendors doing business with the NCUA, name for both employees and vendors, supplier number (system unique) for both employees and vendors, DUNS and DUNS + 4.</p>
                
                </xhtmlContent></subsection>
<subsection type="retentionAndDisposal"><xhtmlContent>

                <p>Records are maintained in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or a NCUA records disposition schedule approved by NARA.</p>
                <p>Records existing on paper are destroyed beyond recognition. Records existing on computer storage media are destroyed according to the applicable NCUA media sanitization practice.</p>
                       </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>NCUA has adopted appropriate administrative, technical, and physical controls in accordance with NCUA’s information security policies to protect the security, integrity, and availability of the information, and to ensure that records are not disclosed to or accessed by unauthorized individuals.</p>
                <p>Records are safeguarded in a secured environment.  Buildings where records are stored have security cameras and 24 hour security guard service.  The records are kept in limited access areas during duty hours and in locked file cabinets and/or locked offices or file rooms at all other times.  Access is limited to those personnel whose official duties require access.  Computerized records are safeguarded through use of access codes and information technology security.  Contractors and other recipients providing supplies and/or services to the NCUA are contractually obligated to maintain equivalent safeguards.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p>Individuals should submit a written request to the Privacy Officer, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>a. Full name.</p>
                <p>b. Any available information regarding the type of record involved, and the name of the system containing the record.</p>
                <p>c. The address to which the record information should be sent.</p>
                <p>d. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
                <p>Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>Individuals wishing to request an amendment to their records should submit a written request to the Privacy Officer, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>a. Full name.</p>
                <p>b. Any available information regarding the type of record involved.</p>
                <p>c. A statement specifying the changes to be made in the records and the justification therefor.</p>
                <p>d. The address to which the response should be sent.</p>
                <p>e. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Privacy Officer, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>a. Full name.</p>
                <p>b. Any available information regarding the type of record involved.</p>
                <p>c. The address to which the record information should be sent.</p>
                <p>d. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
                <p>Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>None.</p>
            </xhtmlContent></subsection></section>

    <section id="ncua20" toc="yes">
        <systemNumber>-20</systemNumber>
        <subsection type="systemName">Small Credit Union Learning Center
            </subsection>
        <subsection type="securityClassification">
              <p>None.</p>
            </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>NCUA, 1775 Duke Street, Alexandria, VA 22314; PowerTrain, 8201 Corporate Drive, Suite 580, Landover, MD 20785; OPM, 1900 E Street, NW, Suite 4439-AB, Washington, DC 20415</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Deputy Director, Office of Small Credit Union Initiatives, NCUA, 1775 Duke Street, Alexandria, VA 22314.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>12 U.S.C 1751.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>To provide and manage online training courses for credit union elected officials and employees.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p> Credit union elected officials and employees who complete the training course(s).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>Training records, which may include name, email address, username, password, credit union name, charter number, course name, and date of completion of the training course(s).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>Individuals who complete the training course(s).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p>In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows, and:</p>
                <p>1. NCUA’s Standard Routine Uses apply to this system of records.</p>
                <p>2.  At the request of a specific credit union, records pertaining to individuals associated with the requesting credit union may be shared with that credit union.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Records are maintained in electronic form.</p>
                      </xhtmlContent>
    </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Records are retrieved by any one or more of the following: name, username, email address, credit union name, charter number, course name, and month or year of completion of a training course.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>Records are maintained in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or a NCUA records disposition schedule approved by NARA.</p>
                <p>Records existing on computer storage media are destroyed according to the applicable NCUA media sanitization practice.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>NCUA has adopted appropriate administrative, technical, and physical controls in accordance with NCUA’s information security policies to protect the security, integrity, and availability of the information, and to ensure that records are not disclosed to or accessed by unauthorized individuals.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p>Individuals wishing access to their records should submit a written request to the Privacy Officer, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>a. Full name.</p>
                <p>b. Any available information regarding the type of record involved.</p>
                <p>c. The address to which the record information should be sent.</p>
                <p>d. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>Individuals wishing to request an amendment to their records should submit a written request to the Privacy Officer, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>a. Full name.</p>
                <p>b. Any available information regarding the type of record involved.</p>
                <p>c. A statement specifying the changes to be made in the records and the justification therefor.</p>
                <p>d. The address to which the response should be sent.</p>
                <p>e. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Privacy Officer, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>a. Full name.</p>
                <p>b. Any available information regarding the type of record involved.</p>
                <p>c. The address to which the record information should be sent.</p>
                <p>d. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>None.</p>
            </xhtmlContent>
        </subsection>
    </section>

    <section id="ncua21" toc="yes">
        <systemNumber>-21</systemNumber>
        <subsection type="systemName">
            <xhtmlContent>
                <p>
                    NCUA Connect
                </p>
            </xhtmlContent>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>Unclassified.</p></xhtmlContent>
                </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>The system is operated and maintained in part by NCUA staff, and in part by third-party vendors.  Please contact the system managers (below) for more information.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Director of the Office of Business Innovation, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p> 12 U.S.C. 1751, et. seq.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>This system of records is maintained for the purpose of carrying out the NCUA’s statutorily mandated examination and supervision activities.  Specifically, this system is the interface through which authorized users access NCUA’s other major examination, supervision, and reporting related systems.  It is designed to provide a one-stop entry point for internal and external users, which should enhance user experience, while also streamlining security activities.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p> Individuals covered by this system are (1) Current and former directors, officers, employees, and agents of credit unions; (2) Current and former credit union service organization representatives; (3) Other individuals engaged in business with the NCUA for a specific purpose (such as outside counsel); and (4) NCUA employees and contractors, and State Supervisory Authority staff.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p> Records in the system contain basic log-in information, including username, password, email address, and role.  The system also contains log-in/access records.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>  The sources of information in the system are the individual users, or someone acting on their behalf (such as an administrator in their organization, or an NCUA employee or contractor).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p> In addition to those disclosures generally permitted under 5 U.S.C. § 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:</p>
                <p>1. NCUA’s Standard Routine Uses apply to this system of records.</p>
              
                </xhtmlContent>
    </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Electronic records and backups are stored on dedicated secure instance, approved by NCUA’s Office of the Chief Information Officer (OCIO), within a FedRAMP-authorized commercial Cloud Service Provider’s (CSP) Infrastructure as a Service (IaaS) hosting environment and accessed only by authorized personnel. No paper files are maintained.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p>Records are retrieved by name, username, affiliated organization, email, role, or date.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p> Records are maintained in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or a NCUA records disposition schedule approved by NARA.  Records existing on computer storage media are destroyed according to the applicable NIST-compliant media sanitization policy.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>NCUA has implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub.L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable federal laws and regulations, including OMB Circular A-130 and NIST Special Publications 800-37.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p>Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>  Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. A statement specifying the changes to be made in the records and the justification therefore.</p>
                <p>4. The address to which the response should be sent.</p>
                <p>5. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>None.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>  This is a new system.</p>
            </xhtmlContent>
        </subsection>
    </section>


    <section id="ncua22" toc="yes">
        <systemNumber>-22</systemNumber>
                    <subsection type="systemName">
                <p> Examination and Supervision System (ESS) – NCUA-22</p>
            </subsection>
            <subsection type="securityClassification">
                <xhtmlContent>
                    <p>Unclassified.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="systemLocation">
                <xhtmlContent>
                    <p>The system is operated and maintained in part by NCUA staff, and in part by third-party vendors.  Please contact the system managers (below) for more information.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="systemManager">
                <xhtmlContent>
                    <p>Director of the Office of Business Innovation and the Director of the Office of Examination and Insurance, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="authorityForMaintenance">
                <xhtmlContent>
                    <p>12 U.S.C. 1751, et. seq.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="purpose">
                <xhtmlContent>
                    <p>This system of records is maintained for the purpose of  carrying out the NCUA’s statutorily mandated examination and supervision activities, including the coordination and conduct of examinations, supervisory evaluations and analyses, enforcement actions and actions in Federal court.  NCUA may coordinate with other financial regulatory agencies on matters related to the safety and soundness of credit unions.  The information collected in this system also supports the conduct of investigations or other supervisory or legal actions by the NCUA or other supervisory or law enforcement agencies.  This may result in criminal referrals, referrals to Offices of Inspectors General, or the initiation of administrative or Federal court actions.  This system continues to track and store examination and supervision documents created during the performance of the NCUA’s statutory duties.  The information also is used for administrative purposes such as quality control, performance metrics, and improvements to examination and supervision processes.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="categoriesOfIndividuals">
                <xhtmlContent>
                    <p>Individuals covered by this system are (1) Current and former directors, officers, employees, and agents of credit unions; (2) Current and former members who are or have been serviced by credit unions; (3) Current and former credit union service organization representatives; (4) Other individuals engaged in business with the NCUA for a specific purpose (such as outside counsel); and (5) NCUA employees and contractors, and (6) State Supervisory Authority staff.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="categoriesOfRecords">
                <xhtmlContent>
                    <p>Records in the system may contain      (1) Contact information about credit union officials (such as members of the Board of Directors, Audit Committee Chair, Chief Executive Officer, Chief Compliance Officer, Internal Auditor, and Independent Auditor), such as name, address, phone number, and e-mail address;               (2) Demographic and financial information about individual credit union members, such as name, address, Social Security number, account information, loan and share information, and publicly available information; (3) Information about NCUA employees assigned to credit union examination and supervision tasks, such as name, work phone number, work e-mail address, and other employment information; (4) User information, such as name, email address, and role about other users of the system (such as contractors, credit union representatives, State Supervisory Authority staff, and Credit Union Service Organization representatives (CUSOs) and; (5) recordings of meetings between individuals representing the NCUA and credit unions.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="recordSourceCategories">
                <xhtmlContent>
                    <p>The information in the system about credit union officials and individual credit union members is generally provided by credit unions and CUSOs. NCUA employees and contractors, and State Supervisory Authorities may add additional information to the system as part of their assigned supervision and examination activities (including analytics/business intelligence activities).  Some of the information may be from third parties with relevant information about covered persons or service providers, or existing databases maintained by other Federal and state regulatory associations, law enforcement agencies, and related entities.  Whenever practicable, the NCUA collects information about an individual directly from that individual.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="routineUsesOfRecords">
                <xhtmlContent>
                    <p>In addition to those disclosures generally permitted under 5 U.S.C. § 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:</p>
                    <p>1. NCUA’s Standard Routine Uses apply to this system of records.</p>
                    <p>2. To a financial institution affected by enforcement activities or reported criminal activities;</p>
                    <p>3. To the Internal Revenue Service and appropriate State and local taxing authorities;</p>
                    <p>4. To another federal or state agency to: (a) permit a decision as to access, amendment or correction of records to be made in consultation with or by that agency, or (b) verify the identity of an individual or the accuracy of information submitted by an individual who has requested access to or amendment or correction of records;</p>
                    <p>5. To a grand jury pursuant either to a federal or state grand jury subpoena, or to a prosecution request that such record be released for the purpose of its introduction to a grand jury, where the subpoena or request has been specifically approved by a court;</p>
                    <p>6. To a court, magistrate, or administrative tribunal in the course of an administrative proceeding or judicial proceeding, including disclosures to opposing counsel or witnesses (including expert witnesses) in the course of discovery or other pre-hearing exchanges of information, litigation, or settlement negotiations, where relevant or potentially relevant to a proceeding related to the NCUA’s mission of providing a safe and sound credit union system.</p>
                    <p>7. To appropriate agencies, entities, and persons, including but not limited to potential expert witnesses, witnesses, or translators, in the course of supervision or enforcement related investigation;</p>
                    <p>8. To appropriate federal, state, local, foreign, tribal, or self-regulatory organizations or agencies responsible for investigating, prosecuting, enforcing, implementing, issuing, or carrying out a statute, rule, regulation, order, policy, or license if the information may be relevant to a potential violation of civil or criminal law, rule, regulation, order, policy, or license; and</p>
                    <p>9. To an entity or person that is the subject of supervision or enforcement activities including examinations, investigations, administrative proceedings, and litigation, and the attorney or non-attorney representative for that entity or person.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="policiesAndPractices">
                <xhtmlContent>
                    <p> Electronic records and backups are stored on dedicated secure servers, approved by NCUA’s Office of the Chief Information Officer (OCIO), within a FedRAMP-authorized commercial Cloud Service Provider’s (CSP) Infrastructure as a Service (IaaS) hosting environment and accessed only by authorized personnel.  No paper files are maintained.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="retrievability">
                <xhtmlContent>
                    <p>Records pertaining to individual credit union members are not generally retrieved outside of a scheduled examination or supervision contact.  However, such records can be retrieved by credit union name, charter number, credit union member’s name or other record in the system.  The system includes advanced search features that function essentially as a full-text search tool.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="retentionAndDisposal">
                <xhtmlContent>
                    <p>Records are maintained in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or a NCUA records disposition schedule approved by NARA.  Records existing on computer storage media are destroyed according to the applicable NIST-compliant media sanitization policy.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="safeguards">
                <xhtmlContent>
                    <p>NCUA has implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub.L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable federal laws and regulations, including OMB Circular A-130 and NIST Special Publications 800-37 and 800-53.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="recordAccessProcedures">
                <xhtmlContent>
                    <p>Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                    <p>1. Full name.</p>
                    <p>2. Any available information regarding the type of record involved.</p>
                    <p>3. The address to which the record information should be sent.</p>
                    <p>4. You must sign your request.</p>
                    <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
                </xhtmlContent>
            </subsection>
            <subsection type="contestingRecordProcedures">
                <xhtmlContent>
                    <p>Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                    <p>1. Full name.</p>
                    <p>2. Any available information regarding the type of record involved.</p>
                    <p>3. A statement specifying the changes to be made in the records and the justification therefore.</p>
                    <p>4. The address to which the response should be sent.</p>
                    <p>5. You must sign your request.</p>
                    <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
                </xhtmlContent>
            </subsection>
            <subsection type="notificationProcedure">
                <xhtmlContent>
                    <p> Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                    <p>1. Full name.</p>
                    <p>2. Any available information regarding the type of record involved.</p>
                    <p>3. The address to which the record information should be sent.</p>
                    <p>4. You must sign your request.</p>
                    <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
                </xhtmlContent>
            </subsection>
            <subsection type="exemptionsClaimed">
                <xhtmlContent>
                    <p> Federal criminal law enforcement investigatory reports maintained as part of this system may be the subject of exemptions imposed by the originating agency pursuant to 5 U.S.C. 552a(j)(2).</p>
                </xhtmlContent>
            </subsection>
            <subsection type="history">
                <xhtmlContent>
                    <p> 84 FR 11331.</p>
                </xhtmlContent>
        </subsection>
    </section>
    <section id="ncua23" toc="yes">
        <systemNumber>-23</systemNumber>
        <subsection type="systemName">
            <xhtmlContent>
                <p>
                    Mailing, Contact and Other Lists
                </p>
            </xhtmlContent>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>
                    Unclassified.
                </p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>The system is operated and maintained in part by the NCUA staff, and in part by third-party vendors.  Please contact the system managers (below) for more information.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Director of the Office of External Affairs and Communications, and the Director of the Office of Examination and Insurance, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>12 U.S.C. 1751, et. seq.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>This system of records is maintained for the purposes of supporting the National Credit Union Administration’s (NCUA’s) communications and outreach efforts to members of the public and to facilitate the  NCUA’s statutorily mandated examination and supervision activities, including:</p>
                <p>1. Handling requests for informational literature, newsletters, and other NCUA materials;</p>
                <p>2. Processing event registrations, conducting surveys, and providing information about NCUA-related activities and events and;</p>
                <p>3. Notifying credit unions of mandatory actions and updates that they must complete and are related to the NCUA’s mission of providing a safe and sound credit union system.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p>Individuals covered by this system are (1) Current and former directors, officers, employees, and volunteers of credit unions; (2) Members of the public; and (3) NCUA employees and contractors.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>Records in the system may contain contact information including name, title, address, phone number, and e-mail address.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>The information in the system about credit union officials is generally provided by credit unions for supervision and examination activities.  Other information may be from members of the public who submit requests for information, subscriptions, inquiries, guidance, and other assistance to the NCUA, and those who have registered for NCUA events and responded to questionnaires, request forms, feedback forms or surveys.  NCUA employees and contractors may add or update information to the system as part of their assigned duties to handle such correspondence, or for credit union supervision and examination activities.  Whenever practicable, the NCUA collects information about an individual directly from that individual.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p>In addition to those disclosures generally permitted under 5 U.S.C. § 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside the NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:</p>
                <p>1. NCUA’s Standard Routine Uses apply to this system of records.</p>
                <p>2. To appropriate agencies, entities, and persons for the purpose of supervision, enforcement, training, or other outreach activities.</p>
                <p>3. To an entity or person that is the subject of supervision or enforcement activities including examinations, investigations, administrative proceedings, and litigation, and the attorney or non-attorney representative for that entity or person.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Electronic records and backups are stored on secure servers, approved by NCUA’s Office of the Chief Information Officer (OCIO), within a FedRAMP-authorized commercial Cloud Service Provider’s (CSP) Software-as-a-Service solution hosting environment and accessed only by authorized personnel.  No paper files are maintained.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p>Records may be retrieved by any of the following: name, address, phone number, or e-mail address.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>Records are maintained until they become inactive and, in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or a NCUA records disposition schedule approved by NARA.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>NCUA and the Cloud Service Provider have implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub.L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable federal laws and regulations, including OMB Circular A-130 and NIST Special Publications 800-37.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p>Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>A statement specifying the changes to be made in the records and the justification therefore.</p>
                4.	<p>The address to which the response should be sent.</p>
                5.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>None.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>This is a new system.</p>
            </xhtmlContent>
        </subsection>
    </section>
    <section id="ncua24" toc="yes">
        <systemNumber>-24</systemNumber>
        <subsection type="systemName">
            <p>  Ensuring Workplace Health and Safety in Response to a Public Health Emergency, NCUA-24.</p>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>Unclassified.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p> Records are maintained at NCUA facilities in Alexandria, Virginia and regional offices.  Original and duplicate systems may exist, in whole or in part, at secure sites and on secure servers maintained by third-party service providers for the NCUA.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p> Director of the Office of Continuity and Security Management, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p> 12 U.S.C. 1751, et seq.; Americans with Disabilities Act, including 42 U.S.C. 12112(d)(3)(B), 29 CFR 1630.2(r), and 1630.14(b), (c), and (d)(4); Workforce safety Federal requirements, including the Occupational Safety and Health Act of 1970, 5 U.S.C. 7902; 29 U.S.C. Chapter 15 (e.g., 29 U.S.C. 668), 29 CFR part 1904, 29 CFR 1910.1020, and 29 CFR 1960.66; Executive Order 12196; Executive Order 14043.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>The information in the system is collected to assist the NCUA with maintaining a safe and healthy workplace and respond to a public health emergency (as defined by the U.S. Department of Health and Human Services and declared by its Secretary), such as a pandemic or epidemic.  These measures may include instituting activities such as: (1) requiring NCUA personnel (including applicants for Federal employment) to provide information and/or submit to a medical screening before being allowed access to an NCUA facility, and (2) contact tracing.  NCUA personnel may also need to provide information before being authorized to travel.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p> Individuals covered by this system include NCUA personnel, such as, political appointees, employees, contractors, detailees, consultants, interns, volunteers, and applicants for Federal employment</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>Information may include:</p>
                <p>●Name</p>
                <p>●Contact information (e.g., email address, phone number)</p>
                <p>●Employee ID number</p>
                <p>●Recent travel history</p>
                <p>●Whether the individual provides dependent care for an individual in a high-risk category</p>
                <p>●Health information, including:</p>
                <p>○Body temperature,</p>
                <p>○Confirmation of pathogen or communicable disease test,</p>
                <p>○Test results,</p>
                <p>○Dates, symptoms, potential or actual exposure to a pathogen or communicable disease,</p>
                <p>○Immunization or vaccination information;</p>
                <p>○Information to support a reasonable accommodation (for example, a request for exemption from a vaccination requirement), and</p>
                <p>○Other medical history related to the treatment of a pathogen or communicable disease</p>
                <p>●Contact tracing information, including:</p>
                <p>○Dates when the individual visited the NCUA facility or event, or worked on-site on behalf of the NCUA,</p>
                <p>○Locations that the individual visited within the facility (e.g., office and cubicle number),</p>
                <p>○Duration of time spent in the facility, and</p>
                <p>○Whether the individual may have potentially come into contact with a contagious person while visiting the facility.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p> The information in this system is collected in part directly from the individual.  Information is also collected from security systems monitoring access to NCUA facilities, such as video surveillance and turnstiles, human resources systems, emergency notification systems, and Federal, State, and local agencies assisting with the response to a public health emergency.  Information may also be collected from property management companies responsible for managing office buildings that house NCUA facilities.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p> In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, all or a portion of the records or information contained in this system may be disclosed outside the NCUA as a routine use as follows:</p>
                <p>1. To appropriate Federal, State, local and foreign authorities responsible for investigating or prosecuting a violation of, or for enforcing or implementing a statute, rule, regulation, or order issued, when the information indicates a violation or potential violation of law, whether civil, criminal, or regulatory in nature, and whether arising by general statute or particular program statute, or by regulation, rule, or order issued pursuant thereto;</p>
                <p>2. To an authorized appeal grievance examiner, formal complaints examiner, equal employment opportunity investigator, arbitrator or other duly authorized official engaged in investigation or settlement of a grievance, complaint, or appeal filed by an employee. Further, a record from any system of records may be disclosed as a routine use to the Office of Personnel Management in accordance with the agency’s responsibility for evaluation and oversight of Federal personnel management;</p>
                <p>3. To a court, magistrate, or other administrative body in the course of presenting evidence, including disclosures to counsel or witnesses in the course of civil discovery, litigation, or settlement negotiations or in connection with criminal proceedings, when the NCUA is a party to the proceeding or has a significant interest in the proceeding, to the extent that the information is determined to be relevant and necessary;</p>
                <p>4. To contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for the NCUA when necessary for the purpose of assisting the NCUA’s response to a public health emergency;</p>
                <p>5. To appropriate agencies, entities, and persons when (1) the NCUA suspects or has confirmed that the security or confidentiality of information in the system of records has been compromised; (2) the NCUA has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by the NCUA or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with the NCUA’s efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm;</p>
                <p>6. To another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in (1) responding to a suspected or confirmed breach or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach;</p>
                <p>7. To a Federal, State, or local agency to the extent necessary to comply with laws governing reporting of infectious disease; and</p>
                <p> 8. To members of Congress in response to requests made at the request of and on behalf of their constituents.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p> Electronic records and backups are stored on secure servers, approved by the NCUA’s Office of the Chief Information Officer (OCIO), within FedRAMP-authorized commercial Cloud Service Providers’ (CSP) Software-as-a-Service solutions hosting environments and accessed only by authorized personnel.  No paper files are maintained.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p>Records may be retrieved by any of the following: name, office, or e-mail address.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>Records are maintained and disposed of in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or an NCUA records disposition schedule approved by NARA.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>The NCUA and the Cloud Service Provider have implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub. L. 113-283, S. 2521, and the NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable Federal laws and regulations, including Office of Management and Budget (OMB) Circular A-130 and National Institute of Standards and Technology (NIST) Special Publications 800-37.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p> Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with the NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p> Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. A statement specifying the changes to be made in the records and the justification therefore.</p>
                <p>4. The address to which the response should be sent.</p>
                <p>5. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p> Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with the NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>None.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>This is a new system.</p>
            </xhtmlContent>
        </subsection>
    </section>
    <section id="ncua25" toc="yes">
        <systemNumber>-25</systemNumber>
        <subsection type="systemName">
            <p> Reasonable Accommodations Records–NCUA-25</p>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>Unclassified.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>The system is operated and maintained at the National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314.  Records may be located in locked cabinets and offices, on NCUA’s local area network, or in authorized cloud service providers.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Chief Human Capital Officer and Director of the Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>12 U.S.C. 1751, et. seq., The Rehabilitation Act of 1973, 29 U.S.C. 701, 791, 794; Title VII of the Civil Rights Act of 1964, 42 U.S.C. 2000e; 29 CFR 1605 (Guidelines on Discrimination Because of Religion); 29 CFR 1614 (Federal Sector Equal Employment Opportunity); 29 CFR 1614 (Regulations to Implement the Equal Employment Provisions of the Americans With Disabilities Act); 5 U.S.C. 302, 1103; Executive Order 13164, Requiring Federal Agencies to Establish Procedures to Facilitate the Provision of Reasonable Accommodation (July 26, 2000); and Executive Order 13548, Increasing Federal Employment of Individuals with Disabilities (July 26, 2010).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>This system of records is maintained for the purposes of:</p>
                <p>1. Collecting and maintaining records on NCUA applicants for employment, employees, and other individuals who participate in NCUA programs or activities and who request or receive reasonable accommodations or other appropriate modifications from the NCUA for medical or religious reasons;</p>
                <p>2. To process, evaluate, and make decisions on individual requests and;</p>
                <p>3. To track and report the processing of such requests agency-wide to comply with applicable requirements in law and policy.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p> Individuals covered by this system are (1) Applicants for Federal employment and (2) Federal employees who requested and/or received reasonable accommodations or other appropriate modifications from the NCUA for medical or religious reasons and; (3) other individuals who participate in NCUA programs or activities and who request or receive reasonable accommodations or other appropriate modifications from the NCUA for medical or religious reasons.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p> Records in the system may contain:</p>
                •	<p>●Requester’s name;</p>
                •	<p>●Requester’s status (applicant, current employee);</p>
                •	<p>●Requester’s position title, series, grade;</p>
                •	<p>●Requester’s supervisor’s name;</p>
                •	<p>● Requester’s contact information (addresses, phone numbers, and email addresses);</p>
                •	<p>● Description of the requester’s medical condition or disability and any medical documentation provided in support of the request;</p>
                •	<p> ●Medical provider’s name and contact information;</p>
                •	<p> ●Requester’s statement of a sincerely held religious belief and any additional information provided concerning that religious belief and the need for an accommodation to exercise that belief;</p>
                •	<p> ●The name/contact information of an individual’s religious or spiritual advisor;</p>
                •	<p> ●Description of the accommodation being requested;</p>
                •	<p>● Description of previous requests for accommodation;</p>
                •	<p> Whether the request was made orally or in writing;</p>
                •	<p> ●Whether the request for reasonable accommodation was granted or denied, and if denied, the reason for the denial;</p>
                •	<p> ●The amount of time taken to process the request;</p>
                •	<p> ●The sources of technical assistance consulted in trying to identify a possible reasonable accommodation;</p>
                •	<p> ●Any reports or evaluations prepared in determining whether to grant or deny the request;</p>
                •	<p> ●Any other information collected or developed in connection with the request for a reasonable accommodation.</p>
                •	<p> ●Decision-Maker’s name/signature and;</p>
                <p> ●Disability Program Manager’s name/signature.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>The information in the system is obtained from the individuals who request and/or receive a reasonable accommodation or other appropriate modification from the NCUA, directly or indirectly from an individual’s medical provider or another medical professional who evaluates the request, directly or indirectly from an individual’s religious or spiritual advisors or institutions, and from management officials.  Whenever practicable, the NCUA collects information about an individual directly from that individual.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p>  In addition to those disclosures generally permitted under 5 U.S.C. § 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside the NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:</p>
                <p>1. To a Federal agency or entity authorized to procure assistive technologies and services in response to a request for reasonable accommodation.</p>
                <p>2. To first aid and safety personnel if the individual’s medical condition requires emergency treatment.</p>
                <p>3. To another Federal agency or oversight body charged with evaluating NCUA’s compliance with the laws, regulations, and policies governing reasonable accommodation requests.</p>
                <p>4. To another Federal agency pursuant to a written agreement with NCUA to provide services (such as medical evaluations), when necessary, in support of reasonable accommodation decisions.</p>
                <p>5. If a record in a system of records indicates a violation or potential violation of civil or criminal law or a regulation, and whether arising by general statute or particular program statute, or by regulation, rule, or order, the relevant records in the system or records may be disclosed as a routine use to the appropriate agency, whether federal, state, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto.</p>
                <p>6. A record from a system of records may be disclosed as a routine use to an authorized appeal grievance examiner, formal complaints examiner, equal employment opportunity investigator, arbitrator or other duly authorized official engaged in investigation or settlement of a grievance, complaint, or appeal filed by an employee.  Further, a record from any system of records may be disclosed as a routine use to the Office of Personnel Management in accordance with the agency's responsibility for evaluation and oversight of federal personnel management.</p>
                <p>7. A record from a system of records may be disclosed as a routine use to a member of Congress or to a congressional staff member in response to an inquiry from the congressional office made at the request of the individual about whom the record is maintained.</p>
                <p>8. Records in a system of records may be disclosed as a routine use to the Department of Justice, when: (a) NCUA, or any of its components or employees acting in their official capacities, is a party to litigation; or (b) Any employee of NCUA in his or her individual capacity is a party to litigation and where the Department of Justice has agreed to represent the employee; or (c) The United States is a party in litigation, where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation.</p>
                <p>9. Records in a system of records may be disclosed as a routine use in a proceeding before a court or adjudicative body before which NCUA is authorized to appear (a) when NCUA or any of its components or employees are acting in their official capacities; (b) where NCUA or any employee of NCUA in his or her individual capacity has agreed to represent the employee; or (c) where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation.</p>
                <p>10. A record from a system of records may be disclosed to contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for NCUA when necessary to accomplish an agency function or administer an employee benefit program.</p>
                <p>11. To appropriate agencies, entities, and persons when (1) the NCUA suspects or has confirmed that there has been a breach of the system of records;·(2) the NCUA has determined that as a result of the suspected or confirmed breach there is a risk of harm to individuals, the NCUA (including its information systems, programs, and operations), the Federal Government, or national security; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with the NCUA’s efforts to respond to the suspected or confirmed breach or to prevent, minimize, or remedy such harm.</p>
                <p>12. To another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in (1) responding to a suspected or confirmed breach or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>  Electronic records and backups are stored on secure servers, approved by NCUA’s Office of the Chief Information Officer (OCIO), within a FedRAMP-authorized commercial Cloud Service Provider’s (CSP) Software-as-a-Service solution hosting environment and accessed only by authorized personnel.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p> Records may be retrieved by any of the following: name, case number, or e-mail address.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p> Records are maintained in accordance with GRS 2.3 and are destroyed three years after separation from the agency or all appeals are concluded, whichever is later, but longer retention is authorized if requested for business use.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p> NCUA and the Cloud Service Provider have implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub.L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable federal laws and regulations, including OMB Circular A-130 and NIST Special Publications 800-37.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p> Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>  Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. A statement specifying the changes to be made in the records and the justification therefore.</p>
                <p>4. The address to which the response should be sent.</p>
                <p>5. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>  Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p> None.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p> This is a new system.</p>
            </xhtmlContent>
        </subsection>
    </section>
    <section id="ncua26" toc="yes">
        <systemNumber>-26</systemNumber>
        <subsection type="systemName">
            <p> NCUA-26, Prospective Official Application Records .</p>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>Unclassified.</p>
            </xhtmlContent>
        </subsection> 
       <subsection type="systemLocation">
            <xhtmlContent>
                <p>National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Director, Office of Credit Union Resources and Expansion, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>12 U.S.C. 1754 and 12 CFR Part 701.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>The NCUA uses information maintained in this system to carry out its statutory and other regulatory responsibilities, including evaluating the general character and fitness of prospective officials and employees of proposed federal credit unions and proposed federally insured state-chartered credit unions, and evaluating that applicants have requisite skills and commitment to dedicate time and effort to operate a successful credit union.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>Records in the system include name, contact information, date of birth, and Social Security numbers of individuals proposed as either officials or management employees of proposed federal credit unions or proposed federally insured state-chartered credit unions. Records may also include interagency or intra-agency correspondence or memoranda; suspicious activity reports; federal, state, or local criminal law enforcement agency investigatory reports, indictments and/or arrest and conviction information; reporting agency credit reports; adverse credit records (e.g., bankruptcies, liens, judgments); administrative enforcement orders or agreements. Records also include actions taken by the NCUA in connection with these proposals.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>The information in the system is obtained from individuals named in notices filed pursuant to 12 CFR 701 Appendix B, federal or state financial regulatory agencies, criminal law enforcement authorities, credit bureaus, and NCUA personnel.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                1.	<p>A record from a system of records may be disclosed as a routine use to third parties to the extent necessary to obtain information that is relevant to an investigation of an individual’s general character and fitness;</p>
                2.	<p>If a record in a system of records indicates a violation or potential violation of civil or criminal law or a regulation, and whether arising by general statute or particular program statute, or by regulation, rule, or order, the relevant records in the system or records may be disclosed as a routine use to the appropriate agency, whether federal, state, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto;</p>
                3.	<p>A record from a system of records may be disclosed as a routine use to a member of Congress or to a congressional staff member in response to an inquiry from the congressional office made at the request of the individual about whom the record is maintained;</p>
                4.	<p>Records in a system of records may be disclosed as a routine use to the Department of Justice, when: (a) NCUA, or any of its components or employees acting in their official capacities, is a party to litigation; or (b) Any employee of NCUA in his or her individual capacity is a party to litigation and where the Department of Justice has agreed to represent the employee; or (c) The United States is a party in litigation, where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation;</p>
                5.	<p>Records in a system of records may be disclosed as a routine use in a proceeding before a court or adjudicative body before which NCUA is authorized to appear (a) when NCUA or any of its components or employees are acting in their official capacities; (b) where NCUA or any employee of NCUA in his or her individual capacity has agreed to represent the employee; or (c) where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation;</p>
                6.	<p>A record from a system of records may be disclosed as a routine use to contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for NCUA when necessary to accomplish an agency function or administer an employee benefit program. Individuals provided information under this routine use are subject to the same Privacy Act requirements and limitations on disclosure as are applicable to NCUA employees;</p>
                7.	<p>A record from a system of records may be disclosed to appropriate agencies, entities, and persons when (1) NCUA suspects or has confirmed that the security or confidentiality of information in the system of records has been compromised; (2) NCUA has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by NCUA or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with NCUA’s efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm; and</p>
                8.	<p>To another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in (1) responding to a suspected or confirmed breach or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Electronic records and backups are stored on secure servers, approved by NCUA’s Office of the Chief Information Officer (OCIO), within a FedRAMP-authorized commercial Cloud Service Provider’s (CSP) Software-as-a-Service solution hosting environment and accessed only by authorized personnel.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p>Records may be retrieved by the name of an individual covered by the system.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>Records are maintained and disposed in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or an NCUA records disposition schedule approved by NARA.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>
                    NCUA has implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub. L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable federal laws and regulations, including OMB Circular A-130 and NIST Special Publication 800-37.
                </p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p>Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>A statement specifying the changes to be made in the records and the justification therefore.</p>
                4.	<p>The address to which the response should be sent.</p>
                5.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>Federal criminal law enforcement investigatory reports maintained as part of this system may be subject of exemptions imposed by the originating agency pursuant to 5 U.S.C. 552a(j)(2).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>This is a new system.</p>
            </xhtmlContent>
        </subsection>
    </section>
    <section id="ncua27" toc="yes">
        <systemNumber>-27</systemNumber>
        <subsection type="systemName">
            <p> NCUA-27, NCUA General Support System Records.</p>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>Unclassified.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p> National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p> Chief Information Officer, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>12 U.S.C. 1751 et seq. and 40 U.S.C. 11331.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p> The information in the system is being collected to enable the NCUA to provide authorized individuals access to NCUA information technology resources. The system enables the NCUA to maintain account information required for approved access to information technology, lists of individuals seeking or receiving access to NCUA information technology or equipment, and lists of individuals who are appropriate organizational points of contact. The information will also be used for administrative purposes to ensure quality control, performance, and improving management processes.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p> Categories of individuals covered by this system include all persons who are authorized to access NCUA information technology resources, including: (1) Employees, contractors, and any lawfully designated representatives of federal, state, territorial, tribal, or local government agencies or entities, in furtherance of the NCUA’s mission; (2) individuals who have business with the NCUA and who have provided personal information in order to facilitate access to NCUA information technology resources; and (3) individuals who are points of contact provided for government business, operations, or programs.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p> Records in this system may contain data relating to individuals, including but not limited to: name; telephone numbers, including business, cellular, and home numbers; level of access; home or other provided address for the receipt of issued IT equipment or resources; email addresses of senders and recipients; records of access to NCUA computers and networks including equipment issued, user ID and passwords, date(s) and time(s) of access, IP address of access, logs of internet activity and records on the authentication of the access request; records of identity management related to individual user’s request including universal resource locator of individual’s chosen identity assurance certificate provider and response from certificate provider of positive or negative authentication; and positions or titles of contacts, their business or organizational affiliations, and other contact information provided to the NCUA that is derived from other sources to facilitate authorized access to NCUA Information Technology resources. The information in this system includes information relating to system access and does not include the data held within the systems or information technology resources to which access or interaction is sought.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>:  Information in this system is obtained from individuals and entities associated with or granted access to NCUA information technology resources.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                1.	<p>If a record in a system of records indicates a violation or potential violation of civil or criminal law or a regulation, and whether arising by general statute or particular program statute, or by regulation, rule, or order, the relevant records in the system or records may be disclosed as a routine use to the appropriate agency, whether federal, state, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto.</p>
                2.	<p>A record from a system of records may be disclosed as a routine use to a member of Congress or to a congressional staff member in response to an inquiry from the congressional office made at the request of the individual about whom the record is maintained;</p>
                3.	<p>Records in a system of records may be disclosed as a routine use to the Department of Justice, when: (a) NCUA, or any of its components or employees acting in their official capacities, is a party to litigation; or (b) Any employee of NCUA in his or her individual capacity is a party to litigation and where the Department of Justice has agreed to represent the employee; or (c) The United States is a party in litigation, where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation, provided, however, that in each case, NCUA determines that disclosure of the records to the Department of Justice is a use of the information contained in the records that is compatible with the purpose for which the records were collected.</p>
                4.	<p>Records in a system of records may be disclosed as a routine use in a proceeding before a court or adjudicative body before which NCUA is authorized to appear (a) when NCUA or any of its components or employees are acting in their official capacities; (b) where NCUA or any employee of NCUA in his or her individual capacity has agreed to represent the employee; or (c) where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation, provided, however, NCUA determines that disclosure of the records is compatible with the purpose for which the records were collected.</p>
                5.	<p>A record from a system of records may be disclosed to contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for NCUA when necessary to accomplish an agency function. Individuals provided information under this routine use are subject to the same Privacy Act requirements and limitations on disclosure as are applicable to NCUA employees.</p>
                6.	<p>Records may be disclosed to the Department of Homeland Security (DHS) if captured in an intrusion detection system used by NCUA and DHS pursuant to a DHS cybersecurity program that monitors internet traffic to and from federal government computer networks to prevent cybersecurity incidents;</p>
                7.	<p>A record from a system of records may be disclosed to appropriate agencies, entities, and persons when (1) NCUA suspects or has confirmed that the security or confidentiality of information in the system of records has been compromised; (2) NCUA has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by NCUA or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with NCUA’s efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm.</p>
                8.	<p>To another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in (1) responding to a suspected or confirmed breach or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p> Electronic records and backups are stored on secure servers, approved by NCUA’s Office of the Chief Information Officer (OCIO), and accessed only by authorized personnel.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p>
                    Records are retrievable by a variety of fields including the individual's name or username.</p>
                    </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>
                    Records are maintained and disposed in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA).
                </p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>
                    NCUA has implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub. L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable federal laws and regulations, including Office of Management and Budget Circular A-130 and NIST Special Publication 800-37.
                </p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>A statement specifying the changes to be made in the records and the justification therefore.</p>
                4.	<p>The address to which the response should be sent.</p>
                5.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>
                    None.
                </p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>
                    This is a new system.
                </p>
            </xhtmlContent>
        </subsection>
    </section>
    <section id="ncua28" toc="yes">
        <systemNumber>-28</systemNumber>
        <subsection type="systemName">
            <p>Anti-Harassment Case Tracking and Records.</p>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>Unclassified.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>  National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia   22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p> Anti-Harassment Coordinator, Office of Ethics Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, VA  22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>  12 U.S.C. 1751, et seq.; Title VII of the Civil Rights Act of 1964, 42 U.S.C. 2000e, et seq.; Age Discrimination in Employment Act of 1967, 29 U.S.C. 621, et seq.; Americans with Disabilities Act, 42 U.S.C. 12101, et seq., including ADA Amendments Act of 2008; Rehabilitation Act of 1973 (Section 501), 29 U.S.C. 791; Notification and Federal Employee Antidiscrimination and Retaliation Act of 2002 (No FEAR Act), Public Law 107-174; Genetic Information Nondiscrimination Act of 2008 (GINA), Public Law 110-233; Executive Order 13087; Executive Order 13152; and further amendments to Executive Order 11478, Executive Order 11246, and EEOC Enforcement Guidance: Vicarious Employer Liability for Unlawful Harassment by Supervisors, Notice 915.002, V.C.1 (June 18, 1999).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>  The information in the system is collected to assist the NCUA with conducting internal investigations into allegations of harassment brought by NCUA employees and NCUA contractors and taking appropriate action(s) to address such allegations.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p>  NCUA employees and NCUA contractors who have submitted complaints or reports of harassment or who have provided information related to an investigation of workplace harassment and NCUA employees and contractors who have been accused of harassment.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>  Records in the system include complaints of harassment, statements of witnesses, reports of investigation, investigator's and Chief Ethics Officer’s findings and recommendations, final decisions and corrective action taken, and related correspondence and exhibits. These records include names of the alleged victim, harasser and witnesses, their contact information, and the specific circumstances relevant to the harassment.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>  The information in this system is collected directly from individuals</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>  In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, all or a portion of the records or information contained in this system may be disclosed outside the NCUA as a routine use as follows:</p>
                1.	<p>To disclose information as necessary to any source from which additional information is requested in the course of processing a complaint or report of harassment.</p>
                2.	<p>To provide to the alleged harasser information in the event of a disciplinary hearing.</p>
                3.	<p>A record from a system of records may be disclosed as a routine use to an authorized appeal grievance examiner, formal complaints examiner, equal employment opportunity investigator, arbitrator, or other duly authorized official engaged in investigation or settlement of a grievance, complaint, or appeal filed by an employee. Further, a record from any system of records may be disclosed as a routine use to the Office of Personnel Management in accordance with the agency's responsibility for evaluation and oversight of federal personnel management.</p>
                4.	<p>If a record in a system of records indicates a violation or potential violation of civil or criminal law or a regulation, and whether arising by general statute or particular program statute, or by regulation, rule, or order, the relevant records in the system or records may be disclosed as a routine use to the appropriate agency, whether federal, state, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto.</p>
                5.	<p>A record from a system of records may be disclosed as a routine use to a member of Congress or to a congressional staff member in response to an inquiry from the congressional office made at the request of the individual about whom the record is maintained;</p>
                6.	<p>Records in a system of records may be disclosed as a routine use to the Department of Justice, when: (a) NCUA, or any of its components or employees acting in their official capacities, is a party to litigation; or (b) Any employee of NCUA in his or her individual capacity is a party to litigation and where the Department of Justice has agreed to represent the employee; or (c) The United States is a party in litigation, where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation, provided, however, that in each case, NCUA determines that disclosure of the records to the Department of Justice is a use of the information contained in the records that is compatible with the purpose for which the records were collected.</p>
                7.	<p>Records in a system of records may be disclosed as a routine use in a proceeding before a court or adjudicative body before which NCUA is authorized to appear: (a) when NCUA or any of its components or employees are acting in their official capacities; (b) where NCUA or any employee of NCUA in his or her individual capacity has agreed to represent the employee; or (c) where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation;</p>
                8.	<p>A record from a system of records may be disclosed as a routine use to contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for NCUA when necessary to accomplish an agency function or administer an employee benefit program. Individuals provided information under this routine use are subject to the same Privacy Act requirements and limitations on disclosure as are applicable to NCUA employees;</p>
                9.	<p>A record from a system of records may be disclosed to appropriate agencies, entities, and persons when: (1) NCUA suspects or has confirmed that the security or confidentiality of information in the system of records has been compromised; (2) NCUA has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by NCUA or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with NCUA’s efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm; and</p>
                10.	<p>To another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in: (1) responding to a suspected or confirmed breach; or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>  Electronic records and backups are stored on secure servers, approved by the NCUA’s Office of the Chief Information Officer (OCIO), and accessed only by authorized personnel.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p>Records may be retrieved by any of the following: name of the individual who files a complaint or report of harassment, name of the alleged victim of harassment, if any, and name of the alleged harasser.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>Records are maintained and disposed of in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or an NCUA records disposition schedule approved by NARA.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>  NCUA has implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub. L. 113-283, S. 2521, and the NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable Federal laws and regulations, including Office of Management and Budget (OMB) Circular A-130 and NIST Special Publication 800-37.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p> After an individual receives verification that they have a record in the system, per the notification procedure above, if they wish to access to their records, they should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with the NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p>  Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>A statement specifying the changes to be made in the records and the justification therefore.</p>
                4.	<p>The address to which the response should be sent.</p>
                5.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                1.	<p>Full name.</p>
                2.	<p>Any available information regarding the type of record involved.</p>
                3.	<p>The address to which the record information should be sent.</p>
                4.	<p>You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with the NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>This system is exempt under 5 U.S.C. 552a(k)(2) from subsections (c)(3), (d), (e)(1), (e)(4)(G), (e)(4)(H), (e)(4)(I) and (f) of the Act.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>This is a new system.</p>
            </xhtmlContent>
        </subsection>
    </section>
    <section id="ncua29" toc="yes">
        <systemNumber>-29</systemNumber>
        <subsection type="systemName">
            <p> Non-Payroll Employee Administrative Records, NCUA-29.</p>
        </subsection>
        <subsection type="securityClassification">
            <xhtmlContent>
                <p>Unclassified.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemLocation">
            <xhtmlContent>
                <p>National Credit Union Administration,</p>
                <p>1775 Duke Street, Alexandria, VA 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="systemManager">
            <xhtmlContent>
                <p>Director, Office of Human Resources, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="authorityForMaintenance">
            <xhtmlContent>
                <p>12 U.S.C. 1766.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="purpose">
            <xhtmlContent>
                <p>The purpose of this system is to collect and maintain information used for non-payroll personnel actions and for human resources administrative purposes, including administering supplemental benefits, employee assistance programs, and work-life programs.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfIndividuals">
            <xhtmlContent>
                <p>To the extent not covered by any other system, this system covers current and former NCUA employees, dependents, and beneficiaries who are enrolled in, apply for, or participate in one or more of NCUA employee benefit programs.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="categoriesOfRecords">
            <xhtmlContent>
                <p>Records in the system include Individual name, Social Security number (SSN), employee ID number, Taxpayer Identification Number (TIN), or similar. Records may also include home and work contact information, including address, telephone number, and email address; information related to an employee’s participation in supplemental retirement, health, and benefit programs, including salary information, contribution amount(s), dependents and beneficiary names, addresses, relationship, and Social Security number(s); information about student loans related to the student loan repayment benefit, including type of loan, loan account number, loan holder name and address, total loan amount and amount outstanding; and service agreement information; and receipts and similar documentation provided as evidence of expenditures for reimbursement through supplemental benefits, employee assistance and work-life programs.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordSourceCategories">
            <xhtmlContent>
                <p>The information in this system is obtained from current and former NCUA employees and from entities associated with benefits and work-life programs including retirement, human resources functions, accounting, and payroll systems administration.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="routineUsesOfRecords">
            <xhtmlContent>
                <p>  In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act, these records or information contained therein may specifically be disclosed outside the NCUA as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:</p>
                <p>1. A record from a system of records may be disclosed as a routine use to carriers, providers, and other Federal agencies involved in the administration of employee benefit programs and such agencies’ contractors or plan administrators, when necessary to determine employee eligibility to participate in such programs, process employee participation in such programs, audit benefits paid under such programs, or perform any administrative function in connection with those programs;</p>
                <p>2. A record from a system of records may be disclosed as a routine use to Federal, state, and local taxation authorities concerning compensation to employees or to contractors; to the Office of Personnel Management, Department of the Treasury, Department of Labor, and other Federal agencies concerning pay, benefits, and retirement of employees; to financial organizations concerning employee allotments to accounts; and to heirs, executors, and legal representatives of beneficiaries;</p>
                <p>3. If a record in a system of records indicates a violation or potential violation of civil or criminal law or a regulation, and whether arising by general statute or particular program statute, or by regulation, rule, or order, the relevant records in the system or records may be disclosed as a routine use to the appropriate agency, whether Federal, State, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto;</p>
                <p>4. A record from a system of records may be disclosed as a routine use to a member of Congress or to a congressional staff member in response to an inquiry from the congressional office made at the request of the individual about whom the record is maintained;</p>
                <p>5. Records in a system of records may be disclosed as a routine use to the Department of Justice, when: (a) NCUA, or any of its components or employees acting in their official capacities, is a party to litigation; or (b) Any employee of NCUA in his or her individual capacity is a party to litigation and where the Department of Justice has agreed to represent the employee; or (c) The United States is a party in litigation, where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation;</p>
                <p>6. Records in a system of records may be disclosed as a routine use in a proceeding before a court or adjudicative body before which NCUA is authorized to appear (a) when NCUA or any of its components or employees are acting in their official capacities; (b) where NCUA or any employee of NCUA in his or her individual capacity has agreed to represent the employee; or (c) where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation;</p>
                <p>7. A record from a system of records may be disclosed as a routine use to contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for NCUA when necessary to accomplish an agency function or administer an employee benefit program. Individuals provided information under this routine use are subject to the same Privacy Act requirements and limitations on disclosure as are applicable to NCUA employees;</p>
                <p>8. A record from a system of records may be disclosed to appropriate agencies, entities, and persons when (1) NCUA suspects or has confirmed that the security or confidentiality of information in the system of records has been compromised; (2) NCUA has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by NCUA or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with NCUA’s efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm; and</p>
                <p>9. To another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in (1) responding to a suspected or confirmed breach or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="policiesAndPractices">
            <xhtmlContent>
                <p>Electronic records and backups are stored on secure servers, approved by NCUA’s Office of the Chief Information Officer (OCIO), within a FedRAMP-authorized commercial Cloud Service Provider’s (CSP) Software-as-a-Service solution hosting environment and accessed only by authorized personnel.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retrievability">
            <xhtmlContent>
                <p>Records are retrievable by a variety of fields including, but not limited to, individual name, SSN, employee ID, or some combination thereof.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="retentionAndDisposal">
            <xhtmlContent>
                <p>Records are maintained and disposed in accordance with the General Records Retention Schedules issued by the National Archives and Records Administration (NARA) or an NCUA records disposition schedule approved by NARA.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="safeguards">
            <xhtmlContent>
                <p>NCUA has implemented the appropriate administrative, technical, and physical controls in accordance with the Federal Information Security Modernization Act of 2014, Pub. L. 113-283, S. 2521, and NCUA’s information security policies to protect the confidentiality, integrity, and availability of the information system and the information contained therein.  Access is limited only to individuals authorized through NIST-compliant Identity, Credential, and Access Management policies and procedures.  The records are maintained behind a layered defensive posture consistent with all applicable Federal laws and regulations, including Office of Management and Budget Circular A-130 and NIST Special Publication 800-37.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="recordAccessProcedures">
            <xhtmlContent>
                <p>Individuals wishing access to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="contestingRecordProcedures">
            <xhtmlContent>
                <p> Individuals wishing to request an amendment to their records should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1. Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. A statement specifying the changes to be made in the records and the justification therefore.</p>
                <p>4. The address to which the response should be sent.</p>
                <p>5. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="notificationProcedure">
            <xhtmlContent>
                <p>Individuals wishing to learn whether this system of records contains information about them should submit a written request to the Senior Agency Official for Privacy, NCUA, 1775 Duke Street, Alexandria, VA 22314, and provide the following information:</p>
                <p>1.Full name.</p>
                <p>2. Any available information regarding the type of record involved.</p>
                <p>3. The address to which the record information should be sent.</p>
                <p>4. You must sign your request.</p>
                <p>Attorneys or other persons acting on behalf of an individual must provide written authorization from that individual for the representative to act on their behalf.  Individuals requesting access must also comply with NCUA’s Privacy Act regulations regarding verification of identity and access to records (12 CFR 792.55).</p>
            </xhtmlContent>
        </subsection>
        <subsection type="exemptionsClaimed">
            <xhtmlContent>
                <p>None.</p>
            </xhtmlContent>
        </subsection>
        <subsection type="history">
            <xhtmlContent>
                <p>This is a new system.</p>
            </xhtmlContent>
        </subsection>
    </section>


    <appendix id="app" toc="yes" letter="A">
<title> Standard Routine Uses Applicable to NCUA Systems of Records </title>
<xhtmlContent>
    <p>1. If a record in a system of records indicates a violation or potential violation of civil or criminal law or a regulation, and whether arising by general statute or particular program statute, or by regulation, rule, or order, the relevant records in the system or records may be disclosed as a routine use to the appropriate agency, whether federal, state, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto.</p>
    <p>2. A record from a system of records may be disclosed as a routine use to a federal, state, or local agency which maintains civil, criminal, or other relevant enforcement information or other pertinent information, such as current licenses, if necessary, to obtain information relevant to an agency decision concerning the hiring or retention of an employee, the issuance of a security clearance, the letting of a contract, or the issuance of a license, grant, or other benefit.</p>
    <p>3. A record from a system of records may be disclosed as a routine use to a federal agency, in response to its request, for a matter concerning the hiring or retention of an employee, the issuance of a security clearance, the reporting of an investigation of an employee, the letting of a contract, or the issuance of a license, grant, or other benefit by the requesting agency, to the extent that the information is relevant and necessary to the requesting agency's decision in the matter.</p>
    <p>4. A record from a system of records may be disclosed as a routine use to an authorized appeal grievance examiner, formal complaints examiner, equal employment opportunity investigator, arbitrator or other duly authorized official engaged in investigation or settlement of a grievance, complaint, or appeal filed by an employee. Further, a record from any system of records may be disclosed as a routine use to the Office of Personnel Management in accordance with the agency's responsibility for evaluation and oversight of federal personnel management.</p>
    <p>5. A record from a system of records may be disclosed as a routine use to officers and employees of a federal agency for purposes of audit.</p>
    <p>6. A record from a system of records may be disclosed as a routine use to a member of Congress or to a congressional staff member in response to an inquiry from the congressional office made at the request of the individual about whom the record is maintained.</p>
    <p>7. A record from a system of records may be disclosed as a routine use to the officers and employees of the General Services Administration (GSA) in connection with administrative services provided to this Agency under agreement with GSA.</p>
    <p>8. Records in a system of records may be disclosed as a routine use to the Department of Justice, when:  (a) NCUA, or any of its components or employees acting in their official capacities, is a party to litigation; or (b) Any employee of NCUA in his or her individual capacity is a party to litigation and where the Department of Justice has agreed to represent the employee; or (c) The United States is a party in litigation, where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation, provided, however, that in each case, NCUA determines that disclosure of the records to the Department of Justice is a use of the information contained in the records that is compatible with the purpose for which the records were collected.</p>
    <p>9. Records in a system of records may be disclosed as a routine use in a proceeding before a court or adjudicative body before which NCUA is authorized to appear  (a) when NCUA or any of its components or employees are acting in their official capacities; (b) where NCUA or any employee of NCUA in his or her individual capacity has agreed to represent the employee; or (c) where NCUA determines that litigation is likely to affect the agency or any of its components, is a party to litigation or has an interest in such litigation, and NCUA determines that use of such records is relevant and necessary to the litigation, provided, however, NCUA determines that disclosure of the records to the Department of Justice is a use of the information contained in the records that is compatible with the purpose for which the records were collected.</p>
    <p>10. A record from a system of records may be disclosed to contractors, experts, consultants, and the agents thereof, and others performing or working on a contract, service, cooperative agreement, or other assignment for NCUA when necessary to accomplish an agency function or administer an employee benefit program. Individuals provided information under this routine use are subject to the same Privacy Act requirements and limitations on disclosure as are applicable to NCUA employees.</p>
    <p>11. A record from a system of records may be disclosed to appropriate agencies, entities, and persons when (1) NCUA suspects or has confirmed that the security or confidentiality of information in the system of records has been compromised; (2) NCUA has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by NCUA or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with NCUA’s efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm.</p>
    <p>12. A record from a system of records may be shared with the Office of Management and Budget (OMB) in connection with the review of private relief legislation as set forth in OMB Circular A-19 at any stage of the legislative coordination and clearance process as set forth in that circular.</p>
    <p>13. To another Federal agency or Federal entity, when the NCUA determines that information from this system of records is reasonably necessary to assist the recipient agency or entity in (1) responding to a suspected or confirmed breach or (2) preventing, minimizing, or remedying the risk of harm to individuals, the recipient agency or entity (including its information systems, programs, and operations), the Federal Government, or national security, resulting from a suspected or confirmed breach.</p>

</xhtmlContent></appendix>

<appendix id="app" toc="yes" letter="B">
<title> List of Regional Offices With Addresses and States Covered by Each Region </title>
<xhtmlContent><p><i>NCUA Region I Regional Office:</i> 9 Washington Square, Washington Avenue Extension, Albany, NY 12205, Phone (518) 862-7400. States covered: Connecticut, Maine, Massachusetts, Michigan, New Hampshire, New York, Rhode Island, and Vermont.
</p><p><i>NCUA Region II Regional Office:</i> 1775 Duke Street, Suite 4206, Alexandria, VA 22314, Phone: (703) 519-4600. States covered: Delaware, District of Columbia, Maryland, New Jersey, Pennsylvania, Virginia, and West Virginia.
</p><p><i>NCUA Region III Regional Office:</i> 7000 Central Parkway, Suite 1600, Atlanta, GA 30328, Phone: (678) 443-3000. States covered: Alabama, Florida, Georgia, Indiana, Kentucky, Mississippi, North Carolina, Puerto Rico, Ohio, South Carolina, Tennessee, and Virgin Islands.
</p><p><i>NCUA Region IV Regional Office:</i> 4807 Spicewood Springs Road, Suite 5200, Austin, TX 78759, Phone: (512) 342-5600. States covered: Arkansas, Illinois Iowa, Kansas, Louisiana, Minnesota, Missouri, Nebraska, North Dakota, Oklahoma, South Dakota, Texas, and Wisconsin.
</p><p><i>NCUA Region V Regional Office:</i> 1230 West Washington Street, Suite 301, Tempe, AZ 85281, Phone: (602) 302-6000. States covered: Alaska, Arizona, California, Colorado, Guam, Hawaii, Idaho, Montana, Nevada, New Mexico, Oregon, Utah, Washington, and Wyoming.
</p></xhtmlContent></appendix>

    
    
<regulations id="reg" toc="yes">
<regulationsTitle number="12">
<heading> Banks and Banking </heading>
<regulationsChapter number="VII">
<heading>National Credit Union Administration </heading>
<regulationsPart number="792">
<heading> REQUESTS FOR INFORMATION UNDER THE FREEDOM OF INFORMATION ACT AND PRIVACY ACT, AND BY SUBPOENA; SECURITY PROCEDURES FOR CLASSIFIED INFORMATION </heading>
<xhtmlContent>
<p><b>Subpart E--The Privacy Act
</b>
</p>
<p>Sec.
</p>
<p>792.52 Scope.
</p>
<p>792.53 Definitions.
</p>
<p>792.54 Procedures for requests pertaining to individual records in a system of records.
</p>
<p>792.55 Times, places, and requirements for identification of individuals making requests and identification of records requested.
</p>
<p>792.56 Notice of existence of records, access decisions and disclosure of requested information; time limits.
</p>
<p>792.57 Special procedures: Information furnished by other agencies; medical records.
</p>
<p>792.58 Requests for correction or amendment to a record; administrative review of requests.
</p>
<p>792.59 Appeal of initial determination.
</p>
<p>792.60 Disclosure of record to person other than the individual to whom it pertains.
</p>
<p>792.61 Accounting for disclosures.
</p>
<p>792.62 Requests for accounting for disclosures.
</p>
<p>792.63 Collection of information from individuals; information forms.
</p>
<p>792.64 Contracting for the operation of a system of records.
</p>
<p>792.65 Fees.
</p>
<p>792.66 Exemptions.
</p>
<p>792.67 Security of systems of records.
</p>
<p>792.68 Use and collection of Social Security numbers.
</p>
<p>792.69 Training and employee standards of conduct with regard to privacy.
</p>
<p><b>Authority:</b> 5 U.S.C. 301, 552, 552a, 552b; 12 U.S.C. 1752a(d), 1766, 1789, 1795f; E.O. 12600, 52 FR 23781, 3 CFR, 1987 Comp., p. 235; E.O. 12958, 60 FR 19825, 3 CFR, 1995 Comp., p.333.
</p>
<p><b>Source:</b> 54 FR 18476, May 1, 1989, unless otherwise noted.
</p>
<p><b>Subpart E--The Privacy Act
</b></p>
<p><b>Source:</b> 54 FR 18476, May 1, 1989, unless otherwise noted. Redesignated at 63 FR 14338, Mar. 25, 1998. Nomenclature change at 73 FR 56938, Oct. 1, 2008.

</p>
<p><b>&#167; 792.52
 Scope.
</b></p>
<p>This subpart governs requests made of NCUA under the Privacy Act (5 U.S.C. 552a). The regulation applies to all records maintained by NCUA which contain personal information about an individual and some means of identifying the individual, and which are contained in a system of records from which information may be retrieved by use of an identifying particular; sets forth procedures whereby individuals may seek and gain access to records concerning themselves and request amendments of those records; and sets forth requirements applicable to NCUA employees' maintaining, collecting, using, or disseminating such records.

</p>
<p><b>&#167; 792.53
 Definitions.
</b></p>
<p>For purposes of this subpart:
</p>
<p>(a) <i>Individual</i> means a citizen of the United States or an alien lawfully admitted for permanent residence.
</p>
<p>(b) <i>Maintain</i> includes maintain, collect, use, or disseminate.
</p>
<p>(c) <i>Record</i> means any item, collection, or grouping of information about an individual that is maintained by NCUA, and that contains the name, or an identifying number, symbol, or other identifying particular assigned to the individual.
</p>
<p>(d) <i>System of records</i> means a group of any records under NCUA's control from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
</p>
<p>(e) <i>Routine use</i> means, with respect to the disclosure of a record, the use of such record for a purpose which is compatible with the purpose for which it was collected.
</p>
<p>(f) <i>Statistical record</i> means a record in a system of records maintained for statistical research or reporting purposes only and not used in whole or in part in making any determination about an identifiable individual, except as provided by section 8 of title 13 of the United States Code.
</p>
<p>(g) <i>Notice of Systems of Records</i> means the annual notice published by NCUA in the <i>Federal Register</i> informing the public of the existence and character of the systems of records it maintains. The Notice of Systems of Records also is available on NCUA's Web site at <i>http://www.ncua.gov</i>.
</p>
<p>(h) <i>System manager</i> means the NCUA official responsible for the maintenance, collection, use or distribution of information contained in a system of records. The system manager for each system of records is provided in the <i>Federal Register</i> publication of NCUA's annual systems of records notice.
</p>
<p>(i) <i>Working day</i> means Monday through Friday excluding legal public holidays.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 73 FR 56938, Oct. 1, 2008]

</p>
<p><b>&#167; 792.54
 Procedures for requests pertaining to individual records in a system of records.
</b></p>
<p>(a) Individuals desiring to know if a system of records contains records pertaining to them, and individuals requesting access to records in a system of records pertaining to them should submit a written request to the appropriate system manager as identified in the Notice of Systems of Records. An individual who does not have access to the <i>Federal Register</i> and who is unable to determine the appropriate system manager to whom to submit a request may submit a request to the Privacy Officer, Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428, in which case the request will be referred to the appropriate system manager.
</p>
<p>(b) Individuals requesting notification of, or access to, records should include the words "PRIVACY ACT REQUEST" on both the letter and, as appropriate, the envelope, cover document or subject line; describe the record sought; the approximate dates covered by the record; and, the systems of record in which records are thought to be included. Individuals must also meet the identification requirements in &#167; 792.55.
</p>
<p>[73 FR 56938, Oct. 1, 2008]

</p>
<p><b>&#167; 792.55
 Times, places, and requirements for identification of individuals making requests and identification of records requested.
</b></p>
<p>(a) The following standards are applicable to an individual submitting requests either in person or by mail under &#167; 792.54:
</p>
<p>(1) Individuals appearing in person, if not personally known to the system manager responding to the request, must present a single document bearing a photograph (such as a passport or identification badge) or two items of identification which do not bear a photograph but do bear both a name and address (such as a driver's license or voter registration card);
</p>
<p>(2) Individuals submitting requests by mail or written electronic form, such as facsimile or e-mail, may establish identity by a signature, address, date of birth, employee identification number if any, and one other identifier such as a photocopy of driver's license or other document. If inadequate identifying information is provided, the system manager responding to the request may require further identifying information before any notification or responsive disclosure.
</p>
<p>(3) Individuals appearing in person or submitting requests by mail or written electronic form, who cannot provide the required documentation or identification, may provide an unsworn declaration subscribed to as true under penalty of perjury.
</p>
<p>(b) The parent or guardian of a minor or a person judicially determined to be incompetent shall, in addition to establishing identity of the minor or other person as required in paragraph (a) of this section, furnish a copy of a birth certificate showing parentage or a court order establishing guardianship.
</p>
<p>(c) A record may be disclosed to a representative of an individual to whom the record pertains provided the system manager receives written authorization from the individual who is the subject of the record.
</p>
<p>(d) An individual seeking to review records about that individual may be accompanied by another person of their own choosing. In such cases, the individual seeking access shall be required to furnish a written statement authorizing discussion of that individual's records in the accompanying person's presence.
</p>
<p>(e) In addition to the requirements set forth in paragraphs (a), (b) and (c) of this section, the published "Notice of System of Records" for individual systems may include further requirements of identification where necessary to retrieve the individual records from the system.
</p>
<p>[54 FR 18476, May 1, 1989. Redesignated at 63 FR 14338, Mar. 25, 1998, as amended at 64 FR 57365, Oct. 25, 1999; 65 FR 63790, Oct. 25, 2000; 73 FR 56939, Oct. 1, 2008]

</p>
<p><b>&#167; 792.56
 Notice of existence of records, access decisions and disclosure of requested information; time limits.
</b></p>
<p>(a) The system manager identified in the record access procedure section of the "Notice of Systems of Records" and identified in accordance with &#167; 792.54(a), by an individual seeking notification of, or access to, a record, shall be responsible:
</p>
<p>(1) For determining whether access is available under the Privacy Act; (2) for notifying the requesting individual of that determination; and (3) for providing access to information determined to be available. In the case of an individual access request made in person, information determined to be available shall be provided by allowing a personal review of the record or portion of a record containing the information requested and determined to be available, and the individual shall be allowed to have a copy of all or any portion of available information made in a form comprehensible to him. In the case of an individual access request made by mail, information determined to be available shall be provided by mail, unless the individual has requested otherwise.
</p>
<p>(b) The following time limits shall be applicable to the required determinations, notification and provisions of access set forth in paragraph (a) of this section:
</p>
<p>(1) A request concerning a single system of records which does not require consultation with or requisition of records from another agency will be responded to within 20 working days after receipt of the request.
</p>
<p>(2) A request requiring requisition of records from or consultation with another agency will be responded to within 30 working days of receipt of the request.
</p>
<p>(3) If a request under paragraphs (b)(1) or (2) of this section presents unusual difficulties in determining whether the records involved are exempt from disclosure, the Privacy Act Officer, in the Office of General Counsel, may extend the time period established by the regulations by 10 working days.
</p>
<p>(c) Nothing in this section shall be construed to allow an individual access to any information compiled in reasonable anticipation of a civil action or proceeding, or any information exempted from the access provisions of the Privacy Act.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 59 FR 36042, July 15, 1994; 64 FR 57365, Oct. 25, 1999; 65 FR 63790, Oct. 25, 2000]

</p>
<p><b>&#167; 792.57
 Special procedures: Information furnished by other agencies; medical records.
</b></p>
<p>(a) When a request for records or information from NCUA includes information furnished by other Federal agencies, the system manager responsible for action on the request shall consult with the appropriate agency prior to making a decision to disclose or refuse access to the record, but the decision whether to disclose the record shall be made in the first instance by the system manager.
</p>
<p>(b) Medical records may be disclosed on request to the individuals to whom they pertain unless disclosing the medical information directly to the requesting individual could have an adverse effect on the individual. Where medical information is potentially adverse to the requesting individual, the system manager responsible may advise the requesting individual that the medical records will be transmitted only to a physician designated in writing by the individual.
</p>
<p>[54 FR 18476, May 1, 1989. Redesignated at 63 FR 14338, Mar. 25, 1998, as amended at 65 FR 63790, Oct. 25, 2000; 73 FR 56939, Oct. 1, 2008]

</p>
<p><b>&#167; 792.58
 Requests for correction or amendment to a record; administrative review of requests.
</b></p>
<p>(a) An individual may request amendment of a record concerning that individual by submitting a written request, either in person or by mail, to the system manager identified in the Notice of Systems of Records. The words "PRIVACY ACT--REQUEST TO AMEND RECORD" should be written on the letter and the envelope. The request must describe the system of records containing the record sought to be amended, indicate the particular record involved, the nature of the correction sought, and the justification for the correction or amendment. An individual who does not have access to NCUA's Notice of Systems of Records, and to whom the appropriate address is otherwise unavailable, may submit a request to the Privacy Act Officer, Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, Virginia 22314-3428, in which case the request will then be referred to the appropriate system manager. The date of receipt of the request will be determined as of the date of receipt by the system manager.
</p>
<p>(b) Within 10 working days of receipt of the request, the appropriate system manager shall advise the individual that the request has been received. The appropriate system manager will promptly (under normal circumstances, not later than 30 working days after receipt of the request) advise the individual that the record will be amended or corrected, or inform the individual of rejection of the request to amend the record, the reason for the rejection, and the procedures established by &#167; 792.59 for the individual to request a review of that rejection.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 59 FR 36041, 36042, July 15, 1994; 65 FR 63790, Oct. 25, 2000; 73 FR 56939, Oct. 1, 2008]

</p>
<p><b>&#167; 792.59
 Appeal of initial determination.
</b></p>
<p>(a) A rejection, in whole or in part, of a request to amend or correct a record may be appealed to the General Counsel within 30 working days of receipt of notice of the rejection. Appeals shall be in writing, and shall set forth the specific item of information sought to be corrected and the documentation justifying the correction. Appeals must be addressed to the Office of General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428 with the words "PRIVACY ACT--APPEAL" written on the letter and the envelope. Appeals shall be decided within 30 working days of receipt unless the General Counsel, for good cause, extends such period for an additional 30 working days.
</p>
<p>(b) Within the time limits set forth in paragraph (a) of this section, the General Counsel shall either advise the individual of a decision to amend or correct the record, or advise the individual of a determination that an amendment or correction is not warranted on the facts, in which case the individual shall be advised of the right to provide for the record a "Statement of Disagreement" and of the right to further appeal pursuant to the Privacy Act. For records under the jurisdiction of the Office of Personnel Management, appeals will be made pursuant to that agency's regulations.
</p>
<p>(c) If an appeal under this section is denied in whole or in part, an individual may file a statement of disagreement concisely stating the reason(s) for disagreeing with the denial for amendment or correction, and clearly identifying each part of any record that is disputed. The statement must be sent within 30 working days of the date of receipt of the notice of General Counsel's refusal to authorize amendment or correction, to the General Counsel, National Credit Union Administration, 1775 Duke Street, Alexandria, VA 22314-3428. Upon receipt of a statement of disagreement in accordance with this section, the General Counsel shall take steps to ensure that the statement is included in the system of records containing the disputed item and that the original item is so marked to indicate that there is a statement of dispute and where, within the system of records, that statement may be found.
</p>
<p>(d) When a record has been amended or corrected or a statement of disagreement has been furnished, the system manger for the system of records containing the record shall, within 30 days thereof, advise all prior recipients of information to which the amendment or statement of disagreement relates whose identity can be determined by an accounting made as required by the Privacy Act of 1974 or any other accounting previously made, of the amendment or statement of disagreement. When a statement of disagreement has been furnished, the system manager shall also provide any subsequent recipient of a disclosure containing information to which the statement relates with a copy of the statement and note the disputed portion of the information disclosed. A concise statement of the reasons for not making the requested amendment may also be provided if deemed appropriate.
</p>
<p>(e) If access is denied because of an exemption, the individual will be notified of the right to appeal that determination to the General Counsel within 30 days after receipt. Appeals will be determined within 20 working days.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 59 FR 36041, July 15, 1994; 65 FR 63790, Oct. 25, 2000; 73 FR 56939, Oct. 1, 2008]

</p>
<p><b>&#167; 792.60
 Disclosure of record to person other than the individual to whom it pertains.
</b></p>
<p>No record or item of information concerning an individual which is contained in a system of records maintained by NCUA shall be disclosed by any means of communication to any person, or to another agency, without the prior written consent of the individual to whom the record or item of information pertains, unless the disclosure would be--
</p>
<p>(a) To an employee of the NCUA who has need for the record in the performance of duty;
</p>
<p>(b) Required by the Freedom of Information Act;
</p>
<p>(c) For a routine use as described in the "Notice of Systems of Records," published in the <i>Federal Register,</i> which describes the system of records in which the record or item of information is contained;
</p>
<p>(d) To the Bureau of the Census for purposes of planning or carrying out a census or survey or related activity pursuant to the provisions of title 13 of the United States Code;
</p>
<p>(e) To a recipient who has provided the NCUA with advance adequate written assurance that the record or item will be used soley as a statistical research or reporting record, and the record is to be transferred in a form that is not individually identifiable;
</p>
<p>(f) To the National Archives and Records Administration as a record or item which has sufficient historical or other value to warrant its continued preservation by the United States Government, or for evaluation by the Archivist of the United States or the designee of the Archivist to determine whether the record has such value;
</p>
<p>(g) To another agency or to an instrumentality of any governmental jurisdiction within or under the control of the United States for a civil or criminal law enforcement activity if the activity is authorized by law, and if the head of the agency or instrumentality has made a written request to NCUA specifying the particular portion desired and the law enforcement activity for which the record or item is sought;
</p>
<p>(h) To a person pursuant to a showing of compelling circumstances affecting the health or safety of an individual if, upon such disclosure, notification is transmitted to the last known address of such individual;
</p>
<p>(i) To either House of Congress, or, to the extent of matter within its jurisdiction, any committee or subcommittee thereof, any joint committee of Congress or subcommittee of any such joint committee;
</p>
<p>(j) To the Comptroller General, or any of his authorized representatives, in the course of the performance of the duties of the Government Accountability Office;
</p>
<p>(k) Pursuant to the order of a court of competent jurisdiction; or
</p>
<p>(l) To a consumer reporting agency in accordance with section 3711(f) of title 31 of the United States Code (31 U.S.C. 3711(f)).
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 73 FR 56939, Oct. 1, 2008]

</p>
<p><b>&#167; 792.61
 Accounting for disclosures.
</b></p>
<p>(a) Each system manager identified in the "Notice of Systems of Records" must establish a system of accounting for all disclosures of information or records under the Privacy Act made outside NCUA. Accounting procedures may be established in the least expensive and most convenient form that will permit the system manager to advise individuals, promptly upon request, of the persons or agencies to which records concerning them have been disclosed.
</p>
<p>(b) Accounting records, at a minimum, shall include the information disclosed, the name and address of the person or agency to whom disclosure was made, and the date of disclosure. When records are transferred to the National Archives and Records Administration for storage in records centers, the accounting pertaining to those records shall be transferred with the records themselves.
</p>
<p>(c) Any accounting made under this section shall be retained for at least five years or the life of the record, whichever is longer, after the disclosure for which the accounting is made.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 73 FR 56939, Oct. 1, 2008]

</p>
<p><b>&#167; 792.62
 Requests for accounting for disclosures.
</b></p>
<p>At the time of the request for access or correction or at any other time, an individual may request an accounting of disclosures made of the individual's record outside the NCUA. Request for accounting shall be directed to the system manager. Any available accounting, whether kept in accordance with the requirements of the Privacy Act or under procedures established prior to September 27, 1975, shall be made available to the individual, except that an accounting need not be made available if it relates to:
</p>
<p>(a) A disclosure made pursuant to the Freedom of Information Act (5 U.S.C. 552);
</p>
<p>(b) A disclosure made within the NCUA;
</p>
<p>(c) A disclosure made to a law enforcement agency pursuant to 5 U.S.C. 552a(b)(7);
</p>
<p>(d) A disclosure which has been exempted from the provisions of 5 U.S.C. 552a(c)(3) pursuant to 5 U.S.C. 552a (j) or (k).

</p>
<p><b>&#167; 792.63
 Collection of information from individuals; information forms.
</b></p>
<p>(a) The system manager for each system of records is responsible for reviewing all forms developed and used to collect information from or about individuals for incorporation into the system of records.
</p>
<p>(b) The purpose of the review shall be to eliminate any requirement for information that is not relevant and necessary to carry out an NCUA function and to accomplish the following objectives:
</p>
<p>(1) To ensure that no information concerning religion, political beliefs or activities, association memberships (other than those required for a professional license), or the exercise of other First Amendment rights is required to be disclosed unless such requirement of disclosure is expressly authorized by statute or by the individual about whom the record is maintained, or unless pertinent to and within the scope of any authorized law enforcement activity;
</p>
<p>(2) To ensure that the form or accompanying statement makes clear to the individual which information by law must be disclosed and the authority for that requirement, and which information is voluntary;
</p>
<p>(3) To ensure that the form or accompanying statement makes clear the principal purpose or purposes for which the information is being collected, and states concisely the routine uses that will be made of the information;
</p>
<p>(4) To ensure that the form or accompanying statement clearly indicates to the individual the effects on him or her, if any, of refusing to provide some or all of the requested information; and
</p>
<p>(5) To ensure that any form requesting disclosure of a social security number, or an accompanying statement, clearly advises the individual of the statute or regulation requiring disclosure of the number, or clearly advises the individual that disclosure is voluntary and that no consequence will flow from a refusal to disclose it, and the uses that will be made of the number whether disclosed mandatorily or voluntarily.
</p>
<p>(c) Any form which does not meet the objectives specified in the Privacy Act and this section shall be revised to conform thereto.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 73 FR 56939, Oct. 1, 2008]

</p>
<p><b>&#167; 792.64
 Contracting for the operation of a system of records.
</b></p>
<p>(a) No NCUA component shall contract for the operation of a system of records by or on behalf of the Agency without the express approval of the NCUA Board.
</p>
<p>(b) Any contract which is approved shall continue to ensure compliance with the requirements of the Privacy Act. The contracting component shall have the responsibility for ensuring that the contractor complies with the contract requirements relating to the Privacy Act.

</p>
<p><b>&#167; 792.65
 Fees.
</b></p>
<p>(a) Fees pursuant to 5 U.S.C. 552a(f)(5) shall be assessed for actual copies of records provided to individuals on the following basis, unless the system manager determining access waives the fee because of the inability of the individual to pay or the cost of collecting the fee exceeds the fee:
</p>
<p>(1) For copies of documents provided, copy fees as stated in NCUA's current FOIA fee schedule; and
</p>
<p>(2) For copying information, if any, maintained in nondocument form, the direct cost to NCUA may be assessed.
</p>
<p>(b) If it is determined that access fees chargeable under this section will amount to more than $25, and the individual has not indicated in advance willingness to pay fees as high as are anticipated, the individual shall be notified of the amount of the anticipated fees before copies are made, and the individual's access request shall not be considered to have been received until receipt by NCUA of written agreement to pay.
</p>
<p>[54 FR 18476, May 1, 1989. Redesignated at 63 FR 14338, Mar. 25, 1998, as amended at 65 FR 63790, Oct. 25, 2000]

</p>
<p><b>&#167; 792.66
 Exemptions.
</b></p>
<p>(a) NCUA maintains several systems of records that are exempted from some provisions of the Privacy Act. The system number and name, description of records contained in the system, exempted provisions and reasons for exemption are as follows:
</p>
<p>(b)(1) System NCUA-1, entitled "Employee Suitability Security Investigations Containing Adverse Information," consists of adverse information about NCUA employees that had been obtained as a result of routine U.S. Office of Personnel Management (OPM) security investigations. To the extent that NCUA maintains records in this system pursuant to OPM guidelines that may require retrieval of information by use of individual identifiers, those records are encompassed by and included in the OPM Central system of records number Central-9 entitled, "Personnel Investigations Records," and thus are subject to the exemptions promulgated by OPM. Additionally, in order to ensure the protection of properly confidential sources, particularly as to those records which are not maintained pursuant to such Office of Personnel Management requirements, the records in these systems of records are exempted, pursuant to section k(5) of the Privacy Act (5 U.S.C. 552a(k)(5)), from section (d) of the Act (5 U.S.C. 552a(d)). To the extent that disclosure of a record would reveal the identity of a confidential source, NCUA need not grant access to that record by its subject. Information which would reveal a confidential source shall, however, whenever possible, be extracted or summarized in a manner which protects the source and the summary or extract shall be provided to the requesting individual.
</p>
<p>(2) System NCUA-8, entitled, "Investigative Reports Involving Any Crime or Suspicious Activity Against a Credit Union, NCUA," consists of investigatory or enforcement records about individuals suspected of involvement in violations of laws or regulations, whether criminal or administrative. These records are maintained in an overall context of general investigative information concerning crimes against credit unions. To the extent that individually identifiable information is maintained for purposes of protecting the security of any investigations by appropriate law enforcement authorities and promoting the successful prosecution of all actual criminal activity, the records in this system are exempted, pursuant to section k(2) of the Privacy Act (5 U.S.C. 552a (k)(2)), from sections (c)(3), (d), (e)(1), (e)(2), (e)(4)(G), (e)(4)(H), (f), and (g). The records in this system are also exempted pursuant to section (j)(2) of the Privacy Act, 5 U.S.C. 552a(j)(2), from sections (c)(3), (d), (e)(1), (e)(2), (e)(4)(G), (e)(4)(H), (f), and (g). Where possible, information that would identify a confidential source will be extracted or summarized in a manner that protects the source and the summary or extract will be provided to the requesting individual.
</p>
<p>(3) System NCUA-20, entitled, "Office of Inspector General (OIG) Investigative Records," consists of OIG records of closed and pending investigations of individuals alleged to have been involved in criminal violations. The records in this system are exempted pursuant to sections (k)(2) of the Privacy Act, 5 U.S.C. 552a(k)(2), from sections (c)(3), (d), (e)(1), (e)(4)(G), (e)(4)(H), (e)(4)(I), and (f). The records in this system are also exempted pursuant to section (j)(2) of the Privacy Act, 5 U.S.C. 552a(j)(2), from sections (c)(3), (c)(4), (d), (e)(1), (e)(2), (e)(3), and (g). NCUA need not make an accounting of previous disclosures of a record in this system of records available to its subject, and NCUA need not grant access to any records in this system of records by their subject. Further, whenever individuals request records about themselves and maintained in this system of records, the NCUA will advise the individuals only that no records available to them pursuant to the Privacy Act of 1974 have been identified. However, if review of the record reveals that the information contained therein has been used or is being used to deny the individuals any right, privilege or benefit for which they are eligible or to which they would otherwise be entitled under federal law, the individuals will be advised of the existence of the information and will be provided the information, except to the extent disclosure would identify a confidential source. Where possible, information which would identify a confidential source will be extracted or summarized in a manner which protects the source and the summary or extract will be provided to the requesting individual.
</p>
<p>(4) System NCUA-13, entitled, "Litigation Case Files," consists of investigatory materials compiled for law enforcement purposes. Records in the Litigation Case Files system are used in connection with the execution of NCUA's legal and enforcement responsibilities. Because the system covers investigatory materials compiled for law enforcement purposes, it is eligible for exemption under subsection (k)(2) of the Privacy Act. 5 U.S.C. 552a(k)(2). The Litigation Case Files system is exempt from subsections (c)(3), (d), (e)(1), (e)(4)(G), (H), (I) and (f) of the Privacy Act. 5 U.S.C. 552a (c)(3), (d), (e)(1), (e)(4)(G), (H), (I) and (f). However, if an individual is denied any right, privilege, or benefit to which he would otherwise be entitled by federal law, or for which he otherwise would be eligible, as a result of the maintenance of such records, the records or information will be made available to him, provided the identity of a confidential source is not disclosed. NCUA need not make an accounting of previous disclosures of a record in this system of records available to its subject, and NCUA need not grant access to any records in this system of records by their subject. Further, whenever individuals request records about themselves and maintained in this system of records, the NCUA will advise the individuals only that no records available to them pursuant to the Privacy Act of 1974 have been identified. However, if review of the record reveals that the information contained therein has been used or is being used to deny the individuals any right, privilege or benefit for which they are eligible or to which they would otherwise be entitled under federal law, the individuals will be advised of the existence of the information and will be provided the information, except to the extent disclosure would identify a confidential source. Where possible, information that would identify a confidential source will be extracted or summarized in a manner which protects the source and the summary or extract will be provided to the requesting individual.
</p>
<p>(c) For purposes of this section, a "confidential source" means a source who furnished information to the Government under an express promise that the identity of the source would remain confidential, or, prior to September 27, 1976, under an implied promise that the identity of the source would be held in confidence.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 60 FR 31912, June 19, 1995; 64 FR 57365, Oct. 25, 1999; 65 FR 63790, Oct. 25, 2000; 73 FR 56940, Oct. 1, 2008; 75 FR 34623, June 18, 2010]

</p>
<p><b>&#167; 792.67
 Security of systems of records.
</b></p>
<p>(a) Each system manager, with the approval of the head of that Office, shall establish administrative and physical controls to insure the protection of a system of records from unauthorized access or disclosure and from physical damage or destruction. The controls instituted shall be proportional to the degree of sensitivity of the records, but at a minimum must insure: that records are enclosed in a manner to protect them from public view; that the area in which the records are stored is supervised during all business hours to prevent unauthorized personnel from entering the area or obtaining access to the records; and that the records are inaccessible during nonbusiness hours.
</p>
<p>(b) Each system manager, with the approval of the head of that Office, shall adopt access restriction to insure that only those individuals within the agency who have a need to have access to the records for the performance of duty have access. Procedures shall also be adopted to prevent accidental access to or dissemination of records.

</p>
<p><b>&#167; 792.68
 Use and collection of Social Security numbers.
</b></p>
<p>The head of each NCUA Office shall take such measures as are necessary to ensure that employees authorized to collect information from individuals are advised that individuals may not be required without statutory or regulatory authorization to furnish Social Security numbers, and that individuals who are requested to provide Social Security numbers voluntarily must be advised that furnishing the number is not required and that no penalty or denial of benefits will flow from the refusal to provide it.

</p>
<p><b>&#167; 792.69
 Training and employee standards of conduct with regard to privacy.
</b></p>
<p>(a) The Director of the Office of Human Resources, with advice from the Senior Privacy Act Officer, is responsible for training NCUA employees in the obligations imposed by the Privacy Act and this subpart.
</p>
<p>(b) The head of each NCUA Office shall be responsible for assuring that employees subject to that person's supervision are advised of the provisions of the Privacy Act, including the criminal penalties and civil liabilities provided therein, and that such employees are made aware of their responsibilities to protect the security of personal information, to assure its accuracy, relevance, timeliness, and completeness, to avoid unauthorized disclosure either orally or in writing, and to insure that no information system concerning individuals, no matter how small or specialized, is maintained without public notice.
</p>
<p>(c) With respect to each system of records maintained by NCUA, Agency employees shall:
</p>
<p>(1) Collect no information of a personal nature from individuals unless authorized to collect it to achieve a function or carry out an NCUA responsibility;
</p>
<p>(2) Collect from individuals only that information which is necessary to NCUA functions or responsibilities;
</p>
<p>(3) Collect information, wherever possible, directly from the individual to whom it relates;
</p>
<p>(4) Inform individuals from whom information is collected of the authority for collection, the purposes thereof, the routine uses that will be made of the information, and the effects, both legal and practical of not furnishing the information;
</p>
<p>(5) Not collect, maintain, use, or disseminate information concerning an individual's religious or political beliefs or activities or his membership in associations or organizations, unless:
</p>
<p>(i) The individual has volunteered such information for his own benefit;
</p>
<p>(ii) The information is expressly authorized by statute to be collected, maintained, used, or disseminated; or
</p>
<p>(iii) Activities involved are pertinent to and within the scope of an authorized investigation or adjudication.
</p>
<p>(6) Advise their supervisors of the existence or contemplated development of any record system which retrieves information about individuals by individual identifier.
</p>
<p>(7) Maintain an accounting, in the prescribed form, of all dissemination of personal information outside NCUA, whether made orally or in writing;
</p>
<p>(8) Disseminate no information concerning individuals outside NCUA except when authorized by 5 U.S.C. 552a or pursuant to a routine use as set forth in the "routine use" section of the "Notice of Systems of Records" published in the <i>Federal Register</i>.
</p>
<p>(9) Maintain and process information concerning individuals with care in order to ensure that no inadvertent disclosure of the information is made either within or outside NCUA; and
</p>
<p>(10) Call to the attention of the proper NCUA authorities any information in a system maintained by NCUA which is not authorized to be maintained under the provisions of the Privacy Act, including information on First Amendment activities, information that is inaccurate, irrelevant or so incomplete as to risk unfairness to the individuals concerned.
</p>
<p>(c) Heads of offices within NCUA shall, at least annually, review the record systems subject to their supervision to ensure compliance with the provisions of the Privacy Act.
</p>
<p>[54 FR 18476, May 1, 1989, as amended at 59 FR 36042, July 15, 1994; 65 FR 63790, Oct. 25, 2000; 67 FR 30774, May 8, 2002; 73 FR 56940, Oct. 1, 2008]
</p>
</xhtmlContent>
</regulationsPart>
</regulationsChapter>
</regulationsTitle>
</regulations>
</agency>
</pai>
