OMB Director Shaun Donovan recently announced a governmentwide council of chief privacy officers.

OMB Director Shaun Donovan recently announced a governmentwide council of chief privacy officers. Manuel Balce Ceneta/AP

Obama's Coming Privacy Council Welcomed by Industry Leader

Budget director's call for professionalization of privacy officers called a turning point.

The White House budget director’s recent announcement of a coming governmentwide council of chief privacy officers marks the Obama administration’s latest response to last June’s revelation of a data breach at the Office of Personnel Management, a step that at least one privacy expert calls “a moment we will look back on as a major change.”

J. Trevor Hughes, president and CEO of the Portsmouth, N.H.-based International Association of Privacy Professionals, told Government Executive that Budget Director Shaun Donovan’s announcement of the council at an agency privacy summit is a welcome step toward “professionalization” of an agency function for which there is currently no career path.

“We’ve seen professionalization of privacy explode in the private sector, and Donovan’s speech” and promise of new guidance from the Office of Management and Budget “are clear indicators of increasing maturity,” he said, a sign that the federal government is taking seriously the need to build privacy into agency life to protect both cyber hygiene and human rights.

“Organizations around the world are recognizing that anyone who touches data or makes decisions must understand privacy, said Hughes, whose association has 25,000 members in 80 countries—double its roster of two years ago.

The term “privacy” encompasses two related ideas, he added. In the cyber sense, privacy refers to “technology measures we take to protect data,” but in the values sense it refers to “our awareness of how we manage data and what we’re permitted to do.”

Hughes added: “You can’t have privacy without good security. So increasingly we are finding the conversation about privacy melds into the conversation about cyber security.”

That view is shared by Donovan, who told 375 agency privacy specialists on Dec. 2 that “we are a country that created the Internet. But we are also a country that pioneered the Bill of Rights, and we have a belief that our privacy should not only be guarded against unwarranted government intrusion, but also protected.”

His speech laid out the administration’s agenda to prevent data breaches, prevent harm to affected individuals should breaches occur, “enhance the productivity, efficiency and effectiveness of government” and, finally, “build and regain trust in government” at a time when surveys show public faith in agency competence at record lows.

As an example, Donovan cited the Census Bureau, which “has identified Americans’ growing distrust of the government’s ability to responsibly collect and store data as one of the most significant challenges they face in conducting the next census.”

Donovan said: "It's time to stop re-inventing the privacy wheel at agencies and do a better job of leveraging the success of each agency's related efforts. It is time to shift from reactive programs to proactive strategies. And it is time to 'professionalize' the privacy profession." 

That means each major agency will be appointing “chief privacy officers” who will meet on a body similar to the Chief Information Officers Council to “serve as an ecosystem for strategic thinking on privacy implementation, bringing together the best minds we have to tackle the cutting-edge privacy issues of the digital era.”

The government needs “chief privacy officers to help continue to identify our high value assets that store sensitive [personally identifiable information], ask tough questions about data minimization, ensure compliance with retention schedules, and evaluate policies for sharing and transferring data,” Donovan said. “If program managers aren’t sure about the sensitivity of a data set or the risk of harm such data may present if compromised, they should ask their CPO,” he added. “Too many projects have been delayed or shelved because of the failure to address responsible data practices up front.” 

Having privacy programs run by experts, he said, “will enable innovation, not slow it down. If we don’t invest in privacy today, these issues will only be more challenging tomorrow.”

Donovan praised acting OPM Director Beth Cobert for creating a powerful senior privacy position and the State Department for its coming new career Senior Executive Service chief privacy officer. The Justice and Defense departments also have moved ahead to create high-level privacy officers that deal with civil liberties.

Donovan also promised new OMB guidance, including a long-sought update of the Y2K-era Circular A-130 on “Managing Information in Strategic Decision Making.” As Marc Groman, whom Donovan last spring appointed as the first OMB senior adviser for privacy, said at the summit, Circular A-130 has gone through two rounds of agency review and a public comment period that ended Dec. 5.

Groman has been surveying agency privacy staff, Donovan noted. Among Groman’s findings are that agencies need more training and professional development in privacy, that hiring top talent is tough and that there is “no career path for privacy in the federal government.” 

Groman also learned that “much of the government’s privacy guidance should be tailored to reflect recent technological and other changes” and that currently there is too much “reacting to incidents and not enough strategic thinking.”

The next challenge, said Hughes, “will be finding those privacy professionals OPM is calling for.” In the private sector, “we’ve had to build over 10,000 new privacy professionals in the world during the last two years. So for anyone looking for career development or a growth field, stepping into privacy is good choice.”

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.