6 CRR-NY 616.21NY-CRR
6 CRR-NY 616.21
6 CRR-NY 616.21
616.21 Designation of privacy compliance officer.
(a) The records access officer is hereby designated privacy compliance officer, and is responsible for ensuring that the department complies with the provisions of the Personal Privacy Protection Law and with these regulations.
(b) The address of the privacy compliance officer is:
Records Access Officer
Department of Environmental Conservation
Albany, NY 12233-1500
(c) The privacy compliance officer shall coordinate the response to individuals' requests for access to records which contain personal information. Individuals may also seek access to records containing personal information from department officials who have been authorized to make such records available.
(d) The privacy compliance officer is responsible for:
(1) assisting an individual in identifying and requesting personal information, if necessary;
(2) describing the contents of systems of records orally or in writing in order to enable an individual to learn if a system of records includes a record or personal information identifiable to an individual requesting such record or personal information; and
(3) ensuring that departmental personnel take one of the following actions upon locating the record sought:
(i) make the record available for inspection, in a printed form without codes or symbols, unless an accompanying document explaining such codes or symbols is also provided;
(ii) permit the individual to copy the record;
(iii) deny access to the record in whole or in part and explain in writing the reasons therefor;
(iv) make a copy available upon request, upon payment of or offer to pay established fees, if any, or permit the individual to copy the record;
(v) upon request, certify that a copy of the record is a true copy; or
(vi) certify, upon request, that:
(a) the department does not have possession of the record sought;
(b) the department cannot locate the record sought after having made a diligent search; or
(c) the information sought cannot be retrieved by use of the description thereof, or by use of the name or other identifier of the individual without extraordinary search methods being employed by the department.
(e) The privacy compliance officer will inform department personnel of their duties pursuant to subdivision 1 of section 94 of the Personal Privacy Protection Act of the Public Officers Law as follows:
(1) to maintain personal information only when it is relevant and necessary to accomplish the purposes of the department in a secure manner and whenever practicable to collect the data from the data subject;
(2) to provide notification to the data subject in accordance with section 94(1)(d) of the Public Officers Law when personal information is sought; and
(3) to keep records of the date, nature and purpose of each disclosure of a personal record and to whom the disclosure was made and retain this information for five years or for the life of the record, whichever is longer.
6 CRR-NY 616.21
Current through February 29, 2020
|End of Document||© 2020 Thomson Reuters. No claim to original U.S. Government Works.|