The Immediate Office of the General Counsel (S9A).
- The Ethics Law Staff (ELS) (S9A-5) is responsible for providing a full range of legal advice and services to the Commissioner, all regional components and every Headquarters component of the Agency regarding ethics laws, regulations and policies. ELS also provides legal ethics guidance to all employees of the Agency. ELS is responsible for interpretation, implementation, and enforcement of ethics related laws, regulations, and policies by the agency. This includes issuance of legal opinions regarding employee and management ethical obligations; establishment of agency rules and processes for an effective agency ethics program; review and comment of proposed ethics legislation; and direction and support in preparation of cases involving ethics violation before administrative bodies or courts.
OPLW is responsible for drafting and reviewing SSA regulations, Federal Register materials, and legal instruments within OPLW’s areas of responsibility; proposals for legislation and specifications for such proposed legislation; reports and letters to congressional committees, the Office of Management and Budget, and others on proposed legislation and legislative matters; and proposed testimony of SSA officials before Congress. OPLW also provides legal advice and opinions to SSA’s headquarters and regional components with respect to matters within its areas of responsibility.
Subchapter S9H - Office of Privacy and Disclosure
- Mission
- The Office of Privacy and Disclosure (OPD) (S9H) develops and interprets SSA policy related to the agency’s collection, use, maintenance and disclosure of information to ensure compliance with: section 1106 of the Social Security Act; the Privacy Act of 1974; the Freedom of Information Act (FOIA); section 6103 of the Internal Revenue Code; the privacy provisions of the E-Government Act 2002 and the Federal Information Security Management Act; and other applicable privacy and disclosure statutes, regulations, and administration policies. To further its mission, OPD develops national guidelines and oversees the agency’s responses to FOIA requests; provides guidance and advice regarding the appropriate disclosure of agency information under the agency’s policies; ensures necessary privacy protections are built into new systems and processes developed to deliver more efficient service to agency customers; and develops policy and procedures for preventing and responding to potential breaches of personally identifiable information (PII). OPD also drafts and manages Computer Matching and Privacy Protection Act (CMPPA) agreements and other agreements governing information sharing.
- The Executive Director for Privacy and Disclosure (S9H)
- The Deputy Executive Director for Privacy and Disclosure (S9H)
- The Immediate Office of the Executive Director for Privacy and Disclosure (S9H)
- The Disclosure and Data Support Division (S9HA)
- The Privacy Implementation Division (S9HB)
- The FOIA and Transparancy Division (S9HC)
- The Electronic Interchange and LIaison Division (S9HE)
- The Breach Division (S9HG)
- The Executive Director for Privacy and Disclosure (S9H) is directly responsible to the General Counsel for carrying out the OPD mission and providing general supervision to the components of OPD.
- The Deputy Executive Director for Privacy and Disclosure (S9H) assists the Executive Director in carrying out the other duties as the Executive Director may prescribe. The Deputy Executive Director for Public Disclosure also serves as SSA’s Freedom of Information Officer and Privacy Officer. The Principal Privacy Compliance Advisor (PPCA) reports directly to the Executive Director of OPD, who, under the guidance of the Senior Agency Official for Privacy (SAOP), is accountable for the overall privacy compliance program. The PPCA serves as a senior technical advisor and the principal advocate for developing and facilitating technical agency compliance with privacy law and policy to synchronize the protection of privacy in the collection, maintenance, use, sharing, and storage of personal information about individuals, while simultaneously facilitating SSA programs and activities.
- The Immediate Office of the Executive Director for Privacy and Disclosure (S9H) provides the Executive Director and Deputy Executive Director with administrative staff assistance, technology leadership, planning, and customer relations support on the full range of their responsibilities, which includes strategic and tactical planning to include priorities and objectives to ensure compliance with privacy law and policy, resulting in improved protection practices with the collection, maintenance, use, sharing, and storage of personal and sensitive agency information.
- The Disclosure and Data Support Division (S9HA)
- Provides guidance and services to SSA Regional and Headquarters components to resolve questions of whether Agency employees may disclose personal information from Agency records.
- Provides guidance on questions arising under other disclosure statutes.
- Responds to requests for personal information pursuant to a law enforcement request.
- Develops, manages, and tracks policy and emerging trends related to alldisclosure and data exchange issues throughout Headquarters and the Regions.
- Provides support on FOIA requests and appeals, and Privacy Act appeals.
- Identifies and ensures that all programs and systems comply with privacy requirements contained in the FISMA certification and accreditation process and the OMB 300 budget submission.
- Develops privacy implementation documentation for Agency systems and programs, i.e., privacy threshold analyses, privacy impact assessments, and systems of records notices.
- Reviews Agency technology business process descriptions, project scope agreements and software development and procurement plans for privacy issues.
- Develops and implements a risk management framework for mitigating privacy risks and ensuring compliance, for all data collections, throughout the information lifecycle, including developing and considering creative solutions to mitigating risks while achieving key mission objectives and working to meet client expectations.
- Prepares notices, manages privacy incidents, and the agency’s non-cyber and cyber-related data breach reporting, and supports the agency’s response to cyber-related data breach incidents.
- Develops, manages, and tracks policy and emerging trends related to all privacyissues throughout Headquarters and the Regions.
- Provides support on FOIA requests and appeals, and Privacy Act appeals.
- Develops national guidelines related to FOIA and coordinates, directs, and provides guidance on FOIA policies and procedures throughout OPD, other Headquarters components, and the Regions.
- Responds to simple and complex FOIA requests and appeals, coordinates office-wide FOIA processes, and handles collection of responsive materials.
- Carries out FOIA-related Open Government initiatives.
- Coordinates and directs any internal or external FOIA reports.
- Plans, directs, and manages use of the eFOIA processing system.
- Supports the FOIA Officer in the coordination of FOIA-related litigation
- Develops, manages, and tracks policy and emerging trends related to FOIA throughout Headquarters and the Regions.
- Provides support on FOIA requests and appeals, and Privacy Act appeals.
- Negotiates and manages matching agreements that are subject to the CMPPA and similar information exchange agreements.
- Provides leadership to the Agency’s Data Integrity Board (DIB) on CMPPA processes that include advising the DIB.
- Develops, manages and tracks policy and emerging trends related to all data exchanges, including the CMPPA throughout Headquarters and the Regions.
- Oversees the maintenance of the Electronic Data Exchange System Tracking System.
- Provides support on FOIA requests and appeals, and Privacy Act appeals.
- Develops, documents, and disseminates agency policy and procedures for reporting suspected or confirmed information losses that contain personally identifiable information (PII) or federal tax information.
- Develops and maintains the agency’s Breach Response Plan in accordance with applicable laws, regulations, and guidance.
- Oversees the monitoring and maintenance of the agency’s PII Loss Reporting Tool, including providing support to Breach Response Coordinators with the completion of Risk of Harm Assessments to determine appropriate remediation efforts, such as notifying affected individuals, oversight entities, and the issuance of credit monitoring.
- Oversees the development and implementation of role-based training for Breach Response Coordinators and other relevant agency personnel.
- Oversees the management of the agency’s Blanket Purchase Agreement for credit monitoring services for individuals impacted by PII or FTI losses.
- Develops reports and executive dashboards comprised of breach-related key performance indicators (KPIs) based on requirements set forth by OMB, FISMA, and other relevant laws or statutes.
- Collaborates with the Office of Information Security to develop and facilitate Tabletop exercises with relevant agency personnel (e.g., Breach Response Coordinators, Breach Response Team, etc.) to test the effectiveness of and make necessary changes to agency policies and plans.
- Provides support on privacy assessments, FOIA requests and appeals, and Privacy Act appeals.
Subchapter S9J - Office of Legal Operations
- Mission
- The Office of Legal Operations (OLO) develops and improves policies, processes, systems and data to support OGC to (1) improve legal advocacy and advice; (2) inform the development and evaluation of litigation strategy; and (3) identify areas where the agency’s decision-making or policy could be improved to provide better service to claimants and beneficiaries. Provides financial resources, human resources, and critical business and legal operations to support OGC’s organizational and technological infrastructure.
- The Executive Director for Legal Operations (S9J)
- The Deputy Executive Director for Legal Operations (S9J)
- The Division of Legal Support Services (S9JA)
- The Division of IT Infrastructure Support (S9JB)
- The Division of Data and Business Intelligence (S9JC)
- The Division of Business Support Services (S9JE)
- The Executive Director for Legal Operations is directly responsible to the General Counsel for carrying out the OLO mission and providing general supervision to the divisions of OLO.
- The Deputy Executive Director for Legal Operations assists in carrying out the Executive Director’s responsibilities and performs other duties as the Executive Director may prescribe.
- The Division of Legal Support Services (S9JA)
- Provides operational support and training for legal issues.
- Promotes nationwide consistency in the administration of SSA’s civil and criminal Special Assistant United States Attorney programs.
- Coordinates and oversees OGC’s records management, including records retention and archiving.
- Coordinates and oversees recruitment of legal professionals with an emphasis on diversity, equity, and inclusion.
- Provides nationwide legal administrative support.
- Oversees and coordinates information technology infrastructure and initiatives.
- Serves as liaison with the Office of Systems.
- Provides information technology oversight and guidance, coordinating OGC system needs and interests with other components and organizations.
- Ensures OGC’s systems operations appropriately interface or integrate with SSA’s systems operations.
- Leads development and implementation of critical infrastructure protection, security measures, and other controls to prepare for and mitigate consequences.
- Manages OGC’s data collection and management information systems.
- Analyzes data and produces business intelligence and management information reports for OGC executives and managers nationwide.
- Conducts evaluations to assess program operations to improve SSA and OGC policies and results and enhance the Agency’s service to the public.
- Coordinates and integrates the full scope of software development projects and initiatives used to manage OGC’s nationwide operation.
- Provides support, as needed, with IT operations.
- Coordinates and oversees human resource program management and policymaking for OGC.
- Develops and implements standard operating procedures and requirements, as well as SSA’s administrative procedures, for OGC nationwide.
- Coordinates and oversees OGC’s facilities management functions and continuity of operations nationwide.
- Formulates, executes, and monitors the component’s budget plans and spending.
- Controls component’s staffing ceilings and funding limits and prepares component allocations and FTEs.
- Analyzes and monitors component productivity in relation to the component’s budget and spending.