A System of Records Notice, or SORN, is the public notice a federal agency publishes in the Federal Register to disclose that it keeps a database of personal information retrievable by your name, Social Security number, or another identifier tied to you. Each notice tells you what the agency collects, why it collects it, who it shares the data with, and how you can see or correct your own file. If you want to know what the federal government has on you, the SORN is the map.
The Law That Requires It
The Privacy Act of 1974, codified at 5 U.S.C. ยง 552a, is what forces agencies to publish these notices. Under subsection (e)(4), any agency that maintains a “system of records” must publish a notice in the Federal Register when the system is created and again whenever it’s significantly revised.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals The statutory definition is specific: a system of records is a group of records under the agency’s control where information is pulled up by an individual’s name or personal identifier. If the agency can look you up by name or ID number, the system needs a SORN.
Agencies cannot quietly stand up a new database without first telling the public. Adding new categories of people, new types of data, or new sharing arrangements with outside entities all trigger an updated notice.
What a SORN Must Tell You
Every notice has to cover nine categories. Reading them gives you a standardized picture of what the agency holds and how to reach it.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
- The system name and where it’s located.
- The categories of individuals whose records are in it, such as benefit applicants, federal employees, or immigration petitioners.
- The categories of records, whether financial, medical, employment, or otherwise.
- The routine uses: every circumstance under which the agency may share your data with outside parties without your consent, and for what purpose.
- How records are stored, retrieved, and secured.
- The name, title, and business address of the official in charge.
- How to ask whether the system contains a record on you.
- How to obtain a copy of your record and how to contest its accuracy.
- Where the agency gets its information, whether from you, other agencies, employers, or third-party databases.
The routine uses section rewards careful reading. Agencies commonly authorize sharing with debt collection contractors, the Department of Justice for litigation, and congressional offices handling constituent inquiries. If your concern is who else sees the data, that section holds the answers.
Who Can Actually Request Records
The Privacy Act’s access rights run only to “individuals,” and the statute defines that as U.S. citizens and lawful permanent residents.2U.S. Department of Justice. OIP Guidance The Interface Between the FOIA and Privacy Act Foreign nationals on temporary visas, non-residents, corporations, and other organizations cannot use the Privacy Act to request records about themselves. If you fall outside the definition, the Freedom of Information Act is the alternative route, with its own rules and exemptions.
FOIA and the Privacy Act work differently. FOIA is open to anyone and covers any agency record. The Privacy Act is limited to eligible individuals and applies only to records held in a system of records. When you request your own file, most agencies process the request under both statutes at once, because the two laws have different exemptions and the agency needs both a Privacy Act and a FOIA basis to withhold anything. Cite both statutes in your request letter. Standard agency forms usually do this for you.
Finding the Right Notice
The Federal Register is the authoritative source. Every SORN is published there, and the archive is searchable through the Federal Register’s dedicated Privacy Act section.3Federal Register. Privacy Act Notices and Regs Most large federal departments also keep a privacy page listing their active SORNs by bureau, which is often easier to navigate if you already know which agency holds your data. If you can’t find what you need online, the agency’s Chief Privacy Officer can point you to the right notice.
Locate the correct SORN before you draft anything. The notice tells you the exact identifiers the agency needs, the official who handles requests, and where to send them. Using the wrong system name or the wrong address is the fastest way to delay a response.
Preparing and Submitting Your Request
Every SORN contains a section called something like “Record Access Procedures.” Read it first. Most requests require your full name, date of birth, and a personal identifier named in the notice, such as a Social Security number, case file number, or employee ID.
Identity verification is where requests most often stall. Agencies are legally barred from releasing your records to an impostor, and requesting records under false pretenses is a federal misdemeanor with a fine up to $5,000.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals Agencies typically accept one of two proofs: a copy of a government-issued photo ID bearing your signature, or a signed and dated statement, sworn under penalty of perjury, that acknowledges the penalties for a false request.4U.S. Department of the Treasury. How to Write a Privacy Act Request – Section: Verification of Identity If the notice calls for notarization, expect a small notary fee, typically $2 to $25 depending on your state.
Many agencies publish a standardized request form. If yours doesn’t, write a letter that includes the system name copied exactly from the SORN, a clear description of the records you want, and your identity verification. Submit it however the SORN directs, whether by mail, a secure online portal, or a designated email address. Keep copies of everything, including any tracking numbers.
Costs are minimal. Under the Privacy Act, agencies cannot charge you for searching for or reviewing your records. The only permissible fee is duplication, which is the actual cost of copying pages or producing digital files.5eCFR. 21 CFR 1401.24 – What Does It Cost to Get Records Under the Privacy Act Filing a request is treated as an agreement to pay applicable duplication fees unless you cap the amount. A line like “please do not exceed $25 without contacting me first” prevents surprises.
How Long the Agency Has
The Privacy Act itself sets no hard deadline for producing records. Individual agency regulations fill that in. The Department of Justice, for instance, requires its components to begin responding within 10 working days of receiving a properly directed request.6eCFR. 28 CFR 16.43 – Responses to a Privacy Act Request for Access
Actual turnaround varies. A well-defined electronic file may come back within weeks. Older paper records, requests spanning multiple systems, or large volumes of documents can take months. The agency may contact you to narrow the search. If nothing exists under the identifiers you supplied, you’ll receive a formal “no records” letter. If records exist but some are withheld under a legal exemption, the response must identify the exemption relied on.
Exemptions That Can Block Access
Not every record is available to you. The Privacy Act lets agencies exempt certain systems from the access and amendment provisions, and the exemptions cluster around law enforcement and national security.
General Exemptions
Subsection (j) authorizes two broad exemptions.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals One covers Central Intelligence Agency systems. The other covers systems held by agencies whose primary function is criminal law enforcement, where the records consist of criminal investigation materials, arrest and disposition data, or enforcement records tied to identifiable individuals. When an agency invokes a general exemption, it can refuse to confirm whether a record about you exists, deny access, and block amendment.
Specific Exemptions
Subsection (k) provides narrower exemptions for particular record types even in agencies that aren’t primarily law enforcement bodies.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals These cover records classified for national defense or foreign policy, investigatory material compiled for law enforcement by non-law-enforcement agencies, Secret Service protective intelligence, federal employment testing materials, and suitability determinations for military service or federal employment.
The (k)(2) investigatory-material exemption has a built-in limit. If you were denied a right, privilege, or benefit because of information in those records, the agency must give you the material. The one carve-out is when disclosure would identify a confidential source.
Correcting a Record
If your records contain something wrong, the Privacy Act gives you the right to request an amendment. You can challenge a record that is inaccurate, irrelevant, untimely, or incomplete. Send the request to the agency component that maintains the record, identify the specific entry, describe the correction you want, and explain why the current version is wrong. Include supporting documentation.7eCFR. 28 CFR 16.46 – Privacy Act Requests for Amendment or Correction
The agency must acknowledge your amendment request in writing within 10 working days of receiving it. It must then act “promptly” to either make the correction or explain the refusal.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
A refusal letter must give reasons and explain how to appeal to a higher official within the agency. You also have the right to file a statement of disagreement, a written explanation of why you believe the record is wrong. The agency must attach that statement to the disputed record, and every future disclosure of the record must include your statement alongside it.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
Appeals and Going to Court
Agency-specific regulations set the deadlines and procedures for internal appeals. Some agencies give you 30 calendar days from the date of denial to appeal, and the reviewing official typically has 30 working days to decide, with extensions for good cause. Check the SORN and the agency’s Privacy Act regulations for the exact process.
If the internal appeal fails, the Privacy Act creates a right to sue in federal district court in four situations: the agency refuses to amend your record after appeal, the agency refuses access, the agency maintains inaccurate records that cause an adverse decision, or the agency violates any other provision of the Act in a way that harms you.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
Remedies depend on the type of violation. In access and amendment cases, the court can order the agency to produce records or make the correction. Where the agency maintained inaccurate records or otherwise violated the statute, and a court finds the agency acted intentionally or willfully, you can recover actual damages with a floor of $1,000, plus reasonable attorney fees and litigation costs.1Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
The $1,000 floor has real limits. In FAA v. Cooper (2012), the Supreme Court held that “actual damages” under the Privacy Act means proven economic harm only, not emotional distress or dignitary injuries. You must first prove actual damages to be entitled to recover; a willful violation causing some vague adverse effect isn’t enough. Without documented financial loss, the $1,000 minimum doesn’t kick in.8U.S. Department of Justice. Overview of the Privacy Act of 1974 2020 Edition – Remedies