A System of Records Notice, or SORN, is the public announcement a federal agency must publish in the Federal Register whenever it maintains a collection of personal information that it retrieves by an individual’s name or other personal identifier. The Privacy Act of 1974 requires it so that no executive branch agency can quietly operate a database of information about people. Each notice spells out what data the agency holds, whose information is in it, who else may receive it, and how you can see or correct your own file.1Office of Privacy and Civil Liberties. Privacy Act of 1974
What Triggers the Notice Requirement
The legal test is narrower than it sounds. A “system of records” under the Privacy Act is any group of records under an agency’s control from which information is actually retrieved by an individual’s name, Social Security number, fingerprint, photograph, or another identifier tied to a specific person.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals Format doesn’t matter. A searchable database qualifies. So does a filing cabinet organized by last name.
What matters is the retrieval method. If an agency stores information about thousands of people but can only pull it by date or project number, that collection isn’t a system of records. The moment it builds an index tied to personal identifiers, the notice requirement kicks in.
Who the Privacy Act Protects
The Act defines “individual” as a U.S. citizen or lawful permanent resident.3Federal Register. Privacy Act of 1974 – System of Records Tourists, undocumented immigrants, and foreign nationals abroad generally have no rights under it, though some agencies voluntarily extend certain protections, and the Judicial Redress Act gives citizens of designated countries limited access and correction rights.
The rules bind executive branch agencies — cabinet departments, the military, and independent agencies like the Social Security Administration. Congress, the federal courts, state and local governments, and private companies are all outside the Act. Data you hand to a state DMV or a private employer isn’t covered.
What a SORN Has to Tell You
Every SORN must include a specific set of elements that, taken together, describe what the agency is doing with personal information.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals The nine required components are:
- The system’s name and location.
- The categories of individuals whose information is in it, such as federal employees, benefit applicants, or veterans.
- The categories of records maintained, from medical histories to financial or employment data.
- The routine uses: every outside entity that may receive the data and the purpose for each disclosure.
- How records are stored, retrieved, and safeguarded.
- How long records are kept before disposal, following schedules set by the National Archives.4National Archives. What Are the General Records Schedules (GRS)
- The system manager’s name and business address.
- The notification, access, and contest procedures — how to check for records about you, get copies, and challenge inaccuracies.
- The categories of sources for the records.
Reading a SORN start to finish is dry work, but for most people the routine uses section is where attention should go. That section identifies every outside organization that may see your information and why. If you’re worried about a particular agency sharing your data with debt collectors, other departments, or contractors, look there first.
When Your Records Can Be Shared Without Consent
The default rule is strict: no agency can disclose a record from a system of records without the individual’s written consent. But the statute carves out 13 exceptions:2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
- Need-to-know access by agency employees doing their jobs.
- Records that must be released under the Freedom of Information Act.
- Routine uses already described in the published SORN and compatible with the purpose of collection.
- Census Bureau use for a census or survey.
- Statistical research where the recipient guarantees the data will be used only in non-identifying form.
- Transfer to the National Archives for records of historical value.
- Law enforcement requests from another agency, made in writing by the requesting agency’s head.
- Health or safety emergencies, with notice to the individual afterward.
- Disclosures to either chamber of Congress or a committee within its jurisdiction.
- Government Accountability Office audits and investigations.
- Congressional Budget Office performance of its duties.
- A court order from a court of competent jurisdiction.
- Consumer reporting agencies, for debt collection, under specific conditions.
The routine use exception does most of the work in practice. Because each agency defines its own routine uses and publishes them in the SORN, how broadly your data can be shared depends on how the agency drafts that section. When an agency proposes a new routine use, the statute requires publication in the Federal Register at least 30 days before it takes effect, giving the public a window to submit comments or objections.5Office of the Law Revision Counsel. 5 US Code 552a – Records Maintained on Individuals That comment window is the main point where individuals and advocacy groups can push back before new sharing begins.
Tracking Who Received Your Records
When an agency discloses your record under most of these exceptions, it must log the date, the nature and purpose of the disclosure, and the name and address of the recipient. Those logs must be kept for at least five years or the life of the record, whichever is longer.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals You can request this accounting to find out who received your information and when. Internal agency access and FOIA releases don’t get logged, and law enforcement disclosures are shielded from the accounting request. If you suspect your records have been improperly shared, asking for the disclosure accounting is usually the first step.
When SORN Protections Are Limited
Not every system of records is subject to the full Privacy Act. The statute recognizes two categories of exemptions, and an agency has to publish a separate rule in the Federal Register to invoke either one.6Federal Register. Privacy Act of 1974 – Exempting a System of Records From Certain Requirements
General exemptions are the broadest and are available only to CIA systems and to systems maintained by agencies whose principal function is criminal law enforcement, covering criminal investigations, arrest data, and correctional or parole records. Even a general exemption cannot excuse an agency from publishing a SORN or from the Act’s criminal penalties.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
Specific exemptions are narrower and open to more agencies. They cover classified national security information, law enforcement investigatory material, Secret Service protective intelligence, records used only for statistical purposes, and a handful of other categories. Under a specific exemption, an agency can waive your access and amendment rights but must still maintain the core SORN elements and comply with most other provisions.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals If a SORN references an exemption rule, that’s the reason your access rights may be limited for that system.
Using a SORN to Access or Correct Your Records
Every SORN contains three procedural sections that let you interact with the system: a notification procedure to find out whether the agency has records about you, an access procedure to get copies, and a contesting procedure to fix inaccuracies. The specific steps vary by agency, but the Privacy Act sets minimum requirements that apply across the board.
Making an Access Request
You typically submit a written request to the system manager listed in the SORN.7U.S. Department of the Interior. Privacy Act Requests Identify the specific system of records by name and number as published in the Federal Register, and include enough personal information for the agency to locate your file. Most agencies require identity verification, usually a notarized signature or a declaration under penalty of perjury that avoids the cost of a notary.8Federal Law Enforcement Training Centers. Information Necessary for Privacy Act Request
The Privacy Act sets no specific deadline for agencies to respond to access requests, unlike FOIA’s 20-business-day clock. Response times vary by agency and complexity. Some agencies have adopted their own timelines by regulation, but there is no universal statutory deadline to hold them to. If an agency refuses your request outright, you can challenge that refusal in federal court.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
You have the right to bring someone with you when reviewing records in person, though the agency may ask you to sign a written statement authorizing discussion of your records in that person’s presence.
Requesting a Correction
If records about you contain errors, you can request an amendment. The agency has 10 business days to acknowledge the request in writing. From there, it must either make the correction promptly or explain its refusal and the appeal process.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
If the agency refuses, you can ask a higher-ranking official to review the decision, and that review must be completed within 30 business days unless the agency head grants an extension for good cause. If the reviewer also denies the change, you have two options. You can file a “statement of disagreement” that gets attached to the disputed record and travels with it in any future disclosure. You can also take the matter to federal court.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals The statement of disagreement is worth filing even if you plan to litigate, because it makes sure anyone later receiving the record also sees your side.
What You Can Do If an Agency Violates the Act
The Privacy Act lets individuals sue in federal district court. You can sue if an agency wrongly refuses to amend your record, refuses to grant you access, maintains inaccurate records that lead to an adverse decision about you, or violates another provision of the Act in a way that harms you.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
For damages claims based on inaccurate records or other harmful violations, you must show the agency acted intentionally or willfully. Clear that bar and you are entitled to actual damages with a guaranteed minimum of $1,000, plus reasonable attorney fees and litigation costs. For access and amendment disputes, a court can order the agency to produce records or make corrections and can award attorney fees if you substantially prevail. The intentional-or-willful standard is a real hurdle. A bureaucratic mistake usually will not qualify; you need evidence the agency knew it was violating the Act or acted with reckless disregard for your rights.2Office of the Law Revision Counsel. 5 USC 552a – Records Maintained on Individuals
The Act also carries criminal penalties. Three categories of conduct are misdemeanors punishable by fines up to $5,000: an agency employee who willfully discloses personal information to an unauthorized recipient; an employee who willfully maintains a system of records without publishing the required SORN; and anyone who knowingly obtains records from an agency under false pretenses, whether or not they work for the government.9United States Department of Justice. Overview of the Privacy Act – 2020 Edition – Criminal Penalties Those penalties are why the notice framework holds together: the whole system collapses if agencies can maintain secret databases, and Congress attached personal criminal consequences to make sure they don’t.