U.S. Department of Labor Holds Contractors Strictly Accountable for Protecting Personal Data
Summary
The U.S. Department of Labor is holding contractors strictly accountable for protecting Personally Identifiable Information, requiring need-to-know access controls, written approval for removing sensitive data, and immediate reporting of any PII theft or loss to the DOL's cybersecurity response team.
Key Points
- The U.S. Department of Labor defines Personally Identifiable Information (PII) as any data that can distinguish or trace an individual's identity, and holds contractors strictly responsible for safeguarding it at all times.
- DOL policy requires that only individuals with an official 'need to know' can access sensitive records, and written management approval must be obtained before removing any sensitive information from a DOL facility.
- Contractors and employees who discover a theft or loss of PII must immediately notify their DOL contract manager or report the incident directly to the DOL Computer Security Incident Response Capability (CSIRC) team at dolcsirc@dol.gov.