Disclosing Federal Records Under the Privacy Act
How the Privacy Act of 1974 governs disclosures of federal records to third parties, including key exceptions, safeguards, and compliance duties.

The Privacy Act of 1974 is the primary U.S. federal law that governs how agencies collect, use, and share records containing personally identifiable information about individuals. A central feature of the statute is its rule that agencies generally may not disclose records to third parties without the individual’s consent, subject to defined exceptions in the law.
This article explains how the Privacy Act regulates disclosure of records to third parties, what the main exceptions are, and what obligations federal agencies must meet when they share information outside the agency. It is intended as an accessible guide for lawyers, compliance professionals, privacy officers, and individuals seeking to understand their rights.
Core Disclosure Rule Under the Privacy Act
The starting point for any disclosure analysis under the Privacy Act is the statutory prohibition found in 5 U.S.C. § 552a(b). That provision states, in substance, that:
- No agency may disclose a record from a system of records by any means of communication to any person or another agency
- Unless the disclosure is made pursuant to a written request by, or with the prior written consent of, the individual to whom the record pertains
- Or the disclosure qualifies under one of the specific exceptions listed in § 552a(b)(1)–(12)
A system of records is a group of records under the control of a federal agency from which information is retrieved by the name or other personal identifier assigned to an individual. If a disclosure does not involve such a system, or the information cannot reasonably identify an individual, the Privacy Act may not apply.
Relationship to Individual Consent
As a general matter, the Privacy Act favors individual control: agencies must obtain written consent before disclosing personally identifiable information, except where Congress has recognized specific situations in which disclosure is necessary for government operations or public interests. This consent requirement aligns with broader fair information practice principles, such as transparency and respect for individual autonomy.
Key Exceptions Allowing Disclosure Without Consent
Although the Privacy Act starts from a rule of non‑disclosure, it also recognizes that government cannot function if it can never share information. Section 552a(b) therefore contains a series of exceptions that authorize the use or disclosure of records without consent in defined circumstances.
Below is an overview of the most significant categories of exceptions commonly relied on by federal agencies.
Internal Agency Access: The “Need to Know” Exception
The first exception permits disclosure to officers and employees of the agency who need access to the record in the performance of their duties. This is often referred to as the “need to know” exception.
- Applies only to personnel of the same agency that maintains the records
- Requires that access be reasonably necessary to perform official job responsibilities
- Does not authorize indiscriminate or curiosity‑based access
Agencies typically implement this exception through role‑based access controls, training, and internal policies that limit who may view which types of records.
Freedom of Information Act (FOIA) Interactions
Another important exception covers disclosures required under the Freedom of Information Act (FOIA). If a FOIA request seeks records that are not protected by any FOIA exemption, the agency may be obliged to release those records even though they are part of a Privacy Act system of records.
The relationship between FOIA and the Privacy Act can be complex:
- FOIA generally favors disclosure of government records, subject to exemptions
- The Privacy Act restricts disclosure of personal information, subject to exceptions
- Agencies must analyze both statutes together to determine whether release is permitted or required
Some personal information will be withheld under FOIA exemptions (such as those for personal privacy), which in turn supports nondisclosure under the Privacy Act.
Routine Use Disclosures
One of the most frequently used exceptions is the “routine use” provision, which allows agencies to disclose records for purposes that are compatible with the purpose for which the information was originally collected.
For a disclosure to qualify as a routine use:
- The purpose of the disclosure must be compatible with the original collection purpose
- The routine use must be described in a published system of records notice (SORN) in the Federal Register
- Members of the public must have an opportunity to review and comment on that SORN
Routine uses are important because they allow agencies to share information with other entities (including other agencies and sometimes contractors) to carry out administrative functions, investigations, program integrity activities, and similar tasks without obtaining consent each time.
Disclosures for Census and Statistical Purposes
The Privacy Act expressly authorizes disclosures to the Census Bureau for planning or conducting censuses, surveys, or related activities. It also permits disclosures for statistical research or reporting so long as the data is used only for those purposes and does not identify specific individuals.
- Recipients must usually provide written assurances that data will be used solely for statistical purposes
- Identifying information must either be removed or robustly protected
- Results should be reported in aggregate form to avoid re‑identification
These exceptions support important public functions such as demographic research, program evaluation, and evidence‑based policymaking.
National Archives and Records Administration (NARA)
The Act allows records to be transferred to the National Archives and Records Administration (NARA) when they have sufficient historical or other value to warrant permanent preservation. NARA may process and store records as part of its statutory duties, subject to its own privacy and access frameworks.
Law Enforcement Disclosures
Section 552a(b) also contains an exception for disclosures to another agency or governmental instrumentality for a civil or criminal law enforcement activity, when certain conditions are met.
- The law enforcement activity must be authorized by law
- The requesting entity must submit a written request describing the specific records sought and the associated law enforcement purpose
- The disclosure should be limited to information reasonably relevant to that activity
This exception enables cooperation among agencies in investigations, prosecutions, and regulatory enforcement, while still imposing procedural safeguards on the flow of personal data.
Compelling Health or Safety Circumstances
To address emergency and safety concerns, the Privacy Act permits disclosure when there are compelling circumstances affecting the health or safety of any individual. For instance, an agency might disclose contact information to first responders in an emergency situation.
When using this exception:
- Agencies must ensure that circumstances are genuinely compelling and relate to health or safety
- The disclosure should be narrowly tailored to the emergency need
- The agency must send notification to the individual’s last known address informing them of the disclosure
Congressional and Oversight Disclosures
Certain exceptions support democratic oversight by allowing disclosures to Congress and to the Government Accountability Office (GAO).
- Records may be disclosed to either House of Congress, or committees and subcommittees, when within their jurisdiction
- Records may be provided to the Comptroller General and authorized GAO representatives in the course of performing GAO’s audit and evaluation functions
These exceptions ensure that legislative bodies and oversight entities can obtain necessary information while carrying out their constitutional and statutory roles.
Court Orders and Debt Collection
The Act authorizes disclosures pursuant to a court order issued by a court of competent jurisdiction. Agencies must carefully review such orders to confirm their validity and scope before releasing records.
Another exception permits disclosures to consumer reporting agencies in connection with certain federal debt collection activities as described in Title 31 of the U.S. Code. This allows agencies to enforce financial obligations, such as unpaid federal loans or fines, using standard credit reporting mechanisms.
Illustrative Table of Major Exceptions
| Exception Category | Typical Recipient | Primary Purpose |
|---|---|---|
| Need to know | Agency employees | Internal use to perform official duties |
| FOIA‑related | Members of the public | Compliance with FOIA when no exemption applies |
| Routine use | Other agencies, contractors, partners | Operational needs compatible with original collection |
| Census & statistics | Census Bureau, researchers | Statistical research and reporting without identifying individuals |
| Law enforcement | Investigative and enforcement agencies | Civil or criminal law enforcement activities authorized by law |
| Health or safety | Emergency responders, relevant parties | Address compelling circumstances affecting health or safety |
Record‑Keeping and Accountability Requirements
The Privacy Act does more than define when information may be shared; it also imposes record‑keeping obligations designed to promote transparency and accountability.
Accounting of Disclosures
Agencies must generally keep an accounting of certain disclosures made from systems of records, including disclosures to third parties under routine uses and other exceptions.
- Each accounting entry typically records the date, nature, and purpose of the disclosure
- It includes the name and address of the person or agency to whom the disclosure was made
- The accounting must be retained for a specified period, often at least five years or the life of the record
Individuals have the right to request an accounting of disclosures pertaining to their own records, subject to certain limitations (such as ongoing law enforcement investigations).
Publication of Systems of Records Notices
To prevent secret databases, agencies must publish notices describing each system of records in the Federal Register. These notices include information about the categories of individuals and records, routine uses, and procedures for individuals to access or amend their records.
Publication serves several purposes:
- Informs the public that a system exists
- Describes how information is used and to whom it may be disclosed
- Allows interested persons to submit comments or concerns
Individual Rights to Access and Amendment
Beyond disclosure rules, the Privacy Act gives individuals the right to access and correct records about themselves maintained by federal agencies. Agencies must provide procedures for individuals to request access or amendments and must respond within reasonable timeframes.
Requests commonly include:
- Verification of identity to ensure that information is released only to the proper person
- Sufficient detail to locate the relevant records
- Explanation of why a record is claimed to be inaccurate, untimely, incomplete, or irrelevant, along with supporting documentation
These rights help mitigate harm from erroneous or outdated information and reinforce the principle that individuals should have meaningful influence over records that describe them.
Penalties for Unlawful Disclosures
The Privacy Act includes civil remedies and potential criminal penalties for violations. For example, an officer or employee who knowingly and willfully discloses information in violation of the Act may be subject to criminal liability. Individuals harmed by intentional or willful violations may also seek damages in certain circumstances.
Best Practices for Agencies Handling Third‑Party Disclosures
To comply with the Privacy Act while maintaining effective operations, agencies should adopt robust practices around third‑party disclosures. Common strategies include:
- Data minimization: Disclose only the information reasonably necessary for the identified purpose
- Formal agreements: Use written agreements or memoranda of understanding when sharing data with other entities, particularly for statistical research and routine uses
- Training: Educate employees about the consent requirement, exceptions, and consequences of unauthorized disclosures
- Access controls: Implement technical and administrative controls limiting who can access systems of records
- Documentation: Maintain detailed accountings of disclosures and periodically review them for compliance trends
Frequently Asked Questions (FAQs)
1. Does the Privacy Act apply to all personal information held by the federal government?
No. The Privacy Act applies specifically to information contained in a system of records that is retrieved by personal identifiers such as a name or Social Security number. Some records that are not part of a system, or cannot reasonably identify an individual, may fall outside the statute.
2. Can agencies always rely on FOIA to disclose personal information?
No. FOIA and the Privacy Act must be read together. If a FOIA exemption applies—such as one protecting personal privacy—agencies may withhold the information, and the Privacy Act’s disclosure prohibition remains in effect.
3. What is a routine use and why does it matter?
A routine use is a disclosure of a record for a purpose compatible with the purpose for which the information was collected, and which is described in a published system of records notice. Routine uses are critical because they enable many day‑to‑day data flows within and among agencies without requiring individualized consent.
4. How can an individual find out who has received their records?
Individuals may request an accounting of disclosures from the agency that maintains the relevant system of records. Subject to certain limitations, the agency must provide information about when and to whom it has disclosed the individual’s records.
5. Are there special rules for disclosures for research purposes?
Yes. When records are disclosed for statistical research or reporting, recipients must typically agree in writing to use the data only for those purposes and to protect against identification of individuals. This ensures that privacy risks are minimized even when data is being analyzed at scale.
References
- Privacy Act of 1974 — U.S. Department of Justice. 2020-01-01. https://www.justice.gov/opcl/privacy-act-1974
- The Privacy Act of 1974: Overview and Issues for Congress — Congressional Research Service. 2024-01-31. https://www.everycrsreport.com/reports/R47863.html
- What Government Agencies Need to Know for Privacy Act 1974 — BigID. 2022-06-15. https://bigid.com/blog/what-government-agencies-need-to-know-for-privacy-act-1974/
- A Privacy Act Primer — Actionable Intelligence for Social Policy, University of Pennsylvania. 2025-06-01. https://aisp.upenn.edu/wp-content/uploads/2025/06/A-Privacy-Act-Primer_6.20-1.pdf
- Privacy Act of 1974, 5 U.S.C. § 552a — Bureau of Justice Assistance, U.S. Department of Justice. 2017-01-01. https://bja.ojp.gov/program/it/privacy-civil-liberties/authorities/statutes/1279
- Privacy Act Exceptions — Department of the Air Force. 2019-05-01. https://www.privacy.af.mil/Home/Privacy-Act-Exceptions/
- Privacy Act Requests — U.S. Department of the Interior. 2022-03-01. https://www.doi.gov/privacy/privacy-act-requests
Read full bio of Sneha Tete








