812 - Protected Information.pdf
Extracted text (via pymupdf)
8125 characters
Policy Buckeye Police Department 812 Policy Manual _____________________________________________________________________________ _________________________________________________________________________________________________________ Issued Date: 05/04/2015 Protected Information Revised Date: 01/06/2025 PROTECTED INFORMATION 812.1 PURPOSE AND SCOPE The purpose of this policy is to provide guidelines for the access, transmission, release, and security of protected information by members of the Buckeye Police Department. This policy addresses the protected information that is used in the day-to-day operation of the department and not the public records information covered in the Records Release and Security Policy. 812.1.1 DEFINITIONS Protected information - Any information or data that is collected, stored, or accessed by members of the Buckeye Police Department and is subject to any access or release restrictions imposed by law, regulation, order or use agreement. This includes all information contained in federal, state, or local law enforcement databases that is not accessible to the public. 812.2 POLICY Members of the Buckeye Police Department will adhere to all applicable laws, orders, regulations, use agreements and training related to the access, use, dissemination, and release of protected information. 812.3 RESPONSIBILITIES I. The Support Services Manager shall be responsible to coordinate the use of protected information including, but not limited to: A. Ensuring member compliance with this policy and with requirements applicable to protected information, including requirements for the National Crime Information Center (NCIC) system, National Law Enforcement Telecommunications System (NLETS), the Arizona Criminal Justice Information System (ACJIS), Arizona Department of Transportation (ADOT) records and Arizona Law Enforcement Telecommunications System (ALETS). B. Developing, disseminating, and maintaining procedures that adopt or comply with the U.S. Department of Justice's current Criminal Justice Information Services (CJIS) Security Policy. C. Developing, disseminating, and maintaining any other procedures necessary to comply with any other requirements for the access, use, dissemination, release, and security of protected information. D. Resolving specific questions that arise regarding authorized recipients of protected information. E. Ensuring security practices and procedures are in place to comply with requirements applicable to protected information. 812.4 ACCESS TO PROTECTED INFORMATION I. Protected information shall not be accessed in violation of any law, order, regulation, user agreement, Buckeye Police Department policy or training. Only those members who have completed applicable training and met any applicable requirements, such as a background check, may access protected information, and only when the member has a legitimate work-related reason for such access. Policy Buckeye Police Department 812 Policy Manual _____________________________________________________________________________ _________________________________________________________________________________________________________ Issued Date: 05/04/2015 Protected Information Revised Date: 01/06/2025 II. Unauthorized access, including access for other than a legitimate work-related purpose, is prohibited and may subject a member to administrative action pursuant to the Personnel Complaints Policy and/or criminal prosecution. 812.5 RELEASE OR DISSEMINATION OF PROTECTED INFORMATION I. Protected information may be released only to authorized recipients who have both a right to know and a need to know. II. A member who is asked to release protected information that should not be released should refer the requesting person to a supervisor or to the Support Services Manager for information regarding a formal request. III. Unless otherwise ordered or when an investigation would be jeopardized, protected information maintained by the department may generally be shared with authorized persons from other law enforcement agencies who are assisting in the investigation or conducting a related investigation. IV. Any such information should be released through the Records Section to ensure proper documentation of the release (see the Records Release and Security Policy). V. Protected information, such as Criminal Justice Information (CJI), which includes Criminal History Records Information (CHRI), will generally not be transmitted by radio, cellular telephone or any other type of wireless transmission to members in the field or in vehicles through any computer or electronic device, except in cases where there is an immediate need for the information to further an investigation or where circumstances reasonably indicate that the immediate safety of officers other department members or the public is at risk. VI. Nothing in this policy is intended to prohibit broadcasting warrant information. 812.6 SECURITY OF PROTECTED INFORMATION I. The Support Services Manager shall be responsible to oversee the security of protected information including, but not limited to: A. Developing and maintaining security practices, procedures, and training. B. Ensuring federal and state compliance with the CJIS Security Policy and the requirements of any state or local criminal history records systems. C. Establishing procedures to provide for the preparation, prevention, detection, analysis, and containment of security incidents including computer attacks. D. Tracking, documenting, and reporting all breach of security incidents to the Chief of Police and appropriate authorities. 812.6.1 EMPLOYEE RESPONSIBILITIES Employees accessing or receiving protected information shall ensure the information is not accessed or received by persons who are not authorized to access or receive it. This includes leaving protected information, such as documents or computer databases, accessible to others when it is reasonably foreseeable that unauthorized access may occur. Policy Buckeye Police Department 812 Policy Manual _____________________________________________________________________________ _________________________________________________________________________________________________________ Issued Date: 05/04/2015 Protected Information Revised Date: 01/06/2025 812.7 OPERATIONAL AUDITS The Buckeye Police Department’s Professional Standards Unit will perform random quarterly audits of 5% of all ACJIS users. The audits will examine all systems each user is authorized to access by the Buckeye Police Department or other government agencies. Users found not in compliance with Agency, State, and Federal guidelines are subject to discipline up to and including termination and criminal prosecution. 812.8 TRAINING All members authorized to access, or release protected information shall complete a training program that complies with any protected information system requirements and identifies authorized access and use of protected information, as well as its proper handling and dissemination. This Order supersedes all previous policies of the BUCKEYE POLICE DEPARTMENT on the above subject. By Order of, Robert Sanders Chief of Police