916ARWVA33-3321 — PII Breach Factors and Risk Determinations

916ARWVA33-3321 governs protection, encryption, and handling requirements for PII breach factors and risk determinations.

Search 916ARWVA33-3321

  • Publication number: 916ARWVA33-3321
  • Title: PII Breach Factors and Risk Determinations
  • Date: 2014-03-06

View 916ARWVA33-3321 on armypubs.army.mil


It identifies privacy factors and assigns low, moderate, or high risk determinations. It requires digital signatures, encryption, a “FOUO” subject line, and a prescribed statement for messages containing listed PII factors.

Topics covered

  • PII breach factors
  • Risk determinations
  • Commercial email restrictions
  • Safe Access File Exchange
  • Digital signatures
  • Privacy Act Statements

Questions and answers

How must the factors in the PII breach table be protected?

All factors in this table require protection in accordance with AFI 33-332. (paragraph 1)

Can PII factors be sent to commercial email addresses?

No factors will be e-mailed to or from commercial e-mail addresses (1.1.11.4) and all require encryption, digital signatures and Privacy Act Statements (found on the bottom of this table). (paragraph 33-332)

What should happen if information is not listed in the PII factor table?

If there are questions regarding information not listed in this table, contact your Privacy Office at DSN 722-7530 or 916.Privacy@us.af.mil before sending. (paragraph 33-332)

Ask Reggie.Bot a question about 916ARWVA33-3321