AFI33-332_TYNDALLAFBSUP — Air Force Privacy And Civil Liberties Program

AFI33-332_TYNDALLAFBSUP governs Tyndall AFB privacy and civil liberties requirements, including PII protection and breach reporting.

Search AFI33-332_TYNDALLAFBSUP

  • Publication number: AFI33-332_TYNDALLAFBSUP
  • Title: AIR FORCE PRIVACY AND CIVIL LIBERTIES PROGRAM
  • Date: 2023-07-14

View AFI33-332_TYNDALLAFBSUP on armypubs.army.mil


The publication establishes Tyndall privacy manager and unit privacy monitor appointments, incident reporting, monthly scans, and training requirements. It also addresses protection of unprotected PII on SharePoint sites and shared drives.

Applies to: It applies to all units and tenants on Tyndall AFB.

Topics covered

  • Privacy violation reporting
  • Civil liberties issues
  • Personally identifiable information protection
  • Privacy manager appointments
  • Unit Privacy Monitor training
  • SharePoint site scans
  • Shared drive scans
  • PII breach reporting

Questions and answers

How quickly must privacy violations, complaints, and breaches be reported?

All Privacy Violations, complaints and breaches will be reported by the Unit Privacy Monitor, or individual discovering the incident, to the Tyndall AFB Privacy Manager within one hour of discovery of the violation, complaint or breach by email to 325cs.scok.tyndallprivacy@us.af.mil.

What must the Tyndall AFB Privacy Manager do after being notified of a privacy incident?

The Tyndall AFB Privacy Manager will verify reported Privacy violations, complaints or breaches, and notify the Wing Commander in addition to the Group Commander or senior official (O-6/GS15, or higher) of the organization where the incident occurred with the details of the incident within 24 hours of being notified.

How often must organizational SharePoint sites and shared drives be scanned for unprotected PII?

Organizational SharePoint® site owners, Site Collection Administrators, and Unit Cybersecurity Liaisons will perform a monthly scan of SharePoint® sites and Shared Drives within their organizations.

What happens when unprotected PII is found during a scan?

If unprotected PII data is discovered during the scan, delete and/or safeguard the PII to ensure only authorized personnel have access and follow instructions outlined in paragraph 2.8.3 and Chapter 3 of this AFI.

When must Unit Privacy Monitor training be completed?

Complete Unit Privacy Monitor training, provided by the Tyndall AFB Privacy Manager within 10 duty days of appointment.

Ask Reggie.Bot a question about AFI33-332_TYNDALLAFBSUP