HOI33-19 — Privacy Act Program Roles And Responsibilities

HOI33-19 governs privacy program roles, responsibilities, procedures, and training for the Headquarters Air Force Privacy Program.

Search HOI33-19

  • Publication number: HOI33-19
  • Title: PRIVACY ACT PROGRAM ROLES AND RESPONSIBILITIES
  • Date: 2026-01-10

View HOI33-19 on armypubs.army.mil


HOI33-19 addresses Personally Identifiable Information collection, maintenance, use, dissemination, and protection of privacy rights. It requires compliance with privacy practices and establishes procedures for reporting and investigating PII breaches.

Applies to: This instruction applies to all civilian employees, military members, and contractors assigned to the HAF (Secretariat, Air Staff, Space Staff, their FOAs and AF elements).

Topics covered

  • Personally Identifiable Information
  • Privacy Act objectives
  • Privacy program roles
  • PII breach reporting
  • PII breach inquiries
  • Privacy training

Questions and answers

What does the HAF Privacy Program ensure?

The HAF Privacy Program ensures the collection, maintenance, use, and dissemination of Personally Identifiable Information (PII) about individuals and the protection of individuals’ rights against invasion of personal privacy is conducted in accordance with (IAW) the Privacy Act of 1974, 5 U.S.C. § 552a, Records Maintained on Individuals, and DoD policies, such as DoDI 5400.11, DoD Privacy and Civil Liberties Programs, and DoD 5400.11-R, Department of Defense Privacy Program. (paragraph 1)

What privacy requirements apply to Air Force personnel?

All Air Force military, civilian, and contractor personnel are to comply with the requirements and practices governing the collection, maintenance, use, and dissemination of PII maintained by Federal agencies IAW the E-Government Act of 2002, Pub. L. 107-347, 44 U.S.C. § 101and Privacy Act of 1974, as appropriate. (paragraph 1)

Who reports PII breaches directly to the SAF/AAI Privacy Office?

Unit Privacy Managers or Monitors assigned to para 2.2.2 will obtain a tracking number from and will report PII breaches directly to the SAF/AAI Privacy Office. (paragraph 33-332)

Through which channels should a PII breach or unauthorized disclosure be reported?

A PII breach and/or an unauthorized disclosure should be reported through Privacy channels as well as CUI channels. (paragraph 33-332)

Who may appoint an investigating official for a major PII incident?

Senior leaders may appoint in writing an investigating official (IO) for unique or major PII incidents IAW AFI 33-332. (paragraph 33-332)

Ask Reggie.Bot a question about HOI33-19