MCO 5211.5 governs the United States Marine Corps Privacy Program, including responsibilities for protecting PII and reporting breaches.
View MCO 5211.5 on armypubs.army.mil
It establishes Privacy Coordinators, Privacy Points of Contact, and a Breach Reporting Officer, and assigns duties for program execution. It addresses Privacy Act requests and complaints, privacy impact assessments, system of records notices, training, and PII breach procedures.
Information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other information that is linked or linkable to a specific individual, including but not limited to: name, date of birth, SSN (or any portion thereof), EDIPI/DoD ID number, biometrics, photograph, address, telephone number, e-mail address, mother’s maiden name, etc. (paragraph 7)
A loss or suspected loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar term referring to situations where persons other than authorized users have access or potential access (whether physical or electronic) to PII, and/or where PII is accessed for an unauthorized purpose. (paragraph 8)
A written analysis to ensure PII in an IT system is collected, stored, protected, used, shared, and managed in a manner that protects privacy and conforms to applicable legal, regulatory, and policy requirements.
Any group of records where a record is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual. (The key is that the record contains PII and is retrieved by PII.) (paragraph 9)
Maintains a list of the Marine Corps Privacy Coordinators and POCs, to include name, command, and contact information (work email address and phone number). (paragraph 4)