SalesforceCRMPrivacyImpactAssessment(PIA)
UNITEDSTATESAGENCYFORINTERNATIONALDEVELOPMENT
OfficeoftheChiefInformationOfficer(M/CIO)
InformationAssuranceDivision
AppO&MITIS/SalesforceCRM
ApprovedDate:May20,2015
AdditionalPrivacyComplianceDocumentationRequired:
None
SystemofRecordsNotice(SORN)
OpenDataPrivacyAnalysis(ODPA)
PrivacyActSection(e)(3)StatementorNotice(PANotice)
USAIDWebSitePrivacyPolicy
PrivacyProtectionLanguageinContractsandOtherAcquisitionRelatedDocuments
RoleBasedPrivacyTrainingConfirmation
PossibleAdditionalComplianceDocumentationRequired:
USAIDFormsManagement.
ADS505
InformationCollectionRequest(ICR).ADS505,ADS506,andADS508PrivacyProgram
RecordsScheduleApprovedbytheNationalArchivesandRecordsAdministration.ADS502
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
ii
TableofContents
1 Introduction.............................................................................................................................................1
2 Information..............................................................................................................................................1
2.1 ProgramandSystemInformation.......................................................................................1
2.2 InformationCollection,Use,Maintenance,and Dissemination .........................................3
3 PrivacyRisksandControls................................................................................................................6
3.1 AuthorityandPurpose(AP)................................................................................................6
3.2 Accountability,Audit,andRiskManagement(AR).............................................................7
3.3 DataQualityandIntegrity(DI)............................................................................................7
3.4 DataMinimizationand Retention(DM).............................................................................8
3.5 IndividualParticipationandRedress(IP)............................................................................9
3.7 Transparency(TR)...............................................................................................................9
3.8 UseLimitation(UL)...........................................................................................................
10
3.9 ThirdPartyWebSitesandApplications...........................................................................10
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
1
1 Introduction
TheUSAIDPrivacyOfficeisusingthisPrivacyImpactAssessment(PIA)Templatetogatherinformation
fromprogrammanagers,systemowners,andinformationsystemsecurityofficersinordertoanalyze
USAIDinformationtechnologyandinformationcollections (systems)thatcollect,use,maintain,or
disseminatepersonallyidentifiableinf ormation(PII).See
ADS508PrivacyProgramSection503.3.5.2
PrivacyImpactAssessments.
2 Information
2.1 ProgramandSystemInformation
2.1.1 DescribethePROGRAManditsPURPOSE.
SalesforceCRMenablesanalysisand reportingthathelpsthepublicengagementteamdevelopstrategiesand
providestrategicsupporttoUSAID’smanyrelationshipsandinteractionswithoutsidegroups.Inaddition,data
willbeusedtoreporttotheAdministratorandFrontOfficeonthebreadthanddepthofengagement.Itwillbe
usedtocoordinaterelationshipmanagementandtrackengagementinformationbybureau,byissue,andbytype
ofpartnerforavarietyofpurposes.SalesforceCRMisaninvaluableresourceforAgencystaffasitprovidesone
clickaccesstofundinginformation,engagementhistory,andinformationmanagement.
2.1.2 DescribetheSYSTEManditsPURPOSE.
TherearetwoapplicationswithinSalesforceCRM:NGOPartnerOutreachandUSAIDPartnershipTracking.
CFBCI,LPA,OTS,BureaususeNGOPartnerOutreachasarepositoryforgrantdataandcountriesofoperationsfor
theirvariouspartnersandgrantees,thusmakingiteasierforUSAIDtotrackandreport.NGOPartnerOutreach
surroundsitselfaroundthe"Engagements"customobject,whichwascreatedforthepurposetrackingexternal
meetingswithUSAIDstakeholdersandpartnersoranyinternalmeetingsthatinvolvethesame.
USAIDPartnershipTrackingapplicationtracksthestatusofpartnershipactivitiesandservicesfortheCTPU.S.
GlobalDevelopmentLabandMobile
Solutionsdepartment.
2.1.3 WhatistheSYSTEMSTATUS?
NewSystemDevelopmentorProcurement
PilotProjectforNewSystemDevelopmentorProcurement
ExistingSystemBeingUpdated
ExistingInformationCollectionFormorSurvey
OMBControlNumber:
NewInformationCollectionFormorSurvey
RequestforDatasettobePublishedonanExternalWebsite
Other:
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
2
2.1.4 WhattypesofINFORMATIONFORMATSareinvolvedwiththeprogram?
Physicalonly
Electroniconly
Physicalandelectroniccombined
2.1.5 Doesyourprogram participateinPUBLICENGAGEMENT?
No.
Yes:
InformationCollectionFormsorSurveys
ThirdPartyWebSiteorApplication
CollaborationTool
2.1.6 Whattypeofsystemand/orTECHNOLOGYisinvolved?
InfrastructureSystem(LocalAreaNetwork,WideAreaNetwork,GeneralSupportSystem,etc.)
Network
Database
Software
Hardware
MobileApplicationorPlatform
MobileDeviceHardware(cameras,microphones,etc.)
QuickResponse(QR)Code(matrixgeometricbarcodesscannedbymobiledevices)
WirelessNetwork
SocialMedia
WebSiteorApplicationUsedforCollaborationwiththePublic
AdvertisingPlatform
WebsiteorWebserver
WebApplication
ThirdPartyWebsiteorApplication
Geotagging(locationaldataembeddedinphotosandvideos)
NearFieldCommunications(NFC)(wirelesscommunicationwheremobiledevicesconnectwithoutcontact)
AugmentedRealityDevices(wearablecomputers,suchasglassesormobiledevices,thataugmentperception)
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
3
2.1.6 Whattypeofsystemand/orTECHNOLOGYisinvolved?
FacialRecognition
IdentityAuthenticationandManagement
SmartGrid
BiometricDevices
BringYourOwnDevice(BYOD)
Remote,SharedDataStorageandProcessing(cloudcomputingservices)
Other:
None
2.1.7 Aboutwhattypesofpeopledoyoucollect,use,maintain,ordisseminate
personalinformation?
CitizensoftheUnitedStates
AlienslawfullyadmittedtotheUnitedStatesforpermanentresidence
USAIDemployeesandpersonalservicescontractors
EmployeesofUSAIDcontractorsand/orservicesproviders
Aliens
BusinessOwnersorExecutives
Others:
None
2.2 InformationCollection,Use,Maintenance,andDissemination
2.2.1 Whattypesofpersonalinformationdoyoucollect,use,maintain,or
disseminate?
Name,FormerName,orAlias
Mother’sMaidenName
SocialSecurityNumberorTruncatedSSN
DateofBirth
PlaceofBirth
HomeAddress
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
4
2.2.1 Whattypesofpersonalinformationdoyoucollect,use,maintain,or
disseminate?
HomePhoneNumber
PersonalCellPhoneNumber
PersonalEMailAddress
WorkPhoneNumber
WorkEMailAddress
Driver’sLicenseNumber
PassportNumberorGreenCardNumber
EmployeeNumberorOtherEmployeeIdentifier
TaxIdentificationNumber
CreditCardNumberorOtherFinancialAccountNumber
PatientIdentificationNumber
EmploymentorSalaryRecord
MedicalRecord
CriminalRecord
MilitaryRecord
FinancialRecord
EducationRecord
BiometricRecord(signature,fingerprint,photo,voiceprint,physicalmovement,DNAmarker,retinalscan,etc.)
SexorGender
Age
OtherPhysicalCharacteristic(eyecolor,haircolor,height,tattoo)
SexualOrientation
MaritalstatusorFamilyInformation
RaceorEthnicity
Religion
Citizenship
Other:
NoPIIiscollected,used,maintained,ordisseminated
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
5
2.2.2 Whattypesofdigitalormobiledatadoyoucollect,use,maintain,or
disseminate?
LogData(IPaddress,time,date,referrersite,browsertype)
TrackingData(single‐ormultisessioncookies,beacons)
FormData
UserNames
Passwords
UniqueDeviceIdentifier
LocationorGPSData
CameraControls(photo,video,videoconference)
MicrophoneControls
OtherHardwareorSoftwareControls
PhotoData
AudioorSoundData
OtherDeviceSensorControlsorData
On/OffStatusandControls
CellTowerRecords(logs,userlocation,time,date)
DataCollectedbyApps(itemize)
ContactListandDirectories
BiometricDataorRelatedData
SDCardorOtherStoredData
NetworkStatus
NetworkCommunicationsData
DeviceSettingsorPreferences(security,sharing,status)
Other:
None
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
6
2.2.4 Whoownsand/orcontrolsthesysteminvolved?
USAIDOffice:
AnotherFederalAgency:
Contractor:
CloudComputingServicesProvider:
ThirdPartyWebsiteorApplicationServicesProvider:
MobileServicesProvider:
DigitalCollaborationToolsorServicesProvider:
Other:
3 PrivacyRisksandControls
3.1 AuthorityandPurpose(AP)
3.1.1 WhatarethestatutesorotherLEGALAUTHORITIESthatpermityoutocollect,
use,maintain,ordisseminatepersonalinformation?
3.1.2 WhyisthePIIcollectedandhowdoyouuseit?
WithinSalesforceCRMaNGOPartnerOutreachoraUSAIDPartnershipTrackingusermaycollectcontact
informationfrominternalorexternalpartnersorUSAlDstakeholdersthatwouldotherwisebecategorizedas
"sensitivebutunclassified.”Thisincludesstatusessuchas"CEOorVP"ofexternalbusinesses.Thecontact
informationiscollected
totrackpointsofcontactforvariouspartneractivitiesorstatusesandalsoobtainreports
onmeetingsthataretrackedbytheFrontOffice.BureaussuchasLPAmaycollectPlldatatocompilemailinglists
tolatersendinvitesforUSAIDeventsandcollecttheresultsofthosewho
attended.
USAIDPartnershipTrackingusersmaycollectPllinformationofstaffrequeststhataremadetosupportamission
activity,suchastraining.Also,contactinformationforpointofcontactsofthosewithinthemissionsor
participatingpartnerstousewhenneeded.
3.1.3 HowwillyouidentifyandevaluateanypossiblenewusesofthePII?
NewusesforPIIinformationwillbeevaluatedateachbureaulevel.
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
7
3.2 Accountability,Audit,andRiskManagement(AR)
3.2.1 Doyouuseanydatacollectionformsorsurveys?
No:
Yes:
FormorSurvey(Pleaseattach)
OMBNumber,ifapplicable:
PrivacyActStatement(PleaseprovidelinkorattachPAStatement)
3.2.3 Whoownsand/orcontrolsthepersonalinformation?
USAIDOffice:
AnotherFederalAgency:
Contractor:
CloudComputingServicesProvider:
ThirdPartyWebServicesProvider:
MobileServicesProvider:
DigitalCollaborationToolsorServicesProvider:
Other:
3.2.8 DoyoucollectPIIforanexclusivelystatisticalpurpose?Ifyoudo,howdoyou
ensurethatthePIIisnotdisclosedorusedinappropriately?
No.
Yes:
3.3 DataQualityandIntegrity(DI)
3.3.1 HowdoyouensurethatyoucollectPIItothegreatestextentpossibledirectly
fromthesubjectindividual?
EachSalesforceuserisresponsibleforupdatingandmaintainingtheirdatatothehighestextent.Userprofilesand
groupshavebeencreatedtocontroltheaccessandinformationthatisbeinginputtedbyeachindividual.Onlythe
systemadministratorhasaccesstoalldataandsettings.
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
8
3.3.2 Howdoyouensure,tothegreatestextentpossible,thatthePIIisaccurate,
relevant,timely,andcompleteatthetimeofcollection?
EachSalesforceuserisresponsibleforupdatingandmaintainingtheirdataascurrentaspossible.TheSalesforce
systemadministratorperformsdatacheckandsystemcleanuponamonthlybasis.TheSalesforcesystem
administratoralsomonitorsthesystemhealthcheckandsystemstatusattrust.salesforce.com.
3.3.3 Howdoyoucheckfor,andcorrectasnecessary,anyinaccurateoroutdatedPII
inthesystem?
TheSalesforcesystemadministrator willworkwitheachbureaupointofcontacttoimporttheircontact
informationandcollectupdatesviadataloader.
3.4 DataMinimizationandRetention(DM)
3.4.1 WhatistheminimumPIIrelevantandnecessarytoaccomplishthelegal
purposeoftheprogram?
SalesforceCRMmaycollect contactinformation such as first name, last name, work address,workemail address o
ranyphonenumbersassociatedwiththeindividual.Thisinformationisneededtocommunicatewithpartnersand
USAIDStakeholdersthatperformpaitneractivitiesandtocapturemeetinginformation.Surveydatamayaldobec
ollectedtoanalyzepotentialcustomersand
pattnershipswithUSAID.IfthiscontactinformationisnotaccessibleU
SAIDmaynotbeabletotrackpointsofcontactandreachouttoit'scustomersorpartners.
3.4.3 Doesthesystemderivenewdataorcreatepreviouslyunavailabledataabout
anindividualthroughaggregationorderivationoftheinformationcollected?
IsthePIIrelevantandnecessarytothespecifiedpurposesandhowisit
maintained?
No.
Yes:
3.4.4 Whattypesofreportsaboutindividualscanyouproducefromthesystem?
Salesforceusersareabletogenerateandcreatereportsbytypesuchastabularreport,summaryreport, ormatrix
report.Usersareabletoanalyzethedataandcontrolaccess.
3.4.6 Doesthesystemmonitorortrackindividuals?
(IfyouchooseYes,pleaseexplainthemonitoringcapability.)
No.
Yes:
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
9
3.5 IndividualParticipationandRedress(IP)
3.5.1 Doyoucontactindividualstoallowthemtoconsenttoyourcollectionand
sharingofPII?
CollectionofPIIinformationisvoluntaryandcollectedthroughsurveys,RSVPs,research,ormeetingswithpartners
orprospectivecustomers.
3.5.2 Whatmechanismdoyouprovideforanindividualtogainaccesstoand/orto
amendthePIIpertainingtothatindividual?
Salesforceusermustbearegistereduserinordertoaccessdatainthesystem.
3.5.3 IfyoursysteminvolvescloudcomputingservicesandthePIIislocatedoutside
ofUSAID,howdoyouensurethatthePIIwillbeavailabletoindividualswho
requestaccesstoandamendmentoftheirPII?
ThereisnodatacollectedoutsideofUSAID.
3.7 Transparency(TR)
3.7.1 Doyouretrieveinformationbypersonalidentifiers,suchasnameornumber?
(IfyouchooseYes,pleaseprovidethetypesofpersonalidentifiersthatareused.)
No.
Yes:
3.7.2 Howdoyouprovidenoticetoindividualsregarding?
1)TheauthoritytocollectPII:
2)TheprincipalpurposesforwhichthePIIwillbeused:
3)TheroutineusesofthePII:
4)Theeffectsontheindividual,ifany,ofnotprovidingalloranypartofthePII:
SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
10
3.7.3 IsthereaPrivacyActSystemofRecordsNotice(SORN)thatcoversthis
system?
No
Yes:
3.7.4 Ifyoursysteminvolvescloudcomputingservices,howdoyouensurethatyou
knowthelocationofthePIIandthattheSORNSystemLocation(s)section
providesappropriatenoticeofthePIIlocation?
Salesforce.comdoesnothaveaccesstoNA21instance.Salesforcemustrequestaccesstothesystem.
3.8 UseLimitation(UL)
3.8.1 WhohasaccesstothePIIatUSAID?
TherearethirtySalesforceusersthatcanaccessthesystem.FourteenfromCTPbureau,sevenfromCFBCI,five
fromLPA,threefromM/CIO.Eachbureauhasaspecificprofilethatisassignedtoitallowingaccesstothat
bureau’sdata.OncetheSalesforceuseracquiresauserlicenseandisregistered,
theuserwillbeabletoaccess
datathatisallowedfortheuser’sspecificgroup.
3.8.3 WithwhomdoyousharethePIIoutsideofUSAID?Andwhether(andhow,if
applicable)youwillbeusingthesystemorrelatedwebsiteorapplicationto
engagewiththepublic?
SalesforceCRMneithersharesinformationoutsideofUSAIDnordoesitengagethepublicinanyway.
3.8.4 DoyousharePIIoutsideofUSAID?
Ifso,howdoyouensuretheprotectionofthePII1)asitmovesfromUSAIDto
theoutsideentityand2)whenitisused,maintained,ordisseminatedbythe
outsideentity?
No.
Yes:
3.9 ThirdPartyWebSitesandApplications
3.9.1 WhatPIIcouldbemadeavailable(eventhoughnotrequested)toUSAIDorits
contractorsandserviceproviderswhenengagingwiththepublic?
SalesforceCRMneithersharesinformationoutsideofUSAIDnordoesitengagethepublicinanyway.

SalesforcePrivacyImpactAssessment
DateApproved:May20,2015
11
AppendixA. LinksandArtifacts
PrivacyComplianceDocumentsorLinks
A.1
None.TherearenodocumentsorlinksthatIneedtoprovide.
PrivacyThresholdAnalysis(PTA)
PrivacyImpactAssessment(PIA)
SystemofRecordsNotice(SORN)
OpenDataPrivacyAnalysisforPostingDatasetstothePublic(ODPA)
DataCollectionFormsorSurveys
PrivacyActSection(e)(3)StatementsorNotices
USAIDWebSitePrivacyPolicy
PrivacyPolicyofThirdPartyWebSiteorApplication
PrivacyProtectionLanguageinContractsandOtherAcquisitionRelatedDocuments