FAACT database audit/use logs
Submitted | Feb. 28, 2022 |
MuckRock users can file, duplicate, track, and share public records requests like this one. Learn more.
Communications
From: Todd Feathers
To Whom It May Concern:
Pursuant to the Virginia Freedom of Information Act, I hereby request the following records:
1) Audit/use logs, since Jan. 1, 2020, documenting each time someone has accessed, queried, uploaded, downloaded, or otherwise used the Virginia Framework for Addiction Analysis and Community Transformation (FAACT) database(s), including, where available, the person's position, the department/organization they work for, the purpose for which the database(s) was used, the date, and any associated criminal case numbers.
Participants in the FAACT program and the Commonwealth Data Trust are required to maintain audit/use logs for transparency and auditing purposes in order to participate in the programs. The Virginia Department of Criminal Justice Services has informed me that ODGA, rather than individual participating agencies, maintains these audit logs.
I ask that all fees be waived as intend to use the requested records to further public understanding of public agencies and not for any commercial purpose. In the event you choose to impose fees, I request a detailed breakdown of the fees, including the hourly wage of each employee involved and an explanation justifying the employee hours required to fulfill the request.
Should you choose to reject this request or redact portions of responsive documents, I ask that you provide a detailed breakdown of the statutory exemptions and associated case law underlying your decision to withhold each/any portions from public review.
The requested documents will be made available to the general public, and this request is not being made for commercial purposes.
In the event that there are fees, I would be grateful if you would inform me of the total charges in advance of fulfilling my request. I would prefer the request filled electronically, by e-mail attachment if available or CD-ROM if not.
Thank you in advance for your anticipated cooperation in this matter. I look forward to receiving your response to this request within 5 business days, as the statute requires.
This request is filed by Tom Nash, a citizen of Virginia, in coordination with Todd Feathers.
From: Virginia Office Of Data Governance And Analytics
Thank you, I have sent this to the ODGA team.
Office of Data Governance and Analytics
Web: odga.virginia.gov
Sign up for the ODGA Newsletter <https://www.cdo.virginia.gov/contact/>
Follow ODGA on LinkedIn
<https://www.linkedin.com/company/office-of-data-governance-analytics/>
Follow ODGA on Twitter <https://twitter.com/VirginiaODGA>
From: Virginia Office Of Data Governance And Analytics
Hi,
The Virginia Office of Data Governance and Analytics has reviewed your
request. Unfortunately, the request cannot be granted because the FOIA
request is for sensitive or unauthorized data. Thank you for submitting
the request.
Office of Data Governance and Analytics
Web: odga.virginia.gov
Sign up for the ODGA Newsletter <https://www.cdo.virginia.gov/contact/>
Follow ODGA on LinkedIn
<https://www.linkedin.com/company/office-of-data-governance-analytics/>
Follow ODGA on Twitter <https://twitter.com/VirginiaODGA>
From: Todd Feathers
Hello,
Thank you very much for your response, but I'd like to ask for a little clarification. Could you please cite the specific exemption to the Virginia Freedom of Information Act you are relying on to withhold these records? Under the law, records cannot be withheld unless they meet one of the enumerated statutory exemptions. Here is the text of the law: https://law.lis.virginia.gov/vacodepopularnames/virginia-freedom-of-information-act/
I'm not sure what you mean by "sensitive or unauthorized data," but there's certainly no statutory exemption that uses that language.
I'd be happy to discuss this request over the phone, if you'd like to set up a time.
Todd
From: Virginia Office Of Data Governance And Analytics
Hi,
The data sharing agreement we have with agencies will not allow us to
release sensitive information. This information is classified as
sensitive. You are welcome to review the Commonwealth’s Data Trust Member
Agreement on our website’s Resources section. Thank you again for the
inquiry.
Thank you,
Office of Data Governance and Analytics
Web: odga.virginia.gov
Sign up for the ODGA Newsletter <https://www.cdo.virginia.gov/contact/>
Follow ODGA on LinkedIn
<https://www.linkedin.com/company/office-of-data-governance-analytics/>
Follow ODGA on Twitter <https://twitter.com/VirginiaODGA>
From: Virginia Office Of Data Governance And Analytics
Good morning,
The Virginia Office of Data Governance and Analytics does not capture and is not required to capture each FAACT database query transaction. Additionally, no single person has the ability to query internal FAACT databases. The information for FAACT is presented to platform users in a dashboard format. We do capture the last time a profile has logged into the reporting platform. The login usernames are email addresses which is sensitive profile information. In providing this response we are taking into consideration the Virginia Freedom of Information Act as well as the Government Data Collection and Dissemination Practices Act.
Thank you.
From: Todd Feathers
Hello,
You state that you are taking into consideration the Virginia Freedom of Information Act but you have not cited a single exemption to the Virginia FOIA that would preclude your agency from providing the responsive login information/audit logs. There is no legal exemption for "sensitive profile information" in the law—that's a made-up phrase. Furthermore, the vast majority of government officials' email addresses are already publicly posted on agencies' websites so there's really no argument to be made at all that email addresses are exempt information.
If you intend to continue denying this request, please provide the statutorily required rejection letter containing citations for the exemptions you are claiming.
Todd Feathers
From: Virginia Office Of Data Governance And Analytics
The Office of Data Governance and Analytics (ODGA) does not have a record of when or who has accessed the FAACT database, as stated previously. ODGA does have a record of user logins to its portal, but that is a different record from what was previously requested. ODGA is supplying a login record, but the email addresses associated with such login record are being redacted, pursuant to Virginia Code 2.2-3705.1 (10). That code section prohibits mandatory disclosure of email addresses. The email addresses in ODGA’s login record were supplied to ODGA without approval from the recipients to disclose their email addresses. Thus, per FOIA we are not required to disclose those email addresses.
Thank you,
Loren Gonzalez, CPC, ELI-MP
(Preferred pronouns: she, her, hers)
Director of Communications, Outreach & Engagement
Commonwealth of Virginia
Office of the Secretary of Administration
Office of Data Governance and Analytics
1111 East Broad Street
Richmond, Virginia 23219
Sign up for the ODGA Newsletter<https://www.odga.virginia.gov/contact/>
loren.gonzalez@governor.virginia.gov<mailto:loren.gonzalez@governor.virginia.gov>
Web: odga.virginia.gov<https://odga.virginia.gov/>
ODGA on LinkedIn<https://www.linkedin.com/company/office-of-data-governance-analytics/>
ODGA on Twitter<https://twitter.com/VirginiaODGA>
ODGA on YouTube<https://www.youtube.com/channel/UCm1svN4ceC-uh3gQ4acfZRw>
-
FAACTFOIA