| HHS Privacy Impact Assessment (PIA) Summary |
| FDA: FDA ORA Recall Enterprise System (RES) |
| Due to the IIF information maintained in the MARCS Recalls system, |
| the choice is based on user acceptance reviews of any requirements |
| and design of the system and as part of the request for user access |
| to the application. In addition, regulations and policies that support |
| processing of recalls data provide guidance for information being |
| displayed or recorded. |
| User Request Forms for user request to gain access to the |
| application. |
| Users are notified verbally during coordinator conference calls and or |
| in writing via email if changes to the system. |
| Does the website have any information or pages |
| directed at children under the age of thirteen? |
| Are there policies or guidelines in place with regard |
| to the retention and destruction of IIF? |
| The information contained within RES is protected by several layers |
| of administrative, physical, and technical controls in accordance with |
| policies and regulations from the FDA, NIST, and OMB. All |
| applicable security controls are reviewed on a periodic basis to |
| ensure that they are implemented correctly, operating as intended, |
| and producing the desired result of protecting all information within |
| RES. |

| PIA-HHS-Form |
| Report Date: 8/13/2007 |
| Page: 93 |
| Note on IIF: Any question about IIF seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it |
| is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily |
| or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or |
| other legislation. Note: If no IIF is contained in the system, please answer the remaining required questions, then promote the PIA to the Sr. Privacy |
| Official who will authorize the PIA. Note: If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature |
| and promotion. |