Document the relevant legal, ethical, policy, and privacy guidance and considerations that emerged from your review. Check Gamechanger, (a comprehensive repository of all DoD statutory and policy-driven requirements) for relevant governance requirements.
If your project involves the use of personally identifiable information (PII), consult with your Privacy Officer to determine if use of the PII: 1) triggers any Privacy Act restrictions or constraints; 2) is consistent with the Fair Information Practice Principles (FIPPs) set forth in OMB Circular A-130, Appendix II; 3) requires creation or modification of a Privacy Impact Assessment (PIA) as mandated by Section 208 of the E-Government Act; 4) requires application of one or more of the Committee on National Security Systems Instruction (CNSSI) No. 1253, Privacy Overlays; 5) involves protected health information (PHI) and requires application of NIST SP 800-66, Rev. 2, Implementing the HIPAA Security Rule: A Cybersecurity Resource Guide, to the project; and, 6) necessitates use of privacy-enhancing cryptograph techniques in addition to differential privacy methods to improve the privacy posture for this project.