Note: Single-source report; awaiting corroboration.

The Centers for Disease Control and Prevention (CDC) emphasizes its commitment to protecting user privacy on CDC websites, mobile applications, and in the dissemination of public health information. The CDC privacy policy states the agency complies with all applicable federal laws regarding the collection, use, and disclosure of personally identifiable information (PII). The CDC does not collect PII unless voluntarily provided by users, such as through forms, comments, emails, or surveys.

If users provide PII (such as name, address, phone number, or email), the CDC may use this information to respond to messages or fulfill information or service requests. This information is retained only as long as necessary to address the user’s inquiry or request. Electronic data is managed and destroyed according to the Federal Records Act and the National Archives and Records Administration's filing schedules.

The policy also states that in certain situations, the CDC may be required to disclose information due to a Freedom of Information Act request, court order, Congressional request, or authorized notification. Users with questions or who need more information about the privacy policy are encouraged to contact the CDC Privacy Office by email or phone.