DGO3.11 "Data Management"
3.11.01 PURPOSE
The purpose of this order is to outline protocols for managing the Department's data, including procedures for external reporting of data, per law, and for public transparency. Establishing data governance, roles, and processes enables police activities to be guided by evidence-based and evidence-informed approaches. Effective data management allows for increased efficiency through targeted resource allocation, reportable accountability, and enhanced crime-reduction efforts.
A core element of developing actionable analytical information is the accurate evaluation and subsequent organization of collected data. The Department will be guided by the 3T’s of data management – Trust, Truth, and Traceability – ensuring reliable data sources, accurate representation, and clear, auditable data pathways.
The Department transforms raw data into intuitive visual tools that provide the public with greater visibility into departmental performance, fostering transparency and accountability.
3.11.02 DEFINITIONS
- Data Accuracy – The level in which data reflects realities of the Department’s operations and outcomes.
- Data Classification – The process of organizing data based upon the level of sensitivity to determine authorized access and release.
- Data Cleaning – The process of preparing data for data analysis, including addressing missing or incomplete data or removing Personally Identifiable Information (PII) before dissemination.
- Data Integrity – The assurance of accuracy, consistency, and reliability of data throughout the life cycle of the data.
- Data Mart – A data repository containing a specific category of data (i.e., traffic stop data).
- Data Owner – The OIC of the individual or the individual who originally entered raw data into a database (i.e., the SFPD member who filled out an incident report in Crime Data Warehouse).
- Data Queries – An internal or external request for data made to the data analysis teams.
- Data Repository – The location of collected data.
- Data Uncertainty – When datasets have missing, incomplete, or inaccurate data.
- Need-to-Know – The purpose of accessing data for official duties.
- Redaction – The process of withholding data pertaining to federal, state and local confidentiality or privacy laws when disseminating the data.
- Right-to-Know – The legal authority for a person or agency to have access to data.
- Source Data – Raw, original, and unaltered information collected directly from its point of origin, serving as the foundation for analysis, processing, or documentation.
3.11.02 POLICY
The Department’s data is managed by the Crime Strategies Division, who shall maintain the data’s lifecycle and disseminate the data appropriately, and is secured by the Technology Division.
The Crime Strategies Division and the Technology Division are responsible for (1) data storage and integration, (2) validation and quality control, (3) centralized accessibility, (4) required reporting of Department data to local, state, and federal government, and (5) data software.
The Technology Division is responsible for (1) data hardware, (2) data security, (3) data retention and disposal, and (4) acquisition of new technologies and off-boarding outdated data systems.
Members of the Department shall only use data for lawful and/or law enforcement purposes and in compliance with San Francisco’s Data Management Policy.
3.11.04 DATA TEAMS
The units that fall under the Crime Strategies Division collaborate on the duties listed below. The Crime Strategies Division includes the Business Analysis Team, the Crime Analysis Unit, and the Business Intelligence Unit:
- Business Analysis Team (BAT) – BAT serves as the central hub for data integrity and transparency in the Department. BAT is responsible for (1) relaying data findings to Command Staff, (2) regulatory reporting and compliance, and (3) inter-agency collaboration.
- Crime Analysis Unit (CAU) – CAU compiles, organizes, analyzes, and presents data and analytical products to the Department in support of Department operations.
- Business Intelligence/Geospatial Team (BI/GIS) – BI/GIS serves as the behind-the-scenes manager of data, reporting, and GIS systems Department-wide. BI/GIS ensures Department data, reporting, and GIS systems are stable, secure, and are always operational.
- There are other specialized units throughout the Department that are responsible for inputting data. The Crime Strategies Division coordinates with these specialized units.
3.11.05 PROCEDURES
- Data Collection
- Data Sources - Sources which data is extracted from includes, but is not limited to, the following:
- Incident and Arrest Reports (CDW)
- CAD and RMS data related to calls for service
- Field Interview reports
- Criminal History Information
- Traffic Citations
- Crash Reports (SWITRS)
- Criminal justice databases
- Sex Offender Registry
- Human Resource Management System
- ALPR Technology
- Drones
- BWS Technology Systems
- 311
- AB 953 RIPA - all contacts, interactions where officers conducted a search, stops (both traffic and pedestrian), detentions, perceived race/ethnicity, gender, age, reason for contact, resulting outcome, not recorded stops, stops with incorrect data entries, and stops with incomplete entries
- Human Trafficking Application
- Coplogic
- Laserfiche
- Data Administration
- Data Entry - Manually completed by SFPD members and the public. All data is entered into databases through internal systems and vendor-provided applications. SFPD members are trained at the Academy on data input.
- Data teams do not alter or modify raw data as it is classified as Criminal Justice Information (CJI), but do organize and categorize the data, adding supplementary fields as needed.
- Data Uncertainty –If data teams find errors in the raw data, they will confer with the data owner and get approval through the chain of command for any adjustments made by the data owner.
- Types of Analysis - To effectively leverage information in decision-making processes, it is essential to determine the type of analysis needed.
- Quantitative - Uses numbers to analyze data, answering questions of "what" and "how many".
- Qualitative - Uses non-numerical, subjective data to understand "why" and "how".
- Types of Scope - The following scopes, as defined by the International Association of Crime Analysts (IACA), range from daily operational support and pattern identification to long-term trend analysis, management reporting, and criminal investigations. Analysts shall determine the methods of analysis needed.
- Tactical Crime - Immediate, short-term, daily or weekly crime patterns.
- Strategic Crime - Long-term, chronic, or trends occurring over months or years.
- Administrative Crime - Administrative reporting and external, internal or governmental communication.
- Criminal Intelligence - Individuals involved in, or networks behind, organized crime, terrorism, or recurring criminal activity.
- Data Classification - See Citywide Data Classification Standard Policy. Data classes are categorized into the following:
- Level 1 (public)
- Level 2 (internal use)
- Level 3 (sensitive)
- Data Sources - Sources which data is extracted from includes, but is not limited to, the following:
- Data Storage
- Data Repositories - Department data is housed internally and across cloud environments on software interface systems called Oracle Analytic Server and Microsoft SQL. Within each data repository, electronic data (crime and performance indicators) captured at the officer-level is contained in data marts that are maintained by the BIU data team.
- Data Security – Each Manager of an analysis team in the Crime Strategies Division has the authority, with Crime Strategies supervisory approval, to grant access to data systems. For access to more specific data, the Crime Strategies’ Managers should request access from the Data Owner. The Crime Strategies Division Managers will track all parties with access.
- Data should only be stored on designated drives and servers.
- Data should only be uploaded to an approved cloud computing service.
- Data should be backed up frequently.
- Data should be encrypted before being transferred electronically.
- All servers and computers containing data should be protected by approved security software and a firewall.
- Data Usage and Sharing
- Law enforcement data shall be accessed in accordance with the “least privilege” principle: restricting data access to the minimum necessary for completion of law enforcement duties and tasks.
- Members are approved to access Department data per Penal Code Sections 830.1-5.
- Members are approved to access Department data on a "need to know" basis specific to their role in the Department.
- Restricted law enforcement data, such as data contained in Level II, CDW, or LaserFiche, is viewable on a "need to know/right to know" basis. For CLETS access, all Department employees must complete a background check, meet CJIS training requirements, and obtain clearance through the CLETS Coordinator.
Crime data access requires explicit approval from the designated data owner per the following approval levels.
Confidential Reports CONFIDENTIAL TYPE GRANT CONFIDENTIAL ACCESS REQUIRED Confidential - General NO Confidential - High Profile YES Confidential - Administrative Investigations YES If a report is marked Confidential-General, it may be viewed/accessed by all.
If a report is marked Confidential - High Profile or Administrative Investigation, only person(s) the author of the report grants access to may view the report. You need to grant access to the appropriate Reviewing Officer and OIC so that they may access and sign off on the report. Once a report is signed by the OIC, no change to the access list may be made.
- For all data managed and maintained by the Crime Strategies Division, access granting and sharing shall be managed and tracked by either the designated OIC over specific datasets or the Crime Strategies Division Managers and reviewed and approved by the Director of Crime Strategies.
- Data Queries
- Members submitting data requests through email or Department memo shall include the requested data scope, how the data will be used, and intended audiences and timelines.
- Analysts may request more information before accepting the request. Analysts must ensure that they are legally permitted to share the data requested.
- PRAs - See DGO 3.16, Release of Police Reports.
- Requests for data from outside agencies or law enforcement agencies will be forwarded to the appropriate Command personnel for approval and align with state sharing laws.
- Ensure a Memorandum of Understanding (MOU) exists before sharing data. If no MOU exists with non-law enforcement outside entities, the Department shall enter into an MOU which shall be fully executed before ongoing data sharing.
- Data Checks - The BIU data team has an automated data-quality process that scans for data errors with safeguards in place that trigger alerts when data failures, duplications, or anomalies occur. The BIU data team reviews automatically generated daily validation reports and conducts manual validation for every released report.
- Law enforcement data shall be accessed in accordance with the “least privilege” principle: restricting data access to the minimum necessary for completion of law enforcement duties and tasks.
- Data Reporting
- Internal Reports - A supervisor from each of the three units (BI/GIS, CAU, BAT) shall review all internal reports created by their teams prior to submission.
- Operational Analysis – Generating crime statistics by District or specific geographic boundaries to support strategic deployment and investigative priorities.
- Administrative Reporting – Fulfilling internal data requests for various units and bureaus to monitor performance metrics and departmental trends.
- Report Requests - Data and reporting generated by data teams will fulfill data requests while complying with mandated data privacy protections.
- Ongoing Reporting Criteria – Ongoing and regular reports on data must be tied to a federal, state, local law, policy, or Commission Resolution requirement.
- Redacted Dataset Publication – Maintaining a proactive open-data portal where the public can access machine-readable datasets.
- The SFPD website houses the Department’s data dashboards, which are automatically connected to DataSF, the hub for Citywide data.
- Data Validation – Data teams shall verify the accuracy of all data before submission to DataSF. Data teams shall remove all Personally Identifiable Information (PII). Data teams shall update dashboard data on a recurring schedule per state and federal reporting cycles.
- The SFPD website and DataSF houses the Department’s Crime, Stop Data, Use of Force, Drone Data, Victim Demographic Data, and Hate Crime Dashboards.
- For any external reporting, data teams shall create reports per legal requirements by extracting raw data from Department databases and receiving approval from the Crime Strategies Director and affected Bureau Chief prior to submission.
- All external reports shall include legally required data points, missing data, data errors, incomplete data entries, and the reporting error percentage (the goal is to have an error rate less than 5%). Department databases shall be able to collect all reporting requirements.
- Upon approval, external reports shall be published on the SFPD website.
- For state and federal reporting, data teams shall upload data through secure channels to the California Justice Information Services (CJIS).
- Federal Reporting - Reports are submitted to the Federal Bureau of Investigations (FBI) through the Uniform Crime Reporting (UCR) or National Incident Based Reporting System (NIBRS) programs in order to contribute to national statistics. Federal reports include, but are not limited to:
- Law enforcement officers killed and assaulted (LEOKA)
- Arson
- Cleary Act
- State Reporting - Reports are submitted to California Department of Justice (Cal DOJ) per Penal and Government Codes. State reports include, but are not limited to:
- Monthly Arrest and Citation Register (MACR)
- Use of Force and Serious Bodily Injury (SBI)
- Officer-Involved Shootings (OIS)
- AB 953 RIPA - Data collection of all contacts, interactions where officers conduct a search, stops (traffic and pedestrian), and detentions noting perceived race/ethnicity, gender, age, reason for contact, and resulting outcome. Data teams shall ensure data validation occurs (3.11.05 (D)(5)(a)).
- Crimes Against Seniors
- Domestic Violence
- Hate Crimes
- Local Reporting
- Sunshine Ordinance Compliance - Managing public data requests to ensure transparency under the California Public Records Act, balancing the public's right to know with data privacy laws.
- Local reporting also includes, but is not limited to: Quarterly Activity and Data Report, the Victim Data Demographic Report, the AB481 Military Equipment Use Report, the Limited English Proficiency (LEP) Report, the Officer-Involved Shootings Report, and the Admin Code 19B General Report.
- See DGO 3.16, Release of Police Reports.
- Internal Reports - A supervisor from each of the three units (BI/GIS, CAU, BAT) shall review all internal reports created by their teams prior to submission.
- Data Disposal - In accordance with California Government Code Section 34090 and Penal Code Section 832.5, records must be retained for their mandated. Once the applicable statute of limitations and retention schedules have been exhausted, all data must be promptly and securely destroyed by the Technology Division.
3.11.06 VENDOR REQUIREMENTS
The Department should do the following when considering a contract with a data-related vendor:
- Determine a testing timeframe.
- Determine whether the vendor fits the Department's current data architecture.
- Evaluate the impact on the Department's data architecture.
3.11.07 TRAINING
Department data teams will receive periodic training on data collection, data management, data security and storage, data analysis and reporting, data disposal, and legal data requirements.