yourstate.us
48 CFR 824.103

824.103 Procedures.

United States · 48 CFR — Federal Acquisition Regulations System · Status: effective

Get this as JSONEmbed this
Cite this
Citation
48 CFR 824.103, 824.103 Procedures, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/247376
Permanent ID
ys:prov:247376@1
SHA-256
c41e3a4ee7273d41c5af443e0665723616fc02bb9465c812d4fb5cd1768144b1

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(c) The contracting officer shall reference the following documents in solicitations and contracts that require the design, development, or operation of a system of records— (1) VA Handbook 6500.6, Contract Security; (2) VA Handbook 6508.1, Procedures for Privacy Threshold Analysis and Privacy Impact Assessment; (3) VA Handbook 6510, VA Identity and Access Management— (i) The contracting officer will ensure that statements of work or performance work statements that require the design, development, or operation of a system of records include procedures to follow in the event of a Personally Identifiable Information (PII) breach; and (ii) The contracting officer shall ensure that Government surveillance plans for contracts that require the design, development, or operation of a system of records include monitoring of the contractor's adherence to Privacy Act/PII regulations. The assessing official should document contractor-caused breaches or other incidents related to PII in past performance reports. Such incidents include instances in which the contractor did not adhere to Privacy Act/PII contractual requirements.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.