Previous PageTable Of ContentsDFARS Home PageNext Page

HHSAR PART 324--PROTECTION OF PRIVACY AND FREEDOM OF INFORMATION


PART 324--PROTECTION OF PRIVACY AND FREEDOM OF INFORMATION


PART 324--PROTECTION OF PRIVACY AND FREEDOM OF INFORMATION

Subpart 324.1--Protection of Individual Privacy

Sec.

324.000 Scope of subpart.

324.102 General.

324.103 Procedures.

Subpart 324.2--Freedom of Information Act

324.202 Policy.

Subpart 324.70--Confidentiality of Information

324.7001 General.

324.7002 Policy.

324.7003 Applicability.

324.7004 Required clause.

Authority: 5 U.S.C. 301; 40 U.S.C. 486(c). [[Page 4246]]

Subpart 324.1--Protection of Individual Privacy

324.000 Scope of subpart.

This part prescribes policies and procedures that apply requirements of the Privacy Act of 1974 (5 U.S.C. 552a) (the Act) and OMB Circular A–130, Revised, November 30, 2000, to Government contracts and cites the Freedom of Information Act (5 U.S.C. 552, as amended).

324.102 General.

(a) It is the Department's policy to protect the privacy of individuals to the maximum possible extent while permitting the exchange of records required to fulfill the Department's administrative and program responsibilities and its responsibilities for disclosing records to which the general public is entitled under the Freedom of Information Act (5 U.S.C. 552). The Privacy Act of 1974 and the Department's implementation under 45 CFR Part 5b apply "when an agency provides by a contract for the operation by or on behalf of the agency of a system of records to accomplish any agency function* * *" The key factor is whether a departmental function is involved. Therefore, the Privacy Act requirements apply to a departmental contract when, under the contract, the contractor must maintain or operate a system of records to accomplish a departmental function.

(e) The program official, and, as necessary, the official designated as the activity's Privacy Act Coordinator and the Office of General Counsel, shall determine the applicability of the Act to each proposed acquisition. The program official is required to include a statement in the request for contract indicating whether the Privacy Act is or is not applicable to the proposed acquisition.

(f) Whenever the contracting officer is informed that the Privacy Act is not applicable, but the resultant contract will involve the collection of individually identifiable personal data by the contractor, the contracting officer shall include provisions to protect the confidentiality of the records and the privacy of individuals identified in the records (see subpart 324.70).

324.103 Procedures.

(a) All requests for contract shall be reviewed by the contracting officer to determine whether the Privacy Act requirements are applicable. The Privacy Act requirements are applicable when the contract will require the contractor to design, develop, or operate any Privacy Act system of records on individuals to accomplish an agency function. When applicable, the contracting officer shall include the solicitation notification and contract clause required by FAR 24.104 in the solicitation, and the contract clause in the resultant contract. In addition, the contracting officer shall ensure that the solicitation notification, contract clause, and other pertinent information specified in this subpart are included in any contract modification which results in the Privacy Act requirements becoming applicable to a contract.

(b)

(1) The Contracting Officer shall identify in the contract work statement the system(s) of records to which the Privacy Act and the implementing regulations are applicable.

(2) The Contracting Officer shall include the clause specified in 352.270–11 in Section H of any RFP or resulting contract to notify the contractor that it and its employees are subject to criminal penalties for violations of the Act (5 U.S.C. 552a(i)) to the same extent as HHS employees. The clause also requires that the contractor ensure that each of its employees knows the prescribed rules of conduct and each contractor employee is aware that he/she is subject to criminal penalties for violations of the Act. These provisions also apply to all subcontracts awarded under the contract which require the design, development or operation of a system of records. The Contracting Officer shall send the contractor a copy of 45 CFR Part 5b, which includes the rules of conduct and other Privacy Act requirements.

(c) The Contracting Officer shall specify in the contract work statement and award the disposition to be made of the system(s) of records upon completion of contract performance. The contract work statement may require the contractor to destroy the records, remove personal identifiers, or turn the records over to the Contracting Officer. If there is a legitimate need for a contractor to keep copies of the records after completion of a contract, the contractor must take measures, as approved by the Contracting Officer, to keep the records confidential and protect the individuals’ privacy.

(d) Whenever an acquisition is determined to be subject to the Privacy Act requirements, a "system notice," prepared by the program official and describing the Department's intent to establish a new system of records on individuals, to make modifications to an existing system, or to disclose information in regard to an existing system, is required to be published in the Federal Register. A copy of the "system notice" shall be attached to the request for contract or purchase request. If a "system notice" is not attached, the contracting officer shall inquire about its status and shall obtain a copy from the program official for inclusion in the contract file. If a "system notice" has not been published in the Federal Register, the contracting officer may proceed with the acquisition but shall not award the contract until the "system notice" is published, and publication is verified by the contracting officer.

Subpart 324.2--Freedom of Information Act

324.203 Policy.

(a) The Department's regulation implementing the Freedom of Information Act (FOIA), 5 U.S.C. 552, as amended, is set forth in 45 CFR Part 5.

(b) The Contracting Officer, upon receiving a Freedom of Information Act (FOIA) request, shall follow Department and OPDIV procedures. As necessary, actions should be coordinated with the cognizant Freedom of Information (FOI) Officer and the General Law Division of the Office of General Counsel. The Contracting Officer must remember that only the FOI Officer has the authority to release or deny release of records. While the Contracting Officer should be familiar with the entire FOIA regulation in 45 CFR Part 5, particular attention should be focused on §§ 5.65 and 5.66; also of interest are §§ 5.32, 5.33, and 5.35

Subpart 324.70--Confidentiality of Information

324.7001 General.

In performance of certain HHS contracts, it is necessary for the contractor to generate data, or be furnished data by the Government, which is about individuals, organizations, or Federal programs. This subpart and the accompanying contract clause require contractors to prudently handle disclosure of certain types of information not subject to the Privacy Act or the HHS human subject regulations set forth in 45 CFR part 46. This subpart and contract clause address the kinds of data to be generated by the contractor and/or data to be furnished by the Government that are considered confidential and how it should be treated.

324.7002 Policy.

It is the policy of HHS to protect personal interests of individuals, corporate interests of non-governmental organizations, and the capacity of the Government to provide public services when information from or about individuals, organizations, or Federal agencies is provided to or obtained by contractors in performance of HHS contracts. This protection depends on the contractor's recognition and proper handling of the information. As a result, the "Confidentiality of Information" contract clause was developed.

324.7003 Applicability.

(a) The "Confidentiality of Information" clause, set forth in 352.224-70, should be used in [[Page 4247]] solicitations and resultant contracts whenever the need exists to keep information confidential. Examples of situations where the clause may be appropriate include:

(1) Studies performed by the contractor which generate information or involve Government-furnished information that is personally identifiable, such as medical records, vital statistics, surveys, and questionnaires;

(2) Contracts which involve the use of salary structures, wage schedules, proprietary plans or processes, or confidential financial information of organizations other than the contractor's; and

(3) Studies or research which may result in preliminary or invalidated findings which, upon disclosure to the public, might create erroneous conclusions which, if acted upon, could threaten public health or safety.

(b) With regard to protecting individuals, this subpart and contract clause are not meant to regulate or control the method of selecting subjects and performing studies or experiments involving them. These matters are dealt with in the HHS regulation entitled "Protection of Human Subjects," 45 CFR Part 46. If a system of records under contract, or portions thereof, is determined to be subject to the requirements of the Privacy Act, in accordance with FAR 24.1 and 324.1 and Title 45 CFR part 5b, the procedures cited in those references are applicable and the Privacy Act contract clause shall be included in the contract. If the contract also involves confidential information, as described in this section, which is not subject to the Privacy Act, the contract shall include the "Confidentiality of Information" clause in addition to the Privacy Act clause.

324.7004 Required clause.

The clause set forth in 352.224-70 shall be included in any RFP and resultant contract(s) where it has been determined that confidentiality of information provisions may apply. Any RFP announcing the intent to include this clause in any resultant contract(s) shall indicate, as specifically as possible, the types of data which would be covered and requirements for handling the data.

Previous PageTop Of PageTable Of ContentsDFARS Home PageNext Page