1605C5-25-R-00007 Attachment 2 - BLS Confidentiality and Security_Final.docx

DOCX document 46 KB Posted

Attached to
DOL BLS Electronic Data Collection (EDI) Center Operations Federal contract opportunity
Solicitation number
1605C5-25-R-00007
Issued by
Department of Labor Office of the Assistant Secretary for Administration and Management

About this file

This document is an attachment to a federal contract solicitation that details confidentiality and security requirements for a Bureau of Labor Statistics (BLS) Electronic Data Collection (EDI) Center Operations contract. The comprehensive document outlines strict protocols for handling confidential information, including statutorily protected data, respondent identifiable information, personally identifiable information, and pre-release economic indicators. Contractors and their employees must comply with the Confidential Information Protection and Statistical Efficiency Act (CIPSEA), undergo background investigations, complete mandatory confidentiality training, and sign detailed agent agreements that prohibit unauthorized disclosure of sensitive information.

Key requirements include maintaining secure worksites, using only FedRAMP-approved cloud services, protecting data through encryption, restricting work locations to within the United States, implementing NIST cybersecurity standards, and immediately reporting any potential security breaches. Contractors must carefully manage access to confidential information, with agents subject to criminal penalties for improper disclosure. The document emphasizes the critical nature of maintaining respondent trust and the statistical integrity of BLS data collection processes, with specific provisions for data handling, storage, transmission, and destruction upon contract completion.

View the file

Other files for this federal contract opportunity

Other files attached to DOL BLS Electronic Data Collection (EDI) Center Operations, newest first.
File Type Posted
1605C5-25-R-00007-0002 Attachment 3 - Pricing Sheet EDI_Final.xlsx XLSX spreadsheet
1605C5-25-R-00007 EDI_RFP Question and Answer_Final.xlsx XLSX spreadsheet
1605C5-25-R-00007-0002_093025.pdf PDF
1605C5-25-R-00007-0002_093025.docx DOCX document
Wage Determinations for EDI.xlsx XLSX spreadsheet
AMNT1 1605C525R00007.pdf PDF
1605C5-25-R-00007 Attachment 3 - Pricing Sheet EDI_Final.xlsx XLSX spreadsheet
1605C5-25-R-00007 Attachment 4 - RFP Question and Answer_Final.xlsx XLSX spreadsheet
1605C5-25-R-00007 Attachment 5 - Part 7 - Technical Exhibit Index_Final.docx DOCX document
1605C5-25-R-00007 Attachment 6 - SMALL BUSINESS SUBCONTRACTING PLAN TEMPLATE_Final.xlsx XLSX spreadsheet
1605C5-25-R-00007.pdf PDF
1605C5-25-R-00007 Attachment 1 - PPQ_Final.doc DOC document
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1605C5-25-R-00007 Attachment 2

Attachment 2 - BLS Confidentiality and Security Requirements

Attachment A: BLS Confidentiality and Security Requirements

Last Updated: March 2024

1. Work under this contract may involve access to Bureau of Labor Statistics (BLS) confidential information, including information to be collected under this contract on behalf of the BLS or information previously collected by the BLS under a pledge of confidentiality for exclusively statistical purposes or other confidential information as defined in Section 2 below. The majority of data collected by or on behalf of the BLS are provided on a voluntary basis by respondents who have agreed to provide the information for the statistical purpose(s) specified by the BLS. A violation of the confidence that respondents place in the BLS would endanger the ability of the BLS to carry out its duties. Therefore, the Contractor and its employees must handle any such data, that they may come into contact with as a result of contract work, in accordance with the Confidential Information Protection and Statistical Efficiency Act (CIPSEA) (44 USC Section 3561 et seq.) and other applicable Federal laws. Due to the possible exposure to data protected by law under CIPSEA, the BLS may, in accordance with this contract, designate Contractor employees as agents of the BLS. All such agents are subject to the fines and penalties under CIPSEA and any other fines and penalties that apply to the mishandling of confidential information. The “Confidential Information Protection” provisions of CIPSEA appear as Attachment A.1 of these requirements.

2. For the purposes of this contract, "confidential information" may include any of the following:

a. Statutorily Protected Information. Data or information collected by the BLS, including its agents, under a pledge of confidentiality and/or data protected from public disclosure under CIPSEA, the Wagner-Peyser Act, the Trade Secrets Act, or other Federal laws.

b. Respondent Identifiable Information. Any representation of information that permits the identity of participants in BLS statistical programs to be reasonably inferred by either direct or indirect means. BLS-specific examples include but are not limited to survey sample composition, lists of reporters, names of respondents, and brand names, regardless of the source of such lists or names. Respondent Identifiable Information may also be Statutorily Protected Information.

c. Personally Identifiable Information. Any representation of information about an individual, maintained by the BLS, that permits the identity of the individual to whom the information applies to be reasonably inferred by either direct or indirect means. BLS-specific examples include but are not limited to, education, financial transactions, and medical, criminal, or employment history, and information which can be used to distinguish or trace an individual’s identity, such as their name, social security number, date and place of birth, mother’s maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual. Personally Identifiable Information may also be Respondent Identifiable Information and Statutorily Protected Information.

d. Principal Federal Economic Indicator (PFEI) Pre-release Information. Statistics and analyses produced by the BLS that have not yet been released to the public and have been designated by the Office of Management and Budget as Principal Federal Economic Indicators. Currently, the following BLS data series have been designated as PFEIs: the Consumer Price Index, Employment Situation, Employment Cost Index, Producer Price Indexes, Productivity and Costs, Real Earnings, and U.S. Import and Export Price Indexes.

e. Non-PFEI Pre-release Information. Statistics and analyses, not designated as PFEIs, that have not yet been released to the public, whether or not there is a set date and time of release before which they must not be divulged.

f. Restricted Access Information. Information describing the internal practices of the BLS that should be limited in access to individuals with a need-to-know. BLS-specific examples include but are not limited to system security documentation and vulnerability assessments, procurement-sensitive information, systems-specific operating procedures, and internal reports.

3. In performing work under this contract, the Contractor agrees that access to the confidential information will be restricted to authorized persons. For the purposes of this contract, "authorized persons" is defined as: BLS employees and non-BLS employees designated as agents of the BLS who are authorized access to the confidential information for the statistical purposes set out under this contract and who have signed a BLS Agent Agreement (Attachment B) swearing to comply with CIPSEA and other applicable Federal laws in the handling of BLS confidential information.

The parties understand and agree to the following:

a. Authorized persons granted access to confidential information will not make use of the information for any purpose other than to carry out tasks specifically authorized under the contract.

b. Authorized persons will not seek to obtain access to confidential information that is not needed to carry out contract work.

c. The Contractor will promptly provide the BLS with a list of Contractor employees who the Contractor believes require access to BLS confidential information to perform work on the contract. The BLS will consider such persons for designation as agents of the BLS. If the BLS deems it necessary to decline to approve any such employee as an agent, the Contractor may provide the name of another Contractor employee to the BLS for consideration.

d. The BLS will provide the Contractor with BLS Agent Agreements for all approved agents. The Contractor will forward all signed BLS Agent Agreements to the Contracting Officer Representative (COR) or a BLS designated official prior to such agents receiving access to the confidential information.

e. The Contractor will keep records on current Agent designations and will report such information promptly to the COR upon request.

f. The Contractor will assure that all agents will comply with their obligations under the BLS Agent Agreement and under the contract.

4. Agents shall not be regarded as employees of the United States Government, the Department of Labor, or the BLS for any purpose. The parties further understand and agree to the following:

a. The Contractor shall notify the BLS COR promptly whenever an agent is no longer associated with the Contractor or when an agent no longer requires access to confidential information. The Contractor shall notify the BLS immediately whenever an agent’s access to confidential data may endanger the confidentiality of data.

b. BLS may, without advance notice, discontinue or suspend any BLS Agent Agreement or any agent’s access to its information at any time, within its own absolute discretion.

c. In the event of such suspension or discontinuance, the employing Contractor will propose a Contractor employee deemed suitable by the BLS as a replacement agent, where such employee’s services are needed to carry out the Contractor’s responsibilities under this contract.

d. No BLS Agent Agreement nor any discontinuance nor suspension thereof, nor any denial of access to information, will result in any payment of any kind nor any legal liability by the BLS, the Department of Labor, or the United States Government.

e. Discontinuance of any BLS Agent Agreement will not affect any obligation of the Contractor or the designated agent to safeguard confidential data or any intellectual property rights set forth in this contract or in any BLS Agent Agreement.

5. The Contractor agrees, in the performance of this contract, to screen employees and to use only those employees who have a demonstrated record of honesty, trustworthiness, integrity, and reliability as ascertained by the Contractor. All Contractor employees selected to work under this contract may be subject to any Federal background investigation(s) deemed appropriate by BLS, including pre-employment checks.

6. All agents will perform activities subject to this contract under the control of the COR, a BLS Task Monitor, or any other BLS official that the BLS designates (in some contracts the COR responsibilities noted in these requirements will be handled by a BLS Task Monitor).

7. The Contractor agrees to notify the BLS COR and/or BLS Task Monitor of any contractor employee’s intent to separate and the proposed effective date at least two weeks prior to the separation. In the event of an unplanned departure due to unforeseen termination or resignation, the Contractor agrees to provide immediate notification of a contractor employee’s separation. Types of separation may include employees transfer or termination. The BLS requires this prompt notification so that additional agency separation procedures for contractors can be initiated.

8. All agents must agree, in writing, to comply with all provisions of law that affect information acquired by the BLS including, among other laws, the Trade Secrets Act, the Wagner-Peyser Act, and the Privacy Act. They must specifically swear (or affirm) to comply with the provisions of CIPSEA, as set forth in the BLS Agent Agreement attached as Attachment B. Agents who improperly disclose confidential information may be subject to criminal sanctions.

9. The Contractor agrees to cooperate with BLS in administering BLS-supplied confidentiality and security trainings to all agents designated under this contract. The Contractor agrees to ensure that all agents complete such training within thirty days of being assigned to BLS work and on an annual basis thereafter. The Contractor agrees to follow BLS instruction with regard to reporting on training completion and to provide reasonable evidence of training completion to the BLS upon request. The BLS may consider, but is not obligated to accept, alternate approaches to training delivery and reporting that the contractor may propose to meet this requirement.

10. The Contractor agrees not to divulge, publish, reproduce, or otherwise disclose, in any manner or to any extent, confidential information, in whole or in part, to any individual other than authorized persons.

11. The Contractor and all of its employees shall not release any reports or other outputs (including those oral or written and regardless of format) prepared using confidential information, unless approved in advance by the COR or other official designated by the BLS. Such approval will be documented to assure that no such outputs involve the inappropriate release of confidential information. All parties, including Contractors and its employees, will be bound by the determinations of such BLS official.

12. The Contractor agrees to notify the COR immediately upon discovering any actual or suspected breach of security or unauthorized disclosure of BLS sensitive information, which includes confidential information, defined above. This includes any opportunity for, or actual instance of, an unauthorized individual accessing sensitive information. Examples of unauthorized disclosures are the loss or theft of a computing device, email or fax transmittals of confidential information sent to an unintended recipient, or any unauthorized advance release.

13. The Contractor agrees to notify the COR immediately upon receipt of any legal, investigatory, or other demand for access to the confidential information in any form.

14. The Contractor agrees not to subcontract or transfer any work in the performance of the contract that would involve the exposure or disclosure of any BLS confidential information orally, in writing, or in any other form, in whole or in part, to the subcontractor or access to such information by the subcontractor except with the prior written approval of the COR. The Contractor agrees to include BLS confidentiality and security provisions as provided by the COR in all subcontracts awarded to carry out work provided for in this contract. The Contractor agrees to consult with the COR regarding whether subcontractor employees are required to be designated as agents. The Contractor agrees to send to the COR, a copy of any approved subcontract upon execution.

15. The Contractor agrees not to attempt to link BLS confidential information with individually identifiable records from any BLS or non-BLS data set without the written approval of the COR. The Contractor must show to the satisfaction of the BLS that they are able to legally extend to the BLS permission to access all such non-BLS data. Permission must be extended to BLS employees and agents to access the non-BLS data. All new data sets created from linking BLS confidential information with other data are protected by CIPSEA and must be handled in accordance with the provisions in this contract.

16. In the case that the contract involves the collection of data from respondents, the contractor agrees to notify the COR immediately should any respondent require an agreement be signed prior to providing data to the BLS.

17. If any contractor employees must be issued BLS Local Area Network (LAN) IDs, then each such employee must agree to abide by BLS network “Rules of Behavior” prior to receiving an ID.

18. Contractor employees shall be required to sign any individual agreements governing access to information that are required by other Federal agencies as a result of the disclosure of data to Contractor employees pursuant to this contract.

19. Contractor employees who have access to pre-release information are prohibited from releasing the data to anyone other than authorized employees of the BLS and authorized agents who require access to such data for the purposes of carrying out their responsibilities under this contract. They shall not gain financially from knowledge of the data. It would be a violation of this contract for Contractor employees to do the following:

a. Use knowledge of pre-release information to buy or sell stocks, mutual funds, bonds, or futures, or to make or divest themselves of other similar investments.

b. Disclose pre-release information to other persons or advise or make recommendations to other persons based on knowledge of such data.

20. Privacy Act notification: If applicable, the Contractor will be required to design, develop, or operate system(s) of records on individuals, to accomplish an Agency function subject to the Privacy Act of 1974, Public Law 93‑579 (5 U.S.C., Section 552a) as amended (the Act), and applicable agency regulations. Violation of the Act may involve the imposition of criminal penalties (FAR 52.224‑1). The title(s) of the system(s) of records shall be listed on the respective task orders, as appropriate.

21. The Contractor agrees to:

a. Comply with the Act and the Agency rules and regulations issued pursuant to the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:

(1) the system(s) of records; and

(2) the design, development, or operation work that the Contractor is to perform.

b. Include the Privacy Act provisions contained in this contract in every solicitation and every subcontract, when the work statement in the proposed subcontract requires the design, development, or operation of a system of records on individuals that is subject to the Act.

c. Include, in all data solicitations requesting information to be placed in a Privacy Act System of Records, a Privacy Act notification statement provided by the BLS.

22. The Federal Information Security Modernization Act tasked the National Institute of Standards and Technology (NIST) with providing minimum security requirements for the protection of sensitive information while residing in nonfederal information systems. The Contractor agrees to ensure that all Contractor-owned systems used to store or process data under this agreement comply with all applicable Federal information security directives, acts, laws, regulations, standards, and guidelines. The Contractor shall ensure implementation of the respective security controls catalogued in the current version of NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations,” and the operating system settings recommended by the manufacturers of the commercial off-the-shelf (COTS) products selected for integration, into any systems used to store or process BLS data. Per NIST 800-171, the BLS reserves the right to request the System Security Plan (SSP) and any associated plans of action for any planned implementations or mitigations. In instances where the Contractor finds that a security control does not apply or cannot be met, the Contractor should notify the COR and may request an exception. Any exceptions must be approved in writing by the BLS.

23. The Contractor agrees to comply with Federal policies regarding the secure transmission of confidential information including both electronic and physical data transfers. The Contractor shall consult with the COR to determine which data transfer methods are acceptable for the various types of confidential information that are involved in contract performance. Per NIST 800-171, confidential electronic data transfers authorized by the COR must utilize encryption technology that meets the standards established by the Federal Information Processing Standards Publication 140, “Security Requirements for Cryptographic Modules” (FIPS PUBS 140) and any subsequent revisions to these standards. Encrypted portable media may be delivered by a courier, a BLS employee, or an authorized individual of the recipient, or may be sent via a mail delivery service with tracking capability. In person pick up of an appropriately labeled paper copy, by an authorized individual of the recipient, is also permitted.

24. The Contractor agrees to maintain secure worksites within the approved facilities for performance of work under this contract. The confidential information shall be secured in a manner so that it cannot be viewed by, and it is not accessible to, persons who have not been designated as agents of the BLS and who have not signed a BLS Agent Agreement.

25. Work under this contract will be performed at BLS facilities or other approved worksites. The parties understand and agree to the following:

a. No worksites outside of the United States will be permitted. In addition, confidential information may not be stored in data centers outside of the United States.

b. The Contractor must provide the COR with a list of worksites for approval at the start of work provided for in this contract and subsequent task orders, and must notify the COR in writing of any proposed changes (additions or deletions) to the list of worksites. The COR shall indicate approval of the worksites in writing. All work provided for under this contract will be performed at those approved locations only.

c. Contractor employee telework locations may be included in the list of worksites. Contractor employees may be permitted to telework on a full-time or temporary basis. All instances of contractor telework must be documented and approved by the COR before any telework begins. No personally owned equipment can be used by the Contractor. Additionally, the Contractor is expected to meet all of the security requirements for the telework site(s). The Contractor should be prepared to demonstrate how it is implementing the security controls catalogued in NIST 800-171 for the telework site(s) and may be required to submit evidence of adherence through a System Security Plan (SSP) or other documentation. Any exceptions of a telework location to the NIST 800-171 requirements would need to be documented and approved in writing by the COR.

d. The Contractor agrees not to remove any digital and/or non-digital media or equipment containing the confidential information from approved worksites. Exceptions to this provision shall be permitted only with prior, written approval of the COR in accordance with BLS confidentiality and security policies.

26. In some cases, such as data collection activities, contract work may necessitate handling of confidential data away from secure worksites. Where the COR has approved such work arrangements in writing, the contractor agrees to maintain all confidential information in a secure fashion. The Contractor shall provide the contract employees with instructions on maintaining the security of all confidential information. Such instructions are subject to the review and approval of the BLS COR upon request.

27. BLS reserves the right to review and approve or disapprove all the security safeguards instituted to comply with the requirements of this contract. BLS also reserves the right on behalf of itself and the Government to conduct confidentiality and security compliance reviews as deemed appropriate to ensure compliance with all security policies and directives, including unannounced security inspections of the Contractor's facilities and approved worksites. Reviews may involve inspection of the facilities, technical capabilities, documentation, records, databases, operations, and procedures provided for the performance of any work under this contract. The Contractor shall support security inspections conducted by Government auditors or other Government representatives, as designated by the COR. Additionally, the Contractor may be asked to submit necessary oversight documentation in support of third-party monitoring. BLS data physically and/or electronically maintained at the Contractor’s worksites will be sufficiently segregated from any other confidential data the Contractor maintains to facilitate BLS security inspections. No other obligations on the part of the Contractor may restrict BLS access to Contractor facilities where BLS confidential information is maintained. The Contractor may not put forth legal qualifications for, or in any way restrict, BLS access to these systems or facilities for the purpose of determining compliance with contract requirements. On the basis of such security inspections, the COR may require specific measures in cases where the Contractor is found to be non-compliant with contract requirements. The Contractor shall implement such measures as soon as possible without additional cost to the Government and support additional reviews as necessary to confirm actions taken to correct defects and deficiencies.

28. Executive Order 14028, “Improving the Nation’s Cybersecurity” (E.O. 14028), required NIST to issue guidance to enhance the security of the software supply chain. In addition, OMB issued Memoranda M-22-18, “Enhancing the Security of the Software Supply Chain through Secure Software Development Practices” (M-22-18) and M-23-16, “Update to Memorandum M-22-18, “Enhancing the Security of the Software Supply Chain through Secure Software Development Practices” (M-23-16), which require federal agencies to adhere to NIST’s supply chain requirements. NIST Special Publication 800-218, “Secure Software Development Framework” (SSDF) (SP 800-218) and the NIST Software Supply Chain Security Guidance provides that a federal agency may use software subject to M-22-18’s requirements only if the producer of that software has first attested to compliance with Federal Government-specified secure software development practices drawn from the SSDF. The parties understand and agree to the following:

a. The contractor agrees to comply with federal Supply Chain Risk Management policies above.

b. The Contractor agrees to validate the authenticity of hardware and software used or provided for this contract through certificates of authenticity and code signing. The BLS reserves the right to inspect hardware and software for signs of tampering.

c. The Contractor agrees to notify the BLS of supply chain compromises within 24 hours of detection.

d. The contractor must obtain from the software producers and submit to the COR a Secure Software Development Self-Attestation form, either on-line or hard copy, which identifies the minimum secure software development requirements a software producer must meet, and attest to meeting, before software subject to M-22-18 and M-23-16 requirements may be used by the BLS.

29. Contractor acquisition of a Cloud Service Provider(s) (CSP) service offerings (CSO) to service BLS confidential information must be acquired through Federal Risk and Authorization Management Program (FedRAMP) compliant vendors. Cloud providers servicing BLS confidential data must have FedRAMP approval with a moderate baseline. Cloud services for confidential information must utilize Government Only Tenants. Contractors must submit a CSP vendor’s FedRAMP package ID and service name for continuous monitoring security review at the request of the BLS. BLS confidential information must have defined access controls and be encrypted at rest and in transit to prevent unauthorized access. Only FIPS-validated cryptography is approved for use in encrypting Federal information. It is a contractor responsibility to ensure that any employee of a CSP who will require access to unencrypted BLS confidential information for any purpose be designated as a BLS agent and complete the required training.

30. Upon termination or completion of the contract, or at an earlier time if required by the COR, all source documents or other media provided to the Contractor by BLS that contain confidential information and any documents or other media created by the Contractor that contain confidential information must be returned to the COR, or with the COR’s permission, be destroyed. The Contractor shall ensure that all data that have been deleted cannot be retrieved and reconstructed. All types of digital and/or non-digital media and equipment must be disposed of, cleared, purged, or destroyed in accordance with Federal guidelines. The Contractor shall certify that unnecessary data processed during the performance of this contract was purged from all data storage components of the Contractor’s computer facilities. The Contractor will retain no output after such time as the contract is completed. If the COR directs the Contractor to retain any data, the Contractor shall certify that any BLS data remaining in any storage component will be safeguarded to prevent unauthorized disclosures in accordance with the terms of this contract. The Contractor's failure to surrender or destroy such materials promptly or the Contractor's conversion of such materials to a use not authorized by the contract may be a violation of 18 U.S.C. Section 641.

31. If the Contractor fails to comply with the requirements contained in this contract, the Contractor may be deemed to have failed to perform the requirements of this contract.

Attachment A.1 – Confidential Information Protection and Statistical Efficiency Act

PART A—GENERAL

§ 3561. Definitions In this subchapter:

(1) AGENCY.—The term ‘agency’ means any entity that falls within the definition of the term ‘executive agency’, as defined in section 102 of title 31, or ‘agency’, as defined in section 3502.

(2) AGENT.—The term ‘agent’ means an individual—

(A) (i) who is an employee of a private organization or a researcher affiliated with an institution of higher learning (including a person granted special sworn status by the Bureau of the Census under section 23(c) of title 13), and with whom a contract or other agreement is executed, on a temporary basis, by an executive agency to perform exclusively statistical activities under the control and supervision of an officer or employee of that agency;

(ii) who is working under the authority of a government entity with which a contract or other agreement is executed by an executive agency to perform exclusively statistical activities under the control of an officer or employee of that agency;

(iii) who is a self-employed researcher, a consultant, a contractor, or an employee of a contractor, and with whom a contract or other agreement is executed by an executive agency to perform a statistical activity under the control of an officer or employee of that agency; or

(iv) who is a contractor or an employee of a contractor, and who is engaged by the agency to design or maintain the systems for handling or storage of data received under this subchapter; and

(B) who agrees in writing to comply with all provisions of law that affect information acquired by that agency.

(3) BUSINESS DATA.—The term ‘business data’ means operating and financial data and information about businesses, tax-exempt organizations, and government entities.

(4) DATA ASSET.—The term ‘data asset’ has the meaning given that term in section 3502.

(5) DIRECTOR.—The term ‘Director’ means the Director of the Office of Management and Budget.

(6) EVIDENCE.—The term ‘evidence’ means information produced as a result of statistical activities conducted for a statistical purpose.

(7) IDENTIFIABLE FORM.—The term ‘identifiable form’ means any representation of information that permits the identity of the respondent to whom the information applies to be reasonably inferred by either direct or indirect means.

(8) NONSTATISTICAL PURPOSE.—The term ‘nonstatistical purpose’—

(A) means the use of data in identifiable form for any purpose that is not a statistical purpose, including any administrative, regulatory, law enforcement, adjudicatory, or other purpose that affects the rights, privileges, or benefits of a particular identifiable respondent; and

(B) includes the disclosure under section 552 of title 5 of data that are acquired for exclusively statistical purposes under a pledge of confidentiality.

(9) RESPONDENT.—The term ‘respondent’ means a person who, or organization that, is requested or required to supply information to an agency, is the subject of information requested or required to be supplied to an agency, or provides that information to an agency.

(10) STATISTICAL ACTIVITIES.—The term ‘statistical activities’—

(A) means the collection, compilation, processing, or analysis of data for the purpose of describing or making estimates concerning the whole, or relevant groups or components within, the economy, society, or the natural environment; and

(B) includes the development of methods or resources that support those activities, such as measurement methods, models, statistical classifications, or sampling frames.

(11) STATISTICAL AGENCY OR UNIT.—The term ‘statistical agency or unit’ means an agency or organizational unit of the executive branch whose activities are predominantly the collection, compilation, processing, or analysis of information for statistical purposes, as designated by the Director under section 3562.

(12) STATISTICAL PURPOSE.—The term ‘statistical purpose’—

(A) means the description, estimation, or analysis of the characteristics of groups, without identifying the individuals or organizations that comprise such groups; and

(B) includes the development, implementation, or maintenance of methods, technical or administrative procedures, or information resources that support the purposes described in subparagraph (A).

§ 3562. Coordination and oversight of policies

(a) In general.—The Director shall coordinate and oversee the confidentiality and disclosure policies established by this subchapter. The Director may promulgate rules or provide other guidance to ensure consistent interpretation of this subchapter by the affected agencies. The Director shall develop a process by which the Director designates agencies or organizational units as statistical agencies and units. The Director shall promulgate guidance to implement such process, which shall include specific criteria for such designation and methods by which the Director will ensure transparency in the process.

(b) Agency rules.—Subject to subsection (c), agencies may promulgate rules to implement this subchapter. Rules governing disclosures of information that are authorized by this subchapter shall be promulgated by the agency that originally collected the information.

(c) Review and approval of rules.—The Director shall review any rules proposed by an agency pursuant to this subchapter for consistency with the provisions of this chapter and such rules shall be subject to the approval of the Director.

(d) Reports.—

(1) The head of each agency shall provide to the Director such reports and other information as the Director requests.

(2) Each Designated Statistical Agency (as defined in section 3576(e)) shall report annually to the Director, the Committee on Oversight and Government Reform of the House of Representatives, and the Committee on Homeland Security and Governmental Affairs of the Senate on the actions it has taken to implement section 3576. The report shall include copies of each written agreement entered into pursuant to section 3576(c)(1) for the applicable year.

(3) The Director shall include a summary of reports submitted to the Director under this subsection and actions taken by the Director to advance the purposes of this subchapter in the annual report to Congress on statistical programs prepared under section 3504(e)(2).

§ 3563. Statistical agencies

(a) Responsibilities.—

(1) IN GENERAL.—Each statistical agency or unit shall—

(A) produce and disseminate relevant and timely statistical information;

(B) conduct credible and accurate statistical activities;

(C) conduct objective statistical activities; and

(D) protect the trust of information providers by ensuring the confidentiality and exclusive statistical use of their responses.

(2) POLICIES, BEST PRACTICES, AND PROCEDURES.—Each statistical agency or unit shall adopt policies, best practices, and appropriate procedures to implement the responsibilities described in paragraph (1).

(b) Support from other agencies.—The head of each agency shall enable, support, and facilitate statistical agencies or units in carrying out the responsibilities described in subsection (a)(1).

(c) Regulations.—The Director shall prescribe regulations to carry out this section.

(d) Definitions.—In this section:

(1) ACCURATE.—The term ‘accurate’, when used with respect to statistical activities, means statistics that consistently match the events and trends being measured.

(2) CONFIDENTIALITY.—The term ‘confidentiality’ means a quality or condition accorded to information as an obligation not to disclose that information to an unauthorized party.

(3) OBJECTIVE.—The term ‘objective’, when used with respect to statistical activities, means accurate, clear, complete, and unbiased.

(4) RELEVANT.—The term ‘relevant’, when used with respect to statistical information, means processes, activities, and other such matters likely to be useful to policymakers and public and private sector data users.

§ 3564. Effect on other laws

(a) Title 44, united states code.—This subchapter does not diminish the authority under section 3510 of the Director to direct, and of an agency to make, disclosures that are not inconsistent with any applicable law.

(b) Title 13 and title 44, united states code.—This subchapter does not diminish the authority of the Bureau of the Census to provide information in accordance with sections 8, 16, 301, and 401 of title 13 and section 2108 of this title.

(c) Title 13, united states code.—This subchapter shall not be construed as authorizing the disclosure for nonstatistical purposes of demographic data or information collected by the Bureau of the Census pursuant to section 9 of title 13.

(d) Various energy statutes.—Data or information acquired by the Energy Information Administration under a pledge of confidentiality and designated by the Energy Information Administration to be used for exclusively statistical purposes shall not be disclosed in identifiable form for nonstatistical purposes under—

(1) section 12, 20, or 59 of the Federal Energy Administration Act of 1974 (15 U.S.C. 771, 779, 790h);

(2) section 11 of the Energy Supply and Environmental Coordination Act of 1974 (15 U.S.C. 796); or

(3) section 205 or 407 of the Department of Energy Organization Act (42 U.S.C. 7135, 7177).

(e) Section 201 of Congressional Budget Act of 1974.—This subchapter shall not be construed to limit any authorities of the Congressional Budget Office to work (consistent with laws governing the confidentiality of information the disclosure of which would be a violation of law) with databases of Designated Statistical Agencies (as defined in section 3576(e)), either separately or, for data that may be shared pursuant to section 3576(c) or other authority, jointly in order to improve the general utility of these databases for the statistical purpose of analyzing pension and health care financing issues.

(f) Preemption of state law.—Nothing in this subchapter shall preempt applicable State law regarding the confidentiality of data collected by the States.

(g) Statutes regarding false statements.—Notwithstanding section 3572, information collected by an agency for exclusively statistical purposes under a pledge of confidentiality may be provided by the collecting agency to a law enforcement agency for the prosecution of submissions to the collecting agency of false statistical information under statutes that authorize criminal penalties (such as section 221 of title 13) or civil penalties for the provision of false statistical information, unless such disclosure or use would otherwise be prohibited under Federal law.

(h) Construction.—Nothing in this subchapter shall be construed as restricting or diminishing any confidentiality protections or penalties for unauthorized disclosure that otherwise apply to data or information collected for statistical purposes or nonstatistical purposes, including, but not limited to, section 6103 of the Internal Revenue Code of 1986.

(i) Authority of congress.—Nothing in this subchapter shall be construed to affect the authority of the Congress, including its committees, members, or agents, to obtain data or information for a statistical purpose, including for oversight of an agency’s statistical activities.

PART B—CONFIDENTIAL INFORMATION PROTECTION

§ 3571. Findings The Congress finds the following:

(1) Individuals, businesses, and other organizations have varying degrees of legal protection when providing information to the agencies for strictly statistical purposes.

(2) Pledges of confidentiality by agencies provide assurances to the public that information about individuals or organizations or provided by individuals or organizations for exclusively statistical purposes will be held in confidence and will not be used against such individuals or organizations in any agency action.

(3) Protecting the confidentiality interests of individuals or organizations who provide information under a pledge of confidentiality for Federal statistical programs serves both the interests of the public and the needs of society.

(4) Declining trust of the public in the protection of information provided under a pledge of confidentiality to the agencies adversely affects both the accuracy and completeness of statistical analyses.

(5) Ensuring that information provided under a pledge of confidentiality for statistical purposes receives protection is essential in continuing public cooperation in statistical programs.

§ 3572. Confidential information protection

(a) Purposes.—The purposes of this section are the following:

(1) To ensure that information supplied by individuals or organizations to an agency for statistical purposes under a pledge of confidentiality is used exclusively for statistical purposes.

(2) To ensure that individuals or organizations who supply information under a pledge of confidentiality to agencies for statistical purposes will neither have that information disclosed in identifiable form to anyone not authorized by this subchapter nor have that information used for any purpose other than a statistical purpose.

(3) To safeguard the confidentiality of individually identifiable information acquired under a pledge of confidentiality for statistical purposes by controlling access to, and uses made of, such information.

(b) Use of statistical data or information.—Data or information acquired by an agency under a pledge of confidentiality and for exclusively statistical purposes shall be used by officers, employees, or agents of the agency exclusively for statistical purposes and protected in accordance with such pledge.

(c) Disclosure of statistical data or information.—

(1) Data or information acquired by an agency under a pledge of confidentiality for exclusively statistical purposes shall not be disclosed by an agency in identifiable form, for any use other than an exclusively statistical purpose, except with the informed consent of the respondent.

(2) A disclosure pursuant to paragraph (1) is authorized only when the head of the agency approves such disclosure and the disclosure is not prohibited by any other law.

(3) This section does not restrict or diminish any confidentiality protections in law that otherwise apply to data or information acquired by an agency under a pledge of confidentiality for exclusively statistical purposes.

(d) Rule for use of data or information for nonstatistical purposes.—A statistical agency or unit shall clearly distinguish any data or information it collects for nonstatistical purposes (as authorized by law) and provide notice to the public, before the data or information is collected, that the data or information could be used for nonstatistical purposes.

(e) Designation of agents.—A statistical agency or unit may designate agents, by contract or by entering into a special agreement containing the provisions required under section 3561(2) for treatment as an agent under that section, who may perform exclusively statistical activities, subject to the limitations and penalties described in this subchapter.

(f) Fines and penalties.—Whoever, being an officer, employee, or agent of an agency acquiring information for exclusively statistical purposes, having taken and subscribed the oath of office, or having sworn to observe the limitations imposed by this section, comes into possession of such information by reason of his or her being an officer, employee, or agent and, knowing that the disclosure of the specific information is prohibited under the provisions of this subchapter, willfully discloses the information in any manner to a person or agency not entitled to receive it, shall be guilty of a class E felony and imprisoned for not more than 5 years, or fined not more than $250,000, or both.

Attachment A.2 – BLS Agent Agreement

1. I, BLS Signatory Name, an authorized official of the Bureau of Labor Statistics (BLS), U.S. Department of Labor, hereby designate Name of Agent as a temporary agent of the BLS, within the meaning of the Confidential Information Protection and Statistical Efficiency Act (CIPSEA), (Attachment A), to serve in accordance with this Agent agreement and agreements entered into between the BLS and Name of Contractor, hereinafter “the Contractor,” for BLS-approved statistical activities, and applicable Federal law.

2. I, Name of Agent, hereby accept the designation as agent in paragraph 1. I certify that I have read all applicable agreements between the BLS and the Contractor and promise that I will comply with all provisions of this Agent Agreement, all agreements between the BLS and the Contractor, and applicable law. I will assure that my actions or inactions do not cause the Contractor to violate its responsibilities under those agreements. I specifically swear (or affirm) to comply with all provisions of law that affect information acquired by the BLS, including, but not limited to, CIPSEA, the Privacy Act, the Trade Secrets Act, and the Wagner-Peyser Act, and I understand that my failure to comply with these provisions may subject me to criminal sanctions.

3. We, the parties, understand that the BLS is granting the Agent access to confidential information only for the purpose of carrying out the Agent's responsibilities under written agreements between the BLS and the Contractor. Confidential information includes respondent identifiable information which is protected from unauthorized use or disclosure under CIPSEA. Confidential information may also include pre-release, personally identifiable, and restricted access information. The BLS will grant access only to that confidential information which is necessary to carry out the Agent’s responsibilities under written agreements between the BLS and the Contractor. The Agent will not seek or obtain such confidential information for any other purpose. The Agent will return all confidential information to the BLS, at the request of the BLS. The Agent will return this information to the BLS when the Agent is no longer affiliated with the Contractor or when the Agent has no further responsibilities under these agreements which require access to such information.

4. I, Name of Agent, will perform all activities subject to this agreement under the control of the BLS Contracting Officer Representative or any other BLS official that the BLS designates. I, the Agent, agree to comply with all BLS information policies.

5. We, the parties, understand and agree that the Agent will not be an employee of the United States government, the Department of Labor, or the BLS for any purpose and will not receive compensation or payment of any kind from the BLS, the Department of Labor, or the Government in connection with the Agent's activities under this agreement or any other agreements between the BLS and the Contractor. Neither this agreement nor any agreement between the BLS and the Contractor provides any right of access to BLS information. The parties also understand and agree that the BLS may decline to give the Agent access to information and/or to terminate this agreement at any time, without notice. The parties agree that neither this agreement, nor any termination thereof will result in any legal liability by the BLS, the Department of Labor, or the Government; however, termination will not affect the Agent's continuing obligation to safeguard all confidential information, and it will not affect any license granted to the Government or any intellectual property rights of the public or the Government pursuant to section 6.

6. I, Name of Agent, understand that I will not acquire any property rights or interests in data accessed, used, or provided as a result of activities performed under this agreement.

7. I, Name of Agent, certify that I currently am an employee of the Contractor, and I will notify the BLS if I should no longer be affiliated with the Contractor or of any change of status with the Contractor.

8. I, Name of Agent, fully understand my responsibilities to protect confidential information from unauthorized disclosure. I will comply with all instructions of the BLS with respect to such information and all security requirements and will avoid all improper use or disclosure of confidential information. I will notify the BLS immediately if I become aware of any request or demand for access to confidential information. I understand that under CIPSEA, the penalty for a knowing and willful disclosure of respondent identifiable information is a class E felony with a fine of not more than $250,000 or imprisonment for not more than 5 years, or both.

BLS Signatory Name

Bureau of Labor Statistics

_______________________________
__________________________
Name of Agent
Date

Name of Contractor

Attachment A.3 - BLS Data Collection Integrity Policy

In order to ensure a clear understanding of the policy, all items of data collected (including micro data, registry and contact information, documentation, and coding) are encompassed in the data collection integrity policy. All modes of collection are encompassed in this data collection integrity policy, including Flex-collected cases. Entry of false or unverified information is grounds for immediate dismissal from the contract.

The BLS Data Integrity Policy is outlined below. If you have any questions, please contact your supervisor immediately.

Data Elements

· Notes must accurately reflect all communication with the respondent. Any data entered into a case must have an accurate corresponding case note explaining how and when the data was received (call, voicemail, email, fax, etc.). All other communication with the respondent, including communication about data verification, must be documented with the same level of detail. Case notes must fully reflect information regarding the business or contacts. Do not enter false information in the case notes.

· Collect data for the correct reference period. Payroll Length of Pay (PLP) must be designated.

· Always ask for the employment information for the pay period including the 12th of the month.

· We are ethically bound to collect our figures from each company each month whether there are changes or stability. If a respondent informs you that data are “the same” as last month, you must receive an actual data value from them, specifically verifying each data item. You CANNOT accept the data as “the same” or “no change” without verification, under any circumstances.

· Estimates are unacceptable when a respondent is reporting data. You are expected to collect accurate data; vague approximations are not acceptable.

· You are always to collect all data items directly from the respondent. You are never to assume certain data items based on partial data or past data items collected. You should not calculate raw data information for respondents. It is your job to educate the respondent on how to provide accurate data to you.

Data Elements with Edit or Screening Errors:

· Placing or changing comment codes to clear edit flags without speaking directly with the person who provided the data is strictly prohibited, including Flex-collected cases.

· If a Flex respondent provides a note or comment with their submitted…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .