NARA_TERMS_AND_CONDITIONS_08.20.2018.docx

DOCX document 32 KB Posted

Attached to
Remedy Force Maintenance Federal contract opportunity
Solicitation number
88310318Q00147
Issued by
National Archives and Records Administration

About this file

Terms and conditions

View the file

Other files for this federal contract opportunity

Other files attached to Remedy Force Maintenance, newest first.
File Type Posted
Schedule_of_Prices_Attachment_1_-_BMC_Remedy_Force.docx DOCX document
J_and_A__BMC_Remedy_Force_-_6_302_Just.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFQ: 88310318Q00147

NARA TERMS AND CONDITIONS

(Addenda to FAR 52.212-4, Contract Terms and Conditions)

The following additional terms and conditions are incorporated and are to remain in full force in any resultant contract and associated delivery order(s):

1. GOVERNMENT ORDER ADMINISTRATION

A. This contract will be administered by:

National Archives and Records Administration Acquisitions Branch, Code BCN Room 3340 8601 Adelphi Road College Park, MD 20740-6001

B. Order Administration (Contract Specialist):

Narciso (Marty) Cruz, Contract Specialist Telephone: 301-837-1633 Email: narciso.cruz@nara.gov

The Contracting Officer (CO) has the overall responsibility for the administration of this order. Written communication should be submitted to the Contract Specialist (CS) and the CO, and must make reference to the order number and must be mailed, postage prepaid, to the above address.

C. Contracting Officer (CO): Any Authorized BCN CO

The CO alone, without delegation, is authorized to take actions on behalf of the Government to amend, modify, or deviate from the order terms, conditions, requirements, specifications, details and/or delivery schedules; make final decisions on disputed deductions from order payments for non-conformance; terminate the order for convenience or default; and issue final decisions regarding order questions or matters under dispute. However, the CO may delegate certain other responsibilities to authorized representatives.

2. GOVERNMENT POINT OF CONTACT (POC)

D. The Government POC for this requirement is:

Mr. Narciso Cruz 8601 Adelphi Road, Room 3340 College Park, MD 20740-6001 Telephone: (301) 837-1633 Email: narciso.cruz@nara.gov

3. DELIVERY

Delivery times will be as established in the purchase orders but shall not be sooner than 30 calendar days after receipt of order. Delivery must be made during regular business hours unless mutually agreed upon by NARA and the Contractor. Delivery must be made as ordered, in the specific quantities, to the specified destinations.

Items will be shipped FOB Destination to NARA as shown on Purchase Orders. The Contractor shall be responsible for risk of loss and any damages to items during shipment (see FAR 52.212-4 (j).

4. INVOICE SUBMISSION REQUIREMENTS

A. The preferred method for invoicing is through the Invoice Processing Platform (IPP) which is a secure web-based electronic invoicing and payment information system. This service is provided by the U.S. Treasury’s Bureau of the Fiscal Service free of charge to federal agencies and contractors. IPP allows contractors to view information regarding their contracts and orders, electronically submit invoices and view payment information.

B. The IPP website address is https://www.ipp.gov. Contractors can obtain enrollment assistance by contacting the Fiscal Service Accounts Payable Help Desk via e-mail at AccountsPayable@bpd.treas.gov or by phone at 304-480-8000, Option 7.

C. Contractors that are not able to utilize the IPP system for submitting payment requests may submit invoices electronically by e-mail to NAR@bpd.treas.gov. Microsoft Excel, Adobe Acrobat Portable Document Format (PDF) and Microsoft Word are acceptable formats.

D. Invoices for services shall be submitted monthly unless otherwise stated elsewhere in the contract.

E. For invoice and payment questions call the Fiscal Service AP Help Desk at 304-480-8000, Option 7.

The following additional clauses and provisions are incorporated and are to remain in full force in any resultant fixed price contract and delivery orders:

5. FAR 52.233-2 -- Service of Protest (Sep 2006)

(a) Protests, as defined in section 33.101 of the Federal Acquisition Regulation, that are filed directly with an agency, and copies of any protests that are filed with the Government Accountability Office (GAO), shall be served on the Contracting Officer (addressed as follows) by obtaining written and dated acknowledgment of receipt from National Archives and Records Administration, Acquisitions Branch, Attn: Ms. Ana Camacho, 8601 Adelphi Road, Room 3340, College Park, MD 20740-6001.

(b) The copy of any protest shall be received in the office designated above within one day of filing a protest with the GAO.

(End of Provision) 52.217-8 -- Option to Extend Services.

As prescribed in 17.208(f), insert a clause substantially the same as the following:

Option to Extend Services (Nov 1999) The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by written notice to the Contractor within 60 days.

(End of Clause) 52.217-9 -- Option to Extend the Term of the Contract.

As prescribed in 17.208(g), insert a clause substantially the same as the following:

Option to Extend the Term of the Contract (Mar 2000)

(a) The Government may extend the term of this contract by written notice to the Contractor within 30 day; provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 60 days before the contract expires. The preliminary notice does not commit the Government to an extension.

(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.

(c) The total duration of this contract, including the exercise of any options under this clause, shall not exceed 24 months (End of Clause)

6. FAR 52.242-15, STOP-WORK ORDER (AUG 1989)

(a) The Contracting Officer may, at any time, by written order to the Contractor, require the Contractor to stop all, or any part, of the work called for by this contract for a period of 90 days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 days after a stop-work is delivered to the Contractor, or within any extension of that period to which the parties shall have agreed, the Contracting Officer shall either --

(1) Cancel the stop-work order; or

(2) Terminate the work covered by the order as provided in the Default, or the Termination for Convenience of the Government, clause of this contract.

(b) If a stop-work order issued under this clause is canceled or the period of the order or any extension thereof expires, the Contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule or contract price, or both, and the contract shall be modified, in writing, accordingly, if --

(1) The stop-work order results in an increase in the time required for, or in the Contractor’s cost properly allocable to, the performance of any part of this contract; and

(2) The Contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage; provided that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and act upon the claim submitted at any time before final payment under this contract.

(c) If a stop-work order is not canceled and the work covered by the order is terminated for the convenience of the Government, the Contracting Officer shall allow reasonable costs resulting from the stop-work order in arriving at the termination settlement.

(d) If a stop-work order is not canceled and the work covered by the order is terminated for default, the Contracting Officer shall allow, by equitable adjustment or otherwise, reasonable costs resulting from the stop-work order.

7. STOP WORK CANCELLATION (APRIL 2014)

The Contractor is required to report to work and resume full contract performance within six (6) hours of receiving notifications of the stop work cancellation unless otherwise instructed by the CO and/or COR.

8. 52.252-2 -- Clauses Incorporated by Reference (Feb 1998) This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):

http://farsite.hill.af.mil or https://www.acquisition.gov/far/ (End of Clause

9. RECORDS MANAGEMENT OBLIGATIONS (Jun 2017) A. Applicability This clause applies to all Contractors whose employees create, work with, or otherwise handle Federal records, as defined in Section B, regardless of the medium in which the record exists.

B. Definitions “Federal record” as defined in 44 U.S.C. § 3301, includes all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.

The term Federal record:

1. includes NARA records.

1. does not include personal materials.

1. applies to records created, received, or maintained by Contractors pursuant to their NARA contract.

1. may include deliverables and documentation associated with deliverables.

C. Requirements

1. Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.

1. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.

1. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.

1. NARA and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of NARA or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to NARA. The agency must report promptly to NARA in accordance with 36 CFR 1230.

1. The Contractor shall immediately notify the appropriate Contracting Officer upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the [contract vehicle]. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to NARA control or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the Contracting Officer or address prescribed in the [contract vehicle]. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).

1. The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and NARA guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.

1. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with NARA policy.

1. The Contractor shall not create or maintain any records containing any non-public NARA information that are not specifically tied to or authorized by the contract.

1. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.

1. The NARA owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which NARA shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.

1. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take NARA-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training.

[Note: To the extent an agency requires contractors to complete records management training, the agency must provide the training to the contractor.] D. Flowdown of requirements to subcontractors

1. The Contractor shall incorporate the substance of this clause, its terms and requirements including this paragraph, in all subcontracts under this [contract vehicle], and require written subcontractor acknowledgment of same.

1. Violation by a subcontractor of any provision set forth in this clause will be attributed to the Contractor.

10. SECURITY OF INFORMATION AND PROTECTION OF CONTROLLED UNCLASSIFIED INFORMATION, INCLUDING PERSONALLY IDENTIFIABLE INFORMATION (APRIL 2017)

(a) Applicability

This clause applies to all controlled unclassified information, which may include personally identifiable information, as defined in Section B, regardless of the medium in which it is found and includes paper records.

(b) Definitions. As used in this clause:

“Breach” means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to personally identifiable information, in usable form whether physical or electronic.

“Controlled Unclassified Information” means information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or Government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic; requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.

“Personally identifiable information (PII)” means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States. Examples of PII include the following:

(1) Name.

(2) Date of birth.

(3) Mailing address.

(4) Telephone number.

(5) Social Security Number.

(6) Email address.

(7) Zip code.

(8) Account numbers.

(9) Certificate/license numbers.

(10) Vehicle identifiers including license plates.

(11) Uniform resource locators (URLs).

(12) Internet protocol addresses.

(13) Biometric identifiers (e.g., fingerprints).

(14) Photographic facial images.

(15) Any other unique identifying number or characteristic.

(16) Any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive personally identifiable information (sensitive PII)” means a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.

(1) Complete social security numbers, alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered sensitive PII even if they are not coupled with additional PII.

(2) Additional examples include any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:

(i) Driver’s license number, passport number, or truncated social security number (such as last 4 digits);

(ii) Date of birth (month, day, and year);

(iii) Citizenship or immigration status;

(iv) Financial information such as account numbers or electronic funds transfer information;

(v) Medical information; and/or

(vi) System authentication information such as mother’s maiden name, account passwords or personal identification numbers.

(3) Other PII may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but it is not sensitive.

(c) Data Security.

(1) The Vendor shall limit access to the data covered by this clause to those employees and subcontractor who require the information in order to perform their official duties under this task order.

(2) The Vendor employees, and subcontractors must physically or electronically secure CUI, which may include sensitive PII, when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss.

(3) When CUI is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed in accordance with NIST 800-88 standards.

(4) The Vendor shall only use CUI obtained under this task order for purposes of the Vendor; it shall not be disclosed, released, disseminated, or published without the prior written consent of the Contracting Officer.

(5) If it is established elsewhere in this task order that information to be utilized under this task order, or a portion thereof, is subject to the Privacy Act, The Vendor shall follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

(6) At expiration or termination of this task order, the Vendor shall turn over all CUI obtained under the Vendor that is in its possession.

(d) Systems Access. Work to be performed under this task order may require the handling of CUI, including PII. The Vendor shall provide the Government access to, and information regarding those systems handling CUI, including sensitive PII for the Government under the Vendor, when requested by the Government, as part of the Vendor’s responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the Government in assuring compliance with such requirements. Government access shall include independent testing of controls, system penetration testing by the Government, Federal Information Security Management Act data reviews, and access by agency Inspectors General (IG) for IG reviews.

When requested by the NARA CO or COR or other NARA official as described herein, in connection with NARA’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of NARA Information, Vendor shall provide NARA, including the NARA OIG, (1) access to any and all information and records, including electronic information, regarding a Covered Information System, and (2) physical access to Vendor's facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by NARA or agents acting on behalf of NARA, and such access shall be provided within 72 hours of the request. Additionally, the Vendor shall cooperate with NARA’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of NARA information.

(e) Systems Security.

(1) In performing its duties related to management, operation, and/or access of systems containing PII under this task order, the Vendor, its employees and subcontractors shall comply with all applicable security requirements and rules of conduct applicable to the agency’s systems as described in:

a) NARA Directive 1608 http://www.archives.gov/foia/directives/nara1608.pdf and

b) FedRAMP baseline controls for moderate IT systems.

(2) In addition, the use of Vendor-Owned laptops or other portable storage devices to process or store sensitive PII is prohibited under this task order until the Vendor provides, and the Contracting Officer, in coordination with the Senior Agency Official for Privacy (SAOP) or the SAOP’s designee, approves the Vendor’s written acknowledgment that the following requirements are met:

(i) Laptops and other portable storage devices must employ encryption that is NIST Federal Information Processing Standard (FIPS) 140-2 validated (or its successor) http://csrc.nist.gov/publications/PubsFIPS.html, and approved.

(ii) The Vendor has developed and implemented a process to ensure that security and other applications software are kept current.

(iii) Mobile computing devices utilize anti-virus software and a host-based firewall mechanism.

(iv) Removable media, such as hard drives, flash drives, devices with flash memory, CDs and floppy disks containing CUI, which may include sensitive PII shall not be removed from a Government facility unless they are encrypted using a NIST FIPS 140-2 or successor approved product.

(v) When no longer needed, all removable media, hard drives, and flash memory shall be destroyed in accordance with Government security requirements identified in NARA’s Media Protection Methodology.

(vi) The Vendor shall maintain an accurate inventory of devices used in the performance of this task order.

(3) All NARA information obtained under this task order shall be removed from Vendor-Owned information technology assets at the direction of the Contracting Officer or Contracting Officer’s Representative. Removal must be accomplished in accordance with standard FedRAMP controls for media protection in moderate IT systems and NIST 800-88 standards. Certification of data removal will be performed by the Vendor’s Project Manager and written notification confirming acknowledgment will be delivered to the Contracting Officer within 30 days of the direction to remove the information.

(4) Back up or mirrors of any systems or files containing CUI shall be treated in the same manner as the original data containing CUI, with the same protections and obligations.

(5) The Vendor shall require FIPS 140-2 (or successor) encryption of any sensitive PII when transmitted electronically across the Internet or other public works.

(f) Breach Notification to Government.

(1) The Vendor has been provided with: NARA Directive 1608, and is aware of its roles, responsibilities, and relationship with the Government in case of data breach.

(2) In the event of any actual or suspected breach of sensitive PII, the Vendor shall immediately, and in no event later than one hour of discovery, report the breach to the Contracting Officer, the COR, the Senior Agency Official for Privacy (currently NARA’s General Counsel garymstern@nara.gov) and the Chief Information Officer (only for IT requirements) in accordance with NARA Directive 1608.

(3) The Vendor is responsible for positively verifying that notification is received and acknowledged by appropriate Government parties identified in subparagraph (2) above.

(4) In the event of a confirmed, potential or suspected Security Breach, involving unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any NARA Information accessed by, retrievable from, processed by stored on, or transmitted within, to or from any such system, Vendor shall immediately (and in no event later than within 1 hour of discovery) report any Confirmed Breach to the NARA CO and the CO's Representative (''COR").

(5) NARA, at its sole discretion, may obtain, and Vendor will permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any security incident, PII or Security Breach. Additionally. NARA, at its sole discretion, may require Vendor to retain, at Vendor's expense, a Third Party Assessing Organization (3PAO) acceptable to NARA, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.

(6) Any report submitted in accordance with paragraphs (1), (2) and (3) above, shall identify (I) both the Information Systems and NARA Information involved or at risk, including the type, amount, and level of sensitivity of the NARA Information and, if the NARA Information contains PII, the estimated number of unique instances of Pll, (2) all steps and processes being undertaken by Vendor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the USCERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by the NARA. Vendor shall continue to provide written updates to the NARA CO regarding the status of the Security incident at least every three (3) calendar days until informed otherwise by the NARA CO.

(7) Response activities related to any security incident or PII or Security Breach undertaken by NARA, including activities undertaken by Vendor, other federal agencies, and any third-party contractors or firms at the request or direction of NARA, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the Security Incident and/or liability for any additional response activities. Vendor shall be responsible for all costs and related resource a locations required for all such response activities related to any Security Incident or Breach, including the cost of any penetration testing.

(g) Personally Identifiable Information Notification Requirement Vendor certifies that it has a security policy in place that contains procedures to promptly notify any individual whose Personally Identifiable Information ("Pll") was, or is reasonably determined by NARA to have been, compromised. Any notification shall be coordinated with the NARA CO and shall not proceed until NARA has made a determination that notification would not impede a law enforcement investigation or jeopardize national security. The method and content of any notification by Vendor shall be coordinated with, and subject to the approval of, NARA. Vendor shall be responsible for taking corrective action consistent with NARA Data Breach Notification Procedures and as directed by the NARA CO, including all costs and expenses associated already covered by above clauses added in PII clause with such corrective action, which may include providing credit monitoring to any individuals whose Pll was actually or potentially compromised.

All determinations regarding whether and when to notify individuals and/or federal agencies potentially affected by a Security Incident, Breach, or PII Breach will be made by NARA senior officials at NARA’s discretion.

(h) Flowdown of security requirements to subcontractors.

(1) The Vendor shall incorporate the substance of this clause, its terms and requirements including this paragraph (g), in all subcontracts under this task order, and require written subcontractor acknowledgement of same.

(2) Violation by a subcontractor of any provision set forth in this clause will be attributed to the Vendor.

11. CONFIDENTIALITY OF INFORMATION

1. Confidential information is any information that, if subject to unauthorized access, modification, loss, or misuse could adversely affect the national interest, the conduct of Federal programs, or the privacy of individuals, but has not been specifically authorized under criteria established by an Executive Order or an Act of Congress to be kept secret in the interest of national defense or foreign policy. Confidential information also includes proprietary data and information for which other restrictions on access apply.

1. The Contracting Officer and the Contractor may, by mutual consent, identify elsewhere in this contract specific information and/or categories of information which the Government will furnish to the Contractor or that the Contractor is expected to generate which is confidential. Similarly, the Contracting Officer and the Contractor may, by mutual consent, identify such confidential information from time to time during the performance of the contract. Failure to agree will be settled pursuant to the “Disputes” clause.

1. While in the course of performance of this Contract, the Contractor may have access to confidential information and communications, including but not limited to Personally Identifiable Information (PII). Confidential information may be contained in printed material or on electronic media. The Contractor will preserve the confidentiality of all such information and communications and agrees not to disclose, release, disseminate, or publish any such information or communications for any purposes whatsoever without the prior approval of the Contracting Officer. Failure to comply with the provisions of this Paragraph will be grounds for Termination for Default and the Contractor may be liable for damages. This provision shall survive the expiration or termination of the period of performance of this Contract.

1. If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, the Contractor will follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

1. During the course of the performance of this Contract, the Contractor may have access to and use of data and information which may be considered proprietary by other contractors, or which may otherwise be of such a nature that its dissemination or use, other than in performance of this Contract, would be adverse to the interest of NARA and these other contractors.

1. Except as may be otherwise agreed to with these other contractors, the Contractor agrees that it will not use, disclose or reproduce proprietary data and information belonging to these other contractors other than as required in the performance of this Contract; provided, however, that nothing herein shall be construed as: (1) precluding the use of any such data or information independently acquired by the Contractor without such limitation; or (2) prohibiting an agreement at no cost to NARA between the Contractor and these contractors which provides for greater rights to the Contractor.

1. When considering a request to disclose, release, disseminate, or publish confidential information, the Contracting Officer will consult with appropriate program and legal officials.

1. At the discretion of the Contracting Officer, the Contractor’s employees may be required to sign a non-disclosure agreement prior to performing any work under this contract.

1. The terms of this paragraph apply to all Contractor employees, subcontractors and consultants and must be incorporated into any subcontract.

File details come from the government source that posted it.