D01 - 15DDHQ24P00000175 (Award).pdf

PDF 841 KB Posted

Attached to
Nikon Camera Equipment/Accessories Federal contract opportunity
Solicitation number
D-24-ST-0046
Issued by
Department of Justice Drug Enforcement Administration

About this file

This award notice documents a contract awarded by the Department of Justice Drug Enforcement Administration to Deal Solutions LLC for Nikon camera equipment, accessories, and related items. The firm fixed price contract was awarded on January 17, 2024 for a total of $93,096.80 to fulfill Quote #DS-00001 dated December 20, 2023. The awarded supplies include Nikon D7500 cameras, Sigma camera lenses, memory cards, camera bags, and other accessories. The contractor will assemble, pack, and dispose of packaging for the camera kits.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

15DDHQ24P00000175 Page 1 of 10

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

NOTE: OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24 AND 30.

1. REQUISITION NUMBER

D-24-ST-0046

PAGE 1 OF

5. SOLICITATION NUMBER2. CONTRACT NUMBER 3. AWARD/EFFECTIVE

DATE

01/16/2024

4. ORDER NUMBER 6. SOLICITATION ISSUE

DATE

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME b. TELEPHONE NUMBER (No collect calls) 8. OFFER DUE DATE / LOCAL

TIME

CODE 15DDHQ

DEA

Attn: Office of Acq & Relo Mgmt (FA)

8701 Morrissette Drive

Springfield, VA 22152-1080

9. ISSUED BY X UNRESTRICTED OR SET ASIDE: % FOR

SMALL BUSINESS

HUBZONE SMALL

BUSINESS

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

(SDVOSB)

WOMEN-OWNED SMALL

BUSINESS (WOSB)

ECONOMICALLY DISADVANTAGED

WOMEN-OWNED SMALL BUSINESS

(EDWOSB)

8(A)

NORTH AMERICAN

INDUSTRY CLASSIFICATION

STANDARD (NAICS):

SIZE STANDARD:

10. THE ACQUISITION IS

SEE SCHEDULE

11. DELIVERY FOR FREE ON BOARD

(FOB) DESTINATION UNLESS

BLOCK IS MARKED

NET 30

12. DISCOUNT TERMS

13a. THIS CONTRACT IS A

RATED ORDER UNDER THE

DEFENSE PRIORITIES AND

ALLOCATIONS SYSTEM -

DPAS (15 CFR 700)

13b. RATING

X REQUEST

FOR QUOTE

(RFQ)

INVITATION

FOR BID

(IFB)

REQUEST

FOR

PROPOSAL

(RFP)

14. METHOD OF SOLICITATION

15DDSTCODE15. DELIVER TO

DEA - Office of Investigative Technology 10555 Furnace Rd Lorton, VA 22079-2616

CODE16. ADMINISTERED BY

FACILITY

CODE

CODE

TELEPHONE NUMBER

17a. CONTRACTOR/

OFFEROR

DEAL SOLUTIONS LLC

5099 MAPLEWOOD DR

COLUMBUS, OH 43231 UEI: VEFPGVCBMKW9

D-HQCODE18a. PAYMENT WILL BE MADE BY

DEA

Attn: Office of Investigative Tech (ST) Invoice.InvestTech@dea.gov Springfield, VA 22152

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN

OFFER SEE ADDENDUM

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

Delivery Date: 03/08/2024

Quote #DS-00001 dated 12/20/2023 is hereby incorporated into this firm-fixed priced (FFP) purchase order (PO).

See Continuation Sheet(s) (Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

DEA-2024-2024-S1D-ST-2335341-DOM-G2-FLS-31043-ST028-TRNG-2335341-2024

26. TOTAL AWARD AMOUNT (For Government Use Only)

$93,096.80 27a. SOLICITATION INCORPORATES BY REFERENCE (FEDERAL ACQUISITION REGULATION) FAR 52.212-1, 52.212-4. FAR 52.212-3

AND 52.212-5 ARE ATTACHED. ADDENDA

ARE ARE NOT ATTACHED

X 27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN ____ COPIES TO

ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DELIVER ALL ITEMS SET FORTH

OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL SHEETS SUBJECT TO THE

TERMS AND CONDITIONS SPECIFIED

29. AWARD OF CONTRACT: REFERENCE __________________

OFFER DATED __________________ . YOUR OFFER ON SOLICITATION

(BLOCK 5) INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH

HEREIN, IS ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED 31b. NAME OF THE CONTRACTING OFFICER (Type or print)

Mahafkey, Kaitlyn

31c. DATE SIGNED

01/16/2024

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION IS NOT USABLE

STANDARD FORM 1449 (REV. 11/2021)

Prescribed by GSA - FAR (48 CFR) 53.212

15DDHQ24P00000175

x

15DDHQ24P00000175 Page 2 of 10

19.

ITEM NUMBER

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: _________________________________

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

PARTIAL FINAL

33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED

CORRECT FOR

COMPLETE PARTIAL FINAL

36. PAYMENT 37. CHECK NUMBER

38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY

41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE

42b. RECEIVED AT (Location)

42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS

STANDARD FORM 1449 (REV. 11/2021) BACK

15DDHQ24P00000175 Page 3 of 10

Section 1 - Commodity or Services Schedule

SCHEDULE OF SUPPLIES/SERVICES

CONTINUATION SHEET

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0001 Nikon D7500 DSLR Camera (Body Only)

PSC: 6780

20 EA $945.00000 $18,900.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0002 Sigma 70 - 200 f/2.8 DG OS HSM Sport Lens for Nikon F

PSC: 6780

20 EA $1,344.00000 $26,880.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0003 Sigma 150 - 600 f/5 - 6.3 Di VC USD G2 for Nikon F

PSC: 6780

20 EA $945.00000 $18,900.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0004 Polar Pro 95mm Quartz Circular Polarizer

PSC: 6780

20 EA $94.00000 $1,880.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0005 Format Hitech 82mm Hi Def Circular Schott-Desag B270

PSC: 6780

20 EA $96.00000 $1,920.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0006 Tiffen 95mm Coarse Thread UV Filter

PSC: 6780

20 EA $57.00000 $1,140.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0007 Tiffen 82 mm UV Filter

PSC: 6780

20 EA $13.00000 $260.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0008 Vello Wireless Shutter Boss 4.0

PSC: 6780

20 EA $64.95000 $1,299.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0009 Nikon EN-EL 15c Rechargeable Lithium-Ion for D7500

PSC: 6780

20 EA $60.00000 $1,200.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0010 ProGrade Digital 128GB UHS-II microSDXC Memory Card with SD Adapter (2-Pack)

PSC: 6780

20 EA $47.89000 $957.80

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0011 Pelican 0915 Memory Card Case for 12 SD 6 miniSD, and 6 microSD Cards (Black)

PSC: 6780

20 EA $30.00000 $600.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0012 Benro Carbon Fiber Three Series Travel Tripod with VX30 Head

PSC: 6780

20 EA

15DDHQ24P00000175 Page 4 of 10

$494.00000 $9,880.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0013 Box of 4 AAA Batteries for Shutter Boss remote and receiver

PSC: 6780

20 EA $4.00000 $80.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0014 Manfrotto ARCA & RC2 Aluminum Plate

PSC: 6780

40 EA $30.00000 $1,200.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0015 LowePro ProTactic BP 450AW II Camera and Laptop Backpack (Black or Grey/OLive)

PSC: 6780

20 EA $300.00000 $6,000.00

ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT

0016 Vendor will assemble and pack kits. Dispose of package materials.

PSC: 6780

20 EA $100.00000 $2,000.00

TOTAL $93,096.80

FUNDING DETAILS:

ITEM NO. FUNDING LINE OBLIGATED AMOUNT ACCOUNTING CODES

N/A 1 $93,096.80 DEA-2024-2024-S1D-ST-2335341-DOM-G2-FLS-31043-ST028-TRNG-2335341-2024

TOTAL: $93,096.80

15DDHQ24P00000175 Page 5 of 10

Section 2 - Contract Clauses

Clauses By Reference

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es): www.acquisition.gov

Clause Title Fill-ins (if applicable)

52.204-23 Prohibition on Contracting for Hardware, Software, and

Services Developed or Provided by Kaspersky Lab

Covered Entities (Dec 2023)

52.204-25 Prohibition on Contracting for Certain

Telecommunications and Video Surveillance Services or

Equipment (Nov 2021)

Clauses By Full Text

DOJ-02 Contractor Privacy Requirements (JAN 2022)

A. Limiting Access to Privacy Act and Other Sensitive Information

(1) Privacy Act Information

In accordance with FAR 52.224-1 Privacy Act Notification (APR 1984) and FAR 52.224-2 Privacy Act (APR 1984), if this contract requires Contractor personnel to have access to information protected by the Privacy Act of 1974, the contractor is advised that the relevant DOJ system of records notices (SORNs) applicable to this Privacy Act information may be found at https://www.justice.gov/opcl/doj-systems-records.[1] Applicable SORNs published by other agencies may be accessed through those agencies’ websites or by searching the Federal Digital System (FDsys) available at http://www.gpo.gov/fdsys/. SORNs may be updated at any time.

(2) Prohibition on Performing Work Outside a Government Facility/Network/Equipment

Except where use of Contractor networks, IT, other equipment, or Workplace as a Service (WaaS) is specifically authorized within this contract, the Contractor shall perform all tasks on authorized Government networks, using Government-furnished IT and other equipment and/or WaaS and Government information shall remain within the confines of authorized Government networks at all times. Any handling of Government information on Contractor networks or IT must be approved by the Senior Component Official for Privacy of the component entering into this contract. Except where remote work is specifically authorized within this contract, the Contractor shall perform all tasks described in this document at authorized Government facilities; the Contractor is prohibited from performing these tasks at or removing Government-furnished information to any other facility; and Government information shall remain within the confines of authorized Government facilities at all times. Contractors may only access

15DDHQ24P00000175 Page 6 of 10 classified materials on government furnished equipment in authorized government owned facilities regardless of remote work authorizations.

(3) Prior Approval Required to Hire Subcontractors

The Contractor is required to obtain the Contracting Officer's approval prior to engaging in any contractual relationship (Subcontractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under or relating to this contract. The Contractor (and any Subcontractor) is required to abide by Government and Agency guidance for protecting sensitive and proprietary information.

(4) Separation Checklist for Contractor Employees

The Contractor shall complete and submit an appropriate separation checklist to the Contracting Officer before any employee or Subcontractor employee terminates working on the contract. The Contractor must submit the separation checklist on or before the last day of employment or work on the contract. The separation checklist must verify: (1) return of any Government-furnished equipment; (2) return or proper disposition of personally identifiable information (PII)[2], in paper or electronic form, in the custody of the employee or Subcontractor employee including the sanitization of data on any computer systems or media as appropriate; and (3) termination of any technological access to the Contractor’s facilities or systems that would permit the terminated employee’s access to PII or other sensitive information.

In the event of adverse job actions resulting in the dismissal of a Contractor or Subcontractor employee before the separation checklist can be completed, the Prime Contractor must notify the Contracting Officer within 24 hours and confirm receipt of the notification. In the case the Contractor is unable to notify the Contracting Officer, then the Contractor should notify the Contract Officer’s Representative (COR).

Contractors must complete the separation checklist with the Contracting Officer or COR by returning all Government-furnished property including, but not limited to, computer equipment, media, credentials and passports, smart cards, mobile devices, Personal Identity Verification (PIV) cards, calling cards, and keys and terminating access to all user accounts and systems. Unless the Contracting Officer requests otherwise, the relevant Program Manager or other Key Personnel designated by the Contracting Officer or COR may facilitate the return of equipment.

B. Privacy Training, Safeguarding, and Remediation

(1) Required Security and Privacy Training for Contractors

The Contractor must ensure that all employees take appropriate privacy training, including Subcontractors who have access to PII as well as the creation, use, dissemination and/or destruction of PII at the outset of the employee’s work on the contract and every year thereafter. Training must include procedures on how to properly handle PII, including heightened security requirements for the transporting or transmission of sensitive PII, and reporting requirements for a suspected breach or loss of PII. These courses, along with more information about DOJ security and training requirements for Contractors, are available at https://www.justice.gov/jmd/learndoj.

The Federal Information Security Modernization Act of 2014 (FISMA) requires all individuals accessing DOJ information to complete training on records management, cybersecurity awareness, and information system privacy awareness. Contractor employees are required to sign the “Privacy Rules of Behavior,” acknowledging and agreeing to abide by privacy law, policy, and certain privacy safeguards, prior to accessing DOJ information. These Rules of Behavior are made available to all new users of DOJ’s computer network and to trainees at the conclusion of DOJ-OPCL-CS-0005.

The Contractor should maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required privacy and cybersecurity training.

(2) Safeguarding PII Requirements

Contractor employees must comply with DOJ Order 0904 and other guidance published to the publicly-available Office of Privacy and Civil Liberties (OPCL) Resources page[3] relating to the safeguarding of PII, including the use of additional controls to safeguard sensitive PII (e.g., the encryption of sensitive PII). This requirement flows down from the Prime Contractor to all Subcontractors and lower tiered subcontracts.

15DDHQ24P00000175 Page 7 of 10

(3) Non-Disclosure Agreement Requirement

Prior to commencing work, all Contractor personnel that may have access to PII or other sensitive information shall be required to sign a Non-Disclosure Agreement (NDA) and the DOJ IT Rules of Behavior. The Non-Disclosure Agreement:

(a) prohibits the Contractor from retaining or divulging any PII or other sensitive information, or derivatives therefrom, furnished by the Government or to which they may otherwise come in contact as a result of their performance of work under the contract/task order that is otherwise not publicly available, whether or not such information has been reduced to writing; and

(b) requires the Contractor to report any loss of control, compromise, unauthorized disclosure, or unauthorized acquisition of PII or other sensitive information to the component-level or headquarters Security Operations Center within one (1) hour of discovery.

The Contractor should maintain signed copies of the NDA for all employees as a record of compliance. The Contractor should also provide copies of each employee’s signed NDA to the Contracting Officer before the employee may commence work under the contract/task order.

(4) Prohibition on Use of PII in Vendor Billing and Administrative Records

The Contractor’s invoicing, billing, and other financial or administrative records or databases is not authorized to regularly store or include any sensitive PII or other confidential government information that is created, obtained, or provided during the performance of the contract without the written permission of the Senior Component Official for Privacy (SCOP). It is acceptable to list the names, titles and contact information for the Contracting Officer, COR, or other personnel associated with the administration of the contract in the invoices as needed.

(5) Reporting Actual or Suspected Data Breach

Contractors must report any actual or suspected breach of PII within one hour of discovery.[4] A “breach” is an incident or occurrence that involves the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where: (1) a person other than an authorized user accesses or potentially accesses PII or (2) an authorized user accesses or potentially accesses PII for an other than authorized purpose.

The report of a breach must be made to DOJ. The Contractor must cooperate with DOJ’s inquiry into the incident and efforts to minimize risks to DOJ or individuals, including remediating any harm to potential victims.

(a) The Contractor must develop and maintain an internal process by which its employees and Subcontractors are trained to identify and report the breach, consistent with DOJ Instruction 0900.00.01[5], Reporting and Response Procedures for a Breach of Personally Identifiable Information.

(b) The Contractor must report any such breach by its employees or Subcontractors to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000); Component-level Security Operations Center and Component-level Management Team, where appropriate; the COR; and the Contracting Officer within one (1) hour of the initial discovery.

(c) The Contractor must provide a written report to the DOJ Security Operations Center (dojcert@usdoj.gov, 202-357-7000) within 24 hours of discovery of the breach by its employees or Subcontractors. The report must contain the following information:

(i) Narrative or detailed description of the events surrounding the suspected loss or compromise of information.[6] Date, time, and location of the incident.

(ii) Amount, type, and sensitivity of information that may have been lost or compromised, accessed without authorization, etc.

(iii) Contractor’s assessment of the likelihood that the information was compromised or lost and the reasons behind the assessment.[7]

(iv) Names and classification of person(s) involved, including victim, Contractor employee/Subcontractor and any witnesses.

(v) Cause of the incident and whether the company’s security plan was followed and, if not, which specific provisions were not followed.[8]

15DDHQ24P00000175 Page 8 of 10

(vi) Actions that have been or will be taken to minimize damage and/or mitigate further compromise.

(vii) Recommendations to prevent similar situations in the future, including whether the security plan needs to be modified in any way and whether additional training may be required.

(d) The Contractor shall provide full access and cooperation for all activities determined by the Government to be required to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

(e) At the Government’s discretion, Contractor employees or Subcontractor employees may be identified as no longer eligible to access PII or to work on that contract based on their actions related to the loss or compromise of PII.

(6) Victim Remediation

At DOJ’s request, the Contractor is responsible for notifying victims and providing victim remediation services in the event of a breach of PII held by the Contractor, its agents, or its Subcontractors, under this contract. Victim remediation services shall include at least 18 months of credit monitoring and, for serious or large incidents as determined by the Government, call center help desk services for the individuals whose PII was lost or compromised. When DOJ requests notification, the Department Chief Privacy and Civil Liberties Officer and SCOP will direct the Contractor on the method and content of such notification to be sent to individuals whose PII was breached. By performing this work, the Contractor agrees to full cooperation in the event of a breach.

The Contractor should be self-insured to the extent necessary to handle any reasonably foreseeable breach, with another source of income, to fully cover the costs of breach response, including but not limited to victim remediation.

C. Government Records Training, Ownership, and Management

(1) Records Management Training and Compliance

(a) The Contractor must ensure that all employees and Subcontractors that have access to PII as well as to those involved in the creation, use, dissemination and/or destruction of PII take the DOJ Records and Information Training for New Employees (RIM) training course or another training approved by the Contracting Officer or COR.

This training will be provided at the outset of the Subcontractor’s/employee’s work on the contract and every year thereafter. The Contractor shall maintain copies of certificates as a record of compliance and must submit an email notification annually to the COR verifying that all employees working under this contract have completed the required records management training.

(b) The Contractor agrees to comply with Federal and Agency records management policies, including those policies associated with the safeguarding of records containing PII and those covered by the Privacy Act of 1974. These policies include the preservation of all records created or received regardless of format, mode of transmission, or state of completion.

(2) Records Creation, Ownership, and Disposition

(a) The Contractor shall not create or maintain any records not specifically tied to or authorized by the contract using Government IT equipment and/or Government records or that contain Government Agency information.

The Contractor shall certify, in writing, the appropriate disposition or return of all Government information at the conclusion of the contract or at a time otherwise specified in the contract. In accordance with 36 CFR 1222.32, the Contractor shall maintain and manage all Federal records created in the course of performing the contract in accordance with Federal law. Records may not be removed from the legal custody of DOJ or destroyed except in accordance with the provisions of the agency records schedules.

(b) Except as stated in the Performance Work Statement and, where applicable, the Contractor’s Commercial License Agreement, the Government Agency owns the rights to all electronic information (electronic data, electronic information systems or electronic databases and all supporting documentation and associated metadata created as part of this contract. All deliverables (including all data and records) under the contract are the property of the U.S. Government and may be considered federal records, for which the Agency shall have unlimited rights to use, dispose of, or disclose such data contained therein. The Contractor must deliver sufficient technical documentation with all data deliverables to permit the agency to use the data.

15DDHQ24P00000175 Page 9 of 10

(c) The Contractor shall not retain, use, sell, disseminate, or dispose of any government data/records or deliverables without the express written permission of the Contracting Officer or Contracting Officer’s Representative. The Agency and its contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. § 2701. Records may not be removed from the legal custody of the Agency or destroyed without regard to the provisions of the Agency records schedules.

D. Data Privacy and Oversight

(1) Restrictions on Testing or Training Using Real Data Containing PII

The use of real data containing PII from any source for testing or training purposes is generally prohibited. The Contractor shall use synthetic or de-identified real data for testing or training whenever feasible.

(2) Requirements for Contractor IT Systems Hosting Government Data

The Contractor is required to obtain an Authority To Operate (ATO) for any IT environment owned or controlled by the Contractor or any Subcontractor on which Government data shall reside for the purposes of IT system development, design, data migration, testing, training, maintenance, use, or disposal.

(3) Requirement to Support Privacy Compliance

(a) If this contract requires the development, maintenance or administration of information technology[9], the Contractor shall support the completion of the Initial Privacy Assessment (IPA) document, if requested by Department personnel. An IPA is the first step in a process to identify potential privacy issues and mitigate privacy risks. The IPA asks basic questions to help components assess whether additional privacy protections may be needed in designing or implementing a project[10] to mitigate privacy risks, and whether compliance work may be needed. Upon review of the IPA, the OPCL determines whether a Privacy Impact Assessment (PIA) document and/or SORN, or modifications thereto, are required. The Contractor shall provide adequate support to complete the applicable risk assessment and PIA document in a timely manner, and shall ensure that project management plans and schedules include the IPA, PIA, and SORN (to the extent required) as milestones. Additional information on the privacy compliance process at DOJ, including IPAs, PIAs, and SORNs, is located on the DOJ OPCL website (https://dojnet.doj.gov/privacy/), including DOJ Order 0601, Privacy and Civil Liberties. The Privacy Impact Assessment Guidance and Template outline the requirements and format for the PIA.

(b) If the contract involves an IT system build or substantial development or changes to an IT system that may require privacy risk assessment and documentation, the Contractor shall provide adequate support to DOJ to ensure DOJ can complete any required assessment, and IPA, PIA, SORN, or other supporting documentation to support privacy compliance. The Contractor shall work with personnel from the program office, OPCL, the Office of the Chief Information Officer (OCIO), and the Office of Records Management and Policy to ensure that the privacy assessments and documentation are kept on schedule, that the answers to questions in the documents are thorough and complete, and that questions asked by the OPCL and other offices are answered in a timely fashion.

The Contractor must ensure the completion of required PIAs and documentation of privacy controls consistent with federal law and standards, e.g. NIST 800-53, Rev. 5; and compliance with the Privacy Act of 1974, E-Government Act of 2002, Federal Information Security Modernization Act of 2014, and key OMB guidelines, e.g., OMB Circular A-130.

[1] “[T]he term ‘record’ means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, his education, financial transactions, medical history, and criminal or employment history and that contains his name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a finger or voice print or a photograph.” 5 U.S.C. § 552a(a)(4). “[T]he term ‘system of records’ means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.” 5 U.S.C. § 552a(a)(5).

[2] As stated in FAR 52.224-3 and Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource (2016), “’personally identifiable information’ means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Regarding “sensitive PII,” “[t]he sensitivity level of the PII will depend on the context, including the purpose for which the PII is created, collected, used, processed, stored, maintained, disseminated, disclosed, or disposed. For example, the sensitivity level of a list of individuals’ names may depend on the source of the information, 15DDHQ24P00000175 Page 10 of 10 the other information associated with the list, the intended use of the information, the ways in which the information will be processed and shared, and the ability to access the information.” OMB Circular A-130, at App. II-2.

[3] The DOJ OPCL Resources page is available at https://www.justice.gov/opcl/resources.

[4] As stated in DOJ Instruction 0900, “Contractors must notify the Contracting Officer, the Contracting Officer’s Representative, and JSOC (or component-level SOC) within 1 hour of discovering any incidents, including breaches, consistent with this Instruction, guidance issued by the CPCLO, NIST standards and guidelines, and the US-CERT notification guidelines.”

[5] https://www.justice.gov/file/4336/download [6] As stated in DOJ Instruction 0900, the description should include the type of information that constitutes PII; purpose for which PII is collected, maintained, and used; extent to which PII identifies a peculiarly vulnerable population; the determination of whether the information was properly encrypted or rendered partially or completely inaccessible by other means; format of PII (e.g., whether PII was structured or unstructured); length of time PII was exposed; any evidence confirming that PII is being misused or that it was never accessed.

[7] As stated in DOJ Instruction 0900, the report should include the nature of the cyber threat (e.g., Advanced Persistent Threat, Zero Day Threat, data exfiltration) for cyber incidents.

[8] As stated in DOJ Instruction 0900, the report should include analysis on whether the data is accessible, usable, and intentionally targeted.

[9] As defined in 40 U.S.C. § 11101, the term “information technology” means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use (i) of that equipment or (ii) of that equipment to a significant extent in the performance of a service or the furnishing of a product; includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but does not include any equipment acquired by a federal contractor incidental to a federal contract.

[10] In this instance, the term “project” is used to scope the activities (e.g., creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, or disposing of information) covered by an IPA. A project is intended to be technology-neutral, and may include an information system, a digital service, an information technology, a combination thereof, or some other activity that may create potential privacy issues or privacy risks that would benefit from an IPA. The scope of a project covered by an IPA is discretionary, but components should work with their SCOP and OPCL.

(End of Clause)

DEA CLAUSE MATRIX – COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES

Updated through FAC 2023-05

Sept 2023 Page 1 of 33

ORDER #: 15DDHQ24P00000175

52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address: https://www.acquisition.gov/far-smart-matrix.

(End of clause)

CONTRACTING OFFICER: Check the appropriate box only for clauses that are applicable to this procurement.

52.203-16 PREVENTING PERSONAL CONFLICTS OF INTEREST (JUN 2020)

52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS AND REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (JUN 2020)

52.204-4 PRINTED OR COPIED DOUBLE-SIDED ON POSTCONSUMER FIBER CONTENT PAPER (MAY 2011)

52.204-9 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR PERSONNEL (JAN 2011)

52.204-12 UNIQUE ENTITY IDENTIFIER MAINTENANCE (OCT 2016)

52.204-13 SYSTEM FOR AWARD MANAGEMENT MAINTENANCE (OCT 2018)

52.204-18 COMMERCIAL AND GOVERNMENT ENTITY CODE MAINTENANCE (AUG 2020)

52.204-19 INCORPORATION BY REFERENCE OF REPRESENTATIONS AND CERTIFICATIONS (DEC 2014)

52.204-21 BASIC SAFEGUARDING OF COVERED CONTRACTOR INFORMATION SYSTEMS (NOV 2021)

52.204-23 PROHIBITION ON CONTRACTING FOR HARDWARE, SOFTWARE, AND SERVICES DEVELOPED OR PROVIDED BY KASPERSKY LAB AND

OTHER COVERED ENTITIES, IN ALL SOLICITATIONS AND CONTRACTS (NOV 2021)

52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN TELECOMMUNICATIONS AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (NOV 2021)

52.204–27 PROHIBITION ON A BYTEDANCE COVERED APPLICATION (JUN 2023)

(a) Definitions. As used in this clause—

Covered application means the social networking service TikTok or any successor application or service developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.

Information technology, as defined in 40 U.S.C. 11101(6)—

(1) Means any equipment or interconnected system or subsystem of equipment, used in the automatic acquisition, storage, analysis, evaluation, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency, if the equipment is used by the executive agency directly or is used by a contractor under a contract with the executive agency that requires the use—

(i) Of that equipment; or

(ii) Of that equipment to a significant extent in the performance of a service or the furnishing of a product;

(2) Includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources; but

(3) Does not include any equipment acquired by a Federal contractor incidental to a Federal contract.

(b) Prohibition. Section 102 of Division R of the Consolidated Appropriations Act, 2023 (Pub. L. 117-328), the No TikTok on Government Devices Act, and its implementing guidance under Office of Management and Budget (OMB) Memorandum M-23-13, dated February 27, 2023, “No TikTok on Government Devices” Implementation Guidance, collectively prohibit the presence or use of a covered application on executive agency information technology, including certain equipment used by Federal contractors. The Contractor is prohibited from having or using a covered application on any information technology owned or managed by the Government, or on any information technology used or provided by the Contractor under this contract, including equipment provided by the Contractor’s employees; however, this prohibition does not apply if the Contracting Officer provides written notification to the Contractor that an exception has been granted in accordance with OMB Memorandum M-23-13.

(c) Subcontracts. The Contractor shall insert the substance of this clause, including this paragraph (c), in all subcontracts, including subcontracts for the acquisition of commercial products or commercial services.

(End of clause)

52.207-5 OPTION TO PURCHASE EQUIPMENT (FEB 1995)

52.212-4 CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (DEC 2022)

52.212-4 ALT I CONTRACT TERMS AND CONDITIONS—COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (DEC 2022) WITH ALTERNATE I (NOV https://www.acquisition.gov/far-smart-matrix https://www.acquisition.gov/content/52203-16-preventing-personal-conflicts-interest https://www.acquisition.gov/far/52.203-17 https://www.acquisition.gov/content/52204-4-printed-or-copied-double-sided-postconsumer-fiber-content-paper https://www.acquisition.gov/content/52204-9-personal-identity-verification-contractor-personnel https://www.acquisition.gov/content/52204-12-unique-entity-identifier-maintenance https://www.acquisition.gov/content/52204-13-system-award-management-maintenance https://www.acquisition.gov/content/52204-18-commercial-and-government-entity-code-maintenance https://www.acquisition.gov/content/52204-19-incorporation-reference-representations-and-certifications https://www.acquisition.gov/content/52204-21-basic-safeguarding-covered-contractor-information-systems https://www.acquisition.gov/content/52204-23-prohibition-contracting-hardware-software-and-services-developed-or-provided https://www.acquisition.gov/content/52204-25-prohibition-contracting-certain-telecommunications-and-video-surveillance-services#id1989I600I4C https://www.acquisition.gov/far/52.204-27 https://www.acquisition.gov/content/52207-5-option-purchase-equipment https://www.acquisition.gov/content/52212-4-contract-terms-and-conditions-commercial-items https://www.acquisition.gov/content/52212-4-contract-terms-and-conditions-commercial-items

Sept 2023 Page 2 of 33

2021)

JAR 2852.212-4 TERMS AND CONDITIONS—COMMERCIAL ITEMS (NOV 2020) (DEVIATION)

When a commercial item is contemplated (using FAR part 12 procedures or otherwise) and the contract will include FAR 52.212–4, the following replaces subparagraph (g)(2); paragraph (h); subparagraph (i)(2); paragraph (s); and paragraph (u), Unauthorized Obligations, of the basic FAR clause, and adds paragraph (w), as follows:

(g)(2) Invoices will be handled in accordance with the Prompt Payment Act (31 U.S.C. 3903) and Office of Management and Budget (OMB) prompt payment act regulations at 5 CFR part 1315, as modified by subparagraph (i)(2), Prompt payment, of this clause.

(h) Patent indemnity. Contractor shall indemnify and hold harmless the Government and its respective affiliates, officers, directors, employees, agents, successors and assigns (collectively, ‘‘Indemnities’’) from and against any and all liability and losses incurred by the Indemnities that are (i) included in any settlement and/or (ii) awarded by a court of competent jurisdiction arising from or in connection with any third party claim of infringement made against Indemnities asserting that any product or service supplied under this contract constitutes infringement of any patent, copyright, trademark, service mark, trade name or other proprietary or intellectual right. This indemnity shall not apply unless Contractor shall have been informed within a reasonable time by the Government of the claim or action alleging such infringement and shall have been given such opportunity as is afforded by applicable laws, rules, or regulations to participate in its defense. This indemnity also shall not apply to any claim unreasonably settled by the Government which obligates Contractor to make any admission or pay any amount without written consent signed by an authorized officer of Contractor, unless required by final decree of a court of competent jurisdiction.

(i)(2) Prompt payment. The Government will make payment in accordance with the Prompt Payment Act (31 U.S.C. 3903) and prompt payment regulations (5 CFR part 1315), with the following modification regarding the due date: For the sole purpose of computing an interest penalty due the Contractor, the Government agrees to inspect and determine the acceptability of any supply delivered or service performed specified in the invoice within thirty (30) days of receipt of a proper invoice from the Contractor, after which time, if no affirmative action has been taken by the Government to accept such supply or service, the supply or service will be deemed accepted and payment due thirty (30) days from the date of deemed acceptance. If the Government makes the determination that the item delivered or service performed is deficient or otherwise unacceptable, or the invoice is otherwise determined not to be a proper invoice, the terms and conditions of this paragraph regarding prompt payment will apply to the date the Contractor corrects the deficiency in the item delivered or service performed or submits a proper invoice. If actual acceptance occurs within the constructive acceptance period, the Government will base the determination of an interest penalty on the actual date of acceptance. The constructive acceptance requirement does not, however, compel Government officials to accept supplies or services, perform contract administration functions, or make payment prior to fulfilling their responsibilities.

(s) Order of precedence. Any inconsistencies in this solicitation or contract shall be resolved by giving precedence in the following order:

(1) The schedule of supplies/services.

(2) The Assignments, Payments, Invoice, Other Compliances, and Compliance with Laws Unique to Government Contracts provisions of the basic FAR clause at 52.212–4, and the Unauthorized Obligations and Contractor’s Commercial Supplier Agreements—Unenforceable Clauses provisions of JAR 2852.212–4.

(3) FAR 52.212–5.

(4) Other paragraphs of the basic FAR clause at 52.212–4, with the exception of paragraph (o), Warranty, and those paragraphs identified in this deviation of 52.212–4.

(5) Addenda to this solicitation, contract, or order, including contractor’s Commercial supplier agreements incorporated into the contract.

(6) Solicitation provisions if this is a solicitation.

(7) Paragraph (o), Warranty, of the basic FAR clause at 52.212–4.

(8) The Standard Form 1449.

(9) Other documents, exhibits, and attachments.

(10) The specification.

(u) Unauthorized obligations.

(1) Except as stated in paragraph (u)(2) of this clause, when any supply or service acquired under this contract or order is subject to any Commercial supplier agreement that includes any language, provision, or clause requiring the Government to indemnify the Contractor or any person or entity for damages, costs, fees, or any other loss or liability that would create an Anti-Deficiency Act violation (see 31 U.S.C. 1341), the following shall govern:

(i) Any such language, provision, or clause is unenforceable against the Government.

(ii) Neither the Government nor any Government authorized end user shall be deemed to have agreed to such clause by virtue of it appearing in the commercial supplier agreement. If the commercial supplier agreement is invoked through an ‘‘I agree’’ click box or other similar mechanism (e.g., ‘‘clickwrap’’ or ‘‘browse-wrap’’ agreements), execution does not bind the Government or any Government authorized end user to such clause.

(iii) Any such language, provision, or clause is deemed to be stricken from the commercial supplier agreement and have no effect.

(2) Paragraph (u)(1) of this clause does not apply to indemnification by the Government that is expressly authorized by statute and specifically authorized under applicable agency regulations and procedures.

(w) Commercial supplier agreements—unenforceable clauses. When any supply or service acquired under this contract or order is subject to a contractor’s commercial supplier agreement, the following shall be deemed incorporated into such agreement and modifies and replaces any similar language, provision, or clause in such agreement. As used herein, ‘‘this agreement’’ means any contractor commercial supplier agreement:

(1) Notwithstanding any other provision of this agreement, when the end user is an agency or instrumentality of the U.S. Government, the following shall apply:

https://www.ecfr.gov/current/title-48/section-2852.212-4

Sept 2023 Page 3 of 33

(i) Applicability. This agreement is a part of a contract between commercial supplier and the U.S. Government for the acquisition of the supply or service that necessitates a license or other similar legal instrument (including all contracts, task orders, and delivery orders under FAR part 12).

(ii) End user. This agreement shall bind the Government as end user but shall not operate to bind the Government employee or person acting on behalf of the Government in his or her personal capacity.

(iii) Law and disputes. This agreement is governed by Federal law.

(A) Any language, provision, or clause purporting to subject the U.S. Government to the laws of any U.S. state, territory, district, or municipality, or the laws of a foreign nation, except where Federal law expressly provides for the application of such laws, is hereby deleted and shall have no effect.

(B) Any language, provision, or clause requiring dispute resolution in a specific forum or venue that is different from that prescribed by applicable Federal law is hereby deleted and shall have no effect.

(C) Any language, provision, or clause prescribing a different time period for bringing an action than that prescribed by applicable Federal law in relation to a dispute is hereby deleted and shall have no effect.

(iv) Continued performance. Notwithstanding any other provision in this agreement, if the Contractor believes the Government to be in breach of this contract, order, or agreement, it shall pursue its rights under the Contract Disputes Act or other applicable Federal statute while continuing performance as set forth in subparagraph (d), Disputes, of FAR 52.212–4.

(v) Arbitration; equitable or injunctive relief. In the event of a claim or dispute arising under or relating to the contract, order, or this agreement,

(A) binding arbitration shall not be used unless otherwise specifically authorized by agency guidance, and

(B) equitable or injunctive relief, including the award of attorney fees, costs or interest, may be awarded against the Government only when explicitly provided by statute.

(vi) Updating terms.

(A) After award, the contractor may unilaterally revise terms if they are not material. Material terms are defined as:

(1) Terms that change Government rights or obligations;

(2) Terms that increase Government prices;

(3) Terms that decrease the overall level of service; or

(4) Terms that limit any other Government right addressed elsewhere in this contract.

(B) For revisions that materially change the terms of the contract, the revised commercial supplier agreement must be incorporated into the contract using a bilateral modification.

(C) Any agreement terms or conditions unilaterally revised subsequent to award that are inconsistent with any material term or provisions of this contract shall not be enforceable against the Government, and the Government shall not be deemed to have consented to them.

(vii) Order of precedence. Any Order of Precedence clause in any commercial supplier agreement is not enforceable against the Government. The applicable Order of Precedence for this contract, order, or agreement is FAR 52.212–4(s), as revised by JAR 2812.302 and 2852.212–4(s).

(viii) No automatic renewals. If any license or service tied to period payment is provided under this agreement (e.g., annual software maintenance or annual lease term), such license or service shall not renew automatically upon expiration of its current term without prior express consent by a properly warranted contracting officer, and any provision or term of any license or service purporting to provide for automatic renewal is unenforceable against the Government.

(ix) Indemnification by the Government or end-user. Any language, provision, or clause of this commercial supplier agreement requiring the Government or End-user to indemnify the commercial supplier or licensor is not enforceable against the Government.

(x) Indemnification by the commercial supplier or licensor. Any clause of this agreement requiring or permitting the commercial supplier or licensor to defend the Government as a condition of indemnifying the Government for any claim of infringement is hereby amended to provide that the U.S.

Department of Justice has the sole right to represent the United States in any such action, in accordance with 28 U.S.C. 516.

(xi) Audits. Any language, provision, or clause of this commercial supplier agreement permitting Contractor to audit the end user’s compliance with this agreement is not enforceable against the Government. To the extent any language, provision or clause of this agreement permits Contractor to audit the Government’s compliance under this contract, order, or agreement, such language, provision, or clause of this agreement is hereby stricken and replaced as follows:

‘‘(A) If Contractor reasonably believes that the Government has violated the terms of this agreement with regard to the restrictions on authorized use and/or the number of authorized users, upon written request from Contractor, including an explanation of the basis for the request, DOJ will provide a redacted version of the Government’s most recent Security Assessment and Authorization package (SAA) to Contractor on a confidential basis, so that Contractor may reasonably verify the Government’s compliance with its obligations under this agreement. Contractor understands and agrees that the Government will remove or redact any information from the SAA that it reasonably believes may compromise (a) the security of the Government’s information technology environment; (b) the confidentiality of any third-party proprietary or confidential information; (c) any confidential, sensitive law enforcement information; and (d) any other information that the Government believes may compromise a past, current, or prospective investigation, prosecution, or litigation.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .