{"data":{"id":"us/48-cfr-824.103","jurisdiction":"us","citation":"48 CFR 824.103","heading":"824.103 Procedures.","body":"(c) The contracting officer shall reference the following documents in solicitations and contracts that require the design, development, or operation of a system of records—\n(1) VA Handbook 6500.6, Contract Security;\n(2) VA Handbook 6508.1, Procedures for Privacy Threshold Analysis and Privacy Impact Assessment;\n(3) VA Handbook 6510, VA Identity and Access Management—\n(i) The contracting officer will ensure that statements of work or performance work statements that require the design, development, or operation of a system of records include procedures to follow in the event of a Personally Identifiable Information (PII) breach; and\n(ii) The contracting officer shall ensure that Government surveillance plans for contracts that require the design, development, or operation of a system of records include monitoring of the contractor's adherence to Privacy Act/PII regulations. The assessing official should document contractor-caused breaches or other incidents related to PII in past performance reports. Such incidents include instances in which the contractor did not adhere to Privacy Act/PII contractual requirements.","path":["Title 48—Federal Acquisition Regulations System","CHAPTER 8—DEPARTMENT OF VETERANS AFFAIRS","SUBCHAPTER D—SOCIOECONOMIC PROGRAMS","PART 824—PROTECTION OF PRIVACY AND FREEDOM OF INFORMATION","Subpart 824.1—Protection of Individual Privacy"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-48.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:26:29Z","sha256":"1220c7918ff1a3490892c5d667507ee42e51a01bb4676dbc57d2884ad075dd0f","source_id":"us-cfr","stale":true,"prev":"us/48-cfr-824.102","next":"us/48-cfr-824.103-70"},"notice":"GroundRules: Original legal text. Not legal advice."}
