82_FR_12392 82 FR 12352 - Privacy Act of 1974; System of Records

82 FR 12352 - Privacy Act of 1974; System of Records

GENERAL SERVICES ADMINISTRATION

Federal Register Volume 82, Issue 40 (March 2, 2017)

Page Range12352-12354
FR Document2017-04037

GSA proposes a new government-wide system of records subject to the Privacy Act of 1974.

Federal Register, Volume 82 Issue 40 (Thursday, March 2, 2017)
[Federal Register Volume 82, Number 40 (Thursday, March 2, 2017)]
[Notices]
[Pages 12352-12354]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-04037]


-----------------------------------------------------------------------

GENERAL SERVICES ADMINISTRATION

[Notice-ID-2016-02; Docket No: 2016-0002; Sequence No. 28]


Privacy Act of 1974; System of Records

AGENCY: Office of the Deputy Chief Information Officer, General 
Services Administration, GSA.

ACTION: Notice of a new system of records.

-----------------------------------------------------------------------

SUMMARY: GSA proposes a new government-wide system of records subject 
to the Privacy Act of 1974.

DATES: The system of records notice is effective upon its publication 
in today's Federal Register, with the exception of the routine uses 
which are effective April 3, 2017. Comments on the routine uses or 
other aspects of the system of records notice must be submitted by 
April 3, 2017.

ADDRESSES: Submit comments identified by ``Notice-ID-2016-02, Notice of 
New System of Records'' by any of the following methods:
     Regulations.gov: http://www.regulations.gov. Submit 
comments via the Federal eRulemaking portal by searching for Notice-ID-
2016-02, Notice of New System of Records. Select the link ``Comment 
Now'' that corresponds with ``Notice-ID-2016-02, Notice of New System 
of Records. Follow the instructions provided on the screen. Please 
include your name, company name (if any), and ``Notice-ID-2016-02, 
Notice of New System of Records'' on your attached document.
     Mail: General Services Administration, Regulatory 
Secretariat Division (MVCB), 1800 F Street NW., Washington, DC 20405. 
ATTN: Ms. Flowers/Notice-ID-2016-02, Notice of New System of Records.
    Instructions: Comments received generally will be posted without 
change to http://www.regulations.gov, including any personal and/or 
business confidential information provided. To confirm receipt of your 
comment(s), please check www.regulations.gov, approximately two to 
three days after submission to verify posting (except allow 30 days for 
posting of comments submitted by mail).

FOR FURTHER INFORMATION CONTACT: Call or email the GSA Chief Privacy 
Officer at telephone 202-322-8246, or email [email protected].

SUPPLEMENTARY INFORMATION:  GSA proposes to establish a new government-
wide system of records subject to the Privacy Act of 1974, 5 U.S.C. 
552a. Pursuant to Section 5 of the Digital Accountability and 
Transparency Act (DATA Act), Public Law 113-101, the Office of 
Management and Budget (OMB), in collaboration with the Chief 
Acquisition Officers Council, Department of Health and Human Services 
(HHS) and GSA, is engaged in a multifaceted effort that aims to reduce 
reporting burden, standardize processes, and reduce costs for Federal 
awardees. OMB is providing strategic leadership for the procurement 
pilot and collaborating with GSA and the Chief Acquisition Officers 
Council for implementation. The objectives of the Section 5 procurement 
pilot focus are to:
     Identify recommendations in the National Dialogue for 
further review
     Develop a central reporting portal prototype and 
collection tool for FAR required reports, and
     Test the portal by centrally collecting select FAR 
required reports that are currently reported across the Federal 
government, beginning with collection of reports required under FAR 
22.406-6.

The goal is to allow contractors doing business with the Federal 
Government to submit FAR required reports to one central location in an 
efficient and effective manner rather than multiple locations and to 
each contracting officer (CO).
    As part of this collaboration, GSA is developing and will operate 
the Federal Acquisition Regulation (FAR) Data Collection System. The 
system allows prime contractors and subcontractors (``submitters''), 
performing work on federal contract awards to enter and certify various 
reports required by the FAR. The system is intended to decrease the 
reporting burden on submitters and prior to full adoption the system 
will be used in a pilot to measure and demonstrate that burden 
reduction.
    Submitters will use the system to report data on their applicable 
awards. Each awarding agency will access the data provided pursuant to 
its award(s) and share it internally as required and

[[Page 12353]]

provided by law. Each agency is responsible for the collection and use 
of data pertaining to the submitters. GSA is the system owner and 
operator.
    OMB and GSA will use ongoing feedback from pilot participants, and 
modify the pilot reporting tool as necessary; and will analyze the 
feedback on pilot and other relevant information to determine expansion 
to other FAR required reports.

Richard Speidel,
Chief Privacy Officer, Office of the Deputy Chief Information Officer, 
General Services Administration.
SYSTEM NUMBER

GSA/GOVT-10

SYSTEM NAME:
    Federal Acquisition Regulation (FAR) Data Collection System.

SECURITY CLASSIFICATION:
    Unclassified.

SYSTEM LOCATION:
    The General Services Administration's (GSA) Federal Acquisition 
Service (FAS) owns the FAR Data Collection System, which is housed in 
secure datacenters in the continental United States. Each agency that 
makes awards has custody of the records pertaining to its own 
contracts. Contact the system manager for additional information.

SYSTEM MANAGER:
    Integrated Award Environment Assistant Commissioner, Office of 
Integrated Award Environment, Federal Acquisition Service, General 
Services Administration, 1800 F Street NW., Washington, DC 20405.

AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
    E-Government Act of 2002 (Pub. L. 107-347) Section 204; Davis-Bacon 
and Related Acts: 40 U.S.C. 3141-3148 40 U.S.C. 276a; 29 CFR parts 1, 
3, 5, 6 and 7; Section 5 of the Digital Accountability and Transparency 
Act (DATA Act), Public Law 113-101.

PURPOSES OF THE SYSTEM:
    The system facilitates collection of data that prime contractors 
and their subcontractors are required to submit. Each agency is 
responsible for the collection, use and review of data pertaining to 
its contracts to verify contractor compliance with applicable 
requirements. The system includes an online portal that allows prime or 
subcontractors to enter, review and as applicable, certify FAR-required 
reports. While logged in, a prime or subcontractor is able to enter 
data and review reports. After a required report has been entered by 
the prime contractor or a subcontractor on a contract, the prime 
contractor certifies that the report is correct and submits it to the 
contracting officer. Contracting officers and other authorized 
officials in the awarding agency use the data from the system to review 
submissions for compliance with contractual terms and conditions for 
contracts for which they are responsible.

CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
    The FAR Data Collection System contains records related to prime 
contractors who are performing on federal contract awards (``prime 
contractor''), subcontractors, their employees (``prime or 
subcontractor employees'') and employed by the Federal Government. An 
owner, agent, or employee of a prime or subcontractor may enter or 
certify information, as applicable.

CATEGORIES OF RECORDS IN THE SYSTEM:
    Categories of records include the name of the person entering, and 
as applicable, certifying, information on behalf of the prime or 
subcontractor, their position within the company, phone number, and 
email address. Categories of records related to employees of prime and 
subcontractors include, but are not limited to: Name, unique identifier 
assigned by the prime or subcontractor, work classification (per the 
Department of Labor's job classifications), regular and overtime hours 
worked by day/date, total hours worked, fringe benefits, whether paid 
as hourly rate in cash amounts or as an employer-paid benefit, and 
federal projects gross earnings. Some prime or subcontractors may be 
obligated to provide contractor employee information about themselves 
if they are self-employed. Categories of records related to acquisition 
personnel include name, position, work phone number, email address and 
other similar records related to their official responsibilities.

RECORD SOURCE CATEGORIES:
    Employee records are created, reviewed and, as appropriate, 
certified by the prime or subcontractor. Records pertaining to the 
individual entering and certifying data in the system may be created by 
the individual, by a contracting officer, or in the case of a 
subcontractor by the prime contractor or another subcontractor. Records 
pertaining to federal acquisition personnel using the system may be 
entered by the individual or by other federal employees at the 
individual's agency.

ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM INCLUDING CATEGORIES 
OF USERS AND THE PURPOSES OF SUCH USES:
    In addition to those disclosures generally permitted under 5 U.S.C. 
552a(b) of the Privacy Act, all or a portion of the records or 
information contained in this system may be disclosed to authorized 
entities, as is determined to be relevant and necessary, outside GSA as 
a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:
    a. To an appropriate Federal, State, tribal, local, international, 
or foreign law enforcement agency or other appropriate authority 
charged with investigating or prosecuting a violation or enforcing or 
implementing a law, rule, regulation, or order, where a record, either 
on its face or in conjunction with other information, indicates a 
violation or potential violation of law, which includes criminal, 
civil, or regulatory violations and such disclosure is proper and 
consistent with the official duties of the person making the 
disclosure.
    b. To a Member of Congress or his or her staff in response to a 
request made on behalf of and at the request of the individual who is 
the subject of the record.
    c. To the Department of Justice or other Federal agency conducting 
litigation or in proceedings before any court, adjudicative or 
administrative body, when: (a) GSA or any component thereof, or (b) any 
employee of GSA in his/her official capacity, or (c) any employee of 
GSA in his/her individual capacity where DOJ or GSA has agreed to 
represent the employee, or (d) the United States or any agency thereof, 
is a party to the litigation or has an interest in such litigation, and 
GSA determines that the records are both relevant and necessary to the 
litigation.
    d. To the National Archives and Records Administration (NARA) for 
records management purposes.
    e. To the Office of Management and Budget (OMB) and the Government 
Accountability Office (GAO) in accordance with their responsibilities 
for evaluation or oversight of Federal programs.
    f. To an expert, consultant, or contractor of GSA in the 
performance of a Federal duty to which the information is relevant.
    g. To appropriate agencies, entities, and persons when (1) GSA 
suspects or has confirmed that there has been a breach of the system of 
records; (2) GSA has determined that as a result of the suspected or 
confirmed breach there is a risk of harm to individuals, GSA (including 
its information systems, programs and operations), the Federal

[[Page 12354]]

Government, or national security; and (3) the disclosure made to such 
agencies, entities, and persons is reasonably necessary to assist in 
connection with GSA's efforts to respond to the suspected or confirmed 
breach or to prevent, minimize, or remedy such harm.
    h. To another Federal agency or Federal entity, when GSA determines 
that information from this system of records is reasonably necessary to 
assist the recipient agency or entity in (1) responding to a suspected 
or confirmed breach or (2) preventing, minimizing, or remedying the 
risk of harm to individuals, the recipient agency or entity (including 
its information systems, programs, and operations), the Federal 
Government, or national security, resulting from a suspected or 
confirmed breach.

POLICIES AND PRACTICES FOR STORAGE OF RECORDS:
    Electronic records and backups are stored on secure servers 
approved by GSA Office of the Chief Information Security Officer 
(OCISO) and accessed only by authorized personnel.

POLICIES AND PRACTICES FOR RETRIEVAL OF RECORDS:
    System records are retrievable by searching against information in 
the record pertaining to the prime or subcontractor (e.g., the prime or 
subcontractor's company's name; the name of the individual entering or 
certifying information on behalf of the prime or subcontractor), the 
contract, (e.g., the contract number), or the contracting officer; 
however, each agency can only access and retrieve the records 
pertaining to contracts being administered by its acquisition 
personnel.

POLICIES AND PRACTICES FOR RETENTION AND DISPOSAL OF RECORDS:
    System records are retained and disposed of according to each 
respective agency's records maintenance and disposition schedules 
including, as applicable, the NARA General Records Schedule 1.1, 
Financial Management and Reporting Records.

ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS:
    Records in the system are protected from unauthorized access and 
misuse through a combination of administrative, technical and physical 
security measures. Administrative measures include but are not limited 
to policies that limit system access to individuals within an agency 
with a legitimate business need, and regular review of security 
procedures and best practices to enhance security. Technical measures 
include but are not limited to system design that allows prime 
contractor and subcontractor employees access only to data for which 
they are responsible; role-based access controls that allow government 
employees access only to data regarding contracts awarded by their 
agency or reporting unit; required use of strong passwords that are 
frequently changed; and use of encryption for certain data transfers. 
Physical security measures include but are not limited to the use of 
data centers which meet government requirements for storage of 
sensitive data.

RECORD ACCESS PROCEDURES:
    Prime and subcontractors enter and review their own data in to the 
system, and are responsible for indicating that those data are correct. 
If an individual wishes to access any data or record pertaining to him 
or her in the system after it has been submitted, that individual 
should consult the Privacy Act implementation rules of the agency to 
which the report was submitted. For example, for reports submitted to 
GSA, procedures for accessing the content of a record can be found at 
41 CFR part 105-64.2.

CONTESTING RECORD PROCEDURES:
    Prime and subcontractors with access to the FAR Data Collection 
System can edit their own reports before submitting them. If an 
individual wishes to contest the content of any record pertaining to 
him or her in the system after it has been submitted, that individual 
should consult the Privacy Act implementation rules of the agency to 
which the report was submitted. For example, for reports submitted to 
GSA, procedures for contesting the content of a record and appeal 
procedures can be found at 41 CFR part 105-64.4.

NOTIFICATION PROCEDURES:
    Prime and subcontractors with access to the FAR Data Collection 
System enter and review their own data in the system. If an individual 
wishes to be notified at his or her request if the system contains a 
record pertaining to him or her after it has been submitted, that 
individual should consult the Privacy Act implementation rules of the 
agency to which the report was submitted. For example, for reports 
submitted to GSA, procedures for receiving notice can be found at 41 
CFR part 105-64.4.

EXEMPTIONS PROMULGATED FOR THE SYSTEM:
    None.

[FR Doc. 2017-04037 Filed 3-1-17; 8:45 am]
 BILLING CODE 6820-34-P



                                                12352                         Federal Register / Vol. 82, No. 40 / Thursday, March 2, 2017 / Notices

                                                breach or (2) preventing, minimizing, or                should contact the system manager at                  confirm receipt of your comment(s),
                                                remedying the risk of harm to                           the above address. Procedures for                     please check www.regulations.gov,
                                                individuals, the recipient agency or                    receiving notice can also be found at 41              approximately two to three days after
                                                entity (including its information                       CFR part 105–64.4.                                    submission to verify posting (except
                                                systems, programs, and operations), the                                                                       allow 30 days for posting of comments
                                                                                                        EXEMPTIONS PROMULGATED FOR THE SYSTEM:
                                                Federal Government, or national                                                                               submitted by mail).
                                                security, resulting from a suspected or                   None.                                               FOR FURTHER INFORMATION CONTACT: Call
                                                confirmed breach.                                       HISTORY:                                              or email the GSA Chief Privacy Officer
                                                POLICIES AND PRACTICES FOR STORAGE OF                     This notice modifies the previous                   at telephone 202–322–8246, or email
                                                RECORDS:                                                notice, published at 77 FR 16839, on                  gsa.privacyact@gsa.gov.
                                                   Electronic records and backups are                   March 22, 2012.                                       SUPPLEMENTARY INFORMATION: GSA
                                                stored on secure servers approved by                    [FR Doc. 2017–04017 Filed 3–1–17; 8:45 am]            proposes to establish a new government-
                                                GSA Office of the Chief Information                     BILLING CODE 6820–34–P
                                                                                                                                                              wide system of records subject to the
                                                Security Officer (OCISO) and accessed                                                                         Privacy Act of 1974, 5 U.S.C. 552a.
                                                only by authorized personnel. Paper                                                                           Pursuant to Section 5 of the Digital
                                                files are stored in locked rooms or filing              GENERAL SERVICES                                      Accountability and Transparency Act
                                                cabinets.                                               ADMINISTRATION                                        (DATA Act), Public Law 113–101, the
                                                                                                                                                              Office of Management and Budget
                                                POLICIES AND PRACTICES FOR RETRIEVAL OF                 [Notice–ID–2016–02; Docket No: 2016–0002;             (OMB), in collaboration with the Chief
                                                RECORDS:                                                Sequence No. 28]
                                                                                                                                                              Acquisition Officers Council,
                                                   Records are retrievable by a variety of                                                                    Department of Health and Human
                                                fields including, without limitation,                   Privacy Act of 1974; System of
                                                                                                        Records                                               Services (HHS) and GSA, is engaged in
                                                name of an individual involved in a                                                                           a multifaceted effort that aims to reduce
                                                case, email address, email heading,                     AGENCY:  Office of the Deputy Chief                   reporting burden, standardize processes,
                                                email subject matter, business or                       Information Officer, General Services                 and reduce costs for Federal awardees.
                                                residential address, social security                    Administration, GSA.                                  OMB is providing strategic leadership
                                                number, phone number, date of birth,                    ACTION: Notice of a new system of                     for the procurement pilot and
                                                contract files, litigation files, or by some            records.                                              collaborating with GSA and the Chief
                                                combination thereof.                                                                                          Acquisition Officers Council for
                                                                                                        SUMMARY:    GSA proposes a new                        implementation. The objectives of the
                                                POLICIES AND PRACTICES FOR RETENTION AND
                                                                                                        government-wide system of records                     Section 5 procurement pilot focus are
                                                DISPOSAL OF RECORDS:
                                                                                                        subject to the Privacy Act of 1974.                   to:
                                                  System records are retained and
                                                disposed of according to GSA records
                                                                                                        DATES: The system of records notice is                   • Identify recommendations in the
                                                                                                        effective upon its publication in today’s             National Dialogue for further review
                                                maintenance and disposition schedules
                                                                                                        Federal Register, with the exception of                  • Develop a central reporting portal
                                                and the requirements of the National
                                                                                                        the routine uses which are effective                  prototype and collection tool for FAR
                                                Archives and Records Administration.
                                                                                                        April 3, 2017. Comments on the routine                required reports, and
                                                ADMINISTRATIVE, TECHNICAL AND PHYSICAL                  uses or other aspects of the system of                   • Test the portal by centrally
                                                SAFEGUARDS:                                             records notice must be submitted by                   collecting select FAR required reports
                                                   Access is limited to authorized                      April 3, 2017.                                        that are currently reported across the
                                                individuals with passwords or keys.                     ADDRESSES: Submit comments                            Federal government, beginning with
                                                Electronic files are maintained behind a                identified by ‘‘Notice–ID–2016–02,                    collection of reports required under
                                                firewall, and paper files are stored in                 Notice of New System of Records’’ by                  FAR 22.406–6.
                                                locked rooms or filing cabinets.                        any of the following methods:                         The goal is to allow contractors doing
                                                RECORD ACCESS PROCEDURES:
                                                                                                           • Regulations.gov: http://                         business with the Federal Government
                                                                                                        www.regulations.gov. Submit comments                  to submit FAR required reports to one
                                                   Individuals wishing to access their                  via the Federal eRulemaking portal by                 central location in an efficient and
                                                own records should contact the system                   searching for Notice-ID–2016–02, Notice               effective manner rather than multiple
                                                manager at the above address.                           of New System of Records. Select the                  locations and to each contracting officer
                                                Procedures for accessing the content of                 link ‘‘Comment Now’’ that corresponds                 (CO).
                                                a record in the Case Tracking and                       with ‘‘Notice–ID–2016–02, Notice of                      As part of this collaboration, GSA is
                                                eDiscovery System and appeal                            New System of Records. Follow the                     developing and will operate the Federal
                                                procedures can also be found at 41 CFR                  instructions provided on the screen.                  Acquisition Regulation (FAR) Data
                                                part 105–64.2.                                          Please include your name, company                     Collection System. The system allows
                                                CONTESTING RECORD PROCEDURES:                           name (if any), and ‘‘Notice–ID–2016–02,               prime contractors and subcontractors
                                                   Individuals wishing to contest the                   Notice of New System of Records’’ on                  (‘‘submitters’’), performing work on
                                                content of any record pertaining to him                 your attached document.                               federal contract awards to enter and
                                                or her in the system should contact the                    • Mail: General Services                           certify various reports required by the
                                                system manager at the above address.                    Administration, Regulatory Secretariat                FAR. The system is intended to decrease
                                                Procedures for contesting the content of                Division (MVCB), 1800 F Street NW.,                   the reporting burden on submitters and
sradovich on DSK3GMQ082PROD with NOTICES




                                                a record in the Case Tracking and                       Washington, DC 20405. ATTN: Ms.                       prior to full adoption the system will be
                                                eDiscovery System and appeal                            Flowers/Notice–ID–2016–02, Notice of                  used in a pilot to measure and
                                                procedures can also be found at 41 CFR                  New System of Records.                                demonstrate that burden reduction.
                                                part 105–64.4.                                             Instructions: Comments received                       Submitters will use the system to
                                                                                                        generally will be posted without change               report data on their applicable awards.
                                                NOTIFICATION PROCEDURES:                                to http://www.regulations.gov, including              Each awarding agency will access the
                                                  Individuals wishing to inquire if the                 any personal and/or business                          data provided pursuant to its award(s)
                                                system contains information about them                  confidential information provided. To                 and share it internally as required and


                                           VerDate Sep<11>2014   16:13 Mar 01, 2017   Jkt 241001   PO 00000   Frm 00018   Fmt 4703   Sfmt 4703   E:\FR\FM\02MRN1.SGM   02MRN1


                                                                              Federal Register / Vol. 82, No. 40 / Thursday, March 2, 2017 / Notices                                              12353

                                                provided by law. Each agency is                         contractor or a subcontractor on a                    ROUTINE USES OF RECORDS MAINTAINED IN THE
                                                responsible for the collection and use of               contract, the prime contractor certifies              SYSTEM INCLUDING CATEGORIES OF USERS AND
                                                data pertaining to the submitters. GSA                  that the report is correct and submits it             THE PURPOSES OF SUCH USES:
                                                is the system owner and operator.                       to the contracting officer. Contracting                  In addition to those disclosures
                                                   OMB and GSA will use ongoing                         officers and other authorized officials in            generally permitted under 5 U.S.C.
                                                feedback from pilot participants, and                   the awarding agency use the data from                 552a(b) of the Privacy Act, all or a
                                                modify the pilot reporting tool as                      the system to review submissions for                  portion of the records or information
                                                necessary; and will analyze the feedback                compliance with contractual terms and                 contained in this system may be
                                                on pilot and other relevant information                 conditions for contracts for which they               disclosed to authorized entities, as is
                                                to determine expansion to other FAR                     are responsible.                                      determined to be relevant and
                                                required reports.                                                                                             necessary, outside GSA as a routine use
                                                                                                        CATEGORIES OF INDIVIDUALS COVERED BY THE              pursuant to 5 U.S.C. 552a(b)(3) as
                                                Richard Speidel,
                                                                                                        SYSTEM:                                               follows:
                                                Chief Privacy Officer, Office of the Deputy
                                                                                                          The FAR Data Collection System                         a. To an appropriate Federal, State,
                                                Chief Information Officer, General Services
                                                Administration.                                         contains records related to prime                     tribal, local, international, or foreign law
                                                                                                        contractors who are performing on                     enforcement agency or other appropriate
                                                SYSTEM NUMBER                                           federal contract awards (‘‘prime                      authority charged with investigating or
                                                                                                        contractor’’), subcontractors, their                  prosecuting a violation or enforcing or
                                                GSA/GOVT–10
                                                                                                        employees (‘‘prime or subcontractor                   implementing a law, rule, regulation, or
                                                SYSTEM NAME:                                            employees’’) and employed by the                      order, where a record, either on its face
                                                  Federal Acquisition Regulation (FAR)                  Federal Government. An owner, agent,                  or in conjunction with other
                                                Data Collection System.                                 or employee of a prime or subcontractor               information, indicates a violation or
                                                                                                        may enter or certify information, as                  potential violation of law, which
                                                SECURITY CLASSIFICATION:
                                                                                                        applicable.                                           includes criminal, civil, or regulatory
                                                   Unclassified.                                                                                              violations and such disclosure is proper
                                                SYSTEM LOCATION:                                        CATEGORIES OF RECORDS IN THE SYSTEM:                  and consistent with the official duties of
                                                  The General Services                                                                                        the person making the disclosure.
                                                                                                          Categories of records include the                      b. To a Member of Congress or his or
                                                Administration’s (GSA) Federal                          name of the person entering, and as
                                                Acquisition Service (FAS) owns the                                                                            her staff in response to a request made
                                                                                                        applicable, certifying, information on                on behalf of and at the request of the
                                                FAR Data Collection System, which is                    behalf of the prime or subcontractor,
                                                housed in secure datacenters in the                                                                           individual who is the subject of the
                                                                                                        their position within the company,                    record.
                                                continental United States. Each agency                  phone number, and email address.
                                                that makes awards has custody of the                                                                             c. To the Department of Justice or
                                                                                                        Categories of records related to                      other Federal agency conducting
                                                records pertaining to its own contracts.                employees of prime and subcontractors
                                                Contact the system manager for                                                                                litigation or in proceedings before any
                                                                                                        include, but are not limited to: Name,                court, adjudicative or administrative
                                                additional information.                                 unique identifier assigned by the prime               body, when: (a) GSA or any component
                                                SYSTEM MANAGER:                                         or subcontractor, work classification                 thereof, or (b) any employee of GSA in
                                                  Integrated Award Environment                          (per the Department of Labor’s job                    his/her official capacity, or (c) any
                                                Assistant Commissioner, Office of                       classifications), regular and overtime                employee of GSA in his/her individual
                                                Integrated Award Environment, Federal                   hours worked by day/date, total hours                 capacity where DOJ or GSA has agreed
                                                Acquisition Service, General Services                   worked, fringe benefits, whether paid as              to represent the employee, or (d) the
                                                Administration, 1800 F Street NW.,                      hourly rate in cash amounts or as an                  United States or any agency thereof, is
                                                Washington, DC 20405.                                   employer-paid benefit, and federal                    a party to the litigation or has an interest
                                                                                                        projects gross earnings. Some prime or                in such litigation, and GSA determines
                                                AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
                                                                                                        subcontractors may be obligated to                    that the records are both relevant and
                                                   E-Government Act of 2002 (Pub. L.                    provide contractor employee
                                                107–347) Section 204; Davis-Bacon and                                                                         necessary to the litigation.
                                                                                                        information about themselves if they are                 d. To the National Archives and
                                                Related Acts: 40 U.S.C. 3141–3148 40                    self-employed. Categories of records
                                                U.S.C. 276a; 29 CFR parts 1, 3, 5, 6 and                                                                      Records Administration (NARA) for
                                                                                                        related to acquisition personnel include              records management purposes.
                                                7; Section 5 of the Digital                             name, position, work phone number,
                                                Accountability and Transparency Act                                                                              e. To the Office of Management and
                                                                                                        email address and other similar records               Budget (OMB) and the Government
                                                (DATA Act), Public Law 113–101.                         related to their official responsibilities.           Accountability Office (GAO) in
                                                PURPOSES OF THE SYSTEM:                                                                                       accordance with their responsibilities
                                                                                                        RECORD SOURCE CATEGORIES:
                                                  The system facilitates collection of                                                                        for evaluation or oversight of Federal
                                                data that prime contractors and their                     Employee records are created,                       programs.
                                                subcontractors are required to submit.                  reviewed and, as appropriate, certified                  f. To an expert, consultant, or
                                                Each agency is responsible for the                      by the prime or subcontractor. Records                contractor of GSA in the performance of
                                                collection, use and review of data                      pertaining to the individual entering                 a Federal duty to which the information
                                                pertaining to its contracts to verify                   and certifying data in the system may be              is relevant.
                                                contractor compliance with applicable                   created by the individual, by a                          g. To appropriate agencies, entities,
sradovich on DSK3GMQ082PROD with NOTICES




                                                requirements. The system includes an                    contracting officer, or in the case of a              and persons when (1) GSA suspects or
                                                online portal that allows prime or                      subcontractor by the prime contractor or              has confirmed that there has been a
                                                subcontractors to enter, review and as                  another subcontractor. Records                        breach of the system of records; (2) GSA
                                                applicable, certify FAR-required reports.               pertaining to federal acquisition                     has determined that as a result of the
                                                While logged in, a prime or                             personnel using the system may be                     suspected or confirmed breach there is
                                                subcontractor is able to enter data and                 entered by the individual or by other                 a risk of harm to individuals, GSA
                                                review reports. After a required report                 federal employees at the individual’s                 (including its information systems,
                                                has been entered by the prime                           agency.                                               programs and operations), the Federal


                                           VerDate Sep<11>2014   18:17 Mar 01, 2017   Jkt 241001   PO 00000   Frm 00019   Fmt 4703   Sfmt 4703   E:\FR\FM\02MRN1.SGM   02MRN1


                                                12354                         Federal Register / Vol. 82, No. 40 / Thursday, March 2, 2017 / Notices

                                                Government, or national security; and                   practices to enhance security. Technical              DEPARTMENT OF HEALTH AND
                                                (3) the disclosure made to such                         measures include but are not limited to               HUMAN SERVICES
                                                agencies, entities, and persons is                      system design that allows prime
                                                reasonably necessary to assist in                       contractor and subcontractor employees                Centers for Disease Control and
                                                connection with GSA’s efforts to                        access only to data for which they are                Prevention
                                                respond to the suspected or confirmed                   responsible; role-based access controls               [60Day–17–1014: Docket No. CDC–2017–
                                                breach or to prevent, minimize, or                      that allow government employees access                0012]
                                                remedy such harm.                                       only to data regarding contracts
                                                  h. To another Federal agency or                       awarded by their agency or reporting                  Proposed Data Collection Submitted
                                                Federal entity, when GSA determines                     unit; required use of strong passwords                for Public Comment and
                                                that information from this system of                    that are frequently changed; and use of               Recommendations
                                                records is reasonably necessary to assist               encryption for certain data transfers.
                                                the recipient agency or entity in (1)                   Physical security measures include but                AGENCY: Centers for Disease Control and
                                                responding to a suspected or confirmed                  are not limited to the use of data centers            Prevention (CDC), Department of Health
                                                breach or (2) preventing, minimizing, or                which meet government requirements                    and Human Services (HHS).
                                                remedying the risk of harm to                           for storage of sensitive data.                        ACTION: Notice with comment period.
                                                individuals, the recipient agency or
                                                                                                        RECORD ACCESS PROCEDURES:                             SUMMARY:    The Centers for Disease
                                                entity (including its information
                                                                                                           Prime and subcontractors enter and                 Control and Prevention (CDC), as part of
                                                systems, programs, and operations), the
                                                                                                        review their own data in to the system,               its continuing efforts to reduce public
                                                Federal Government, or national
                                                                                                        and are responsible for indicating that               burden and maximize the utility of
                                                security, resulting from a suspected or
                                                                                                        those data are correct. If an individual              government information, invites the
                                                confirmed breach.
                                                                                                        wishes to access any data or record                   general public and other Federal
                                                POLICIES AND PRACTICES FOR STORAGE OF                   pertaining to him or her in the system                agencies to take this opportunity to
                                                RECORDS:
                                                                                                        after it has been submitted, that                     comment on proposed and/or
                                                  Electronic records and backups are                    individual should consult the Privacy                 continuing information collections, as
                                                stored on secure servers approved by                    Act implementation rules of the agency                required by the Paperwork Reduction
                                                GSA Office of the Chief Information                     to which the report was submitted. For                Act of 1995. This notice invites
                                                Security Officer (OCISO) and accessed                   example, for reports submitted to GSA,                comment on the updated ‘‘CDC
                                                only by authorized personnel.                           procedures for accessing the content of               WORKSITE HEALTH SCORECARD,’’ an
                                                                                                        a record can be found at 41 CFR part                  organizational assessment and planning
                                                POLICIES AND PRACTICES FOR RETRIEVAL OF
                                                                                                        105–64.2.                                             tool designed to help employers identify
                                                RECORDS:
                                                                                                                                                              gaps in their health promotion programs
                                                   System records are retrievable by                    CONTESTING RECORD PROCEDURES:                         and prioritize high-impact strategies for
                                                searching against information in the                      Prime and subcontractors with access                health promotion at their worksites.
                                                record pertaining to the prime or                       to the FAR Data Collection System can                 DATES: Written comments must be
                                                subcontractor (e.g., the prime or                       edit their own reports before submitting
                                                subcontractor’s company’s name; the                                                                           received on or before May 1, 2017.
                                                                                                        them. If an individual wishes to contest              ADDRESSES: You may submit comments,
                                                name of the individual entering or                      the content of any record pertaining to
                                                certifying information on behalf of the                                                                       identified by Docket No. CDC–2017–
                                                                                                        him or her in the system after it has                 0012 by any of the following methods:
                                                prime or subcontractor), the contract,                  been submitted, that individual should
                                                (e.g., the contract number), or the                                                                              • Federal eRulemaking Portal:
                                                                                                        consult the Privacy Act implementation                Regulations.gov. Follow the instructions
                                                contracting officer; however, each                      rules of the agency to which the report
                                                agency can only access and retrieve the                                                                       for submitting comments.
                                                                                                        was submitted. For example, for reports                  • Mail: Leroy A. Richardson,
                                                records pertaining to contracts being                   submitted to GSA, procedures for
                                                administered by its acquisition                                                                               Information Collection Review Office,
                                                                                                        contesting the content of a record and                Centers for Disease Control and
                                                personnel.                                              appeal procedures can be found at 41                  Prevention, 1600 Clifton Road NE., MS–
                                                POLICIES AND PRACTICES FOR RETENTION AND                CFR part 105–64.4.                                    D74, Atlanta, Georgia 30329.
                                                DISPOSAL OF RECORDS:                                                                                             Instructions: All submissions received
                                                                                                        NOTIFICATION PROCEDURES:
                                                  System records are retained and                                                                             must include the agency name and
                                                                                                          Prime and subcontractors with access
                                                disposed of according to each respective                                                                      Docket Number. All relevant comments
                                                                                                        to the FAR Data Collection System enter
                                                agency’s records maintenance and                                                                              received will be posted without change
                                                                                                        and review their own data in the
                                                disposition schedules including, as                                                                           to Regulations.gov, including any
                                                                                                        system. If an individual wishes to be
                                                applicable, the NARA General Records                                                                          personal information provided. For
                                                                                                        notified at his or her request if the
                                                Schedule 1.1, Financial Management                                                                            access to the docket to read background
                                                                                                        system contains a record pertaining to
                                                and Reporting Records.                                                                                        documents or comments received, go to
                                                                                                        him or her after it has been submitted,
                                                                                                                                                              Regulations.gov.
                                                ADMINISTRATIVE, TECHNICAL, AND PHYSICAL                 that individual should consult the
                                                SAFEGUARDS:                                             Privacy Act implementation rules of the                 Please note: All public comment should be
                                                   Records in the system are protected                  agency to which the report was                        submitted through the Federal eRulemaking
                                                                                                                                                              portal (Regulations.gov) or by U.S. mail to the
                                                from unauthorized access and misuse                     submitted. For example, for reports
                                                                                                                                                              address listed above.
                                                through a combination of                                submitted to GSA, procedures for
sradovich on DSK3GMQ082PROD with NOTICES




                                                administrative, technical and physical                  receiving notice can be found at 41 CFR               FOR FURTHER INFORMATION CONTACT:    To
                                                security measures. Administrative                       part 105–64.4.                                        request more information on the
                                                measures include but are not limited to                                                                       proposed project or to obtain a copy of
                                                                                                        EXEMPTIONS PROMULGATED FOR THE SYSTEM:
                                                policies that limit system access to                                                                          the information collection plan and
                                                individuals within an agency with a                       None.                                               instruments, contact the Information
                                                legitimate business need, and regular                   [FR Doc. 2017–04037 Filed 3–1–17; 8:45 am]            Collection Review Office, Centers for
                                                review of security procedures and best                  BILLING CODE 6820–34–P                                Disease Control and Prevention, 1600


                                           VerDate Sep<11>2014   16:13 Mar 01, 2017   Jkt 241001   PO 00000   Frm 00020   Fmt 4703   Sfmt 4703   E:\FR\FM\02MRN1.SGM   02MRN1



Document Created: 2017-03-02 00:09:28
Document Modified: 2017-03-02 00:09:28
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice of a new system of records.
DatesThe system of records notice is effective upon its publication in today's Federal Register, with the exception of the routine uses which are effective April 3, 2017. Comments on the routine uses or other aspects of the system of records notice must be submitted by April 3, 2017.
ContactCall or email the GSA Chief Privacy Officer at telephone 202-322-8246, or email [email protected]
FR Citation82 FR 12352 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR