---
kind: "section"
citation: "48 C.F.R. § 39.105"
title: "48"
number: "39.105"
heading: "Privacy."
url: "https://uscodex.org/cfr/48/39.105"
---

# §39.105. Privacy.


Agencies shall ensure that contracts for information technology address protection of privacy in accordance with the Privacy Act ([5 U.S.C. 552a](/usc/5/552a.md)) and [part 24](/cfr/48/part24.md). In addition, each agency shall ensure that contracts for the design, development, or operation of a system of records using commercial information technology services or information technology support services include the following:

- (a) Agency rules of conduct that the contractor and the contractor's employees shall be required to follow.
- (b) A list of the anticipated threats and hazards that the contractor must guard against.
- (c) A description of the safeguards that the contractor must specifically provide.
- (d) Requirements for a program of Government inspection during performance of the contract that will ensure the continued efficacy and efficiency of safeguards and the discovery and countering of new threats and hazards.

## Notes

### Authority

Authority: 40 U.S.C. 121(c); 10 U.S.C. chapter 4 and 10 U.S.C. chapter 137 legacy provisions (see 10 U.S.C. 3016); and 51 U.S.C. 20113.

### Source

Source: 61 FR 41470, Aug. 8, 1996, unless otherwise noted.
