Privacy Standards
What privacy standards does USDOT prioritize? Should the vendor leverage methods like synthetic or modeled data to safeguard PII?
-
Sophie Abo commented
Data are expected be maintained in a secure environment, with proper administrative and technical safeguards and measures in place to prevent unauthorized access, disclosure, acquisition, destruction, use, or modification. Offerors are expected to be mindful of reidentification and other risks of data sharing and have an approach to minimize these risks in the final product. Any data collected, developed, received, transmitted, or stored on the ‘cloud;’ shall be done so using a cloud service provider that meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline. The Government does not expect to receive any data with Personally Identifiable Information (PII).