Standardizing Federal PII Breach Response: OMB Updates Guidance for Agencies, Contractors, and Grant Recipients
Client Alert | 1 min read | 01.11.17
On January 3, 2017, the Office of Management and Budget (OMB) issued M-17-12, which updates and supersedes 2006 and 2007 OMB memoranda on preparing for and responding to breaches of personally identifiable information (PII) by imposing minimum standards on agencies for incident response programs, training and awareness, reporting, and documentation, coupled with requiring use of a flexible framework to assess and mitigate the risk of harm to individuals potentially affected by a PII breach. While making clear that a PII breach does not necessarily indicate an absence of adequate safeguards, the updated guidance also requires agencies to impose specific requirements, such as encryption, training, and incident-response obligations, on all contractors and subcontractors (at any tier); identifies PII-related requirements for federal grant recipients; and directs the FAR Council to “promptly… create appropriate contract clauses and regulatory coverage.”
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 4 min read | 02.20.26
SCOTUS Holds IEEPA Tariffs Unlawful
On February 20, 2026, the Supreme Court issued a pivotal ruling in Trump v. V.O.S. Selections, negating the President’s ability to impose tariffs under IEEPA. The case stemmed from President Trump’s invocation of IEEPA to levy tariffs on imports from Canada, Mexico, China, and other countries, citing national emergencies. Challengers argued—and the Court agreed—that IEEPA does not delegate tariff authority to the President. The power to tariff is vested in Congress by the Constitution and cannot be delegated to the President absent express authority from Congress.
Client Alert | 7 min read | 02.20.26
Section 5949 Proposed Rule Puts the FAR Council's Chips on the Table
Client Alert | 5 min read | 02.20.26
Trump Administration Pursues MFN Pricing for Prescription Drugs
Client Alert | 4 min read | 02.19.26
Proposed NY Legislation May Mean Potential Criminal Charges for Unlicensed Crypto Firms

