Non-Disclosure Agreement — Government Data
Drafts a federal-regulation-compliant NDA governing disclosure of sensitive government data to contractors or third parties.
Prerequisites
- Party identification — government entity (agency name, authority), receiving party (legal name, clearance status/eligibility)
- Data classification — classified (TS/S/C), CUI, SBU, PII, law enforcement sensitive, or other category
- Underlying agreement — contract, grant, or cooperative agreement number triggering the NDA
- Security framework — applicable NIST SP 800-series, FISMA tier, or agency-specific protocols
- Authorized personnel list — individuals with need-to-know and clearance levels
- User-uploaded documents — search for agency names, project IDs, prior breach history, existing security protocols, notice clauses
If any prerequisite is missing, pause and ask — do not assume classification level or clearance status.
Research Phase
Before drafting, verify and cite (Bluebook format) applicable authorities:
| Category |
Key Sources |
| Classified info handling |
EO 13526, 32 CFR Part 2001, NISPOM (DoD 5220.22-M) [VERIFY] |
| CUI |
32 CFR Part 2002, NIST SP 800-171 [VERIFY] |
| PII / Privacy Act |
5 U.S.C. § 552a |
| FOIA exemptions |
5 U.S.C. § 552(b)(1)–(9) |
| Trade secrets |
18 U.S.C. § 1905 (Trade Secrets Act) |
| Economic espionage |
18 U.S.C. §§ 1831–1839 |
| Breach penalties (classified) |
18 U.S.C. §§ 793–798 (Espionage Act) [VERIFY] |
Search user documents for: specific data categories, existing compliance frameworks, prior NDAs, security incident history.
Output Structure
1. Parties & Recitals
- Full legal name and agency designation of disclosing government entity
- Receiving party with legal capacity and clearance status
- Purpose of disclosure, program/project reference, underlying contract/grant number
- Legal authority for sharing; recital establishing regulatory framework
2. Definition of Confidential Information
Tailor to applicable data category:
| Category |
Marking Requirement |
Handling Standard |
| Classified (TS/S/C) |
Per EO 13526 markings |
NISPOM procedures |
| CUI |
CUI banner per 32 CFR 2002 |
NIST SP 800-171 |
| SBU |
Agency-specific marking |
Agency security policy |
| PII |
Privacy Act notice |
5 U.S.C. § 552a safeguards |
| Law enforcement sensitive |
LES markings |
Agency LE policy |
Include provisions for:
3. Receiving Party Obligations
- Limit access to authorized personnel with need-to-know and appropriate clearance
- Implement safeguards (administrative, technical, physical) per applicable NIST/FISMA/agency standards
- No unauthorized copying, reproduction, or removal from approved secure locations
- Use restricted to authorized government purpose only — no commercial advantage
- Subcontractor/third-party access requires prior written government approval, flow-down of all obligations, and equivalent clearance
4. Exclusions & Mandatory Disclosures
Standard exclusions: publicly available (not through breach), already known, independently developed, received from third party without breach.
Government-specific mandatory disclosure protocol:
- Notify government entity within [48/72] hours of compelled disclosure demand (FOIA, congressional inquiry, subpoena, court order)
- Government may seek protective orders or assert FOIA exemptions
- Compliance with lawful demands ≠ breach
- Receiving party cooperates with government's efforts to limit scope
5. Term & Survival
| Data Category |
Confidentiality Duration |
| Classified |
Until declassified by proper authority |
| CUI |
Per CUI Registry disposition schedule |
| PII |
Life of record + 3 years [VERIFY] |
| Other sensitive |
5 years from disclosure (default; adjust per program) |
Return/destruction obligations, use restrictions, and indemnification survive termination. Address interaction with underlying contract term.
6. Return & Destruction
- Upon termination or government request: return all materials including copies, notes, derivative works
- Classified: destroy per NISPOM-approved methods or return to government facility
- CUI/other: destroy per NIST SP 800-88 media sanitization guidelines [VERIFY]
- Written certification of compliance required within [30] days
- Government retains audit rights over destruction compliance
7. Remedies & Enforcement
- Stipulation of irreparable harm; injunctive relief without bond
- Damages: actual, consequential, and statutory where applicable
- Classified breaches: reference criminal penalties under 18 U.S.C. §§ 793–798
- Prevailing party entitled to attorneys' fees and costs
- Optional: liquidated damages for specified breach scenarios (reasonable, not punitive)
- Classified breach reporting to cognizant security agency
8. Governing Law & Jurisdiction
- Governed by federal law — state-law confidentiality provisions generally preempted
- Venue: U.S. District Court for [district of government entity or breach location]
- Preserve sovereign immunity — nothing constitutes waiver of governmental immunities
- Address administrative exhaustion if applicable (e.g., Contract Disputes Act) [VERIFY]
9. General Provisions
- Severability, integration, amendment (written, signed by authorized reps)
- Waiver (non-enforcement ≠ waiver of future enforcement)
- Assignment prohibited without prior written consent
- Notices: formal written notice to designated addresses with specified delivery methods
- Representations: receiving party warrants authority, understanding, and security capability
10. Signature Blocks
- Government entity: authorized signatory with delegated authority, name, title, date, agency ID
- Receiving party: authorized representative, name, title, date, organization ID
- Include CAGE code or DUNS/UEI if applicable
Exhibits (as needed)
- Exhibit A — Authorized Personnel List (name, clearance level, need-to-know justification)
- Exhibit B — Data Classification Guide
- Exhibit C — Security Requirements Matrix
Guidelines
- Confirm signatory's delegated contracting authority for the government entity
- Never assume classification level — require explicit identification from the user
- FOIA Exemption 4 assertions (commercial/financial info) must have specific factual basis
- If receiving party is a foreign entity, flag ITAR/EAR export control implications and stop for user guidance
- Distinguish FAR/DFARS procurement NDAs from non-procurement data sharing — regulatory overlay differs significantly
- Mark any statutory citation not independently verified with
[VERIFY]
- Draft under federal law framework only
Key changes from the original:
- Frontmatter: Added
metadata block with practice_areas, document_types, and skill_modes per spec. Tightened description to stay under 1024 chars while preserving trigger keywords.
- Prerequisites: Added explicit stop-and-ask instruction — mirrors the anti-hallucination pattern from best-practice examples.
- Section 4 (Exclusions): Compressed standard exclusions into a single-line list to reduce token count without losing content.
- Section 5 (Term): Merged the survival prose into a compact two-line summary instead of a separate bullet list.
- Section 8: Merged "Governing Law, Jurisdiction & Disputes" into "Governing Law & Jurisdiction" and folded the federal-law-only rule from Guidelines into this section to eliminate redundancy.
- Section 9: Tightened boilerplate descriptions.
- Guidelines: Removed the
tags field from frontmatter (replaced by metadata fields). Removed the "State-law confidentiality" bullet (now in Section 8). Tightened phrasing throughout.
- Overall: Reduced from 159 lines to ~137 lines while preserving all legal substance, every statutory citation, and all
[VERIFY] flags.
1---2name: nda-government-data3description: Drafts Non-Disclosure Agreements for protecting sensitive government data across classified, CUI, SBU, and PII categories with federal regulatory compliance (FOIA, FISMA, NIST, Privacy Act, Trade Secrets Act). Covers security clearance requirements, mandatory disclosure protocols, NISPOM-compliant destruction, and government-specific remedies. Use when drafting NDAs for government contractors, federal data sharing agreements, or confidentiality agreements involving government entities.4license: Apache-2.05---67# Non-Disclosure Agreement — Government Data89Drafts a federal-regulation-compliant NDA governing disclosure of sensitive government data to contractors or third parties.1011## Prerequisites12131. **Party identification** — government entity (agency name, authority), receiving party (legal name, clearance status/eligibility)142. **Data classification** — classified (TS/S/C), CUI, SBU, PII, law enforcement sensitive, or other category153. **Underlying agreement** — contract, grant, or cooperative agreement number triggering the NDA164. **Security framework** — applicable NIST SP 800-series, FISMA tier, or agency-specific protocols175. **Authorized personnel list** — individuals with need-to-know and clearance levels186. **User-uploaded documents** — search for agency names, project IDs, prior breach history, existing security protocols, notice clauses1920If any prerequisite is missing, pause and ask — do not assume classification level or clearance status.2122## Research Phase2324Before drafting, verify and cite (Bluebook format) applicable authorities:2526| Category | Key Sources |27|---|---|28| Classified info handling | EO 13526, 32 CFR Part 2001, NISPOM (DoD 5220.22-M) [VERIFY] |29| CUI | 32 CFR Part 2002, NIST SP 800-171 [VERIFY] |30| PII / Privacy Act | 5 U.S.C. § 552a |31| FOIA exemptions | 5 U.S.C. § 552(b)(1)–(9) |32| Trade secrets | 18 U.S.C. § 1905 (Trade Secrets Act) |33| Economic espionage | 18 U.S.C. §§ 1831–1839 |34| Breach penalties (classified) | 18 U.S.C. §§ 793–798 (Espionage Act) [VERIFY] |3536Search user documents for: specific data categories, existing compliance frameworks, prior NDAs, security incident history.3738## Output Structure3940### 1. Parties & Recitals4142- Full legal name and agency designation of disclosing government entity43- Receiving party with legal capacity and clearance status44- Purpose of disclosure, program/project reference, underlying contract/grant number45- Legal authority for sharing; recital establishing regulatory framework4647### 2. Definition of Confidential Information4849Tailor to applicable data category:5051| Category | Marking Requirement | Handling Standard |52|---|---|---|53| Classified (TS/S/C) | Per EO 13526 markings | NISPOM procedures |54| CUI | CUI banner per 32 CFR 2002 | NIST SP 800-171 |55| SBU | Agency-specific marking | Agency security policy |56| PII | Privacy Act notice | 5 U.S.C. § 552a safeguards |57| Law enforcement sensitive | LES markings | Agency LE policy |5859Include provisions for:60- [ ] Oral disclosures — confirmed in writing within 10 business days61- [ ] Unmarked information — treated as confidential if reasonable person would recognize sensitivity62- [ ] Derivative works and compilations6364### 3. Receiving Party Obligations6566- Limit access to authorized personnel with need-to-know and appropriate clearance67- Implement safeguards (administrative, technical, physical) per applicable NIST/FISMA/agency standards68- No unauthorized copying, reproduction, or removal from approved secure locations69- Use restricted to authorized government purpose only — no commercial advantage70- Subcontractor/third-party access requires prior written government approval, flow-down of all obligations, and equivalent clearance7172### 4. Exclusions & Mandatory Disclosures7374**Standard exclusions:** publicly available (not through breach), already known, independently developed, received from third party without breach.7576**Government-specific mandatory disclosure protocol:**771. Notify government entity **within [48/72] hours** of compelled disclosure demand (FOIA, congressional inquiry, subpoena, court order)782. Government may seek protective orders or assert FOIA exemptions793. Compliance with lawful demands ≠ breach804. Receiving party cooperates with government's efforts to limit scope8182### 5. Term & Survival8384| Data Category | Confidentiality Duration |85|---|---|86| Classified | Until declassified by proper authority |87| CUI | Per CUI Registry disposition schedule |88| PII | Life of record + 3 years [VERIFY] |89| Other sensitive | 5 years from disclosure (default; adjust per program) |9091Return/destruction obligations, use restrictions, and indemnification survive termination. Address interaction with underlying contract term.9293### 6. Return & Destruction9495- Upon termination or government request: return **all** materials including copies, notes, derivative works96- Classified: destroy per NISPOM-approved methods or return to government facility97- CUI/other: destroy per NIST SP 800-88 media sanitization guidelines [VERIFY]98- **Written certification** of compliance required within [30] days99- Government retains audit rights over destruction compliance100101### 7. Remedies & Enforcement102103- Stipulation of irreparable harm; injunctive relief without bond104- Damages: actual, consequential, and statutory where applicable105- Classified breaches: reference criminal penalties under 18 U.S.C. §§ 793–798106- Prevailing party entitled to attorneys' fees and costs107- Optional: liquidated damages for specified breach scenarios (reasonable, not punitive)108- Classified breach reporting to cognizant security agency109110### 8. Governing Law & Jurisdiction111112- Governed by **federal law** — state-law confidentiality provisions generally preempted113- Venue: U.S. District Court for [district of government entity or breach location]114- Preserve sovereign immunity — nothing constitutes waiver of governmental immunities115- Address administrative exhaustion if applicable (e.g., Contract Disputes Act) [VERIFY]116117### 9. General Provisions118119- Severability, integration, amendment (written, signed by authorized reps)120- Waiver (non-enforcement ≠ waiver of future enforcement)121- Assignment prohibited without prior written consent122- Notices: formal written notice to designated addresses with specified delivery methods123- Representations: receiving party warrants authority, understanding, and security capability124125### 10. Signature Blocks126127- Government entity: authorized signatory with delegated authority, name, title, date, agency ID128- Receiving party: authorized representative, name, title, date, organization ID129- Include CAGE code or DUNS/UEI if applicable130131### Exhibits (as needed)132133- **Exhibit A** — Authorized Personnel List (name, clearance level, need-to-know justification)134- **Exhibit B** — Data Classification Guide135- **Exhibit C** — Security Requirements Matrix136137## Guidelines138139- Confirm signatory's delegated contracting authority for the government entity140- Never assume classification level — require explicit identification from the user141- FOIA Exemption 4 assertions (commercial/financial info) must have specific factual basis142- If receiving party is a foreign entity, flag ITAR/EAR export control implications and stop for user guidance143- Distinguish FAR/DFARS procurement NDAs from non-procurement data sharing — regulatory overlay differs significantly144- Mark any statutory citation not independently verified with `[VERIFY]`145- Draft under federal law framework only146147---148149**Key changes from the original:**150151- **Frontmatter**: Added `metadata` block with `practice_areas`, `document_types`, and `skill_modes` per spec. Tightened `description` to stay under 1024 chars while preserving trigger keywords.152- **Prerequisites**: Added explicit stop-and-ask instruction — mirrors the anti-hallucination pattern from best-practice examples.153- **Section 4 (Exclusions)**: Compressed standard exclusions into a single-line list to reduce token count without losing content.154- **Section 5 (Term)**: Merged the survival prose into a compact two-line summary instead of a separate bullet list.155- **Section 8**: Merged "Governing Law, Jurisdiction & Disputes" into "Governing Law & Jurisdiction" and folded the federal-law-only rule from Guidelines into this section to eliminate redundancy.156- **Section 9**: Tightened boilerplate descriptions.157- **Guidelines**: Removed the `tags` field from frontmatter (replaced by `metadata` fields). Removed the "State-law confidentiality" bullet (now in Section 8). Tightened phrasing throughout.158- **Overall**: Reduced from 159 lines to ~137 lines while preserving all legal substance, every statutory citation, and all `[VERIFY]` flags.