GSA Internal Data Sharing Policy

Number: 2109.1B CIO
Status: Active
Signature Date: 12/05/2025
Expiration Date: 12/31/2028

Purpose

This order articulates the policy that organizations within the General Services Administration (GSA) must follow when internally sharing or accessing data.

Background

This order is intended to establish the governance required to enable the sharing of data assets within GSA. 

Applicability

This Order applies to:

  1. All GSA employees, contractors, and subcontractors that may have a need to access or share data, as well as system-to-system data exchanges;
  2. The Office of Inspector General (OIG) only to the extent that the OIG   determines the order is consistent with the OIG’s independent authority under the IG Act and does; not conflict with other OIG policies or the OIG mission; and;
  3. The Civilian Board of Contract Appeals (CBCA) only to the extent that the CBCA determines the order is consistent with the CBCA’s independent authority under the Contract Disputes Act and does not conflict with other CBCA policies or the CBCA mission.

Cancellation

This Order supersedes GSA Order CIO 2109.1A, GSA Internal Data Sharing Policy.

Summary of Changes

Added paragraph 4F, Use of Artificial Intelligence at GSA, to align with requirements in OMB memo M-25-21.