MICSI procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | unknown | “ The PHS/NIH Awarding Component and/or HHS may inquire at any time before, during, or after award into any Investigator disclosure of financial interests and MICSI’s review, including any retrospective review, and response to such disclosure. MICSI will submit, or permit on-site review of, all records pertinent to compliance with the regulation and this policy. The PHS/NIH Awarding Component may determine that imposition of specific award conditions under 2 CFR 200.208, or suspension of funding or other enforcement action under 2 CFR 200.339, is necessary until the matter is resolved.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ Where we transfer personal information from a non-EEA country to another country, you acknowledge that third parties in other jurisdictions may not be subject to similar data protection laws to the ones in our jurisdiction. There are risks if any such third party engages in any act or practice that would contravene the data privacy laws in our jurisdiction and this might mean that you will not be able to seek redress under our jurisdiction’s privacy laws.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ The personal information we collect is stored and processed in the United States, or where we or our partners, affiliates and third-party providers maintain facilities. By providing us with your personal information, you consent to the disclosure to these overseas third parties.” | Captured 2026-09-25Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | unknown | “ We will ensure that any transfer of personal information from countries in the European Economic Area (EEA) to countries outside the EEA will be protected by appropriate safeguards, for example by using standard data protection clauses approved by the European Commission, or the use of binding corporate rules or other legally accepted means.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ MICSI will maintain all records of Investigator financial interest disclosures and MICSI’s review of, and response to, such disclosures, whether or not a disclosure resulted in a determination of an FCOI, and all actions under this policy or retrospective review, if applicable, for at least three years from the date the final expenditures report is submitted to PHS/NIH or, where applicable, from other dates specified in 2 CFR 200.334. Copies of Investigator management plans will be retained as part of MICSI’s records and not submitted to NIH except as required or requested, consistent with NIH guidance.” | Captured 2026-09-25Open source →Finding permalink → |
| Data retention | All applicable tiers | unknown | “ We don’t keep personal information for longer than is necessary. While we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorized access, disclosure, copying, use or modification. That said, we advise that no method of electronic transmission or storage is 100% secure and cannot guarantee absolute data security. If necessary, we may retain your personal information for our compliance with a legal obligation or in order to protect your vital interests or the vital interests of another natural person.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ third-party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, web-hosting and server providers, debt collectors, maintenance or problem-solving providers, marketing or advertising providers, professional advisors and payment systems operators;” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ third parties, including agents or sub-contractors, who assist us in providing information, products, services or direct marketing to you.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ If we or our assets are acquired, or in the unlikely event that we go out of business or enter bankruptcy, we would include data among the assets transferred to any parties who acquire us. You acknowledge that such transfers may occur, and that any parties who acquire us may continue to use your personal information according to this policy.” | Captured 2026-09-25Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | unknown | “ We may disclose personal information to:” | Captured 2026-09-25Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.