If a contractor operates a system of records on behalf of the Postal Service, the privacy regulations as described in this chapter are applicable unless otherwise agreed to in writing by the parties. If the contractor has access to personal information, such information may only be used for the purposes of the contract and the contractor must restrict access to the information to only its employees who need the information in order to perform work under the contract, and those employees must sign a nondisclosure agreement. The contractor must also develop a security plan to protect personal information and the contractor must notify the Postal Service if there is an actual or suspected breach of personal information. Complete requirements are set forth in Clause 1-1 of the Supplying Principals and Practices. Also see the purchasing regulations in 39 CFR Part 601.