FAR and DFARS › FAR Part 24

FAR Part 24: Protection of Privacy and Freedom of Information

The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.

In plain English

FAR Part 24 implements the Privacy Act of 1974 and the Freedom of Information Act (FOIA) in Government contracts. It requires agencies to apply Privacy Act requirements to contractors that design, develop, or operate systems of records on individuals, and it prohibits agencies from disclosing certain contractor information under FOIA. It also mandates privacy training for contractor employees who handle personally identifiable information or systems of records.

Key rules

  • When a contract requires the design, development, or operation of a system of records on individuals to accomplish an agency function, the agency must apply the Privacy Act requirements to the contractor and its employees.
  • Contractors and their employees are considered employees of the agency for purposes of the criminal penalties of the Privacy Act when the contract provides for operation of a system of records on individuals.
  • The contracting officer must review requirements to determine if the contract will involve the design, development, or operation of a system of records on individuals, and if so, must ensure the work statement identifies the system and make agency Privacy Act rules available.
  • The contracting officer must insert the clauses at FAR 52.224-1, Privacy Act Notification, and FAR 52.224-2, Privacy Act, in solicitations and contracts when the design, development, or operation of a system of records on individuals is required. (24.104)
  • A proposal submitted in response to a competitive solicitation that is in the possession or control of the Government shall not be made available to any person under FOIA, unless the proposal is incorporated by reference in a contract.
  • Contractors must ensure that initial and annual privacy training is completed by employees who have access to a system of records, handle personally identifiable information on behalf of the agency, or design, develop, maintain, or operate a system of records.
  • Privacy training must be role-based, cover specified topics including the Privacy Act, safeguarding personally identifiable information, authorized use, restrictions on unauthorized equipment, prohibitions on unauthorized use, and breach procedures, and must test knowledge.
  • The contracting officer must insert the clause at FAR 52.224-3, Privacy Training, when contractor employees will have access to a system of records, handle personally identifiable information, or design, develop, maintain, or operate a system of records.

Who does what

Contracting officers
  • Review requirements to determine if the contract will involve the design, development, or operation of a system of records on individuals.
  • Ensure the contract work statement specifically identifies the system of records and the work to be performed.
  • Make available agency rules and regulations implementing the Privacy Act.
  • Insert the required Privacy Act clauses (52.224-1 and 52.224-2) and the Privacy Training clause (52.224-3) when applicable.
Contractors
  • Ensure that initial and annual privacy training is completed by applicable employees.
  • Maintain and provide documentation of privacy training completion upon request.
  • Comply with Privacy Act requirements when operating a system of records on behalf of an agency.
Agencies
  • Apply the requirements of the Privacy Act to contractors and their employees when a contract provides for the design, development, or operation of a system of records on individuals.
  • May be civilly liable to individuals injured if they fail to require that systems of records operated on their behalf conform to the Privacy Act.

In practice

  • If your contract involves designing, developing, or operating a system of records on individuals, you must follow the Privacy Act as if you were a Government employee, and your employees may face criminal penalties for violations.
  • You must provide initial and annual privacy training to employees who handle personally identifiable information or systems of records, and you must keep records of that training.
  • Your proposal submitted in response to a competitive solicitation is generally protected from FOIA disclosure, but if it becomes part of a contract, it may be disclosed.

Common pitfalls

  • Assuming that because you are a contractor, the Privacy Act does not apply to you; when you operate a system of records on behalf of an agency, you and your employees are treated as agency employees for criminal penalties.
  • Failing to provide or document required privacy training for employees who handle personally identifiable information or systems of records.
  • Not ensuring that the contract work statement specifically identifies the system of records and the work to be performed, which is required when the contract involves a system of records.

Written by AI from this part's codified text (2026-10-04); cited sections are checked against the part. A guide, not legal advice: the regulation text, the solicitation and your contract rule.

Rule changes for FAR Part 24

Subparts and sections

Subpart 24.1: Protection of Individual Privacy

Subpart 24.2: Freedom of Information Act

Subpart 24.3: Privacy Training

← Part 23: Environment, Sustainable Acquisition, and Material SafetyPart 25: Foreign Acquisition →

All FAR parts

Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗.

FAR Part 24: Protection of Privacy and Freedom of Information · SpendQuery