FAR and DFARS › FAR Part 24
FAR Part 24: Protection of Privacy and Freedom of Information
The codified text (eCFR, as of 2026-10-02). Under the Revolutionary FAR Overhaul ↗, agencies follow class deviations with new text for many parts while the formal rules go through the Federal Register: check the solicitation and your contract's clauses, which rule.
In plain English
FAR Part 24 implements the Privacy Act of 1974 and the Freedom of Information Act (FOIA) in Government contracts. It requires agencies to apply Privacy Act requirements to contractors that design, develop, or operate systems of records on individuals, and it prohibits agencies from disclosing certain contractor information under FOIA. It also mandates privacy training for contractor employees who handle personally identifiable information or systems of records.
Key rules
- When a contract requires the design, development, or operation of a system of records on individuals to accomplish an agency function, the agency must apply the Privacy Act requirements to the contractor and its employees.
- Contractors and their employees are considered employees of the agency for purposes of the criminal penalties of the Privacy Act when the contract provides for operation of a system of records on individuals.
- The contracting officer must review requirements to determine if the contract will involve the design, development, or operation of a system of records on individuals, and if so, must ensure the work statement identifies the system and make agency Privacy Act rules available.
- The contracting officer must insert the clauses at FAR 52.224-1, Privacy Act Notification, and FAR 52.224-2, Privacy Act, in solicitations and contracts when the design, development, or operation of a system of records on individuals is required. (24.104)
- A proposal submitted in response to a competitive solicitation that is in the possession or control of the Government shall not be made available to any person under FOIA, unless the proposal is incorporated by reference in a contract.
- Contractors must ensure that initial and annual privacy training is completed by employees who have access to a system of records, handle personally identifiable information on behalf of the agency, or design, develop, maintain, or operate a system of records.
- Privacy training must be role-based, cover specified topics including the Privacy Act, safeguarding personally identifiable information, authorized use, restrictions on unauthorized equipment, prohibitions on unauthorized use, and breach procedures, and must test knowledge.
- The contracting officer must insert the clause at FAR 52.224-3, Privacy Training, when contractor employees will have access to a system of records, handle personally identifiable information, or design, develop, maintain, or operate a system of records.
Who does what
- Review requirements to determine if the contract will involve the design, development, or operation of a system of records on individuals.
- Ensure the contract work statement specifically identifies the system of records and the work to be performed.
- Make available agency rules and regulations implementing the Privacy Act.
- Insert the required Privacy Act clauses (52.224-1 and 52.224-2) and the Privacy Training clause (52.224-3) when applicable.
- Ensure that initial and annual privacy training is completed by applicable employees.
- Maintain and provide documentation of privacy training completion upon request.
- Comply with Privacy Act requirements when operating a system of records on behalf of an agency.
- Apply the requirements of the Privacy Act to contractors and their employees when a contract provides for the design, development, or operation of a system of records on individuals.
- May be civilly liable to individuals injured if they fail to require that systems of records operated on their behalf conform to the Privacy Act.
In practice
- If your contract involves designing, developing, or operating a system of records on individuals, you must follow the Privacy Act as if you were a Government employee, and your employees may face criminal penalties for violations.
- You must provide initial and annual privacy training to employees who handle personally identifiable information or systems of records, and you must keep records of that training.
- Your proposal submitted in response to a competitive solicitation is generally protected from FOIA disclosure, but if it becomes part of a contract, it may be disclosed.
Common pitfalls
- Assuming that because you are a contractor, the Privacy Act does not apply to you; when you operate a system of records on behalf of an agency, you and your employees are treated as agency employees for criminal penalties.
- Failing to provide or document required privacy training for employees who handle personally identifiable information or systems of records.
- Not ensuring that the contract work statement specifically identifies the system of records and the work to be performed, which is required when the contract involves a system of records.
Written by AI from this part's codified text (2026-10-04); cited sections are checked against the part. A guide, not legal advice: the regulation text, the solicitation and your contract rule.
Rule changes for FAR Part 24
- Federal Acquisition Regulation: Revolutionary Federal Acquisition Regulation Overhaul Parts 5, 24, and 29 ↗ · proposed 2026-06-23 · comments due 2026-07-23
Subparts and sections
Subpart 24.1: Protection of Individual Privacy
Subpart 24.2: Freedom of Information Act
Subpart 24.3: Privacy Training
← Part 23: Environment, Sustainable Acquisition, and Material SafetyPart 25: Foreign Acquisition →
All FAR parts
- Part 1 Federal Acquisition Regulations System
- Part 2 Definitions of Words and Terms
- Part 3 Improper Business Practices and Personal Conflicts of Interest
- Part 4 Administrative and Information Matters
- Part 5 Publicizing Contract Actions
- Part 6 Competition Requirements
- Part 7 Acquisition Planning
- Part 8 Required Sources of Supplies and Services
- Part 9 Contractor Qualifications
- Part 10 Market Research
- Part 11 Describing Agency Needs
- Part 12 Acquisition of Commercial Products and Commercial Services
- Part 13 Simplified Acquisition Procedures
- Part 14 Sealed Bidding
- Part 15 Contracting by Negotiation
- Part 16 Types of Contracts
- Part 17 Special Contracting Methods
- Part 18 Emergency Acquisitions
- Part 19 Small Business Programs
- Part 22 Application of Labor Laws to Government Acquisitions
- Part 23 Environment, Sustainable Acquisition, and Material Safety
- Part 24 Protection of Privacy and Freedom of Information
- Part 25 Foreign Acquisition
- Part 26 Other Socioeconomic Programs
- Part 27 Patents, Data, and Copyrights
- Part 28 Bonds and Insurance
- Part 29 Taxes
- Part 30 Cost Accounting Standards Administration
- Part 31 Contract Cost Principles and Procedures
- Part 32 Contract Financing
- Part 33 Protests, Disputes, and Appeals
- Part 34 Major System Acquisition
- Part 35 Research and Development Contracting
- Part 36 Construction and Architect-engineer Contracts
- Part 37 Service Contracting
- Part 38 Federal Supply Schedule Contracting
- Part 39 Acquisition of Information Technology
- Part 40 Information Security and Supply Chain Security
- Part 41 Acquisition of Utility Services
- Part 42 Contract Administration and Audit Services
- Part 43 Contract Modifications
- Part 44 Subcontracting Policies and Procedures
- Part 45 Government Property
- Part 46 Quality Assurance
- Part 47 Transportation
- Part 48 Value Engineering
- Part 49 Termination of Contracts
- Part 50 Extraordinary Contractual Actions and the Safety Act
- Part 51 Use of Government Sources by Contractors
- Part 52 Solicitation Provisions and Contract Clauses
- Part 53 Forms
Source: eCFR, 48 CFR chapters 1 and 2 (GPO GovInfo bulk data) ↗.