Low RiskFARGeneral

52.224-3Privacy Training.

Researched by the BidStride Research Team

What This Clause Requires

FAR 52.224-3 — Privacy Training.. This clause is part of the Federal Acquisition Regulation and may be included in government contracts as a solicitation provision or contract clause.

Official Regulation Text

52.224-3 Privacy Training. As prescribed in 24.302(a), insert the following clause: Privacy Training (JAN 2017) (a) Definition. As used in this clause, personally identifiable information means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. (See Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource). (b) The Contractor shall ensure that initial privacy training, and annual privacy training thereafter, is completed by contractor employees who— (1) Have access to a system of records; (2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information on behalf of an agency; or (3) Design, develop, maintain, or operate a system of records (see also FAR subpart 24.1 and 39.105). (c)(1) Privacy training shall address the key elements necessary for ensuring the safeguarding of personally identifiable information or a system of records. The training shall be role-based, provide foundational as well as more advanced levels of training, and have measures in place to test the knowledge level of users. At a minimum, the privacy training shall cover— (i) The provisions of the Privacy Act of 1974 (5 U.S.C. 552a), including penalties for violations of the Act; (ii) The appropriate handling and safeguarding of personally identifiable information; (iii) The authorized and official use of a system of records or any other personally identifiable information; (iv) The restriction on the use of unauthorized equipment to create, collect, use, process, store, maintain, disseminate, disclose, dispose or otherwise access personally identifiable information; (v) The prohibition against the unauthorized use of a system of records or unauthorized disclosure, access, handling, or use of personally identifiable information; and (vi) The

Source: eCFR, 48 CFR 52.224-3 (https://www.ecfr.gov/current/title-48/section-52.224-3)

Compliance Checklist

  • (b) The Contractor shall ensure that initial privacy training, and annual privacy training thereafter, is completed by contractor employees who— (1) Have access to a system of records; (2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information on behalf of an agency; or (3) Design, develop, maintain, or operate a system of records (see also FAR subpart 24.1 and 39.105).
  • (c)(1) Privacy training shall address the key elements necessary for ensuring the safeguarding of personally identifiable information or a system of records.
  • The training shall be role-based, provide foundational as well as more advanced levels of training, and have measures in place to test the knowledge level of users.
  • At a minimum, the privacy training shall cover— (i) The provisions of the Privacy Act of 1974 (5 U.S.C.
  • (2) Completion of an agency-developed or agency-conducted training course shall be deemed to satisfy these elements.
  • (d) The Contractor shall maintain and, upon request, provide documentation of completion of privacy training to the Contracting Officer.
  • (e) The Contractor shall not allow any employee access to a system of records, or permit any employee to create, collect, use, process, store, maintain, disseminate, disclose, dispose or otherwise handle personally identifiable information, or to design, develop, maintain, or operate a system of records unless the employee has completed privacy training, as required by this clause.
  • (f) The substance of this clause, including this paragraph (f), shall be included in all subcontracts under this contract, when subcontractor employees will— (1) Have access to a system of records; (2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information; or (3) Design, develop, maintain, or operate a system of records.

Flow-Down to Subcontractors

Flow-down required

This clause must be included in subcontracts with no subcontractors where the subcontractor will perform work covered by this clause. Typically appears in contract Section Section I.

Frequently Asked Questions

BidStride automatically scans your RFPs for 52.224-3

Stop hunting through solicitations manually. BidStride identifies every FAR and DFARS clause in your RFP, flags risk level, and surfaces compliance requirements before you submit your bid.

This summary is for informational purposes only and reflects the BidStride Research Team's plain-English interpretation of the regulation. It is not legal advice and does not constitute an attorney-client relationship. Always consult the official Federal Acquisition Regulation (FAR) or Defense Federal Acquisition Regulation Supplement (DFARS) text and qualified legal counsel for compliance decisions.