yourstate.us
48 CFR 24.301

24.301 Privacy training.

United States · 48 CFR — Federal Acquisition Regulations System · Status: effective

Get this as JSONEmbed this
Cite this
Citation
48 CFR 24.301, 24.301 Privacy training, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/240445
Permanent ID
ys:prov:240445@1
SHA-256
f3b55e66e796492790e6236259a9f238f75eb1eb54dce305b10c48a657c9b887

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

(a) Contractors are responsible for ensuring that initial privacy training, and annual privacy training thereafter, is completed by contractor employees who— (1) Have access to a system of records; (2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information on behalf of the agency; or (3) Design, develop, maintain, or operate a system of records (see FAR subpart 24.1 and 39.105). (b) Privacy training shall address the key elements necessary for ensuring the safeguarding of personally identifiable information or a system of records. The training shall be role-based, provide foundational as well as more advanced levels of training, and have measures in place to test the knowledge level of users. At a minimum, the privacy training shall cover— (1) The provisions of the Privacy Act of 1974 (5 U.S.C. 552a), including penalties for violations of the Act; (2) The appropriate handling and safeguarding of personally identifiable information; (3) The authorized and official use of a system of records or any other personally identifiable information; (4) The restriction on the use of unauthorized equipment to create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise access personally identifiable information; (5) The prohibition against the unauthorized use of a system of records or unauthorized disclosure, access, handling, or use of personally identifiable information; and (6) Procedures to be followed in the event of a suspected or confirmed breach of a system of records or unauthorized disclosure, access, handling, or use of personally identifiable information (see Office of Management and Budget guidance for Preparing for and Responding to a Breach of Personally Identifiable Information). (c) The contractor may provide its own training or use the training of another agency unless the contracting agency specifies that only its agency-provided training is acceptable (see 24.302(b)). (d) The contractor is required to maintain and, upon request, to provide documentation of completion of privacy training for all applicable employees. (e) No contractor employee shall be permitted to have or retain access to a system of records, create, collect, use, process, store, maintain, disseminate, disclose, or dispose, or otherwise handle personally identifiable information, or design, develop, maintain, or operate a system of records, unless the employee has completed privacy training that, at a minimum, addresses the elements in paragraph (b) of this section.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.