Skip to main content
EDARAgency supplement

Department of Education

The Education Department's procurement supplement — significant for student data.

Last reviewedJune 9, 2026Version v1

Cybersecurity rules in this supplement

The Education Department Acquisition Regulation (EDAR) centers on protecting student data:

EDAR clause 3452.239-71 — Department Information Security and Privacy Requirements. Requires contractors that handle Department IT or data to meet ED information-security and privacy requirements (FISMA, NIST, privacy controls).

EDAR clause 3452.224-73 — Protection of Student Privacy in Compliance with FERPA. Requires contractors handling student records to comply with the Family Educational Rights and Privacy Act (FERPA).

EDAR clause 3452.204-71 — Contractor Security Vetting Requirements. Governs background vetting for contractor personnel with access to Department systems or data.

EDAR clause 3452.204-70 — Records Management. Requires proper handling and management of Department records.

In plain terms

Education's rules protect student information first. If you handle Department data or systems, you must meet ED's information-security and privacy requirements, follow FERPA for student records, and have your staff vetted before they get access.

Who it applies to

Contractors and subcontractors that access Department of Education IT, data, or student records.

What it requires

Follow the FAR baseline, then: meet ED information-security and privacy requirements, comply with FERPA for student data, vet personnel for system access, and follow records-management rules.

Why it matters

Student records are protected by FERPA, and the Department's combined security/privacy clause means a data-handling failure can be both a cybersecurity and a statutory-privacy violation.

Citation

Education Department Acquisition Regulation (EDAR), codified at 48 C.F.R. Chapter 34.