DoD’s New Employee-Data Clause Creates a Supply-Chain Privacy Obligation for Contractors
The Department of Defense’s latest overhaul of its information-security and supply-chain regulations contains an important new requirement that could easily be overlooked amid larger debates over CMMC, Chinese suppliers, telecommunications restrictions, and cybersecurity.
It concerns what contractors may do with personal information belonging to DoD personnel.
In September 2026, DoD issued Revision 3 of Class Deviation 2026-O0025 implementing its revised FAR Part 40 and DFARS Part 240 framework. Among other statutory changes, the deviation implements provisions of the FY2024 and FY2025 National Defense Authorization Acts concerning individually identifiable DoD employee information.
The resulting restriction is straightforward but potentially broad.
A contractor may not sell, license, or otherwise transfer covered personally identifiable information concerning DoD employees—including members of the Armed Forces—that the contractor obtains in connection with its work to an individual or entity other than the Government, except where the transfer is required to perform the contract, otherwise authorized by law, or subject to an applicable waiver.
The requirement is particularly significant because it does not stop with the prime contractor.
The new DFARS clause requires contractors to insert its substance into all subcontracts and other contractual instruments, including those for commercial products and commercial services.
That creates a supply-chain compliance issue extending beyond traditional defense subcontractors.
Many federal contractors rely on commercial vendors for cloud hosting, payroll, benefits administration, workforce management, travel, analytics, software-as-a-service platforms, communications, medical administration, and other business functions. Some of those providers may receive information about military members or civilian DoD personnel during contract performance.
Commercial vendor agreements, however, are often drafted around broad rights to process, analyze, combine, retain, or otherwise use customer data.
The new DoD restriction makes it important to determine whether those ordinary commercial terms are consistent with federal contract requirements.
Contractors should therefore know what covered DoD employee information they receive, where it resides, which third parties can access it, and the contractual basis permitting each downstream transfer. They should also examine whether existing subcontract and vendor templates contain the required flowdown and whether procurement personnel recognize that a routine commercial subscription may constitute another contractual instrument subject to the requirement.
This is not simply a privacy-policy issue. Because the restriction is embedded in the contracting framework, compliance requires coordination among contracts, legal, privacy, cybersecurity, procurement, HR, and vendor-management personnel.
The larger trend is familiar across modern federal contracting: the Government increasingly expects prime contractors to understand not only their own compliance environment but also how sensitive information moves through their commercial supply chains.
The newest DFARS requirement adds another category contractors should place on that map.
Recommended FedContractPros Product: FedClause360
FedClause360 can help contractors identify and understand contract clauses, representations, restrictions, and subcontract flowdowns—including requirements that may appear in otherwise routine commercial-service arrangements.
Disclaimer:
This article is provided for general informational and educational purposes only and does not constitute legal, privacy, cybersecurity, or government-contracting advice. Contractors should review Class Deviation 2026-O0025, applicable DFARS requirements, contract clauses, waivers, privacy laws, vendor agreements, and specific data flows when evaluating compliance.