Cross-Border Transfers

The Justice Department's Bulk Sensitive Data Rule: Six Countries, Six Data Categories, and Two Compliance Dates in 2025

Key Takeaways

  • 28 CFR part 202 took effect at 12:01 a.m. ET on April 8, 2025; subpart J and the reporting duties in §§ 202.1103 and 202.1104 applied from October 6, 2025
  • China (with Hong Kong and Macau), Cuba, Iran, North Korea, Russia and Venezuela are the countries of concern listed in § 202.601
  • Data brokerage and any access to bulk human 'omic data or biospecimens are prohibited; vendor, employment and investment agreements are allowed only if the CISA security requirements are met
  • Violations carry IEEPA civil penalties of up to the greater of $368,136 or twice the transaction value, and up to $1,000,000 and 20 years' imprisonment if willful
  • The Federal Register shows one amendment since the final rule, a correction of a cross-reference in § 202.401 effective April 18, 2025

Executive Order 14117 and 28 CFR Part 202

Executive Order 14117, signed February 28, 2024 and published at 89 FR 15421, expanded the national emergency declared in Executive Order 13873 of 2019 to cover "the continuing effort of certain countries of concern to access Americans' sensitive personal data and United States Government-related data." Section 2(a) directed the Attorney General, in coordination with the Secretary of Homeland Security, to issue regulations prohibiting or restricting United States persons from transactions that give those countries, or persons tied to them, access to such data. Section 2(d) directed the Cybersecurity and Infrastructure Security Agency to write security requirements for the transactions that would be restricted rather than barred.

The National Security Division published the final rule on January 8, 2025 at 90 FR 1636, after proposed rules in March and October 2024. It is codified at 28 CFR part 202 under the authority of the International Emergency Economic Powers Act. The Department calls the result the Data Security Program and, on its program page, describes it as establishing "what are effectively export controls."

The rule is aimed at a counterparty, not at a practice. It does not govern how a company collects or uses data about its own customers. It governs a small set of commercial relationships when the other side is a country of concern or a covered person, and only when the data crosses a volume threshold or falls in a government-related category.

Countries of Concern and Covered Persons

Section 202.601 names six countries of concern: China, Cuba, Iran, North Korea, Russia and Venezuela. Section 202.208 defines China to include the Special Administrative Regions of Hong Kong and Macau. Any change to the list applies to transactions initiated, pending or completed on or after the amendment's effective date.

A covered person under § 202.211 falls into one of five classes: a foreign entity 50 per cent or more owned by a country of concern or by other covered persons, or organized or headquartered in one; a foreign entity 50 per cent or more owned by such an entity; a foreign individual who is an employee or contractor of a country of concern or a covered entity; a foreign individual primarily resident in a country of concern; and any person, wherever located, the Attorney General designates. Ownership aggregates across covered holders, directly or indirectly.

The examples in the rule turn on nationality less than on status. A Chinese or Russian citizen in the United States is a U.S. person and not a covered person unless designated. A Russian citizen living in the European Union is not a covered person unless designated or employed by a covered entity. Section 202.701 makes a designation effective from public announcement, and publication in the Federal Register is deemed constructive knowledge.

The Six Categories and Their Bulk Thresholds

Section 202.249 lists six kinds of sensitive personal data. Section 202.205 sets a separate threshold for each, counted over the preceding 12 months and aggregated across all transactions between the same U.S. person and the same counterparty:

Category (definition)Counted inBulk above
Human genomic data (§ 202.224)U.S. persons100
Other human 'omic data: epigenomic, proteomic or transcriptomic (§ 202.224)U.S. persons1,000
Biometric identifiers (§ 202.204)U.S. persons1,000
Precise geolocation data, within 1,000 meters (§ 202.242)U.S. devices1,000
Personal health data (§ 202.241)U.S. persons10,000
Personal financial data (§ 202.240)U.S. persons10,000
Covered personal identifiers (§ 202.212)U.S. persons100,000

Combined datasets are measured against the lowest applicable threshold. Section 202.206 applies the thresholds "regardless of whether the data is anonymized, pseudonymized, de-identified, or encrypted." A covered personal identifier is a listed identifier, such as a government ID number, a device identifier, an advertising ID or a name, linked to another listed identifier or to other sensitive data. A standalone Social Security number is not one; a name linked to a Social Security number is. Demographic or contact data linked only to other demographic or contact data is excluded; the rule's own example is a first and last name linked to a residential street address.

Government-related data under § 202.222 has no threshold at all. It covers precise geolocation data for any area on the Government-Related Location Data List in § 202.1401, and any sensitive personal data a party markets as linked to current or recent former federal employees or contractors, including the military, or to former senior officials. "Recent" means within the past two years.

Prohibited Transactions

Subpart C bars three things outright, each subject to a knowledge standard. Section 202.230 defines "knowingly" to include what a person "reasonably should have known."

  • Data brokerage with a country of concern or covered person (§ 202.301). The rule's examples include selling advertising inventory that passes IP addresses and advertising IDs of more than 100,000 devices to an exchange in a country of concern, and knowingly installing a pixel or SDK that sends bulk data to an app owned by a covered person
  • Data brokerage with any other foreign person unless the contract bars onward brokerage to a country of concern or covered person and the U.S. person reports known or suspected breaches of that term (§ 202.302)
  • Any covered data transaction giving a country of concern or covered person access to bulk human 'omic data or to human biospecimens from which it could be derived (§ 202.303), whatever the form of the transaction

Section 202.304 separately prohibits evasion, attempts, causing violations and conspiracies, and § 202.305 bars a U.S. person from knowingly directing a transaction by a foreign person that would be prohibited or restricted if a U.S. person engaged in it. The relationship to state data broker registration laws is covered in this publication's data broker guide; part 202 is a national security control with no registry or consumer deletion mechanism.

Restricted Transactions and the CISA Security Requirements

Three other kinds of covered data transaction are allowed on conditions. Section 202.401 permits a vendor agreement (including cloud computing), an employment agreement (including board seats and executive roles), or an investment agreement (excluding the narrowly defined passive investments in § 202.228(b), such as publicly traded securities giving a covered person under 10 per cent with no board rights) with a country of concern or covered person only if the U.S. person "complies with the security requirements" and the rest of the part. The rule's second example is plain about the alternative: a company that substitutes its own controls for the required ones has entered a prohibited transaction.

Section 202.248 incorporates by reference CISA's Security Requirements for Restricted Transactions, January 2025. CISA describes them as organizational-, system- and data-level requirements that together deny covered persons access to data that is "linkable, identifiable, unencrypted, or decryptable using commonly available technology."

Subpart J adds the paperwork. By October 6, 2025, § 202.1001 required a data compliance program with risk-based procedures to verify and log data types and volumes, counterparties and end uses, vendor identity checks, and two written policies certified annually by a compliance officer. Section 202.1002 requires an independent audit for each calendar year in which restricted transactions occur, covering the preceding 12 months, by an independent auditor who may not be a covered person, with the written report due within 60 days of the audit's completion. Section 202.1101 requires records to be kept for at least 10 years.

Two reports run on their own triggers. Under § 202.1103, a U.S. person at least 25 per cent owned by a country of concern or covered person that engages in a restricted transaction involving cloud computing files an annual report by March 1. Under § 202.1104, anyone who rejects an offer to engage in a prohibited data brokerage transaction reports it within 14 days.

Exemptions

Subpart E removes several classes of transaction from subparts C, D, J and K, although most exemptions leave the on-demand reporting duty in § 202.1102 and the rejected-transaction report in § 202.1104 in place:

  • Personal communications, informational materials and travel (§§ 202.501 to 202.503)
  • Official U.S. Government business, including by grantees and contractors (§ 202.504)
  • Transactions ordinarily incident to financial services, including payments, e-commerce purchases and investment management (§ 202.505)
  • Transactions between a U.S. person and its own subsidiary or affiliate in a country of concern, when ordinarily incident to administrative or ancillary operations (§ 202.506)
  • Transactions required or authorized by federal law or international agreements (§ 202.507), and investment agreements subject to a CFIUS action (§ 202.508)
  • Telecommunications services, except data brokerage (§ 202.509)
  • Regulatory approval data for drugs, biologics and devices, and FDA-regulated clinical investigations and post-marketing surveillance (§§ 202.510 and 202.511)

Effective Dates, Enforcement Policy and Penalties

Section 202.216 fixes the effective date at 12:01 a.m. ET on April 8, 2025. The National Security Division's Implementation and Enforcement Policy of April 11, 2025 confirmed the split: the prohibitions, restrictions and everything else applied from April 8, and subpart J with §§ 202.1103 and 202.1104 from October 6, 2025. "These effective dates remain in force," it said. The policy added that the Division "will not prioritize civil enforcement actions" for violations from April 8 through July 8, 2025 by persons making good-faith efforts to comply, while reserving action for "egregious, willful violations." The Division's FAQs dated September 24, 2025 restate the same two dates.

Section 202.1301 applies the penalties in section 206 of IEEPA, 50 U.S.C. 1705: a civil penalty up to the greater of $368,136 or twice the value of the transaction, subject to inflation adjustment, and for willful violations a fine up to $1,000,000 and imprisonment up to 20 years. Subpart M sets a pre-penalty notice process before any civil penalty. Subparts H and I let the Department issue general and specific licenses and advisory opinions on actual, non-hypothetical transactions.

The text has barely moved since January 2025. The Federal Register's index of documents affecting 28 CFR part 202 lists two proposed rules, the final rule and one correcting amendment effective April 18, 2025, which replaced a mistaken reference to "§ 202.408" in § 202.401 with "§ 202.248." The eCFR version history, read on September 21, 2026, shows no other change. This publication did not find a civil penalty or published enforcement action under part 202 on the program page or in the Division's guidance documents, and does not treat that as proof none exists.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

When did the DOJ bulk sensitive data rule take effect?
Section 202.216 sets the effective date at 12:01 a.m. ET on April 8, 2025. The due diligence and audit duties in subpart J, the annual cloud report in § 202.1103 and the rejected-transaction report in § 202.1104 applied from October 6, 2025. The National Security Division's April 2025 policy said both dates remained in force.
Does encrypting or de-identifying data take it outside 28 CFR part 202?
Not for measuring bulk. Section 202.206 applies the thresholds regardless of whether the data is anonymized, pseudonymized, de-identified or encrypted. For restricted transactions, encryption is instead one of the tools the CISA security requirements use to prevent covered persons from accessing linkable data.
Is a Chinese citizen working in the United States a covered person under the DOJ rule?
Not by nationality alone. The rule's examples state that Chinese or Russian citizens located in the United States are treated as U.S. persons and are not covered persons unless the Attorney General individually designates them.
What happens if a restricted transaction does not meet the CISA requirements?
Section 202.401 authorizes vendor, employment and investment agreements with covered persons only when the U.S. person complies with the security requirements. The rule's example states that implementing different controls instead leaves the agreement unauthorized, which makes it a prohibited transaction.
Has the Data Security Program been amended since the final rule?
Only by a correcting amendment effective April 18, 2025, which fixed a cross-reference in § 202.401. The Federal Register's index for part 202 lists no other rule, and the eCFR shows no later change as of September 21, 2026.

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.