Cross-Border Transfers

The Justice Department's Bulk Sensitive Data Rule: Six Countries, Six Data Categories, and Two Compliance Dates in 2025

September 21, 2026

Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.

Read more →
Data Security Rules

Five Years of the Civil Cyber-Fraud Initiative: Sixteen Settlements, Ten Whistleblower Suits and No Judgment

September 21, 2026

The Justice Department launched the Civil Cyber-Fraud Initiative on October 6, 2021 to pursue government contractors and grantees under the False Claims Act for knowing cybersecurity failures. This publication located sixteen resolved matters announced in DOJ releases through September 1, 2026, totaling about $69.1 million. Every one settled, and most began as whistleblower suits.

Read more →
Data Brokers

Data Broker Registration: The Four State Registries and What They Require

August 24, 2026

Data broker registration is the one privacy obligation that starts with a public filing rather than a consumer request. Four states — California, Vermont, Texas and Oregon — operate registries, and each defines the regulated entity differently enough that a company can be a broker in one and not the next. This guide reads the four statutes against each other.

Read more →