Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The DOJ’s Data Security Program restricts certain transactions that could give countries of concern or covered persons access to government-related data or bulk U.S. sensitive personal data. Some covered transactions are prohibited; others may proceed only if they meet security requirements developed by CISA. The final rule took effect April 8, 2025, subject to congressional-review procedures.

What the DOJ rule does—and what it does not

Executive Order 14117, issued February 28, 2024, directed the Attorney General to prevent countries of concern from accessing Americans’ bulk sensitive personal data and U.S. government-related data. DOJ’s final rule implements that order through the Data Security Program.

The rule is not a blanket ban on international data transfers. It targets certain covered transactions involving a country of concern or a covered person when those transactions could provide access to the specified data. The relevant questions are what data is involved, how much there is, what kind of transaction is being used, and who could obtain access.

DOJ issued its proposed rule on October 29, 2024, and announced the final rule on December 27, 2024. The final rule was published in the Federal Register on January 8, 2025. The Federal Register lists April 8, 2025, as its effective date, subject to possible changes through congressional-review procedures. DOJ announced implementation of the program on April 11, 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which data can bring a transaction within scope?

The rule covers specified categories of U.S. sensitive personal data when the applicable bulk threshold is exceeded. The thresholds are assessed over a preceding 12-month period. Transactions involving the same U.S. person and foreign person or covered person can be aggregated, so a company should not assess each transfer in isolation.

Data category Bulk threshold
Human genomic data More than 100 U.S. persons
Other human omic data More than 1,000 U.S. persons
Biometric identifiers More than 1,000 U.S. persons
Precise geolocation data More than 1,000 U.S. devices
Personal health data More than 10,000 U.S. persons
Personal financial data More than 10,000 U.S. persons
Covered personal identifiers More than 100,000 U.S. persons

“More than” matters: the listed count is not itself the trigger; the threshold is crossed when the number exceeds it. Precise geolocation is measured by devices, while the other thresholds in this table are measured by U.S. persons.

Bulk U.S. sensitive personal data can count regardless of format, including when it has been anonymized, pseudonymized, de-identified, or encrypted, if the applicable threshold is met. Transforming a dataset therefore does not by itself establish that the rule is inapplicable.

Government-related data is a separate part of the rule’s scope. The bulk thresholds above describe categories of sensitive personal data; they should not be treated as a test that determines whether government-related data is covered.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which transaction types are covered?

The rule identifies four principal transaction categories: data brokerage, vendor agreements, employment agreements, and investment agreements. The category describes the relationship or deal through which access may be provided; it does not, by itself, settle whether a particular transaction is prohibited, restricted, exempt, or subject to a license.

  • Data brokerage: Transactions that make data available through a brokerage relationship are a central focus of the restrictions. Determine whether the arrangement qualifies as data brokerage under the rule, including whether it is an onward transfer.
  • Vendor agreements: A service or supply arrangement may be relevant when it gives a vendor access to covered data or systems holding that data.
  • Employment agreements: The rule addresses employment arrangements that can provide a covered person access to data through work duties or systems.
  • Investment agreements: An investment arrangement may be covered when it could result in access to the specified data, subject to the rule’s terms and any applicable exemption.

DOJ’s framework separates prohibited transactions from restricted transactions. Some covered transactions are prohibited, while others may be allowed only if they satisfy the applicable requirements, including CISA’s security controls. The classification depends on the rule’s detailed definitions, parties, data, and transaction facts; do not infer it from a contract label alone.

What CISA’s security requirements require

CISA developed the security requirements in coordination with DOJ for restricted transactions. They combine organizational and system-level safeguards with controls applied to the data itself. The rule’s description includes:

  • Data minimization, limiting collection, use, and access to what the activity requires.
  • Masking and encryption to reduce exposure of covered data.
  • Privacy-enhancing techniques, where applicable to the data and transaction.
  • Organizational and system-level safeguards designed to control access and protect systems involved in the transaction.

These are categories of controls, not a substitute for the detailed requirements applicable to a particular restricted transaction. Organizations should consult the operative rule and CISA requirements to determine the safeguards, implementation, and documentation that apply; a general claim that data is encrypted or access-controlled is not enough to establish compliance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which transactions are exempt?

DOJ lists exemptions for several classes of transactions, including personal communications; certain financial-services transactions; transactions within a corporate group; investment agreements subject to a CFIUS action; telecommunications; biological-product and medical-device authorizations; and clinical investigations.

An exemption is not a general carve-out for every deal that resembles one of these categories. The conditions and boundaries matter. Before relying on an exemption, check the regulation’s detailed terms against the actual parties, data, purpose, and transaction structure.

How to assess a proposed transaction

  1. Map the data. Identify whether the transaction involves government-related data or any listed category of U.S. sensitive personal data. Record the relevant population or device count.
  2. Calculate the 12-month volume. Test the applicable threshold over the preceding 12 months and assess whether transactions with the same U.S. person and foreign person or covered person must be aggregated.
  3. Identify who can access it. Determine whether the transaction could provide access to a country of concern or covered person, including through a vendor, employee, investor, or onward recipient.
  4. Classify the transaction. Evaluate whether it is data brokerage, a vendor agreement, an employment agreement, or an investment agreement, then determine whether the rule treats it as prohibited or restricted under the specific facts.
  5. Check exemptions and licensing provisions. Confirm that every condition for an exemption or any applicable license is met; do not rely on a broad description of the transaction.
  6. Apply and document required controls. If the transaction is restricted and may proceed, implement the relevant CISA-developed controls and retain records supporting the assessment and safeguards.

This sequence is a screening aid, not a legal determination. The rule’s definitions and conditions govern a specific transaction.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.