On February 28, 2024, President Joe Biden signed Executive Order 14117 to limit countries of concern and covered persons from obtaining certain bulk sensitive personal data about Americans and certain U.S. Government-related data. The order directed the Justice Department to create the rules; DOJ’s later final rule sets out which transactions are prohibited, restricted, or exempt. It is a targeted national-security program, not a general U.S. consumer-privacy law or a blanket ban on data transfers.
What did the executive order do?
Executive Order 14117, titled “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern,” directed the Attorney General to issue regulations for transactions that could give countries of concern or covered persons access to specified data. The Attorney General was to coordinate with the Department of Homeland Security and consult other relevant agencies.
The administration’s stated concern was that access to sensitive information could enable espionage, blackmail, cyber operations, profiling, or other harmful activity. The order established the policy and rulemaking direction; it did not itself set out a complete consumer privacy code or all the operational rules businesses must follow.
What information and transactions are covered?
The program focuses on bulk sensitive personal data and certain U.S. Government-related data. The sensitive-data categories identified in the order include:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
- Human genomic and other “omic” data.
- Biometric identifiers.
- Personal health data.
- Precise geolocation data.
- Personal financial data.
- Certain covered personal identifiers.
Data can be made accessible through more than a direct sale. The rule addresses transaction routes such as data-brokerage arrangements, vendor agreements, employment agreements, investment agreements, network infrastructure, and healthcare or research relationships. A transaction’s classification depends on the data, whether the relevant bulk threshold is met, the parties’ connection to a country of concern, and the transaction type.
Data brokers are a concern because they can combine separate details—such as health, financial, and travel information—into more revealing profiles. But the order does not itself ban data brokers as a business category.
Rank #2
Which countries are covered?
In its February 28, 2024 announcement, DOJ said the administration was contemplating China, Russia, Iran, North Korea, Cuba, and Venezuela as countries of concern. DOJ’s December 27, 2024 final-rule announcement describes the rule as identifying covered countries and persons. The announcement’s “contemplated” list should not be treated as a substitute for the operative rule’s designations or any later changes to covered-person lists and guidance.
DOJ’s National Security Division leads implementation, with support from Homeland Security and other agencies. The executive order also encouraged the Consumer Financial Protection Bureau to use its existing consumer-protection authorities in relation to data brokers; that is distinct from a general DOJ ban on brokerage.
How does the final rule treat transactions?
DOJ’s final rule organizes covered transactions into prohibited, restricted, and exempt classes. The labels matter: a transaction that is prohibited is not simply made permissible by applying the security controls required for a restricted transaction. The rule also provides licensing and advisory-opinion processes. Its category-specific bulk thresholds and detailed conditions determine how a particular transaction is classified.
| Class | What it means | Relevant conditions and obligations |
|---|---|---|
| Prohibited | Specified transactions are not allowed when they meet the rule’s criteria. | Classification depends on the data, applicable bulk threshold, counterparty or country-of-concern connection, and transaction type. The rule provides a licensing process; the existence of that process does not make a prohibited transaction automatically permissible. |
| Restricted | Specified transactions may proceed only subject to the rule’s conditions. | Applicable security controls and compliance obligations apply. The rule also establishes due-diligence, reporting, recordkeeping, and auditing requirements, with certain affirmative requirements phased in later than the general effective date. |
| Exempt | Transactions within listed exemptions are outside the prohibitions and restrictions described for covered transactions. | Exemptions include personal communications, certain financial services, corporate-group transactions, authorized transactions, telecommunications, medical-device activities, and clinical research, among others. The exemption’s exact scope depends on the rule’s conditions. |
This is a framework, not a single threshold or universal test. The bulk threshold varies by data category, and the counterparty and transaction details matter. Businesses assessing a specific arrangement need to use the rule’s definitions, thresholds, exceptions, security requirements, and licensing procedures rather than relying on the executive-order announcement alone.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When did the DOJ rule take effect?
DOJ announced the comprehensive final rule on December 27, 2024. The rule states that its general effective date is 90 days after publication. Certain affirmative due-diligence, reporting, and auditing requirements take effect 270 days after publication. Those periods run from publication—not from the announcement date—so the announcement date alone does not establish either calendar deadline.
Does the policy require data to be stored in the United States?
No. The executive order and final rule do not impose generalized data localization or require every computing facility that handles covered data to be located in the United States. Their focus is on specified transactions that could provide countries of concern or covered persons access to covered data. They also do not broadly prohibit ordinary commercial transactions: the final rule includes exemptions for several transaction types, subject to their stated conditions.
What this means for readers and businesses
For individuals, the order is not a new general right to control all personal data held by U.S. companies. It is a national-security measure aimed at certain bulk data and access pathways. For an organization, the practical question is not simply whether data crosses a border: it is whether the information falls within a covered category and threshold, whether a relevant party or country connection exists, and whether the transaction is prohibited, restricted, or exempt under the final rule.
The 2024 order and the later DOJ rule should therefore be read as two stages of the same policy: the order directed action, while the final rule supplies the transaction classifications and compliance framework.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

