DOJ Data Security Program: Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons
DOJ Bulk Data Rule
Data brokers · Data security · Genetic · Biometric · Location · Health · Financial
This regulation bars U.S. persons from data brokerage and genomic-data transactions that give countries of concern or covered persons access to bulk sensitive personal data or government-related data. Other vendor, employment, and investment transactions are allowed only if CISA security requirements are met. Bulk thresholds range from 100 persons (genomic data) to 100,000 persons (covered identifiers); due diligence, audit, and reporting duties began October 6, 2025.
- Where
- Federal
- Citation
- 28 CFR Part 202 (implementing Executive Order 14117 under IEEPA, 50 U.S.C. 1701-1706)
- Status
- In force
- In force since
- 2025-04-08
- Last amended
- 2025-04-18
- Enforced by
- U.S. Department of Justice, National Security Division
- People can sue
- No
- Penalties
- IEEPA penalties apply (50 U.S.C. 1705): civil penalties per violation (the greater of an inflation-adjusted fixed amount or twice the transaction value) and criminal fines and imprisonment for willful violations.
- Applies to
- U.S. persons (companies and individuals) that engage in data brokerage, vendor, employment, or investment agreements giving countries of concern (China incl. Hong Kong and Macau, Cuba, Iran, North Korea, Russia, Venezuela) or covered persons access to bulk U.S. sensitive personal data or government-related data
Practices it requires
- Do not knowingly engage in covered data transactions involving data brokerage with a country of concern or covered person.28 CFR 202.301
- Data brokerage with other foreign persons requires contractual limits on onward transfer to countries of concern and reporting of known or suspected violations.28 CFR 202.302
- Do not engage in transactions giving countries of concern or covered persons access to bulk human 'omic data or biospecimens.28 CFR 202.303
Security duties
- Restricted (vendor, employment, investment) transactions are permitted only in compliance with the incorporated CISA security requirements.28 CFR 202.401, 202.248
Other duties
- Keep full and accurate records of each transaction subject to the rule for at least 10 years.28 CFR 202.1101(a)
- U.S. persons engaged in restricted transactions must implement a written data compliance program with data-flow verification and vendor procedures.28 CFR 202.1001 · From 2025-10-06
- Obtain an independent annual audit of restricted transactions.28 CFR 202.1002 · From 2025-10-06
- Report rejected prohibited data brokerage offers to DOJ within 14 days; certain cloud-computing restricted transactions require annual reports.28 CFR 202.1103, 202.1104 · From 2025-10-06
Sources
- Official text
- 28 CFR Part 202 (eCFR)
- DOJ final rule, 90 FR 1636 (Jan. 8, 2025)
- DOJ correction, 90 FR 16466 (Apr. 18, 2025)
Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.
Unverified: IEEPA penalty amounts were not fetched | A search result mentioned 2026 updates to the rule; no 2026 Federal Register rule for 28 CFR 202 was found and eCFR shows no amendment after 2025-04-18
Research reference, not legal advice.