0% found this document useful (0 votes)
11 views1 page

U.S. Data Security Program Overview

Data security

Uploaded by

sendilks96
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
11 views1 page

U.S. Data Security Program Overview

Data security

Uploaded by

sendilks96
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

U.S.

Data Security
Program
Cheat Sheet
The U.S. Department of Justice’s final rule on protecting Americans’ sensitive data took effect on 8 April 2025. The Data Security Program was adopted
pursuant to Executive Order 14117 and is implemented by the DOJ’s National Security Division. The DSP establishes controls to prevent foreign
adversaries, and those subject to their control and direction, from accessing bulk U.S. sensitive personal data and U.S. government-related data.

Scope Thresholds for bulk data


The Data Security Program applies to any U.S. person that engages in transactions Sensitive personal data means human genomic and other human `omic data,
involving U.S. sensitive personal data or U.S. government-related data when there biometric identifiers, precise geolocation data, personal financial data, personal
is a potential for access by covered persons or countries of concern. health data, covered personal identifiers or any combination thereof. “Bulk” sensitive
personal data is defined by numerical thresholds. The thresholds apply over any
A transaction is within the scope of the rule if:
12-month period and may be met through a single transaction or multiple related
 It involves any access by a country of concern or covered person to any transactions.
bulk U.S. sensitive personal data or government-related data.

 It involves: Type Bulk threshold


• Data brokerage
Human genomic data More than 100 U.S. persons
• Vendor agreements
• Employment agreements
• Investment agreements Human `omic data (§ 202.224) More than 1,000 U.S. persons

Access means logical or physical access, including the ability to obtain, read, copy,
decrypt, edit, divert, release, affect, alter the state of or otherwise view or receive, Biometric identifiers (§ 202.204) More than 1,000 U.S. persons
in any form, including through information systems, information technology systems,
cloud-computing platforms, networks, security systems, equipment or software.
Precise geolocation data (§ 202.242) More than 1,000 U.S. devices
Currently, there are six designated countries of concern:

1. China (including Hong Kong and Macau) Personal financial data (§ 202.240) More than 10,000 U.S. persons
2. Cuba
3. Iran Personal health data (§ 202.241) More than 10,000 U.S. persons
4. North Korea
5. Russia Covered personal identifiers
More than 100,000 U.S. persons
6. Venezuela (§ 202.212)

Aggregate for the lowest number


Combined data (§ 202.205(g)) of U.S. persons or U.S. devices
Selected definitions in that category of data

A U.S. person is anyone who is a U.S. citizen, national, or lawful permanent


resident, i.e., green card holder; any individual admitted to the U.S. as a refugee
or granted asylum; any individual or entity physically present in the U.S., regardless
of citizenship or immigration status; and any entity organized solely under the
laws of the U.S., including the foreign branches of such entities. Exemptions
A covered person is a foreign entity with its principal place of business in, or Several categories of transactions are exempt from all or parts of the DSP.
organized under the laws of, a country of concern or that is 50% or more owned, Notable exemptions include:
directly or indirectly, individually or in the aggregate, by one or more countries • Personal communications, such as email or phone calls, not involving the
of concern or other covered persons; a foreign individual that is an employee or transfer of anything of value (§ 202.501).
contractor of a country of concern or of an entity that is a covered person; or a
foreign individual primarily resident in a country of concern. In addition, anyone • The import or export of information or informational materials (§ 202.502).
the U.S. attorney general determines to meet certain specified criteria, such as • Activities conducted on behalf of the U.S. government or required by federal
acting on behalf of, being controlled by, or being subject to the jurisdiction of a law (§§ 202.504, 202.507).
country of concern or a covered person.
• Data transactions ordinarily incident to and part of the provision of financial
A country of concern is a foreign nation that has shown a long-term pattern or services (§ 202.505) or telecommunications service (§ 202.509).
serious instances of conduct significantly harmful to U.S. national security or the
safety of its citizens and poses a significant risk of exploiting sensitive U.S. personal • Corporate group transactions (§ 202.506).
data or government-related data in ways that could harm the U.S. • Investment agreements subject to a Committee on Foreign Investment in the
Bulk U.S. sensitive personal data means a collection or set of sensitive personal United States action (§ 202.508).
data relating to U.S. persons, where the volume of such data meets or exceeds the • Drug, biological product and medical device authorizations (§ 202.510).
threshold specified in the rule for the particular type of data. Whether the data
qualifies as “bulk” depends on volume thresholds over a 12-month period. • Medical research or clinical trials that fall under certain regulatory
frameworks (§§ 202.510–511).
Government-related data is
• Any precise geolocation data, regardless of volume, that relates to areas
identified on the DOJ’s Government-Related Location Data List, including
but not limited to military installations, intelligence facilities or worksites Compliance, recordkeeping and reporting obligations
of national security employees. U.S. persons engaging in restricted transactions must implement robust
• Any sensitive personal data, regardless of volume, that is marketed compliance measures including:
as being linked or linkable to current or recent federal employees or
contractors, or former senior officials of the U.S. government, including • Due diligence (§ 202.1001).
the military and intelligence community. • Audits (§ 202.1002).
• Recordkeeping and reporting (§§ 202.1101–1104).

Data brokerage refers to the sale of data, licensing of access to data or similar U.S. persons must maintain detailed records of restricted and prohibited
commercial transactions where the recipient did not directly collect or process the transactions, internal controls and due diligence efforts. U.S. persons must also:
data from the individuals to whom it relates. This definition excludes employment,
investment and vendor agreements, but it includes both first-party, or primary, data • Submit annual reports to the DOJ summarizing covered transactions
brokers who collect and sell information from their own customers and third-party (§ 202.1103).
data brokers who purchase and resell data they did not collect in the first instance. • Report if they have received and affirmatively rejected any offer from
another person to engage in a prohibited transaction involving data
brokerage (§ 202.1104).

Transaction types • Provide additional documentation if requested by the DOJ (§ 202.1102).

A covered data transaction is any transaction that involves any access by a


country of concern or covered person to any government-related data or bulk U.S.
sensitive personal data and that involves data brokerage, a vendor agreement,
an employment agreement or an investment agreement.
Licensing
The DOJ provides two mechanisms for permitting otherwise restricted transactions:
Prohibited transactions are
• Any data brokerage transaction that involves any access by a country of 1. General licenses, which authorize a broad class of transactions, may be
concern or covered person to any government-related data or bulk U.S. published by the DOJ (§ 202.801).
sensitive personal data; 2. A specific license applies to a particular transaction and must be
• Any data brokerage transaction with a foreign person who is not a requested by submitting an application to the DOJ (§ 202.802).
covered person unless the U.S. person contractually requires that the
foreign person refrain from onward sale with a country of concern or
covered person and reports any known or suspected violations of that
contractual requirement; and Enforcement
• Any covered data transactions with countries of concern or covered The DOJ is responsible for enforcing this rule and may take action through:
persons involving access to bulk human `omic data or human
1. Civil penalties, including fines up to USD368,136 or twice the amount of
biospecimens from which bulk human `omic data could be derived.
the transaction that is the basis of the violation, whichever is greater.
Evasions, attempts, causing violations and conspiracies to violate the DSP are
2. Criminal penalties: up to 20 years’ imprisonment and a fine of up to
also prohibited.
USD1 million for a person who willfully commits, willfully attempts to
Restricted transactions are covered data transactions involving a vendor commit, willfully conspires to commit, or aids or abets in the commission
agreement, employment agreement or investment agreement with a country of a violation.
of concern or covered person. See Subpart D of the rule.

Legal authority: 50 U.S.C. § 1701 et seq.; Executive Order 14117


Implementing regulation: 28 C.F.R. Part 202
Effective date: 8 April 2025

© 2025 IAPP. All rights reserved.


Published July 2025.
IAPP disclaims all warranties, expressed or implied, with respect to the contents of this material, including any warranties
of accuracy, merchantability or fitness for a particular purpose. Nothing herein should be construed as legal advice. [Link]

You might also like