US Federal Law United States

EO 14117 Bulk Data Rules: The DOJ Data Security Program

Executive Order 14117 and the DOJ's 28 CFR Part 202 rules: covered data categories, bulk thresholds, countries of concern, prohibited and restricted transactions, and compliance dates.

Regulation

Executive Order 14117 (Feb 28, 2024); DOJ final rule, 28 CFR Part 202 (Data Security Program), effective April 8, 2025, with due-diligence/audit/reporting obligations from October 6, 2025

Max Penalty

IEEPA-based: civil penalties up to the greater of ~$368,000 (inflation-adjusted) or twice the transaction value per violation; willful criminal violations up to $1,000,000 and 20 years

Enforcing Authority

US Department of Justice, National Security Division; CISA security requirements for restricted transactions

Official Source

www.justice.gov

Executive Summary

  • EO 14117 and the DOJ's implementing Data Security Program (28 CFR Part 202) restrict transactions that give countries of concern, China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela, access to bulk US sensitive personal data or government-related data.
  • Six covered data categories: covered personal identifiers, precise geolocation, biometric identifiers, human 'omic data, personal health data, and personal financial data, each with its own bulk threshold (from 100 US persons for human genomic data to 100,000 for identifiers).
  • Prohibited outright: data brokerage with countries of concern or covered persons, and transactions giving access to human 'omic data or biospecimens above thresholds; restricted (allowed with CISA security requirements): vendor, employment, and investment agreements.
  • Government-related data has no bulk threshold: any amount of precise geolocation in listed areas or data marketed as concerning government personnel is covered.
  • The rule took effect April 8, 2025; due diligence, audit, and reporting obligations for restricted transactions applied from October 6, 2025, and DOJ signaled full enforcement after an initial good-faith period ended July 8, 2025.

EO 14117 imported export-control logic into data: some information is now effectively a controlled commodity when the counterparty is China, Russia, or their proxies, and no amount of consent, anonymization, or contractual cleverness converts a prohibited transfer into a permitted one. That design choice, covering de-identified and encrypted data, counting devices as well as people, reaching foreign vendors’ employees, breaks every intuition trained on privacy law, which is precisely the point: the threat model is re-identification and intelligence exploitation at scale, not individual notice and choice. The compliance center of gravity is the data inventory: firms that know their categories, volumes, and foreign access paths can run the thresholds and paper the program; firms that treated ‘where does our data go?’ as unanswerable are the rule’s intended audience.

AuthorityEO 14117 + 28 CFR Part 202 (DOJ NSD)
CountriesChina (incl. HK/Macau), Russia, Iran, North Korea, Cuba, Venezuela
Thresholds100 (genomic) to 100,000 (identifiers); geolocation 1,000 devices; gov-related data: any volume
ProhibitedData brokerage; ‘omic data access
RestrictedVendor/employment/investment deals, under CISA requirements
Key datesEffective Apr 8, 2025; program duties Oct 6, 2025
No exit viaAnonymization, de-identification, encryption, consent

Standing up DSP compliance

Build the covered-data inventory first. Categories, 12-month volumes, and every foreign access path; thresholds are unanswerable without it.

Screen counterparties to the ownership and workforce level. Covered-person status hides in cap tables and staffing locations; the vendor-diligence playbook operationalizes the screens.

Classify transactions before paper. Brokerage is dead on arrival with covered persons; vendor and employment deals need the CISA requirements wired in, tech-company patterns cover the common structures.

Treat it as sanctions law, not privacy law. IEEPA penalties, criminal exposure for willfulness, 10-year records; existing health-data and privacy programs are complements, not substitutes.

Covered data often leaves through the web stack first: map what your site sends where with a free scan.

Frequently Asked Questions

What data is covered, and what are the bulk thresholds?

Six categories of sensitive personal data, counted over the preceding 12 months: human 'omic data (genomic, epigenomic, proteomic, transcriptomic), bulk at 100 US persons for genomic (1,000 for the others); biometric identifiers (facial templates, voiceprints, fingerprints), 1,000 US persons; precise geolocation (within 1,000 meters), 1,000 US devices; personal health data, 10,000 US persons; personal financial data (payment cards, accounts, credit history), 10,000 US persons; covered personal identifiers (listed classes of identifiers, government IDs, device identifiers, demographic or contact data linked to other identifiers, that are linked or linkable), 100,000 US persons. Combined datasets take the lowest applicable threshold. Anonymization is no exit: the rule covers data regardless of whether it is anonymized, pseudonymized, de-identified, or encrypted, a deliberate rejection of the privacy-law playbook, grounded in re-identification risk at bulk scale. Government-related data (precise geolocation within the Government-Related Location Data List's coordinates, or any data marketed as concerning federal employees or contractors) is covered at ANY volume.

What is prohibited versus restricted?

Prohibited (no license, no security measures suffice): data brokerage, selling, licensing, or otherwise providing access to covered data where the recipient did not collect it directly, with countries of concern or covered persons; any covered transaction giving access to bulk human 'omic data or human biospecimens from which it can be derived; and knowingly directing prohibited transactions, plus evasion structures. Data brokerage with ANY foreign person requires contractual onward-transfer restrictions (the foreign counterparty must agree not to resell to countries of concern) with reporting of known violations. Restricted (permitted only under CISA's security requirements plus the compliance program): vendor agreements (including cloud and IT services), employment agreements, and non-passive investment agreements involving covered data access by covered persons. The CISA requirements are substantive: asset inventories, logical and physical access controls, data minimization and masking, encryption with key custody outside countries of concern, and denial-by-default configurations for covered systems.

Who is a 'covered person'?

Four definitional classes plus designations: entities 50-percent-or-more owned by, organized under the laws of, or with principal place of business in a country of concern; entities 50-percent-or-more owned by covered persons; foreign-person employees and contractors of such entities or of countries of concern; and foreign persons primarily resident in countries of concern. DOJ can also designate specific persons anywhere. The practical sting is in the workforce and corporate-structure math: a US company's transaction with a European vendor becomes restricted if that vendor's covered-person employees (say, staff resident in China) get access to the covered data; a Cayman fund majority-owned by PRC entities is a covered person regardless of domicile. Diligence therefore has to reach ownership chains and workforce location for any counterparty touching covered data, screening the entity's flag alone misses most of the definition.

What compliance program does the rule expect?

For restricted transactions, mandatory since October 6, 2025: a written data compliance program with risk-based procedures verifying data flows (types and volumes of covered data, transaction parties, end-use), vendor identity validation, and written policies certified annually; annual independent audits verifying compliance and CISA-requirement implementation; recordkeeping (10 years); and reports to DOJ for certain transactions, including any rejected prohibited-transaction offers and known onward-transfer violations. For everyone: know-your-data as a de facto obligation, you cannot apply thresholds you have not measured, so data inventories mapping categories, volumes, and foreign access paths are the foundational artifact. DOJ's April 2025 guidance promised enforcement restraint through July 8, 2025 for good-faith compliance efforts, then expected full implementation; NSD has framed the program as national-security enforcement, meaning IEEPA-scale penalties and criminal referral for willful evasion, not privacy-style corrective plans.

How does this interact with PADFAA and existing privacy law?

Three regimes now govern foreign access to Americans' data, with different hooks. EO 14117/DSP: transaction-based, six data categories with thresholds, six countries, DOJ-enforced. PADFAA (April 2024): prohibits data brokers from selling personally identifiable sensitive data of US individuals to foreign-adversary-controlled entities, FTC-enforced, no bulk thresholds, narrower actor (brokers) but immediate effect. CFIUS: investment-based review where foreign acquisitions implicate sensitive personal data of US citizens (the Grindr and TikTok fact patterns). None preempts privacy law: state comprehensive statutes, sectoral rules (HIPAA, GLBA, FCRA), and state genetic-privacy acts apply concurrently, and their consent or de-identification mechanisms do NOT excuse DSP compliance, again, the DSP covers even de-identified data. Practical synthesis: map covered data once, then run three screens (am I brokering to adversary-controlled entities? do my transactions give covered persons access? does any investment involve my data assets?), because the same dataset can trigger all three regimes on a single deal.

Regulatory Crosswalk

CFIUSProtecting Americans' Data from Foreign Adversaries Act (PADFAA)State genetic-privacy laws

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.