EO 14117 imported export-control logic into data: some information is now effectively a controlled commodity when the counterparty is China, Russia, or their proxies, and no amount of consent, anonymization, or contractual cleverness converts a prohibited transfer into a permitted one. That design choice, covering de-identified and encrypted data, counting devices as well as people, reaching foreign vendors’ employees, breaks every intuition trained on privacy law, which is precisely the point: the threat model is re-identification and intelligence exploitation at scale, not individual notice and choice. The compliance center of gravity is the data inventory: firms that know their categories, volumes, and foreign access paths can run the thresholds and paper the program; firms that treated ‘where does our data go?’ as unanswerable are the rule’s intended audience.
| Authority | EO 14117 + 28 CFR Part 202 (DOJ NSD) |
|---|---|
| Countries | China (incl. HK/Macau), Russia, Iran, North Korea, Cuba, Venezuela |
| Thresholds | 100 (genomic) to 100,000 (identifiers); geolocation 1,000 devices; gov-related data: any volume |
| Prohibited | Data brokerage; ‘omic data access |
| Restricted | Vendor/employment/investment deals, under CISA requirements |
| Key dates | Effective Apr 8, 2025; program duties Oct 6, 2025 |
| No exit via | Anonymization, de-identification, encryption, consent |
Standing up DSP compliance
Build the covered-data inventory first. Categories, 12-month volumes, and every foreign access path; thresholds are unanswerable without it.
Screen counterparties to the ownership and workforce level. Covered-person status hides in cap tables and staffing locations; the vendor-diligence playbook operationalizes the screens.
Classify transactions before paper. Brokerage is dead on arrival with covered persons; vendor and employment deals need the CISA requirements wired in, tech-company patterns cover the common structures.
Treat it as sanctions law, not privacy law. IEEPA penalties, criminal exposure for willfulness, 10-year records; existing health-data and privacy programs are complements, not substitutes.
Covered data often leaves through the web stack first: map what your site sends where with a free scan.