US Federal Law United States

EO 14117 for Tech Companies: SaaS, Cloud, and AI Impacts

How the DOJ Data Security Program hits tech companies: global engineering access, cloud and support models, AI training data, investment terms, and the restructuring patterns emerging.

Regulation

Executive Order 14117; 28 CFR Part 202 (DOJ Data Security Program); CISA Security Requirements for Restricted Transactions

Max Penalty

IEEPA framework: civil penalties per violation up to the greater of ~$368,000 or twice transaction value; willful violations criminal, up to $1,000,000 and 20 years

Enforcing Authority

US Department of Justice, National Security Division

Official Source

www.justice.gov

Executive Summary

  • The DSP reaches routine tech-industry arrangements: a US SaaS company whose China-based engineers can access production data holding bulk US sensitive personal data is in a restricted employment/vendor transaction requiring CISA security controls.
  • 'Access' is the operative concept, logical access to covered data counts, so global support rotations, follow-the-sun ops, offshore QA, and admin credentials all require mapping, not just data exports.
  • AI intersects twice: training datasets containing covered data at bulk thresholds are covered assets, and model access arrangements can constitute covered data transactions.
  • Investment terms matter: non-passive investments from covered persons in companies holding bulk covered data are restricted transactions, adding a DSP screen alongside CFIUS in financings.
  • Emerging compliance patterns: geo-fenced access architectures, dedicated US data enclaves, workforce-location attestations in vendor contracts, and DSP representations appearing in enterprise procurement.

For tech companies the DSP’s radical move is redefining ‘transaction’ to include how you already operate: the offshore on-call rotation, the global admin plane, the labeling vendor, the strategic investor’s information rights. Nobody at the affected companies thinks of these as data transfers to foreign adversaries; the rule says the ability to access is the event, and location of personnel is the fact that matters. The engineering response is converging on a familiar shape, the same enclave and geo-fencing architectures FedRAMP and export-control regimes taught the industry, applied to sensitive personal data. The strategic response is more interesting: when holding bulk covered data narrows your vendor options, your investor pool, and your buyer universe, minimization stops being a privacy virtue and becomes balance-sheet hygiene.

Trigger arrangementsOffshore engineering access, global support, labeling vendors, non-passive investments
Key conceptLogical access = access; workforce location = covered-person status
AI surfacesTraining corpora as covered assets; model-access structures
Architecture patternsGeo-fenced access, US data enclaves, segregated admin planes
Deal impactDSP reps/covenants alongside CFIUS; minimization as valuation strategy
AuthorityDOJ NSD Data Security Program

The tech-company playbook

Map access, not just storage. Every credential and role that can reach covered data, by person and location; the bulk-data rule’s thresholds apply to what can be reached.

Re-architect where cheaper than complying. Deny-by-default geo-fencing that takes covered persons out of covered data often beats running the full restricted-transaction program.

Put DSP screens in the deal path. Procurement, hiring, financing, and data licensing each need a classification step; the vendor-diligence framework covers counterparty screening.

Tag training data provenance now. Covered-data content in corpora determines what model and data deals you can sign later; automated decision-making rules govern the same systems from the privacy side.

Bulk data exposure often starts with client-side collection: see what your web properties gather and transmit with a free scan.

Frequently Asked Questions

Our engineers in China can technically access production. Is that really a covered transaction?

Very likely yes, if production holds covered data at bulk thresholds. The rule treats employment agreements as covered data transactions when they involve access by covered persons, and foreign employees primarily resident in a country of concern are covered persons. 'Access' means logical or physical access, the ability to obtain the data, not proof anyone exported it; standing admin credentials, database read permissions, and debugging access to unmasked production data all qualify. That makes the arrangement a restricted transaction: permissible, but only with the CISA security requirements implemented (deny-by-default access to covered systems, minimization and masking so covered-person roles see no covered data, encryption with keys held outside countries of concern, logging) plus the written compliance program, annual audit, and recordkeeping. The alternative most companies choose: re-architect so covered-person roles cannot reach covered data at all, taking the arrangement outside the rule rather than into its compliance regime.

How does the DSP apply to cloud and managed-service providers?

Both directions. As customer: your vendor agreements are restricted transactions if the vendor's covered-person personnel (a global provider's China-based operations staff, a support subcontractor in a country of concern) can access your bulk covered data, so procurement diligence now asks where support and engineering sit, and contracts add workforce-location and access-control representations. As provider: US cloud/SaaS companies serving customers who are covered persons face the mirror analysis, providing services that give a covered person access to bulk US sensitive data can be brokerage or a restricted transaction depending on structure, and DOJ guidance addresses telecommunications and cloud scenarios specifically. Multi-tenant architecture is not a defense if tenant staff in countries of concern hold platform-level access to US persons' covered data. The market response visible in enterprise deals: US-persons-only support tiers, EU/US data enclaves with segregated admin planes, and DSP compliance attestations joining SOC 2 in security questionnaires.

What does the DSP mean for AI training data and model deals?

Two exposure surfaces. Training data: datasets assembled for model training routinely aggregate exactly the rule's categories, health records, financial transactions, geolocation traces, biometric images, and the bulk thresholds count over 12 months across the dataset, so licensing such a corpus to a covered person, or granting one access for labeling, evaluation, or fine-tuning, is a covered transaction (brokerage if you did not collect it directly, prohibited outright with countries of concern). De-identification does not exit the rule. Model access: the harder frontier question, DOJ's rule addresses data, not weights, but arrangements where a covered person's queries or fine-tuning jobs surface covered data from training corpora, or where model outputs systematically reveal US persons' sensitive data, invite scrutiny as indirect access, and evasion doctrine reaches structures designed to launder data access through models. Practical posture: provenance-tag training corpora for covered-data content, screen data-licensing and labeling counterparties as you would data buyers, and put DSP analysis in the deal path for any model licensing into China-linked entities.

How does the DSP change financings and M&A for data-rich companies?

It adds a transaction screen that runs alongside CFIUS but with different mechanics. Investment agreements giving a covered person non-passive rights (board seats, information rights beyond passive thresholds, operational involvement) in a US business holding bulk covered data are restricted transactions, requiring the CISA controls and compliance program, and passive investments must actually be passive to stay exempt. Unlike CFIUS, there is no filing-and-clearance path that blesses the deal; the obligations attach to the transaction itself and persist. Diligence consequences: cap-table screening for covered-person status (50-percent ownership chains), data-inventory disclosure (what categories and volumes does the target hold?), and DSP representations and covenants in purchase agreements, sellers warrant threshold status, buyers covenant program compliance. For exits, a covered-data-heavy asset now carries a narrower buyer universe and a diligence burden, which is pushing data minimization from compliance virtue to valuation strategy: data you deleted is a liability you no longer carry into the deal.

What should a tech company's first 90 days of DSP work look like?

Weeks 1-3, scoping: inventory covered-data categories and 12-month volumes across production, analytics, backups, and training corpora; map every access path, human and service-account, by role and location; screen the vendor list and cap table for covered persons. Weeks 4-8, triage: kill obviously prohibited flows (any brokerage-like sharing reaching countries of concern); for restricted transactions you keep, gap-assess against the CISA requirements (deny-by-default, masking, key custody, logging); for arrangements cheaper to exit than secure, re-architect access (geo-fencing, US-persons support tiers, enclave admin planes). Weeks 9-12, program: write the data compliance program (data-flow verification procedures, vendor validation, annual certification), stand up recordkeeping (10 years), schedule the annual independent audit, and wire DSP screens into procurement, hiring, and deal checklists so new transactions are classified before signature. Throughout: document good-faith effort, DOJ's enforcement posture credits demonstrated diligence, and the audit trail is the difference between a remediation conversation and an IEEPA penalty action.

Regulatory Crosswalk

CFIUSExport controls (EAR) analogiesSOC 2 / FedRAMP architectures

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.