Skip to main content
ExplainerData GovernanceExplainerAug 21, 2026, 3:56 PM· 5 min read· in technology

DOJ Begins Enforcing New Restrictions on Bulk Transfers of Americans' Sensitive Data

The Department of Justice is actively enforcing its new Data Security Program, effectively creating an export control regime for Americans' sensitive personal data. The rule prohibits or heavily restricts the transfer of bulk health, financial, and geolocation data to six designated 'countries of concern.'

By Elena Castillo

National Security Advocates 40%Healthcare & Research Compliance 35%Corporate Risk Managers 25%
National Security Advocates
Argue that the commercial data market is a standing vulnerability that foreign adversaries exploit for espionage and AI development.
Healthcare & Research Compliance
Focus on the chilling effect these export-style controls could have on international scientific collaboration and clinical trials.
Corporate Risk Managers
Highlight the immense compliance burden of auditing global supply chains, vendor agreements, and cloud infrastructure.

At a glance

  • The DOJ's Data Security Program restricts the transfer of Americans' bulk sensitive data to six countries of concern.
  • The rule applies to data brokers, vendor agreements, employment contracts, and investment agreements.
  • Volume thresholds dictate what is covered, such as 100 persons for genomic data and 1,000 for geolocation data.
  • Anonymized and encrypted data is still subject to the restrictions if it meets the volume thresholds.
  • Active enforcement of the rule's strict audit and reporting requirements begins in October 2026.

Why it matters now

This rule fundamentally changes how U.S. companies manage data, turning consumer privacy into a national security mandate. Organizations must now audit their entire global supply chain to ensure sensitive information does not reach foreign adversaries, carrying the risk of massive fines and criminal charges for non-compliance.

The United States has officially turned data privacy into a matter of national security. Under the Department of Justice’s new Data Security Program (DSP), it is now illegal for American companies to transfer bulk sensitive personal data to six designated "countries of concern." The rule, which was finalized to implement a sweeping executive order, effectively creates an export control regime for digital information. It targets China—including Hong Kong and Macau—along with Russia, Iran, North Korea, Cuba, and Venezuela. By shifting the regulatory focus from consumer privacy to counterintelligence, the federal government is acknowledging a reality that the tech industry has long downplayed: the commercial data market is a standing national security vulnerability that adversaries have actively exploited.[1][4]

For years, the global data economy operated with minimal friction. While technology companies marketed their cloud infrastructure as seamless and borderless, the underlying reality was far more transactional. Data brokers were legally scraping, packaging, and selling the sensitive information of millions of Americans to the highest bidder, which frequently included foreign actors and state-sponsored entities. The DSP was designed specifically to close this exact vulnerability. It addresses the commercial means by which foreign adversaries acquire Americans’ sensitive personal data, recognizing that bulk data can be weaponized for espionage, surveillance, and the development of military artificial intelligence.[1]

Despite the sweeping "national security" framing often utilized in political speeches, the actual capability of the rule is highly specific. It does not ban all international data flows or attempt to break the global internet. Instead, the DOJ established strict volume thresholds that define exactly what constitutes "bulk" data. For example, the threshold for human genomic data is set at just 100 U.S. persons. For precise geolocation data or biometric identifiers, the limit is 1,000 persons. Once those specific thresholds are met within a rolling 12-month period, the data becomes subject to the DSP’s stringent restrictions.[4][5]

The rule targets the commercial data market, blocking bulk transfers to designated foreign adversaries.

Crucially, the rule cuts through common tech-industry marketing language regarding data anonymization. The DSP applies regardless of whether the data has been anonymized, pseudonymized, de-identified, or encrypted. If the volume threshold is met, the data is covered by the regulation. This closes a major loophole that data brokers historically used to justify selling sensitive datasets, arguing that the removal of names and social security numbers rendered the information harmless. The DOJ’s stance is clear: at scale, anonymized data can easily be de-anonymized by sophisticated state actors with access to massive computing power.[4]

The mechanism of the rule goes far beyond traditional data brokerage. The DSP heavily regulates vendor agreements, employment contracts, and investment agreements. This means a U.S. company utilizing a cloud storage provider, a software-as-a-service platform, or a managed service provider based in a country of concern could be in direct violation of the rule if bulk sensitive data is accessible to that vendor. It forces companies to look past the marketing brochures of their IT vendors and conduct deep due diligence on where their data physically resides and who holds the decryption keys.[1][2]

The mechanism of the rule goes far beyond traditional data brokerage.

Healthcare organizations and research institutions are particularly exposed to these new compliance mandates. Clinical trials that involve sharing biospecimens or genomic data with international partners must now navigate these national security restrictions alongside existing HIPAA compliance. Even data that is fully de-identified in accordance with HIPAA regulations may still be regulated under these new national security rules if it meets the DOJ’s bulk thresholds. This adds a massive layer of complexity for universities and pharmaceutical companies working with offshore resources or international research coalitions.[2][5]

The DOJ has established strict volume thresholds that define what constitutes 'bulk' data.

However, the DOJ did carve out specific exemptions to protect scientific progress and prevent a total freeze on global research. The rule does not prohibit U.S. persons from conducting medical, scientific, or other research in countries of concern, provided the activity does not involve the exchange of payment or other consideration as part of a covered data transaction. While this exemption exists on paper, research compliance offices are currently scrambling to audit their international collaborations, often pausing risky transfers until they can secure specific licenses or implement bulletproof contractual safeguards against onward transfers.[5]

The operational reality for corporate America is daunting. While the core prohibitions took effect in April 2025, the active enforcement of the rule’s security, audit, and reporting mandates ramps up in October 2026. Organizations must implement comprehensive data compliance programs, conduct annual independent audits, and maintain detailed records of all restricted transactions for at least ten years. These audits must examine a range of activities, including data practices, security safeguards, and recordkeeping, with a company officer required to certify the accuracy of these records annually.[4]

Companies face strict new audit and reporting mandates, with severe penalties for non-compliance.

The penalties for getting it wrong are severe, reflecting the government's zero-tolerance approach to national security breaches. Civil fines can reach nearly $378,000 per violation, or twice the value of the transaction, whichever is greater. More significantly, willful criminal violations carry fines of up to $1 million and up to 20 years in prison for individuals. This shifts the risk calculus for executives, making data compliance a board-level issue rather than a standard operational cost that can simply be absorbed.[2][4]

This regulatory shift is part of a broader, aggressive federal playbook for cyber risk. It aligns with updated Department of Defense certification rules and increasingly stringent state-level privacy mandates. Ultimately, the DSP forces a fundamental reevaluation of global supply chains. Data security is no longer just an IT problem relegated to the server room; it is a core geopolitical compliance mandate. Companies can no longer afford to be ignorant of their data's geography, requiring continuous, skeptical vetting of every vendor and partner in their network.[3][6]

Terms to know

Data Security Program (DSP)
The DOJ regulatory framework that functions as an export control regime for sensitive personal data.
Countries of Concern
Specific foreign nations designated by the U.S. government as posing a national security threat regarding data access.
Covered Person
An individual or entity that is owned, controlled by, or subject to the jurisdiction of a country of concern.
Bulk Data
Sensitive personal data that meets or exceeds specific volume thresholds within a 12-month period.
Human 'omic Data
Biological data, such as genomic information, used in scientific and medical research.

Questions readers ask

What is the DOJ Data Security Program?

A federal rule that restricts the transfer of Americans' bulk sensitive data to six designated countries of concern.

Which countries are considered "countries of concern"?

The rule currently designates China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela.

Does this rule apply to anonymized data?

Yes. If the data meets the volume threshold, it is covered regardless of whether it is anonymized, pseudonymized, or encrypted.

What happens if a company violates the rule?

Violators face steep civil penalties of up to $377,700 per violation, and willful violations can result in criminal charges and prison time.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

National Security Advocates 40%Healthcare & Research Compliance 35%Corporate Risk Managers 25%
  1. [1]LawfareNational Security Advocates

    The Data Security Program was designed to address this risk

    Read on Lawfare
  2. [2]Healthcare Law InsightsHealthcare & Research Compliance

    Department of Justice Bulk Sensitive Personal Data Transfer Rule (28 CFR Part 202)

    Read on Healthcare Law Insights
  3. [3]Morgan LewisCorporate Risk Managers

    A New Federal Playbook for Cyber Risk

    Read on Morgan Lewis
  4. [4]Government Contracts LawNational Security Advocates

    DOJ Launches New Data Security Program—What Your Company Needs to Know

    Read on Government Contracts Law
  5. [5]UCSFHealthcare & Research Compliance

    DOJ Bulk Sensitive Data Transfer Rule

    Read on UCSF
  6. [6]Factlen Editorial Team

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.