DOJ Data Security Program (Bulk Sensitive Personal Data Rule)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 8 April 2025.
A cross border transfer rule binding private bodies.
As of 23 August 2026.
What it requires
- Do not engage in a prohibited bulk data-brokerage transaction involving bulk U.S. sensitive personal data, including biometric identifiers such as facial images or voice prints, or government-related data, with a country of concern or covered person.
- Apply the required security safeguards to a restricted vendor, employment, or investment transaction that would give a country of concern or covered person access to that data.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Willfully committing, attempting, or conspiring to commit a violation of a Data Security Program license, order, regulation, or prohibition is a federal crime under 50 U.S.C. 1705(c) and 28 CFR 202.1301(a)(3): a fine of up to $1,000,000, and for a natural person imprisonment of up to 20 years, or both.
Penalty structure
IEEPA (50 U.S.C. 1705(b)), applicable to a Data Security Program violation via 28 CFR 202.1301(a), sets the nominal civil penalty ceiling at the greater of $250,000 or twice the transaction value underlying the violation. 28 CFR 202.1301(a)(2) states the current inflation-adjusted figure for the fixed leg as $368,136; a court or the Department may instead impose twice the transaction amount where that alternative is greater, which is not a fixed dollar figure and so is not itself recorded as a cap here.
- Rule
- Fixed only
- As of
- 2 September 2026
- Currency
- USD
- Fixed cap
- 368,136
Who enforces it
Enforcement body
U.S. Department of Justice, National Security Division
Enforcement record
The National Security Division's own Public Actions page for the Foreign Investment Review Section, its chronological log of program milestones and enforcement matters, lists only rulemaking and policy documents under its Data Security tag: the February 2024 executive order and advance notice, the October 2024 proposed rule, the December 2024 final rule, and the April 11, 2025 announcement implementing the program with an initial 90-day enforcement policy. It names no civil penalty, judicial action, or other completed enforcement matter brought under 28 CFR Part 202 as of the page's own last update. NSD's separate Data Security Program overview page, updated more recently on September 24, 2025, likewise lists only the rule text, FAQs, and a compliance guide under its Current Resources heading and names no enforcement action. The rule took effect April 8, 2025 with an initial enforcement policy running through July 8, 2025.
- As of
- 17 September 2026
- Source link
- https://www.justice.gov/nsd/public-actions-0
What it reaches
Excludes recording-derived identifiersNo
Obligation class
Transfer, Security, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Prohibits U.S. persons from engaging in data-brokerage transactions involving bulk U.S. sensitive personal data or government-related data with a country of concern or covered person, and restricts, subject to required security measures, vendor, employment, and investment-agreement transactions that would give such a country or person access to bulk sensitive personal data, including biometric identifiers such as facial images or voice prints collected on more than 1,000 U.S. persons, or human genomic data on more than 100.
When LexLint raises it
crawls_webtrains_modelsprocesses_biometricsprocesses_voice
Read the law
Federal Register final rule text, via govinfo.gov
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.