Law / United States

DOJ Data Security Program (Bulk Sensitive Personal Data Rule)

28 CFR Part 202

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 8 April 2025.

A cross border transfer rule binding private bodies.

As of 23 August 2026.

What it requires

  • Do not engage in a prohibited bulk data-brokerage transaction involving bulk U.S. sensitive personal data, including biometric identifiers such as facial images or voice prints, or government-related data, with a country of concern or covered person.
  • Apply the required security safeguards to a restricted vendor, employment, or investment transaction that would give a country of concern or covered person access to that data.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Willfully committing, attempting, or conspiring to commit a violation of a Data Security Program license, order, regulation, or prohibition is a federal crime under 50 U.S.C. 1705(c) and 28 CFR 202.1301(a)(3): a fine of up to $1,000,000, and for a natural person imprisonment of up to 20 years, or both.

Penalty structure

IEEPA (50 U.S.C. 1705(b)), applicable to a Data Security Program violation via 28 CFR 202.1301(a), sets the nominal civil penalty ceiling at the greater of $250,000 or twice the transaction value underlying the violation. 28 CFR 202.1301(a)(2) states the current inflation-adjusted figure for the fixed leg as $368,136; a court or the Department may instead impose twice the transaction amount where that alternative is greater, which is not a fixed dollar figure and so is not itself recorded as a cap here.

Rule
Fixed only
As of
2 September 2026
Currency
USD
Fixed cap
368,136

Who enforces it

Enforcement body

U.S. Department of Justice, National Security Division

Enforcement record

The National Security Division's own Public Actions page for the Foreign Investment Review Section, its chronological log of program milestones and enforcement matters, lists only rulemaking and policy documents under its Data Security tag: the February 2024 executive order and advance notice, the October 2024 proposed rule, the December 2024 final rule, and the April 11, 2025 announcement implementing the program with an initial 90-day enforcement policy. It names no civil penalty, judicial action, or other completed enforcement matter brought under 28 CFR Part 202 as of the page's own last update. NSD's separate Data Security Program overview page, updated more recently on September 24, 2025, likewise lists only the rule text, FAQs, and a compliance guide under its Current Resources heading and names no enforcement action. The rule took effect April 8, 2025 with an initial enforcement policy running through July 8, 2025.

As of
17 September 2026
Source link
https://www.justice.gov/nsd/public-actions-0

What it reaches

Excludes recording-derived identifiersNo

Obligation class

Transfer, Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Prohibits U.S. persons from engaging in data-brokerage transactions involving bulk U.S. sensitive personal data or government-related data with a country of concern or covered person, and restricts, subject to required security measures, vendor, employment, and investment-agreement transactions that would give such a country or person access to bulk sensitive personal data, including biometric identifiers such as facial images or voice prints collected on more than 1,000 U.S. persons, or human genomic data on more than 100.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

Read the law

Federal Register final rule text, via govinfo.gov

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app