Skip to content

DOJ Bulk Data Rule

In force United States (Federal) · In force Apr 8, 2025 · no upcoming deadlines

Deadlines

DateWhat happens
Oct 6, 202511 months agoDue diligence, audit and reporting obligations apply
Apr 8, 20251 year agoProhibitions and restrictions take effect

Summaries for reference, not legal advice. Check the official text.

What it does

Prohibits U.S. persons from data brokerage and genomic-data transactions with countries of concern or covered persons, and restricts vendor, employment and investment agreements involving bulk U.S. sensitive personal data or government-related data unless CISA security requirements are met. Restricted transactions require a data compliance program, due diligence, audits, recordkeeping and reporting.

Who it applies to
U.S. persons (companies and individuals) engaging in covered data transactions with China (incl. Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela, or covered persons. Bulk thresholds over the preceding 12 months: human genomic data on 100+ U.S. persons; other human 'omic data or biometric identifiers on 1,000+; precise geolocation on 1,000+ devices; personal health or personal financial data on 10,000+; covered personal identifiers on 100,000+. Government-related data has no threshold.
Penalties
Civil penalty up to the greater of $368,136 (as stated in the rule; inflation-adjusted) or twice the transaction value per violation; willful violations up to $1,000,000 in fines and, for individuals, up to 20 years' imprisonment (IEEPA).
Enforced by
U.S. Department of Justice, National Security Division
Official name
Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (28 CFR Part 202) - DOJ Data Security Program
Citation
28 CFR Part 202; 90 FR 1636 (Jan. 8, 2025); Executive Order 14117; IEEPA (50 U.S.C. 1701 et seq.)
Topics
privacy, data-residency, cybersecurity, biometrics, health, financial
Verified 2026-09-22 ecfr.gov justice.gov federalregister.gov
Research notes

DOJ announced a 90-day limited enforcement period after April 8, 2025 for good-faith efforts (per DOJ NSD policy, not re-verified here). An April 18, 2025 technical amendment (90 FR 16466) corrected the rule. Penalty figure is the one printed in the January 2025 rule.

Related

Questions about DOJ Bulk Data Rule
What are the DOJ Bulk Data Rule compliance deadlines?
Apr 8, 2025: Prohibitions and restrictions take effect. Oct 6, 2025: Due diligence, audit and reporting obligations apply.
When does DOJ Bulk Data Rule take effect?
DOJ Bulk Data Rule took effect on Apr 8, 2025.
Who does DOJ Bulk Data Rule apply to?
U.S. persons (companies and individuals) engaging in covered data transactions with China (incl. Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela, or covered persons. Bulk thresholds over the preceding 12 months: human genomic data on 100+ U.S. persons; other human 'omic data or biometric identifiers on 1,000+; precise geolocation on 1,000+ devices; personal health or personal financial data on 10,000+; covered personal identifiers on 100,000+. Government-related data has no threshold.
What are the penalties under DOJ Bulk Data Rule?
Civil penalty up to the greater of $368,136 (as stated in the rule; inflation-adjusted) or twice the transaction value per violation; willful violations up to $1,000,000 in fines and, for individuals, up to 20 years' imprisonment (IEEPA).

Rule changes by email

The morning after a new data, privacy or AI law, or a deadline change; nothing in quiet weeks.

Double opt-in. Unsubscribe any time.