DOJ Bulk Data Rule
In force United States (Federal) · In force Apr 8, 2025 · no upcoming deadlines
Deadlines
| Date | What happens | When |
|---|---|---|
| Apr 8, 2025 | Prohibitions and restrictions take effect18 months ago | 18 months ago |
| Oct 6, 2025 | Due diligence, audit and reporting obligations apply12 months ago | 12 months ago |
Summaries for reference, not legal advice. Check the official text.
What it does
Prohibits U.S. persons from data brokerage and genomic-data transactions with countries of concern or covered persons, and restricts vendor, employment and investment agreements involving bulk U.S. sensitive personal data or government-related data unless CISA security requirements are met. Restricted transactions require a data compliance program, due diligence, audits, recordkeeping and reporting.
- Who it applies to
- U.S. persons (companies and individuals) engaging in covered data transactions with China (incl. Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela, or covered persons. Bulk thresholds over the preceding 12 months: human genomic data on 100+ U.S. persons; other human 'omic data or biometric identifiers on 1,000+; precise geolocation on 1,000+ devices; personal health or personal financial data on 10,000+; covered personal identifiers on 100,000+. Government-related data has no threshold.
- Penalties
- Civil penalty up to the greater of $368,136 (as stated in the rule; inflation-adjusted) or twice the transaction value per violation; willful violations up to $1,000,000 in fines and, for individuals, up to 20 years' imprisonment (IEEPA).
- Enforced by
- U.S. Department of Justice, National Security Division
- Official name
- Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (28 CFR Part 202) - DOJ Data Security Program
- Citation
- 28 CFR Part 202; 90 FR 1636 (Jan. 8, 2025); Executive Order 14117; IEEPA (50 U.S.C. 1701 et seq.)
- Topics
- privacy, data-residency, cybersecurity, biometrics, health, financial
Research notes
DOJ announced a 90-day limited enforcement period after April 8, 2025 for good-faith efforts (per DOJ NSD policy, not re-verified here). An April 18, 2025 technical amendment (90 FR 16466) corrected the rule. Penalty figure is the one printed in the January 2025 rule.
Related
Questions about DOJ Bulk Data Rule
- What are the DOJ Bulk Data Rule compliance deadlines?
- Apr 8, 2025: Prohibitions and restrictions take effect. Oct 6, 2025: Due diligence, audit and reporting obligations apply.
- When does DOJ Bulk Data Rule take effect?
- DOJ Bulk Data Rule took effect on Apr 8, 2025.
- Who does DOJ Bulk Data Rule apply to?
- U.S. persons (companies and individuals) engaging in covered data transactions with China (incl. Hong Kong and Macau), Cuba, Iran, North Korea, Russia or Venezuela, or covered persons. Bulk thresholds over the preceding 12 months: human genomic data on 100+ U.S. persons; other human 'omic data or biometric identifiers on 1,000+; precise geolocation on 1,000+ devices; personal health or personal financial data on 10,000+; covered personal identifiers on 100,000+. Government-related data has no threshold.
- What are the penalties under DOJ Bulk Data Rule?
- Civil penalty up to the greater of $368,136 (as stated in the rule; inflation-adjusted) or twice the transaction value per violation; willful violations up to $1,000,000 in fines and, for individuals, up to 20 years' imprisonment (IEEPA).