DOJ Data Security Program Reaches Full Enforcement for Bulk Data Transfers
The Department of Justice's Data Security Program (DSP), codified at 28 CFR Part 202 and implementing Executive Order 14117, took effect on April 8, 2025 and reached full enforcement on July 8, 2025 when DOJ's 90-day good-faith compliance policy expired. The program prohibits or restricts transactions that give countries of concern (China, Cuba, Iran, North Korea, Russia, and Venezuela) or covered persons access to government-related data or bulk US sensitive personal data, including genomic, biometric, geolocation, health, and financial data. Additional affirmative obligations for restricted transactions, including due diligence, audits, and reporting, took effect on October 6, 2025.
Key Analytics
Impact Analysis
The DSP functions as a set of export controls for data, reaching vendor agreements, cloud and IT service arrangements, employment relationships, and investment deals that could give covered persons access to bulk US sensitive personal data. Violations carry civil and criminal penalties under the International Emergency Economic Powers Act, and with the grace period over, DOJ's National Security Division is no longer deprioritizing enforcement against companies still working toward compliance. Organizations handling US personal data at scale should treat DSP screening as a standing element of their privacy and third-party risk programs, distinct from but adjacent to state privacy law compliance. As of August 2026, the rule text stands as issued in 2025 with only a technical correcting amendment; monitor DOJ NSD guidance for changes.
Recommended Actions
- Map data flows to identify covered data transactions: any data brokerage, vendor, employment, or investment agreement that could give a country of concern or covered person access to bulk US sensitive personal data or government-related data.
- Screen counterparties against the six designated countries of concern and DOJ's Covered Persons List, and embed this screening into procurement, hiring, and deal diligence workflows.
- For restricted transactions, implement the CISA security requirements plus the due diligence, audit, and reporting obligations that took effect October 6, 2025.
- Cease or restructure any prohibited transactions, and document the classification analysis (prohibited, restricted, exempt) for each covered data transaction.
- Review DOJ NSD's Compliance Guide and FAQs, and establish an escalation path to counsel for license applications or advisory opinion requests.
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Data flow mapping for bulk US sensitive and government-related data
- ›Counterparty screening embedded into procurement, hiring, and deal diligence
- ›Restricted transaction due diligence, audit, and reporting build
- ›Prohibited transaction cessation or restructuring
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 110 to 230 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.