The US Department of Justice’s Data Security Program (28 CFR Part 202) comes into force today, restricting transactions that could give “countries of concern” access to Americans’ bulk sensitive personal data and US government-related data.
Key points
- Countries of concern are China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba and Venezuela.
- Data brokerage transactions with countries of concern or covered persons are prohibited, as are transactions giving access to bulk genomic data.
- Vendor, employment and investment agreements are “restricted transactions” that must meet CISA security requirements.
- Due diligence, audit and reporting obligations apply from 6 October 2025.
UK organisations handling US personal data, for example as processors or through offshore support teams, may be caught if they are, or engage, covered persons. Supply chains and data flows should be mapped now.
Source: DOJ final rule, 28 CFR Part 202 (Federal Register)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.