What US DOJ National Security Division Final Rule on Bulk Sensitive Personal Data Transactions - 28 CFR 202 (December 27 2024) requires
The US Department of Justice National Security Division issued a Final Rule on December 27, 2024 implementing Executive Order 14117 of February 28, 2024 on access by countries of concern to Americans bulk sensitive personal data and US government-related data. The Rule is codified at 28 CFR 202 and took effect April 8, 2025. It implements two regulatory pathways. The first is Prohibited Transactions which are flatly forbidden absent a DOJ licence: data brokerage to a country of concern or covered person; transactions involving bulk human genomic data or biospecimens; and any transaction posing unacceptable national security risk. The second is Restricted Transactions which may proceed only subject to CISA security requirements: vendor agreements (including cloud computing services), employment agreements, and investment agreements involving covered data. The Rule defines bulk thresholds for each covered data category - 100 US persons for genomic data; 1000 US persons for biometric, geolocation, health, or financial data; 10000 US persons for human-derived identifiers - measured over a 12-month period. The Rule defines covered persons as foreign persons primarily resident in a country of concern, foreign entities organised in or majority-owned by a country of concern, certain employees and contractors, and entities designated by the Attorney General. Penalties under IEEPA apply for violations.
Pillar: AI Governance & Law · Authority: US Department of Justice National Security Division - Final Rule on Bulk Sensitive Personal Data Transactions, 28 CFR 202, published December 27 2024 · Version: 1.0.0 · Last updated:
Primary source: https://www.justice.gov/nsd
SHA-256 integrity: 385f7a412ddc86ba085251c2d880454b7ef3dab850965d75817c233eec1d80ac
Primary Citations — 8 traced to source
- US Department of Justice National Security Division, Final Rule on Bulk Sensitive Personal Data Transactions, codified at 28 CFR 202, published in the Federal Register December 27, 2024, effective April 8, 2025
- DOJ NSD Bulk Data Rule prohibited transactions: prohibited absent a DOJ licence including data brokerage to a country of concern or covered person, transactions involving bulk human genomic data or biospecimens, and transactions posing unacceptable national security risk
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/us-doj-nsd-bulk-data-final-rule-28-cfr-202-2024.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/us-doj-nsd-bulk-data-final-rule-28-cfr-202-2024.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/us-doj-nsd-bulk-data-final-rule-28-cfr-202-2024
- Back to registry: Browse all 10,108 compliance nodes