Executive Order 14117 · Signed Feb 28, 2024

89 FR 15421 · Published Mar 1, 2024 · Effective on signing

Newsworthy
Share

Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern

data privacynational securityforeign adversariesartificial intelligencehealth and genomic data

Signed by President Joseph R. Biden Jr.

The order substantially expands the national emergency declared in Executive Order 13873 to restrict access by foreign adversaries — called 'countries of concern' — to Americans' bulk sensitive personal data and U.S. Government-related data, invoking the International Emergency Economic Powers Act to authorize a new federal regulatory program.

It is the first executive order to apply IEEPA's emergency transaction-blocking powers specifically to bulk data sales, brokerage arrangements, and employment or investment agreements that could funnel sensitive American data to hostile governments, with the Attorney General empowered to prohibit or conditionally permit such transactions through notice-and-comment rulemaking.

What this order does

What it orders

The order expands the scope of the national emergency declared in EO 13873 and directs the Attorney General, coordinating with the Secretary of Homeland Security, to issue regulations that prohibit or restrict U.S. persons from engaging in transactions involving bulk sensitive personal data or U.S. Government-related data when those transactions could enable a country of concern or covered person to access such data. Within 180 days, the AG must publish a proposed rule identifying classes of prohibited and restricted transactions, naming countries of concern, establishing a licensing mechanism for exceptions, and setting recordkeeping requirements. The order also directs CISA to develop security requirements under which otherwise-prohibited transactions may proceed as "restricted transactions" with safeguards in place.

Beyond the core transaction-blocking program, the order directs the Committee for the Assessment of Foreign Participation in Telecommunications Services to prioritize submarine cable license reviews tied to countries of concern; directs the Secretaries of Defense, HHS, and Veterans Affairs and the NSF Director to consider restricting federal research assistance that enables adversarial access to health and genomic data; and requires a series of reports on implementation effectiveness, economic impact, and the risks of extending the regulatory framework to human biological data types beyond genomic data.

Who it affects

U.S. persons — including businesses, data brokers, healthcare organizations, research institutions, and individual contractors — who sell, transfer, or otherwise provide bulk sensitive personal data to entities linked to countries of concern. Federal employees and contractors whose data carries elevated risk are protected. Foreign entities owned or controlled by countries of concern are subject to the new restrictions.

Why it matters

Data brokers, health-data firms, genomics companies, and employers with international ties will face new federal compliance obligations once regulations take effect. Americans whose data has already been transferred to adversarial countries gain new government attention to mitigation. Federal researchers and healthcare grantees may see conditions attached to future federal funding.

What must happen and when

How the order is supposed to work

The AG leads a two-track process: a rulemaking track that identifies prohibited and restricted transaction classes, names countries of concern, and builds a licensing regime; and a security-requirements track run by CISA that defines the standards a restricted transaction must meet to remain lawful. Both tracks require public notice and comment. IEEPA provides the enforcement backbone — evasion and conspiracy to evade are expressly prohibited. Licensing decisions require concurrence from State, Commerce, and DHS. Interagency disputes escalate through NSM-2 processes. Multiple time-gated reports feed back into future regulatory adjustments.

Actions and deadlines

  • Publish proposed rule identifying prohibited and restricted transaction classes, countries of concern, and licensing processes for public notice and commentWithin 180 days of signing
  • Propose and seek public comment on CISA security requirements for restricted transactions, based on NIST Cybersecurity and Privacy FrameworksWithin 180 days of signing
  • Submit report to the President assessing risks and benefits of regulating human 'omic data transactions beyond human genomic dataWithin 120 days of signing
  • Secretaries of Defense, HHS, Veterans Affairs, and NSF Director jointly submit report to the President on progress protecting bulk health and genomic data from countries of concernWithin 1 year of signing
  • AG, Secretary of Homeland Security, and Director of National Intelligence recommend to APNSA actions to address national security risks from prior bulk data transfers to countries of concernWithin 120 days of the effective date of regulations issued under Section 2(c)
  • APNSA review agency recommendations and consult on implementing mitigations for prior bulk data transfersWithin 150 days of the effective date of regulations issued under Section 2(c)
  • AG submit report to the President assessing effectiveness of order's measures and economic impact on U.S. industryWithin 1 year of the effective date of regulations issued under Section 2(c)

Agencies directed to act

Department of JusticeDepartment of Homeland SecurityCybersecurity and Infrastructure Security AgencyDepartment of DefenseDepartment of Health and Human ServicesDepartment of Veterans AffairsNational Science FoundationCommittee for the Assessment of Foreign Participation in the United States Telecommunications Services SectorOffice of the Director of National IntelligenceOffice of Science and Technology PolicyOffice of Pandemic Preparedness and Response Policy

Authority and reach

Authorities cited

International Emergency Economic Powers Act (IEEPA)

Grants the President broad authority to regulate financial and commercial transactions during a declared national emergency.

National Emergencies Act (NEA)

Governs how presidents declare and maintain national emergencies and requires periodic reporting to Congress.

3 U.S.C. § 301

Allows the President to delegate presidential functions and authorities to executive branch officers.

What this order changes

Amends Executive Order 13873

Executive Order

Ask GovernmentReporter about this order

Ask anything about what this order does, who it affects, and how it changes policy.

Executive Order 14117: Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern | EO Reporter