Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern
The order substantially expands the national emergency declared in Executive Order 13873 to restrict access by foreign adversaries — called 'countries of concern' — to Americans' bulk sensitive personal data and U.S. Government-related data, invoking the International Emergency Economic Powers Act to authorize a new federal regulatory program.
It is the first executive order to apply IEEPA's emergency transaction-blocking powers specifically to bulk data sales, brokerage arrangements, and employment or investment agreements that could funnel sensitive American data to hostile governments, with the Attorney General empowered to prohibit or conditionally permit such transactions through notice-and-comment rulemaking.
What this order does
What it orders
The order expands the scope of the national emergency declared in EO 13873 and directs the Attorney General, coordinating with the Secretary of Homeland Security, to issue regulations that prohibit or restrict U.S. persons from engaging in transactions involving bulk sensitive personal data or U.S. Government-related data when those transactions could enable a country of concern or covered person to access such data. Within 180 days, the AG must publish a proposed rule identifying classes of prohibited and restricted transactions, naming countries of concern, establishing a licensing mechanism for exceptions, and setting recordkeeping requirements. The order also directs CISA to develop security requirements under which otherwise-prohibited transactions may proceed as "restricted transactions" with safeguards in place.
Beyond the core transaction-blocking program, the order directs the Committee for the Assessment of Foreign Participation in Telecommunications Services to prioritize submarine cable license reviews tied to countries of concern; directs the Secretaries of Defense, HHS, and Veterans Affairs and the NSF Director to consider restricting federal research assistance that enables adversarial access to health and genomic data; and requires a series of reports on implementation effectiveness, economic impact, and the risks of extending the regulatory framework to human biological data types beyond genomic data.
Who it affects
U.S. persons — including businesses, data brokers, healthcare organizations, research institutions, and individual contractors — who sell, transfer, or otherwise provide bulk sensitive personal data to entities linked to countries of concern. Federal employees and contractors whose data carries elevated risk are protected. Foreign entities owned or controlled by countries of concern are subject to the new restrictions.
Why it matters
Data brokers, health-data firms, genomics companies, and employers with international ties will face new federal compliance obligations once regulations take effect. Americans whose data has already been transferred to adversarial countries gain new government attention to mitigation. Federal researchers and healthcare grantees may see conditions attached to future federal funding.
What must happen and when
How the order is supposed to work
The AG leads a two-track process: a rulemaking track that identifies prohibited and restricted transaction classes, names countries of concern, and builds a licensing regime; and a security-requirements track run by CISA that defines the standards a restricted transaction must meet to remain lawful. Both tracks require public notice and comment. IEEPA provides the enforcement backbone — evasion and conspiracy to evade are expressly prohibited. Licensing decisions require concurrence from State, Commerce, and DHS. Interagency disputes escalate through NSM-2 processes. Multiple time-gated reports feed back into future regulatory adjustments.
Actions and deadlines
- Publish proposed rule identifying prohibited and restricted transaction classes, countries of concern, and licensing processes for public notice and comment
- Propose and seek public comment on CISA security requirements for restricted transactions, based on NIST Cybersecurity and Privacy Frameworks
- Submit report to the President assessing risks and benefits of regulating human 'omic data transactions beyond human genomic data
- Secretaries of Defense, HHS, Veterans Affairs, and NSF Director jointly submit report to the President on progress protecting bulk health and genomic data from countries of concern
- AG, Secretary of Homeland Security, and Director of National Intelligence recommend to APNSA actions to address national security risks from prior bulk data transfers to countries of concern
- APNSA review agency recommendations and consult on implementing mitigations for prior bulk data transfers
- AG submit report to the President assessing effectiveness of order's measures and economic impact on U.S. industry
Agencies directed to act
Authority and reach
What this order changes
Amends Executive Order 13873