What the DOJ bulk sensitive data rule means for companies licensing US data
The DOJ bulk sensitive data rule (28 CFR Part 202) limits transactions that give countries of concern or covered persons access to bulk US sensitive personal data or government-related data, and a data license can count as data brokerage. Operational records with HR, financial, health and location data excluded rarely reach it, but counsel should screen counterparties.
The short answer
The DOJ bulk sensitive data rule, codified at 28 CFR Part 202, can reach a data license, but only when the dataset holds bulk US sensitive personal data or government-related data and the deal involves a country of concern, a covered person or, for contract terms, another foreign person. Whether it applies turns on three facts: what remains in the dataset after scoping, who receives it, and what the contract lets the recipient do next.
For most companies licensing operational records, the honest answer is that the rule rarely bites. The records AI buyers value describe work rather than people: tickets and their resolutions, project histories, code reviews, approvals and SOPs. The categories the rule targets, such as health, financial, location and biometric data, sit mostly in HR, payroll, benefits and device systems that a well-scoped license leaves out. That conclusion still needs a documented check, not an assumption.
What does 28 CFR Part 202 cover?
The rule is administered by the National Security Division of the Department of Justice and implements a presidential executive order on Americans' bulk sensitive personal data. It is a national security rule rather than a privacy law: it gives individuals no new rights and focuses on who can gain access to data, not on how the data was collected. This page links no primary text for the rule, so read the current regulation on the eCFR and the Division's own guidance before relying on any summary, including this one.
| Rule element | What it means in plain terms | Question for a licensing deal |
|---|---|---|
| Countries of concern | A short list of countries named in the rule | Is the licensee, its parent or any recipient located in or controlled from one of them? |
| Covered persons | Entities owned by, organized in or principally based in a country of concern, individuals primarily resident there, certain employees and contractors of those entities, and persons the Department designates | Has anyone screened the licensee's ownership and the people who will access the data? |
| Sensitive personal data | Covered personal identifiers, precise geolocation, biometric identifiers, human 'omic data, personal health data and personal financial data | After scoping, does any of this remain? |
| Bulk thresholds | Volume triggers set per category, lower for the most sensitive types, counted across transactions with the same counterparty over a look-back period | Could residual data cross a threshold, alone or combined with other deliveries to the same licensee? |
| Government-related data | Location data tied to listed sensitive government sites, and data marketed as linked to government personnel, with no volume threshold | Does the company serve federal, defense or intelligence customers? |
| Prohibited transactions | Data brokerage with a country of concern or covered person, plus transactions giving them access to bulk human 'omic data | If covered data remains and the counterparty is covered, the deal stops |
| Restricted transactions | Vendor, employment and investment agreements, allowed only with specified security requirements | Rarely relevant to a one-time license, but counsel should confirm |
| Other foreign persons | Data brokerage requires contract terms barring onward transfer to countries of concern or covered persons, plus reporting of known or suspected violations | Does the license prohibit onward transfer and set up reporting? |
Two definitions deserve a second reading. First, data brokerage covers the sale of data and the licensing of access to it where the recipient did not collect the data directly from the people it describes, so a data license is in scope by form; content and counterparty decide whether any obligation follows. Second, the definitions are drafted so that anonymizing, pseudonymizing, de-identifying or encrypting data does not by itself take it out of scope. Excluding the sensitive fields, rather than masking them, is the dependable control. The rule also lists exempt transactions, such as certain intra-company dealings ancillary to business operations; read them with counsel rather than assuming one applies.
Which workplace systems can hold covered data?
Most of the exposure sits in a handful of systems. A data map built for privacy compliance usually answers these questions already.
| System | Covered categories that can hide there | Usual scoping decision |
|---|---|---|
| HRIS, payroll and benefits | Government ID numbers, bank account details, health and leave information | Exclude the whole system |
| Badge, time clock and access control | Fingerprint or face templates | Exclude |
| Field service and fleet apps | Precise location trails of technicians and drivers | Exclude the location fields, or ask counsel before any coarsened version |
| CRM and support desk | Contact details combined with account IDs, device IDs or IP addresses | Remove identifiers and keep the work content |
| Email and chat archives | Forwarded pay stubs, doctor's notes, ID scans, card numbers | Filter attachments and apply the agreed redaction rules |
| Engineering repos and logs | Device identifiers and IP addresses in logs, real customer data in test fixtures | Scrub logs, check fixtures, leave production dumps out |
| Finance and accounts payable | Bank details of individual payees, employee expense cards | Remove account numbers and individual payee files |
How does the rule apply in common licensing situations?
| Situation | What to check | Outcome to confirm with counsel |
|---|---|---|
| Support tickets with identifiers removed, licensed to a US-organized AI developer | Residual categories; licensee ownership and who will access the data | Usually outside the rule; keep a written record |
| Licensee organized in an allied country | Whether any covered data remains | If it does, add onward-transfer and reporting terms; if not, document why |
| Licensee's parent or major investor sits in a country of concern | Covered-person status | If covered data remains, the transaction is prohibited |
| Dataset includes location history from technicians' phones | Precise geolocation category and volume | Exclude the location data |
| Federal contractor whose project files name agency staff | Government-related data | Specialist review; exclusion is the common answer |
| Benefits enrollment files inside an HR archive | Personal health and financial data, plus HIPAA if a group health plan is involved | Exclude; see HIPAA and AI training data |
The 3C screen: content, counterparty, contract
Run these checks in order before any dataset that touches personal data leaves the company. Even when the first answer is a clear no, record the other two; they cost little and show diligence.
- Content: after the agreed exclusions, does any listed category remain, and could it approach a bulk threshold across all deliveries to this licensee?
- Counterparty: who is the licensee, where is it organized, who owns or controls it, and which people or contractors will touch the data?
- Contract: does the license bar onward transfer to countries of concern and covered persons, limit access to named recipients, and require prompt notice of any suspected breach of those terms?
Which other US rules apply to the same data?
The DOJ rule sits alongside other regimes rather than replacing them. Customer financial information held by a financial institution under the FTC's jurisdiction is also subject to the Gramm-Leach-Bliley Act, whose Privacy Rule requires notices and opt-out rights before sharing with certain nonaffiliated third parties. Accounting and tax firms should also read the guide to the FTC Safeguards Rule for CPA firms. Health information can be protected health information under HIPAA. And if a dataset includes personal data of people in the EU, the General Data Protection Regulation can apply even to a US company that offers goods or services to, or monitors the behavior of, people there.
How the SourceX process keeps the analysis manageable
In a SourceX engagement, no data moves before scope is settled. The company completes a data inventory listing each system and how far back it goes, de-identification and redaction rules are settled with the company before any work starts, and files go out only once an agreement is executed and the company authorizes delivery. Nothing binds the company until it accepts price and terms and signs, which gives its counsel time to review the licensee and the transfer terms against the rule. The how it works page lays out the full sequence.
Referral partners stay outside this entirely. A partner makes the introduction and shares basic fit information; a partner never exports, uploads or describes the company's records, so a partner never has custody of the data the rule regulates.
Questions to ask your counsel
- Which of the rule's categories, if any, remain in the dataset after our exclusions, and how close are we to a bulk threshold?
- Have we screened the licensee, its owners and everyone who will access the data for covered-person status?
- Does the license prohibit onward transfer to countries of concern and covered persons, and who reports a suspected violation?
- Do any of our customers or projects create government-related data?
- Do separate federal or state laws on data brokers add obligations for this dataset?
- What written record of this analysis should we keep, and for how long?
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting, and check the rule's current text, because designations and guidance can change.
Next step
If you advise an owner whose company holds years of operational records, run a quick screen with the company fit checker and note which systems hold HR, financial, health or location data so they can be excluded early. The guide on how to explain company data licensing to a founder helps with the first conversation. Then register as a partner to make the introduction, or have the company apply directly at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does the DOJ rule apply if the AI developer licensing the data is a US company?
The prohibitions bite only when a country of concern or covered person is involved, so a US-organized licensee with no such ownership or access is generally outside them. Covered-person status can still reach some individuals and entities physically in the US, such as certain employees of covered entities or persons the Department designates, so screen ownership and access rather than relying on an address.
Does anonymizing or encrypting a dataset take it outside the rule?
Not by itself. The rule's definitions are written so that anonymized, pseudonymized, de-identified or encrypted data can still count as sensitive personal data. The reliable control is exclusion: leave HR, payroll, badge and location systems out of the license, strip identifiers from what remains, and document the result. Counsel should review any dataset where listed fields survive.
Is the DOJ rule the same as the federal law on data brokers and foreign adversaries?
No. Congress separately enacted the Protecting Americans' Data from Foreign Adversaries Act, which the Federal Trade Commission enforces and which targets data brokers that make certain sensitive data available to foreign adversary countries or entities they control. The two overlap in purpose but differ in definitions, scope and enforcement, so counsel should check both for any dataset that contains personal data.
What penalties apply to violations of 28 CFR Part 202?
The rule is issued under the International Emergency Economic Powers Act, so violations can lead to civil penalties and, for willful violations, criminal prosecution. Penalty amounts are set by statute and adjusted over time. Read the current figures in the rule and the statute rather than relying on secondary summaries, and involve counsel early if a transaction might be covered.
Do referral partners take on obligations under the rule?
A referral partner only introduces the company and shares basic fit information, and never handles the records themselves, so a partner does not hold the data the rule regulates. Partners can be based in any supported country. Questions about the licensee and transfer terms are settled by the company and its counsel before it signs, and nothing is delivered without an executed agreement.
Related pages
- Data mapping for privacy compliance that doubles as data licensing prep
- HIPAA and AI training data: what the rules allow and what stays out of a license
- FTC Safeguards Rule for CPA firms: what it means for client records and referrals
- How SourceX US company data referrals work
- Check Company Fit for Data Licensing
- How to explain company data licensing to a US founder
Free resources
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- Earnout scenario calculator — Probability-weighted earnout value and its present value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment