What the DOJ bulk sensitive data rule means for companies licensing US data

The DOJ bulk sensitive data rule (28 CFR Part 202) limits transactions that give countries of concern or covered persons access to bulk US sensitive personal data or government-related data, and a data license can count as data brokerage. Operational records with HR, financial, health and location data excluded rarely reach it, but counsel should screen counterparties.

The short answer

The DOJ bulk sensitive data rule, codified at 28 CFR Part 202, can reach a data license, but only when the dataset holds bulk US sensitive personal data or government-related data and the deal involves a country of concern, a covered person or, for contract terms, another foreign person. Whether it applies turns on three facts: what remains in the dataset after scoping, who receives it, and what the contract lets the recipient do next.

For most companies licensing operational records, the honest answer is that the rule rarely bites. The records AI buyers value describe work rather than people: tickets and their resolutions, project histories, code reviews, approvals and SOPs. The categories the rule targets, such as health, financial, location and biometric data, sit mostly in HR, payroll, benefits and device systems that a well-scoped license leaves out. That conclusion still needs a documented check, not an assumption.

What does 28 CFR Part 202 cover?

The rule is administered by the National Security Division of the Department of Justice and implements a presidential executive order on Americans' bulk sensitive personal data. It is a national security rule rather than a privacy law: it gives individuals no new rights and focuses on who can gain access to data, not on how the data was collected. This page links no primary text for the rule, so read the current regulation on the eCFR and the Division's own guidance before relying on any summary, including this one.

Rule elementWhat it means in plain termsQuestion for a licensing deal
Countries of concernA short list of countries named in the ruleIs the licensee, its parent or any recipient located in or controlled from one of them?
Covered personsEntities owned by, organized in or principally based in a country of concern, individuals primarily resident there, certain employees and contractors of those entities, and persons the Department designatesHas anyone screened the licensee's ownership and the people who will access the data?
Sensitive personal dataCovered personal identifiers, precise geolocation, biometric identifiers, human 'omic data, personal health data and personal financial dataAfter scoping, does any of this remain?
Bulk thresholdsVolume triggers set per category, lower for the most sensitive types, counted across transactions with the same counterparty over a look-back periodCould residual data cross a threshold, alone or combined with other deliveries to the same licensee?
Government-related dataLocation data tied to listed sensitive government sites, and data marketed as linked to government personnel, with no volume thresholdDoes the company serve federal, defense or intelligence customers?
Prohibited transactionsData brokerage with a country of concern or covered person, plus transactions giving them access to bulk human 'omic dataIf covered data remains and the counterparty is covered, the deal stops
Restricted transactionsVendor, employment and investment agreements, allowed only with specified security requirementsRarely relevant to a one-time license, but counsel should confirm
Other foreign personsData brokerage requires contract terms barring onward transfer to countries of concern or covered persons, plus reporting of known or suspected violationsDoes the license prohibit onward transfer and set up reporting?

Two definitions deserve a second reading. First, data brokerage covers the sale of data and the licensing of access to it where the recipient did not collect the data directly from the people it describes, so a data license is in scope by form; content and counterparty decide whether any obligation follows. Second, the definitions are drafted so that anonymizing, pseudonymizing, de-identifying or encrypting data does not by itself take it out of scope. Excluding the sensitive fields, rather than masking them, is the dependable control. The rule also lists exempt transactions, such as certain intra-company dealings ancillary to business operations; read them with counsel rather than assuming one applies.

Which workplace systems can hold covered data?

Most of the exposure sits in a handful of systems. A data map built for privacy compliance usually answers these questions already.

SystemCovered categories that can hide thereUsual scoping decision
HRIS, payroll and benefitsGovernment ID numbers, bank account details, health and leave informationExclude the whole system
Badge, time clock and access controlFingerprint or face templatesExclude
Field service and fleet appsPrecise location trails of technicians and driversExclude the location fields, or ask counsel before any coarsened version
CRM and support deskContact details combined with account IDs, device IDs or IP addressesRemove identifiers and keep the work content
Email and chat archivesForwarded pay stubs, doctor's notes, ID scans, card numbersFilter attachments and apply the agreed redaction rules
Engineering repos and logsDevice identifiers and IP addresses in logs, real customer data in test fixturesScrub logs, check fixtures, leave production dumps out
Finance and accounts payableBank details of individual payees, employee expense cardsRemove account numbers and individual payee files

How does the rule apply in common licensing situations?

SituationWhat to checkOutcome to confirm with counsel
Support tickets with identifiers removed, licensed to a US-organized AI developerResidual categories; licensee ownership and who will access the dataUsually outside the rule; keep a written record
Licensee organized in an allied countryWhether any covered data remainsIf it does, add onward-transfer and reporting terms; if not, document why
Licensee's parent or major investor sits in a country of concernCovered-person statusIf covered data remains, the transaction is prohibited
Dataset includes location history from technicians' phonesPrecise geolocation category and volumeExclude the location data
Federal contractor whose project files name agency staffGovernment-related dataSpecialist review; exclusion is the common answer
Benefits enrollment files inside an HR archivePersonal health and financial data, plus HIPAA if a group health plan is involvedExclude; see HIPAA and AI training data

The 3C screen: content, counterparty, contract

Run these checks in order before any dataset that touches personal data leaves the company. Even when the first answer is a clear no, record the other two; they cost little and show diligence.

  • Content: after the agreed exclusions, does any listed category remain, and could it approach a bulk threshold across all deliveries to this licensee?
  • Counterparty: who is the licensee, where is it organized, who owns or controls it, and which people or contractors will touch the data?
  • Contract: does the license bar onward transfer to countries of concern and covered persons, limit access to named recipients, and require prompt notice of any suspected breach of those terms?

Which other US rules apply to the same data?

The DOJ rule sits alongside other regimes rather than replacing them. Customer financial information held by a financial institution under the FTC's jurisdiction is also subject to the Gramm-Leach-Bliley Act, whose Privacy Rule requires notices and opt-out rights before sharing with certain nonaffiliated third parties. Accounting and tax firms should also read the guide to the FTC Safeguards Rule for CPA firms. Health information can be protected health information under HIPAA. And if a dataset includes personal data of people in the EU, the General Data Protection Regulation can apply even to a US company that offers goods or services to, or monitors the behavior of, people there.

How the SourceX process keeps the analysis manageable

In a SourceX engagement, no data moves before scope is settled. The company completes a data inventory listing each system and how far back it goes, de-identification and redaction rules are settled with the company before any work starts, and files go out only once an agreement is executed and the company authorizes delivery. Nothing binds the company until it accepts price and terms and signs, which gives its counsel time to review the licensee and the transfer terms against the rule. The how it works page lays out the full sequence.

Referral partners stay outside this entirely. A partner makes the introduction and shares basic fit information; a partner never exports, uploads or describes the company's records, so a partner never has custody of the data the rule regulates.

Questions to ask your counsel

  1. Which of the rule's categories, if any, remain in the dataset after our exclusions, and how close are we to a bulk threshold?
  2. Have we screened the licensee, its owners and everyone who will access the data for covered-person status?
  3. Does the license prohibit onward transfer to countries of concern and covered persons, and who reports a suspected violation?
  4. Do any of our customers or projects create government-related data?
  5. Do separate federal or state laws on data brokers add obligations for this dataset?
  6. What written record of this analysis should we keep, and for how long?

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting, and check the rule's current text, because designations and guidance can change.

Next step

If you advise an owner whose company holds years of operational records, run a quick screen with the company fit checker and note which systems hold HR, financial, health or location data so they can be excluded early. The guide on how to explain company data licensing to a founder helps with the first conversation. Then register as a partner to make the introduction, or have the company apply directly at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does the DOJ rule apply if the AI developer licensing the data is a US company?

The prohibitions bite only when a country of concern or covered person is involved, so a US-organized licensee with no such ownership or access is generally outside them. Covered-person status can still reach some individuals and entities physically in the US, such as certain employees of covered entities or persons the Department designates, so screen ownership and access rather than relying on an address.

Does anonymizing or encrypting a dataset take it outside the rule?

Not by itself. The rule's definitions are written so that anonymized, pseudonymized, de-identified or encrypted data can still count as sensitive personal data. The reliable control is exclusion: leave HR, payroll, badge and location systems out of the license, strip identifiers from what remains, and document the result. Counsel should review any dataset where listed fields survive.

Is the DOJ rule the same as the federal law on data brokers and foreign adversaries?

No. Congress separately enacted the Protecting Americans' Data from Foreign Adversaries Act, which the Federal Trade Commission enforces and which targets data brokers that make certain sensitive data available to foreign adversary countries or entities they control. The two overlap in purpose but differ in definitions, scope and enforcement, so counsel should check both for any dataset that contains personal data.

What penalties apply to violations of 28 CFR Part 202?

The rule is issued under the International Emergency Economic Powers Act, so violations can lead to civil penalties and, for willful violations, criminal prosecution. Penalty amounts are set by statute and adjusted over time. Read the current figures in the rule and the statute rather than relying on secondary summaries, and involve counsel early if a transaction might be covered.

Do referral partners take on obligations under the rule?

A referral partner only introduces the company and shares basic fit information, and never handles the records themselves, so a partner does not hold the data the rule regulates. Partners can be based in any supported country. Questions about the licensee and transfer terms are settled by the company and its counsel before it signs, and nothing is delivered without an executed agreement.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment