President Biden’s Executive Order 14117 did not cut China off from every American’s data. It directed the Justice Department to restrict specified high-risk transactions that could give China and other countries of concern access to bulk sensitive personal data or U.S. government-related data. The DOJ’s implementing rule, 28 CFR part 202, took effect on April 8, 2025.
What the executive order changed
Signed on February 28, 2024, Executive Order 14117, titled “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern,” directed the Justice Department to create a targeted national-security program. The order itself set that process in motion; the DOJ’s final rule established the operative requirements.
The rule, published in late 2024 and codified at 28 CFR part 202, identifies transaction types that are prohibited, transaction types that may proceed only if they meet specified security requirements, and exemptions. It also establishes licensing and advisory-opinion processes and sets compliance obligations for covered transactions.
What information is covered
The rule addresses bulk amounts of specified categories of sensitive data, as well as U.S. government-related data. It defines thresholds for what counts as “bulk”; the applicable threshold depends on the data category. The categories include:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- Human genomic and other “omic” data.
- Biometric identifiers.
- Precise geolocation data.
- Personal health data.
- Personal financial data.
- Certain covered personal identifiers.
- U.S. government-related data.
Being in one of these categories does not, by itself, mean every transfer is prohibited. The rule’s definitions, bulk thresholds, transaction type, and parties determine whether a transaction falls within the program. The rule does not provide the numeric thresholds, so a business assessing a particular dataset should consult the applicable rule rather than assume that any amount qualifies as bulk data.
Can China still buy Americans’ data?
Not without restriction, but the rule is not a blanket ban on every purchase or transfer of information involving China. It targets specified transactions that could provide countries of concern or covered persons access to covered data. Data-brokerage is among the transaction types addressed. Some transactions are prohibited outright; others may proceed only if they satisfy the rule’s security requirements. Exemptions and licensing routes apply in specified circumstances.
Rank #2
Whether a particular sale, service, or data-sharing arrangement is covered depends on the details: the data involved, its volume, the type of transaction, and whether a country of concern or covered person is involved. The rule also creates processes for general and specific licenses and for advisory opinions. It does not establish a general right to sell covered data to China, nor does it bar every commercial relationship or data flow involving China.
Who and what transactions does the rule address?
The rule identifies countries of concern and defines covered persons. China is within the policy’s target, but the program also reaches other countries of concern and qualifying persons associated with them. It is therefore not simply a rule about a company’s nationality: whether a party is a covered person and how it accesses or receives data matter.
Its central distinction is between prohibited transactions and restricted transactions that can proceed only under predefined security requirements. The program also recognizes exemptions and provides licensing procedures. Those distinctions make the rule a targeted transaction regime, rather than a general prohibition on handling sensitive data or sending it across a border.
Does it ban TikTok or require all data to stay in the United States?
The DOJ says the final rule does not impose generalized data-localization requirements or require computing facilities to be based in the United States. It also does not broadly prohibit medical, scientific, or other research outside the covered categories of paid data transfers. The rule is not a blanket ban on TikTok, every Chinese-owned service, or all cross-border data flows. Whether a specific arrangement is covered depends on the rule’s definitions and transaction requirements; the order itself is not a substitute for that analysis.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What companies handling personal data must do
For businesses, the rule creates more than a limit on particular transactions. It also imposes due-diligence, recordkeeping, and reporting obligations for covered activity. Companies involved in data brokerage or other potentially covered arrangements need to determine whether their data, counterparties, and transactions fall within the rule and whether a prohibition, security requirement, exemption, or license applies.
- Assess whether the information fits a covered data category and meets its applicable bulk threshold, or is U.S. government-related data.
- Identify whether a counterparty is a country of concern or a covered person under the rule.
- Classify the transaction as prohibited, restricted, or potentially exempt; do not treat all transfers as having the same status.
- For a restricted transaction, determine whether the required security measures are in place before proceeding.
- Meet applicable due-diligence, recordkeeping, and reporting requirements, and use the licensing or advisory-opinion processes where appropriate.
The rule’s coverage and the status of particular persons can depend on definitions and designations. Businesses should check current DOJ Data Security Program materials and the applicable regulatory text when making a compliance decision.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Why the government says bulk data is a national-security risk
The DOJ’s stated concern is that access to large datasets can help adversaries conduct malicious cyber-enabled activity, influence operations, surveillance, and profiling, or develop military capabilities. The final rule describes risks that include tracking and profiling military members, federal employees, activists, journalists, dissidents, political figures, and nongovernmental organizations.
That rationale explains the focus on bulk access and specified sensitive categories: combining large quantities of data can reveal patterns about people and groups even when a transaction does not involve a single conspicuous record. The rule addresses those national-security risks through controls on defined transactions, rather than through a universal restriction on personal-data transfers.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




