DOJ Guidance on Bulk Sensitive Data Rules: Enforcement Grace Period and Prohibited Transactions

The DOJ has issued guidance to facilitate compliance with its final rules, referred to as the Data Security Program (DSP), implementing former President Biden’s Executive Order on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern. Though much of the guidance material rearticulates language in the DSP, there was some notable new compliance information for organizations. This two-part article series highlights the key elements of the guidance, with commentary from Edward McNicholas, a partner at Ropes & Gray. This first installment covers the enforcement grace period, definitions of bulk data and covered persons, and prohibited transactions. Part two will distill guidance on restricted transactions, recordkeeping, reporting requirements, licenses and advisory opinions. See “Examining DOJ’s Final Rules on Access to Government and Sensitive U.S. Personal Data” (Jan. 29, 2025).

To read the full article

Continue reading your article with a CSLR subscription.