logo
Clock Is Ticking For Companies To Comply With Complex Data Transfer Rule

Clock Is Ticking For Companies To Comply With Complex Data Transfer Rule

Forbes07-05-2025

The National Security Division of the Department of Justice has given companies 90 days to avoid civil penalties under the new Data Security Program entitled 'Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons' ( 'DSP'). By July 8, 2025, companies operating in the international arena must make 'good faith efforts' to restrict access to personal and government-related data by foreign adversaries. Although the DSP may apply to any business, regardless of size or industry, if the business makes certain sensitive data available to third parties, businesses in the financial services, life sciences, and information technology sectors are most likely to feel the impact of the DSP due to the nature of the data they handle. Data brokers who collect and sell data, as well as companies that engage in cross-border transactions are also expected to feel the effect of the DSP because of the nature of their transactions. The DSP represents a rare point of agreement between the Biden Administration, which enacted the legislation, and the Trump Administration, which finalized the DSP on January 8, 2025. The DSP has been in effect since April 8, 2025, and the DOJ does not intend to delay criminal enforcement for willful violations, which can bring up to 20 years in prison. Remarks from President Trump's former defense attorney and current Deputy Attorney General Todd Blanche have indicated that the DOJ will embrace the DSP as a necessity for combating an 'increasingly urgent' threat to national security, targeting access by certain 'countries of concern' and individuals connected to these countries. The 90-day pause may appear at first blush to signal leniency, but do not be fooled – plenty of caveats exist, including the possibility of civil enforcement for companies not working to restrict access to data by foreign adversaries during the 90 days.
The DOJ has established itself as a key regulator of data transfers, and it expects U.S. companies to determine in the coming days whether their data practices, third-party relationships, or ownership structures allow foreign governments and individuals of concern to access Americans' sensitive personal data or government-related data. The DSP extends beyond existing privacy and security law restrictions. To help companies get up to speed, the DOJ issued further guidance to provide clarification on key provisions and examples of its expectations during the enforcement hiatus, including working on a written data compliance program. The DOJ is giving companies 90 days to 'get it right' to protect sensitive data, and if not, its enforcement hammer will come down on companies demonstrating anything less than 'full compliance.'
The Who, What, Where of the Data Security Program
The finalized DSP closely aligns with the Biden Administration's proposed rule. It goes beyond traditional privacy laws to execute President Biden's order to combat the 'unusual and extraordinary threat' by foreign governments using sensitive U.S. data for purposes of 'espionage, influence, kinetic, or cyber operations.' In general, the DSP prohibits 'U.S. persons' from 'knowingly engag[ing] in a covered data transaction' that provides a 'country of concern' or 'covered person' with access to 'covered data.' Each of these terms contain complexities and carve-outs requiring careful consideration, including that 'U.S. persons' includes foreign citizens located in the United States, as well as U.S. entities.
The final Rule's knowledge standard is not a strict liability standard and instead the Rule explains that 'knowingly engage' should be interpreted to mean that an individual or entity 'had actual knowledge of, or reasonably should have known about, the circumstances, or result' of providing access to covered data by prohibited persons and governments. For example, if a company engaged in data brokerage (a 'covered transaction') and is deceived by a country of concern to provide its government with access to protected data, the company would not be liable because it did not have 'actual knowledge of, nor would they have reasonably known of, the circumstances.' The DOJ warns that despite the knowledge requirement under the DSP, companies are expected to have compliance systems in place that prevent restricted conduct by their customers, even if companies do not necessarily have 'actual knowledge' of their customers' every activity.
The term 'access' to covered data is left 'intentionally broad' to include the ability to obtain or otherwise view or receive data, including through information systems, cloud-computing platforms, and security systems or software, meaning that companies' third-party relationships may put them at risk. The DSP even applies to activity conducted between the U.S. and non-covered countries if certain links exist to a country of concern.
'Covered data' includes six categories of 'bulk sensitive personal data.' The term 'bulk' refers to the volume of sensitive data that triggers application of the DSP, and the triggering threshold amounts vary based on the type of the data. The categories of data and their thresholds are as follows: (1) covered personal identifiers (data collected or maintained on more than 100,000 U.S. persons); (2) precise geolocation data (data collected or maintained on more than 1,000 U.S. devices); (3) biometric identifiers (data collected or maintained on more than 1,000 U.S. persons); (4) human genomic (data collected or maintained on more than 100 U.S. persons) and other ˋomic data (epigenomic, proteomic, and transcriptomic data collected or maintained on more than 1,000 U.S. persons); (5) personal health data (data collected or maintained on more than 10,000 U.S. persons); and (6) personal financial data (data collected or maintained on more than 10,000 U.S. persons). Data meeting the specified thresholds is covered under the DSP regardless of whether the data is anonymized, pseudonymized, de-identified, or encrypted. U.S. government-related data is also covered, with any amount of data triggering DSP rules.
The DSP restricts access to covered data by 'countries of concern' (China, including Hong Kong and Macau; Russia; Iran; North Korea; Cuba; and Venezuela) identified for their perceived long-term pattern or serious instances of conduct significantly adverse to the United States. Additionally, the DSP also encompasses access by 'covered persons,' meaning: (1) foreign entities headquartered in or organized under the laws of a country of concern; (2) foreign entities 50% or more owned by a country of concern or covered person; (3) foreign individuals primarily resident in a country of concern; and (4) foreign individuals who are employees or contractors of a covered person entity or a country-of-concern government. The DOJ can designate, at any time, a 'covered person.'
Big Consequences for Regulated Transactions
If a company handles data covered by the DSP and employs or otherwise has relationships with countries of concern or covered individuals, the DSP will restrict, or completely prohibit, certain categories of transactions. The DSP restricts transactions that involve a vendor agreement, employment agreement, or investment agreement with a country of concern or covered person. Restricted transactions are subject to strict 'Security Requirements' established by the Cybersecurity and Infrastructure Security Agency and essentially mandate companies to 'fully and effectively prevent access to covered data' through data minimization and masking, encryption, and privacy-enhancing technologies.
The final Rule includes a few examples of restricted transactions, including a U.S. wealth-management services company that collects bulk personal financial data on U.S. clients and decides to appoint an individual from a country of concern that resides in the country of concern to the company's board. Because the company allows board members access to bulk personal financial data in connection with data security and cybersecurity responsibilities that the board handles, the appointment of the director is a restricted employment agreement. In contrast, a U.S. institution that conducts medical research at its own laboratory in a country of concern and sends a U.S. citizen-employee to assist with the research does not engage in a covered transaction because no data is being accessed by a covered person or government.
Prohibited transactions include data brokerage transactions with a country of concern or covered person, or any foreign person unless certain contractual requirements are in place. Data brokerage is defined as the selling, licensing or other sharing of covered data. The DSP also prohibits any data transaction involving access to human `omic data (human genomic, epigenomic, proteomic, and transcriptomic data) or to human biospecimens from which `omic data could be derived. Additionally, transactions with the purpose of evading or avoiding or causing a violation, or U.S persons knowingly directing a prohibited or restricted transaction are prohibited under the DSP.
Some examples of prohibited transactions include a U.S. organization that maintains a database of bulk U.S. sensitive personal data and offers annual memberships (including to covered persons) for a fee so that members receive a license to access the data, or a U.S. company that owns a mobile app containing tracking pixels knowingly installed into the app and those pixels transfer bulk U.S. sensitive data of U.S. users to a covered person-owned social media app for targeted advertising. Additionally, a U.S tech company that operates an autonomous driving platform that collects the precise geolocation data of its cars operating in the U.S. and then sells this data to its parent company headquartered in a country of concern to help develop other technological advances is prohibited under the DSP.
The DSP threatens penalties up to the amounts provided for under the International Emergency Economic Powers Act(IEEPA). As for civil penalties, the IEEPA's amounts are subject to adjustment pursuant to the Federal Civil Penalties Inflation Adjustment Act of 1990, so the DSP today provides for maximum civil penalties of $377,700 (based on a statutory amount of $250,000 established in 2007 that is subject to inflation adjustments) or an amount that is twice the amount of the transaction at issue, whichever is greater. For criminal liability for willful conduct, violators of the DSP may face imprisonment of up to 20 years and a $1,000,000 fine. The Final Rule took into consideration that DOJ's approach to criminal violations should be consistent with criminal penalties under the IEEPA.
Reading Between the Lines of the Exemptions and Exclusions
Exemptions and exclusions to the DSP's prohibitions exist, but the general categories of exempt transactions in the Rule actually are limited by the details. Personal communications, informational materials, and travel information, are classified by the IEEPA as exempt transactions, but the U.S. Department of the Treasury Office of Foreign Assets Control ('OFAC') is known to interpret these exemptions narrowly. The DOJ is expected to follow in OFAC's footsteps.
The DSP also includes broad categories of 'financial services' and 'corporate group transactions,' but restrictions limit the exemptions. Financial services are limited to transactions 'ordinarily incident to and part of the provision of financial services,' such as banking, capital-markets, or financial-insurance services, or the transfer of personal financial data or covered personal identifiers incidental to the purchase and sale of goods and services. Similarly, 'corporate group transactions' are limited to data transactions that are '[b]etween a U.S. person and its subsidiary or affiliate located in (or otherwise subject to the ownership, direction, jurisdiction, or control of) a country of concern' and '[o]rdinarily incident to and part of administrative or ancillary business operations.'
Similarly, telecommunications services are exempted but limited to data transactions 'ordinarily incident to and part of the provision of telecommunication services.' The DSP warns that a U.S. telecommunications service provider that collects precise geolocation data on its U.S. subscribers that then sells the data to a covered person for the purpose of targeted advertising is not exempt from the DSP since the sale is 'not ordinarily incident to and part of the provision of telecommunications services.'
DOJ's Great Expectations for DSP Regulated Companies
The DSP imposes a number of requirements on companies that engage in restricted and prohibited transactions, including recordkeeping, reporting, audit, and due diligence requirements, as well as implementation of a formal compliance program tailored to the entity's risk profile. The latest Compliance Guidance clarifies that companies engaged in restricted transactions must implement a written 'Data Compliance Program' that meets several minimum requirements to comply with the DSP. Failure to maintain such a program may constitute a DSP violation in itself.
In general, the DOJ will look for a risk-based compliance program that includes procedures for verifying data flows involved in restricted transactions, such that a company may want to complete ongoing risk assessments to determine coverage of the DSP against the company's current data holdings and vendor, employee, or investment agreements, as well as examine the company's current security measures, offered products and services, and geographic locations of its third party relationships. The Guidance further explains that a company's Data Compliance Program is expected to include policies and procedures that will 'identify, escalate, and report activity,' including for bringing newly acquired entities into compliance with the Program. Throughout finalization of the DSP, the DOJ declined to allow for contractual language or consent to share data to eliminate the requirement of a formalized Data Compliance Program.
DOJ Gives the Gift of (Limited) Time
The DOJ has given companies an extra 90 days, until July 8, 2025, to avoid civil enforcement in recognition that individuals and companies 'may need to take steps to determine whether the DSP's prohibitions and restrictions apply' and 'to implement changes.' The 90-day enforcement hiatus, however, is limited since the DOJ still plans to pursue criminal enforcement and civil enforcement is paused 'so long as the person is engaging in good faith efforts to comply' during that time. Accordingly, the DOJ has made clear that now is the time to come into compliance with the DSP, and starting July 8, enforcement is coming.
The Implementation and Enforcement Policy provides instructive examples of 'good-faith efforts' the Department expects of companies during the 'pause.' Such efforts, some of which may be costly and time consuming, include transferring products and services to new vendors, conducting internal review of access to covered data, adjusting employees' work locations and their roles or responsibilities to prevent their access to covered data, evaluating investments from and renegotiating investment agreements with countries of concern or covered persons, as well as implementing the strict Security Requirements. The July 8 date is fast approaching, and promptly implementing good faith efforts to comply with the DSP will be critical to avoid the serious penalties and reputational harm DSP violations can bring.
To read more from Robert Anello , please visit www.maglaw.com .
Emily Smit , an associate at the firm, assisted in the preparation of this blog.

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Why We're Dodging These 3 Gold CEFs (Even With Gold Soaring)
Why We're Dodging These 3 Gold CEFs (Even With Gold Soaring)

Forbes

time5 minutes ago

  • Forbes

Why We're Dodging These 3 Gold CEFs (Even With Gold Soaring)

A lump of gold on a stone floor getty Here's a surprise from a die-hard closed-end fund (CEF) fan like me: Sometimes CEFs aren't your best bet. I'll admit, that's tough for me to say—especially when the average CEF yields a historically high 9.1%. (CEF yields are usually around 8.5%). That high yield partly reflects the fact that many CEFs are trading at steep discounts to their net asset value (NAV). Translation: The fund is trading for less than what its underlying portfolio is worth. That, in turn, has resulted in lower prices among some CEFs, along with higher yields (as yields and prices move in opposite directions). All of this simply means that CEFs are generally out of favor right now, which is an opportunity for us. But not every CEF is ripe for buying. We especially want to avoid the three top performers among CEFs with market caps over $200 million: ASA Gold and Precious Metals (ASA), the Sprott Physical Gold Trust (PHYS) and the Sprott Physical Gold and Silver Trust (CEF). The fact that these funds have booked strong runs this year shouldn't come as a surprise: They're all gold funds, and gold has taken off due to rising economic uncertainty (the usual fuel for the yellow metal). Even so, as you can see, there are some clear differences in performance here, and those are worth unpacking. Gold Funds Ycharts Above we see that the Sprott Physical Gold and Silver Trust—with the somewhat confusing 'CEF' ticker, not to be confused with CEFs in general (in purple)—and PHYS (in blue) have similar returns to the benchmark SPDR Gold Shares (GLD) ETF (in green), at around 25%. Then there's ASA (in orange), which has more than doubled even the best of these three other funds. There is some logic at work here. For starters, PHYS and GLD really should track each other, since they both devote almost 100% of their portfolios to physical gold (both own gold bars that are locked up in vaults), and both have similar expense ratios (0.4% for GLD, 0.41% for PHYS). The lower performance of 'CEF' is also not surprising, given that the fund also holds silver, and the 'poor man's gold' hasn't done as well as its yellow counterpart this year. ASA, however, is the clear outperformer. That's thanks in part to its ownership of several gold-mining stocks. Its largest position, G Mining Ventures Inc., a Canadian firm that explores for precious metals, has nearly doubled year to date. ASA's fast short-term gain is, of course, great, but it's unlikely to last. Here's why. Note that, if we go back to 2010, the year the last of these funds, PHYS, launched, we see that GLD (again in green) outran all three of the CEFs. This shows that CEFs were poor options in the case of gold. Moreover, ASA (again in orange) was actually the worst performer, returning just 53% over 15 years, and being in the red for most of that time. ASA Underperforms Ycharts In terms of key takeaways, there are a few here. First, if you want to hold gold, this is a rare case where an ETF, not a CEF, is the better choice. Second, gold is not a great play for income, given that the highest yielder among these funds is ASA, with a puny 0.2%. Third, gold itself is a poor play for the long term, no matter how you invest in it. To see why, all we need to do is splice the S&P 500's performance (in pink below) into that last chart. Gold Underperforms Ycharts It doesn't get much clearer than that! This, however, is where the good news ends for ETF investors. Because when it comes to investing in stocks (or pretty well any other asset class, for that matter), you're far better off with CEFs. Let's take a look at the Adams Diversified Equity Fund (ADX), a CEF we've held in my CEF Insider service since its earliest days: We bought ADX in July 2017, just a few months after CEF Insider's launch. Here's how the fund—current yield: 9% (and in orange below)—has done since, as compared to the S&P 500 index fund SPDR S&P 500 ETF Trust (SPY), in purple, with dividends reinvested: ADX Outperforms Ycharts This chart says it all: CEFs like ADX can crush the S&P 500 and pay us generously while doing so. Plus they give us access to top-notch management and upside-generating discounts to NAV, too. Those are strengths no index fund can match. Michael Foster is the Lead Research Analyst for Contrarian Outlook. For more great income ideas, click here for our latest report 'Indestructible Income: 5 Bargain Funds with Steady 10% Dividends.' Disclosure: none

WWDC to focus on redesigns as Apple remains sidelined on AI, Bloomberg says
WWDC to focus on redesigns as Apple remains sidelined on AI, Bloomberg says

Yahoo

time9 minutes ago

  • Yahoo

WWDC to focus on redesigns as Apple remains sidelined on AI, Bloomberg says

Apple's (AAPL) upcoming Worldwide Developers Conference will do little to assuage fears that the iPhone maker is a laggard in AI, Blomberg's Mark Gurman reports. Instead, the event will focus on design and productivity enhancements for its long-established operating system franchises. The company's keynote address will introduce redesigned software interfaces for the iPhone, iPad, Mac, Apple TV and Apple Watch, in addition to more minor tweaks to the Vision Pro headset. As part of the end-to-end overhaul, the company is also making a sweeping change to its software branding, which will shift from version numbers to a year-based system. That means Apple will introduce iOS 26, iPadOS 26, tvOS 26, visionOS 26, macOS 26 and watchOS 26 – named for 2026. Internally, the operating systems are known as Luck, Charisma, Discovery, Cheer and Nepali, respectively, the author notes. The AI changes will be surprisingly minor are unlikely to impress industry watchers, especially considering the rapid pace of innovation by Alphabet's (GOOG) (GOOGL) Google, Meta Platforms (META), Microsoft (MSFT) and OpenAI, the publication adds. Easily unpack a company's performance with TipRanks' new KPI Data for smart investment decisions Receive undervalued, market resilient stocks right to your inbox with TipRanks' Smart Value Newsletter Published first on TheFly – the ultimate source for real-time, market-moving breaking financial news. Try Now>> See the top stocks recommended by analysts >> Read More on AAPL: Disclaimer & DisclosureReport an Issue Apple's growing list of issues hinders AI reboot, WSJ says Apple expands partnership in India with Tata, Reuters reports Morning News Wrap-Up: Thursday's Biggest Stock Market Stories Apple says App Store ecosystem facilitated $1.3T in developer sales in 2024 This Is How Much Analysts Expect Apple's (AAPL) EPS to Fall after Court Ruling

Vance says Musk making a 'huge mistake' in going after Trump but also tries to downplay the attacks
Vance says Musk making a 'huge mistake' in going after Trump but also tries to downplay the attacks

Associated Press

time10 minutes ago

  • Associated Press

Vance says Musk making a 'huge mistake' in going after Trump but also tries to downplay the attacks

BRIDGEWATER, N.J. (AP) — Vice President JD Vance said Elon Musk was making a 'huge mistake' going after President Donald Trump in a storm of bitter and inflammatory social media posts after a falling out between the two men. But the vice president, in an interview released Friday after the very public blow up between the world's richest man and arguably the world's most powerful, also tried to downplay Musk's blistering attacks as an 'emotional guy' who got frustrated. 'I hope that eventually Elon comes back into the fold. Maybe that's not possible now because he's gone so nuclear,' Vance said. Vance's comments come as other Republicans in recent days have urged the two men, who months ago were close allies spending significant time together, to mend fences. Musk's torrent of social media posts attacking Trump came as the president portrayed him as disgruntled and 'CRAZY' and threatened to cut the government contracts held by his businesses. Musk, who runs electric vehicle maker Tesla, internet company Starlink and rocket company SpaceX, lambasted Trump's centerpiece tax cuts and spending bill but also suggested Trump should be impeached and claimed without evidence that the government was concealing information about the president's association with infamous pedophile Jeffrey Epstein. 'Look, it happens to everybody,' Vance said in the interview. 'I've flown off the handle way worse than Elon Musk did in the last 24 hours.' Vance made the comments in an interview with ' manosphere' comedian Theo Von, who last month joked about snorting drugs off a mixed-race baby and the sexuality of men in the U.S. Navy when he opened for Trump at a military base in Qatar. The vice president told Von that as Musk for days was calling on social media for Congress to kill Trump's 'Big Beautiful Bill,' the president was 'getting a little frustrated, feeling like some of the criticisms were unfair coming from Elon, but I think has been very restrained because the president doesn't think that he needs to be in a blood feud with Elon Musk.' 'I actually think if Elon chilled out a little bit, everything would be fine,' he added. Musk appeared by Saturday morning to have deleted his posts about Epstein. The interview was taped Thursday as Musk's posts were unfurling on X, the social media network the billionaire owns. During the interview, Von showed the vice president Musk's claim that Trump's administration hasn't released all the records related to sex abuser Jeffrey Epstein because Trump is mentioned in them. Vance responded to that, saying, 'Absolutely not. Donald Trump didn't do anything wrong with Jeffrey Epstein.' 'This stuff is just not helpful,' Vance said in response to another post shared by Musk calling for Trump to be impeached and replaced with Vance. 'It's totally insane. The president is doing a good job.' Vance called Musk an 'incredible entrepreneur,' and said that Musk's Department of Government Efficiency, which sought to cut government spending and laid off or pushed out thousands of workers, was 'really good.' The vice president also defended the bill that has drawn Musk's ire, and said its central goal was not to cut spending but to extend the 2017 tax cuts approved in Trump's first term. The bill would slash spending but also leave some 10.9 million more people without health insurance and spike deficits by $2.4 trillion over the decade, according to the nonpartisan Congressional Budget Office. Musk has warned that the bill will increase the federal deficit and called it a 'disgusting abomination.' 'It's a good bill,' Vance said. 'It's not a perfect bill.' He also said it was ridiculous for some House Republicans who voted for the bill but later found parts objectional to claim they hadn't had time to read it. Vance said the text had been available for weeks and said, 'the idea that people haven't had an opportunity to actually read it is ridiculous.' Elsewhere in the interview, Vance laughed as Von cracked jokes about famed abolitionist Frederick Douglass' sexuality. 'We're gonna talk to the Smithsonian about putting up an exhibit on that,' Vance joked. 'And Theo Von, you can be the narrator for this new understanding of the history of Frederick Douglass.' The podcaster also asked the vice president if he 'got high' on election night to celebrate Trump's victory. Vance laughed and joked that he wouldn't admit it if he did. 'I did not get high,' he then said. 'I did have a fair amount to drink that night.' The interview was taped in Nashville at a restaurant owned by musician Kid Rock, a Trump ally.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store