Skip to content

Logistics and distribution

Customs brokers and client confidentiality: what 19 CFR 111.24 allows

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

19 CFR 111.24 treats a licensed customs broker's records about its clients' business as confidential and limits disclosure to a short list of recipients, such as the client and authorized government officers, plus court subpoenas. For any other use, including licensing records to AI developers, treat written client authorization as the gating step and confirm the reading with counsel.

Key takeaways

  • 19 CFR 111.24 is a confidentiality rule for licensed customs brokers, and it reaches information connected with client records, not only the documents themselves.
  • An AI developer is not among the recipients the rule names, so licensing client-related records generally starts with the client's written authorization.
  • Removing an importer's name may not end the duty, because product, supplier and port details can still identify a client.
  • Client contracts, privacy laws and customs recordkeeping rules sit on top of 111.24 and are reviewed alongside it.
  • A metadata-only fit check describes systems and volumes without disclosing the contents of any client record.

What does 19 CFR 111.24 say in plain English?#

19 CFR 111.24 says that a licensed customs broker's records relating to the business of its clients are confidential. The broker may share their contents, or information connected with them, only with a short list of recipients the rule names. Broadly, that list covers the client itself, the client's surety on a particular entry, named CBP officials and other duly accredited officers or agents of the United States, and a subpoena from a court of competent jurisdiction can compel disclosure.

The rule sits in Part 111 of Title 19, which governs customs broker licensing, permits and broker duties. Part 111 has been amended over time, so read the current text on the official electronic Code of Federal Regulations rather than a summary saved years ago, and have customs counsel confirm how it applies to your facts.

Two words do most of the work: records and connected. The duty does not stop at the entry packet. It reaches information drawn from those records, which can include summaries, spreadsheets and data extracts built from client files.

Which broker records does the rule reach?#

The records 19 CFR 111.24 reaches are, in practice, most of what a brokerage holds, because nearly every workflow starts with a client shipment. The table sorts common record types by how closely they tie to client business. Treat it as a starting map for counsel, not a conclusion.

The practical lesson is that very few broker records are free of client information. Even internal training material tends to use real entries as examples, so treat any record as client-related until someone has checked it.

Which broker records does the rule reach?
Record typeTie to client businessWhat to note
Entry summaries and entry packetsDirectBuilt entirely from client shipment facts and filings.
Commercial invoices, packing lists and bills of ladingDirectReveal suppliers, prices, quantities and routings.
Classification and valuation worksheetsDirectThe broker's own reasoning, applied to a client's goods.
Powers of attorney and client onboarding filesDirectAlso hold personal details of the people who signed.
Email with importer staff about holds, exams and information requestsDirectMix client facts with the broker's judgment.
Internal procedures, training decks and checklistsOften indirectMay quote client examples that need removal.
Staffing schedules and queue reportsOften indirectCan reference client names, volumes or ports.

Why client authorization is the gating step#

Client authorization is the gating step because an AI developer, a data intermediary or any other commercial recipient is not one of the parties the rule names. The cleanest way to bring client-related records into a license is for the client to authorize that disclosure in writing, with a defined scope.

Some brokers ask whether stripping client names or aggregating data takes the information outside the rule. That is an open legal question to put to counsel, not an assumption to build a deal on. Entry data can point to an importer through product descriptions, supplier names, ports and timing, even with the name removed.

A useful authorization is specific. Broad consent buried in general terms and conditions of service invites dispute later, and it may not satisfy counsel's reading of the rule. A stand-alone authorization should cover the points below.

  • Which records are covered, by system and date range.
  • The purpose: training or evaluating AI models, not marketing or resale.
  • Who may receive the prepared records, including any intermediary.
  • What preparation applies, such as removing personal and confidential details.
  • How long the permission lasts and how the client can withdraw it.
  • Who signs for the client, in what capacity, and on what date.

What a broker can review before asking any client#

A broker can review its own systems and volumes before asking any client, because describing an archive is different from disclosing its contents. Knowing which ABI software holds entries, which document management system holds images and how many years remain accessible lets leadership decide whether client conversations are worth starting.

Keep this review descriptive. Record counts, date ranges, system names and field lists are the right level of detail. Do not paste sample entries into emails, slide decks or questionnaires, even for outside advisors, until counsel has said whether that is itself a disclosure.

The review also shows which clients matter most. A broker whose classification work concentrates in a few long-standing accounts has a short list of authorizations to request, while one with a long tail of small importers may find that only a subset is practical to approach.

Rules and contracts that sit on top of 111.24#

19 CFR 111.24 is one layer among several, and a broker reviewing a data request checks them together. Clearing the confidentiality rule with client authorization does not settle what the client contract, privacy law or a separate nondisclosure agreement says.

Which laws apply is assessed deal by deal with counsel. A broker with individual importers among its accounts, or clients spread across many states, will usually need a closer privacy review than one serving only business importers.

Rules and contracts that sit on top of 111.24
LayerWhat it governsWhat to check
Customs recordkeeping under 19 CFR 163What must be kept and produced to CBPThat no licensing project removes or alters records you must retain.
Client service agreementsConfidentiality, data use and liabilityWhether the terms allow, limit or forbid secondary use.
Nondisclosure agreementsSpecific client or supplier informationScope, duration and any carve-out for de-identified data.
Privacy lawsPersonal information inside filesWhich state laws may apply to signers, contacts and individual importers.
Export control and sanctions rulesControlled goods and technical dataExclude shipments involving controlled items entirely.

Illustrative: a regional broker answers an AI data inquiry#

Illustrative: a fictional regional customs brokerage hears that classification histories may interest AI developers. Its entries live in ABI software, scanned invoices and rulings research sit in a document management system, and client conversations run through shared email boxes.

Counsel reads 19 CFR 111.24 with the leadership team and concludes that client-related records need written client authorization. The brokerage drafts a short authorization covering classification worksheets and related email for named date ranges, and offers it to its longest-standing business clients. It excludes individual importers and any shipment flagged for export control review.

Some clients sign and some decline. The resulting package is narrower than the full archive, but every record in it traces to a signed authorization, and the declined accounts are simply left out.

How SourceX approaches broker confidentiality#

SourceX treats 19 CFR 111.24 as a Rights question within the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Nothing leaves the brokerage during the first assessment, which works from system names, date ranges and volumes alone, so the broker and its counsel can decide whether to proceed before any client file is touched.

Where a package goes ahead, the SourceX Evidence Packet covers provenance, licensing rights, permitted use, the privacy record and release authorization. For a broker, the licensing rights entry lists each client authorization, so the scope of every release can be checked against a signed document.

Frequently asked questions

Does 19 CFR 111.24 apply to freight forwarders that are not licensed brokers?

The rule sits in Part 111, which governs licensed customs brokers, so its direct reach is the broker. A forwarder without a broker license is generally outside it, but client contracts, confidentiality agreements and privacy laws still apply. Many forwarders operate alongside an affiliated brokerage, so check which legal entity actually holds each record set.

Can a broker's software vendor use client data to train its own AI?

That depends on the vendor contract and on how counsel reads the broker's confidentiality duty. Brokers rely on vendors to file entries and store images, but a vendor using that data for its own product development is a separate use. Read the data use, aggregation and AI clauses in each vendor agreement and raise gaps at renewal.

What happens if a broker discloses client information without authorization?

A broker that breaches its Part 111 duties can face disciplinary action from CBP, and the client may have contract claims. The relationship cost can be larger than either. That is why authorization, scope and a written record of each release matter more than speed in any data project.

Who inside the brokerage should own this decision?

The licensed broker who exercises responsible supervision and control should own it, working with counsel and the executive responsible for client relationships. Operations and IT staff supply the system facts. Keeping the decision with licensed leadership aligns it with the duties Part 111 already places on them.

Do client authorizations need to be renewed?

Authorizations should state their own duration and withdrawal terms, so renewal follows the document. If a license runs longer than an authorization, or the scope of records changes, go back to the client before releasing anything new. Store signed authorizations with the license file so they can be produced on request.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify