Skip to content

Logistics and distribution

DOJ bulk data rule and fleet location data: what to check before licensing

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

The DOJ bulk data rule limits transactions that could give countries of concern or covered persons access to bulk U.S. sensitive personal data, and precise geolocation is one of its named categories. Before licensing fleet telematics or GPS history, check whether the data is device-level location, whether volumes may cross the thresholds, and who the recipient really is.

Key takeaways

  • Precise geolocation data is a named category under the Justice Department's data security rule, so fleet location histories need a check before any license.
  • The rule applies volume thresholds over a lookback period, which counsel should compare against the actual dataset.
  • Recipient screening covers ownership, control, staff location and onward transfers, not just the company name on the contract.
  • Removing driver names does not settle the question, because location trails can identify people on their own.
  • Coarsening, aggregating or excluding raw location points can change the analysis, and often the value as well.

What is the DOJ bulk data rule?#

The DOJ bulk data rule is the Justice Department's data security regulation, published at 28 CFR part 202, which prohibits or restricts certain transactions that could give countries of concern or covered persons access to bulk U.S. sensitive personal data or government-related data. It implements a presidential executive order on protecting Americans' sensitive data.

The rule names several categories of sensitive personal data, including precise geolocation data, alongside biometric identifiers, human genomic and related data, personal health data, personal financial data and certain personal identifiers. Each category carries its own bulk threshold, and some transaction types are prohibited outright while others are allowed only if specified security requirements are met.

Logistics companies rarely think of themselves as holders of sensitive personal data. Fleet telematics changes that.

Why fleet location data falls in scope#

Fleet location data falls in scope because telematics, ELD and driver app records are precise, timestamped location points tied to a vehicle, a device or a person. A truck's breadcrumb trail shows where its driver starts and ends the day, where they stop and how they travel, even with the name removed.

The rule also has a category for government-related data, which can include location data connected to certain sensitive government sites regardless of volume. Fleets that deliver to, or park near, military installations or other government facilities need a closer look at that category.

Records that usually carry this kind of data include GPS pings and trip histories from telematics platforms, ELD duty status records with locations, stop and geofence events, driver mobile app locations and proof-of-delivery scans with coordinates.

The pre-licensing checklist#

The pre-licensing checklist asks about the data, the volume, the recipient, the transaction and any government sites. Work through it with counsel before a sample leaves the company, not after a term sheet is signed.

Keep the answers. A short memo recording what the dataset contained, how volume was counted, who the recipient was and what counsel concluded is the record you will want if the transaction is ever questioned, and it saves repeating the work for the next buyer.

The pre-licensing checklist
QuestionWhat to checkWho usually answers
Does the dataset contain precise geolocation?Raw points, trip histories and stop locations, their precision, and whether they link to a vehicle, device or driverIT and the telematics administrator
Could volumes cross the rule's thresholds?How many distinct devices or people appear over the rule's lookback period, compared with the current threshold for each categoryIT with counsel
Who is the recipient?Ownership, control, place of organization, where staff with access are located, and onward transfer plansCounsel, with diligence answers from the buyer
What kind of transaction is it?Whether a data license falls within the rule's defined transaction types, such as data brokerage, and which requirements followCounsel
Does any location touch government sites?Deliveries, yards or routes near sensitive government facilitiesOperations and counsel

Does removing driver names take the data out of scope?#

Removing driver names does not reliably take fleet location data out of scope, and companies should not assume it does. Location trails can identify a person by where they sleep and work, and the rule's definitions are written to reach data even after it has been anonymized, pseudonymized or de-identified, so name removal alone should not be treated as an exit. Ask counsel to apply the definitions to the prepared dataset.

Preparation choices still matter, because they can change both the legal analysis and the dataset's usefulness to a buyer. Common options include:

  • Coarsening coordinates to a grid or postal area instead of exact points.
  • Aggregating trips to lane or region level rather than individual vehicle trails.
  • Removing vehicle, device and driver identifiers, with no retained key.
  • Trimming route ends so home terminals and overnight stops do not appear.
  • Excluding locations near sensitive sites entirely.
  • Dropping raw pings and keeping only derived events, such as arrival and departure at customer docks.

Recipient screening: what to ask the buyer#

Recipient screening asks who ultimately controls the licensee and where the data will go, because a domestic contracting party can still be owned by, or employ, covered persons. Ask the buyer to describe its ownership, its parent companies, where its staff with data access sit and which vendors will store or process the data.

A foreign buyer that is not itself a covered person still needs attention: the rule may require specific contract terms for some data brokerage transactions with foreign persons, such as limits on onward transfer to countries of concern, so counsel should check whether those apply.

Write the answers into the license. Onward-transfer limits, approved processing and storage locations, audit rights and notice of ownership changes are terms counsel may consider. Provenance standards already have slots for this: the Data & Trust Alliance's Data Provenance Standards include elements for allowed and excluded processing and storage geographies.

Other rules that may apply to fleet location data#

Other rules that may apply to fleet location data include state privacy laws, several of which treat precise geolocation as sensitive information, as well as employee notice and consent obligations, union agreements and customer contracts. A separate federal statute, the Protecting Americans' Data from Foreign Adversaries Act, may also be relevant to companies that transfer certain sensitive data, including location data.

Driver consent deserves its own review. Telematics notices written for safety and compliance may not describe licensing to third parties, and owner-operators under lease may have their own terms. Each of these is assessed deal by deal with counsel.

Illustrative: a regional carrier's telematics archive#

Illustrative: a fictional regional carrier runs dry van and final-mile operations with a telematics unit in every tractor. An AI developer working on routing and arrival-time models asks about its trip history, and the CEO wants to know whether the archive can be licensed.

Counsel works through the checklist. The archive holds precise points tied to vehicles and, through dispatch records, to drivers, and its device count across the lookback period needs comparing with the current threshold. Some routes serve a government facility. The buyer is domestically owned but uses an offshore data labeling contractor.

The carrier decides to offer lane-level trip summaries with coarse times and no vehicle or driver identifiers, to exclude routes near the government facility, and to require that the data stay with approved processors in approved locations. Raw pings stay out of the package.

How SourceX handles location data#

SourceX handles fleet location data as a restricted record type. In the Rights step of the SourceX five-step transaction, recipient diligence and the national security checks above are reviewed with the supplier's counsel before any sample is shared; in Preparation, the agreed coarsening and identifier removal are applied. The privacy record and permitted use are documented in the SourceX Evidence Packet, and the supplier approves the final scope.

Frequently asked questions

Does the rule matter if the buyer is a U.S. company?

It can. The rule looks at who controls and can access the data, not only where the contracting company is organized. A domestic buyer owned by a foreign parent, or one that uses staff or vendors in a country of concern, may raise questions. Recipient diligence and contract terms address this.

Is lane-level or aggregated location data still covered?

Aggregation can change the analysis, but whether a specific dataset still counts as precise geolocation depends on its precision, its linkage to people or devices and the rule's definitions. Ask counsel to review the prepared dataset, not just the raw archive, and record the decision with the transaction.

Does the rule require a compliance program?

For some restricted transactions, the rule sets due diligence, recordkeeping and security requirements, and companies engaged in covered transactions may need written policies. Whether any of that applies depends on the transaction. Counsel can advise on what a licensing program needs.

What about location data our telematics vendor already holds?

Your vendor's own obligations and contract terms govern what it does with location data. Review its data-use clause and ask whether it shares or licenses aggregated location data, since that can affect both your compliance posture and what you can license yourself.

Who at the company should own this review?

Usually the general counsel or outside counsel, with the telematics administrator and IT supplying facts about the data. Operations should confirm which routes, yards and customer sites are involved, and the executive signer should see the conclusion in writing before any sample is shared.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for allowed and excluded processing and storage geographies, among others such as license to use and intended data use. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify