Privacy and preparation
DOJ bulk data rule: licensing data to foreign buyers
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Licensing data to a foreign buyer can fall under the DOJ bulk sensitive data rule. It bars data brokerage of bulk US sensitive personal data and government-related data with countries of concern and covered persons, and expects licenses to other foreign parties to forbid onward transfer to them. Removing identifiers alone does not take data out of scope.
Key takeaways
- A data license is a form of data brokerage under the rule, because its definition reaches licensing access to data.
- Each data category has its own bulk threshold, and stripping identifiers or encrypting the data does not by itself exclude it.
- Licenses to foreign parties outside the countries of concern still need terms forbidding onward transfer to them.
- Screen the licensee as carefully as the data: ownership, control, location and who will actually touch the records.
What the rule is and why licensors should care#
The DOJ bulk sensitive data rule is the Justice Department's Data Security Program, run by its National Security Division. It stops US persons from entering certain transactions that would give countries of concern, or covered persons tied to them, access to bulk US sensitive personal data or government-related data.
Covered categories include precise location data, biometric identifiers, genomic and other omic data, health data, financial data and certain personal identifiers. Government-related data, such as data linked to sensitive government sites or personnel, is handled separately and is not tied to the same bulk minimums.
Whether a counterparty is a covered person depends on ownership, control, place of organization or principal place of business, and, for individuals, residence or employment. The Department can also designate covered persons by name, and the countries of concern are listed in the rule itself, so read the current text.
How the rule sorts a licensing deal#
The rule sorts transactions into groups with different consequences, and a licensing deal lands in one of them. The table is a general map; counsel should test any specific deal against the text.
Licensing sits squarely inside the rule's idea of data brokerage. The definition reaches selling data, licensing access to it and comparable commercial arrangements in which the recipient did not gather the data from the individuals themselves, which describes a training data license.
| Group | What falls in it | Effect on a license |
|---|---|---|
| Prohibited | Brokering data to a country of concern or covered person; certain transactions in human genomic data or biospecimens | Stop unless counsel identifies an exemption or a DOJ license |
| Restricted | Vendor, employment and investment agreements that would give those parties access to covered data | Possible only with the prescribed security requirements in place |
| Brokerage with other foreign persons | A license to a foreign developer that is not a covered person | Allowed, with contract terms against onward transfer |
| Exempt | Listed categories, for example certain official government work and some transactions incident to financial services | Check the exemption's exact wording before relying on it |
Deal structures to look at closely#
Deal structures matter as much as the data, because access can reach a covered person through routes other than the named licensee. Many of these structures are workable with the right terms; the point is to see them before a contract is drafted.
| Structure | Why it needs review |
|---|---|
| Direct license to a developer incorporated abroad | The licensee is a foreign person, so covered-person status and onward-transfer terms must be checked |
| License to a US company with foreign owners | Ownership and access paths can lead to a covered person even though the licensee itself is a US person |
| US licensee using offshore contractors or labeling teams | People abroad may reach the records, so access terms and vendor arrangements matter |
| Evaluation samples shared before signing | Samples are still data given to the counterparty and may count toward volumes over time |
| Hosting or processing by a foreign vendor | A vendor agreement that gives access may be a restricted transaction |
Thresholds, aggregation and de-identification#
The rule bites only at bulk volumes, and the bulk line is drawn separately for each category of sensitive data, counted in US persons or devices. Location and biometric data reach their thresholds at far smaller volumes than general identifiers, so a modest telematics export can matter more than a large CRM extract.
Deliveries can be added together. Volumes exchanged with the same counterparty over a look-back period may be combined, so phased deliveries or repeated samples to one licensee should be tallied. Confirm the current figures and period in the rule.
Preparation work does not reset the count. The rule states that covered data can qualify whether or not it has been anonymized, pseudonymized, de-identified or encrypted, so a dataset that passes a state-law de-identification test can still be in scope. Record families that most often come close are fleet and dispatch GPS traces, HR and payroll records, and home service records with street addresses.
Screening and contract terms for a foreign licensee#
Screening a foreign licensee means establishing who owns and controls it and then writing those facts into the contract. Most of these terms are sound practice for any licensee, domestic or foreign.
The rule also places reporting, due diligence and record-keeping expectations on US persons for some transactions, including reporting certain suspected breaches of the onward-transfer term. Counsel should confirm which of these apply to the deal.
- Ownership disclosure down to ultimate owners, with a representation that the licensee is not a covered person.
- A prohibition on any resale, sublicense or other onward transfer that would put the data in the hands of a country of concern or covered person.
- Prompt notice to the licensor of any known or suspected breach of that prohibition.
- Named storage locations and a list of who may access the records.
- Audit or certification rights, and a right to terminate on a change of control.
- The same obligations flowed down to any sublicensee, contractor or vendor.
Illustrative: a moving company group weighs an overseas licensee#
Illustrative: a fictional private equity-backed group of regional moving companies is considering a license of move records: job scheduling, crew notes, damage claims and truck telematics. The interested developer is incorporated outside the US and wants evaluation samples first.
Counsel screens the record families before any sample goes out. Truck GPS traces are precise location data and, across the group's fleet and years of history, could exceed the relevant threshold, while customer files hold names and home addresses. Counsel also asks for the developer's ownership chain and finds a minority investor whose own owners need checking.
The group narrows the scope to crew notes and damage claim narratives, with customer details removed and locations generalized to metro areas, and drops the telematics. The draft license carries a covered-person representation, an onward-transfer ban, notice duties and a termination right on change of control, and no records move until counsel clears the licensee.
How SourceX handles cross-border licensing questions#
SourceX raises cross-border questions during Rights, the second stage of the SourceX five-step transaction, where the licensee's identity, owners and location are reviewed next to the record families in scope. Raising them before Preparation lets the scope be shaped around the rule instead of trimmed after a licensee appears.
In the Approval step the supplier approves the named licensee, and the SourceX Evidence Packet ties permitted use, the privacy record and release authorization to that licensee. Whether the rule reaches a particular deal is for the supplier's counsel to determine.
Frequently asked questions
Does the rule matter if the licensee is a US company?
The rule targets access by foreign parties, so a license between US companies is generally outside its prohibitions. Ownership links and onward access still count: if a US licensee could pass data to a covered person, or a deal is structured to sidestep the rule, counsel should review it. Onward-transfer terms are sensible either way.
Does the rule cover employee data?
It can. The categories describe data about US persons, not only customers, so HR, payroll and benefits records can hold covered data. Those records are usually kept out of licensing for privacy reasons anyway, but operational records can carry employee identifiers and location traces, such as technician or driver GPS.
How is this different from export controls?
Export controls cover technology, software and technical data; this rule covers access to sensitive personal data and government-related data. One deal can raise both questions. Export-controlled engineering work is handled under separate rules and is outside the scope of SourceX licensing projects.
Do state privacy laws still matter for the same deal?
Yes. The rule sits alongside state privacy laws, which have their own definitions of sale and de-identification, and other federal rules on data brokers and foreign adversaries may also apply. Satisfying one regime does not show compliance with another, so counsel should review the deal against each.
What if the licensee's ownership changes after signing?
The contract should anticipate it. A representation is only true when made, so add a duty to report ownership changes and a right to suspend delivery or terminate if the licensee becomes a covered person. Keep a record of the ownership checks made at signing.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.