Rights and contracts
DOJ bulk sensitive data rule: does it apply to licensing data to AI developers?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
The DOJ bulk sensitive data rule can apply to licensing data to AI developers, because licensing access to data counts as data brokerage under the rule. It matters when a package holds government-related data or covered sensitive personal data at bulk volumes and the recipient is a covered person or another foreign party. Screen category, volume and recipient first.
Key takeaways
- The rule treats licensing access to data as data brokerage, so data licensing sits squarely within its scope.
- The rule matters only for covered categories of sensitive personal data and government-related data, measured against bulk thresholds.
- The prohibitions target deals with countries of concern and covered persons, so buyer diligence must reach ownership, location and everyone who will access the records.
- Licenses to foreign recipients outside the countries of concern generally need contract terms against onward transfer.
- Removing covered categories outright is more reliable than masking, because the rule can treat de-identified or encrypted data as covered.
What is the DOJ bulk sensitive data rule?#
The DOJ bulk sensitive data rule is a national security regulation, administered by the Justice Department's National Security Division as the Data Security Program, that limits transactions giving certain foreign countries and people access to Americans' sensitive personal data and to government-related data. It applies to US persons, including US companies, and it reaches commercial deals that most privacy laws treat as routine.
Some transaction types are prohibited outright when they involve a country of concern or a covered person. Others, such as certain vendor, employment and investment agreements, are restricted and allowed only when specified security requirements are met. Violations can carry civil and criminal penalties.
The rule differs from state privacy laws in its purpose. It is not about consumer choice or notice; it is about keeping large volumes of sensitive data out of the reach of foreign adversaries, which is why consent from the people in the data does not resolve it.
Does licensing data count as data brokerage?#
Licensing data generally counts as data brokerage under the rule, because the definition covers selling data, licensing access to data and similar commercial transactions where the recipient did not collect the data directly from the people it describes. A license of operational records to an AI developer fits that description.
That does not make every license a problem. The prohibitions bite only when three conditions line up: the data falls into a covered category, the volume reaches a bulk threshold (government-related data has none), and the counterparty is a country of concern or a covered person. Licenses of covered data to other foreign recipients are allowed but carry contract duties. Failing any one of the first two screens usually takes a package outside the rule's data brokerage provisions.
A decision tree for a licensing deal#
A decision tree for the rule moves from the data to the recipient to the contract. Work through it with counsel for each package, since the same company can hold one clean package and another that needs restructuring.
Keep a written record of each answer. If a question arises later, the record shows that the screen happened before delivery, which is the point at which it could still change the outcome.
- Step one: does the package contain government-related data, such as precise location data for sensitive government sites on the government's published list, or data described or marketed as linked to government personnel? If so, stop and involve counsel, because that category applies without a bulk threshold.
- Step two: does it contain covered sensitive personal data, such as precise geolocation, biometric identifiers, health, financial or genomic data, or covered personal identifiers? If not, the rule is unlikely to reach the package.
- Step three: do volumes reach the bulk threshold for any category, counted across the deal and related transactions over the rule's lookback period? If not, the prohibitions generally do not apply.
- Step four: is the recipient a country of concern or a covered person, for example an entity owned by, organized in or based in a country of concern? If so, the license is likely prohibited. If the buyer would route access through affiliates, staff or contractors who fit those descriptions, stop and involve counsel.
- Step five: is the recipient a foreign person outside those categories? If so, the contract generally needs a clause barring onward transfer to countries of concern and covered persons.
- Step six: is the recipient a US person with no such links? Document the diligence and keep onward-transfer limits in the license anyway.
Which operational records can contain covered data?#
Operational records can contain covered data in places a general counsel might not expect, especially in field service, logistics and HR systems. The categories were written with consumer data in mind, but telematics, timeclocks and payroll create the same data types inside ordinary businesses.
Combination is the subtle risk. A device ID or account number may be harmless alone and covered once it sits next to other identifying fields, so review identifiers as sets rather than one column at a time.
| Covered category | Where it appears in operational records | Preparation response |
|---|---|---|
| Precise geolocation | Telematics from Samsara or ELDs, technician GPS, proof-of-delivery coordinates | Remove coordinates or coarsen to city or region |
| Biometric identifiers | Fingerprint templates from timeclocks, face or voice templates enrolled in verification systems | Exclude |
| Personal financial data | Payment details, credit applications, payroll records | Exclude or remove the fields |
| Personal health data | Workers' compensation notes, safety incident reports, accommodation requests | Exclude or remove the fields |
| Covered personal identifiers | Government ID numbers, account numbers and device IDs combined with other identifying data | Remove the identifiers |
| Government-related data | Job or delivery coordinates at sensitive government sites; records described as linked to government personnel | Flag for counsel; often exclude |
Who is the recipient, really?#
The recipient that matters is everyone who can access the data, not only the company that signs the license. AI developers routinely use contractors for annotation, evaluation and engineering, and some operate affiliates or teams abroad, so the diligence questions have to reach past the signature block.
| Recipient situation | General position under the rule | What to check |
|---|---|---|
| US developer with no ownership, staffing or contractor links to a country of concern | Generally outside the prohibitions | Ownership, affiliates and contractor locations |
| US developer with affiliates, staff or contractors in a country of concern | Your transaction may still be permitted, but routing access to covered persons can raise evasion and knowing-direction questions, and the buyer's own staffing and vendor deals may be restricted | Access controls, where work is performed and contract limits on who may see the records |
| Foreign developer outside the countries of concern | Generally permitted with onward-transfer terms | The required contract clause and any reporting duties |
| Entity owned, organized or based in a country of concern | Data brokerage generally prohibited | Do not proceed without counsel |
| Annotation or evaluation vendor used by the buyer | Assessed by where it is and who controls it | Subcontracting limits and approval rights in the license |
Illustrative: a 3PL screens records and recipients#
Illustrative: a fictional third-party logistics company runs three warehouses and a small delivery fleet. It wants to license WMS exception records, dispatch notes and proof-of-delivery records to a US model developer building a warehouse operations assistant.
Counsel's screen finds three issues. Proof-of-delivery coordinates and telematics pings are precise geolocation, warehouse timeclocks store enrolled employee fingerprints, and some deliveries go to a military installation, so those coordinates are checked against the government's published list of sensitive locations. The company removes all coordinates and keeps only city-level locations, excludes timeclock data and drops the installation deliveries from the package.
Buyer diligence then turns up an annotation vendor whose ownership the developer cannot confirm. The license limits access to the developer's staff and vendors approved in writing, bars onward transfer to countries of concern and covered persons, and requires notice before any new vendor sees the records. The 3PL files the screen, the buyer's representations and the approved vendor list with the deal.
How SourceX applies the rule in a transaction#
SourceX screens for the rule in the Rights step of the SourceX five-step transaction, flagging covered categories and asking buyers about ownership, affiliates and contractor locations. In Preparation, covered fields such as coordinates and identifiers are removed rather than masked, because the rule can treat de-identified data as covered.
The SourceX Evidence Packet records the categories excluded, the recipient information provided and the permitted use, alongside release authorization. The supplier and its counsel decide whether the rule applies; SourceX keeps the record that supports the decision.
Frequently asked questions
Does anonymizing data take it outside the rule?
Do not rely on it. The rule's definitions can treat anonymized, pseudonymized, de-identified or encrypted data as covered, which is unlike most state privacy laws. Removing covered fields, such as coordinates and identifiers, is the more dependable step. Counsel can confirm how the definitions apply to your package.
What are the bulk thresholds?
The thresholds differ by data category and are measured by the number of US persons or devices involved, aggregated across related transactions over a lookback period. Some categories have low thresholds, and government-related data has none. Check the current text with counsel rather than relying on summaries.
Which countries are countries of concern?
The rule names a short list of countries of concern, and the list can change. Covered persons include entities owned, organized or based in those countries, people primarily resident there, and individuals or entities the Justice Department designates. Check the current list and designations before signing.
Is there another federal law to check?
Yes. A separate federal statute restricts data brokers from transferring Americans' sensitive data to foreign adversary countries and entities they control, and the FTC enforces it. Its definitions differ from the DOJ rule's, so counsel should review both for any package that contains personal data.
Do we need a formal compliance program?
Companies engaged in restricted transactions generally need a written compliance program, security requirements, recordkeeping and audits. A company that only licenses packages free of covered data has lighter obligations, but documenting the screen for each package is still prudent.
Related resources
- IndustryLegal data
- QuestionDo AI labs buy legal documents?
- InsightDo you need a DPA when licensing de-identified data?
- InsightIs an AI data buyer a controller, a processor or a third party?
- InsightData licensing partner vs law firm vs doing it yourself
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.