Private equity and portfolios
The DOJ bulk data rule: what portfolio companies licensing data must check
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
The DOJ bulk data rule restricts transactions that could give countries of concern, or covered persons linked to them, access to bulk US sensitive personal data or government-related data. Before licensing records, a portfolio company should screen data categories, volumes, counterparty and transaction type together. Many B2B licenses to US buyers end up documented and contract-protected, not blocked.
Key takeaways
- The rule is a national security rule, so consent and privacy compliance do not answer it on their own.
- Applicability turns on data category, volume, counterparty and transaction type, read together.
- Licensing access to data the recipient did not collect can fall within the rule's description of data brokerage.
- Removing names may not take records out of scope; read the definitions rather than assume.
- Contract terms on onward transfer and access by covered persons are the usual practical controls.
What is the DOJ bulk data rule?#
The DOJ bulk data rule is a Justice Department regulation, administered as the Data Security Program, that prohibits or restricts certain transactions giving countries of concern or covered persons access to bulk US sensitive personal data or US government-related data. It is a national security rule, so it applies alongside privacy laws rather than through them.
For portfolio companies, the rule matters because licensing records is a commercial transaction in data. Even when the buyer is a US company, the rule's concepts of covered persons, data brokerage and onward transfer mean a license should be screened before signing.
The rule's definitions, thresholds and list of countries of concern are specific and can change. Counsel should work from the current rule text and Justice Department guidance rather than secondhand summaries, including this one.
The four-part applicability checklist#
The applicability checklist has four parts that must be read together: what kind of data, how much of it, who receives or can reach it, and what kind of transaction it is. A license sits outside the prohibited and restricted categories only when the analysis of all four supports that conclusion.
The rule's categories of sensitive personal data are covered personal identifiers, precise geolocation data, biometric identifiers, human 'omic data, personal health data and personal financial data. Government-related data is a separate category. Covered persons, as the rule defines them, are foreign persons such as entities organized or principally based in a country of concern, entities owned above a threshold the rule sets by countries of concern or covered persons, individuals who work for those entities or primarily reside in a country of concern, and anyone the Justice Department designates. The countries of concern are a short list named in the rule, including China and Russia.
- Treat government-related data as its own check, because the rule covers it regardless of volume.
- Count by category, not by system: a CRM and a telematics platform may each fall below a threshold while together describing far more people.
- Record the answer to every question, including the ones that came back clean.
| Question | What to check | Where the answer usually sits |
|---|---|---|
| Data category | Whether records include a category of sensitive personal data the rule defines, or government-related data | Field inventory and free-text review for each record family |
| Volume | Whether the number of US persons covered meets the rule's bulk threshold for that category over its lookback period | Counts of unique individuals in each system, by category |
| Counterparty | Whether the buyer, its owners, staff, contractors or hosts are a country of concern or covered person | Ownership disclosures, buyer questionnaires, subprocessor lists |
| Transaction type | Whether the deal is data brokerage, a vendor, employment or investment agreement, or exempt | The license structure and how the buyer accesses the records |
Why many B2B operational-record licenses are screened, not blocked#
Many B2B operational-record licenses are screened rather than blocked because the records center on business workflows, not on sensitive facts about individuals. A support ticket about software configuration, a dispatch note about a failed compressor or an order exception about a damaged pallet carries little of what the rule targets once preparation removes personal details.
Licensees for these records are also often US companies with no ownership or control link to a country of concern. In that situation the screen usually ends with documented answers and contract protections rather than a prohibition.
The screen still has to be done and recorded, because the risk sits in the details: a CRM with large contact lists, telematics with precise locations or a buyer whose contractors work abroad.
The data brokerage point that catches licensors#
The data brokerage concept catches licensors because it is broad: as generally described, it covers selling data or licensing access to data where the recipient did not collect it directly from the individuals involved. A license of operational records to a model developer can fit that description.
The rule also addresses data brokerage with foreign persons who are not themselves covered persons, including contract terms meant to stop onward transfer to countries of concern or covered persons and reporting of known violations. Counsel should confirm whether those provisions reach a given license, especially when the buyer or an affiliate is organized outside the United States.
De-identification helps but may not end the analysis. The rule's definition of bulk US sensitive personal data applies regardless of whether the data is anonymized, pseudonymized, de-identified or encrypted, so removing obvious identifiers does not by itself take records out of scope. Run the screen on the prepared dataset and on what the buyer could link it to.
Records portfolio companies hold that need a closer look#
Records that need a closer look are the ones where personal details are the substance rather than incidental noise. Operators and software companies often hold more of these than leadership assumes, usually in systems nobody thinks of as personal data stores.
| Record family | Why it may be in scope | Typical handling |
|---|---|---|
| Fleet telematics and route history | Precise locations of drivers, vehicles and customer sites | Exclude, coarsen or aggregate before licensing |
| CRM contact histories | Large volumes of personal identifiers tied to accounts | Remove identifiers and count any individuals that remain |
| HR, payroll and benefits records | Financial and health-related details about employees | Usually excluded from operational licenses |
| Call recordings | Voiceprints can count as biometric identifiers, and recordings carry names and account details | Transcribe and de-identify; confirm with counsel before licensing audio |
| Billing and payment records | Personal financial information | Exclude card and account details and keep business-level fields |
| Work orders at government or defense sites | Possible government-related data | Exclude those sites and confirm with counsel |
What to add to the license#
The license is where the screen's conclusions become enforceable. Even when a deal is clearly outside the prohibited categories, contract terms show that the supplier considered the rule and limit what the buyer can do next.
- Buyer representations about its ownership, control and location, and those of its affiliates.
- A covenant not to transfer, resell or give access to the licensed records to a country of concern or covered person.
- Limits on access by employees, contractors and hosting providers located in or controlled from countries of concern.
- Notice of any change in the buyer's ownership that could make it a covered person.
- Cooperation with compliance questions, plus suspension and termination rights if a representation stops being true.
Illustrative: a 3PL portfolio company screening a license#
Illustrative: a fictional third-party logistics company owned by a mid-market sponsor plans to license warehouse exception records and carrier communication histories from its WMS, TMS and help desk to a US model developer. The company also runs Samsara telematics across its fleet.
Sponsor counsel runs the four-part checklist. Telematics and route history are excluded because they carry precise locations. Carrier email threads are de-identified, and the remaining contact identifiers are counted and found to be limited. The buyer confirms it is US-owned but discloses an annotation contractor with staff outside the United States.
The license adds a prohibition on access by any covered person, a requirement to disclose subprocessors and a termination right if ownership changes. The company files the completed screen with the deal record, and the license proceeds.
Where the screen sits in a SourceX transaction#
The screen sits in the Rights and Preparation steps of the SourceX five-step transaction. The Rights step records the record families, the counterparty and the intended transaction so the supplier's counsel can run the analysis, and the Preparation step removes or coarsens the fields the screen flags.
The results are kept in the SourceX Evidence Packet as part of the privacy record and permitted use, alongside the supplier's release authorization. SourceX does not decide whether a law applies to a given deal; that judgment stays with the supplier's counsel.
Frequently asked questions
Does the rule matter if the buyer is a US company?
It can. A US buyer may have foreign owners, affiliates, employees or contractors, and the rule looks at who can access the data, not only where the buyer is incorporated. Screening a US buyer is usually quick, but the answers should still be documented.
Is de-identified data outside the rule?
Not automatically. The rule does not treat removing names as a safe harbor on its own, so counsel should assess the prepared dataset, the volumes that remain and what the buyer could link it with. Strong preparation still reduces risk and often narrows what needs analysis.
How does the rule interact with state privacy laws?
They run in parallel. State privacy laws such as the CCPA govern notices, consumer rights and sales of personal information, while the DOJ rule addresses national security access. A license may need to satisfy both, and compliance with one does not show compliance with the other.
Are there other federal rules on sharing data with foreign adversaries?
Yes. A separate statute, the Protecting Americans' Data from Foreign Adversaries Act, enforced by the FTC, restricts data brokers from making certain sensitive data about US individuals available to foreign adversary countries or entities they control. Its definitions differ from the DOJ rule's, so counsel may need to check both for the same license.
Who should own the screen in a portfolio?
Usually the portfolio company's counsel runs it with support from sponsor counsel, because the company holds the records and signs the license. A sponsor can supply a standard checklist and contract language so every company screens the same way.
Related resources
- QuestionDo AI labs buy legal documents?
- IndustryLegal data
- QuestionDo AI companies buy private business data?
- InsightHow do I de-identify contracts and legal documents for AI training?
- InsightIndemnification in data licenses: who covers which claims
- InsightDocuments to gather before a data licensing review
See if your company qualifies
A short company assessment. No data uploads are needed.