United States of America: Audit, compliance and reporting requirements in Department of Justice rule on access to Americans’ bulk sensitive personal data and government-related data by countries of concern enter into force

Description

Audit, compliance and reporting requirements in Department of Justice rule on access to Americans’ bulk sensitive personal data and government-related data by countries of concern enter into force

On 6 October 2025, the Department of Justice rule on access to Americans’ bulk sensitive personal data and government-related data by countries of concern including audit and reporting requirements enter into force. The rule addresses the processing of sensitive US personal and government-related data by foreign adversaries, specifically by six countries of concern, including China, Cuba, Iran, North Korea, Russia, and Venezuela. The rule applies to entities handling government-related or bulk-sensitive personal data and mandates risk-based due diligence measures, including verification of data flows, transaction parties, and data end-use. It also introduces recordkeeping obligations for at least 10 years and requires independent audits assessing compliance with security requirements. The rule incorporates risk-based flexibility, allowing streamlined measures for lower-risk transactions and permitting companies to use existing audit reports for compliance. The audit process must cover transaction records, security measures, and compliance effectiveness, with reports detailing vulnerabilities and recommended improvements.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cross-border data transfer regulation
Regulated Economic Activity
cross-cutting
Implementation Level
national
Government Branch
executive
Government Body
other regulatory body

Complete timeline of this policy change

Hide details
2024-03-05
in consultation

On 5 March 2024, the Department of Justice (DOJ) opened the public consultation on the proposed Rul…

2024-04-19
in consultation

On 19 April 2024, the Department of Justice (DOJ) closed the public consultation on the proposed Ru…

2024-10-21
under deliberation

On 21 October 2024, the United States Department of Justice (DOJ) issued a Notice of Proposed Rulem…

2024-10-29
in consultation

On 29 October 2024, the US Department of Justice (DOJ) opened a consultation on the Notice of Propo…

2024-11-30
processing consultation

On 30 November 2024, the US Department of Justice (DOJ) closed the consultation on the Notice of Pr…

2024-12-26
adopted

On 26 December 2024, the US Department of Justice (DOJ) adopted the final Rule on Access to America…

2025-04-08
in force

On 8 April 2025, the US Department of Justice’s (DOJ) Rule on Access to Americans' Bulk Sensitive P…

2025-07-08
in force

On 8 July 2025, the US Department of Justice (DOJ) began enforcing the rule on access to Americans’…

2025-10-06
in force

On 6 October 2025, the Department of Justice rule on access to Americans’ bulk sensitive personal d…