Changeflow GovPing Courts & Legal 2026 Institute Addresses U.S. Data Security Ris...
Routine Notice Added Final

2026 Institute Addresses U.S. Data Security Risks Under EO 14117

Favicon for www.americanbar.org ABA Legal News
Detected
Email

Summary

The 2026 Privacy and Emerging Technology National Institute highlighted the first U.S. federal outbound national data security rule, enacted under Executive Order 14117, which restricts how certain U.S. data can be transferred by foreign entities. The rule targets 'covered persons' (entities owned or controlled by more than 50% by China, Russia, Iran, North Korea, Cuba, and Venezuela) and defines 'bulk sensitive data' categories including personal identifiers, biometric data, human omic data, personal health data, personal financial data, and precise geolocation data. Thresholds range from 100 U.S. persons for human genomic data to 100,000 for personal identifiers, calculated over a 12-month period, with government-related data having no volume threshold. The regulation uses an aggregation approach to prevent circumvention through incremental transactions.

“The Data Transfer Rule enacted under Executive Order 14117 reflects increasing concern among policymakers that adversarial nations can easily obtain large amounts of sensitive data about U.S. individuals through commercial data markets.”

ABA , verbatim from source
Why this matters

Companies transferring bulk sensitive data to foreign entities should map their transactions over the past 12-month period against the rule's thresholds, particularly for human genomic data (100 U.S. persons) and personal health data categories, where the lowest thresholds apply. Any entity-to-entity data transfers structured to avoid these thresholds may still trigger liability under the aggregation approach — firms should not assume that dividing datasets across subsidiaries avoids coverage.

AI-drafted from the source document, validated against GovPing's analyst note standards . For the primary regulatory language, read the source document .
Published by ABA on americanbar.org . Detected, standardized, and enriched by GovPing. Review our methodology and editorial standards .

About this source

GovPing monitors ABA Legal News for new courts & legal regulatory changes. Every update since tracking began is archived, classified, and available as free RSS or email alerts — 103 changes logged to date.

What changed

The article reports on the Data Transfer Rule enacted under Executive Order 14117, the first U.S. outbound national data security rule focused on restricting foreign adversaries' access to U.S. data at scale. Key provisions include: definitions of 'bulk sensitive data' categories (personal identifiers, biometric identifiers, human omic data, personal health data, personal financial data, precise geolocation data); volume thresholds from 100 U.S. persons (human genomic data) to 100,000 (personal identifiers) over a 12-month period; government-related data with no volume threshold; and an aggregation approach blocking circumvention through incremental transactions.

Affected companies that transfer sensitive data to foreign entities owned or controlled by governments of China, Russia, Iran, North Korea, Cuba, or Venezuela should review their data transfer volumes over the past 12 months against these thresholds, particularly for genomic and health data categories where the thresholds are lowest. Organizations handling government-related data face strictest restrictions with no volume threshold for triggering compliance.

Archived snapshot

Apr 23, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

Science & Technology Law Section



The 2026 Privacy and Emerging Technology National Institute highlighted a notable shift in how policymakers and practitioners are approaching data governance. Speakers emphasized the growing convergence of national security and commercial data practices, particularly in the transfer of sensitive information. The discussions reflected a regulatory approach that focuses less on individual privacy harms and more on systemic risks, specifically, the potential for foreign adversaries to access and exploit U.S. data at scale..

For the first time, the United States federal government has established an outbound national data security rule aimed at restricting how certain types of U.S. data can be transferred by foreign entities. This new regulatory framework marks a shift from traditional data transfer rules toward a broader data security program that emphasizes national security risks. The Data Transfer Rule enacted under Executive Order 14117 reflects increasing concern among policymakers that adversarial nations can easily obtain large amounts of sensitive data about U.S. individuals through commercial data markets.

This rule is not a privacy regulation because it is based on national security concerns rather than individual privacy rights. The issue is not whether someone's privacy has been violated, but whether foreign adversaries can gather large datasets about U.S. people and use that information for intelligence gathering. The rule aims to limit transactions that could enable foreign adversaries to access large amounts of sensitive personal or government-related data. It applies to transactions involving covered persons, which include entities owned or controlled by more than 50% of the governments of specific countries of concern, currently China, Russia, Iran, North Korea, Cuba, and Venezuela.





A key concept in the rule is the definition of “bulk” data, especially “bulk sensitive data.” This includes personal and biometric identifiers, human omic data, personal health data, personal financial data, and precise geolocation data. Regulatory restrictions are triggered when a dataset includes sensitive personal data concerning a specified number of U.S. persons. The thresholds depend on how sensitive the data category is. For example, the rule may apply to datasets involving as few as 100 U.S. persons for human genomic data and up to 100,000 U.S. persons for personal identifiers. Put simply, the more sensitive the data, the lower the threshold needed to trigger the rule. These thresholds are not based on a single data transaction but are calculated from the total transactions over a 12-month period.

Government-related data is treated even more strictly. This category includes location-based data connected to intelligence or law enforcement facilities and personnel-based data about individuals working in the government. Unlike bulk sensitive data, government-related data has no volume threshold since even a single data point can trigger the rule.

The rule also includes safeguards to prevent companies from bypassing this threshold through incremental transactions. The regulations adopt an entity-to-entity or aggregation approach, essentially blocking companies from avoiding the rule simply by dividing data into smaller parts. For example, if the threshold is triggered at 10,000 individual data points, a company cannot spread out the dataset by selling portions to different companies if those companies are ultimately under the same corporate structure.

This new rule prompts broader questions about the operational and economic sustainability of compliance for certain data-driven business models. Companies face difficult decisions ahead as they adapt to the new rules, the challenge will be balancing national security concerns with the realities of commercial data practice.


Endnotes


Author

Jessica Ogu

Jessica Ogu is a law student at The George Washington University Law School with an interest in intellectual property, privacy, and international law, particularly in the governance of emerging technologies and regulatory...

View Bio →


Author

Jessica Ogu


Committees

This content was produced by:

Related Content

Named provisions

Bulk Sensitive Data Thresholds Government-Related Data Aggregation Approach

Get daily alerts for ABA Legal News

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from ABA.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
ABA
Instrument
Notice
Branch
Executive
Legal weight
Non-binding
Stage
Final
Change scope
Minor

Who this affects

Applies to
Technology companies Manufacturers Importers and exporters
Industry sector
5112 Software & Technology
Activity scope
Data transfer compliance Bulk data transactions Cross-border data policy
Geographic scope
United States US

Taxonomy

Primary area
Data Privacy
Operational domain
Compliance
Topics
National Security Export Controls

Get alerts for this source

We'll email you when ABA Legal News publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!