• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new u.s. doj rule halts bulk data transfers to adversarial

New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy

You are here: Home / General Cyber Security News / New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy
December 31, 2024

The U.S. Department of Justice (DoJ) has issued a final rule carrying out Executive Order (EO) 14117, which prevents mass transfer of citizens’ personal data to countries of concern such as China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia, and Venezuela.

“This final rule is a crucial step forward in addressing the extraordinary national security threat posed of our adversaries exploiting Americans’ most sensitive personal data,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division.

Cybersecurity

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“This powerful new national-security program is designed to ensure that Americans’ personal data is no longer permitted to be sold to hostile foreign powers, whether through outright purchase or other means of commercial access.”

Back in February 2024, U.S. President Joe Biden signed an executive order to address the national risk posed by unauthorized access to Americans’ sensitive personal and government-related data for malicious activities, such as espionage, influence, kinetic, or cyber operations.

Furthermore, the order noted that the countries of concern can leverage their access to bulk data to develop or refine artificial intelligence and other advanced technologies, as well as purchase such information from commercial data brokers and other companies.

“Countries of concern and covered persons can also exploit this data to collect information on activists, academics, journalists, dissidents, political opponents, or members of nongovernmental organizations or marginalized communities to intimidate them; curb political opposition; limit freedoms of expression, peaceful assembly, or association; or enable other forms of suppression of civil liberties,” the DoJ said.

The rule issued by the DoJ is expected to become effective in 90 days. It identifies certain classes of prohibited, restricted, and exempt transactions; sets bulk thresholds for triggering the rule’s prohibitions and restrictions on covered data transactions involving bulk sensitive personal data; and establishes enforcement mechanisms such as civil and criminal penalties.

Cybersecurity

This covers data spanning six categories: personal identifiers (e.g., Social Security numbers, driver’s license etc.), precise geolocation data, biometric identifiers, human ‘omic (genomic, epigenomic, proteomic, and transcriptomic) data, personal health data, and personal financial data.

However, it bears noting that the rule neither imposes data localization requirements, nor does it prohibit U.S. citizens from conducting medical, scientific, or other research in countries of concern.

“The final rule also does not broadly prohibit U.S. persons from engaging in commercial transactions, including exchanging financial and other data as part of the sale of commercial goods and services with countries of concern or covered persons, or impose measures aimed at a broader decoupling of the substantial consumer, economic, scientific, and trade relationships that the United States has with other countries,” the DoJ said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «chinese apt exploits beyondtrust api key to access u.s. treasury Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents
Next Post: The Tools You Need to Combat Ransomware in 2025Dec 30, 2024Endpoint Security / WebinarDiscover proactive strategies to identify vulnerabilities, block encrypted threats, and prevent ransomware from infiltrating your network. the tools you need to combat ransomware in 2025dec 30,»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.