Close Menu
Global News HQ
    What's Hot

    Aptos Double Bottom Pattern Points To $10 Bullish Target – Details

    June 28, 2025

    US multinationals on track for minimum tax reprieve after G7 deal

    June 28, 2025

    Is The Velvet Sundown an AI-generated band?

    June 28, 2025
    Recent Posts
    • Aptos Double Bottom Pattern Points To $10 Bullish Target – Details
    • US multinationals on track for minimum tax reprieve after G7 deal
    • Is The Velvet Sundown an AI-generated band?
    • Lucite Is the Trending Furniture with Lasting Appeal—Designers Reveal Top Styling Tips
    • Why Investing Abroad Could Pay Off
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • Aptos Double Bottom Pattern Points To $10 Bullish Target – Details
    • US multinationals on track for minimum tax reprieve after G7 deal
    • Is The Velvet Sundown an AI-generated band?
    • Lucite Is the Trending Furniture with Lasting Appeal—Designers Reveal Top Styling Tips
    • Why Investing Abroad Could Pay Off
    • NYC real estate reels from primary, while big deals emerged
    • How to Master Leadership and Prevent ‘Owner Bottleneck’ From Hindering Your Team
    • A practical guide to being an ally in the workplace
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Legal - Transferring U.S. Data Overseas? Consider Whether the DOJ’s Bulk Data Regulations or PADFA May Apply to Your Organization
    Legal

    Transferring U.S. Data Overseas? Consider Whether the DOJ’s Bulk Data Regulations or PADFA May Apply to Your Organization

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Transferring U.S. Data Overseas? Consider Whether the DOJ’s Bulk Data Regulations or PADFA May Apply to Your Organization
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Covered Data The Bulk Data Regs regulate covered transactions involving government-related data and bulk sensitive personal data.

    Government-Related Data
    (1) Any precise geolocation data, regardless of volume, for any location enumerated on the “Government-Related Location Data List” in the Bulk Data Regs.
    (2) Any sensitive personal data, regardless of volume, that a transacting party markets as linked or linkable to current or recent former employees or contractors, or former senior officials, of the United States Government, including the military and Intelligence Community.

    Sensitive Personal Data
    The term sensitive personal data means covered personal identifiers, precise geolocation data, biometric identifiers, human ‘omic data, personal health data, personal financial data, or any combination thereof.

    Covered Personal Identifiers
    The term covered personal identifiers means any listed identifier: (1) In combination with any other listed identifier; or (2) In combination with other data that is disclosed by a transacting party pursuant to the transaction such that the listed identifier is linked or linkable to other listed identifiers or to other sensitive personal data. (b) Exclusion. The term covered personal identifiers excludes: (1) Demographic or contact data that is linked only to other demographic or contact data (such as first and last name, birthplace, ZIP code, residential street or postal address, phone number, and email address and similar public account identifiers); and (2) A network-based identifier, account-authentication data, or call-detail data that is linked only to other network-based identifier, account-authentication data, or call detail data as necessary for the provision of telecommunications, networking, or similar service.

    Listed Identifier
    The term listed identifier means any piece of data in any of the following data fields: (a) Full or truncated government identification or account number (such as a Social Security number, driver’s license or State identification number, passport number, or Alien Registration Number); (b) Full financial account numbers or personal identification numbers associated with a financial institution or financial-services company; (c) Device-based or hardware-based identifier (such as International Mobile Equipment Identity (“IMEI”), Media Access Control (“MAC”) address, or Subscriber Identity Module (“SIM”) card number); (d) Demographic or contact data (such as first and last name, birth date, birthplace, ZIP code, residential street or postal address, phone number, email address, or similar public account identifiers); (e) Advertising identifier (such as Google Advertising ID, Apple ID for Advertisers, or other mobile advertising ID (“MAID”)); (f) Account-authentication data (such as account username, account password, or an answer to security questions); (g) Network-based identifier (such as Internet Protocol (“IP”) address or cookie data); or (h) Call-detail data (such as Customer Proprietary Network Information (“CPNI”)).

    Personal Financial Data
    The term personal financial data means data about an individual’s credit, charge, or debit card, or bank account, including purchases and payment history; data in a bank, credit, or other financial statement, including assets, liabilities, debts, or trades in a securities portfolio; or data in a credit report or in a “consumer report” (as defined in 15 U.S.C. 1681a(d)).

    Personal Health Data
    The term personal health data means health information that indicates, reveals, or describes the past, present, or future physical or mental health or condition of an individual; the provision of healthcare to an individual; or the past, present, or future payment for the provision of healthcare to an individual. This term includes basic physical measurements and health attributes (such as bodily functions, height and weight, vital signs, symptoms, and allergies); social, psychological, behavioral, and medical diagnostic, intervention, and treatment history; test results; logs of exercise habits; immunization data; data on reproductive and sexual health; and data on the use or purchase of prescribed medications.

    Human ‘Omic Data
    The term human ‘omic data means human genomic data, human epigenomic data, human proteomic data, and human transcriptomic data, but excludes pathogen-specific data embedded in human ‘omic data sets.

    Bulk
    The term bulk means any amount of sensitive personal data that meets or exceeds the following thresholds at any point in the preceding 12 months, whether through a single covered data transaction or aggregated across covered data transactions involving the same U.S. person and the same foreign person or covered person: (a) Human ‘omic data collected about or maintained on more than 1,000 U.S. persons, or, in the case of human genomic data, more than 100 U.S. persons; (b) Biometric identifiers collected about or maintained on more than 1,000 U.S. persons; (c) Precise geolocation data collected about or maintained on more than 1,000 U.S. devices; (d) Personal health data collected about or maintained on more than 10,000 U.S. persons; (e) Personal financial data collected about or maintained on more than 10,000 U.S. persons; (f) Covered personal identifiers collected about or maintained on more than 100,000 U.S. persons; or (g) Combined data, meaning any collection or set of data that contains more than one of the categories in paragraphs (a) through (g) of this section, or that contains any listed identifier linked to categories in paragraphs (a) through (e) of this section, where any individual data type meets the threshold number of persons or devices collected or maintained in the aggregate for the lowest number of U.S. persons or U.S. devices in that category of data.

    Exclusions
    The term sensitive personal data, and each of the categories of sensitive personal data, excludes: (1) Public or nonpublic data that does not relate to an individual, including such data that meets the definition of a “trade secret” (as defined in 18 U.S.C. 1839(3)) or “proprietary information” (as defined in 50 U.S.C. 1708(d)(7)); (2) Data that is, at the time of the transaction, lawfully available to the public from a Federal, State, or local government record (such as court records) or in widely distributed media (such as sources that are generally available to the public through unrestricted and open-access repositories); (3) Personal communications; and (4) Information or informational materials and ordinarily associated metadata or metadata reasonably necessary to enable the transmission or dissemination of such information or informational materials.

    (5) Personally identifiable sensitive data -The term `personally identifiable sensitive data” means any sensitive data that identifies or is linked or reasonably linkable, alone or in combination with other data, to an individual or a device that identifies or is linked or reasonably linkable to an individual. This is much broader than the Bulk Data Regs, in part because it does not require a certain volume of data.

    (7) Sensitive data. — The term “sensitive data” includes the following:
    • (A) A government-issued identifier, such as a Social Security number, passport number, or driver’s license number.
    • (B) Any information that describes or reveals the past, present, or future physical health, mental health, disability, diagnosis, or healthcare condition or treatment of an individual.
    • (C) A financial account number, debit card number, credit card number, or information that describes or reveals the income level or bank account balances of an individual.
    • (D) Biometric information.
    • (E) Genetic information.
    • (F) Precise geolocation information.
    • (G) An individual’s private communications such as voicemails, emails, texts, direct messages, mail, voice communications, and video communications, or information identifying the parties to such communications or pertaining to the transmission of such communications, including telephone numbers called, telephone numbers from which calls were placed, the time calls were made, call duration, and location information of the parties to the call.
    • (H) Account or device log-in credentials, or security or access codes for an account or device.
    • (I) Information identifying the sexual behavior of an individual.
    • (J) Calendar information, address book information, phone or text logs, photos, audio recordings, or videos, maintained for private use by an individual, regardless of whether such information is stored on the individual’s device or is accessible from that device and is backed up in a separate location.
    • (K) A photograph, film, video recording, or other similar medium that shows the naked or undergarment-clad private area of an individual.
    • (L) Information revealing the video content requested or selected by an individual.
    • (M) Information about an individual under the age of 17.
    • (O) Information identifying an individual’s online activities over time and across websites or online services.
    • (P) Information that reveals the status of an individual as a member of the Armed Forces.
    (Q) Any other data that a data broker sells, licenses, rents, trades, transfers, releases, discloses, provides access to, or otherwise makes available to a foreign adversary country, or entity that is controlled by a foreign adversary, for the purpose of identifying the types of data listed in subparagraphs (A) through (P).

    Covered data recipients The term covered person means: (1) A foreign person that is an entity that is 50% or more owned, directly or indirectly, individually or in the aggregate, by one or more countries of concern or persons described in paragraph (a)(2) of this section; or that is organized or chartered under the laws of, or has its principal place of business in, a country of concern; (2) A foreign person that is an entity that is 50% or more owned, directly or indirectly, individually or in the aggregate, by one or more persons described in paragraphs (a)(1), (3), (4), or (5) of this section; (3) A foreign person that is an individual who is an employee or contractor of a country of concern or of an entity described in paragraphs (a)(1), (2), or (5) of this section; (4) A foreign person that is an individual who is primarily a resident in the territorial jurisdiction of a country of concern; or (5) Any person, wherever located, determined by the Attorney General: (i) To be, to have been, or to be likely to become owned or controlled by or subject to the jurisdiction or direction of a country of concern or covered person; (ii) To act, to have acted or purported to act, or to be likely to act for or on behalf of a country of concern or covered person; or (iii) To have knowingly caused or directed, or to be likely to knowingly cause or direct a violation of this part.

    Countries of concern = China (incl. Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela.

    “Person” means an individual or entity.

    “Foreign person” means any person that is not a U.S. person.

    “U.S. person” means any United States citizen, national, or lawful permanent resident; any individual admitted to the United States as a refugee under 8 U.S.C. 1157 or granted asylum under 8 U.S.C. 1158; any entity organized solely under the laws of the United States or any jurisdiction within the United States (including foreign branches); or any person in the United States.

    “Foreign adversary” = China, Russia, Iran, and North Korea.

    The term “controlled by a foreign adversary” means, with respect to an individual or entity, that such individual or entity is– (A) a foreign person that is domiciled in, is headquartered in, has its principal place of business in, or is organized under the laws of a foreign adversary country; (B) an entity with respect to which a foreign person or combination of foreign persons described in subparagraph (A) directly or indirectly own at least a 20 percent stake; or (C) a person subject to the direction or control of a foreign person or entity described in subparagraph (A) or (B).

    Notable Exemptions The Final Rule provides a number of exemptions:
    • Personal communications;
    • Information or informational materials;
    • Travel;
    • Official business of the U.S. government;
    • Transactions “ordinarily incident to and part of the provision of financial services”;
    • Corporate group transactions;
    • “Transactions required or authorized by Federal law or international agreements, or necessary for compliance with Federal law”;
    • Investment agreements subject to a CFIUS action”;
    • Transactions “ordinarily incident to and part of the provision of telecommunications services”;
    • “Drug, biological product, and medical device authorizations”; and
    • “Other clinical investigations and post-marketing surveillance data.” (B) Exclusion.–The term “data broker” does not include an entity to the extent such entity–(i) is transmitting data of a United States individual, including communications of such an individual, at the request or direction of such individual, (ii) is providing, maintaining, or offering a product or service with respect to which personally identifiable sensitive data, or access to such data, is not the product or service; (iii) is reporting or publishing news or information that concerns local, national, or international events or other matters of public interest; (iv) is reporting, publishing, or otherwise making available news or information that is available to the general public–(I) including information from–(aa) a book, magazine, telephone book, or online directory; (bb) a motion picture; (cc) a television, internet, or radio program; (dd) the news media; or (ee) an internet site that is available to the general public on an unrestricted basis; and (II) not including an obscene visual depiction (as such term is used in section 1460 of title 18, United States Code); or (v) is acting as a service provider.

    (8) Service provider.–The term “service provider” means an entity that– (A) collects, processes, or transfers data on behalf of, and at the direction of– (i) an individual or entity that is not a foreign adversary country or controlled by a foreign adversary; or (ii) a Federal, State, Tribal, territorial, or local government entity; and (B) receives data from or on behalf of an individual or entity described in subparagraph (A)(i) or a Federal, State, Tribal, territorial, or local government entity.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous Article10 Food Allergy Safety Tips for Kids at Home, School, or While Traveling
    Next Article Automaker Pleads Guilty and Agrees to $1.6 Billion in Payouts

    Related Posts

    Lawyer Calls Judge ‘Honey’ in Viral Moment | Law.com

    June 28, 2025

    Microsoft Sued in Manhattan Federal Court for Allegedly Using Pirated Material to Train AI Models | Law.com

    June 28, 2025

    Trump Thinks Reporting The Truth Is A Punishable Offense – See Also – Above the Law

    June 28, 2025

    State Appellate Court Revives Data Breach Action Against Candy Company | Law.com

    June 28, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Cryptocurrency & Blockchain
    3 Mins Read

    Aptos Double Bottom Pattern Points To $10 Bullish Target – Details

    In line with the broader crypto market, Aptos (APT) experienced a remarkable price upswing in…

    US multinationals on track for minimum tax reprieve after G7 deal

    June 28, 2025

    Is The Velvet Sundown an AI-generated band?

    June 28, 2025

    Lucite Is the Trending Furniture with Lasting Appeal—Designers Reveal Top Styling Tips

    June 28, 2025
    Top
    Cryptocurrency & Blockchain
    3 Mins Read

    Aptos Double Bottom Pattern Points To $10 Bullish Target – Details

    In line with the broader crypto market, Aptos (APT) experienced a remarkable price upswing in…

    US multinationals on track for minimum tax reprieve after G7 deal

    June 28, 2025

    Is The Velvet Sundown an AI-generated band?

    June 28, 2025
    Our Picks
    Cryptocurrency & Blockchain
    3 Mins Read

    Aptos Double Bottom Pattern Points To $10 Bullish Target – Details

    In line with the broader crypto market, Aptos (APT) experienced a remarkable price upswing in…

    Finance & Investment
    5 Mins Read

    US multinationals on track for minimum tax reprieve after G7 deal

    The world’s leading economies have agreed a deal to spare the US’s largest companies from…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version