Status as of August 16, 2026: the Department of Justice’s Data Security Program (DSP), codified at 28 CFR Part 202, has been fully in force for over ten months. The rule implements Executive Order 14117, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern,” signed February 28, 2024. The DOJ National Security Division’s final rule was published in the Federal Register on January 8, 2025, took effect April 8, 2025, and its due-diligence, audit, and reporting obligations became enforceable on a delayed compliance date of October 6, 2025. It is not an export-control regime and it is not run by the Bureau of Industry and Security or the State Department’s Directorate of Defense Trade Controls — it is a standalone national-security data-transfer control, and it reaches university research operations in ways that ITAR and EAR compliance programs do not automatically cover.
What the Data Security Program actually restricts
The DSP does not restrict research collaboration in general, and it is not a data-privacy law like GDPR. It restricts a defined set of covered data transactions: data brokerage, vendor agreements, employment agreements, and investment agreements that would give a “country of concern” or a “covered person” access to bulk U.S. sensitive personal data or U.S. government-related data. The rule designates six countries of concern — China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela — and extends to entities and individuals substantially owned by or acting on behalf of those governments, wherever they are physically located. The current designations sit in 28 CFR 202.601 and are DOJ’s to amend, so this list should be checked against the current regulatory text rather than treated as fixed.
“Sensitive personal data” covers six categories: precise geolocation data, biometric identifiers, human genomic (and other human ‘omic) data, personal health data, personal financial data, and certain covered personal identifiers. Each category has its own numeric “bulk” threshold, set out in the rule’s definitions at 28 CFR 202.205 — DOJ deliberately set some thresholds low (human genomic data in particular) because of the re-identification risk that category carries even in small volumes. A transaction only needs to clear one category’s threshold in a 12-month period to be “bulk,” and DOJ has said aggregation across a research program’s combined activity counts, not just a single transfer.
Yes, a university is a “U.S. person” in scope
There is no blanket academic or research exemption in the DSP. Any “U.S. person” — which includes universities, their component units, and their employees — is covered when it engages in a covered data transaction with a country of concern or covered person. During the rulemaking, at least one commenter identified as an academic medical center, and separately a commenter asked DOJ to exempt nonclinical research data where research subjects had already consented to disclosure. DOJ rejected that request. Participant consent under an IRB-approved protocol governs whether you may collect and use the data; it does not by itself authorize transferring bulk sensitive data to a country of concern or covered person under the DSP. Those are two separate compliance questions, and conflating them is one of the more consequential mistakes an RA office can make right now.
Prohibited transactions vs. restricted transactions
Prohibited transactions are banned outright — principally data brokerage transactions with a country of concern or covered person, and any transaction involving bulk human genomic data or human biospecimens (from which genomic data could be derived) with a country of concern or covered person, regardless of the transaction type. There is no compliance pathway that makes a prohibited transaction permissible; the only options are not doing it, or seeking a specific license from DOJ.
Restricted transactions — vendor agreements, employment agreements, and investment agreements that involve bulk sensitive data but don’t rise to data brokerage — are permitted, but only if the U.S. person complies with security requirements published by the Cybersecurity and Infrastructure Security Agency (CISA), plus the DSP’s own affirmative due-diligence, annual certification, and (for larger volumes) independent audit obligations. A cloud-hosting agreement, a data-processing subcontract, or an employment relationship with a covered person that touches bulk sensitive data can all fall into this category depending on the facts.
The exemption that actually matters for sponsored research
The rule exempts transactions conducted pursuant to an agreement with the U.S. government, including grants and contracts for activities such as outbreak and pandemic prevention, preparedness, and response. That exemption is real and useful for a meaningful slice of federally sponsored research, but it is narrower than it sounds: it covers the government-agreement relationship itself, not every downstream data transfer a grant-funded project happens to make with a foreign collaborator. A federally funded study that separately enters into a data-sharing agreement, consortium agreement, or vendor contract involving a country of concern still has to evaluate that agreement against the DSP on its own terms.
Where this actually shows up in research administration
- Data-sharing agreements (DSAs) with a co-investigator, institution, or biobank located in (or majority-owned from) a country of concern, where the shared dataset includes genomic, health, financial, biometric, or precise-location data at bulk volume.
- Material Transfer Agreements that move human biospecimens capable of yielding genomic data — these sit closest to the DSP’s flat prohibition on genomic-data transactions with covered persons and warrant the earliest legal review in any agreement-drafting queue.
- Consortium agreements and multi-site study agreements where a subawardee or partner institution is a covered person, even if the prime award itself is domestic.
- Cloud, SaaS, and data-processing vendor agreements where the vendor or its subprocessors have ownership or operational ties to a country of concern — a growing due-diligence question as research computing and AI-tooling vendor lists lengthen.
- Employment, visiting-scholar, and consulting arrangements that give a covered person access to bulk sensitive data as part of their role, distinct from (and in addition to) any deemed-export screening already done for export-controlled technology.
- Data management plans for projects anticipating international data sharing should now name the DSP explicitly alongside funder data-sharing requirements, not treat it as implicitly covered by IRB or export-control review.
A practical compliance checklist
- Inventory before you draft. Before executing a new DSA, MTA, consortium agreement, or vendor contract involving genomic, health, financial, biometric, or precise-location data, identify every counterparty’s country and ownership structure, not just its physical address.
- Separate IRB/consent review from DSP review. A signed consent form or an IRB-approved data-sharing plan answers a human-subjects question, not a national-security data-transfer question — run both, and don’t let one substitute for the other.
- Flag genomic and biospecimen transfers first. These carry the lowest bulk thresholds and the only flat prohibition category (when the counterparty is a country of concern or covered person) — they deserve the fastest escalation path to your research security or export-control office.
- Treat restricted-transaction vendor relationships as an ongoing obligation, not a one-time check. CISA’s security requirements, DOJ’s due-diligence expectations, and annual certification are recurring, not “review once at signing.”
- Coordinate with, but don’t conflate, export-control review. A Research Security Officer or export-control office already screening for NSPM-33 foreign-influence disclosure or deemed-export risk is the right owner to add DSP screening to their intake process, since much of the underlying due-diligence data (foreign-national access, foreign ownership/control/influence) overlaps — but the legal basis, thresholds, and prohibited/restricted categories are distinct from EAR/ITAR and need their own checklist item, not a rider on an existing one.
- Watch for agency-level guidance. As of this writing, funders have not uniformly issued DSP-specific grantee guidance the way they did for NSPM-33 disclosure requirements; institutions are largely applying the DOJ rule directly to their own agreements rather than through funder-specific instructions. That is likely to change as more institutions report restricted-transaction activity.
What’s still unsettled
The DSP is young relative to the multi-year rulemaking histories behind EAR and ITAR, and DOJ itself has signaled the countries-of-concern and covered-person designations are subject to review, not fixed permanently. Two things are worth tracking specifically: how DOJ handles enforcement discretion for good-faith compliance efforts in this first full year after the October 2025 compliance date, and whether NIH, NSF, or other major funders formalize DSP-specific expectations in grant terms and conditions the way several already have for research-security disclosure. Institutions that have built a DSP screening step into agreement review — rather than waiting for funder-specific instructions — are better positioned either way.
Common questions
Does the DSP replace or duplicate export-control review under EAR/ITAR? No. Export controls govern controlled technology, technical data, and deemed exports to foreign nationals; the DSP governs bulk transfers of specific categories of sensitive personal data to countries of concern and covered persons, regardless of whether any controlled technology is involved. A research program can be fully compliant with export control and still need separate DSP review, and vice versa.
Does informed consent from research participants satisfy DSP requirements? No. DOJ explicitly declined to exempt nonclinical research data on the basis that participants had consented to disclosure. Consent governs collection and use under human-subjects rules; it does not authorize a bulk transfer to a country of concern or covered person under the DSP.
Is federally funded research automatically exempt? Only the specific transaction conducted pursuant to the government grant or contract itself is exempt — and even then, only for certain categories such as outbreak and pandemic prevention, preparedness, and response. A separately negotiated data-sharing agreement, MTA, or vendor contract tied to that same federally funded project is not automatically covered by the exemption and needs its own DSP review.
Who should own DSP screening inside a research administration office? There is no single required answer, but institutions are generally routing it to whichever office already owns research security and export-control screening — often a Research Security Officer or export-control officer — and building it into the same agreement-intake workflow used for NSPM-33 disclosure and deemed-export review, rather than creating a parallel process.







