Published: December 19, 2025. Amended: January 23; February 26; April 7, 2026; August 11, 2026.
The National Security Division of the Department of Justice (DOJ) has issued a Final Rule (codified at 28 CFR Part 202), effective April 8, 2025, implementing Executive Order 14117 "Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons" as a Data Security Program (DSP).
Note: For guidance, see: University Policy 4.22 Export and Import Control Compliance.
Applies to: All Cornell data custodians, including research faculty and staff who handle government-related data and U.S. sensitive personal data as those terms are defined in the Bulk Data Rule.
Does the Bulk Data Rule impact your research or international transactions?
If you are dealing with U.S. government-related data or bulk U.S. sensitive personal data meeting the volume thresholds and plan to disclose or make the data accessible to an external entity, immediately notify exportcontrols@cornell.edu to determine if the transaction will be permissible.
Important Notice: Civil and criminal penalties may be imposed by the DOJ for violations of the Bulk Data Rule. If you suspect that a violation may have occurred, work to remediate it as soon as possible and immediately contact exportcontrols@cornell.edu.
Bulk Data Flowchart
The following flowchart shows a summary of bulk data guidelines:

Bulk Data Rule Regulations
The DOJ’s Bulk Data Rule imposes requirements on U.S. persons and entities that provide access to bulk U.S. sensitive personal data and government-related data, including the need to prohibit or restrict transfers of such data to Countries of Concern or Covered Persons, as defined in the Rule.
| Definition | Description | Notes |
|---|---|---|
| Countries of Concern |
| |
| Covered Person |
| |
| Foreign Person |
| |
| U.S. Person (United States Person) |
| |
| Covered Data Transactions | Any transaction that involves access by a Country of Concern or Covered Person to any bulk U.S. sensitive personal data or government-related data and that involves:
Includes payment or other valuable consideration, meaning the following all qualify:
| |
| Exempt transactions | The Bulk Data Rule includes exempt transactions which allow data transactions that would otherwise be prohibited or restricted. Some exemptions may trigger reporting requirements. Note: If you have questions about the applicability of any exemption, please contact exportcontrols@cornell.edu for additional guidance. |
Note: For guidance, see the Bulk Data Rule High-Level Decision Tree.
Covered Data Transactions Threshold
The regulations apply to Covered Data Transactions that involve transfer or access to:
- Bulk U.S. Sensitive Personal Data when the volume exceeds the specified “bulk threshold” listed in the Chart below at any point over a rolling 12-month period for covered data transactions (single or in the aggregate) involving the same parties.
Note: If the applicable threshold is met, the Bulk Data Rule’s prohibitions and restrictions on data transactions apply regardless of whether the data is de-identified, anonymized, pseudonymized, or encrypted.
For a data set that contains more than one covered data category, the data set is subject to the lowest threshold for any covered data category contained within it.
| Data Category | Bulk Threshold |
|---|---|
| Covered Personal Identifiers | 100,000 U.S. Persons |
| Personal Financial Data | 10,000 U.S. Persons |
| Personal Health Data | 10,000 U.S. Persons |
| Precise Geolocation Data | 1,000 U.S. Persons |
| Biometric Identifiers | 1,000 U.S. Persons |
| Human ‘omic Data (not Genomic) | 1,000 U.S. Persons |
| Human Genomic Data | 100 U.S. Persons |
| Combined data | Lowest applicable number |
Prohibited Transactions
The following transactions are not allowed under the Bulk Data Rule:
| Prohibited Category | Prohibited Criteria |
|---|---|
| Data Brokerages |
|
| Covered Data Transactions | Covered data transactions with Countries of Concern or Covered Persons that involves:
When the Bulk U.S. Sensitive Personal Data volume exceeds the specified “bulk threshold” listed in the chart below at any point over a rolling 12-month period for covered data transactions (single or in the aggregate) involving the same parties. |
| Data Sharing |
|
| U.S. Government-Related Data | U.S. Government-related data that includes precise geolocation data for:
There is no “bulk” threshold for U.S. Government-related data. |
Note: Any known or suspected violations must be reported to the DOJ within 14 days.
Activities that are not restricted by the Bulk Data Rule
Generally, the Bulk Data Rule does not apply to:
- Purely domestic data sharing between U.S. Persons or entities within the U.S. except to the extent that a U.S. Person has not been specially designated as a Covered Person;
- Data sharing that is without any kind of financial benefit or consideration;
- Data about non-U.S. Persons; or
- Data sharing that is directed or authorized pursuant to the terms of a federal grant. Non-federally funded research data is not exempt.
The Bulk Data Rule does not apply when a U.S. person is given access to U.S. sensitive personal data or U.S. government-related data by a Covered Person.
Restricted Transactions
Some covered data transactions are not prohibited, but are restricted and have certain reporting, recordkeeping, data security and auditing requirements.
Contact exportcontrols@cornell.edu if you are working with:
- vendor agreements
- employment agreements
- investment agreements.
Additional Resources
- More information can be found in the DOJ’s Data Security Program FAQ and on the DOJ’s National Security Division website.
- For specific questions, please reach out to exportcontrols@cornell.edu.