Have a Question?
Have a question about the DOJ Sensitive Data Rule? Contact us.
Have a question about the DOJ Sensitive Data Rule? Contact us.
The DOJ Sensitive Data Rule
At Georgia Tech, we are committed to safeguarding all our data, whether it is the personal data of our students, staff, and broader communities or the data that allows us to advance research innovation.
In 2025, the U.S. Department of Justice (DOJ) issued a new regulation on “Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons.” This new regulation, commonly known as the “DOJ Sensitive Data Rule,” is codified at Title 28 of the Code of Federal Regulations Part 202. At the same time, the DOJ National Security Division established a “Data Security Program” to implement and enforce the new regulations.
The DOJ Sensitive Data Rule restricts or prohibits U.S. persons, including Georgia Tech and its employees and researchers, from sharing access to data in ways that might compromise U.S. national security.
This page is intended as a resource to help the Georgia Tech community to understand the DOJ Sensitive Data Rule and what members of the Georgia Tech community must do in order to maintain compliance.