Learn more about Frequently Asked Questions below:
What does the DOJ Rule do?
The DOJ Sensitive Data Rule restricts or in some cases prohibits U.S. persons, including Georgia Tech and its employees and researchers, from engaging in any transaction (called a “covered data transaction”) that involves:
- Access (including physical access, direct digital access, or remote access—by any means) to
- Certain kinds of data (which we will call “covered data”)
- By Covered Persons, which are the governments of or individuals or entities associated with six (6) designated Countries of Concern: China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia, or Venezuela.
What is a “Country of Concern”?
The DOJ Sensitive Data Rule currently designates six (6) countries as countries of concern:
- China (including Hong Kong and Macau);
- Cuba;
- Iran;
- North Korea;
- Russia; and
- Venezuela.
What is a Covered Person?
A “covered person” is generally an individual or entity with a significant connection to a countries of concern. “Covered persons” may include:
- Entities that are controlled by a Country of Concern, such as a business or other organization formed under the laws of a Country of Concern, an organization with a principal place of business in a Country of Concern;
- Entities or organizations that are 50% or more owned by a Country or Concern or Covered Person;
- Individuals who are employees or contractors of a Country of Concern or of an entity controlled by a Country of Concern;
- Individuals who primarily reside in a Country of Concern; or
- Any individual or entity identified on the U.S. Attorney General’s Covered Persons List.
Note: It is important to seek guidance from Georgia Tech regarding whether a research collaborator, sponsor, vendor, or other party may be a Covered Person because their affiliations with a Country of Concern may not be apparent.
What is a “U.S. person”?
U.S. persons include:
- Any business or other organization formed solely under the laws of the U.S. (including foreign branches);
- Any U.S. citizen, national, or lawful permanent resident;
- Any individual admitted to the U.S. as a refugee or asylee;
- Any person who is located in the U.S.
Note: Anyone who is located within the U.S. is a “U.S. Person,” regardless of their citizenship, nationality, or residency status, including individuals who would otherwise be covered persons, such as individuals who primarily reside in a country of concern. However, such a person from a country of concern who is lawfully present in the United States is considered a U.S. person only so long as they are physically present in the United States. If that person travels outside of the United States, even temporarily to a third country that is not a country of concern, that person ceases to be a U.S. person and again becomes a covered person.
What is a “Covered Data Transaction”?
The DOJ Sensitive Data Rule regulates four (4) kinds of transactions that involve Access to U.S. sensitive data by countries of concern or covered persons:
- Vendor Agreements,
- Employment Agreements,
- Investment Agreements, and
- Data Brokerage Transactions.
Note: “Data Brokerage Transactions” include a wide range of potential arrangements involving the transfer of data from a provider to a recipient where the recipient did not collect or process the data directly from the individuals linked or linkable to the data. This may include the sale of data, licensing of access to data, or similar exchanges for valuable consideration.
What is “Access”?
“Access” is any way of viewing or receiving data, including physical access, direct digital access, or remote access.
This means that “Access” includes “the ability to obtain, read, copy, decrypt, edit, divert, release, affect, alter the state of, or otherwise view or receive, in any form, including through information systems, information technology systems, cloud-computing platforms, networks, security systems, equipment, or software.”
What is bulk U.S. Sensitive Data?
Bulk U.S. sensitive data is data from the following categories that meets or exceeds the listed volume threshold.
| U.S. Sensitive Personal Data | Threshold of data collected or maintained on |
| Human genomic data | 100 U.S. persons |
| Human epigenomic data | 1,000 U.S. persons |
| Human proteomic data | 1,000 U.S. persons |
| Human transcriptomic data | 1,000 U.S. persons |
| Biometric identifiers | 1,000 U.S. persons |
| Precise geolocation data | 1,000 U.S. persons |
| Personal health data | 10,000 U.S. persons |
| Personal financial data | 10,000 U.S. persons |
| Covered personal identifiers | 100,000 U.S. persons |
| Combined data (Any collection or set of data that contains more than one category of U.S. sensitive personal data or that contains any listed Personal Identifiers linked to data from any other categories of U.S. sensitive personal data) | Lowest applicable threshold |
Note: The DOJ Sensitive Data Rule also regulates human biospecimens from which bulk human genomic, human epigenomic, human proteomic, or human transcriptomic data may be derived.
What about De-Identified or Anonymized Data?
Unlike regulations designed to protect the identity of human subjects of research, the DOJ Sensitive Data Rule allows for no exceptions for de-identified or anonymized data.
Instead, the DOJ Sensitive Data Rule applies to “data relating to U.S. persons, in any format, regardless of whether the data is anonymized, pseudonymized, de-identified, or encrypted, where such data meets or exceeds” specific bulk thresholds.
What U.S. government-related data are covered under the Data Security Program?
The DOJ Sensitive Data Rule generally defines U.S. government-related data as:
- Any precise geolocation data, of any volume, for any location within any area on the Government-Related Location Data List and
- Sensitive personal data that is marketed as linkable to employees, contractors, or officials of the United States government.
Note: There is no “bulk” threshold for U.S. government-related data.
Are there exemptions to the DOJ Sensitive Data Rule?
The DOJ Sensitive Data Rule does include certain exemptions that may allow you or Georgia Tech to allow access to covered data by Covered Persons. It is important, however, to understand that even if there is an exemption that is relevant to your research project, that exemption may not apply to all aspects of the project.
- Some exemptions, for example, may allow you to share covered data with a Covered Person only for a specific purpose, such as data-sharing that is strictly necessary to perform a US federal government grant, contract, or other agreement. Other data-sharing activities associated with the same project may not fit within the exemption.
- Even when activities are exempt under the DOJ Sensitive Data Rule, they might nevertheless be restricted or prohibited by other regulations or sponsor policies.
- If you believe that an exemption under the DOJ Sensitive Data Rule might apply to your research project, it is critical to seek confirmation or guidance from GTprivacy@gatech.edu before you allow Access to data so that you, your research project, and GT remain in compliance with all applicable requirements.
What are the potential consequences of noncompliance?
The DOJ Sensitive Data Rule allows for both civil and criminal penalties. when an organization or person engages in a Covered Data Transaction that they know or reasonably should have known is restricted or prohibited, and it allows for criminal penalties for willful violations.
- Civil: When a person or organization engages in sharing or otherwise providing access to covered data knows or reasonably should have known is restricted or prohibited by the DOJ Sensitive Data Rule, that person or organization may receive a civil penalty of up to $368,136 or twice the amount of the transaction involved, whichever is greater.
- Criminal: A person who willfully commits, willfully attempts to commit, willfully conspires to commit, or aids or abets in the commission of a violation of the DOJ Sensitive Data Rule may be fined up to $1,000,000, imprisoned for up to 20 years, or both.
Can an individual from a country of concern who is lawfully present in the United States access covered data?
Any individual, including an individual from a country of concern, can access covered data while lawfully present in the United States, unless such individual is named on the DOJ’s Covered Persons List.
However, when an individual who is primarily a resident of a country of concern, or who is an employee or contractor of a covered person or country of concern, leaves the United States, even for a brief period of time such as to attend a conference or visit family overseas, that individual will become a covered person upon exiting the United States and may no longer have access to covered data.
Any attempt to avoid the regulation’s prohibitions, such as by having a covered person enter the United States to receive covered data, could constitute evasion and a violation of the regulation.
What about data-sharing activities within research collaborations?
As noted above, the DOJ Sensitive Data Rule regulates “Data Brokerage Transactions,” which include a wide range of potential arrangements involving the transfer of data from a provider to a recipient where the recipient did not collect or process the data directly from the individuals linked or linkable to the data.
- Data brokerage transactions are common in research environments where researchers regularly collaborate on projects that involve sharing of data.
- Data brokerage transactions might involve grants or other funding agreements that direct a researcher to share research data with a sponsor or other third party.
- They may also include any arrangement in which one person allows another to have access to data in exchange for goods, services, or anything of value.
In evaluating the applicability of the DOJ Sensitive Data Rule to individual research projects, it is important to remember that unlike regulations designed to protect the identity of human subjects of research, the DOJ Sensitive Data Rule does not allow for exceptions for de-identified or anonymized data.
For further guidance, please contact Georgia Tech’s Chief Privacy Officer via email at GTPrivacy@gatech.edu.
What about sharing data with foreign collaborators who are not covered persons?
The DOJ Sensitive Data Rule prohibits you and Georgia Tech from engaging in any data brokerage transaction with a foreign person who is not a covered person that involves any access by a foreign person to government-related data or bulk U.S. sensitive personal data unless Georgia Tech contractually requires that foreign person to comply with the provisions of the DOJ Sensitive Data Rule.
Further, in the event that you and Georgia Tech engage in such a data brokerage transaction with a foreign person that is not a covered person and you suspect that the foreign noncovered person violates that contractual agreement, the DOJ Sensitive Data Rule requires Georgia Tech to report the known or suspected violation within 14 days of when you become aware of the known or suspected violation.
For further guidance related to data-sharing activities with foreign persons or entities that are not countries of concern or covered persons, please contact Georgia Tech’s Chief Privacy Officer via email at GTPrivacy@gatech.edu.
What if someone offers to engage in a transaction that might be prohibited under the DOJ Sensitive Data Rule?
The DOJ Sensitive Data Rule requires Georgia Tech to report any offer to engage in a prohibited transaction involving data brokerage to the DOJ within 14 days of affirmatively rejecting the offer, even if the offer is rejected automatically using software, technology, or automated tools.
If you receive a verbal or written offer for Georgia Tech to engage in a transaction that you know or have reason to suspect might be a Prohibited Data-Sharing Transaction, you must immediately contact Georgia Tech’s Chief Privacy Officer via email at GTPrivacy@gatech.edu.
What if someone asks me to certify compliance with the DOJ Sensitive Data Rule?
Many research projects that involve data sharing also utilize data use agreements or similar agreements. These agreements may include language certifying Georgia Tech’s compliance with the DOJ Sensitive Data Rule or other laws, regulations or policies. You may also receive communications from research collaborators requesting you to certify or otherwise agree to comply with terms or conditions related to this or other regulations.
If you receive a request to certify compliance or to agree to similar terms or conditions, please contact Georgia Tech’s Chief Privacy Officer at GTPrivacy@gatech.edu for review prior to entering into the agreement.
Where can I find more information?
To learn more about the DOJ Sensitive Data Rule, please consider visiting the following links.
- DOJ Sensitive Data Rule: Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (28 CFR Part 202)
You may visit the Electronic Code of Federal Regulations to read the full text of the DOJ Sensitive Data Rule as it is codified in the Code of Federal Regulations. - DOJ National Security Division, Data Security Program
The DOJ National Security Division maintains this website to provide guidance and related to the implementation and enforcement of the DOJ Sensitive Data Rule. - U.S Department of Justice, Data Security Program, Frequently Asked Questions
The DOJ National Security Division maintains a detailed set of frequently asked questions” regarding the DOJ Sensitive Data Rule.
For further questions or assistance, you may also reach out to Georgia Tech’s Chief Privacy Officer at GTPrivacy@gatech.edu.
What if I have additional questions?
If you have additional questions or need further assistance, please contact Georgia Tech’s Chief Privacy Officer via email at GTPrivacy@gatech.edu.