In October 2025, the U.S. Department of Justice (DOJ) began full enforcement of its Data Security Program (DSP), which sets rules for how businesses handle sensitive U.S. data.
The move follows Executive Order 14117, issued in 2024, aimed at preventing certain foreign countries from gaining access to large sets of sensitive U.S. data that could threaten national security. The new policy affects businesses, healthcare providers, tech companies and others by setting rules on how bulk data can be handled, transferred and shared around the world.
Addressing Rising Concerns
The executed order, issued under former President Joe Biden, was made in response to concerns that some foreign nations, labeled by federal officials as “countries of concern,” could misuse the data. The worry is that these nations could use the data in harmful ways, including intelligence operations or manipulating U.S. citizens, both ploys to gain strategic advantages.
“At the same time, the United States is committed to promoting an open, global, interoperable, reliable, and secure Internet; protecting human rights online and offline; supporting a vibrant, global economy by promoting cross-border data flows required to enable international commerce and trade; and facilitating open investment,” the Federal Register noted.
To manage those risks and continue the secure promotion of foreign data flows, the DOJ was ordered to draft regulations. Those regulations, which began full enforcement late last year, set clear definitions, including:
The program focuses on “bulk sensitive personal data,” and does not restrict all international data transfers. It targets large-volume data transfers to high-risk countries. Through the executive order, businesses are required to assess all data transfers for potential risks, implement security controls and request exemptions when necessary.
Order Across Industries
The new DSP directly impacts sectors across industries, many of which are gaining momentum in Indiana and throughout the Midwest. Those in sensitive data areas, including health, biotech, cloud computing, and data brokerage, will face the most impact for the regulations.
For example, a tech company collecting DNA samples and health data from Americans may process that information overseas. If that lab or data servers are located in one of the “countries of concern,” and the data is over the bulk threshold stated in the regulations, that company will face restrictions or need to work with the DOJ for approval to continue its work.
In the manufacturing and logistics industries, companies that use cloud vendors to store data from employees or contractors located in a “country of concern” may be restricted or required to implement additional security measures if that data exceeds the threshold, which for this case, the Federal Register notes is more than 1,000 people.
Data brokers collect and sell large volumes of personal information, making this segment highly subject to the new regulations. If those lists, sometimes containing information for hundreds of thousands of Americans, including data such as emails, addresses or other geolocation data, and those lists are accessed by individuals in “countries of concern,” they could be restricted.
What Indiana Business Leaders Should Do
Businesses that handle large volumes of sensitive data can take steps to ensure they are operating within the regulations of the DSP. Those steps include:
Even companies not currently operating in high-risk areas must stay vigilant, continuously reviewing processes, vendor contracts and security practices to remain in compliance with the regulations. It is important to note that amendments to the “countries of concern,” threshold numbers or other restrictions in the regulations could be made in the future.