Legal authority

Executive Order 14117 (2024)

Executive Order 14117 directed the creation of a United States transaction-control regime for access to Americans' bulk sensitive personal data and specified government-related data. The operational regime is the Department of Justice Data Security Program in 28 CFR Part 202. It is not a universal data-export ban.

The order set policy and delegated rulemaking. The final rule defines countries of concern, covered persons, covered data categories, bulk thresholds, covered transactions, exemptions and enforcement provisions. CISA issued security requirements for classes of restricted transactions. A regulated party's compliance decision is not itself a government prohibition.

The programme took effect on 8 April 2025. Covered data-brokerage transactions involving a country of concern or covered person are prohibited. Specified vendor, employment and investment agreements are restricted, meaning they may proceed only if the rule's conditions and CISA security requirements are met. Affirmative due-diligence, audit and reporting requirements applied from October 2025.

Each assessment should state the data category, threshold, transaction class, country-of-concern or covered-person connection, exemption and effective date. Government-related data has separate coverage. A transaction may involve sensitive data without meeting a bulk threshold, while some exemptions operate by activity rather than volume.

Relationship to other authorities

The regime is part of Data as strategic terrain and overlaps analytically with Data-localisation and cross-border-data restriction, but it does not generally require domestic storage. It differs from China's Data Security Law (China, 2021) and from supply-chain controls under Executive Order 13873 and ICTS rules (2019). The existence of one regime does not establish reciprocal intent by another state.

Implementation and effects

Compliance requires classification, counterparty diligence, contractual controls, security measures and recordkeeping. A prohibited transaction, restricted transaction, exempt transaction and activity under a licence are distinct. Violations, civil penalties and criminal charges also require their own procedural status.

As at 30 July 2026, DOJ's programme page, 28 CFR Part 202 and September 2025 FAQs are the current official sources. Effects on research, cloud services or investment require evidence tied to covered data and transactions, not broad claims about digital decoupling.

Compliance sequence

A covered party should first identify whether data are government-related or fall within a listed sensitive personal-data category. It then measures the relevant data set against the rule's threshold, identifies counterparties and countries, classifies the transaction and tests exemptions. Restricted transactions require the prescribed security controls and compliance programme; they are not prohibited if all conditions are met.

Data brokerage receives distinct treatment because transfer or access can enable onward availability. Vendor, employment and investment agreements use other definitions and controls. A company may also be subject to privacy, export-control or sectoral rules, but those obligations should not be attributed to Part 202.

Enforcement evidence should preserve notice, investigation, civil penalty, charge and final judgment as separate stages. Because technical access and contractual rights can change, an assessment should record the data snapshot, transaction period and security-control version. That makes claims reproducible and avoids treating a broad corporate relationship as proof of covered data access.

Sources

  1. United States Department of Justice, Data Security Program (accessed 30 July 2026).
  2. Electronic Code of Federal Regulations, 28 CFR Part 202 (accessed 30 July 2026).
  3. Federal Register, Executive Order 14117, 28 February 2024.
  4. United States Department of Justice, Data Security Program FAQs, September 2025.

Recommended citation

Cite this entry

Tennant, James J., ed. 'Executive Order 14117 (2024).' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/executive-order-14117-2024/.

Suggest an edit