DOJ Data Security Program

Overview

The U.S. Department of Justice (DOJ) Data Security Program (DSP) is a federal regulation designed to protect U.S. national security by prohibiting or restricting certain transactions that could provide countries of concern or covered persons with access to bulk U.S. sensitive personal data or U.S. government-related data (collectively, sensitive data).

While the rule applies only in specific circumstances, it may prohibit or restrict certain research collaborations, data sharing arrangements, material transfer agreements, vendor relationships, and other activities involving sensitive data. 

International transfers of sensitive data should be reviewed by Columbia’s Office of Research Compliance and Training (RCT) before the data are shared or made accessible to an external party.  If you are unsure whether the DOJ Data Security Program applies to your activity, please contact RCT for guidance before proceeding ([email protected]).

 

Could the DOJ Data Security Program Apply to My Activity?

The DSP may apply if your activity involves:

  • Sharing sensitive personal data with collaborators or service providers outside the U.S.;
  • Sending human biospecimens to collaborators or service providers outside the U.S.;   
  • Providing collaborators or service providers outside the United States with remote access to research databases containing sensitive data;
  • Providing access to large datasets involving U.S. persons to collaborators or service providers outside the U.S. 

The DOJ Data Security Program applies only in specific circumstances and does not apply to every international research collaboration or transfer of research materials. If you answer yes to any of the above or are unsure whether the rule applies, contact Research Compliance and Training before proceeding. 

What Does the DSP Rule Do?

The DOJ Data Security Program regulates certain covered data transactions that could provide countries of concern or covered persons with access to:

  • Bulk U.S. sensitive personal data, or
  • U.S. Government-related data.

Depending on the type of transaction, the rule may:

  • prohibit the transaction;
  • permit the transaction only if mandatory contractual provisions are included in agreements and/or if specified security requirements are satisfied; or
  • exempt the transaction if a regulatory exemption applies. 

Key Concepts

The DOJ rule applies to specific categories of data defined in the regulations. Please note that the DSP Rule applies regardless of whether the data is anonymized, pseudonymized, de-identified, or encrypted.

The categories of data covered by the DSP include:

Human 'omic Data

  • Human 'omic data includes:
    • human genomic data;
    • human epigenomic data;
    • human proteomic data; and
    • human transcriptomic data.
  • Researchers working with human 'omic data should consult Research Compliance and Training before sharing these data internationally.
  • Regulatory definition: 28 CFR 202.224

Human Biospecimens

  • The DSP also regulates transactions involving human biospecimens from which bulk human 'omic data could be derived.
  • Human biospecimens include tissue, blood, urine, cells, cell cultures, plasma, sera, and other human-derived materials, as defined in the regulations.
  • Researchers planning international shipments of human biospecimens, regardless of quantity, should contact Research Compliance and Training before proceeding.
  • Regulatory definition: 28 CFR 202.223

Personal Health Data

  • Health information describing an individual's physical or mental health, healthcare, or payment for healthcare, including diagnostic information, treatment history, laboratory results, and other health-related information.
  • Regulatory definition: 28 CFR 202.241

Personal Financial Data

  • Information regarding financial accounts, payment history, bank accounts, securities portfolios, credit reports, and similar financial information.
  • Regulatory definition: 28 CFR 202.240

Biometric Identifiers

  • Measurable physical characteristics used to recognize or verify an individual's identity, including fingerprints, facial recognition, voiceprints, iris scans, and similar identifiers.
  • Regulatory definition: 28 CFR 202.204

Precise Geolocation Data

  • Location information identifying the physical location of an individual or device within 1,000 meters.
  • Regulatory definition: 28 CFR 202.242

Covered Personal Identifiers

  • Certain listed identifiers that are linked or linkable to other identifiers or sensitive personal data.
  • Regulatory definition: 28 CFR 202.212

U.S. Government-related Data

  • Government-related data includes certain sensitive personal data linked to specified U.S. Government personnel and certain geolocation data associated with designated government-related locations.
  • Regulatory definition: 28 CFR 202.222

The DSP applies only when specified categories of sensitive personal data meet applicable regulatory thresholds.  Human genomic data has the lowest bulk threshold under the DOJ Data Security Program—100 U.S. persons. Other categories of human 'omic data have thresholds of 1,000 U.S. persons. 

Bulk thresholds are included in the table below. 

The Countries of Concern are:

  • China (including Hong Kong and Macau)
  • Russia
  • Iran
  • North Korea
  • Cuba
  • Venezuela

A covered person is an individual or entity that falls into one of the following categories:

  • Foreign entities headquartered in or organized under the laws of a country of concern;
  • Foreign entities 50% or more owned by a country of concern or covered person;
  • Foreign individuals primarily resident in a country of concern;
  • Foreign individuals who are employees or contractors of a covered person entity or a country-of-concern government; and
  • Any person who is listed on NSD’s “Covered Persons List”.

Covered data transactions are transactions involving access by Countries of Concern or Covered Persons to bulk U.S. sensitive personal data or U.S. government-related data through:

  • data brokerage;
  • vendor agreements;
  • employment agreements; or
  • investment agreements. 

Covered transactions are either prohibited or restricted under the regulations.

Common Research Activities That May Require Review 

  • International transfers of human biospecimens;
  • International sharing of large human research datasets;     
  • International service providers analyzing or processing sensitive data; or
  • Questions regarding whether data meet the DOJ's bulk thresholds.

How Can Researchers Reduce Risk? 

Resources