← Back to insights

“Contract Tomorrow, Data Friday”: What the DOJ Transaction Record Must Show

Reconstruct a planned vendor or data-transfer arrangement under the DOJ Data Security Program before the contract, access and control records drift apart.

A cross-border data transaction record connects sensitive data, counterparty control, transaction type and required safeguards
#DOJ Data Security Program#28 CFR Part 202#Covered Data Transaction#CISA Security Requirements

Signals to watch

  • A vendor contract is due before the data category, prior-12-month volume and government-related-data status have been reconciled
  • The contracting entity is named, but ownership, control, principal place of business and remote-access personnel are not
  • Encryption or a security questionnaire is presented as the answer before the transaction has been classified as exempt, restricted or prohibited

Before a cross-border data contract is approved, reconstruct the arrangement as one transaction record: identify the U.S. data and volume, the foreign parties and their ownership or control, the access they will receive, the agreement type, any exemption, and the rule outcome. Do not start with a security questionnaire. Encryption and access controls may be required for a restricted transaction, but they do not decide whether the transaction is covered or prohibited.

A covered data transaction under 28 CFR Part 202 is a transaction involving access by a country of concern or covered person to U.S. Government-related data or bulk U.S. sensitive personal data through data brokerage, a vendor agreement, an employment agreement or an investment agreement. “Access” is broader than downloading a file: it includes the logical or physical ability to obtain, read, copy, decrypt, edit, divert, release, affect or otherwise view or receive data. The rule tests access without regard to whether security requirements have been applied.

That definition matters to one person in particular: the engagement lead at a U.S. data-security compliance consultancy who sees contract deadlines in authorised cross-border data, supplier-risk and legal-operations Telegram groups. If the message sits until after signature or transfer, the first paid task may go to the provider that can state which data, party, agreement and control record must be examined.

09:10 — A deadline appears before the transaction

This illustrative message chain is not a customer story or a record of an actual transfer:

09:10 — “DPA needs signing tomorrow. Regional analytics vendor will support the U.S. account. Can security clear it today?”

DPA usually means data processing agreement. The message does not identify the dataset, number of U.S. individuals, access method, contracting entity, remote personnel, ownership chain or planned transfer. It is a reason to open a review, not evidence that the arrangement is permitted or prohibited.

The first transaction-card entry should preserve the exact message, sender context, source, time, contract deadline and named legal entities. Add a separate column for every claim that still lacks a primary record. This prevents “regional vendor” or “U.S. account” from becoming an invented country or data conclusion.

TOP Prospect can prioritise fragments from authorised Telegram groups deliberately connected by the user, preserving text, source and time for human review. The matching-target screen saves configuration only; it neither runs the rule nor creates candidates. The product cannot read contracts, identify covered persons, inspect data flows, apply CISA controls or make legal decisions.

11:40 — The data appendix changes the first question

11:40 — “Appendix says device IDs and account activity. Support may see location events. No final volume yet.”

The work now moves from the contract label to the data. The DOJ program covers specified categories, including human genomic and other human ’omic data, biometric identifiers, precise geolocation, personal health data, personal financial data and covered personal identifiers. Each category has its own regulatory definition and, for bulk U.S. sensitive personal data, a threshold.

The bulk test looks at whether the applicable threshold was reached at any point in the preceding 12 months. It can aggregate covered data transactions involving the same U.S. person and the same foreign person or covered person. A single transfer estimate may therefore be incomplete. Government-related data has its own definition and can be covered without relying on the ordinary bulk calculation.

Record the dataset name, fields, source systems, U.S.-person population, category, measurement date and prior-12-month aggregation. Then record what the recipient can actually do: view through a support console, query, export, decrypt, edit, administer or receive a copy. “Pseudonymised” and “no export” are control claims that need evidence; neither phrase removes access by itself.

Completion here means a cited data inventory from which a reviewer can reproduce the category and volume decision. Otherwise, mark the threshold and government-related status unknown.

14:15 — The contracting company is only one party

14:15 — “Contract entity is in Singapore. Procurement says the parent and the night support team still need checking.”

A third-country registration does not end the party analysis. Section 202.211 includes several covered-person routes, including qualifying ownership by countries of concern or specified covered persons, organisation or principal place of business in a country of concern, certain foreign employees or contractors, primary residence in a country of concern, and individual designation by the Attorney General.

Build the party record from official corporate documents and the real access roster. Capture the contracting entity, direct and indirect owners, ownership percentages, principal place of business, controlling entities, subcontractors, remote administrators and where foreign individuals primarily reside or work. A sanctions result can be useful evidence, but the DOJ covered-person test is not interchangeable with an OFAC result. The OFAC 50 Percent Rule ownership-chain analysis is a related method, not a substitute legal test.

The message still does not establish that the Singapore entity, its parent or any worker is a covered person. Show the ownership and access gaps instead of filling them with nationality assumptions.

16:30 — The agreement type determines the next fork

16:30 — “Vendor says it can complete the CISA checklist. Legal asks whether that is enough to sign.”

Not yet. First classify the commercial arrangement from what the parties will do, not only from the heading on the contract:

  • Data brokerage includes a sale, licence of access or similar commercial transaction in which data moves from a provider to a recipient that did not collect or process it directly from the linked individuals. Covered data brokerage with a country of concern or covered person is prohibited.
  • Vendor agreements, employment agreements and investment agreements can be restricted transactions when they provide the relevant access and are not otherwise prohibited or exempt. A restricted transaction may proceed only when the rule’s conditions and the CISA security requirements are satisfied.
  • Certain access involving bulk human genomic data or biospecimens is prohibited under a separate rule route. The rule also contains exemptions that depend on the actual activity, not on a checkbox labelled “exempt.”

CISA’s requirements address organisational, system-level and data-level safeguards. They belong on the card with an owner, implementation evidence and validation result. They cannot convert prohibited data brokerage into a restricted vendor agreement. Nor can a clean security review replace the data, party and transaction classification.

If the facts remain genuinely uncertain, the card can route the matter for qualified counsel, a DOJ advisory opinion or a licence analysis where applicable. It should not convert uncertainty into a same-day approval.

Before approval — Freeze the facts that can change the answer

Keep these six decisions on one controlled record:

Card fieldEvidence to retainDecision it controls
DataField inventory, U.S.-person scope, category, volume and 12-month aggregationGovernment-related or bulk covered data
PartiesLegal entities, ownership/control, principal place of business, residence and access rosterCountry-of-concern or covered-person nexus
AccessArchitecture, permissions, support path, exports, keys and subcontractorsWhether the foreign party can access the data
TransactionExecuted terms and actual activityBrokerage, vendor, employment or investment route
Rule treatmentExemption analysis, prohibition/restriction basis, licence or opinionWhether and how the arrangement may proceed
Controls and recordsCISA evidence, due diligence, audit result, approvals and change triggersRestricted-transaction conditions and continuing review

The program took effect on 8 April 2025. The DOJ Data Security page states that specified affirmative due-diligence and audit requirements for restricted transactions, annual reports and rejected-prohibited-transaction reports became applicable on 5 October 2025. A current review therefore needs the operating evidence, not only the original 2025 implementation memo.

Record the decision date, reviewer, source versions, assumptions and the fact that would reopen the review—for example, a new subprocessor, a larger U.S. dataset or a change in ownership. Use the official-source ladder for a compliance claim when a forwarded summary conflicts with the current rule. The SEC incident-response evidence map offers a separate example of keeping event, owner and reporting records connected without merging their legal tests.

Key facts

  • The DOJ Data Security Program took effect on 8 April 2025; specified affirmative compliance and reporting requirements became applicable on 5 October 2025.
  • A covered data transaction combines covered data, access by a country of concern or covered person, and data brokerage or a vendor, employment or investment agreement.
  • Access is tested without regard to the application or effect of security requirements.
  • Bulk thresholds are category-specific and use a preceding-12-month test that can aggregate transactions involving the same parties.
  • CISA security requirements apply to restricted transactions; they do not make prohibited data brokerage permissible.
  • A contract deadline, foreign address or security questionnaire cannot replace the data, party, access and transaction records.

FAQ

Does encryption make a transaction fall outside the DOJ Data Security Program?

No. The rule determines access without regard to the application or effect of security requirements. Encryption can be relevant to a restricted transaction’s controls, but it does not erase a covered or prohibited transaction.

Is every contract with a vendor in a country of concern prohibited?

No. The result depends on the covered data, access, counterparty, agreement type and any exemption. Some vendor, employment and investment agreements are restricted rather than prohibited when all applicable conditions are met.

Which data volume should the transaction card use?

Apply the threshold for the relevant data category at any point in the preceding 12 months, including required aggregation across covered data transactions involving the same U.S. person and the same foreign person or covered person.

When did the DOJ Data Security Program requirements become applicable?

The program took effect on 8 April 2025. Certain due-diligence, audit, annual-reporting and rejected-prohibited-transaction reporting provisions became applicable on 5 October 2025.

Editorial review completed 21 August 2026 against the current DOJ Data Security page, 28 CFR Part 202, the DOJ Compliance Guide, CISA Security Requirements and the final rule. This article is not legal advice or a transaction authorisation.

Frequently asked questions

Does encryption make a transaction fall outside the DOJ Data Security Program?

No. The rule determines access without regard to the application or effect of security requirements. Security measures matter to a restricted transaction, but they do not by themselves make a covered or prohibited transaction disappear.

Is every contract with a vendor in a country of concern prohibited?

No. The analysis still requires covered data, access, the counterparty relationship, transaction type and any exemption. Some vendor, employment and investment agreements are restricted rather than prohibited when the rule and CISA requirements are satisfied.

Which data volume should the transaction card use?

Use the applicable category and test whether its bulk threshold was met at any point in the preceding 12 months, including aggregation across covered data transactions involving the same U.S. person and the same foreign person or covered person.

When did the DOJ Data Security Program requirements become applicable?

The program took effect on 8 April 2025. Certain affirmative due-diligence, audit, annual-reporting and rejected-prohibited-transaction reporting requirements became applicable on 5 October 2025.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage