Armed Conflict Intelligence Surveillance & Privacy

Closing the Front Door: The Case for DOJ’s Bulk Data Security Program

Lee Licata
Wednesday, August 12, 2026, 1:00 PM

No one hacked us. Adversaries are buying U.S. troops’ location data on the open market. Privacy laws can’t stop them, but DOJ can.

A demonstration of a computing environment at Aberdeen Proving Ground, MD, 2018. (U.S. Army - PEO C3T, https://tinyurl.com/mvcytrsc, CC BY-ND 2.0, https://creativecommons.org/licenses/by-nd/2.0/)

You’re the head of Iranian intelligence services. During the recent U.S. attack, you discover that you can track U.S. troop movements for pennies without the need for sophisticated satellite imagery. This is not a fantasy; this is what happened just a few months ago. In April, U.S. Central Command confirmed it had received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in the Persian Gulf, where U.S. forces are fighting the Iranian military to reopen the Strait of Hormuz.

A bipartisan group of legislators wrote to the Pentagon the same day, warning that commercial location data can be used to identify where U.S. troops congregate and reconstruct their pattern of life, enabling adversaries to direct missile, drone, and roadside bomb attacks against them. It was the first official confirmation that U.S. forces had been targeted in an active war zone using data sourced from the commercial market.

Nor was this some out-of-the-blue innovation. Researchers, reporters, and national security professionals warned about this scenario for years. In 2018, the fitness app Strava published a global heat map of user activity that inadvertently traced the running routes of soldiers around forward operating bases, exposing the layout and location of military installations in Afghanistan, Syria, and elsewhere.

In November 2023, researchers at Duke University set out to test how hard it would be for a foreign government to assemble a dossier on U.S. service members using nothing more than a credit card. Posing as international buyers, the team contacted U.S. data brokers that advertised datasets on active-duty military personnel. For between 12 and 32 cents per record, the researchers walked away with information on nearly 30,000 service members and another 5,000 of their friends and family members, covering home addresses, health conditions, religious affiliations, financial details, and the presence of children in the home. The researchers could filter the dataset by geolocation to isolate personnel living near Fort Bragg or Quantico. No statute was broken, no system was breached, and the transaction was, in every commercial sense, ordinary.

Two and a half years later, what the Duke team demonstrated in a controlled study is now a matter of public record. In March 2026, the Electronic Privacy Information Center flagged 33 data brokers that, in disclosures filed with the State of California for 2025 under the state’s Delete Act, reported selling data to, or sharing it with, “foreign actors”—defined by California law as governments or principal-place-of-business entities tied to China, Russia, Iran, or North Korea. The disclosures were not the product of a sting or a leak. They were self-reported, on an annual form, to a state agency.

The commercial data market has become a standing national security vulnerability, and the U.S. government already has the right instrument to close it. The Department of Justice’s Bulk Data Security Program (DSP) was the first and only federal regulatory regime built specifically to stop foreign adversaries from buying or accessing Americans’ most sensitive data through ordinary, lawful commercial channels. But the program appears to have stalled, and a stalled program protects no one. The Justice Department must build out the regulatory machinery that lets companies comply and resource the program at a level commensurate with the threat, and Congress must codify the program through legislation so that it cannot be quietly abandoned. Treating the DSP as a real regulatory regime rather than an occasional enforcement tool is the difference between closing the front door to adversary data acquisition and leaving it open.

How We Got Here

For the better part of a decade, U.S. national security policy has recognized that foreign adversaries, principally China and Russia, have sought to acquire Americans’ most sensitive data—such as genomic, financial, biometric, geolocation, health, and other personal identifiers—through legitimate commercial channels. The strategic payoff for these countries to acquire this type of sensitive data on Americans has become clear. Foreign adversary intelligence and security services can use these datasets to conduct espionage, blackmail, and coercion against U.S. persons. These intelligence services can also use this type of data to identify federal government and military-affiliated individuals by pattern-matching across otherwise unrelated datasets. Finally, this type of data can also facilitate malicious cyber activities and be used to train artificial intelligence systems that can make subsequent exploitation faster and more precise while also identifying Americans’ broad patterns of life.

The intelligence value of bulk sensitive personal data is no longer debatable. Genomic data supports the building of biological weapons and enables identification of intelligence officers and their families, biomedical targeting, and counterintelligence analysis at a population scale. Precise geolocation data, sold routinely on commercial data broker markets, allows the mapping of military installations, intelligence facilities, and personnel with security clearances and their patterns of life—even when the data is completely anonymized. Health and financial data support coercion and recruitment. Combined datasets, increasingly available for purchase through data brokers, enable the kind of analytic work to identify both the individuals in the set and the broader patterns that previously required years of covert collection.

Privacy law cannot close this gap because it aims to solve a different problem. Consumer privacy regimes are built around individual choice. They provide a person with the right to know what data is collected, to consent or object, to opt out of a sale, or to demand deletion. But the national security risk here does not turn on any one individual’s choices. An adversary does not need to defeat a single person’s privacy settings when it can simply buy 30,000 service members’ records in bulk on the open market. Even a regime of perfect individual consent would leave that aggregate data flow largely untouched, because the danger lies precisely in the bulk, combined, population-scale dataset rather than in any single record an individual might choose to protect. Cross-referenced records reveal patterns no individual file contains, potentially exposing units, installations, supply chains, and command relationships that allow an adversary to target the military population as a system rather than as individuals.

Anonymization is also insufficient to address the national security risk. Privacy regimes often treat anonymization or deidentification as sufficient protection, but extracting the identifiers does not remove the national security risk from a dataset. In its 2019 “One Nation, Tracked” investigation, the New York Times analyzed a file of more than 50 billion supposedly anonymous location pings from 12 million Americans. The investigation showed how trivially the data reidentified individuals: reporters tracked a Secret Service agent’s movements closely enough to reconstruct the president’s whereabouts and followed a senior Defense Department official from the Pentagon to his home in Virginia. Precise location, movement, and behavioral patterns are themselves identifying, and they carry intelligence value whether or not an individual’s name is attached. An adversary that can map where cleared personnel work, sleep, and congregate does not need the name on the record to act on it. Privacy is about protecting the individual’s right to control their own information, whereas national security is about protecting the country from a hostile foreign power assembling that information at scale.

Until 2024, the government tried to mitigate this type of risk through case-by-case reviews of commercial transactions involving various forms of foreign investment or ownership. For example,

  • The interagency Committee on Foreign Investment in the United States (CFIUS), which is composed of representatives from nine federal departments and agencies, including the Departments of Treasury, Defense, Energy, Homeland Security, and Justice, reviews investments that might give a foreign acquirer access to a U.S. company’s data. Team Telecom, an interagency group that includes representatives from the Departments of Justice, Defense, and Homeland Security, assesses the risk of Federal Communications Commission (FCC) telecommunication licenses that may expose Americans’ data and communications to investors, vendors, and employees in foreign adversary jurisdictions.
  • The Commerce Departments Information and Communications Technology Supply Chain (ICTS) authority targets covered transactions involving foreign-adversary information and communications technology that present certain risks of espionage or sabotage against the United States.
  • The Protecting Americans from Foreign Adversary Controlled Applications Act (PAFACA or the TikTok law) empowers the president to designate specific software-connected applications as foreign adversary controlled, forcing divestiture from foreign adversary ownership or resulting in the ban of those applications from U.S. app stores.
  • The Protecting Americans Data from Foreign Adversaries Act, enacted in the same April 2024 statutory package as PAFACA, makes it unlawful for third-party U.S. data brokers—or brokers that sell data they did not directly collect in the first instances—to sell, license, or otherwise transfer personally identifiable sensitive data of U.S. individuals to China, Russia, Iran, North Korea, or entities they control, with enforcement assigned to the Federal Trade Commission.

Each of these programs addresses some small portion of this risk to Americans’ personal data, but none of them address all of them in a comprehensive way that aims to secure the data itself.

The Justice Department’s Bulk Data Security Program

The Data Security Program was designed to address this risk. (The author previously served as the first deputy section chief for national security data risk in the Department of Justice National Security Division’s Foreign Investment Review Section, which houses the DSP.) The regulation prohibits or restricts covered data transactions, including outright sales, vendor agreements, employment relationships, and investment agreements, when they would give foreign adversaries (or “countries of concern” to use the rule’s parlance) access to bulk U.S. sensitive personal data or government-related data. The program, whose architecture is inspired by the Treasury Department’s sanctions programs and the Commerce Department’s dual-use export control regime, was an attempt by the Justice Department to shift the government’s posture away from this decade-long, largely unsuccessful, whack-a-mole approach to a horizontal, rule-based paradigm.

Rather than relying on case-by-case reviews of transactions, the DSP addresses the national security risk associated with foreign adversary access to Americans’ sensitive personal data through a complex set of rules, administered by the National Security Division, that require U.S. companies that possess this type of data to manage their individual data security risk. And the DSP can bring to bear significant civil and criminal enforcement for those companies that fail to do so. The Trump administration published information about this program in April 2025 through the release of a compliance guidance, a frequently asked questions set, and an enforcement memorandum; since then, the program has largely remained inert.

Some observers speculate that the Department of Justice now seeks to shift the DSP’s ministerial functions (for example, licensing, advisory opinions, covered list determinations, civil enforcement, and additional rulemaking) to another agency while focusing solely on criminal enforcement efforts. Doing so would untether the DSP’s ministerial functions from its enforcement ones and shift the DSP’s ministerial functions away from the department with the most appropriate expertise to implement and administer them.

Some of this speculation appears to correlate with the significant and well-documented staffing loss in the National Security Division, which houses the program; the program’s significant complexity (as demonstrated by the more than 700-page implementing regulation); and a broader geopolitical dynamic in which the U.S. government attempts to address foreign adversary-related technology and data security risks without mentioning China. For example, the recent FCC Covered List determinations prohibiting FCC authorization of certain drones, routers, inverters, and advanced robotics devices, while focused largely on the risk associated with Chinese manufacturers, are scoped so broadly as to apply to all foreign-made products other than those that can satisfy specific manufacturing reshoring requirements to obtain conditional approval from the Pentagon.

The budget picture tells the same story. The Trump administration’s fiscal year 2027 budget request includes no funding for the DSP. That omission is striking when measured against the resources Congress and the executive branch have committed to comparable national economic security regimes. The Comprehensive Outbound Investment National Security (COINS) Act authorizes $150 million for the Treasury Department to implement the Outbound Investment Security Program in each of fiscal year 2026 and fiscal year 2027. The Commerce Department’s ICTS program is housed within the Bureau of Industry and Security’s (BIS’s) Management and Policy Coordination account, which the fiscal year 2026 budget funds at roughly $30 to $40 million, though that account covers leadership and policy functions well beyond ICTS alone.

The DSP, by contrast, is the only one of these regimes that regulates the commercial data flows foreign adversaries are actively exploiting, yet it would receive nothing. In a supplemental appropriations request disclosed publicly to Congress, the Justice Department estimated that the DSP would require roughly $15 million annually to operate. This request is a fraction of what the Treasury and Commerce Departments devote to their adjacent authorities; a rounding error compared to the scale of the threat the program is designed to address. A program that can be made to work for $15 million—and that addresses a national security risk that no other authority truly reaches—should not go unfunded.

In the meantime, U.S. companies continue to spend significant resources to grapple with this complexity in building their compliance programs, mapping data flows, conducting data audits, managing data access by vendors, employees, and investors, and contemplating whether to request any advisory opinions or licenses from the Department of Justice to manage their enterprise’s risk exposure and minimize the program’s burden on their business. In other words, much of U.S. industry is trying to meet its end of the bargain to prevent foreign adversaries from gaining data access, but the Justice Department is simply not doing its part to meet them halfway.

The DSP should not be allowed to wither. The commercial vectors it regulates (brokerage, vendor, employment, and investment) are the vectors foreign adversaries use, and no other authority in the U.S. government addresses them comprehensively. Reducing the program to a criminal enforcement vehicle would gut its core function. Companies need licenses, advisory opinions, general licenses, and predictable rulemaking to build compliance programs and structure transactions in the first place. Without that regulatory scaffolding, enforcement has nothing to enforce against except the firms least equipped to navigate the rule. The harder path of fully resourcing the National Security Division, issuing the licenses and opinions companies are waiting on, and bringing the first civil enforcement actions is the one that makes the program work. And this path can be calibrated appropriately to reflect the timing it will take for the division to obtain these resources and develop the DSP’s ministerial functions.

The Justice Department Is the Right Home for the DSP

There was a suggestion during the rulemaking process, if not direct criticism, that the Department of Justice was not the appropriate agency to implement this program. Industry stakeholders, in the context of dozens of virtual and in-person engagements with DOJ, also regularly inquired as to why the program was housed at Justice Department and not, for example, Treasury’s Office of Foreign Assets Control (OFAC) or Commerce’s BIS, two agencies with which the industry regularly engages on economic security issues within their regulatory purview  But this line of inquiry reflects misreading of what the program is and a lack of understanding of the expertise that the Justice Department brings to bear.

Treasury’s regulatory tools, OFAC and CFIUS, were built for asset freezes and investment review, respectively. Neither is structured to administer the kind of conduct-based, intent-sensitive rule that bulk data requires. To be sure, according to public reporting CFIUS has struggled to mitigate data-related risk as it arose in TikTok’s acquisition of Musical.ly and Tencent’s video game investments in Epic, Riot, and Supercell reflects, in part, the challenge of using CFIUS to “box out” an adversary investor from having access to a U.S. acquiree’s sensitive personal data. While OFAC has some blanket sanctions programs (for example, Cuba and North Korea). OFAC’s strength is list-based, entity-specific prohibitions, whereas the DSP is calibrated to transaction types, data categories, bulk thresholds, and end uses. By contrast, CFIUS reviews specific covered transactions on a case-by-case basis. The DSP operates at the level of categorical rules of general applicability.

Commerce’s ICTS authority is closer in form, and the two regimes share architects and structural DNA. Indeed, the national emergency declared in Executive Order 13873 is a through line to the risk identified in and addressed by Executive Order 14117 and its implementing regulations. But ICTS sits in a department whose primary mission is to promote U.S. industry. Commerce will always be asked, correctly, to weigh national security restrictions against the commercial interests of the regulated entities. That balance may be appropriate for export controls and supply chain security where U.S. competitiveness is a policy interest at stake.

It is not appropriate for a rule whose entire purpose is preventing U.S. firms from selling or providing sensitive data to adversary buyers or acquirers, where the commercial interest of the regulated firm and the national security interest of the United States are so directly opposed. Further to this point, the tension between national security and commercial interest is likely one of the fundamental reasons why the ICTS program has struggled in its seven years of existence. Despite having broad authority, ample resourcing, staffing and career leadership with deep national security expertise and ambition, and an aggressive regulatory agenda, the program has been responsible for exactly two actions since the ICTS executive order was signed in 2019: the prohibition on the sale of Kaspersky software and the Connected Vehicles rule. The risk to U.S. persons' sensitive data is such that this lack of action simply will not suffice.

The Department of Justice is structurally suited to administer the program for four reasons. First, the National Security Division has the prosecutorial, intelligence, and regulatory experience to handle the classified inputs that drive scoping decisions about countries of concern, covered persons, and license determinations. Second, the Justice Department’s culture is comfortable with the conduct-based, fact-intensive analysis the rule requires, including the kind of intent inquiries that arise when assessing knowing violations and willful blindness. (In writing this article, the author extends his appreciation to the dozen-plus people in the Foreign Investment Review Section data security unit and the section more broadly, the National Security Division, and the Justice Department who undertook the herculean effort of building this program from the ground up.)

Third, the department does not have a competing institutional interest in promoting the regulated industry. That lack of interest is necessary to administer and enforce a rule that asks U.S. firms not to enter profitable transactions. And finally, the Justice Department has the benefit of serving as the nation’s predominant counterintelligence agency. It is the FBI’s body of investigative work on hybrid commercial threats, or commercial entities that operate at the behest of foreign adversaries. Ultimately, the risk that the DSP seeks to address is a counterintelligence one, and no other department or agency is more appropriate to address that risk through the DSP than the Department of Justice.

The Program Must Be a Regulatory Regime, not Just an Enforcement One

The temptation in any new national security authority is to lead with cases. Finding an obvious and willful DSP violator to “make an example of” is an easy way to raise the program’s deterrent profile. But while prosecutions generate headlines and can create support for resources, they are also slow, resource intensive, and dependent on identifying evidence sufficient for criminal or civil enforcement. And the program’s complexity in this case may create challenges with showing the requisite “willfulness” alleged in a violation, which is necessary to bring criminal charges against the offending companies and individuals.

More importantly, a program focused only on criminal enforcement will fail to address the threat at scale. Most covered transactions are conducted by firms that want to comply but do not know how and will not be reached by enforcement actions against bad actors. The regulatory infrastructure required to shrink the flow of sensitive personal data to countries such as China—including general licenses, advisory opinions, FAQs, examination expectations, recordkeeping standards, and a voluntary disclosure path—is at least as important as the enforcement docket.

That infrastructure must be built deliberately and resourced separately from the prosecutorial function. Industry will not invest in compliance programs for a regime that cannot answer questions in reasonable time. Foreign counterparties will not adjust their practices for a regime that does not publish guidance showing them how to do so. The program’s deterrent effect depends on its predictability as much as its severity.

Recommendations

Standing up a program of the DSP’s magnitude and complexity, particularly in a moment in which the Department of Justice is severely under-resourced, is no doubt a daunting task. Yet a viable approach exists that will allow the program to scale commensurate with the Justice Department’s resources while giving industry time to comply.

Sequence Implementation and Enforcement of the Program

Start with genomics followed by data brokerage, and then scale accordingly. Genomics presents the clearest national security case (for example, support for an adversary’s military capabilities and biological weapons programs), the smallest regulated population, and the most sophisticated stakeholders. The data broker industry is likely the largest commercial flow and the area where the rule will produce the most measurable risk reduction. The genomics sector is reachable with minimal staffing if implementation is sequenced rather than launched simultaneously across all six covered data categories. Data brokerage should come second, after any initial staffing increase beyond current levels. The restricted transaction set should phase in as the Justice Department obtains additional resources.

Build Out the Regulatory Infrastructure Before Scaling Enforcement

That means—beginning with the prohibition on genomics—standing up a general and specific licensing program, a working advisory opinion process with reasonable turnaround times, and clear FAQ guidance on the most frequent compliance questions. It also means a voluntary self-disclosure framework with meaningful credit for firms that file appropriately, as firms with sophisticated compliance functions are the most likely to identify their own violations in the genomics sector and the most useful source of factual development to expand the program.

Focus Enforcement on Willful Violations

The program will not have the resources to investigate every potential violation, and enforcement priorities should reflect that. Cases involving knowing transfers to countries of concern, structured transactions designed to evade the rule or to conduct a transaction through “knowing direction,” and willful violations by firms with existing compliance programs should be the priority. For surfacing those cases, the program should rely on the mechanisms that have worked in adjacent regulatory regimes: whistleblower complaints with appropriate financial incentives, plaintiff’s bar civil litigation under adjacent privacy and consumer protection authorities, and interagency referrals from the U.S. intelligence community and from other national security programs such as CFIUS, Team Telecom, and ICTS. The program does not need to generate its own investigative leads to be effective; it needs to make external information actionable.

Codify the Program in Statute

The DSP currently rests on a single executive order and an International Economic Emergency Powers Act (IEEPA)-based rulemaking. That foundation is functional but fragile. A future administration can rescind Executive Order 14117, narrow the rule, or simply decline to enforce it, and the entire architecture industry now investing in it disappears.

Two national security regimes show how to fix this. CFIUS began as a 1975 executive order, gained statutory footing in the 1988 Exon-Florio amendment to the Defense Production Act, and was rebuilt as a modern, mandatory-filing regime in the 2018 Foreign Investment Risk Review Modernization Act. The Outbound Investment Security Program was established by Executive Order 14105 in August 2023, implemented through January 2025 regulations, and codified in statute through the COINS Act in the National Defense Authorization Act for Fiscal Year 2026 in December 2025. Both programs gained durability, clearer authority, dedicated appropriations, and bipartisan political support by moving from executive order to statute. Congress should give the DSP the same treatment.

A DSP statute should codify the country-of-concern designation process, the covered data categories and bulk thresholds, the prohibited and restricted transaction structures, the National Security Division’s administering role, and a civil and criminal enforcement framework that does not depend on IEEPA. It should also authorize dedicated appropriations rather than forcing the program to compete for resources within the National Security Division’s existing budget lines.

Resource the Program at a Level Commensurate With Its Mission

A regulatory regime as broad as the DSP needs dedicated licensing staff, advisory-opinion staff, and policy and regulatory attorneys, staffed at a level closer to OFAC than to a typical National Security Division section. Recognizing that in the current austere budget environment, it is likely impossible to request an appropriation significant enough to staff the entire program, the Justice Department should consider smaller, more incremental requests to build out the staff over time. Congress can then appropriate accordingly.

Now Is the Window

The DSP is the first U.S. regulatory regime designed specifically to address the commercial means by which foreign adversaries acquire Americans’ sensitive personal data. It addresses a real and growing threat through a more holistic regulatory authority, with an architecture that maps to the types of commercial transactions known to implicate this risk, and is housed in an institution with the cultural and legal infrastructure to administer it. What it needs now is implementation, resources, human capital, and a clear-eyed acceptance that the compliance programs combined with a wave of headline enforcement cases is what will move adversary data acquisition off the commercial market.

Get the next 18 months right, and the program becomes a durable piece of the U.S. national security toolbox. Get them wrong, and it becomes another China-focused paper tiger authority with a thin track record and an uncertain future—except for the certainty that foreign adversaries will continue collecting and using this data to our detriment.


Lee Licata is a national security and technology policy leader with nearly two decades of experience spanning telecommunications, data security, emerging technology, technology supply chain security, and international trade. He has served in senior roles across the U.S. Department of Justice, the White House, and the Department of Homeland Security, where he has led major policy, regulatory, and interagency initiatives to safeguard U.S. national and economic security.
}

Subscribe to Lawfare