DOJ Bulk Data Rule: Geolocation Licensing Thresholds
Geolocation thresholds are low enough that thousands of devices, not millions, can trigger duties, and government-related sensitive data may carry no volume exception at all. Covered-person and country-of-concern definitions turn on ownership, so an IP check is not diligence. Enterprise buyers increasingly import the federal contract language into commercial deals.
How to use this article
Read the checklist here, then use the linked hub and product pages for procurement citations.
The Department of Justice bulk sensitive personal data rule (see Federal Register NPRM and final rule materials) restricts certain transfers of US sensitive personal data to countries of concern and covered persons. For precise geolocation, the bulk threshold is data on more than 1,000 US devices at any point in the preceding 12 months (28 CFR 202.205(c)): a volume many mobility brokers exceed in a single metro pilot. Government-related data categories may lack a volume safe harbor. Data brokers licensing global mobility, POI geofencing, and maid feed must map buyer corporate trees, cloud regions, and end users before transfer. Align with PADFAA screening and federal procurement artifacts.
Sensitive Categories and Volume Thresholds
The rule enumerates sensitive personal data classes, including precise geolocation, human genomic data, biometric identifiers, personal health data, financial data, covered personal identifiers, and certain government-related data. Thresholds vary by category: geolocation meets the threshold at data on more than 1,000 US devices in the preceding 12 months when transferred to a country of concern or covered person. Brokers selling national mobility panels blow past that threshold routinely. Coarse mobility still demands analysis: combined with MAIDs, home-work inference, or venue labels, coarse data can become functionally precise.
Read the rule alongside Executive Order 14117 framing. DOJ implementation translates policy into licensing mechanics brokers feel in MSAs. The Department of Justice overview summarizes category definitions buyers can paste into security reviews.
Precise geolocation: device traces, visit-level feeds, many POI visit products.
Biometric identifiers: face and voice templates; see BIPA guide.
Covered personal identifiers: when bundled with other sensitive fields under rule definitions.
Government-related data: treat as restricted regardless of hobbyist "small batch" assumptions.
Countries of Concern and Covered Persons
The rule targets transfers to defined countries of concern and entities meeting covered person tests (foreign adversary nexus, military-industrial ties, etc.). Screening must include beneficial ownership, subsidiaries, and cloud administrative access: a US-incorporated buyer owned by a covered foreign entity is the classic failure mode. PADFAA uses overlapping adversary lists; operate one matrix for both regimes. Reference CFIUS thinking for M&A re-reviews when buyers change parents mid-contract.
Subprocessors and analytics vendors in third countries still matter: transfer includes access, not only disk location. Document subprocessors in /trust/security-program and DPA exhibits.
Licensed analytics consultancies in countries of concern can be covered-person access even when the buyer is US-based: sublicensing clauses must require written approval before any consultant environment touches sensitive fields. The same rule applies to offshore labeling vendors reviewing raw mobility traces.
Vendor Operations: Counting, Blocking, and Logging
Maintain rolling device counts per buyer entity for geolocation SKUs. Do not wait for annual true-ups.
Enforce geo-blocks on download endpoints and query APIs for restricted destinations.
Log denied transfer attempts and buyer attestations: retain for audits.
Re-screen after corporate restructuring, cloud region migration, or new sublicensees.
Mobility vendors should cross-check FTC sensitive location orders. FTC defines consumer-harm patterns; DOJ defines export-style transfer limits. A feed can be FTC-compliant yet fail DOJ transfer rules if hosted by the wrong entity.
Contract Language Federal and Enterprise Buyers Expect
Include: transfer prohibitions to countries of concern and covered persons; volume attestations; sublicense approval; audit rights; 72-hour breach notification for impermissible access; and termination for screening failures. Federal buyers add DFARS-style flow-downs; commercial banks and telcos paste the same clauses for supply-chain risk. Link product schedules to global mobility delivery specs so precision claims match contract definitions of "precise geolocation."
Indemnity and compliance representations should be specific: "compliant with all laws" without screening methodology fails enterprise security review. Use RFP scorecard governance columns for transfer risk.
Historical archives raise retroactive transfer questions: if a buyer already stored three years of geolocation before screening matured, counsel may require deletion or segmentation of legacy partitions. New licenses should state that pre-effective-date archives are out of scope or must be certified clean.
Buyer Playbook Before Licensing Mobility at Scale
Map minimum viable geography: do you need national US mobility or three DMAs? Right-size volume to business need and document aggregation if device-level traces are not required. For measurement, prefer aggregate cross-channel measurement outputs over raw traces when possible. Run geo-panel audit and sensitive location checklist in the same diligence pass as DOJ screening.
Treasury and Commerce export-control updates can expand countries of concern lists faster than vendor contracts update: build a regulatory watch step into quarterly business reviews. When lists change, trigger re-screening of active buyers even if contract term has not expired.
Identity-only buyers licensing core email file without geolocation still need PADFAA/DOJ review when files contain government IDs, health fields, or genomic data: geolocation is not the only triggered category.
Cloud architecture matters: data replicated to backup regions in countries of concern can be a transfer even when primary processing stays in the US. Map replication, analytics replicas, and disaster-recovery failover in the same questionnaire as primary hosting. For developers integrating APIs, require buyer certificates that name every environment (prod, staging, DR) that will hold sensitive fields.
When pilots convert to production, re-count devices: a three-market pilot under 1,000 devices can exceed thresholds nationally within weeks. Build renewal clauses that force re-screening when volume tiers change or when buyers add sublicenses.
Joint ventures and SPVs confuse screening: ask whether the licensee entity or the funding parent is the counterparty. If both can access storage, both need clearance. Escrow arrangements where data sits with a US trustee still require analysis of who can direct decryption.
Volume counters should be SKU-specific: a buyer under threshold on email may be over threshold on mobility; do not net across unrelated sensitive categories without counsel guidance. Export monthly transfer reports to buyers upon request so they can prove compliance to their regulators and boards. Reports should list unique US device identifiers counted, not just row volumes, because duplicate events inflate row counts without increasing covered risk.
Buyers building location, foot-traffic, or geofence programs can scope POI data with polygon coverage, brand hierarchy, and a refresh schedule set per dataset before production licensing.
Frequently Asked Questions
Does the DOJ bulk data rule apply only to government contracts?
The rule is regulatory, not only FAR/DFARS flow-downs. Commercial enterprise buyers increasingly paste the same transfer prohibitions for supply-chain risk management.
Is coarse ZIP-level mobility below the thresholds?
Coarse data may avoid precise geolocation definitions, but combining ZIP with timestamps, venue names, or MAIDs can increase sensitivity. Evaluate holistically. Do not rely on labeling alone.
How does the 1,000-device geolocation threshold work?
The rule counts US devices over the preceding 12 months, aggregated across covered data transactions involving the same U.S. person and the same foreign person or covered person: many commercial pilots exceed 1,000 devices in a single market. Count before you close.
What is the relationship between DOJ rule and PADFAA?
Both restrict sensitive US person data flows toward foreign adversaries; PADFAA is statutory broker-focused law, DOJ adds category thresholds and covered-person tests. One screening program should satisfy both.
Where should GSDSI buyers document DOJ compliance?
✓ Opt-Out Request Honored via Global Privacy Control
We use cookies and similar technologies to improve your experience. No marketing cookies are pre-selected. Learn more in our Privacy Policy. Your Privacy Choices.