EO 14117

EO 14117 is in enforcement — a gate every US-bound company must clear

China (including Hong Kong and Macau) is a country of concern: for China-affiliated businesses, transactions in Americans' bulk sensitive data are either prohibited outright or carry strict conditions.

The DOJ final rule took effect April 8, 2025, and the compliance buffer ended October 6, 2025; enforcement can begin at any time. Chinese companies with a US presence are first in line — and even those without one are pushed by US counterparts to contract through a US entity, amend contracts, and support diligence.

End-to-end analysis · Field-level sensitive-data discovery · Trusted by nearly 200 leading global enterprises

2025-10-06
compliance buffer has ended; affirmative obligations are fully in force
$368,136
maximum civil penalty (or twice the transaction value, whichever is greater)
20 years
maximum prison term for willful violations, plus up to $1M criminal fine

What does EO 14117 cover?

The order prohibits or restricts US persons from engaging in specific data transactions involving bulk sensitive personal data and US government-related data with countries of concern and restricted persons. Three elements must converge for a transaction to fall in scope: who transacts, with whom, and what data changes hands.

Countries of concern include China (incl. HK & Macau)

The list covers China (including Hong Kong and Macau), Russia, Iran, North Korea, Cuba, and Venezuela. Entities majority-owned (50%+) by a country of concern, incorporated under its laws, or with their principal place of business there — plus their controlled subsidiaries, employees, and principal-domicile individuals — are restricted persons.

Prohibited transactions: off-limits

Data-broker transactions (sales, licensing of access, or similar transfers to recipients with no direct relationship) and human-genomic-data transactions are wholly prohibited once thresholds are met — there is no room to remediate.

Restricted transactions: allowed with conditions

Vendor agreements, employment agreements, and investment agreements are restricted transactions: they must meet CISA security requirements and carry due-diligence, audit, reporting, and record-keeping obligations.

Anonymization and encryption are no exemption

Bulk status is measured by cumulative volume over the prior 12 months, whether the data is anonymized, pseudonymized, de-identified, or encrypted. Only effective safeguards recognized by CISA are accepted.

Bulk sensitive-data thresholds (12-month cumulative)

Data typeThreshold
Human genomic dataMore than 100 US persons
Human omic data (epigenomic, proteomic, transcriptomic)More than 1,000 US persons
Biometric identifiers (face, voiceprint, fingerprint, etc.)More than 1,000 US persons
Precise geolocation data (within 1,000 meters)More than 1,000 devices
Personal health dataMore than 10,000 US persons
Personal financial dataMore than 10,000 US persons
Specified personal-identifier combinationsMore than 100,000 US persons

Why China-linked businesses must act

This is not a rule that only giants run into. If you do business or hold data in the US, either of two typical setups is already in scope.

Businesses with a US entity

Data of your US company or subsidiary must not be transferred across the border to data centers, parent companies, or affiliates in China; cross-border access by China-based employees and third-party vendors is restricted too, and hiring for sensitive roles also counts as a restricted transaction.

Businesses without a US entity

If any party upstream or downstream is a US company, you will be asked to contract through a US entity, amend contract clauses, respond to diligence, and assume compliance responsibility. Without preparing in advance, you accept conditions passively at the negotiating table.

Enforcement is already in place

The DOJ's National Security Division (FIRS) holds investigation, hearing, and subpoena powers. The buffer ended in October 2025; violations now carry both civil and criminal exposure.

How Kaamel helps

Powered by end-to-end analysis and field-level sensitive-data discovery, we turn EO 14117 from legal text into a checklist you can verify item by item.

  1. 01

    Full data-transaction mapping

    We scan client, server, and third-party flows, recognize sensitive personal data by field across collection, storage, and movement, and flag every transaction that touches a country of concern or a restricted person.

  2. 02

    Applicability judgment and classification

    Against the thresholds and person definitions, each transaction is classified as prohibited, restricted, or out of scope, with the reasoning recorded. For prohibited deals we propose alternative architectures; for restricted ones we list the conditions for release.

  3. 03

    Remediation and CISA delivery

    Data-architecture changes, access isolation, and contract amendments, plus the technical and organizational measures that map to CISA security requirements — with due-diligence, audit, reporting, and record-keeping obligations stood up.

  4. 04

    Sustained compliance and enforcement readiness

    Pre-assessment mechanisms for new business, new vendors, and new hires, plus an evidence package for US customer diligence and regulator inquiries — so your compliance stays maintainable and provable.

Want a timeline and a quote for your case?

Why Kaamel

EO 14117 is hard because it tests legal reading, data engineering, and China-US coordination at once — exactly our combination.

A technology engine, not interviews

End-to-end analysis and field-level sensitive-data discovery automate the data map — faster than questionnaire interviews and closer to the evidence standard regulators recognize.

We know the rule and your architecture

Silicon Valley and Asia teams deliver in Chinese and English. We read the DOJ rule and understand how Chinese companies are really structured — ownership, hiring, and data.

Reuse what you already built

The security requirements of EO 14117 overlap heavily with SOC 2 and ISO 27001 controls; existing controls count toward the gap rather than being rebuilt.

Industry playbooks in hand

Our EO 14117 impact analysis and response for gaming, consumer electronics, manufacturing, and enterprise services have been refined across client engagements and industry talks.

What's included

  • Full data-transaction mapping and a sensitive-data map
  • Applicability report and transaction-classification list
  • Alternative-architecture options for prohibited transactions
  • CISA security-requirements gap assessment and delivery
  • Contract-clause amendments and vendor due-diligence support
  • Due-diligence, audit, reporting, and record-keeping mechanisms
  • Readiness for US customer diligence and regulator inquiries
  • Pre-assessment process for new business

EO 14117: frequently asked questions

We do not have a US subsidiary. Does EO 14117 still apply to us?

The direct obligations fall on US persons, but the impact travels through contracts: US companies upstream or downstream will ask you to contract through a US entity, amend clauses, cooperate with diligence, and assume compliance responsibility. Map your data transactions in advance — that is where your leverage at the negotiating table comes from.

We are a Singapore company doing business in the US, and we are not majority-owned (over 50%) by a Chinese or China-based entity, but we employ many Chinese nationals. Are we subject to EO 14117?

EO 14117 defines a Covered Person as: 1. A restricted entity: an entity that is 50% or more owned, directly or indirectly, by a country of concern, organized under the laws of a country of concern, or whose principal place of business is in a country of concern; 2. A foreign entity: an entity that is 50% or more owned, directly or indirectly, by a restricted entity; 3. A foreign employee or contractor: an employee or contractor of an entity that is a country of concern or a restricted entity, and who is a foreign person; 4. A foreign person: a foreign person whose principal residence is in a country of concern (excluding US persons, unless they are otherwise on the list); 5. Any person or entity the Attorney General designates as restricted. Notice there is no employee-nationality requirement: a foreign person only meets the definition if their principal residence is in a country of concern — a Chinese national living long-term in Singapore on a work visa, for instance, does not. Nor does your corporate entity meet definitions 1, 2, or 3. So there is exactly one scenario in which the company would be subject to EO 14117: the US Attorney General designating the company or its employees as Covered Persons.

Our US business data sits in a US region of a data center. Are we free of compliance risk?

EO 14117 is concerned with whether countries of concern and Covered Persons can access Covered Data — it is not a simple data-localization requirement.

The US data flowing back from our product R&D all stays in a US region of a data center. Do we still need a cross-border risk assessment?

Product R&D is not the only path that moves data across borders. In real cases, operations teams have run database synchronization across regions or even across clouds, and that sync service can move US personal data into a country of concern. Data analytics and even routine business-operations needs can likewise be configured with data or file sync services that produce cross-border transfers.

If our data is encrypted or anonymized, is it still restricted?

Yes. Bulk status does not depend on the form of the data: anonymized, pseudonymized, de-identified, and encrypted data all count toward the 12-month cumulative volume. Only methods that meet CISA-recognized standards and effectively prevent re-identification and access are accepted — which has to be assessed item by item.

If we have no prohibited transactions, then as long as we meet the CISA security requirements for our restricted transactions, can we access Covered Data from a country of concern?

The CISA security requirements include, at the organizational and system level (item B), logical and physical access controls that prevent covered persons or countries of concern from accessing covered data that does not meet the data-level requirements, and at the data level, a combination of mitigation measures that, taken together, are sufficient to fully and effectively prevent covered persons or countries of concern from accessing covered data that is linkable, identifiable, unencrypted, or decryptable using commonly available technology. Cross-border access to Covered Data from a country of concern is therefore not itself consistent with the CISA security requirements.

The vendor our US subsidiary works with is not a Covered Person, but the vendor employs Covered Persons to process US personal data. Would we be judged in violation?

Under Example 8 of the EO 14117 Final Rule, where the vendor did not hire Covered Persons to process US personal data at the subsidiary's direction or as a deliberate attempt to evade the compliance requirements, the vendor agreement between the subsidiary and the vendor is not a restricted transaction and the subsidiary is not judged in violation.

What exactly are the costs of a violation?

Civil penalties reach a maximum of $368,136 or twice the transaction value, whichever is higher; willful violations additionally carry a criminal fine of up to $1 million and up to 20 years in prison. Enforcement sits with the DOJ's National Security Division, which holds investigation, hearing, and subpoena powers.

Unsure whether your data transactions cross the line?

Book a free assessment — we first map your data transactions and entity relationships, flag what is prohibited or restricted, and only then talk about how to fix it.