Coated individuals: This system will likely be outlined categorically to incorporate sure lessons of entities and people topic to the jurisdiction, path, possession, or management of nations of concern, if knowledge to those individuals will place that knowledge inside the attain of the international locations of concern. The EO defines 4 classes of lined individuals:
- “An entity owned by, managed by, or topic to the jurisdiction or path of a rustic of concern”
- “A international one that is an worker or contractor of such an entity”
- “A international one that is an worker or contractor of a rustic of concern” and
- “A international one that is primarily resident within the territorial jurisdiction of a rustic of concern”
Based on the EO and the ANPRM, the classes of lined individuals wouldn’t embrace anybody who’s a US citizen, nationwide, or lawful everlasting resident, anybody admitted to america as a refugee or granted asylum, any entity organized solely underneath US legal guidelines or jurisdiction, and any particular person positioned in america.
The EO additionally authorizes DOJ to complement these classes of lined individuals by designating particular entities or people as lined individuals in the event that they meet sure standards, equivalent to being owned or managed by or topic to the jurisdiction or path of a rustic of concern or appearing on behalf of a rustic of concern or one other lined particular person.
Delicate private knowledge: The EO defines “delicate private knowledge” to imply lined private identifiers, geolocation, and associated sensor knowledge, biometric identifiers, private well being knowledge, human genomic knowledge, private monetary knowledge, or any mixture thereof that might be exploited by a rustic of concern to hurt United States nationwide security if that knowledge is linked or linkable to any identifiable United States particular person or a discrete and identifiable group of United States people.
The DOJ plans to refine the scope of those delicate private knowledge classes additional in its rulemaking. Delicate private data won’t embrace knowledge that could be a matter of public report, equivalent to courtroom or different authorities information, that’s lawfully and customarily obtainable to the general public or private communications.
Bulk thresholds and US government-related knowledge: The DOJ’s program will typically regulate the required classes of information transactions within the six classes of delicate private knowledge provided that the transactions exceed prescribed bulk volumes (i.e., a threshold variety of US individuals or US units). Nevertheless, these bulk volumes wouldn’t apply to transactions involving sure US government-related knowledge. This system will regulate knowledge transactions involving delicate private knowledge on US authorities personnel or areas whatever the quantity of such knowledge.
For presidency-related personnel knowledge, the ANPRM will ponder specializing in delicate private knowledge {that a} transacting occasion (equivalent to a knowledge dealer) markets as linked or linkable to present or latest former staff or contractors or former senior officers of the federal authorities, together with the intelligence neighborhood and navy. For US government-related knowledge on areas, the ANPRM will ponder specializing in geolocation knowledge that’s linked or linkable to sure delicate areas inside geofenced areas that the Division would specify on a public listing.
Coated knowledge transactions: The forthcoming ANPRM contemplates figuring out two classes of prohibited knowledge transactions between US individuals and international locations of concern or lined individuals: