{"data":{"id":"us/28-cfr-202.1001","jurisdiction":"us","citation":"28 CFR 202.1001","heading":"Due diligence for restricted transactions.","body":"(a) Data compliance program. By no later than October 6, 2025, U.S. persons engaging in any restricted transactions shall develop and implement a data compliance program.\n(b) Requirements. The data compliance program shall include, at a minimum, each of the following requirements:\n(1) Risk-based procedures for verifying data flows involved in any restricted transaction, including procedures to verify and log, in an auditable manner, the following:\n(i) The types and volumes of government-related data or bulk U.S. sensitive personal data involved in the transaction;\n(ii) The identity of the transaction parties, including any ownership of entities or citizenship or primary residence of individuals; and\n(iii) The end-use of the data and the method of data transfer;\n(2) For restricted transactions that involve vendors, risk-based procedures for verifying the identity of vendors;\n(3) A written policy that describes the data compliance program and that is annually certified by an officer, executive, or other employee responsible for compliance;\n(4) A written policy that describes the implementation of the security requirements as defined in § 202.248 and that is annually certified by an officer, executive, or other employee responsible for compliance; and\n(5) Any other information that the Attorney General may require.","path":["Title 28—Judicial Administration","CHAPTER I—DEPARTMENT OF JUSTICE","PART 202—ACCESS TO U.S. SENSITIVE PERSONAL DATA AND GOVERNMENT-RELATED DATA BY COUNTRIES OF CONCERN OR COVERED PERSONS","Subpart J—Due Diligence and Audit Requirements"],"source_url":"https://www.ecfr.gov/api/versioner/v1/full/2026-08-25/title-28.xml","current_through":"2026-08-25","vintage":"","retrieved_at":"2026-08-27T02:25:14Z","sha256":"fc0f95d36452980bd3910460c148adf019b8a5903af531d646103545158a0567","source_id":"us-cfr","stale":true,"prev":"us/28-cfr-202.901","next":"us/28-cfr-202.1002"},"notice":"GroundRules: Original legal text. Not legal advice."}
