For most of the internet era, the answer to "may we move this data offshore?" was, from a U.S. perspective, yes. Unlike the European model, U.S. law contained no general prohibition on transferring personal data across borders. What restrictions existed came from specific sectors, specific technologies, or specific contracts.

That is no longer a complete description. As of mid-2026, a national-security-driven regime restricting access to Americans' bulk sensitive personal data by certain countries sits alongside the older sector rules, and it is newly operative and still evolving. Meanwhile, the harder constraints for many U.S. companies continue to come from the other direction: foreign law governing data that flows into the United States.

The U.S. default, and where it stops

Neither the state comprehensive privacy statutes nor the FTC's general authority impose a location requirement on personal data. California's law, for example, grants rights and imposes contract duties without restricting geography; the Attorney General's CCPA materials reflect an obligations-based rather than a borders-based model. What state law does require is that your processor contracts hold up wherever processing happens, which is a contract-drafting problem rather than a transfer-permission problem.

Four other bodies of law do restrict movement, and they existed long before the current wave of attention:

  • Export controls. Technical data and encryption-related software are subject to export administration rules, and releasing controlled technical data to a foreign national — even inside the United States — can constitute an export. Defense-related technical data carries its own stricter regime.
  • Government contracts. Federal cloud authorization programs, controlled unclassified information requirements, and agency-specific clauses routinely mandate U.S.-only storage and U.S.-person access.
  • Sector statutes. Health and financial regulators do not forbid offshore processing outright, but impose vendor-oversight, confidentiality, and examination-access duties that offshore arrangements must satisfy.
  • Consumer commitments. A privacy notice or customer contract promising U.S.-only processing is enforceable on its own terms; breaking it is both a contract breach and, potentially, a deceptive practice under the standards described in the FTC's privacy and security business guidance.

The bulk sensitive data program

In 2024 an executive order directed the creation of a program restricting transactions that give countries of concern, and persons subject to their jurisdiction, access to bulk U.S. sensitive personal data and to certain government-related data. The Department of Justice built the implementing rules, which took effect during 2025 with additional diligence, audit, and reporting obligations phasing in afterward. As of mid-2026 the program is operative and its interpretive guidance continues to develop.

Three features make it different from ordinary privacy compliance. First, it is a national-security control, so it prohibits or conditions entire categories of transaction rather than granting individual rights. Second, it keys to access, including remote administrative access by personnel abroad, not merely to storage location. Third, thresholds matter: the restrictions attach at defined volumes of records within a rolling period, and those volumes differ by data type.

  1. Identify covered data. Categories include personal identifiers, precise geolocation, biometric identifiers, human genomic and related biological data, personal health data, and personal financial data, along with data linked to government personnel or facilities.
  2. Measure volume. Compare your holdings against the applicable thresholds, remembering that combined datasets can cross a line no single dataset reaches.
  3. Map counterparties. Look through the direct contract to ownership, control, and personnel location. An offshore development center or a support desk staffed abroad is exactly the kind of access the program contemplates.
  4. Classify transactions. Some categories, notably data brokerage and certain genomic transfers, are prohibited outright. Others — vendor, employment, and investment agreements — are permitted subject to security requirements.
  5. Apply security requirements. Where a transaction is restricted rather than prohibited, compliance depends on specified organizational and technical safeguards, plus diligence and recordkeeping.
  6. Document the analysis. Keep the volume calculations, the counterparty assessment, and the conclusion. The reasoning is the deliverable if you are ever asked.

Watch out: This regime is not satisfied by a data processing agreement. A perfectly drafted DPA does not authorize a transaction the program prohibits. Run the national-security analysis separately from, and before, the privacy analysis in your processor contracts.

What foreign law adds when data comes to you

For many U.S. companies the binding constraint is European rather than American. The EU and U.K. regimes prohibit transfers of personal data outside their territory unless a recognized mechanism applies: a determination that the destination provides adequate protection, standard contractual clauses, binding corporate rules, or a narrow derogation. A transfer includes remote access from the U.S. to a database sitting in Europe.

The Department of Commerce administers the U.S. side of the transatlantic framework through which participating U.S. organizations self-certify to a set of principles and become an approved destination for European data; the Commerce Department is the authoritative starting point for current program details and participation requirements. Frameworks of this kind have been challenged and replaced before, so most companies maintain standard contractual clauses as a fallback even when certified.

Beyond Europe, an increasing number of countries impose localization or approval requirements — for financial records, health data, mapping data, or government-related information. Requirements vary substantially by country, and the practical question is usually not whether a transfer is theoretically permitted but whether your architecture can segregate the affected data at all.

Building a transfer map you can maintain

The document that answers all of these questions is the same one: an honest map of where data goes and who can reach it. Most companies discover on first attempt that their real map differs from the diagram in the security questionnaire.

What a usable transfer map records for each data flow
FieldWhy it matters
Data categoriesDetermines which sensitive-data and sector rules attach
Volume and growthThreshold-based restrictions turn on counts, not intentions
Storage locationBaseline for localization and contract commitments
Access locationRemote access is the exposure most maps omit entirely
Counterparty ownershipControl and jurisdiction, not just the entity on the invoice
Transfer mechanismClauses, certification, or derogation relied upon, with dates
Technical controlsEncryption, key custody, and access segregation actually deployed

Practical step: Key custody is the most underused control. Encrypting data at rest matters far less if the offshore team holds the keys and full administrative rights. Separating key management from processing changes the risk profile of many flows, and the NIST Privacy Framework offers a structure for documenting those decisions.

Contracts carry the rest of the load. Vendor agreements should identify processing and access locations, require notice before adding a new country or offshore support team, flow obligations down the subprocessor chain, and give a termination right if a location change creates a compliance problem. Those provisions belong in the same negotiation as the rest of your software and SaaS terms, alongside the breach-notification clauses that determine what you learn, and when, if something goes wrong abroad.

Quick answers

Does storing data in a U.S. data center solve the problem?

Not by itself. Modern restrictions focus on access as much as storage. If engineers, support staff, or subprocessors outside the country can reach the data remotely, a U.S. data center does not end the analysis. Map who holds credentials and administrative rights, not only where the disks are, and treat remote access as a transfer for planning purposes.

We are a small company with an offshore development team. Is the bulk data program our concern?

Possibly, depending on data categories, volumes, and where the team is located. The thresholds mean many small companies fall outside, but data types like precise geolocation or health information reach the restrictions at lower volumes than people expect. Run the calculation, write down the result and the date, and repeat it when the data set grows or the vendor arrangement changes.

Do we need standard contractual clauses if we are certified under the transatlantic framework?

Certification can be sufficient for covered transfers while it remains in force, but many companies keep clauses in place as a fallback because arrangements of this kind have been invalidated in the past. Maintaining both is inexpensive relative to rebuilding a transfer mechanism under time pressure, and enterprise customers frequently require the clauses regardless.

How should we handle a vendor that will not disclose its processing locations?

Treat non-disclosure as a finding. You cannot document a flow you cannot see, and both the national-security analysis and any European mechanism depend on knowing where processing occurs. Ask for the subprocessor list with locations as a condition of renewal; if it is refused for anything sensitive, escalate the risk decision to whoever owns it rather than signing around the gap.

Your next moves

Build the transfer map before reading another summary of the rules — nearly every question depends on facts only the map supplies. Then run three separate screens over each flow: national-security restrictions on bulk sensitive data, sector and export-control rules, and inbound obligations imposed by foreign law. Fix contracts to require location transparency and change notice, and move key custody where it does the most good. Recheck on a schedule, because this area will look different in a year. Related guides on vendor terms, workforce records, and interface rights sit in the technology, privacy, and IP pathway, and the applicability thresholds behind much of it are set out in the state privacy law map.