Data Protection and Privacy 2025

USA TRENDS AND DEVELOPMENTS Contributed by: Paul Lanois, Fieldfisher

address the national security threat posed by “countries of concern” (and covered persons that they can leverage) accessing and exploit - ing Americans’ bulk sensitive personal data and certain US government-related data. The “coun - tries of concern” include China (including Hong Kong and Macao), Russia, Iran, North Korea, Venezuela and Cuba. The rule defines six categories of “sensitive per - sonal data”: • certain covered personal identifiers (eg, names linked to device identifiers, social security numbers, driver’s licence or other government identification numbers); • precise geolocation data (eg, GPS co-ordi - nates); • biometric identifiers (eg, facial images, voice prints and patterns, and retina scans); • human genomic data and three other types of human omic data (epigenomic, proteomic or transcriptomic); • personal health data (eg, height, weight, vital signs, symptoms, test results, diagnosis, digi - tal dental records and psychological diagnos - tics); and • personal financial data (eg, information related to an individual’s credit, debit cards, bank accounts and financial liabilities, includ - ing payment history).

Data excluded from the definition of “sensitive personal data” includes public or non-public data that does not relate to an individual (eg, trade secrets and proprietary information), data that is already lawfully publicly available from government records or widely distributed media, and personal communications and certain infor - mational materials. These exclusions apply to each of the categories of sensitive data. According to the US Department of Justice, the final rule is intended to address the vulnerabil - ity of bulk sensitive data, as such data may be used to develop and enhance AI capabilities and algorithms that, in turn, enable the use of large datasets in ways to the detriment of US national security – for example, to identify US persons whose links to the federal government would otherwise be obscured in a single dataset and who can then be targeted for espionage or blackmail.

549 CHAMBERS.COM

Powered by