A foreign investment can trigger CFIUS review over sensitive personal data when the U.S. target holds identifiable information on more than one million people, holds any genetic test results, or tailors its products to intelligence, national security, or homeland security personnel. When that target is acquired by a foreign investor whose upstream ownership includes a foreign government at 49 percent or more, and the investor is taking 25 percent or more of the U.S. business, the filing is mandatory and must reach the Committee at least 30 days before closing. Missing that filing carries a civil penalty of up to $5,000,000 or the value of the transaction, whichever is greater.1eCFR. 31 CFR 800.901 – Penalties and Damages
What Data the Rule Covers
Sensitive personal data under 31 CFR 800.241 has to be “identifiable,” meaning usable to distinguish or trace an individual, and it has to fall within one of ten regulated categories:2eCFR. 31 CFR 800.241 – Sensitive Personal Data
- Financial records that could reveal an individual’s financial hardship.
- The contents of a consumer report under the Fair Credit Reporting Act, unless obtained for a permissible purpose and not substantially similar to a full consumer file.
- Applications for health, long-term care, professional liability, mortgage, or life insurance.
- Records relating to physical, mental, or psychological health.
- Non-public electronic communications between users of a platform whose primary purpose is facilitating those communications.
- Geolocation data from positioning systems, cell towers, or WiFi access points, including from mobile apps, vehicle GPS, and wearables.
- Biometric enrollment data covering face, voice, retina, iris, and fingerprint templates.
- Data stored or processed for generating a state or federal government identification card.
- An individual’s U.S. government personnel security clearance status.
- Data contained in applications for security clearances or positions of public trust.
Two categories account for a large share of deal-side questions. Geolocation from mobile apps and connected vehicles is in scope because it reveals patterns of daily movement for identifiable people. Private messaging content is in scope because a communications platform with a U.S. user base becomes a surveillance opportunity if a foreign person gains any decision role over how that data is stored or accessed.
Genetic Test Results Are Treated Separately
Genetic test results, including related sequencing data, sit outside the volume threshold. Under 31 CFR 800.241(a)(2), a company holding any genetic test results is treated as handling sensitive personal data regardless of how many people are in the dataset.2eCFR. 31 CFR 800.241 – Sensitive Personal Data A consumer genetics service with a few thousand customers is within CFIUS scope; a health-tech firm with lab-sequencing data is as well.
The One Million Person Threshold
For the identifiable categories other than genetic data, a company generally comes within the definition through one of three paths.2eCFR. 31 CFR 800.241 – Sensitive Personal Data
The first is scale. If the U.S. business has maintained or collected identifiable data on more than one million individuals at any point during the twelve months before the transaction’s completion date or filing date, whichever comes first, it is within scope. A company can step out of this trigger only by showing that, at completion, it no longer has the capability to maintain or collect such data on more than one million people.
The second path applies to companies that have not yet crossed one million but have a demonstrated business objective to do so, where data collection is an integrated part of their core products or services. This captures scaling startups whose growth trajectory clearly puts them over the line.
The third path removes volume from the analysis entirely. A company falls within the definition if it targets or tailors its products or services to executive branch agencies with intelligence, national security, or homeland security responsibilities, or to the personnel and contractors of those agencies. A vendor with a few hundred customers built for intelligence community contractors is covered, because even small datasets about cleared personnel are high-value to foreign adversaries.
What the Rule Does Not Cover
Several categories are carved out of the definition even when they otherwise look like sensitive personal data.2eCFR. 31 CFR 800.241 – Sensitive Personal Data
Employee data a U.S. business maintains about its own workforce is excluded, with one important exception: records about employees who are U.S. government contractors holding personnel security clearances remain in scope. That distinction catches deal teams who assume all HR data is exempt and only later realize the target employs cleared contractors.
Data that is a matter of public record, such as court filings and other government records generally available to the public, is out. The regulation gives court records as an example rather than an exhaustive list.
Data that has been anonymized or encrypted so individuals cannot be identified is generally excluded, but only if the encryption is robust and the decryption keys or tools are not accessible to the foreign investor. If the buyer would receive the keys as part of the deal, the exclusion does not apply.
How a Data Company Becomes a CFIUS Target
A U.S. company that meets the sensitive personal data definition qualifies as a “TID U.S. business,” alongside businesses involved in critical technologies or covered investment critical infrastructure. The three prongs are independent: a data-heavy company is a TID U.S. business even without any defense technology or critical infrastructure exposure.3eCFR. 31 CFR 800.248 – TID U.S. Business
The TID label expands what CFIUS can review. Ordinary acquisitions fall under CFIUS only when a foreign person acquires control. For a TID U.S. business, non-controlling investments are also covered if they give the foreign investor access to material nonpublic technical information, a board seat or observer rights, or any involvement in decisions about how the company handles sensitive personal data.4eCFR. 31 CFR 800.211 – Covered Investment A minority investor who negotiates a board observer seat at a data-heavy startup has created a covered investment even without a controlling stake.
When Filing Is Mandatory
CFIUS filings are generally voluntary, and parties often file to obtain a safe harbor letter. But for certain transactions involving TID U.S. businesses, filing is required. The primary mandatory trigger tied to sensitive personal data occurs when a foreign person acquires a “substantial interest” in a TID U.S. business and a foreign government holds a substantial interest in that foreign investor.5eCFR. 31 CFR 800.401 – Mandatory Declarations
The two “substantial interest” thresholds are set separately. A foreign person holds a substantial interest in a U.S. business when it acquires, directly or indirectly, 25 percent or more of the voting interest. A foreign government holds a substantial interest in the foreign investor when it holds, directly or indirectly, 49 percent or more of the voting interest in that investor.6eCFR. 31 CFR 800.244 – Substantial Interest Both must exist at once. An investment fund backed by a sovereign wealth fund taking a 30 percent stake in a data analytics company is the textbook example.
A separate mandatory filing path exists for critical-technologies transactions that would require a U.S. export license, but that trigger runs off the technology prong of TID rather than the data prong. Investors from certain allied countries can qualify as “excepted investors” and are exempt from the mandatory declaration requirement, subject to organizational, board-composition, and ownership conditions and a clean five-year compliance record.7U.S. Department of the Treasury. CFIUS Excepted Foreign States
The 30-Day Deadline
When a mandatory declaration is required, it must be filed at least 30 days before the transaction’s completion date, meaning the earliest date on which any ownership interest is conveyed to the foreign person.8U.S. Department of the Treasury. CFIUS Frequently Asked Questions If closing is set for August 1, the filing must reach CFIUS no later than July 1. Experienced counsel files well before the 30-day minimum to leave room for follow-up questions or a request to convert the declaration into a full notice.
If a mandatory declaration prompts CFIUS to request a full notice, the 45-day review clock does not begin until the notice is accepted as complete. Parties who discover the mandatory filing obligation late in a deal sometimes face the choice of delaying closing or accepting penalty exposure.
Declaration or Full Notice
A mandatory filing obligation can be satisfied by a short-form declaration or a full written notice. A declaration triggers a 30-day assessment period. At the end of it, CFIUS can clear the transaction, request a full notice, initiate a unilateral review, or state that it cannot conclude action based on the declaration alone.9U.S. Department of the Treasury. CFIUS Overview
A written notice runs on a longer track: a 45-day initial review, a 45-day investigation if the Committee determines one is warranted, and a 15-day presidential decision window if the matter is referred to the President.9U.S. Department of the Treasury. CFIUS Overview Complex data transactions, especially those with foreign-government-linked investors, often end up on the notice track because the Committee needs more information than a declaration provides. A declaration can resolve in 30 days; a notice going through investigation can take over three months.
Filing Fees
Declarations are free. Written notices carry a tiered filing fee based on the total transaction value:10eCFR. 31 CFR Part 800 Subpart K – Filing Fees
- Under $500,000: no fee.
- $500,000 to under $5 million: $750.
- $5 million to under $50 million: $7,500.
- $50 million to under $250 million: $75,000.
- $250 million to under $750 million: $150,000.
- $750 million and above: $300,000.
Transaction value includes all consideration: cash, assets, shares, debt forgiveness, and services or in-kind contributions provided by or on behalf of the foreign person. CFIUS will not accept a notice until the fee is received. If the Committee later determines the transaction is not a covered transaction, the fee is refunded.
What Non-Compliance Costs
Failing to file a mandatory declaration when required carries a civil penalty of up to $5,000,000 or the value of the transaction, whichever is greater, with the amount calibrated to the nature of the violation.1eCFR. 31 CFR 800.901 – Penalties and Damages
Violations of a mitigation agreement, material condition, or order are steeper. For violations occurring on or after December 26, 2024, the maximum civil penalty per violation is the greatest of $5,000,000, the value of the person’s interest in the U.S. business at the time of the transaction, the value of that interest at the time of the violation, or the value of the transaction as filed with the Committee.11eCFR. 31 CFR Part 800 Subpart I – Penalties and Damages For a large transaction that can far exceed the $5 million floor, and because the penalty is per violation, ongoing non-compliance compounds. CFIUS can also refer completed transactions to the President for divestment under Section 721.
Why Silence Is Not a Strategy
CFIUS does not depend on parties to self-report. The Committee actively screens non-notified transactions using tips from the public, referrals from Congress and executive branch agencies, media reports, commercial databases, and classified intelligence.12U.S. Department of the Treasury. CFIUS Non-Notified Transactions When it identifies a transaction that may fall within its jurisdiction and raise national security concerns, Treasury contacts the parties to request additional information or a formal filing.
This function was formalized after the Foreign Investment Risk Review Modernization Act of 2018, and Treasury has dedicated substantial staffing to it. Members of the public can submit tips directly to CFIUS.tips@treasury.gov. Closing a deal without filing and hoping it goes unnoticed exposes the parties to the penalty framework above and to the risk that CFIUS will unwind the transaction months or years later.