National Security & Privacy

PADFAA: When Selling Data to a Foreign Adversary Becomes a Federal Crime

Privacy Pulse — Civora Advisory 8 min read
Week 18 · Q3 2026

Why You Should Care

Selling sensitive American data to a foreign adversary is now a federal crime — and most data brokers still have not mapped whether their business practices comply. The FTC has already warned 13 companies. The penalty is $53,088 per violation with no volume threshold.

13
Data brokers warned by FTC on Feb 9, 2026
$53K
Per violation, per day — no volume threshold
4
Designated adversaries: China, Russia, Iran, North Korea
2024
PADFAA enacted — already in effect

A data partnerships manager at a media company is reviewing her organization’s data licensing agreements.

Standard review. Routine contracts. Nothing unusual.

Then legal flags one partner.

The partner resells data to a joint venture. The joint venture has significant ownership from a company incorporated in a country on the PADFAA designated list.

She checks the categories of data in the licensing agreement.

Precise geolocation. Financial account information. Health-adjacent behavioral signals.

All three are covered under PADFAA.

What started as a routine contract review became an urgent conversation with outside counsel.

Privacy Law and National Security Law Have Converged. Most Compliance Teams Are Not Ready for Both.

For most of the past decade, privacy compliance and national security compliance were separate disciplines. Privacy teams managed consumer data. National security teams managed export controls and sanctions. The two rarely overlapped.

PADFAA changed that. It sits at the intersection of consumer privacy and national security — and it applies to any organization that qualifies as a data broker under its definition, regardless of whether that organization thinks of itself as operating in a national security context.

PADFAA does not care whether you knew your data reached a foreign adversary. It cares whether it did.

The intent standard is not the compliance standard. The result is.

What PADFAA Actually Prohibits — and Who It Reaches

The Protecting Americans’ Data from Foreign Adversaries Act was enacted in 2024 and is currently in effect. It prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to any foreign adversary — currently defined as North Korea, China, Russia, and Iran — or any entity controlled by those countries. The FTC enforces PADFAA and treats violations as unfair or deceptive practices under Section 5 of the FTC Act. Civil penalties reach up to $53,088 per violation. There is no volume threshold — any amount of personal information a company discloses may trigger PADFAA’s restrictions.

On February 9, 2026, the FTC sent warning letters to 13 data brokers whose identities it has not publicly disclosed. The letters notified the recipients that the FTC had identified specific instances in which they offered data solutions involving the status of individuals as members of the U.S. Armed Forces — a category subject to PADFAA’s requirements. The letters instructed each company to conduct a comprehensive review of its business practices.

PADFAA’s reach is broader than the term “data broker” implies. The law can apply to companies that collect data directly from consumers, enrich it with details obtained from third parties, and then share it with other companies for those companies’ own purposes — even if those companies do not think of themselves as data brokers. The DOJ’s 2025 Data Security Program, implementing Executive Order 14117, runs a parallel track with its own bulk data transfer restrictions to countries of concern. Organizations with international data flows need to assess both frameworks, as they overlap but do not mirror each other.

Covered Data Categories Under PADFAA

Health and medical information
Financial account numbers and balances
Biometric data
Genetic data
Precise geolocation (within 1,850 feet)
Government-issued identifiers (SSN, passport)
Private communications content
Military and armed forces status

5-Question Compliance Check: Have You Mapped Your PADFAA Exposure?

1
Does your organization qualify as a data broker under PADFAA’s definition?

The definition is broader than it appears. Companies that collect data from consumers, enrich it, and share it with third parties may qualify — even if they do not sell data as a primary business model. If you have not formally assessed this question, you do not know your exposure.

2
Do any of your data products or services include PADFAA-covered categories?

Health, financial, biometric, genetic, precise geolocation, government identifiers, private communications, and military status data are all covered. If your data products touch any of these categories, PADFAA applies to every transaction involving that data.

3
Have you traced your data’s downstream recipients — including through resale chains?

The human story illustrates the compliance gap: the original data sale may be clean, but the resale to a joint venture with foreign adversary ownership creates the violation. PADFAA liability travels with the data, not just with the direct transaction. You need to know where your data goes after the initial sale.

4
Have you screened your business partners against foreign adversary ownership structures?

An entity “controlled by” a foreign adversary includes companies with significant ownership, board representation, or operational influence from China, Russia, Iran, or North Korea — even if the company is incorporated elsewhere. Standard vendor due diligence may not surface this. You need a specific PADFAA screening process.

5
Have you assessed the DOJ Data Security Program alongside PADFAA?

The DOJ’s 2025 regulations implementing Executive Order 14117 cover bulk data transfers to countries of concern. The two frameworks overlap but are not identical — some transactions may trigger one but not both. Organizations with significant international data flows need a compliance assessment that covers both.

Who This Affects and How

Legal and Compliance Teams

PADFAA creates a compliance obligation that sits outside your normal privacy review process. Most privacy assessments are built around consumer data rights and breach notification. PADFAA adds a foreign adversary screening requirement to every data licensing, partnership, and resale agreement involving covered data categories. If your current vendor due diligence process does not include a PADFAA ownership screen, it is incomplete for any transaction involving sensitive personal data.

Data Partnerships and Business Development Teams

Every data licensing agreement involving covered categories now requires a downstream use assessment. Who receives the data after the initial transaction? What are their ownership structures? Do any downstream recipients have significant ties to China, Russia, Iran, or North Korea? These are not hypothetical questions — they are the questions the FTC’s February 2026 warning letters signaled are being asked. Build them into your standard contract review process before the next deal closes.

Security and Risk Teams

PADFAA sits at the intersection of consumer privacy and national security — which means the compliance failure mode is not a breach notification. It is a federal enforcement action with civil penalties of up to $53,088 per violation, no volume threshold, and FTC enforcement authority. The risk profile is different from a typical privacy violation. Brief your security and risk leadership on PADFAA separately from your standard privacy compliance reporting.

For Organizations

For Individuals

Unpopular Opinion

Most organizations that are exposed under PADFAA are not data brokers in any traditional sense of that term. They are marketing companies, media companies, and analytics platforms that have been sharing enriched consumer data through partnership chains without tracing where it ultimately goes. PADFAA closes that gap — and most of them have not noticed yet.

Myth vs Reality

Myth: PADFAA only applies to companies that directly sell data to foreign governments.

Reality: PADFAA applies to any transfer — sale, disclosure, licensing, or access — to any entity controlled by a foreign adversary country, including companies incorporated outside those countries that have significant ownership, board representation, or operational influence from China, Russia, Iran, or North Korea. The liability is not about intent. It is about result.

Privacy Pulse — where law, technology, and human dignity meet.

If you traced every downstream recipient of your organization’s most sensitive data products today, how confident are you that none of them has significant ownership or operational ties to a PADFAA-designated foreign adversary?

Poll

Has your organization formally assessed its PADFAA exposure — including downstream data recipients?

Yes — full assessment completed including downstream screening
Partial — we reviewed direct transactions but not downstream
Not yet — PADFAA is on our list but not assessed
We did not know PADFAA applied to organizations like ours
#PrivacyPulse #PADFAA #DataPrivacy #NationalSecurity #FTCEnforcement