A data partnerships manager at a media company is reviewing her organization’s data licensing agreements.
Standard review. Routine contracts. Nothing unusual.
Then legal flags one partner.
The partner resells data to a joint venture. The joint venture has significant ownership from a company incorporated in a country on the PADFAA designated list.
She checks the categories of data in the licensing agreement.
Precise geolocation. Financial account information. Health-adjacent behavioral signals.
All three are covered under PADFAA.
What started as a routine contract review became an urgent conversation with outside counsel.
Privacy Law and National Security Law Have Converged. Most Compliance Teams Are Not Ready for Both.
For most of the past decade, privacy compliance and national security compliance were separate disciplines. Privacy teams managed consumer data. National security teams managed export controls and sanctions. The two rarely overlapped.
PADFAA changed that. It sits at the intersection of consumer privacy and national security — and it applies to any organization that qualifies as a data broker under its definition, regardless of whether that organization thinks of itself as operating in a national security context.
The intent standard is not the compliance standard. The result is.
What PADFAA Actually Prohibits — and Who It Reaches
The Protecting Americans’ Data from Foreign Adversaries Act was enacted in 2024 and is currently in effect. It prohibits data brokers from selling, releasing, disclosing, or providing access to personally identifiable sensitive data about Americans to any foreign adversary — currently defined as North Korea, China, Russia, and Iran — or any entity controlled by those countries. The FTC enforces PADFAA and treats violations as unfair or deceptive practices under Section 5 of the FTC Act. Civil penalties reach up to $53,088 per violation. There is no volume threshold — any amount of personal information a company discloses may trigger PADFAA’s restrictions.
On February 9, 2026, the FTC sent warning letters to 13 data brokers whose identities it has not publicly disclosed. The letters notified the recipients that the FTC had identified specific instances in which they offered data solutions involving the status of individuals as members of the U.S. Armed Forces — a category subject to PADFAA’s requirements. The letters instructed each company to conduct a comprehensive review of its business practices.
PADFAA’s reach is broader than the term “data broker” implies. The law can apply to companies that collect data directly from consumers, enrich it with details obtained from third parties, and then share it with other companies for those companies’ own purposes — even if those companies do not think of themselves as data brokers. The DOJ’s 2025 Data Security Program, implementing Executive Order 14117, runs a parallel track with its own bulk data transfer restrictions to countries of concern. Organizations with international data flows need to assess both frameworks, as they overlap but do not mirror each other.
Covered Data Categories Under PADFAA
5-Question Compliance Check: Have You Mapped Your PADFAA Exposure?
The definition is broader than it appears. Companies that collect data from consumers, enrich it, and share it with third parties may qualify — even if they do not sell data as a primary business model. If you have not formally assessed this question, you do not know your exposure.
Health, financial, biometric, genetic, precise geolocation, government identifiers, private communications, and military status data are all covered. If your data products touch any of these categories, PADFAA applies to every transaction involving that data.
The human story illustrates the compliance gap: the original data sale may be clean, but the resale to a joint venture with foreign adversary ownership creates the violation. PADFAA liability travels with the data, not just with the direct transaction. You need to know where your data goes after the initial sale.
An entity “controlled by” a foreign adversary includes companies with significant ownership, board representation, or operational influence from China, Russia, Iran, or North Korea — even if the company is incorporated elsewhere. Standard vendor due diligence may not surface this. You need a specific PADFAA screening process.
The DOJ’s 2025 regulations implementing Executive Order 14117 cover bulk data transfers to countries of concern. The two frameworks overlap but are not identical — some transactions may trigger one but not both. Organizations with significant international data flows need a compliance assessment that covers both.
Who This Affects and How
Legal and Compliance Teams
PADFAA creates a compliance obligation that sits outside your normal privacy review process. Most privacy assessments are built around consumer data rights and breach notification. PADFAA adds a foreign adversary screening requirement to every data licensing, partnership, and resale agreement involving covered data categories. If your current vendor due diligence process does not include a PADFAA ownership screen, it is incomplete for any transaction involving sensitive personal data.
Data Partnerships and Business Development Teams
Every data licensing agreement involving covered categories now requires a downstream use assessment. Who receives the data after the initial transaction? What are their ownership structures? Do any downstream recipients have significant ties to China, Russia, Iran, or North Korea? These are not hypothetical questions — they are the questions the FTC’s February 2026 warning letters signaled are being asked. Build them into your standard contract review process before the next deal closes.
Security and Risk Teams
PADFAA sits at the intersection of consumer privacy and national security — which means the compliance failure mode is not a breach notification. It is a federal enforcement action with civil penalties of up to $53,088 per violation, no volume threshold, and FTC enforcement authority. The risk profile is different from a typical privacy violation. Brief your security and risk leadership on PADFAA separately from your standard privacy compliance reporting.
For Organizations
- Assess whether your organization qualifies as a data broker under PADFAA’s definition and document the conclusion.
- Inventory every data product, licensing agreement, and partnership that involves PADFAA-covered data categories and flag them for PADFAA review.
- Screen existing data partners for ownership structures that could connect them to China, Russia, Iran, or North Korea — including indirect ownership and board representation.
- Add a PADFAA downstream use clause to all new data licensing agreements requiring recipients to confirm they will not transfer covered data to foreign adversary-connected entities.
- Brief your legal team on the DOJ Data Security Program alongside PADFAA so your assessment covers both frameworks.
For Individuals
- Understand that PADFAA is specifically designed to prevent your sensitive personal data — health, financial, geolocation, biometric — from reaching foreign governments or entities they control.
- Submit deletion requests through California’s DROP platform or directly to data brokers for your most sensitive data categories if you are concerned about downstream exposure.
- Report concerns about data broker practices to the FTC at reportfraud.ftc.gov if you believe a company is sharing your data with foreign adversary-connected entities.
Unpopular Opinion
Most organizations that are exposed under PADFAA are not data brokers in any traditional sense of that term. They are marketing companies, media companies, and analytics platforms that have been sharing enriched consumer data through partnership chains without tracing where it ultimately goes. PADFAA closes that gap — and most of them have not noticed yet.
Myth vs Reality
Myth: PADFAA only applies to companies that directly sell data to foreign governments.
Reality: PADFAA applies to any transfer — sale, disclosure, licensing, or access — to any entity controlled by a foreign adversary country, including companies incorporated outside those countries that have significant ownership, board representation, or operational influence from China, Russia, Iran, or North Korea. The liability is not about intent. It is about result.
If you traced every downstream recipient of your organization’s most sensitive data products today, how confident are you that none of them has significant ownership or operational ties to a PADFAA-designated foreign adversary?
Poll
Has your organization formally assessed its PADFAA exposure — including downstream data recipients?