当地时间2月28日,美国总统拜登发布《关于防止受关注国家访问美国公民的大量敏感个人数据和美国政府相关数据的行政命令》(Executive Order on Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern,“行政命令”),重点旨在限制向中国(含香港和澳门)、俄罗斯、伊朗、朝鲜、古巴和委内瑞拉等受关注国家传输美国公民的敏感个人数据,包括基因组数据、生物识别数据、个人健康数据、地理位置数据、财务数据和某些类型的个人身份识别信息。行政命令在中美两国科技领域竞争不断加剧的背景之下孕育而生,纽约时报称其为“华盛顿和北京之间数字冷战的最新升级”[1]。
  • 司法部发布法规,限制受关注国家对于美国公民的敏感个人数据的访问和利用,阻止敏感个人数据大规模转移到这些国家。

  • 司法部发布法规,加强对敏感政府数据的保护,包括敏感政府场所的地理位置信息和军事人员的信息。

  • 美国司法部和国土安全部将共同制定高安全标准,以防止受关注国家通过其他商业手段获取美国公民的信息,如通过投资、供应商和雇佣关系。

  • 卫生与公共服务部、国防部和退伍军人事务部确保联邦拨款、合同、奖励不被用于帮助受关注国家(包括通过位于美国的公司)获取美国公民的敏感健康数据。

  • 美国电信服务行业外国参与评估委员会需要在审查海底电缆许可证时考虑对美国公民敏感个人数据的威胁。

  • 数据跨境传输受阻:行政命令限制了美国公民的个人数据被传输至中国。这意味着出海企业在美国获取并跨境传输敏感个人数据会面临更多的限制和困难,从而影响到业务运营和研发能力,并增加企业在数据保护和隐私方面的合规风险;

  • 商业合作受阻:行政命令可能会导致中资企业在与美国企业进行商业合作时面临更多的障碍。美国企业可能会因为担心数据泄露和合规问题而减少与中资企业的合作,从而影响美国市场的拓展和发展;

  • 全球战略布局调整:面对美国的数据限制政策,中资企业可能需要重新评估其全球战略布局。企业可能需要考虑在其他国家或地区建立数据中心,或寻求其他合作伙伴来弥补美国数据跨境传输方面的限制。






  • 由关注国家所拥有、控制、或受其司法管辖或指导的实体(an entity owned by, controlled by, or subject to the jurisdiction or direction of a country of concern);

  • 作为上述实体的员工或承包商的外国人(a foreign person who is an employee or contractor of such an entity);

  • 作为关注国家的员工或承包商的外国人(a foreign person who is an employee or contractor of a country of concern);

  • 主要居住在关注国家领土司法管辖区内的外国人(a foreign person who is primarily resident in the territorial jurisdiction of a country of concern)。




  • 特别列出的个人识别信息类别及其组合(specifically listed categories and combinations of covered personal identifiers)——并非所有个人可识别信息,不包含仅与另一条人口统计或联系数据(如名字和姓氏、出生日期、出生地、邮政编码、住宅街道或邮寄地址、电话号码以及电子邮件地址和类似的公共账户标识符)相关联的人口统计或联系数据,或一个基于网络的标识符、账户认证数据或呼叫详细数据(只与提供电信、网络或类似服务的另一个基于网络的标识符、账户认证数据或呼叫详细数据相关联);

  • 精确地理位置数据(precise geolocation data)

  • 生物识别标识(biometric identifiers)

  • 人类基因组数据(human genomic data)

  • 个人健康数据(personal health data)

  • 个人财务数据(personal financial data)

“敏感个人数据”不包括公共记录中的数据,例如法院记录或其他政府记录,这些记录是合法且普遍对公众开放的;根据50 U.S.C. § 1702(b)(1)的个人通信;或根据50 U.S.C. 1702(b)(3)的表达性信息,如视频、艺术作品或出版物。



  • 被禁止的数据交易类别:

  • 数据经纪交易(data-brokerage transactions)

  • 涉及批量人类基因组数据或可从中提取此类数据的生物样本转移的基因组数据交易(genomic-data transactions involving the transfer of bulk human genomic data or biospecimens from which such data can be derived)

  • 受限制的数据交易类别:

    • 涉及提供商品和服务的供应商协议(vendor agreements involving the provision of goods and services),包括云服务协议;

    • 雇佣协议(employment agreements)

    • 投资协议(investment agreements)。

    这些受限制交易的安全要求将由国土安全部的网络安全和基础设施安全局 (CISA)制定。这些安全要求旨在减轻关注国家或受管制个人访问数据的风险,可能包括诸如基本组织网络安全态势要求、物理和逻辑访问控制、数据掩码和最小化,以及使用保护隐私技术的网络安全措施。



    • 涉及某些美国政府相关数据的交易(涉及美国政府人员或位置的敏感个人数据):无涉及美国人数量与设备数量的限制,均受管制;

    • 其他:一般只会对超过规定数量(即,一定数量的美国人或美国设备)的敏感个人数据的特定数据交易进行规管;



    • 通常作为金融服务、支付处理和监管合规的一部分(ordinarily incident to and part of financial services, payment processing, and regulatory compliance),如银行业、资本市场或金融保险活动;其他监管机构监管范围内的金融活动;涉及转移个人财务数据或受管制个人识别信息的支付提供或处理,用于商品和服务的购买和销售;以及法律和监管合规;

    • 通常作为跨国美国公司内部附属业务操作的一部分(ordinarily incident to and part of ancillary business operations),如工资支付或人力资源;

    • 美国政府及其承包商、雇员和资助者的活动(activities of the U.S. Government and its contractors, employees, and grantees),如联邦资助的健康和研究活动,这些活动将由资助机构自行规管;

    • 联邦法律或国际协议要求或授权的交易(transactions required or authorized by federal law or international agreements),如乘客名单信息的交换、国际刑警组织(INTERPOL)的请求和公共卫生监视。


    FACT SHEET: President Biden Issues Executive Order to Protect Americans’ Sensitive Personal Data

    Today, President Biden will issue an Executive Order to protect Americans’ sensitive personal data from exploitation by countries of concern. The Executive Order, which marks the most significant executive action any President has ever taken to protect Americans’ data security, authorizes the Attorney General to prevent the large-scale transfer of Americans’ personal data to countries of concern and provides safeguards around other activities that can give those countries access to Americans’ sensitive data.
    The President’s Executive Order focuses on Americans’ most personal and sensitive information, including genomic data, biometric data, personal health data, geolocation data, financial data, and certain kinds of personally identifiable information. Bad actors can use this data to track Americans (including military service members), pry into their personal lives, and pass that data on to other data brokers and foreign intelligence services. This data can enable intrusive surveillance, scams, blackmail, and other violations of privacy.
    Companies are collecting more of Americans’ data than ever before, and it is often legally sold and resold through data brokers. Commercial data brokers and other companies can sell this data to countries of concern, or entities controlled by those countries, and it can land in the hands of foreign intelligence services, militaries, or companies controlled by foreign governments.
    The sale of Americans’ data raises significant privacy, counterintelligence, blackmail risks and other national security risks—especially for those in the military or national security community. Countries of concern can also access Americans’ sensitive personal data to collect information on activists, academics, journalists, dissidents, political figures, and members of non-governmental organizations and marginalized communities to intimidate opponents of countries of concern, curb dissent, and limit Americans’ freedom of expression and other civil liberties.
    To protect Americans’ sensitive personal data, President Biden is directing:
    • The Department of Justice to issue regulations that establish clear protections for Americans’ sensitive personal data from access and exploitation by countries of concern. These protections will extend to genomic data, biometric data, personal health data, geolocation data, financial data, and certain kinds of personal identifiers. They will prevent the large-scale transfer of that data to countries of concern—which have a track record of collecting and misusing data on Americans.


    • The Department of Justice to issue regulations that establish greater protection of sensitive government-related data, including geolocation information on sensitive government sites and information about military members.


    • The Departments of Justice and Homeland Security to work together to set high security standards to prevent access by countries of concern to Americans’ data through other commercial means, such as data available via investment, vendor, and employment relationships.


    • The Departments of Health and Human Services, Defense, and Veterans Affairs to help ensure that Federal grants, contracts, and awards are not used to facilitate access to Americans’ sensitive health data by countries of concern, including via companies located in the United States.


    • The Committee for the Assessment of Foreign Participation in the United States Telecommunications Services Sector (often called “Team Telecom”) to consider the threats to Americans’ sensitive personal data in its reviews of submarine cable licenses.

      美国通信服务业外国参与审查委员会(常被称为 "电信小组")在审查海底电缆许可证时,将考虑美国公民敏感个人信息所面临的威胁。

    That these activities do not stop the flow of information necessary for financial services activities or impose measures aimed at a broader decoupling of the substantial consumer, economic, scientific, and trade relationships that the United States has with other countries.
    These actions not only align with the U.S.’ longstanding support for the trusted free flow of data, but also are consistent with U.S.’ commitment to an open Internet with strong and effective protections for individuals’ privacy and measures to preserve governments’ abilities to enforce laws and advance policies in the public interest. The Administration will continue its engagements with stakeholders, including technology companies and advocates for privacy, safety, competition, labor, and human rights, to move forward in a way that appropriately balances all these objectives.
    The President has encouraged the Consumer Financial Protection Bureau to consider taking steps, consistent with CFPB’s existing legal authorities, to protect Americans from data brokers that are illegally assembling and selling extremely sensitive data, including that of U.S. military personnel.
    Additionally, President Biden continues to urge Congress to do its part and pass comprehensive bipartisan privacy legislation, especially to protect the safety of our children.




