SECURE Data Act Cross-Border Data Flow Rules — International Transfers & Covered Nations
International Data Transfers Under the SECURE Data Act
Section 9 addresses how personal data moves across international borders — a critical issue for multinational companies and any business using cloud services hosted outside the United States.
The Secretary of Commerce as Principal Advisor
Under the bill, the Secretary of Commerce becomes the president’s principal advisor on international data flow policy. This is a significant elevation of the Commerce Department’s role in tech and privacy governance.
The Secretary’s responsibilities include:
- Assessing foreign privacy laws for alignment with the SECURE Data Act’s protections, and for any impact on US consumers, businesses, and national security
- Developing policy on maximizing the benefits of international data flows while protecting against risks
- Negotiating frameworks and certifications to facilitate cross-border data flows in commerce
- Coordinating with other federal agencies as needed
International Agreements
The Secretary may enter into agreements with foreign governments, international forums, or political/economic unions to facilitate international data flows.
Any such agreement must:
- Not conflict with the SECURE Data Act’s consumer protections
- Be consistent with US economic and security interests
- Be submitted to the relevant Congressional committees within 60 days of being signed
The “Covered Nation” Restriction
Throughout the bill, special rules apply when data is transferred to, processed in, stored in, or sold to a covered nation. Covered nations are defined by reference to 10 U.S.C. §4872(f) — the list of countries identified as posing national security risks, which currently includes:
- China
- Russia
- Iran
- North Korea
Controllers must disclose in their privacy notices whether any personal data is transferred to covered nations. This is a mandatory element of the privacy notice requirement under Section 3.
Relationship to the Gramm-Leach-Bliley Act
Section 9 explicitly states that it does not alter the authority of agencies with rulemaking and enforcement authority under the Gramm-Leach-Bliley Act — preserving the existing regulatory framework for financial data flows.
Key Takeaways
- Secretary of Commerce leads US international data flow policy under this Act
- International data transfer agreements must not weaken US consumer protections
- Data flows to covered nations (China, Russia, Iran, North Korea) must be disclosed in privacy notices
- GCLB financial data rules are preserved separately
Frequently Asked Questions
We use AWS or Google Cloud which has data centers globally. Does this affect us? Potentially, yes — particularly if data is routed through or stored in covered nations. You should review your cloud provider’s data residency settings and disclose any covered nation data flows in your privacy notice.
Is there an EU-US data transfer framework equivalent under this Act? Not yet. The Secretary of Commerce is empowered to negotiate such frameworks, but none are specified in the bill’s text. Existing frameworks like the EU-US Data Privacy Framework would continue to operate independently.