Skip to content
LexBuild

28 CFR § 202.249 - Sensitive personal data.

---
identifier: "/us/cfr/t28/s202.249"
source: "ecfr"
legal_status: "authoritative_unofficial"
title: "28 CFR § 202.249 - Sensitive personal data."
title_number: 28
title_name: "Judicial Administration"
section_number: "202.249"
section_name: "Sensitive personal data."
chapter_name: "DEPARTMENT OF JUSTICE"
part_number: "202"
part_name: "ACCESS TO U.S. SENSITIVE PERSONAL DATA AND GOVERNMENT-RELATED DATA BY COUNTRIES OF CONCERN OR COVERED PERSONS"
positive_law: false
currency: "2026-04-05"
last_updated: "2026-04-05"
format_version: "1.1.0"
generator: "[email protected]"
authority: "50 U.S.C. 1701  50 U.S.C. 1601  E.O. 14117, 89 FR 15421."
regulatory_source: "90 FR 1706, Jan. 8, 2025, unless otherwise noted."
cfr_part: "202"
---

# 202.249 Sensitive personal data.

(a) *Definition.* The term *sensitive personal data* means covered personal identifiers, precise geolocation data, biometric identifiers, human `omic data, personal health data, personal financial data, or any combination thereof.

(b) *Exclusions.* The term *sensitive personal data,* and each of the categories of *sensitive personal data,* excludes:

(1) Public or nonpublic data that does not relate to an individual, including such data that meets the definition of a “trade secret” (as defined in 18 U.S.C. 1839(3)) or “proprietary information” (as defined in 50 U.S.C. 1708(d)(7));

(2) Data that is, at the time of the transaction, lawfully available to the public from a Federal, State, or local government record (such as court records) or in widely distributed media (such as sources that are generally available to the public through unrestricted and open-access repositories);

(3) Personal communications; and

(4) Information or informational materials and ordinarily associated metadata or metadata reasonably necessary to enable the transmission or dissemination of such information or informational materials.