Organizations subject to the U.S. Department of Justice’s Bulk Data Transfer Rule should begin preparing now for the first annual audit and certification deadline, which is due by October 6, 2026. The rule requires covered
entities to assess compliance with security and data governance requirements, document findings, and certify adherence to the regulations. Companies handling sensitive personal or government-related data should establish audit procedures, address compliance gaps, and maintain thorough records to demonstrate compliance and reduce regulatory risk.


