EO 14034Executive OrderBiden · D Quiet signal

Executive Order 14034

Protecting Americans' Sensitive Data From Foreign Adversaries

This executive order revokes Trump-era bans on TikTok, WeChat, and other Chinese apps (EOs 13942, 13943, 13971) and replaces them with a broader, evidence-based framework for evaluating risks from foreign adversary-connected software applications. It directs the Commerce Secretary to produce two reports with recommendations for protecting Americans' sensitive data and addressing risks from connected software applications.

Impact dates

  1. Commerce report recommending additional executive and legislative actions on connected software applications

  2. Commerce report on protecting against harm from unrestricted sale/transfer/access to sensitive data

  3. DNI threat assessments and DHS vulnerability assessments due to Secretary of Commerce

Key directives

  • Revoke EO 13942 (TikTok ban)
  • Revoke EO 13943 (WeChat ban)
  • Revoke EO 13971 (Chinese software ban)
  • OMB and agency heads rescind implementing rules for revoked orders
  • Abolish positions/committees established under revoked orders
  • DNI provide threat assessments to Commerce within 60 days
  • DHS provide vulnerability assessments to Commerce within 60 days
  • Commerce report on sensitive data protection recommendations within 120 days
  • Commerce report on additional executive/legislative actions for connected software risks within 180 days
  • Commerce Secretary conduct continuing evaluation of transactions involving connected software applications

Who is ordered

Timeline

Immediate

  • Revocation of EOs 13942, 13943, 13971
  • Rescission of implementing rules/policies for revoked orders
  • Abolition of personnel positions/committees established under revoked orders

Near term (90d)

  • DNI threat assessments due to Commerce (60 days)
  • DHS vulnerability assessments due to Commerce (60 days)
  • Commerce report on protecting sensitive data from unrestricted sale/transfer/access (120 days)

Long term

  • Commerce report on additional executive/legislative actions for connected software application risks (180 days)
  • Continuing evaluation of transactions involving connected software applications by Commerce Secretary

Risks & tensions

  • Vague standard for 'undue' or 'unacceptable' risk leaves significant discretion to Commerce Secretary
  • Human rights abuse language (Section preamble) suggests potential for secondary sanctions but lacks implementing mechanism in order text
  • Continuing evaluation mandate without defined triggers or timelines creates regulatory uncertainty for industry
  • Revocation of specific app bans may be perceived as weakening position vis-a-vis China despite broader framework
  • Dependent on appropriations availability per Section 4(b)
Executive Order 14034: Protecting Americans' Sensitive Data From Foreign Adversaries · Executive Orders