Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature Data Privacy

PADFAA Is Real Enforcement Now: What Fintech Data Companies Need to Know Before the FTC Files Its First Case

The Protecting Americans' Data from Foreign Adversaries Act prohibits data brokers from selling sensitive consumer data — including financial records — to entities in China, Russia, Iran, North Korea, Cuba, and Venezuela. The FTC sent 13 warning letters in February 2026. Here's what counts as a data broker, what data is covered, and what your compliance program needs before enforcement begins.

By Rebecca Leung · September 5, 2026 ·
Table of Contents

TL;DR

  • PADFAA (2024) prohibits data brokers from selling, licensing, or providing access to sensitive US consumer data — including financial records — to entities in China, Russia, Iran, North Korea, Cuba, or Venezuela.
  • In February 2026, the FTC sent 13 warning letters reminding data brokers of their PADFAA obligations — the clearest enforcement ramp-up signal the agency has issued under the statute.
  • Any fintech that aggregates or sells customer financial data to third parties may qualify as a PADFAA-covered data broker; the definition turns on whether you collected the data directly from the individual.
  • Civil penalties reach $53,088 per violation; beneficial ownership scrutiny means “incorporated in Singapore” doesn’t clear the analysis.

In February 2026, the Federal Trade Commission sent warning letters to 13 data brokers reminding them of their obligations under the Protecting Americans’ Data from Foreign Adversaries Act. Most financial services compliance teams had never heard of it.

That’s a problem. Because PADFAA — signed in April 2024, effective June 23, 2024 — prohibits any “data broker” from selling or transferring sensitive consumer data, including financial records, to foreign adversary countries or entities under their control. The statute defines “sensitive data” to include financial account numbers, credit and debit card information, and financial transaction data. And it defines “data broker” in a way that reaches a significant portion of the fintech data ecosystem.

The February letters weren’t a courtesy. They were the FTC’s standard enforcement ramp-up pattern: publish the obligation, send public notice, then file the first case.

What PADFAA Actually Does

PADFAA’s core prohibition is straightforward: a data broker may not sell, license, rent, trade, transfer, release, disclose, provide access to, or otherwise make available personally identifiable sensitive data of US individuals to:

  1. A foreign adversary country (China, Russia, Iran, North Korea, Cuba, Venezuela)
  2. Any entity owned by, controlled by, or subject to the jurisdiction of a foreign adversary country

The prohibition is not limited to intentional transfers to government actors. It reaches commercial transactions — a data broker that licenses US consumer financial profiles to a data analytics company majority-owned by Chinese nationals has violated PADFAA, regardless of whether the buyer intends to provide that data to Chinese intelligence services.

Congress passed the law as part of a broader package addressing national security data risks. The TikTok provisions in the same legislation got more press coverage. PADFAA, which establishes the permanent enforcement framework for data broker transfers, received less attention — but it’s the mechanism that will generate the first FTC enforcement actions.

Who Is a Data Broker Under PADFAA?

The statute defines a data broker as an entity that, as a business, sells, licenses, trades for consideration, or provides access to covered data concerning a US individual that the entity did not collect directly from that individual.

The direct collection carve-out is critical. A bank that collects its own customer’s financial data, uses it for its own purposes, and shares it with its own affiliates is not a PADFAA data broker with respect to that data. The bank collected it directly.

But a company that:

  • Purchases aggregated financial data from a core processor and resells it to analytics vendors
  • Builds a financial profile product using data from multiple sources and licenses it to lenders
  • Operates a lead generation platform that monetizes consumer financial attributes purchased from third parties
  • Aggregates account data through an open banking API and sells analytical outputs to third parties

…may qualify as a PADFAA data broker, because the financial data at the core of its product was not collected directly from the consumers it describes.

Many fintechs have built exactly this kind of secondary data monetization business alongside their primary consumer product. A consumer lending platform that licenses its repayment behavior dataset to credit bureaus. A payments app that sells merchant spend analytics to advertising platforms. A banking aggregation service that provides financial insights to insurance companies. Each of these warrants a PADFAA coverage analysis.

What Counts as “Sensitive Data” — And Why Financial Records Are Front and Center

PADFAA’s sensitive data definition covers:

Data CategoryExamples in Financial Services
Government identifiersSocial Security numbers used in credit applications, EINs
Financial account dataAccount numbers, routing numbers, credit/debit card numbers
Precise geolocationTransaction location data, branch visit patterns
Biometric dataFingerprint/face authentication data for account access
Health dataMedical payment records, pharmacy transaction data
Private communicationsIn-app messages, email content in customer service systems
Browsing and search historyIf collected by a fintech’s embedded browser or app
Government benefits statusEBT transaction data, disability payment records

Financial account data is one of PADFAA’s enumerated sensitive categories — not inferred or implied. If your data product includes financial account numbers, credit card data, or transaction records, you are dealing with covered data.

Precise geolocation is worth a separate flag. Transaction location data — the coordinates attached to every card-present or mobile payment — is geolocation data. If you’re a payments platform that sells merchant analytics built from transaction location patterns, that data may be covered under both the geolocation category and the financial account category. The location data enforcement wave that hit Kochava, GM, and Allstate Arity in 2024-2026 demonstrates that geolocation is a top regulatory priority; PADFAA layered on top of that trend isn’t an incremental risk.

What the Thirteen Warning Letters Actually Signal

The FTC’s February 2026 letters were not the agency’s first PADFAA action. But they’re the clearest public signal of enforcement direction. The 13 letters went to named data brokers with the FTC’s explicit reminder that PADFAA violations carry civil penalties of up to $53,088 per violation — a number that can compound quickly when violations are measured per transaction or per record transferred.

FTC Commissioner Holyoak has publicly stated PADFAA enforcement as a priority. The warning letter pattern the agency uses is consistent: send letters establishing that companies are on notice, then file cases against entities that didn’t comply after receiving notice.

The 13 letters covered companies across the data broker spectrum — credit data aggregators, behavioral analytics firms, contact data companies. Financial services data was among the data types flagged. Whether the first enforcement case targets a financial services data company specifically, or a company with financial services data as one of many product lines, the underlying analysis is the same.

PADFAA vs. the DOJ Data Security Program: Two Frameworks, Different Scope

The DOJ’s Data Security Program, which became effective April 8, 2025, regulates a different set of data transactions. Understanding the distinction matters because they impose different obligations and enforcement mechanisms:

PADFAA is an FTC statute focused specifically on data brokers — companies that sell or license data they didn’t collect directly. It prohibits transferring sensitive data to foreign adversary entities. Enforcement is by the FTC through civil penalty actions. It applies broadly to the commercial data broker market.

The DOJ DSP applies to a broader range of entities (not just data brokers) and distinguishes between prohibited “restricted transactions” (which can’t happen at all) and “covered transactions” (which can happen subject to security requirements). The DOJ DSP focuses on bulk data transactions above defined thresholds and on specific relationship types — vendor agreements, employment arrangements, investment relationships. It’s enforced through civil and criminal action by the DOJ’s National Security Division.

If your company transfers significant volumes of sensitive data to foreign-connected entities — whether as a data monetization product or through vendor relationships — you may need both analyses. They’re not redundant; they cover different transaction types through different frameworks.

What Your Compliance Program Needs Before the First Case Drops

If your organization sells, licenses, or provides access to data you didn’t collect directly from the consumers it describes, PADFAA should be in your data governance framework. Here’s the compliance checklist:

1. Conduct a data product inventory. Map every data product or data sharing arrangement where you sell, license, or provide access to consumer data. For each product, determine whether the data was collected directly from consumers or aggregated from third-party sources.

2. Screen your buyers and licensees. For each data sharing arrangement where you may qualify as a data broker, conduct a counterparty screening to identify any connections to PADFAA’s six foreign adversary countries. Beneficial ownership screening matters — look through to ultimate beneficial owners, not just the contracting entity’s country of incorporation. Update your contract templates to include representations about foreign adversary ties and beneficial ownership.

3. Build a data broker determination into your product launch review. If your company is developing any new product that involves selling or licensing consumer data to third parties, add a PADFAA data broker determination to the pre-launch compliance checklist. This is particularly important for API-based data products, data licensing programs, and analytics platforms built on purchased data assets.

4. Review existing data licensing agreements. For contracts already in place, add a review for foreign adversary exposure. Update contract terms to require counterparty certification that the buyer is not owned or controlled by a foreign adversary country.

5. Establish a monitoring process for counterparty changes. PADFAA compliance is not a one-time point-in-time analysis. Buyers can be acquired. Ownership can change. A company that was PADFAA-compliant at contract signing may not be compliant 18 months later if the buyer was acquired by a foreign adversary-linked entity. Build periodic re-screening into your data licensing program management.

The Broader Picture: PADFAA in the 2026 Data Privacy Enforcement Landscape

PADFAA sits at the intersection of two enforcement trends that have been accelerating throughout 2026. The state-level data broker enforcement wave — California’s DELETE Act, New Jersey’s A5328, and the growing number of states requiring data broker registration — is establishing that data broker status has regulatory consequences across multiple frameworks simultaneously.

PADFAA adds a federal layer with a national security rationale and an FTC enforcement mechanism that can reach companies regardless of where they’re incorporated or where their customers are located. The statute’s scope is broad enough to capture most commercially significant data monetization businesses in the US.

The compliance calculus is straightforward: if you sell consumer data — particularly financial data — to third parties, determine whether PADFAA applies before the FTC files its first case and makes the analysis for you.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is PADFAA and when did it take effect?
PADFAA — the Protecting Americans' Data from Foreign Adversaries Act of 2024 — was signed into law in April 2024 and took effect June 23, 2024. The law prohibits data brokers from selling, licensing, renting, trading, transferring, releasing, disclosing, providing access to, or otherwise making available personally identifiable sensitive data of US individuals to a foreign adversary country or to an entity controlled by or owned by a foreign adversary country. Congress passed PADFAA as part of the same legislation that imposed requirements on TikTok, driven by national security concerns about US consumer data — including financial records — being accessible to adversary intelligence services.
Who counts as a 'data broker' under PADFAA?
PADFAA applies to entities that, as a business, sell, license, trade for consideration, or provide access to covered data concerning a US individual that the entity did not collect directly from that individual. The key phrase is 'did not collect directly from that individual.' A bank that collects its own customers' financial data and shares it with its affiliates is not a PADFAA data broker. But a company that purchases, aggregates, or licenses financial data from multiple sources and resells or shares it — a data aggregator, a credit data reseller, a lead generator that monetizes financial profiles — may qualify. Many fintechs that have built data monetization businesses alongside their core product sit precisely in this ambiguous territory.
What categories of data are 'sensitive' under PADFAA?
PADFAA's sensitive data definition is broad. It covers: government-issued identifiers (Social Security numbers, passport numbers, driver's license numbers); financial account and credit/debit card numbers; biometric data; genetic data; precise geolocation data; private communications content (messages, emails); browsing and search histories; health and medical data; and data revealing religious practices, immigration status, political views, or sexual behavior or orientation. Financial account data is explicitly covered. A fintech that aggregates account balances, transaction histories, credit scores, or payment patterns — and shares or sells that data to a party with foreign adversary ties — falls directly within the statute.
Which countries are designated 'foreign adversaries' under PADFAA?
The six foreign adversary countries designated under PADFAA, by reference to 15 U.S.C. §4872(d), are: China (including Hong Kong), Russia, Iran, North Korea, Cuba, and Venezuela. The designation is entity-level, not just geography: a company incorporated in Singapore but majority-owned by a Chinese national or controlled by the Chinese government falls within the prohibition. The FTC has signaled it will look through corporate structures to identify beneficial ownership, as the national security concern driving the statute is data access by adversary-state intelligence services, not just country-of-incorporation formalism.
What is the difference between PADFAA and the DOJ Data Security Program (DSP)?
PADFAA and the DOJ's Data Security Program (DSP), which became effective in April 2025, address related but distinct concerns. PADFAA prohibits data brokers specifically from transferring sensitive data to foreign adversary entities — it is primarily an FTC enforcement statute aimed at the commercial data broker market. The DOJ DSP is broader: it restricts data transactions involving sensitive US government or personal data with covered foreign adversaries, applies to a wider range of companies (not just data brokers), and distinguishes between 'restricted transactions' (prohibited) and 'covered transactions' (requiring security requirements). If you're a fintech with significant data flows, both statutes may apply depending on your data types and transaction partners. PADFAA typically captures the data monetization side; DSP captures the vendor and cross-border transfer side.
We use cloud infrastructure and SaaS tools from global vendors. Could that create PADFAA exposure?
The PADFAA prohibition is focused on deliberate transfers — sales, licenses, and intentional provision of access — not on standard vendor hosting arrangements where the vendor processes data on your behalf under a service agreement and data processing addendum. That said, if a SaaS vendor's subprocessors include entities with significant foreign adversary ties, and those subprocessors have access to sensitive US consumer financial data, you should conduct a data flow mapping exercise to understand the exposure. PADFAA is a separate analysis from the DOJ DSP vendor provisions — confirm with counsel which statute applies to which data flows in your architecture.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Data Privacy Compliance Kit

Multi-state privacy compliance templates covering 19 state laws plus GLBA and CCPA.

◆ Keep reading

Related posts.

Data Privacy

FTC Chairman Ferguson Says a Privacy Enforcement Surge Is Coming in H2 2026. Here's What Financial Services Companies Need in Place.

FTC Chairman Andrew Ferguson publicly warned that reporters covering the FTC will 'have a hard time keeping up' with the number of privacy enforcement cases coming in the second half of 2026. The Kochava settlement and new Section 5 standalone data-security cases telegraph exactly what's in the crosshairs. Here's what financial services companies need to have documented before the cases start landing.

Sep 9, 2026

Data Privacy

CalPrivacy Has Issued Eight Data Broker Fines and Is Still Going. What the September 2026 Enforcement Advisory Means for Your Fintech.

California's Privacy Protection Agency issued Enforcement Advisory 2026-01 on September 3, making clear that inaccurate data broker registration is a live $200-per-day penalty risk. Two August 2026 settlements and eight prior enforcement actions signal that CalPrivacy is done with warnings. Here's what fintech compliance teams need to know.

Sep 7, 2026

Data Privacy

GM Paid $12.75M for Selling Driver Data Without Consent. Your Fintech May Have the Same Problem.

California's record $12.75M CCPA settlement with General Motors over unconsented data sales to LexisNexis and Verisk exposes a pattern that runs through fintech: sharing consumer data with analytics firms, credit bureaus, and third parties without adequate notice or consent. Here's what the enforcement signal means for financial services compliance teams.

Sep 3, 2026

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.