Cybersecurity, Privacy, & AI

Trending Now
GSA Introduces a New Framework for Protecting CUI in Contractor Systems • The AI Power Crunch: 3 Ways Renewable Developers Can Win the “Data Center” Game • International AI Safety Report 2026 Examines AI Capabilities, Risks, and Safeguards • Why ‘Secure-by-Design’ Systems Are Non-Negotiable in the AI Era • CISA to Furlough Most of Its Workforce Under Impending DHS Shutdown

Buy American, Hire American: Will It Impact a Government Contractor’s Ability to Store Data Offshore?

The administration’s April “Buy American and Hire American” executive order, and “Buy American” bills in the House and Senate, are all pushing for the same simple idea. One little-examined angle of these initiatives is the question of how it affects government contractors, and where they maintain or store data relating to their performance of those contracts.

Attorneys Merle M. DeLancey, Jr. and Lyndsay A. Gorton point out that there are no federal regulations prohibiting contractors from using non-U.S. service providers for this data. But the question of where their service providers are located is being raised in contract bidding at both federal and state levels, and seven states prohibit contractors from using overseas providers without a waiver.

The Senate’s “BuyAmerican.gov Act” would clamp down on waivers, requiring more thorough justification and reporting of them. In addition to vouching for the security of private or classified data, contractors would be required to publicly justify hiring a vendor not located in the U.S.

Companies offshoring data operations could then face public backlash, challenges of their contract awards, and even liability under the False Claims Act, and should be prepared for any of these.

More at Blank Rome

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.