On August 12, 2026, President Trump issued a memorandum directing the creation of a federal program (the “Program”) under which vetted U.S. companies may be authorized to conduct certain cyber operations against foreign cyber-enabled transnational criminal organizations (“CE-TCOs”) under U.S. government control and oversight. The memorandum assigns joint leadership to the Department of Justice (“DOJ”) and Department of Homeland Security (“DHS”), requires implementing procedures within 60 days, and sets out the basic structure, approval requirements, operational definitions, and safeguards for the Program.The memorandum states that the Program is intended to expand federal efforts to combat cyber-enabled crime, fraud, and related schemes targeting Americans by incorporating private-sector cyber capabilities into government operations.
Program Structure
The memorandum directs the National Coordination Center (“NCC”), established pursuant to Executive Order 14159, to create, manage, and maintain the Program.
The Program will authorize private “Participating Companies” to conduct Cyber Surveillance Operations and Cyber Effects Operations. The memorandum states that these operations are to be conducted exclusively on behalf of, and under the supervision of, the federal government as part of lawful investigatory, protective, or intelligence operations carried out by federal law enforcement.
The Program is to be overseen by two co-Executive Directors, one from the DOJ, designated by the Attorney General, and one from DHS, designated by the Secretary of Homeland Security. These officials may approve cyber operations after coordinating with one another, except for operations resulting in defined “Critical Outcomes.”
Participating Companies
The memorandum defines “Participating Companies” as private U.S. companies accepted into the Program and authorized to conduct cyber operations under government direction. Participating Companies must enter into contracts with the DOJ or DHS to ensure rigorous vetting of Participating Companies and adherence to operational procedures established in implementing guidance.
The memorandum also permits Participating Companies to enter into commercial agreements with private sector entities and with federal, state, local, tribal, and territorial agencies. Private sector entities may provide to Participating Companies threat information collected in the course of those entities’ normal business activities for the purpose of proposing responsive cyber operations to the NCC. Government agencies may identify CE-TCO threats to Participating Companies in a manner that enables them to propose responsive cyber operations to the NCC.
Required Implementing Procedures
Within 60 days, the Program Executive Directors, in coordination with the Homeland Security Council, must establish operating procedures for the Program. The memorandum provides that no operation may be approved unless it complies with such operating procedures.
According to the memorandum, the operating procedures must address: (1) minimum eligibility and performance standards; (2) participation by large and smaller specialized companies; (3) disclosure of certain contractual relationships; (4) operational workflows (5) target-identification processes; (6) reporting requirements; (7) DOJ review where an operation implicates a U.S. person or other constitutional, statutory, or international law considerations; (8)cessation and notification procedures if operations exceed approved parameters; (9) annual evaluation of Participating Companies; and (10) written approval and direction before any cyber operation may proceed. The memorandum also authorizes DOJ and DHS to require Participating Companies to maintain a bond or escrow of at least $1 million as a condition of participation in the Program.
Covered Activity
The memorandum identifies two types of cyber operations that Participating Companies may conduct: (1) “Cyber Surveillance Operation,” which is defined as an activity conducted primarily to collect information or intelligence from information systems, networks, or infrastructure, including information that may be used for future cyber effects operations, with the intent to remain undetected; and (2) “Cyber Effects Operation,” which is defined as an activity resulting in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, infrastructure, or data.
Critical Outcomes and Safeguards
Operations resulting in “Critical Outcomes” are excluded from the approval authority delegated to the Program Executive Directors. The memorandum defines “Critical Outcomes” as actions likely to result in loss of life or serious injury, or to rise to the level of use of force or armed attack under international law.
The memorandum also requires procedures addressing operations directed at U.S. persons or affecting domestic systems. It provides that Participating Companies must cease operations, conduct minimization, and notify the NCC if they discover activity exceeding approved parameters, including unintentional targeting of a U.S. person, an information system in the United States, or an information system under the control of a U.S. person.
Reporting and Legal Framework
The memorandum requires the Program Executive Directors to submit a status report to the Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor and the National Cyber Director within 180 days and annually thereafter. It further states that Program activities must be conducted in accordance with the Constitution, applicable law, and U.S. international obligations, including 18 U.S.C. § 1030. The memorandum also provides that it does not create any enforceable right or benefit against the U.S. or any other person.
Search
Recent Posts
Categories
- Behavioral Advertising
- Centre for Information Policy Leadership
- Children’s Privacy
- Cyber Insurance
- Cybersecurity
- Enforcement
- European Union
- Events
- FCRA
- Financial Privacy
- General
- Health Privacy
- Identity Theft
- Information Security
- International
- Marketing
- Multimedia Resources
- Online Privacy
- Security Breach
- U.S. Federal Law
- U.S. State Law
- Workplace Privacy
Tags
- Aaron P. Simpson
- Accountability
- Adequacy
- Advertisement
- Advertising
- Age Appropriate Design Code
- Age Verification
- Alabama
- American Privacy Rights Act
- Anna Pateraki
- Anonymization
- Anti-terrorism
- APEC
- Apple Inc.
- Argentina
- Arkansas
- Article 29 Working Party
- Artificial Intelligence (AI)
- Attorney General
- Audit
- Australia
- Austria
- Automated Decisionmaking
- Baltimore
- Bankruptcy
- Belgium
- Biden Administration
- Big Data
- Binding Corporate Rules
- Biometric Data
- Blockchain
- Bojana Bellamy
- Brazil
- Brexit
- British Columbia
- Brittany Bacon
- Brussels
- Business Associate Agreement
- BYOD
- California
- CalPrivacy
- CAN-SPAM
- Canada
- Cayman Islands
- CCPA
- CCTV
- Centre for Information Policy Leadership (CIPL)
- Chatbot
- Children’s Online Privacy Protection Act (COPPA)
- Chile
- China
- Chinese Taipei
- Christopher Graham
- CIPA
- Class Action
- Clinical Trial
- Cloud
- Cloud Computing
- CNIL
- Colombia
- Colorado
- Committee on Foreign Investment in the United States
- Commodity Futures Trading Commission
- Compliance
- Computer Fraud and Abuse Act
- Congress
- Connecticut
- Consent
- Consent Order
- Consumer Protection
- Consumer Rights
- Cookies
- COPPA
- Coronavirus/COVID-19
- Council of Europe
- Council of the European Union
- Court of Justice of the European Union
- CPPA
- CPRA
- Credit Monitoring
- Credit Report
- Criminal Law
- Critical Infrastructure
- Croatia
- Cross-Border Data Flow
- Cross-Border Data Transfer
- Cyber Attack
- Cybersecurity
- Cybersecurity and Infrastructure Security Agency
- Data Breach
- Data Brokers
- Data Controller
- Data Localization
- Data Minimization
- Data Privacy Framework
- Data Processor
- Data Protection Act
- Data Protection Authority
- Data Protection Impact Assessment
- Data Protection Officer
- Data Security
- Data Transfer
- David Dumont
- David Vladeck
- Deceptive Trade Practices
- Delaware
- Denmark
- Department of Commerce
- Department of Defense
- Department of Health and Human Services
- Department of Homeland Security (DHS)
- Department of Justice
- Department of the Treasury
- Design
- Digital Markets Act
- District of Columbia
- Do Not Call
- Do Not Track
- Dobbs
- Dodd-Frank Act
- DORA
- DPIA
- E-Privacy
- E-Privacy Directive
- Ecuador
- Ed Tech
- Edith Ramirez
- Electronic Communications Privacy Act
- Electronic Privacy Information Center
- Electronic Protected Health Information
- Elizabeth Denham
- Employee Monitoring
- Encryption
- ENISA
- EU Data Protection Directive
- EU General Data Protection Regulation (GDPR)
- EU Member States
- European Commission
- European Data Protection Board
- European Data Protection Supervisor
- European Parliament
- European Union
- Facial Recognition Technology
- FACTA
- Fair Credit Reporting Act
- Fair Information Practice Principles
- Federal Aviation Administration
- Federal Bureau of Investigation
- Federal Communications Commission
- Federal Data Protection Act
- Federal Trade Commission
- FERC
- Financial Data
- FinTech
- Florida
- Food and Drug Administration
- Foreign Intelligence Surveillance Act
- France
- Franchise
- Fred Cate
- Freedom of Information Act
- Freedom of Speech
- Fundamental Rights
- GDPR
- Genetic Data
- Geofencing
- Geolocation
- Geolocation Data
- Georgia
- Germany
- Global Privacy Assembly
- Global Privacy Enforcement Network
- Gramm Leach Bliley Act
- Grok
- Hacker
- Hawaii
- Health Data
- HIPAA
- HITECH Act
- Hong Kong
- House of Representatives
- Hungary
- Illinois
- India
- Indiana
- Indonesia
- Information Commissioners Office
- Information Sharing
- Insurance Provider
- Internal Revenue Service
- International Association of Privacy Professionals
- International Commissioners Office
- Internet
- Internet of Things
- Iowa
- IP Address
- Ireland
- Israel
- Italy
- Jacob Kohnstamm
- Japan
- Jason Beach
- Jay Rockefeller
- Jenna Rode
- Jennifer Stoddart
- Jersey
- Jessica Rich
- John Delionado
- John Edwards
- Kentucky
- Korea
- Large Language Model
- Latin America
- Laura Leonard
- Law Enforcement
- Lawrence Strickling
- Legislation
- Liability
- Lisa Sotto
- Litigation
- Location-Based Services
- London
- Louisiana
- Madrid Resolution
- Maine
- Malaysia
- Maryland
- Massachusetts
- Meta
- Mexico
- Michigan
- Microsoft
- Minnesota
- Missouri
- Mobile
- Mobile App
- Mobile Device
- Montana
- Morocco
- MySpace
- Natascha Gerlach
- National Institute of Standards and Technology
- National Labor Relations Board
- National Science and Technology Council
- National Security
- National Security Agency
- National Telecommunications and Information Administration
- Nebraska
- NEDPA
- Netherlands
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- New Zealand
- Nigeria
- Ninth Circuit
- North Carolina
- North Dakota
- North Korea
- Norway
- Obama Administration
- OCPA
- OECD
- Office for Civil Rights (OCR)
- Office of Foreign Assets Control
- Ohio
- Oklahoma
- Online Behavioral Advertising
- Online Privacy
- Opt-In Consent
- Opt-Out
- Oregon
- Outsourcing
- Pakistan
- Parental Consent
- Payment Card
- PCI DSS
- Penalty
- Pennsylvania
- Personal Data
- Personal Health Information
- Personal Information
- Personally Identifiable Information
- Peru
- Philippines
- Poland
- PRISM
- Privacy
- Privacy and Information Security Law
- Privacy By Design
- Privacy Notice
- Privacy Policy
- Privacy Rights
- Privacy Rule
- Privacy Shield
- Profiling
- Protected Health Information
- Purpose Limitation
- Ransomware
- Record Retention
- Red Flags Rule
- Rhode Island
- Richard Thomas
- Right to Be Forgotten
- Right to Privacy
- Risk Assessment
- Risk-Based Approach
- ROSCA
- Rosemary Jay
- Russia
- Safe Harbor
- Salesforce
- Sanctions
- Schrems
- Scott Kimpel
- SECURE Data Act
- Securities and Exchange Commission
- Security Rule
- Senate
- Sensitive Data
- Serbia
- Service Provider
- Singapore
- Smart Grid
- Smart Metering
- Social Media
- Social Security Number
- South Africa
- South Carolina
- South Dakota
- South Korea
- Spain
- Spyware
- Standard Contractual Clauses
- State Attorneys General
- Steven Haas
- Stick With Security Series
- Stored Communications Act
- Student Data
- Supreme Court
- Surveillance
- Surveillance Pricing
- Sweden
- Switzerland
- Taiwan
- Targeted Advertising
- Telecommunications
- Telemarketing
- Telephone Consumer Protection Act
- Tennessee
- Terry McAuliffe
- Texas
- Text Message
- Thailand
- Transparency
- Transportation Security Administration
- Trump Administration
- United Arab Emirates
- United Kingdom
- United States
- Unmanned Aircraft Systems
- Uruguay
- Utah
- Vermont
- Video Privacy Protection Act
- Video Surveillance
- Virginia
- Viviane Reding
- Washington
- Whistleblowing
- Wireless Network
- Wiretap
- ZIP Code