(a) In addition to the factors identified in subsections (f)(1)-(10) of section 721, the Committee shall consider, in reviewing the effects of a covered transaction on the national security of the United States, the following factors relating to aggregate industry investment trends that may have consequences for an individual covered transaction's impact on national security:
(i) Incremental investments over time in a sector or technology may cede, part-by-part, domestic development or control in that sector or technology and may give a foreign person who might take actions that threaten to impair the national security of the United States as a result of the transaction, or their relevant third-party ties that might cause the transaction to pose such a threat, control of or rights in United States businesses in a manner that may result in national security risk. A series of acquisitions in the same, similar, or related United States businesses involved in activities that are fundamental to national security or on terms that implicate national security may result in a particular covered transaction giving rise to a national security risk when considered in the context of transactions that preceded it. In aggregate, these transactions may facilitate harmful technology transfer in key industries or otherwise harm national security through the cumulative effect of these investments. As the Congress identified in section 1702(c)(2) of FIRRMA, the Committee may consider “the cumulative control of, or pattern of recent transactions involving, any one type of critical infrastructure, energy asset, critical material, or critical technology by a foreign government or foreign person” in considering national security risks. Contextualizing the Committee's review of an individual transaction in light of the aggregate or series of related transactions could reveal national security risks arising from the covered transaction that were not otherwise apparent.
(ii) The Committee shall consider, as appropriate, as part of the Committee's review of a covered transaction, the risks arising from the covered transaction in the context of multiple acquisitions or investments in a single sector or in related manufacturing capabilities, services, critical mineral resources, or technologies, by any foreign person who might take actions that threaten to impair the national security of the United States as a result of the transaction, or involving relevant third-party ties that might cause the transaction to pose such a threat.
(iii) The Committee may request, as part of the Committee's review of a covered transaction, that the Department of Commerce's International Trade Administration provide the Committee an analysis of the industry or industries in which the United States business operates, and the cumulative control of, or pattern of recent transactions by, a foreign person, including, directly or indirectly, a foreign government, in that sector or industry.
(b) In addition to the factors identified in subsections (f)(1)-(10) of section 721, the Committee shall consider, in reviewing the effects of a covered transaction on the national security of the United States, the following factors relating to cybersecurity risks resulting from a covered transaction that threaten to impair national security:
(i) It is important for the United States to ensure that foreign investment in United States businesses does not erode United States cybersecurity. Investments by foreign persons with the capability and intent to conduct cyber intrusions or other malicious cyber-enabled activity—such as activity designed to affect the outcome of any election for Federal, State, Tribal, local, or territorial office; the operation of United States critical infrastructure; or the confidentiality, integrity, or availability of United States communications—may pose a risk to national security. The Congress, in section 1702(c)(6) of FIRRMA, identified “exacerbating or creating new cybersecurity vulnerabilities” as a relevant consideration for the Committee when considering national security risks arising from a covered transaction. Review of foreign investment is an important tool as part of broader United States efforts to ensure the cybersecurity of the United States.
(ii) The Committee shall consider, as appropriate, whether a covered transaction may provide a foreign person who might take actions that threaten to impair the national security of the United States as a result of the transaction, or their relevant third-party ties that might cause the transaction to pose such a threat, with direct or indirect access to capabilities or information databases and systems on which threat actors could engage in malicious cyber-enabled activities affecting the interests of the United States or United States persons, including:
(A) activity designed to undermine the protection or integrity of data in storage or databases or systems housing sensitive data;
(B) activity designed to interfere with United States elections, United States critical infrastructure, the defense industrial base, or other cybersecurity national security priorities set forth in Executive Order 14028 of May 12, 2021 (Improving the Nation's Cybersecurity); and
(C) the sabotage of critical energy infrastructure, including smart grids.
(iii) The Committee shall also consider, as appropriate, the cybersecurity posture, practices, capabilities, and access of both the foreign person and the United States business that could allow a foreign person who might take actions that threaten to impair the national security of the United States as a result of the transaction, or their relevant third-party ties that might cause the transaction to pose such a threat, to manifest cyber intrusion and other malicious cyber-enabled activity within the United States.
(c) In addition to the factors identified in subsections (f)(1)-(10) of section 721, the Committee shall consider, in reviewing the effects of a covered transaction on the national security of the United States, the following factors relating to national security concerns surrounding sensitive data:
(i) Data is an increasingly powerful tool for the surveillance, tracing, tracking, and targeting of individuals or groups of individuals, with potential adverse impacts on national security. In section 1702(c)(5) of FIRRMA, the Congress recognized that the Committee may consider whether a covered transaction may “expose, either directly or indirectly, personally identifiable information, genetic information, or other sensitive data of United States citizens to access by a foreign government or foreign person that may exploit that information in a manner that threatens national security.” Moreover, advances in technology, combined with access to large data sets, increasingly enable the re-identification or de-anonymization of what once was unidentifiable data. Therefore, it is important for the United States Government to stay current with threats posed by advances in such technology, including by considering potential risks posed by foreign persons who might exploit access to certain data on United States persons to target individuals or groups within the United States to the detriment of national security. Accordingly, the Committee shall consider whether foreign investments in United States businesses that have access to or that store United States persons' sensitive data, including health and biological data, involve a foreign person who might take actions that threaten to impair the national security of the United States as a result of the transaction, including whether the foreign person might have relevant third-party ties that might cause the transaction to pose such a threat.
(ii) The Committee shall consider, as appropriate, whether a covered transaction involves a United States business that:
(A) has access to United States persons' sensitive data, including United States persons' health, digital identity, or other biological data and any data that could be identifiable or de-anonymized, that could be exploited to distinguish or trace an individual's identity in a manner that threatens national security; or
(B) has access to data on sub-populations in the United States that could be used by a foreign person to target individuals or groups of individuals in the United States in a manner that threatens national security.
(iii) The Committee shall also consider, as appropriate, whether a covered transaction involves the transfer of United States persons' sensitive data to a foreign person who might take actions that threaten to impair the national security of the United States as a result of the transaction, and whether the foreign person has relevant third-party ties that have sought to exploit such information or have the ability to exploit such information to the detriment of national security, including through the use of commercial or other means.