Webull’s China Scrutiny: Why U.S. Data Storage Is Only Part of the Compliance Picture

Congressional scrutiny of Webull brings renewed attention to the relationship between data residency, foreign access, corporate control, and the Department of Justice’s Data Security Program.

Where a company stores customer information is an important compliance question. Who can access that information and who can influence the systems that process it may be just as consequential.

That distinction is central to the congressional scrutiny of digital brokerage platform Webull. An October 7, 2026 CNBC report described a bipartisan House committee’s concerns about the company’s connections to China. The subsequent publication of the committee’s investigation provides a broader basis for examining the legal and operational questions facing businesses with international technology teams and sensitive U.S. data.

The practical significance extends beyond brokerage firms. Fintech companies, software providers, healthcare businesses, and other organizations increasingly depend on global engineering, support, and cloud infrastructure. Those arrangements require an assessment of data access alongside server location, contractual protections, and corporate structure.

What the Committee Alleged and How Webull Responded

On October 7, 2026, the House Select Committee on the Strategic Competition Between the United States and the Chinese Communist Party released Free Trades, Hidden Ties: Exposing Webull’s China Links. It raises concerns about the relationship between the U.S. brokerage, a Singapore technology entity, and a mainland China subsidiary that supports technology development and platform operations.

The report questions whether China-based personnel and infrastructure could access or influence systems that handle American investor information, despite assurances of domestic storage. It also identifies unanswered questions about historical use of Tencent Cloud and associated data migration and access records. These are the committee’s findings and inferences, rather than independently verified conclusions of this article.

The committee’s official announcement identifies additional concerns involving personnel disclosures, corporate control, regulatory safeguards, Chinese government funding, and clearing and custody arrangements.

Webull disputes the report. In a statement published on October 7, the company said the committee’s conclusions were inaccurate and unsupported, and criticized the investigation’s lack of clarification requests. Webull maintained that its U.S. business operates from Florida and New York, U.S. customer data is stored domestically, and access to sensitive customer information is controlled in the United States.

A congressional investigation is distinct from a judicial decision or agency enforcement determination. The materials discussed here do not establish that Chinese authorities obtained Webull customer data or that Webull violated the DOJ’s data-transfer restrictions. The report itself acknowledges that the Chinese laws it discusses do not prove government access occurred. The compliance questions nevertheless warrant attention.

Data Residency and Data Access Are Different Questions

Data residency concerns where information is stored. Data access concerns the people, entities, and systems capable of obtaining or interacting with it. A U.S. database may coexist with offshore support accounts, globally administered cloud services, overseas debugging workflows, or development environments containing copies of production records.

The DOJ rule’s definition of access encompasses logical and physical access, including capabilities to read, copy, decrypt, edit, divert, or otherwise affect data. It also directs that access be assessed without considering the effect of the prescribed security requirements when determining whether a transaction is covered. Companies therefore need to distinguish initial transaction coverage from the controls that may authorize a restricted transaction.

For an operational review, consider the following examples. These are assessment questions, not assertions about Webull’s systems:

Arrangement or assuranceQuestion to investigate
Customer records remain in a U.S. cloud region.Can overseas personnel query the database or obtain records through support tools?
Production access is limited.Do logs, backups, test environments, or troubleshooting attachments contain the same sensitive information?
Data is encrypted.Who controls keys, credentials, and applications that decrypt or display the records?
U.S. staff approve access requests.Are approvals narrow, temporary, recorded, and technically enforced?
Offshore developers cannot directly view customer records.Can their deployment privileges change logging, exports, or access permissions?

A development team’s location does not, by itself, establish prohibited access. Its permissions, employer, responsibilities, and relationship to the relevant data transactions require examination. Conversely, a statement about U.S. hosting does not answer those questions.

The Connection to the Airwallex Controversy

Our earlier analysis, When Data Residency Meets Geopolitical and Competitive Reality: The Airwallex Controversy and DOJ Data Transfer Rules, examined a related dispute about international fintech operations and the segregation of U.S. customer data.

Webull and Airwallex involve different businesses, allegations, and factual records. Neither controversy establishes the facts of the other. Their common compliance lesson is that businesses should be prepared to substantiate claims about access boundaries across affiliates and jurisdictions.

That substantiation should connect legal relationships to technical evidence: which entity employs each relevant team, which systems the team administers, what information those systems contain, and what prevents access outside authorized purposes. An organizational chart and a list of hosting locations are useful starting points; they need to be reconciled with actual operating practices.

How the DOJ Data Security Program Fits Into the Analysis

The DOJ Data Security Program, implemented through 28 C.F.R. Part 202, addresses specified transactions that could give countries of concern or covered persons access to Americans’ bulk sensitive personal data or U.S. government-related data. The program took effect on April 8, 2025. China, including Hong Kong and Macau, is among the designated countries of concern.

Our overview of the DOJ data-transfer rule discusses the framework’s origins and principal requirements. Applying it to a particular business requires a transaction-specific analysis.

1. Identify the Data and Applicable Thresholds

Brokerage operations can involve financial account information, transaction records, and personal identifiers. Under the rule’s bulk thresholds, personal financial data concerning more than 10,000 U.S. persons can qualify as bulk data. Covered personal identifiers generally have a threshold of more than 100,000 U.S. persons. Other categories have different thresholds, and combined datasets require separate analysis.

The thresholds account for relevant transactions aggregated across the same U.S. person and the same foreign person or covered person over the preceding 12 months. Government-related data is addressed separately and does not require meeting the bulk thresholds.

Encryption and de-identification do not automatically remove information from the definition of bulk U.S. sensitive personal data. Companies should assess what information exists and how it is used before relying on a security measure as a coverage exclusion.

2. Determine Whether the Counterparty Is a Covered Person

The covered-person definition reaches specified foreign entities based on incorporation, principal place of business, or qualifying ownership, as well as certain foreign individuals based on employment, contracting relationships, or primary residence. The Attorney General can also designate persons under the rule.

Chinese citizenship alone does not automatically make every individual a covered person. Likewise, any Chinese investment does not automatically satisfy the entity ownership tests. U.S.-person status, ownership percentages, residence, and employment relationships matter. Businesses should apply the actual regulatory criteria rather than substituting broad labels about nationality or foreign ties.

3. Classify the Transaction

The program distinguishes prohibited transactions from restricted transactions. Specified data-brokerage transactions with countries of concern or covered persons are prohibited. Covered vendor, employment, and investment agreements may fall within the restricted-transaction framework, subject to applicable exceptions, exemptions, and other requirements.

Accordingly, an offshore technology services arrangement should be evaluated by asking what agreement exists, who the parties are, what covered data is involved, and what access the arrangement provides. A business does not need to describe itself as a data broker for its vendor or employment arrangements to raise DSP issues.

Financial Institutions Are Not Categorically Exempt

The financial-services exemption covers data transactions to the extent they are ordinarily incident to and part of providing qualifying financial services. Its scope includes specified banking, capital-markets, payment-processing, and investment-management activities. It does not exempt every data transaction undertaken by a regulated financial institution.

The DOJ’s FAQs, particularly Question 75, expressly distinguish financial institutions from exempt activities. For example, a cloud-service or employment arrangement giving a covered person access to bulk sensitive U.S. data for wholly domestic financial operations is not automatically exempt merely because the customer is a financial institution.

The regulation illustrates the distinction through contrasting examples: certain offshore processing associated with international payments may qualify, while an otherwise comparable arrangement supporting payments solely between U.S. persons in the United States may not. The business purpose and underlying financial activity matter.

For a brokerage or fintech company, the appropriate inquiry therefore separates individual financial-service flows from platform development, infrastructure administration, analytics, and other supporting arrangements. Each claimed exemption should be tied to its legal basis and supporting facts.

Affiliate Relationships Also Require a Specific Exemption Analysis

The corporate-group exemption addresses qualifying transactions between a U.S. person and its subsidiary or affiliate that are ordinarily incident to administrative or ancillary business operations. Listed examples include human resources, payroll, regulatory compliance, risk management, and customer support.

It is not a blanket authorization for sharing sensitive customer data throughout a corporate group. The regulation specifically distinguishes qualifying support activities from sending bulk financial data to a foreign subsidiary to develop a financial software tool. Customer support can qualify in appropriate circumstances; product development should not be reclassified as support simply to invoke an exemption.

The practical approach is to identify each affiliate’s functions and separate the associated data flows. Shared ownership does not eliminate the need to determine why access occurs and whether the specific transaction fits the exemption.

Cybersecurity Assurances Need Evidence and Appropriate Scope

Encryption, access policies, and independent assurance reports can provide valuable evidence of security controls. Their usefulness depends on what they actually cover. A report addressing one entity or system may leave other affiliates, support environments, or administrative pathways outside its scope.

As a practical matter, businesses should examine the systems tested, relevant time periods, control exceptions, key custody, privileged access, and changes since testing. A SOC 2 report can inform diligence, but it should not be treated as a legal determination that a particular cross-border arrangement complies with Part 202.

For restricted transactions, the prescribed security requirements are incorporated into the DOJ framework. As described by NIST’s incorporated-standards resource, they encompass organizational and system requirements alongside data protections such as minimization, masking, encryption, or privacy-enhancing techniques. Selecting familiar controls without examining the applicable requirements is insufficient.

The rule also requires a data compliance program for persons engaging in restricted transactions, including auditable verification of relevant data flows and parties and annual certification of specified policies. Its audit requirements call for a qualified, independent auditor and an audit for each calendar year involving restricted transactions. These obligations have applied since October 6, 2025.

This is a point of convergence between cross-border data-transfer counseling and cybersecurity legal advice: the legal classification of an arrangement needs to be supported by controls that operate as described and evidence that can be reviewed.

The DOJ Framework Operates Alongside Financial Privacy Requirements

Financial-sector security duties remain relevant even if a particular transaction is exempt from the DSP. The SEC’s 2024 amendments to Regulation S-P strengthened requirements concerning incident response, customer information safeguards, service-provider oversight, and compliance records for covered institutions.

The SEC’s small entity compliance guide identifies compliance dates of December 3, 2025 for larger entities and June 3, 2026 for smaller entities. Both dates have passed as of this article. Overseas technology and support arrangements should therefore be assessed within the institution’s broader security and incident-response obligations.

A DSP exemption answers a question under that program. It does not resolve whether an organization meets other applicable privacy, cybersecurity, contractual, or regulatory requirements. Businesses handling data across multiple markets may also need separate analyses under the relevant foreign transfer regimes.

What Businesses Should Review Now

The following steps provide a practical starting point for organizations with sensitive U.S. data and international operations. Their scope should reflect the business’s actual risk and applicable legal obligations.

  1. Map access as well as storage. Include production systems, support platforms, logs, backups, development environments, cloud administration, and encryption-key management.
  2. Connect permissions to legal entities. Identify who employs relevant personnel, which entities provide technology services, and who can approve or modify access.
  3. Classify the arrangements. Record the relevant data categories, volumes, counterparties, transaction types, and supporting basis for any exemption.
  4. Reconcile contracts with operations. Check that access restrictions, subcontracting terms, audit rights, incident reporting, and foreign-government request procedures reflect how services are actually delivered.
  5. Test the claimed boundaries. Examine privilege escalation, emergency access, deployment permissions, and export capabilities. Use synthetic test data where practical to reduce unnecessary exposure.
  6. Preserve the evidence. Retain access reviews, migration records, approvals, control assessments, and required compliance documentation so that statements can be substantiated.
  7. Reassess material changes. New investors, acquisitions, support locations, cloud providers, and platform integrations may alter the underlying analysis.

The DOJ’s compliance guide also explains an important limit: the DSP generally does not require a U.S. company to investigate every employee of a foreign vendor that is not a covered person, absent circumstances involving evasion or knowing direction. A broader cybersecurity review may reasonably examine personnel access, but businesses should distinguish that risk-management work from the program’s specific legal requirements.

Proposed Brokerage Reforms Are a Separate Development

The committee recommended stronger regulatory visibility into brokerage operations, additional protections for financial records, scrutiny of clearing and custody relationships, and changes concerning foreign-controlled broker-dealers and CFIUS jurisdiction.

These are policy recommendations. Their inclusion in the committee’s announcement does not itself create new obligations. Companies should track any subsequent legislation, rulemaking, or enforcement action while continuing to assess the laws already applicable to their operations.

Our Takeaway

Businesses should be able to explain and substantiate where sensitive data resides, who can access it, which entities control the relevant systems, and why each cross-border arrangement is legally permitted.

The Webull investigation illustrates how questions about privacy, cybersecurity, corporate structure, and national security can converge. It does not establish that every company with Chinese operations violates U.S. law. It does reinforce the need for careful, evidence-based analysis of international data access.

For businesses navigating these issues, the goal is a defensible relationship between legal obligations, contractual commitments, technical controls, and public representations.


RICHT LAW FIRM PLLC advises businesses on cross-border data transfers and cybersecurity compliance, including the evaluation of international data arrangements and related contractual risks.