ACE Rebrand Update: The Alliance for Citizen Engagement is now the Alliance for Civic Engagement.

U.S. Regulations on Foreign Applications: An Overview

U.S. Regulations on Foreign Apps An Overview
Authors: Jan De Leon, Samarth Ghodke, Kiera Glazer, Katelyn Balakir
Coauthors: Jake Ryan, Olivia Scott

In U.S. foreign policy, an application is classified as a foreign technology if it is controlled by a company not headquartered within the United States. As some applications update precise location and other trackers as frequently as 14,000 times a day, foreign applications and online privacy have bred considerable security concerns. While many apps are safe to use, relationships with foreign nations are subject to change, and few countries have reliable data ethics regulations in place. For example, China’s information regulation laws “grant Beijing broad authority to access data from companies based in China,” such as DeepSeek A.I. Beyond citizen privacy, the misuse of broad swaths of U.S. government or civilian information could lead to a serious breach of national security. In this report, we will consider how U.S. presidential administrations have employed existing U.S. cybersecurity regulatory mechanisms to respond to these threats.

Existing Regulatory Mechanisms

The U.S. provides a considerable number of regulatory offices to implement cybersecurity practices and review foreign technology services. 

  1. The Commerce Department’s Office of Information and Communications Technology and Services reviews and updates cybersecurity policy.
  2. The Federal Communications Commission’s “Covered List” names applications that pose national security risks.
  3. The Commerce Department’s “Know Your Customer” requirements cut off foreign companies using cloud services for espionage.
  4. “Team Telecom,” operating under the National Security Division of the Departments of Justice, Defense, and Homeland Security, keeps high-risk companies from operating in the country.
  5. The Department of Justice’s “Data Security” order prevents bulk data transfers to China.
  6. The Federal Trade Commission’s Protecting Americans’ Data from Foreign Adversaries Act of 2024 prevents the sale of personally identifiable information to China or Chinese companies.
  7. The Committee on Foreign Investment in the United States reviews foreign acquisitions of U.S. companies, primarily telecommunications or key infrastructure sales.
  8. The Federal Acquisition Security Council reduces cybersecurity and supply chain risks.
  9. The Protecting Americans from Foreign Adversary Controlled Applications Act creates divestment requirements to protect social media users, such as in the TikTok cases.

Administrative Responses to Cybersecurity: The TikTok Ban, RESTRICT Act, and PAFACA Act 

In the last decade, both the Biden and Trump administrations have been actively pursuing protectionist data policies, often directly targeting China and its domestic companies. 

At the end of his first term, President Trump signed the Secure Networks Act into law, establishing guidelines protecting American supply and communication chains from foreign-made products. This act limited foreign entities’ ability to spy on personal and government communications by barring federal entities from purchasing or maintaining equipment considered outdated or a security risk. In particular, the act prohibited government entities from using federal funds to purchase or maintain equipment considered a security risk. Additionally, the act created a reimbursement program to remove old equipment labeled as a security risk. While the Secure Networks Act updated infrastructure, it also allowed the FCC to target companies. In March 2021, under the Secure Networks Act, the FCC designated five Chinese companies on the “covered” list: Huawei, ZTE, Hytera, Hangzhou, Hikvision, and Zhejiang. This trend of targeting companies only escalated to the end of Trump’s term.

In August 2020, President Trump issued an executive order banning TikTok and WeChat from American markets, believing that the Chinese government’s data laws forced the platforms to provide Americans’ private information. While the company’s policies were generally unclear, his administration believed these platforms were sending American personal data to the Chinese government, giving the C.C.P. potentially dangerous information that would jeopardize private and national security. The subsequent ban limited the accessibility of these apps in American markets until their parent companies could show that they met U.S. data transparency regulations. The later Biden administration, too, would continue targeting specific Chinese companies.

Under the Biden administration, the U.S. continued to cover technological infrastructure and target Chinese companies. After two years in office, President Biden banned both ZTE and Huawei from operating in the U.S., citing espionage and national security risks. Similarly active at the end of its term, the Biden administration passed the Restricting the Emergence of Security Threats that Risk Information and Communications Technology Act, or the RESTRICT Act, to provide oversight of non-Americans on social media. Likewise, the Biden administration also utilized bans, introducing the Protecting Americans from Foreign Adversary Controlled Applications Act, or PAFACA Act. The PAFACA Act allowed the executive to ban social media services the president deems controlled by “foreign adversaries” for 270 days, with the option of a 90-day extension. 

Once the second Trump administration entered office, it immediately reactivated its aggressive campaign of technological national security. In December 2024, the Justice Department implemented a “final rule” to limit the sale of personal data to “countries of concern” that have attempted to blackmail federal employees or curtail civil liberties, namely Russia, China, and Iran. However, in a sharp turn of position, President Trump halted the Protecting Americans from Foreign Adversary Controlled Applications Act in early 2025. The implications of this move are unclear, especially as President Trump’s global tariffs “strike a blow at the tech industry” and disrupt trade.

Broken Down: The TikTok Ban, RESTRICT Act, and PAFACA Act 

To help understand the implications of the most significant actions of the Biden and Trump administrations, the key actions of the TikTok Ban, RESTRICT Act, and PAFACA Act must be broken down.

The TikTok Ban

Despite a lack of evidence to support their fears, the U.S. believed that TikTok and its parent company, ByteDance, could spy on U.S. citizens and collect government data. Proponents of a ban saw the ban as preventing a cybersecurity crisis, arguing that a government must control its citizens’ data to ensure their privacy and data regulation.

However, opponents point out this claim’s inverted logic: the proposed bans or regulations would allow the government to ban any foreign platform regardless of a sufficient threat level or legitimate concern. The ban could also curtail free speech and violate the First Amendment by implementing censorship.

Regardless of these risks, in April 2024, the TikTok ban passed through Congress, the Senate, and the Executive Office as part of a foreign aid bill providing military aid to Ukraine. Compounding much-needed aid and the ban enabled its passage. 

The RESTRICT Act

While the TikTok ban received bipartisan support, the RESTRICT Act was exclusively backed by the Biden administration. Empowered by the RESTRICT Act, the Commerce Department gained the ability to review, regulate, and potentially criminalize apps owned by foreign adversaries. However, opponents argue that delegating this authority to a department reduces administrative oversight and also leads to politically motivated censorship. Critics have also noted that the act may be too ambiguous and allocates too much legislative power to the department.

The PAFACA Act

As an extension of the TikTok bans, the Foreign Adversaries Controlled Applications Act, passed by the Trump administration, aimed to protect citizens’ data and regulate Chinese and other foreign applications. 

However, right before the Act could take hold, the Trump administration passed an executive order pausing the Act. The administration cited concerns that the act would conflict with other security measures and the negotiation of a settlement with TikTok. Additionally, President Trump gave the Attorney General a 75-day review period for applications affected by the order. The consequent effects of the Act’s implementation and removal are unclear.

Even so, with few regulatory analogues to this act besides the Supreme Court’s intervention in ByteDance’s divestment of Musical.ly, many question the government’s right to oversee and regulate these issues, leading to a hesitant and inconsistent approach. 

At the time of writing, TikTok’s lawsuit against the federal government has reached the Supreme Court, and the Act has yet to be instated. The original bill still remains stagnant in the Senate, facing ongoing reviews by the Committee on Commerce, Science, and Transportation.

Conclusion

High-tech firms from China now face immense threats due to escalating trade barriers, as highlighted by Forbes. Protectionist policies aim at strengthening U.S. technological independence by tightening regulations on foreign tech applications, enhancing scrutiny of foreign investments in critical sectors, and promoting domestic competition. According to the Information Technology and Innovation Foundation (ITIF), these restrictions have disrupted stable supply chains, causing companies to reevaluate their manufacturing and distribution strategies. Additionally, the use of legal and regulatory tactics, or “lawfare,” has restricted firms’ access to critical markets and resources. As a result, these shifts have not only reshaped global trade dynamics but also set the stage for a long-term divide.

[pvc_stats postid="" increase="1" show_views_today="0"]

Share this post

Related Briefs

Give feedback on this brief:

Free to read. Funded by people like you. Support the Fellows making it possible.