Where Can Foreign Capital Be Stopped? - Practical Judgments of CFIUS and Reverse CFIUS
---
Carefree Dad
---
20251224
---
The following is the accurate organization and legal framework in the United States that reviews corporate and real estate acquisitions by foreign capital due to national security concerns, and can order divestment or stop transactions in certain cases:
⸻
🇺🇸 Key Organization and System: Committee on Foreign Investment in the United States (CFIUS)
Official Name (English):
Committee on Foreign Investment in the United States (CFIUS)
(Committee on Foreign Investment in the United States) 
✔︎ What does this organization do?
• It is an **interagency committee of the U.S. government** that reviews whether acquisitions or investments by foreign companies or capital in U.S. companies or critical assets affect national security. 
• After review, it has the legal authority to recommend that the President issue an executive order for divestment, withdrawal, or restriction, and ultimately, the President can issue such an order. 
• Its authority was strengthened by the Foreign Investment Risk Review Modernization Act (FIRRMA), enacted in 2018, which expanded the scope to include broad investments such as data access and real estate. 
⸻
🇺🇸 Legal Background (Basis for Divestment/Stop Orders)
The legal basis for executive orders based on CFIUS reviews includes the following:
✅ 1. Defense Production Act, Section 721
Defines the President's authority to issue orders to stop or divest transactions that pose national security concerns. 
✅ 2. Foreign Investment Risk Review Modernization Act (FIRRMA)
Enacted and implemented in 2018, it expanded the scope of transactions that CFIUS can review (e.g., critical infrastructure, real estate, data, etc.). 
⸻
📌 Examples under the Trump Administration
🧱 ① HNA Group's Manhattan Building (850 Third Avenue)
• Case Details: HNA Group, a major Chinese conglomerate, owned 90% of 850 Third Avenue (near Trump Tower in Manhattan, New York) in 2016. 
• Reason for Concern: The building housed the NYPD 17th Precinct (responsible for security around Trump Tower), which was flagged by CFIUS as a national security concern. 
• CFIUS Response: Advised that divestment be ordered, and HNA transferred the asset to a blind trust to proceed with the sale. 
• Actual Sale Price:
• Initial acquisition price was approximately $463 million. 
• It was reported that it was subsequently sold for approximately $422 million (some reports mention a range of $410–420 million). 
• There are reports that this resulted in a loss of approximately $41 million to $43 million. 
⸻
🧾 ② Shiji (Beijing Shiji Information Technology) U.S. Divestment Order
• Case: In March 2020, President Trump issued a divestment order regarding the ownership of a U.S. hotel management software company (StayNTouch) by the Chinese company Beijing Shiji Information Technology. 
• Reason for Divestment Order: Access to U.S. hotel guest data held by the company was determined to be a security concern. 
• Grace Period: Usually, divestment or disposal of shares/interests is ordered within a few months. 
⸻
🧠 Summary of Points
Item Content
Actual Organization CFIUS (Committee on Foreign Investment in the United States)
Basis of Authority Defense Production Act §721 + FIRRMA
Purpose Review, restrict, or order divestment if foreign investment threatens national security
Representative Example HNA's 850 Third Avenue divestment order (approx. $420 million)
Additional Example Shiji's StayNTouch divestment order
---
Below, I will summarize the "review process," "stages where the President can issue orders," "conditions under which divestment/unwind orders are likely to be issued," and "representative case studies" of CFIUS, in a way that makes the "institutional flow" as visible as possible.
⸻
1) Mechanism of the CFIUS Review Process (Overall Flow)
CFIUS reviews acquisitions of U.S. companies by foreigners (including foreign companies and foreign government involvement), as well as investments in certain real estate transactions/critical data/critical infrastructure/critical technology (so-called TID U.S. business) from the perspective of national security. The institutional basis is Section 721 of the Defense Production Act (so-called Exon-Florio), which was strengthened by FINSA and FIRRMA. 
A. Entry (Types of Filings)
There are two main ways to file (*Note: The authorities may also "pick up" cases on their own and start a review = self-initiated review is also possible).
• Declaration (Short Form): A short filing. In principle, CFIUS makes a decision within 30 days (clearance, request for additional Notice, pending decision, etc.). 
• Notice (Formal Notification/Long Form): A full filing. Once accepted (determined to be "complete"), the review clock starts ticking. 
*Which one becomes a "mandatory filing" depends on the transaction type (e.g., it can become mandatory if a foreign government obtains a "substantial interest" in a TID U.S. business). 
B. Standard Timeline for Notice (Framework of Practice)
According to the Treasury Department's explanation, the filing must first meet the requirements and be determined to be "complete" (acceptable) before it is distributed, and the next business day is the first day of the review. The review period is a maximum of 45 days. 
Typical Flow (Conceptual Diagram):
1. Filing → Acceptance (Complete determination)
2. Review (45 days): First, broadly scrutinize risks 
3. Investigation (45 days): If concerns remain, move to an "additional investigation phase" (this is the real climax for some cases) 
4. Presidential Decision Phase (Maximum 15 days): If CFIUS refers the case to the President, the legal framework requires the "President to announce a decision within a certain period." 
(In practice, it is also common for parties to change conditions or withdraw and refile during the process.)
C. "Exit" of the Review (Result Patterns)
• Clearance (Unconditional)
• Conditional Clearance (Mitigation): Approved with conditions such as data isolation, restricted access to U.S. persons, monitoring, etc.
• Abandonment/Withdrawal (by the parties)
• Prohibition/Stop by Executive Order, or "Divestment (Unwind) Order" 
⸻
2) Can the President issue an order at "any stage"?
This is a point where misunderstandings often occur.
• Under the law (50 U.S.C. §4565), the President has the authority to stop or prohibit a "covered transaction" that could impair national security. 
• However, in practice, the basic form is CFIUS review → (if necessary) referral to the President → Executive Order (CFIUS acts as the "operational execution side" of the President's authority).
In conclusion:
• In terms of institutional design, the "President is the final authority." 
• In terms of practical procedure, it is normal to go through the CFIUS process (review/investigation) before entering the Presidential decision phase. 
• However, because CFIUS can pick up cases that were not filed after the fact, it can happen that "completed transactions are subsequently unwound by a divestment order" (Grindr, mentioned later, is a typical example). 
⸻
3) Major Conditions for Divestment/Unwind Orders (Patterning)
Divestment orders are likely to be issued when it is judged that "national security risks cannot be fully eliminated by mitigation measures." Specific "landmines" fall into the following categories:
A. Large-scale possession of sensitive personal data (PII/health/location information, etc.)
• U.S. personal information, health information, location information, behavioral history, messages, etc.
→ The possibility of access by foreign parties (especially hostile nations, etc.) is often the focus.
Example: Grindr (reported that HIV status, etc., were points of contention) 
Example: StayNTouch (concerns about access to hotel guest data came to the fore) 
B. Critical Technology (semiconductors, telecommunications, AI, etc.) / Supply Chain / Military Conversion
• Impact on "U.S. technological superiority" or defense industrial base.
Example: Broadcom–Qualcomm was prohibited by executive order due to national security reasons 
C. Critical Infrastructure / Real Estate near government/security agencies (Location Factors)
• Sometimes the location (proximity to police/military/government facilities, etc.) is more of an issue than the "facility itself."
Example: Manhattan property near Trump Tower (HNA's 850 Third Avenue), where it was reported that CFIUS sought divestment 
D. Foreign Government Involvement (State-owned enterprises, sovereign wealth funds, etc.)
• Even if it is private in form, it tends to be viewed heavily if actual control or command systems are suspected.
(CRS also organizes the point that mandatory filing can occur in cases where a foreign government obtains a substantial interest in a TID U.S. business, etc.) 
E. "Credible evidence" + inability to address by other means
A phrase that often appears in executive orders is the form "credible evidence that ... might take action that threatens to impair national security" (also pointed out in the StayNTouch commentary). 
Once in this framework, **prohibition + divestment within a certain period** are likely to be ordered as a set. 
⸻
4) Case Studies (Including the "building in front of Trump Tower" you specified)
Case 1: HNA (China) — 850 Third Avenue (NY, near Trump Tower)
• What was the problem? "Location factors" such as location (reported to involve security/public safety-related circumstances)
• What happened? Through CFIUS's intervention, HNA transferred its stake to a blind trust and moved toward divestment 
• Amount (Sale): Reuters reported it was sold for approximately $422 million 
This is a case that is highly likely to be consistent with the context of the "building in front of Trump Tower" that Morera-san mentioned (it is reported as "near Trump Tower"). 
⸻
Case 2: Beijing Shiji (China) — StayNTouch (Hotel Management Software) Divestment Order (2020)
• What was the problem? Access to hotel guest data, etc. (sensitive data)
• What happened? By executive order on March 6, 2020, **divestment of all interests within 120 days (+ provisionally prohibiting data access, etc.)** was ordered. Designed so that CFIUS can be involved in conditions, extensions, etc. 
• Primary Source (Order): The specific requirements for divestment are written on the executive order page of the Trump administration archives. 
⸻
Case 3: Kunlun (China) — Grindr (Dating App) Divestment Order (2019)
• What was the problem? Personal data (reported that private messages, HIV status, etc., were points of contention)
• What happened? According to Reuters, CFIUS ordered divestment in 2019 and sought completion of the deal by a set deadline. 
⸻
Case 4: Broadcom (then Singapore-registered) — Qualcomm acquisition prohibited by executive order (2018)
• What was the problem? Technological hegemony in 5G, etc./industrial base (reported as a concern that it would indirectly lead to Chinese dominance)
• What happened? The President prohibited the acquisition. The order was also published in the Federal Register. 
⸻
5) Summarizing this into a "map that can be used in practice" in one sentence
• Entry (Declaration/Notice or CFIUS self-initiated) → Review/Investigation → (if necessary) Presidential decision (max 15 days) → Clearance/Conditional/Prohibition/Divestment Order
And divestment orders are generally issued when one (or a combination) of "data," "critical technology," "critical infrastructure/location," or "foreign government involvement" is deeply pierced and it is judged that it cannot be eliminated by mitigation. 
⸻
From here, I will summarize ① "CFIUS Practical Checklist" and ② "List of representative examples where divestment/prohibition occurred frequently with Chinese capital from 2018–2020" in a form that can actually be used.
(*Note: The system name is officially CFIUS in all cases)
⸻
① CFIUS (SeaFace) Practical Checklist
― For Pre-transaction Self-Screening ―
The following is a checklist created from the perspective of "if even one of these strongly applies, CFIUS risk jumps up at once."
It can be used for real estate, corporate acquisitions, or minority investments.
⸻
A. Investment Entity (Who)
Who is the counterparty?
• Countries of Concern such as China, Russia, Iran, etc.
• State-owned enterprises / Sovereign wealth funds / Involvement of Communist Party cells
• Nominally private, but
- Government officials on the board
- Party organization exists within the company
- Under the influence of National Security Law/Intelligence Law
• Ultimate Beneficial Owner (UBO) is opaque
👉 If even one applies → CFIUS suspects "possibility of hostile government influence"
⸻
B. Transaction Target (What)
What are you buying/holding?
1. Data (Most Important)
• Personal data of U.S. persons
• Location information
• Health/Medical
• Biometric information
• Behavioral history/Communications
• Hotels / SNS / Apps / SaaS / FinTech
• Data theoretically accessible from outside the U.S.
👉 Grindr / StayNTouch type risk
⸻
2. Technology (TID U.S. Business)
• Semiconductors / AI / Quantum / Telecommunications / Satellites / Encryption
• Military conversion (dual-use)
• Fields that influence U.S. technological superiority
👉 Broadcom–Qualcomm type risk
⸻
3. Infrastructure/Location (Including Real Estate)
• Proximity to military bases/government facilities/police facilities
• Key points in major cities (NYC, DC, SF, etc.)
• Telecommunications/Power/Ports/Airports
👉 HNA (near Trump Tower) type risk
⸻
C. Transaction Form (How)
To what extent is control exercised?
• Majority acquisition
• Right to appoint directors
• Right to access technology/data
• Veto power
• Minority investment but "substantial influence"
👉 "Not controlling" is not a get-out-of-jail-free card
⸻
D. Can it be settled with Mitigation?
What CFIUS thinks about first is "conditional approval."
• Is isolation of data within the U.S. possible?
• Is blocking access by foreign officers possible?
• Is installation of a government-approved third-party monitor possible?
• Is separation/detachment of technology possible?
👉 If this is judged "impossible" or "untrustworthy," a divestment order is issued
⸻
E. Final Judgment Flow (Practical Sense)
Low risk → Unconditional approval
Medium risk → Conditional approval (mitigation)
High risk → Prohibition by executive order or divestment order
⸻
② List of representative examples where divestment/prohibition occurred frequently with Chinese capital from 2018–2020
During the Trump administration, it became strictly tightened at once with "China × Data/Technology/Location."
⸻
【A】 Divestment Order
■ Kunlun (China) → Grindr (2019)
• Field: SNS / Dating App
• Problem:
• Sexual orientation, health information, location information of U.S. persons
• Result:
• CFIUS ordered divestment
• Lesson:
👉 Personal data is the most dangerous
⸻
■ Beijing Shiji → StayNTouch (2020)
• Field: Hotel Management Software
• Problem:
• Chinese access to guest data
• Result:
• Divestment within 120 days by executive order
• Lesson:
👉 Even in B2B, if you have "personal data in the background," you are out
⸻
■ HNA Group → 850 Third Avenue (NY)
• Field: Real Estate
• Location: Near Trump Tower
• Problem:
• Security/Public Safety/Location Risk
• Result:
• Divestment under CFIUS pressure
• Approx. $420 million
• Lesson:
👉 Even in real estate, you are out because of "location"
⸻
【B】 Prohibition of Acquisition
■ Broadcom (then Singapore-registered) → Qualcomm (2018)
• Substance: Concern that China would gain technological superiority
• Field: 5G/Semiconductors
• Result:
• Acquisition prohibited by executive order
• Lesson:
👉 If a "future where China benefits" is seen, it will be stopped
⸻
【C】 Characteristic Common Points (Chinese Cases)
Common Item Content
Appears private Substance is state influence
Review even after completion Post-facto divestment exists
Quality over amount Subject even if small-scale
Data-focused Stricter than technology
⸻
One-point advice for practice
• "If you don't file, they won't find out" does not work
• Chinese capital × U.S. person data = almost a red light
• In real estate, "location" is everything
• CFIUS is not a court, but a "national judgment"
⸻
I will summarize "CFIUS (Committee on Foreign Investment in the United States)," in the order of: mechanism → Presidential authority → conditions for divestment orders → cases → checklist → reverse CFIUS risk when a Japanese company becomes the "receiving side" → (Biden period vs. Trump period) continuity/disruption → and finally a 5-minute judgment flowchart.
⸻
1) CFIUS Review Process (Mechanism: What happens in chronological order)
CFIUS is a government-wide committee chaired by the Treasury Department that reviews the impact of investments by foreigners (including foreign companies/foreign government officials) on U.S. national security. 
A. Entry: Transactions likely to be subject (roughly)
• "Acquisition of control" (acquisitions, mergers, etc.) of a U.S. business
• Investments involving critical technology/critical infrastructure/sensitive personal data (so-called "TID")
• Certain real estate transactions near military facilities, etc. (scope expanded since FIRRMA) 
B. Two types of procedures (shorter one/frontal breakthrough)
• Declaration (Simplified filing): Initial judgment in principle within 30 days ("clear," "to full review," "file formal Notice," "cannot say anything," etc.) 
• Notice (Formal filing): Usually this is the main line
C. Standard timeline for Notice (order in which the "clock" moves)
*Details vary by case, but this is the skeleton.
1. Review: Maximum 45 days (30 → 45 with FIRRMA) 
2. Investigation: In principle 45 days
3. (Exception) 15-day extension: An additional 15 days is possible due to special circumstances 
4. Presidential decision phase: 15 days
• If CFIUS refers the case to the President, the President must announce a decision within 15 days of the completion of the CFIUS investigation. 
D. Branches that "often occur" along the way (reality of practice)
• Mitigation negotiations: Data isolation, U.S. person officers/audit, source code management, blocking government access, facility entry restrictions, etc. 
• Withdraw & Refile: Often used for buying time + adjusting conditions
• Abandon (parties withdraw): "White flag" is also common if it looks like it will be troublesome
⸻
2) At what stage can the President issue an order? (This is super important)
Conclusion: The President issues a "divestment order/prohibition order" basically "when it is referred after a CFIUS investigation."
CFIUS itself has strengthened its authority to reach mitigation agreements with parties, impose fines for violations, and demand information submission, but the royal road for ultimately issuing a "prohibition/unwind (divestment)" as an "order" is the Presidential route. 
Also, under the law (regulations based on Section 721 of the Defense Production Act), the framework is such that the President can stop/prohibit transactions under conditions such as "credible evidence" (the same applies to real estate cases). 
⸻
3) Major conditions under which divestment orders are likely to be issued (patterns of "landmines")
Practical landmines are generally one of the following (or a combination):
Landmine A: Sensitive data (especially personal information, location information, health information)
• In the Grindr case, "personal data (including HIV, etc.)" was strongly viewed as a problem, and a divestment order was issued to the Chinese company Kunlun. 
Landmine B: Critical technology, semiconductors, dual-use
• The acquisition of Lattice Semiconductor was blocked by the President in 2017 (acquisition by a Chinese-affiliated fund).
Landmine C: Critical infrastructure/supply chain control
• Energy, telecommunications, ports, cloud, payments, logistics, etc. Systems that "if they stop, the nation stops."
Landmine D: Real estate near military facilities (surveillance/intelligence risk)
• In 2024, President Biden issued a prohibition on purchase + divestment order regarding real estate for a crypto-asset mining facility near a military base. 
• Furthermore, in the 2024 final rule, the targets around military facilities that CFIUS can look at have been greatly expanded. 
Landmine E: The counterparty has a "strong shadow of the state" (state-owned, military-related, subject to sanctions, opaque actual control)
• It is tough if you cannot explain "who the Ultimate Beneficial Owner (UBO) is" or "the relationship with the government."
⸻
4) Case Studies (Including those where "divestment orders were frequent")
Case 1: Building near Trump Tower (HNA / 850 Third Avenue)
• Through CFIUS's intervention, HNA transferred its stake to a blind trust and moved toward divestment (the point that police-related facilities were housed in the building was the focus of reports). 
• It is reported that the sale was for approximately $422 million. 
Case 2: StayNTouch (Beijing Shiji) — President Trump's divestment order (2020)
• By executive order in March 2020, **transaction prohibition + divestment of held interests** was ordered. 
Case 3: Grindr (Kunlun) — Personal data is the core
• CFIUS ordered divestment in 2019, and the deadline setting was reported. 
Case 4: MineOne (Real estate near military base) — President Biden's divestment order (2024)
• "Right next to the base + foreign-made equipment" was the problem setting, and divestment + equipment removal was ordered. 
⸻
5) "SeaFace (CFIUS) Checklist": "Instant screening" items to look at first
5-1. Does the transaction fall within CFIUS's range? (The more "Yes," the heavier)
• Target has U.S. subsidiary/U.S. base/U.S. customer data
• Control is transferred (includes right to appoint directors, veto power, consent rights for important matters, etc.)
• Likely to fall under critical technology/critical infrastructure/sensitive data (TID)
• Involves real estate near military facilities (buy/rent/concession) 
• Counterparty is state-owned/government-affiliated/close to sanctions/export controls, or UBO is opaque
5-2. Initial moves to "get it through" (deal design)
• Store data within the U.S. + block access (do not let the Chinese side touch it)
• Governance separation (U.S. person directors, security committee, audit authority)
• Isolate technology/source/blueprints/encryption keys from the Chinese side
• For real estate, scrutinize everything including distance, line of sight, communication equipment, airspace/radio waves
• Consider Declaration at an early stage (however, for cases where the result cannot be read, be prepared for Notice)
⸻
6) "Reverse CFIUS" risk when a Japanese company becomes the "receiving side" of Chinese capital
The point is this:
Even in transactions by Japanese companies, ① if there is a connection to the U.S., CFIUS will appear / ② even outside the U.S., "data/technology" regulations will pierce through other routes.
Specifically:
• Japanese company has a U.S. subsidiary, has business/government projects/defense projects/important customers in the U.S.
• Data handled by the Japanese company includes U.S. persons/U.S. government-related (hotels, payments, health, etc.)
• Japanese company is positioned in the supply chain of critical technology (semiconductor materials, manufacturing equipment, AI-related, quantum, telecommunications, etc.)
• Assets/technology acquired by the Japanese company could result in transfer to the Chinese side (director access, joint research, IT management authority, log viewing, etc.)
→ Even if the company being acquired is not a U.S. company, just having a "U.S. subsidiary" or "U.S. data" makes it a practical CFIUS point (Grindr/StayNTouch type thinking). 
⸻
7) Differences from the Biden period / Continuity and disruption with the Trump period (including as of December 2025)
First premise: The President as of December 2025 is Donald Trump (inaugurated 2025/1/20). 
Continuity (Trump → Biden → Trump, basically always strong)
• Security review against China is consistently in the direction of strengthening (strengthening monitoring of data, technology, real estate)
• As a flow after FIRRMA, CFIUS is strengthening **monitoring and enforcement** 
• Expansion of targets for real estate near military facilities has also progressed 
Disruption ("placement of thinking" is different)
• Biden period (especially EO 14083):
Explicitly expanded national security factors to "supply chain resilience," "cyber," "sensitive data," etc., and verbalized the "perspective CFIUS looks at." 
• Trump period (especially 2017–2020):
Block/divestment orders in individual cases were symbolic (StayNTouch, etc.). 
• New axis seen in Trump 2.0 (2025):
On the Treasury site, **Known Investor Program (KIP) based on America First Investment Policy (2025/2/21) is under development = movement in the direction of "allies and other 'known investors' will have streamlined procedures" is indicated. 
→ In other words, it is not "tightening across the board," but the color-coding of "allies are fast, countries of concern are heavy"** may become more blatant.
⸻
8) 5-minute judgment: "Will this case pass?": Super simple flowchart (for Japanese companies)
[START]
|
| Q1 U.S. connection? (U.S. subsidiary/U.S. customer/U.S. data/U.S. base/U.S. government contract)
|----NO----> Q2 Fall under critical technology/critical infrastructure/sensitive data (TID)?
| |----NO----> [CFIUS direct hit risk low] However, export controls/sanctions/each country's FDI review are separate
| |----YES---> [Medium] Room for avoidance through deal design and information blocking
|
|----YES--->
Q3 Is the investor "shadow of the state is thick"? (State-owned/military-related/country of concern/UBO opaque)
|----NO----> Q4 Control transfers/veto power/director appointment/consent to important matters exists?
| |----NO----> [Medium] Even with minority investment, if there is data/technology access, it goes up
| |----YES---> [High] Premise of filing (Declaration/Notice) + mitigation package
|
|----YES--->
Q5 What are you touching: data, technology, or real estate near a base?
|----Real estate near base--> [Most dangerous] Location/equipment/visibility/radio waves almost decide the outcome
|----Sensitive data------> [Most dangerous] Isolation within U.S./access blocking is the minimum condition
|----Critical technology--------> [Most dangerous] Technology isolation/governance separation/export control alignment is essential
Tips for judgment:
• It is decided by "what can be accessed" (data/technology/location) rather than "the counterparty is Chinese" itself (Grindr and StayNTouch are typical).
⸻
If you apply the contents so far to "your case"
If you are on the side of "putting Chinese capital into a Japanese company," and there is any possibility of U.S. subsidiary/U.S. customer data/technology transfer abroad, first
1. Identify the reason why it falls into "high/most dangerous" in the 5-minute flow
2. Crush that reason (e.g., data access) with contracts and systems (isolation/audit/officer composition)
3. If it still remains, deal design premised on Declaration/Notice
is the standard.
⸻
