Latest Coverage
See all articles
DOT airline passenger privacy: GAO investigation demanded by U.S. Rep. Shontel Brown
WASHINGTON - U.S. Rep. Shontel Brown and U.S. Sen. Ron Wyden want federal auditors to investigate the Department of Transportation’s handling of airline passenger privacy. The agency has not taken a single enforcement action despite mounting evidence that the government is buying and exploiting passenger data without warrants, the lawmakers say.
The pair sent a letter Wednesday that asks the Government Accountability Office to investigate what they called DOT’s “systemic failure to protect passenger privacy using its authority to regulate the practices of commercial airlines and ticket agents.”
Brown, of Warrensville Heights, is the top Democrat on the House Oversight Subcommittee on Cybersecurity, Information Technology and Government Innovation. Oregon’s Wyden is the top Democrat on the Senate Finance Committee.
DOT has had sole authority to safeguard passenger data for more than 40 years. A Congressional Research Service review found the agency has never taken a public enforcement action or issued civil penalties over consumer privacy violations, Wyden’s office says.
“In addition to harming the public, DOT’s regulatory inaction also potentially threatens national security,” the letter says. “Travel data held by airlines and travel agencies may be of interest to foreign adversaries, who could exploit such information to track U.S. military, diplomatic, and other U.S. government personnel.”
As examples of privacy violations, the letter describes how Airline Reporting Corporation — a data broker owned by Delta, American, United, Southwest, JetBlue and other carriers — sold Customs and Border Protection bulk access to domestic flight records. ARC ended the practice following bipartisan congressional scrutiny and public backlash, the letter says, but notes that earlier this year, DHS issued a public request to government contractors for a replacement airline passenger surveillance system.
The letter also highlights a separate surveillance practice: the Drug Enforcement Administration’s use of paid airline employees as informants to identify passengers carrying large amounts of cash. A 2016 Justice Department inspector general audit found the DEA paid at least 19 airline employees, along with employees of Amtrak and TSA, for passenger data including itineraries, baggage information and dates of birth, according to the letter.
“The DEA used this passenger data to identify travelers who would then be approached before boarding their flight and pressured to consent to a search of their bags,” the letter says. “If passengers refused, they could be detained until they missed their flight. The DEA’s goal was to identify passengers carrying large amounts of cash, which agency personnel could then seize without arresting the passenger or charging them with a crime.”
The letter also says former U.S. Transportation Secretary Pete Buttigieg tried to address the problem in March 2024, announcing the first industry-wide review of privacy practices at the 10 largest U.S. airlines. The lawmakers say DOT “appears to have abandoned this effort” since President Donald Trump took office, and has not announced any additional privacy reviews.
Wyden and Brown asked GAO to determine why DOT relies on a complaint-driven enforcement model instead of proactive privacy audits and to review the status of the privacy review that Buttigieg sought.
The lawmakers also asked GAO to assess whether DOT’s enforcement approach is consistent with commitments the agency made to the European Commission in 2023 to support the EU-U.S. Data Privacy Framework, and to recommend legislative changes to strengthen DOT’s enforcement authority.
In addition, they asked GAO to provide legislative recommendations to address the DOT’s inaction and compel the agency to more vigorously protect the privacy rights of travelers, including any legislative changes required to remove obstacles to enforcement.
“DOT’s abdication of its role as a privacy regulator has left the sensitive personal information of hundreds of millions of Americans exposed to corporate exploitation, warrantless government surveillance, and warrantless seizure of money and other property,” the lawmakers wrote.