Micron Document

PANOPTICON epic odni data purchases
page 1 / 6

EPIC — ODNI Report on Intelligence Agencies' Data Purchases Underscores Urgency of Reform
retrieved 2026-07-11

archived for offline mesh reading
------------------------------------------------------------

Join EPIC’s fight to STOP THE SURVEILLANCE STATE.

epic.org/stop-the-surveillance-state

Dismiss message.

EPIC - Electronic Privacy Information Center

Search

Menu

Analysis

ODNI Report on Intelligence Agencies’ Data Purchases Underscores Urgency of Reform

July 7, 2023
/
Chris Baumohl, EPIC Law Fellow

Last month, in response to oversight efforts by Sen. Ron Wyden and EPIC’s FOIA request, the Office of the Director of National Intelligence (ODNI) released a partially declassified report by the ODNI Senior Advisory Group (SAG) on the Intelligence Community’s (IC) purchase of commercially available information (CAI). The report found that the IC is collecting increasing amounts of CAI—including sensitive information like location data—but does not know how much CAI it is collecting, what types, or even what it is doing with that data.[1] The report also found that, despite the Supreme Court’s 2018 decision in Carpenter v. United States, which requires a warrant for persistent location information and potentially other data, the IC has no formal, community-wide position on the issue.[2] Predictably, IC elements continue to narrowly construe the decision to allow it to purchase otherwise protected information from data brokers without a warrant.[3]

These findings underscore the urgency of the yearslong effort by members of Congress to curtail the government’s data broker pipeline. This week, EPIC, along with over forty other organizations, endorsed a bipartisan amendment—led by Reps. Warren Davidson and Sara Jacobs—to the National Defense Authorization Act (NDAA) that would prohibit the government from purchasing data protected by the Fourth Amendment, such as location information and internet records. Congress should take this opportunity to close the data broker loophole, which is a key piece of this year’s reform of the warrantless surveillance ecosystem, along with the debate over reauthorizing Section 702 of the Foreign Intelligence Surveillance Act (FISA) and related authorities.

The Exploding Government Data Broker Pipeline

Law enforcement and intelligence agencies’ ability to collect personal data has been traditionally bound by constitutional restraints like the Fourth Amendment’s warrant requirement or statutory regimes like the Electronic Communications Privacy Act and FISA. As private companies have stockpiled personal data, including sensitive data on Americans, these agencies have increasingly turned to the private sector, purchasing Americans’ data and circumventing traditional legal processes, and without providing any transparency about the government agency procedures (or lack thereof) for protecting Americans’ privacy. This end-run around the Fourth Amendments’ protections has only grown more pervasive—and more severe—in recent years.

As the ODNI SAG report concludes, “[t]oday, in a way that far fewer Americans seem to understand, and even fewer of them can avoid, CAI includes information on nearly everyone that is of a type and level of sensitivity that historically could have been obtained, if at all, only through targeted (and predicated) collection[.]”[4] This includes location information, information about a person’s religion, sexual orientation, gender identity, health (including their mental health and reproductive health needs), political affiliations, and more. And, as the report underscores, the resulting stockpiling of this data raises significant risks of harm to an individual’s “reputation, emotional well-being, or physical safety.”[5] Examples abound of government agents abusing their access to sensitive databases, including by searching for love interests, racial justice protestors, and politicians. Therefore, any expansion of government access to sensitive data need be vetted carefully for necessity and safeguards.

Key Takeaways from the ODNI SAG Report

Per its terms of reference (TOR), this 90-day report, commissioned by the ODNI, attempts to: “(1) describe the role of CAI in intelligence collection and analysis; (2) reflect on the existing framework for ensuring the protection of privacy and civil liberties; and (3) make[] recommendations to the IC regarding how and under what circumstances an IC element should collect, use, retain, and disseminate CAI.”[6] However, it does not attempt “an independent legal analysis” of the issues involved with CAI, an important limitation on its ability to parse the IC’s rules for CAI.[7]

Let’s be clear, though: this report doesn’t cover all types of commercially available information. Rather, it covers only the subset of commercially available information that is also publicly available information, i.e., that it’s available commercially to the general public.[8] Therefore, it does not address information that is commercially available exclusively to governments. This means that it doesn’t cover, for example, reports that the CIA was paying AT&T more than $10 million a year to search its database of phone records for records relating to overseas terrorism suspects. It also wouldn’t cover the DEA’s reported practice of paying informants inside airline, bus, and parcel companies for access to customer data, rather than getting a warrant. And it also would not cover the IC’s purchase of tools similar to Fog Reveal, which are typically only available to government agencies and allow them to search location data based on advertising.[9] The report makes clear that if the government is indeed purchasing significant amounts of CAI that is not available to the public—and it’s hard to believe this isn’t absolutely the case—further reporting is needed.[10] One, then, would hope that further oversight is on its way, either via ODNI or by Congress.


< prev page 1/6 next >