Micron Document

PANOPTICON epic odni data purchases
page 2 / 6


Overall, the report highlights three findings:

- There is a “large and growing amount of CAI that is available to the general public, including foreign governments (and their intelligence services) and private-sector entities, as well as the IC.”[11]
- CAI “clearly provides intelligence value.”[12]
- “Under IC elements’ rules and procedures, CAI (because it is also PAI) is less strictly regulated than other forms of information acquired by the IC[,]” and that “profound changes in the scope and sensitivity of CAI have overtaken traditional understandings, at least as a matter of policy.”[13]

The report underscores that “CAI is increasingly powerful for intelligence and increasingly sensitive for individual privacy and civil liberties, and the IC therefore needs to develop more refined policies to govern its acquisition and treatment.”[14]

While there are a number of key takeaways from the report, three are worth exploring at length:

- The IC is vacuuming up all sorts of new and sensitive CAI, but it doesn’t know what it’s buying or what it’s doing with that information.

The IC is purchasing vast amounts of CAI, including social media data, location data, and other sensitive information. While the report is light on specific examples of IC CAI contracts, there are some worth noting. For example:

- The FBI contracted with ZeroFox for social media alerting.[15] Well before the FBI chose to pay ZeroFox, the company was the subject of significant controversy after it reportedly monitored Black Lives Matter protestors and flagged several as “threat actors” as part of another contract.
- The Defense Intelligence Agency (DIA), as previously reported, provides or has provided funding to another agency that purchases geolocation metadata from smartphones, including information about U.S. persons.[16]
- The U.S. Navy contracted with Sayari Analytics, Inc. for access to its database of CAI.[17]
- The U.S. Coast Guard contracted with well-known data broker Babel Street for an “Open Source Data Collection, Translation, Analysis Application.”[18] EPIC has detailed at length Babel Street’s sale of bulk location data, internet records, and other information to government agencies—including Customs and Border Patrol and Immigration and Customs Enforcement—through tools including Babel X.
- DHS I&A purchased access to Thomson Reuters CLEAR—a massive investigative software platform with “billions of data points”—to “resolve identities” and “provide[] leads for further analysis in DHS systems.”[19] Thomson Reuters has faced sustained pressure to cut its ties with DHS components after concerns were raised that the platform enabled detention and deportation operations.

However, the report emphasizes that the IC as a whole does not understand what CAI individual elements are purchasing, nor how they are using it. Therefore, the report recommends that the IC “develop a multi-layered process to catalog, to the extent feasible, the CAI that IC elements acquire.”[20] It underscores that “[t]he IC cannot understand and improve how it deals with CAI unless and until it knows what it is doing with CAI.”[21]

The report correctly takes a functional approach, rather than a process-oriented approach. The report notes that any cataloguing effort should include formal contracts and procurement decisions, as well as functionally equivalent agency-specific data acquisition processes, such as when an agency acquires CAI via another agency or from a non-IC element without a formal procurement decision.[22] The report also emphasizes the need to triangulate CAI acquisition and use at various stages of the CAI lifecycle.[23] The IC would be wise to follow these recommendations. Establishing a comprehensive inventory of CAI purchases and use is not just a privacy issue, it’s a good governance issue—without knowing what it’s purchasing, it’s hard for the government to argue that these purchases are necessary rather than a wasteful and privacy-invasive use of taxpayer funds.

- Years after Carpenter, the IC has no community-wide standards and procedures for CAI.

Despite the IC’s acquisition of vast amounts of CAI, the report underscores the lack of IC-wide standards and procedures governing acquisition and use of this information. Executive Order 12333, which is the foundational framework for government intelligence activities, treats publicly available information as “relatively unprotected,” though it does not define the term.[24] Individual IC elements—which operate through procedures established by the head of that element and the Attorney General (procedures known as Attorney General guidelines)—may define those terms, taking into account guidance from ODNI.[25]

According to the report, there is considerable variance in the maturity of agency policies governing CAI acquisition. Some agencies have CAI-specific guidance and specific guidelines for sensitive information, while others have either not updated their outdated policies to address new forms of CAI or are in the process of drafting CAI policies, likely in response to increased scrutiny.[26] For example, the CIA and Department of Defense (DOD) Attorney General Guidelines set forth basic standards for intelligence collection about U.S. persons. This includes permitting collection of publicly available information—even that which includes U.S. person information (USPI)—whenever the IC has an authorized intelligence purpose and the information is “reasonably believed to be necessary to that purpose.” The CIA and DOD Attorney General Guidelines also generally permit a collection technique if it is the “least intrusive means” of acquiring that information.[27] Overall, these examples of existing guidelines encourage the collection of CAI without acknowledging how intrusive today’s CAI really is, and without mandating strong safeguards to protect Americans’ privacy.