Micron Document

PANOPTICON epic odni data purchases
page 3 / 6


- Years after Carpenter, the IC has no community-wide standards and procedures for CAI.

Despite the IC’s acquisition of vast amounts of CAI, the report underscores the lack of IC-wide standards and procedures governing acquisition and use of this information. Executive Order 12333, which is the foundational framework for government intelligence activities, treats publicly available information as “relatively unprotected,” though it does not define the term.[24] Individual IC elements—which operate through procedures established by the head of that element and the Attorney General (procedures known as Attorney General guidelines)—may define those terms, taking into account guidance from ODNI.[25]

According to the report, there is considerable variance in the maturity of agency policies governing CAI acquisition. Some agencies have CAI-specific guidance and specific guidelines for sensitive information, while others have either not updated their outdated policies to address new forms of CAI or are in the process of drafting CAI policies, likely in response to increased scrutiny.[26] For example, the CIA and Department of Defense (DOD) Attorney General Guidelines set forth basic standards for intelligence collection about U.S. persons. This includes permitting collection of publicly available information—even that which includes U.S. person information (USPI)—whenever the IC has an authorized intelligence purpose and the information is “reasonably believed to be necessary to that purpose.” The CIA and DOD Attorney General Guidelines also generally permit a collection technique if it is the “least intrusive means” of acquiring that information.[27] Overall, these examples of existing guidelines encourage the collection of CAI without acknowledging how intrusive today’s CAI really is, and without mandating strong safeguards to protect Americans’ privacy.

Overall, the report emphasizes that “current practices vary more, and more unsystematically, than is best. Put differently, the IC’s approach to CAI so far has been mainly federated, with individual elements operating as what might be called laboratories of CAI governance.”[28] Put yet another way, we appear to still be in the Wild West of government data purchases.

Nowhere is this free-for-all clearer—and more alarming—than in the context of location data. In 2018, the Supreme Court ruled in Carpenter v. United States that law enforcement cannot obtain persistent location information without a warrant. As the Court noted, this data “provides an intimate window into a person’s life, revealing not only his particular movements, but through them his ‘familial, political, professional, religious, and sexual associations.’”[29] However, according to the ODNI SAG report, “to our knowledge the IC has not arrived at a communitywide formal position” on whether Carpenter applies to the IC.[30] Indeed, as of January 2021, DIA told Congress as much, writing that the agency “does not construe the Carpenter decision to require a judicial warrant endorsing purchase or use of commercially available data for intelligence purposes.” It is deeply concerning that IC elements may have different—and conflicting—interpretations of a warrant requirement for the same type data, data which the Supreme Court has clearly stated is protected by the Fourth Amendment. Congress should continue to use its oversight authorities to address any inconsistencies and ensure that the IC protects Americans’ constitutional rights.

Another area of concern is the extent to which agencies collect USPI. The report makes clear that in at least some instances, agencies do not have the ability to filter out USPI prior to ingestion, meaning that agencies are hoovering up vast amounts of data—including sensitive data about Americans—with no ex ante safeguards. For example, the purchased geolocation data DIA received is not identified as U.S. location data or foreign location data, meaning that DIA acquires the information and then must identify and segregate any USPI. Note, however, that DIA may still retain—and query—the U.S. location data it obtains. Given the significant risks posed by the IC’s collection, retention, and use of this data, data minimization procedures form a key safeguard against abuse and inappropriate use. However, the report makes clear that agencies’ procedures vary considerably.

Finally, another area where the IC appears to have lagged behind common sense is deanonymization and reidentification. As the report recognizes, “anonymized” CAI may be deanonymized and linked to individuals, whether by combining that CAI with other information (commercially available or not).[31] At least as of the writing of the report, some elements still did not treat information as sensitive because they either “did not possess other data sets that could be used to reidentify (deanonymize) or because they did not intend to reidentify the individuals in the data.”[32] The ODNI SAG report correctly characterizes these agencies’ interpretation as “unacceptably narrow,” but does not recommend a particular standard, in keeping with its TOR.[33] This is yet another area ripe for strong and consistent protections, such as by legislating a definition of de-identified data that ensures information cannot be reasonably re-identified.