Micron Document

PANOPTICON epic odni data purchases
page 4 / 6


The report recommends that, based on its catalogue of CAI, the IC should “develop a set of standards and procedures for CAI, governing and requiring regular re-evaluation of acquisition and use decisions, including as to the use of CAI.”[34] While the report recognizes that these standards will need to be adapted for different IC elements given their different needs and missions, it emphasizes that all IC element approaches to CAI must be consistent in principle—one of several worrying notes that may suggest this is not currently the case.[35]

- The IC is not doing enough to protect Americans’ most sensitive information.

As the report details, the IC’s procedures are particularly lacking when it comes to Americans’ most sensitive information, such as their location information. Although some agencies conduct Volume, Proportion, Sensitivity (VPS) assessments of collection programs regarding the USPI that is likely to be acquired, these requirements do not apply specifically to CAI, and leave significant room for discretion in determining what “enhanced safeguards” can be used to mitigate the risks to Americans’ privacy.[36] Further existing guidance—like the NSA’s—may not always be triggered because of definitional issues, like how USPI is applied in the context of publicly available CAI.[37]

Other IC elements have done even less to protect Americans’ privacy. Some have adopted a binary approach “in which CAI is non-sensitive if the government could and/or historically did overtly and lawfully acquire it directly, and sensitive if the government could not or historically did not do so.”[38] As noted above, other agencies treat “anonymized” data as less sensitive, even where there is the potential to re-identify the data and link to individuals.

The report also indicates that at least some IC elements are purchasing CAI in bulk, meaning it is ingested with no filtering terms or discriminants, and where a significant portion is not reasonably likely to be relevant to intelligence objectives. As the report notes, CAI acquired in bulk “will almost always be more sensitive than CAI in smaller data sets.”[39] Nonetheless, some of IC elements’ current guidelines still encourage the acquisition of CAI (at least when it is PAI)—even in bulk—over other sources of information, even when those sources are more narrowly targeted.[40] The Department of the Treasury and DHS each have internal data review mechanisms that are apparently applied in the context of at least some CAI acquisitions, including those in bulk.[41] However, little if any public information is available on these mechanisms and from the report appears to indicate that they are not binding authorities and may be overridden by higher authorities.[42] Therefore, key questions remain about whether these internal mechanisms are effective checks on CAI acquisition. 

Given these gaps, the report recommends that the IC develop—either as part of the above policies and procedures, and/or as a complement to it—“more precise guidance to identify and protect sensitive CAI that implicates privacy and civil liberties concerns.”[43] In developing this guidance on CAI, the report recommends that IC elements consider a set of procedural and substantive issues, including those listed below:[44]

Structural and Procedural IssuesSubstantive Issues

Required involvement of relevant parties at all stages, for the most sensitive cases including legal, privacy, and civil liberties personnel within IC elementsSensitivity of the CAI

VPS assessments generally being made prior to acquisition, or at least prior to analytic use of CAIDeanonymization/reidentification issues

Approval requirements, with high levels of approval required for more sensitive casesImportance of mission served by CAI (to balance against sensitivity of CAI)

Documentation, retention, and availability to relevant personnel of assessments, approvals, and mitigation measures adoptedStrength of nexus between CAI and mission, and availability, feasibility, costs, and risks of (less intrusive) alternatives

Re-evaluation of VPS assessments and measures, both on a regular basis and as circumstances changeAbility to filter USPI prior to ingestion

Forwarding of assessments and other documentation to ODNI, and a formal mechanism for periodic reviewTraditional minimization approaches and techniques

Availability of other privacy-protective measures

These are certainly laudable goals, and hopefully ODNI will build off these processes. Ultimately, though, more internal IC processes only go so far. Therefore, Congress should use this framework as a roadmap to establish the scope of—and safeguards for—government data purchases.

For example, while it certainly should be the case that VPS assessments are made prior to acquisition, that is also the case with Privacy Impact Assessments (PIAs), but agencies regularly ignore or delay their obligation to conduct a PIA until well after a program has been implemented. Similarly, requiring the involvement of all relevant parties should be a no-brainer, it’s vital that review mechanisms—whether individual privacy and civil liberties officers or boards like at Treasury or DHS—have sufficient power to act as a meaningful check on CAI acquisitions.