A blue architectural blueprint-style graphic with white grid lines and hand-lettered labels arranged like room names on a floor plan, symbolizing the architecture of institutional reinvention.

Reinvention Blueprint No. 3: To Unmake the Surveillance State, Rethink the Privacy Act

Editor’s Note

This article is part of Just Security’s Series: Reinvention Blueprints.

Federal, state, and local law enforcement agencies now operate against a backdrop of nearly limitless access to data. Networked cameras, sensors, and applications can keep tabs on our locations and identify our faces. Social media, search engines, and other online service providers capture records of our communications and relationships. Retailers and airlines collect information about what we buy and where we travel. All of these sources are useful to – and increasingly used by – law enforcement agencies.

Federal privacy law has been of surprisingly little help to those hoping to constrain surveillance abuses. That is because the dominant approach to privacy, as codified in the federal Privacy Act of 1974, focuses on individual rights to correct, access, and control information people share with government agencies. Today, everyday interactions generate new kinds of data agencies use to classify, rank, and predict individual and collective risks. Agencies acquire personal information from sources Congress could not have foreseen, share it under conditions Congress did not contemplate, and analyze it with tools that did not yet exist.

The government’s recent information-gathering and -aggregation activities underscore how existing laws have failed to effectively guard against the very dangers they were meant to prevent. As written, the Privacy Act is ill-equipped to address contemporary privacy risks, much less to constrain an executive branch determined to use the data in its possession for new purposes. This essay offers a blueprint for how to change it: expand the Privacy Act’s coverage, narrow its exceptions, and create independent oversight of how the government gathers, shares, and uses data. Congress must also enable independent oversight of the government’s data gathering, sharing, and use to ensure that the Privacy Act’s values remain protected.

The Problem: A Privacy Act Built for 1974

Data Consolidation

At the federal level, the Trump administration has eroded the silos that previously limited interagency access to data, particularly in service of its expanded immigration enforcement actions. In 2025, for example, the Social Security Administration and Internal Revenue Service began sharing the home addresses of immigrant taxpayers with Immigration and Customs Enforcement, reversing a longstanding previous policy. The Department of Health and Human Services also began sharing individual-level Medicaid data with the Department of Homeland Security to facilitate deportation efforts.

These attempts to collect and consolidate personal data are not limited to the federal government. State-level protections have come under parallel strain. For instance, DHS recently pressured California into feeding driver’s license records into NLETS, an interstate law enforcement data network. California issues driver’s licenses to undocumented residents and bars its DMV from sharing that data with federal immigration authorities, but its cooperation with NLETS effectively bypasses the protections the state legislature put in place. These recent efforts expand on existing information-sharing arrangements such as “Secure Communities,” under which DHS and federal, state, and local law enforcement efforts had already integrated the criminal database maintained by the FBI’s National Crime Information Center database with immigration records systems.

Meanwhile, the private sector continues to assemble precise, granular, and dynamic dossiers on individuals – and to sell them to government agencies. Private companies hold more information than most government agencies could dream of, and face fewer constraints on collecting it. Consider location information: in 2018, the Supreme Court held in Carpenter v. United States that law enforcement needed to get a warrant before obtaining more than six days of cell phone location information from a cell service provider. But many other types of businesses acquire and store location information: apps, ad networks, and data brokers, to name a handful. Some agencies have therefore responded to Carpenter by simply opting to buy access to location information from commercial sources.

Data as Enforcement Mechanism

Data consolidation efforts are unfolding alongside two parallel expansions of executive surveillance authority that compound their reach: National Security Presidential Memorandum 7 (NSPM-7), and the failed reauthorization of Section 702 of the Foreign Intelligence Surveillance Act. Issued in September 2025, NSPM-7 marks a structural shift in how the executive branch deploys federal investigative authority against perceived political opposition. The memorandum directs federal agencies to prioritize the monitoring and investigation of organizations and individuals engaged in First Amendment protected activity and recasts a subset of ideological opposition to the administration’s agenda as “domestic terrorism.” It underscores the administration’s systematic effort to “demonize” political opposition and deploy the capabilities of the national security state against dissent. Such targeting depends on the kind of cross-agency data infrastructure described above, and tests whether the Privacy Act’s protection for First Amendment activity can do meaningful work in practice.

The other concerns the future of Section 702 of the Foreign Intelligence Surveillance Act. Section 702 authorized the government to direct electronic communication service providers to collect and turn over the communications of foreigners located abroad. However, it sweeps in many Americans’ emails, phone calls, and text messages as well. The FBI can (and often does) examine that data without a warrant, a practice known as “backdoor searching.” After President Donald Trump installed Bill Pulte as Acting Director of National Intelligence, Congress allowed Section 702 to expire in mid-June because of concerns Pulte would misuse his authority, among other reasons.

Meanwhile, a public dispute between the Department of Defense and Anthropic highlights the expanded role of generative artificial intelligence (AI) in facilitating surveillance, as the Pentagon demanded that Anthropic drop restrictions on how its Claude product could be used. Anthropic insisted that Claude was not designed for “mass domestic surveillance,” arguing that such use is “incompatible with democratic values” and “presents serious, novel risks to our fundamental liberties.” According to Anthropic,

To the extent that such surveillance is currently legal, this is only because the law has not yet caught up with the rapidly growing capabilities of AI. For example, under current law, the government can purchase detailed records of Americans’ movements, web browsing, and associations from public sources without obtaining a warrant, a practice the Intelligence Community has acknowledged raises privacy concerns and that has generated bipartisan opposition in Congress. Powerful AI makes it possible to assemble this scattered, individually innocuous data into a comprehensive picture of any person’s life—automatically and at massive scale.

Together, expanded cross-agency data sharing, warrantless searching of databases, and increasingly capable AI tools extend the reach of federal surveillance into private records and communications in previously unimaginable ways.

Why the Privacy Act Fails

Information is essential to effective regulatory oversight, monitoring, and law enforcement. Enabling and maintaining government access to information is critical to ensuring sound policy and good governance, not to mention public safety.

In some respects, however, the current system of information gathering and consolidation is difficult to legitimate. The Constitution is of surprisingly little help in constraining government’s misuse of information: The Fourth Amendment regulates only how law enforcement conducts “searches” and “seizures,” and not all government efforts to collect information meet those definitions. This means that at least some information that individuals provide to third parties is not subject to the Fourth Amendment at all. And once the government has collected information, the way it later uses that information is typically not subject to constitutional constraint.

Moreover, although the Fourth Amendment imposes procedural and substantive limits on government data collection, it does not constrain private actors at all. One result is that the private sector can exploit its ability to gather information and sell it back to the government, which then accesses it without complying with any of the constitutional safeguards meant to hold it in check. In short, the Fourth Amendment’s strict regulation of government information-gathering has perversely encouraged agencies to avoid its application.

The federal data governance regime intentionally creates procedural and substantive guardrails against unfettered data-sharing between agencies. Those guardrails can be imposed by specific sectoral statutes: for example, in response to the Watergate scandal and President Richard Nixon’s use of tax audits as a weapon to harass and intimidate his “enemies,” Congress passed the Tax Reform Act of 1976, which amended the Internal Revenue Code and deemed some taxpayer return information confidential. The Act anticipates, and regulates, the circumstances in which taxpayer return information might be shared for law enforcement purposes.

The federal Privacy Act of 1974 places other limits on interagency data sharing. Rooted in concern about the surging use of automated data systems to gather and store individual information, the Privacy Act limits agencies’ collection of information about and from individuals. Among other restrictions, the Privacy Act bars agencies from disclosing individuals’ records without consent, requires agencies to allow individuals to correct and amend their records, and provides that agencies should only maintain records that are “relevant and necessary” to an authorized purpose. The Privacy Act also imposes procedural safeguards on “computer matching programs,” requiring agencies to enter into written agreements specifying how, why, and under what authority they compare two or more systems of records.

In drafting the Privacy Act’s core provisions, Congress appeared to have specific risks in mind: an agency sharing information about an individual, without their knowledge or consent, with another agency that might rely on it or misuse it to the individual’s detriment. As a result, many of the Privacy Act’s strongest protections belong to individuals, who can use its provisions to obtain access to their own records and request agencies to amend their records. The Privacy Act’s core provisions also require individuals to consent in writing before their records can be shared.

The Privacy Act’s provision barring agencies from sharing individual records without consent addresses a major risk. Without guardrails, law enforcement agencies may well be tempted to exploit other agencies’ data to generate leads or evidence. Using this workaround might be a convenient shortcut to avoid the more onerous processes of getting a warrant or court order.

But the Privacy Act’s exceptions are broad enough to drive a truck through. Individual records may be disclosed even without individual consent for law enforcement purposes, statistical purposes, or a “routine use.” These exceptions are expansive, as recent controversies have illustrated. In particular, the “routine use” exception permits agencies to disclose records for purposes compatible with the original collection purpose. In order to share information for a “routine use,” an agency must publish the proposed use in a System of Records Notice in the Federal Register, but by the time a notice is published, the sharing arrangement is often already in place.

The “law enforcement” exception is equally broad, and authorizes agencies to share data upon an agency’s written request. The Privacy Act’s computer matching rules also do not apply to computerized matching of two or more data sets “for the purpose of gathering evidence” in a criminal or civil investigation.

Moreover, many of the Privacy Act’s requirements only apply to agencies that maintain “systems of records,” defined as a “group of any records under the control of any agency from which information is retrieved by the name of the individual” or some other individual identifier. Likewise, under guidance developed by the Office of Management and Budget, the Privacy Act only limits how agencies collect information about individuals when they do so in a “system of records.”

The problem is that contemporary data practices often may not involve “systems of records” covered by the statute. Record systems containing information that is not, in fact, retrieved by using individual identifiers are not “systems of records.” This leaves agencies free to collect and retain information about individuals, so long as they do not access it by searching using an individualized identifier.

Many contemporary uses of individual data are likely not covered by the Privacy Act at all. In the first Trump administration, for example, the Department of Homeland Security expanded its collection of social media handles and identifiers in connection with its broader efforts to expand social media monitoring and implement “extreme vetting.” Collecting social media handles for inclusion in an immigrant’s so-called “Alien File,” or “A-File,” triggers the Privacy Act because the A-File is included in a statutory “system of records.”

But when ICE uses facial recognition, social media monitoring, and cell phone surveillance tools to track, identify, and monitor immigrants and dissenters, the agency routes around the Privacy Act’s protections: if these systems are not accessed using individual identifiers, but rather through algorithmic sorting based on risk, then they may not be considered a “system of records.”

And because the Privacy Act binds only federal agencies, not the private sector, it does not limit government purchases of data or software licenses from private actors. Consider a tool like Flock Safety, a venture capital-funded business that sells cameras equipped with automated license plate recognition (ALPR) technology to law enforcement, private organizations, and individuals. Flock’s tens of thousands of cameras photograph each vehicle that passes by, capturing billions of license plate reads each month. Using artificial intelligence, the software creates a “vehicle fingerprint,” recording the make, model, license plate number, and other distinctive features of each passing car. Users can search these records using natural language descriptions: “red truck with trailer” or “black car with Biden sticker.” And by simply toggling a setting, users can enable nationwide searching of data.

Flock has also sparked a furious debate about law enforcement’s use of license plate readers to track protestors, immigrants, and women seeking abortions. That debate grew more heated when news reports revealed that Flock had given federal agencies — including Customs and Border Protection (CBP) and the investigative arm of Immigration and Customs Enforcement — access to data from the network’s tens of thousands of devices. While the privacy implications of Flock are chilling, the Privacy Act has nothing to say about it: Flock is not a system of records under the control of a government agency.

The Privacy Act’s remedial provisions are focused on two circumstances: agencies’ refusal to disclose records or amend inaccurate records on a request from an individual. But the bigger problem with the government’s mass collection and use of data is not necessarily inaccuracy, but misuse.

Indeed, the Privacy Act recognizes that even the collection of accurate data comes with risks. It therefore generally bars agencies from maintaining records “describing” how individuals exercise First Amendment rights. The provision recognizes that government surveillance has a widespread chilling effect that undermines freedom of speech, religion, association, and privacy. But the provision is undermined by a large carveout that permits the accumulation of records about First Amendment rights if “pertinent to and within the scope of an authorized law enforcement activity.” Initiatives like NSPM-7, which treats much First Amendment activity as the appropriate target of criminal investigation and prosecution, cast doubt on the Privacy Act’s ability to withstand abuse.

Of course, there are always tradeoffs among interests in government information-gathering, free expression, and privacy. But contemporary surveillance is ubiquitous and enduring. With the help of modern data practices and computational technology, government agencies and the private sector can create precise, encyclopedic, permanent dossiers on individuals. These techniques are particularly chilling when — as now — they are deployed in connection with efforts to stifle dissent and bolster law enforcement’s overreach.

The Goals: Information Access with Accountability

Government’s misuse of data was the major motivation for the Privacy Act’s passage in 1974. Today, however, the statute is not effective at limiting government surveillance or constraining how it validates and shares information. If anything, its structure incentivizes law enforcement to use informational techniques not addressed by the Act and to cooperate with actors not regulated by its restrictions. Meanwhile, government activities of information collection and use remain opaque and unaccountable in spite of the Act’s mandates of individual notice and public transparency. The present moment demands new substantive and procedural limits on the kind of widespread surveillance that inhibits free expression and association and makes anyone a potential target.

The Concrete Solutions: Remaking Data Law for the 21st Century

Over the last 50 years, the system of surveillance and data sharing has proven both extraordinarily vulnerable to abuse and impervious to reform. But the present moment highlights that remaking surveillance law should be an urgent priority. Just as Congress enacted pathbreaking new legal frameworks to regulate government information-gathering and use practices in the wake of Watergate and the Church Committee Report — including the Privacy Act of 1974, Tax Reform Act of 1976, and Foreign Intelligence Surveillance Act of 1978 — Congress can and should impose new kinds of constraints on government information collection and use.

Executive and Congressional Actions: Map the Data Landscape and Fill the Regulatory Vacuum

Any project of remaking surveillance law must, at a minimum, address two elements. First, the federal government needs to catalog and map how agencies acquire, share, and use information. Several years ago, a senior advisory panel for the Office of the Director of National Intelligence called for the intelligence community to review how it acquires and uses commercially available information, describing the effort as a “complex undertaking.” The project has become significantly thornier and more important in the intervening years. Cataloging how agencies acquire commercially available information is doubly complicated because many agencies may use informal agreements or software licenses in lieu of formal compulsory process or procurement mechanisms. Meanwhile, the Trump administration has expanded information-sharing between agencies while deliberately avoiding its record-keeping obligations.

All of this underscores the urgent need for an assessment of the federal government’s practices of acquiring and sharing information. There is precedent for this effort, albeit partial and haphazard. In 2007, Congress created the Privacy and Civil Liberties Oversight Board, an independent agency dedicated to overseeing the privacy implications of the government’s counterterrorism programs. Federal law also requires each agency to develop a “comprehensive data inventory” that accounts for the data assets “created by, collected by, under the control or direction of, or maintained by the agency.” Similarly, the Advancing American AI Act of 2022 directs the Office of Management and Budget (OMB) to require agencies to catalog how they are using AI. And under a March 2024 OMB memorandum, agencies are also required to identify “safety-impacting” and “rights-impacting” AI systems and publish additional information about their risks. The Privacy Act itself, as amended by the Computer Matching and Privacy Protection Act, mandates that each agency involved in a computer matching program create a Data Integrity Board to oversee those programs.

In short, requiring oversight of how agencies acquire, use, and share data is nothing new. The next president could mandate OMB, in coordination with agency heads and Chief Information Officers, to undertake this effort to inventory and account for how agencies share data within six months. Such an effort should, at a minimum, map the types of interagency agreements and memoranda of understanding, as well as technological systems, enabling agencies to access other agencies’ data and records systems. Moreover, it should catalog how agencies acquire data from commercial actors, including through purchase, procurement, and licenses.

This mapping would better equip law and policymakers to determine which datasets and information assets are being used for what purposes and by whom. Within sixty days, OMB can identify criteria and frameworks for conducting such an inventory, and within six months, the inventory should be complete.

Second, the government must also ensure that data-sharing and surveillance does not operate in what Barry Friedman and Danielle Citron have aptly described as a “regulatory vacuum.” Congress could start by passing the Fourth Amendment Is Not For Sale Act, proposed legislation that would close the loophole that enables government entities to avoid the warrant requirement when they purchase data from data brokers.

Congressional Action: Close the Loopholes in the Privacy Act

But Congress can and should go further. As Congresswoman Lori Trahan has recognized, the nation faces a “combination of challenges stemming from unchecked government officials and significant technological advances.” Congress should therefore reconsider central elements of the Privacy Act that made sense in 1974 but no longer effectively protect privacy half a century later.

First, Congress should establish new oversight mechanisms to monitor data sharing for civil and criminal law enforcement activity. Currently, the Privacy Act permits agencies to share individual data without consent for the purposes of civil and criminal law enforcement. Some agencies have also established “blanket” or “universal” routine uses that authorize sharing of data for law enforcement purposes. As scholar Bridget Fahey has put it, this exemption effectively permits agencies to “self-regulate” with respect to their data practices.

Congress could, moreover, require interagency data-sharing to be grounded in explicit legal authorization, at least for certain categories of data. To illustrate: federal law explicitly authorizes the Bureau of the Census, Bureau of Labor Statistics, and Bureau of Economic Analysis to share business data for statistical purposes. However, certain Census statistical data products are generated using tax data deemed confidential under the Tax Reform Act of 1976 and therefore cannot be shared.

To close this gaping loophole in the Privacy Act, Congress might consider differentiating between the sharing of individual records on a case-by-case basis (i.e., for predicated investigations or pursuant to a warrant, court order, or subpoena) and the wholesale or systemic sharing of records systems between agencies of the type that the Trump administration is currently exploiting. A new provision of the Privacy Act could regulate when agencies can obtain ongoing access, whether directly or indirectly, to a system of records in the control of another agency. The statute might enable agencies to share access to systems of records with other agencies pursuant to either (a) a court order or (b) specific statutory authorization.

Second, the statutory definition of “system of records” must be updated to account for changing data infrastructures and practices. The Privacy Act was passed at a time when Congress was particularly concerned about uses of Social Security numbers and other ways of persistently identifying individuals across multiple government data resources. These types of abuses remain concerning. But the Privacy Act’s definition of “system of records” depends too heavily on how a government agency retrieves records: by using an individual identifier. Today, however, it is increasingly common for government systems to use AI and algorithmic ranking techniques to assess risk and predict behavior and to access records without searching by individual identifiers.

A “system of records” should include a “group of any records under the control of any agency from which information is retrieved about an individual,” regardless of how that retrieval occurs. Some have suggested that the idea of a “system of records” might become redundant if privacy law more closely tracked how government agencies use individual records. In my view, however, Congress should consider imposing more demanding conditions for agencies’ wholesale access to a group of records than on its acquisition of records on a more individualized basis. The “system of records” remains a useful way of distinguishing between systemic and individualized access to data.

Congressional Action: Create an Independent Watchdog

Congress must also consider creating an ombudsman or other entity with authority to at least monitor and perhaps control interagency data transfers. It has previously considered doing this: in 1974, Senator Sam Ervin proposed the creation of a “Federal Privacy Board” empowered to oversee “the gathering, maintenance and disclosure of information concerning individuals by Federal agencies, State and local governments, and private organizations.” The PCLOB’s limited purview, combined with the Roberts Court’s new restrictions on agency independence, have made it a less effective watchdog than many would have liked.

In calling for an overhaul of the Privacy Act, Trahan has therefore argued that oversight should be “collocated” in the legislative branch, either by expanding the Government Accountability Office or by creating a new oversight entity that could “subsume” the PCLOB. A new privacy oversight entity should have sufficiently broad authority to oversee executive-branch practices of data acquisition and use, but should be located in the legislative branch to secure its independence.

Congressional Action: Regulate the Private Sector

Finally, regulating government collection and use of data while private companies are unrestrained would have the unwelcome result of putting the federal government at a distinct disadvantage to industry. Although the United States has historically treated government data-gathering techniques as particularly dangerous, the private sector now plays an enormously important role in supporting and enabling government surveillance. A new era of data privacy law should therefore address both government and private collection and use of data (as Congress originally contemplated in the Privacy Act itself).

Specifically, Congress should pass comprehensive privacy legislation that imposes data minimization obligations on businesses. To date, it has failed to do so: though some business practices are regulated under a sectoral privacy approach that applies to health, financial institutions, children’s privacy, and other areas, no overarching law creates limits on the kinds of data that businesses can acquire and create. Doing so would reduce the incentive for agencies to route around their own legal limits by exploiting the private sector’s relatively unconstrained ability to stockpile and exploit information.

***

The Privacy Act of 1974 was written just as the computer was transforming recordkeeping and information management both inside and outside government. Today, agencies, individuals, and the private sector operate in a different world, one in which records can be accessed and retrieved in new ways and at much lower cost. It is past time to reinvent the law of information privacy to respond to the technological, legal, and political realities that exist today.

Filed Under

, , , , , , , , , , , , , , , , , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: