A woman fills out paperwork at a driver's license office counter, with a 'Fill Out Application' sign in the foreground and other visitors standing at counters in the background.

States Can Fight Federal Overreach by Protecting State Data

Editor’s Note

This article is part of Just Security’s Series: “Fight Back: How States Can Counter Authoritarianism.” Adapted with permission from The New Press, from the forthcoming publication Fight Back: How States Can Counter Authoritarianism edited by Erwin Chemerinsky and Aziz Z. Huq.

The second Trump administration is teaching states an important lesson about their data: how powerful it is. In recent weeks, the federal government attempted to obtain the contents of a centralized, state-led database of Commercial Driver’s License (CDL) information. Historically, states have shared driver’s license data relatively freely with the federal government, and state data about truck driver’s licenses might not seem exciting or potent enough to fight back over. But by this point in the administration, states have wised up — they know that the federal government can use even seemingly mundane datasets to accomplish its goals. On Aug. 13, 21 states sued to stop the feds from getting the CDL data. Seven days later, a federal judge issued a temporary restraining order blocking the transfer of over 17 million individuals’ CDL records to federal custody.

The CDL data is only the latest in a series of state datasets the second Trump administration has tried to obtain and use to advance its ends. Over the past year, the administration has sought to obtain state Medicaid data, state data from the Supplemental Nutrition Assistance Program (SNAP, also known as food stamps), and even data from the National Directory of New Hires (NDNH), a federal repository of state employment data originally created to enforce child support obligations. Typically, the administration has tried to use this state data for immigration law enforcement, but sometimes — as when DOGE sought access to the NDNH — it has not really been clear why the administration was after the data.

What the administration’s efforts have made clear is that state data is powerful. And that means states must be vigilant about when and on what terms they let the federal government use their data. In the same way everyone recognizes that land and money are sources of power, states must remember that data is a source of power — and, in an age of artificial intelligence, possibly a more important one than land or money. Especially when the federal government seeks to use this new form of power to advance its own ends, states must be vigilant stewards of their data.

States can do this in three ways: keep track of their data better; think about when they don’t actually need to give their data to the federal government; and throw their weight around to put rules on how the federal government uses their data — and to enforce the legal constraints that already exist.

Data Audits

States first need to figure out what data they have and where it is. This is harder to do than it might sound, but is a vitally important first step in defending states’ prerogatives over their data.

Many state governments do not know all the data they have, where it came from, or where it is going. This would be like Texas not knowing about its oil. It can cost a lot of money to figure out where oil is and how best to extract and process it — but few people doubt that task is worth the trouble. The same should be true of data. States need to see the task of understanding what data they hold as a difficult and expensive but ultimately extremely worthwhile undertaking.

States need to put real resources into conducting data audits that show where their data is. They should set up centralized data offices that track pooled data collected across the state and set out best practices for sharing and using state data. Imagine a map showing the data flows moving into and out of the various state agencies that collect and pool large amounts of data — and crucially when data flows out of the state to the federal government or private parties. That map is what states need to build now.

Using language like “maps” and “where data is” might strike some readers as odd. Does data really have a physical location? Actually, yes. Even if states store their data in the cloud (remote computing services offered by companies like Amazon), it is encoded in a specific place, and states should know where their data lives and who can access it. Sometimes important data is in old, legacy systems that are difficult to access — and might be physically housed in a particular office somewhere. States should know things like that and should see updating old systems as important management of a precious asset, not a desirable but unnecessary convenience that can be deferred until something breaks.

Over the last 15 years or so, many states have taken steps in the right direction by naming chief data officers and by constructing public-facing portals that share data with the public. Some of these portals were inspired by the Obama administration’s launch of the federal version, data.gov, in 2009. These are good starting points, but they are not the same thing as a comprehensive data audit.

The question is not which data can states easily make available to the public, but instead how much data do states have and how can they keep track of all of it? Some of the most important data that states have, especially in relation to the federal government, is highly personal data — such as Medicaid data — that is never going to go on a public portal. Similarly, for the states that do have chief data officers, their staffs and budgets are often too small to undertake complete data audits.

Of course, it is easy to say that states should do expensive things when one is not in charge of balancing a state’s budget. The point here though is that data audit projects should be seen not only as good governance initiatives (although they are that) but as a crucial part of protecting state sovereignty and fighting back against federal overreach — and therefore worth spending money on.

Stop Oversharing

A good audit lets states take the next important step — asking if they can cut back on sharing data with the federal government. As a practical matter, states are not going to stop sharing all data with the federal government. But the balance is probably off right now, with states sharing a lot more data than they really need to.

Law enforcement is a good example of this oversharing. Many states have laws modeled on the federal Driver’s Privacy Protection Act (from 1994) that prevent DMVs from sharing driver’s license information. But these laws have broad exceptions for law enforcement, and many states have memoranda of understanding with the FBI wherein they agree to share DMV photos freely with the federal government. Not just that — many states share their DMV photos through an interstate data system called the National Law Enforcement Telecommunications System (or “Nlets”). Recently, the FBI has used these photos and others, like arrest photos, to construct massive facial recognition technology databases that run on artificial intelligence. AI facial recognition technology and Nlets have, in turn, been fused together in an app called “Mobile Fortify” that ICE agents have on their phones: they can use the app to scan and identify the faces of, well, everyone, from people without legal status to protesters.

The point here is not so much that states need to immediately stop sharing DMV photos with each other or the FBI, rather, the point is for states to ask, “Why should we not be doing this?” and “What are the risks to our citizens and our values?” Sharing DMV photos seems like a positive thing in isolation — a small, mundane part of an ongoing and fruitful collaboration across state and federal law enforcement. But many people’s attitudes toward this initiative probably shift when they hear ICE agents tell an observer after they recorded her face and car, “[W]e have a nice little database, and now you’re considered a domestic terrorist.” States need to understand exactly where that shift occurs, talk about it publicly, and change their operations accordingly.

These will be hard conversations to have. Especially in the law enforcement context, there are real risks to cutting back on sharing data with the federal government. But democracy means publicly weighing those risks against the special dangers of combining large amounts of data in one pair of hands. States need to have such hard conversations so that they can reach decisions backed by democratic consensus — and then act accordingly to limit or modify how they share their data.

Throw States’ Weight Around

It’s all well and good to ask states to have more robust democratic conversations about when to share their data, but implementing those choices can be tricky in practice. Even if a state decides it is not comfortable with how its data will be used, multi-state programs often make it tough for states to avoid sharing their data. What is a state to do then?

The answer is to play smart and use the political and legal weight that states have in the best ways possible. Especially when states band together to advance their interests, they can meaningfully affect the substance of federal laws and the design of interstate data-sharing programs. Sometimes states might be the best or only political groups able to enforce constraints on the federal government.

Consider again the use of facial recognition technology. Over the last decade, different bodies within the federal government, including the Government Accountability Office and the U.S. Commission on Civil Rights, have produced a series of reports highlighting the potential risks of facial recognition technology, the absence of effective regulation, and its tendency to be biased against Black people. There were public hearings and outcry. After which… not much happened. The facial recognition technology databases remain in use.

Importantly, though, they still pull in data from state and local organizations all across the country, particularly arrest photos. In other words, these databases work only because of states’ ongoing grant of their resources — their data — to the federal government without substantial conditions or oversight. Given the direction of this relationship, states have special leverage over whether and how facial recognition technology is used that other organizations do not.

States should use that leverage to force the federal government to use data on terms that states approve of. Some states have already begun to follow this approach: in response to aggressive immigration enforcement by the federal government and apps such as Mobile Fortify, some states have begun specifically to block ICE use of Nlets, albeit without pulling out of Nlets completely. This is a real way to push back on federal government overreach and one that can be used in other contexts as well.

The new CDL lawsuit offers another example of how states can throw their weight around. In August 2026, the Department of Transportation and the Department of Homeland Security demanded CDL data not from states directly, but from a third-party nonprofit organization that contracts with states to host their CDL data. The nonprofit, on its own, was poorly positioned to resist the federal government’s demands, including because it is funded in part by the federal government — which threatened to cut off funding if the organization failed to comply.

By bringing their lawsuit, states were able to deploy greater legal firepower against the administration. For instance, states raised contractual claims against the nonprofit, arguing that the nonprofit would violate its agreements with the states were it to accede to the federal government’s demands. The states also asserted some of their unique constitutional prerogatives against the federal government, including that the federal government must give them clear notice of any conditions it puts on money provided to the states — in this case, money for highways.

Another important constitutional prerogative that the states do not appear to have raised in the new CDL lawsuit but that states should assert more frequently is a state’s right not to have its resources — including its data — commandeered by the federal government. As Jessica Bulman-Pozen explained in her essay for this series, states can use anti-commandeering doctrine to stop the federal government from using their personnel or infrastructure without their consent. Under this principle, states cannot be forced to just hand over their data to the federal government. State reticence to raise anti-commandeering claims in the data context may be partly the Supreme Court’s fault. In 1997, it suggested there might be a data exception to the anti-commandeering rule. But more recently, particularly in an article called “Data Federalism” in the Harvard Law Review, legal experts have explained why that view cannot be right. States should be confident that the Constitution protects them from outright commandeering of their data — and should include anti-commandeering claims when challenging federal government attempts to take control of their data.

* * *

In many ways, data’s rise to prominence is a boon for states. Like land in the nineteenth century — that era’s fundamental asset — state governments have a lot of valuable data. States need to realize the treasure they are holding and treat it accordingly.

First, they need to figure out how much data they have, where it is, and where it goes. Second, they need to stop handing it out for free to the federal government when they do not have to. Finally, they need to play smart when some data sharing is unavoidable. From demanding changes to national databases where their data is stored to asserting their constitutional rights to control their own resources, states can use the emerging power of data to put real weight behind their efforts to fight back.

Filed Under

, , , , , , , , , , , , , , , , , , , , ,
Send A Letter To The Editor

DON'T MISS A THING. Stay up to date with Just Security curated newsletters: