> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Resisting the Menace of Federal Data Consolidation

[SOURCE] EFF Deeplinks [AUTHOR: Adam Schwartz] [DATE: 09/10/2026 21:46] [LANGUAGE: EN]
Resisting the Menace of Federal Data Consolidation
In the past two years, the federal government has unlawfully consolidated data exposing our private information.  This consolidation has been chaotic but generally came in three rolling waves: It started with DOGE, moved to agency-to-agency data sharing with ICE, and then attempted data-driven purges of state voter rolls. We all deserve to live in a world where the data we use to pay our taxes, receive benefits, and vote is not combined and weaponized against us. The amalgamation of data leads to mistakes, abuses, and a lack of trust in institutions meant to protect us. Overall, it can chill our participation in society. This is particularly true for groups disfavored by this administration—especially immigrants and protesters. Congress highlighted similar abuses—including the creation of enemies lists and snooping on activists and federal employees—following the McCarthy and Watergate eras. And the increasing use of computers to magnify those harms led Congress to pass a slate of protections like the federal Privacy Act of 1974. The good news is that many people have stepped forward to resist the federal government’s unprecedented and unlawful data consolidations. Many groups, including EFF, have filed lawsuits to enforce our data privacy laws, and many states have, too. Legislators at the federal and state levels have worked to expose and oppose these surveillance programs. And many people have protested for their right to data privacy. Existing data privacy protections have been essential in the past two years, but they can be improved. This should include: narrowing loopholes and increasing enforcement in existing laws, limiting the government’s purchase of data on the commercial market, and passing a comprehensive consumer privacy law. Data Consolidation by DOGE Starting on January 20, 2025, President Trump created DOGE—essentially renaming an existing agency originally meant to modernize government technology. Rather than engage in modernization, DOGE quickly obtained high-level access to sensitive databases across the government that store millions of people’s personal records—including at the Office of Personnel Management (OPM), the Social Security Administration, and the Treasury Department. DOGE was staffed with people with little government or cybersecurity knowledge and who often had conflicts of interest. DOGE’s early aim was not always clear, aside from gaining “prompt access to all unclassified agency records” and the “sharing and consolidation” of those records. The result? The indiscriminate firing of government employees and the decimation of important agencies that focused on consumer protection and foreign aid. It also resulted in clear misuses of data. For example, while working with DOGE at the Social Security Administration, one individual signed an outside agreement with an advocacy group with the aim of using SSA data to find evidence of alleged voter fraud and “overturn election results in certain States.” DOGE’s data access and consolidation violated the federal Privacy Act, which limits the sharing and consolidation of government databases. Many groups stepped in to sue. For example, EFF and our co-counsel at Lex Lumina LLC and Democracy Defenders Fund, on behalf of two public employee unions (AFGE and AALJ), sued the OPM for unlawfully disclosing federal workers’ information to DOGE. After EFF and others secured early victories, the government sought to end the lawsuits by firing many DOGE agents and removing their access to records. A great deal of damage remains in need of a judicial remedy. Data Consolidation by the Department of Homeland Security (DHS) Even as DOGE’s influence diminished, federal agencies have attempted to share, compare, and seize large databases, in order to target immigrants. In some cases, they have succeeded. This happened with tax records at the IRS, Medicaid data from the Department of Health and Human Services (HHS), and public housing data from the Department of Housing and Urban Development. The Department of Agriculture also sought to collect databases regarding Supplemental Nutrition Assistance Programs (SNAP) from states. Many groups have filed lawsuits to block this anti-immigrant-motivated data consolidation, alleging it violates privacy protection laws. EFF filed amicus briefs in support of two of these lawsuits: Centro de Trabajadores v. Bessent, which concerns IRS data; and California v. HHS, which concerns Medicaid data (and where we teamed up with EPIC and Protect Democracy). Most recently, states have stepped up to challenge the federal government’s attempted seizure, for immigration enforcement purposes, of state commercial driver’s license data held by the American Association of Motor Vehicle Administrators, a non-profit organization. This data consolidation for immigration enforcement has also included government purchase of commercial products. This includes ICE’s purchase of commercial location data without a warrant, and its interest in “Big Data and Ad Tech providers.” ICE also has contracts with companies like Palantir, which help organize all the datasets the agency collects. Data Consolidation for Voter Purges The right to vote is fundamental to every democracy. That’s why EFF has long advocated for cybersecurity in voting systems, to make sure every vote is properly counted. Voter purges are a longstanding threat to the right to vote. State and local officials regularly delete people from the voter registration rolls, often for bad reasons and without adequate notice. This has a disparate impact against people of color. Now the federal government is trying to purge voters, too. To do so, it has consolidated our data in three ways. First, it is using an old data system called SAVE for a new purpose: checking voter eligibility. Second, it has seized voter information from states. Third, it has created a federal list of eligible voters. As a direct result, people with a right to vote will be purged from voter rolls because of erroneous data. Others will be intimidated from voting or registering. And all registered voters suffer a violation of their data privacy rights: information collected for one purpose is being used against them for another purpose. Expansion of SAVE Since 1986, the federal government has operated SAVE, which stands for Systematic Alien Verification for Entitlements. It is not a database, but it facilitates easy access to databases. It is used to determine whether immigrants and naturalized citizens are eligible for various government benefits, such as food stamps. In 2025, the federal government started using SAVE for a new purpose: checking voters’ eligibility. Further, SAVE now provides access to new databases and allows bulk searches. More than 60 million voters have been run through SAVE, and 21,000 were flagged as potential noncitizens who are ineligible to vote. Erroneous flags have caused purges of lawful voters – such as Anthony Nell. A case called League of Women Voters v. DHS challenges this expansion of SAVE. The plaintiffs are represented by CREW, Democracy Forward, the Fair Elections Center, and EPIC. A federal judge held this program unlawful and set it aside. DHS appealed and asked for a stay of this order, and a federal appellate court denied the stay. Unfortunately, the U.S. Supreme Court granted the stay, exercising its controversial “shadow docket” authority by a six-to-three vote. Federal employees in DHS’s “Fraud Detection and National Security Unit,” which ordinarily investigates alleged immigration fraud, have been re-assigned to examine voter eligibility. A whistleblower alleges that employees have been directed to go to state election agency websites, enter some of a voter’s personal information, and thereby access more of it. This may violate state laws requiring a person, before accessing a voter’s information, to attest they are that voter or have that voter’s authorization. Federal Seizure of States’ Voter Information Since 2025, the federal government has demanded that at least 48 states hand over their voter information. At least 16 states have complied. The federal government is running this information through SAVE, searching for voters to purge. The federal government has sued 30 states for refusing to comply. So far, courts have dismissed 25 of these suits. There’s also a lawsuit against this data grab, titled Common Cause v. DOJ, brought by CREW, Protect Democracy, and the ACLU. The New Federal Voter Eligibility List In March 2026, President Trump issued an executive order requiring DHS to create a list of people who are U.S. citizens, aged 18 or older, and residents of the state. The order also requires DOJ to prosecute anyone, including state and local officials, who provides a ballot to a person who is not eligible to vote in federal elections. In California v. Trump, 24 states allege that this executive order violates the Constitution’s separation of powers. A federal judge enjoined this program, and an appellate court denied a stay. But the U.S. Supreme Court by a six-to-three vote granted a stay, which allows the program to move forward. (By a seven-to-two vote, the Court denied a stay of an injunction against a different part of the same executive order, which concerned mail-in ballots.) Another legal challenge, titled EPIC v. USCIS, alleges that the new federal voter eligibility list violates the Privacy Act as well as the separation of powers. Next Steps It is encouraging to see so many people, groups, and states step forward to protect our data privacy from these unlawful waves of federal data consolidations. Still, more work remains. For example: The Privacy Act of 1974 has proven a critical bulwark. But after a half century, it could use a refresh. For example, Congress should close its loopholes and expand its enforceability. Law enforcement agencies must be prohibited from avoiding the Constitution’s warrant requirement by buying our personal data from brokers. For example, Congress should pass the “Fourth Amendment Is Not For Sale Act.” We need a comprehensive consumer data privacy law, among other reasons to reduce the flood of our personal data that corporations provide to law enforcement agencies. Legislators should check out EFF’s “privacy first” framework. In the meantime, there’s no time like the present to practice surveillance self-defense, like using strong passwords and disabling your phone’s ad identification.   Related Cases: American Federation of Government Employees v. U.S. Office of Personnel Management
[messages.read_original_source] →