Skip to content

CIV-010 — Congressional Authorization for Secondary Use of Government-Held Personal Data

Issue Snapshot

Problem: Personal data can be repurposed without explicit congressional authorization.
Repair: Require congressional authorization, necessity, minimization, logging, review, and prospective relief.
Vehicle: Privacy Act and conforming amendments to program-specific data statutes.

Project Policy Position

ARRP expressly adopts the following policy judgment:

The federal government should not use personal data for purposes Congress has not explicitly authorized.

Existing law does not necessarily establish that rule in full. This proposal is therefore transparent about asking Congress to adopt a stronger government-wide purpose limitation. It does not treat every disputed disclosure as unlawful, and it does not infer an institutional failure merely because an agency loses a case. When existing law prohibits a use and a court supplies timely, effective relief, that is the existing system correcting unlawful conduct.

The distinct concern is what happens when materially unrelated secondary use is lawful, arguably lawful, or practically unreviewable because Congress has not supplied a clear general prohibition, program statutes differ, agency-defined exceptions reach beyond the original collection purpose, or available remedies cannot prevent the use before harm occurs.

Institutional Anomaly

People routinely must provide tax, benefits, employment, health, identity, immigration, licensing, and other personal information to administer federal programs. Congress may restrict those records through a program statute, leave them primarily to the Privacy Act, or create a separate disclosure regime.

That fragmented architecture does not establish one clear rule requiring Congress to authorize a materially different governmental purpose. The Privacy Act generally restricts disclosure from a system of records, but it contains twelve statutory exceptions, permits agencies to publish compatible “routine uses,” allows exemptions for specified systems, and provides remedies whose availability depends on the kind of violation. Agency publication, an executive order, an interagency agreement, or a broad claim of administrative authority may therefore play a larger role in defining secondary use than the proposed congressional-authorization principle would allow.

Manifestations of the Failure

Program-specific disputes produce different authorization rules

Recent litigation over disclosure of tax, benefits, personnel, and other administrative records illustrates that legality can turn on the particular program statute rather than a common government-wide rule.

In Centro de Trabajadores Unidos v. Bessent, the D.C. Circuit concluded that 26 U.S.C. § 6103(i)(2) can authorize qualifying disclosures of taxpayer address information for a non-tax federal criminal investigation when the statutory requirements are satisfied. That result illustrates the principle advanced here: Congress may authorize a defined secondary use. Whether a particular request or disclosure satisfied the statute remains a compliance question, not the independent basis for this proposal.

In litigation concerning Supplemental Nutrition Assistance Program records, a federal district court's preliminary-injunction order concluded that the plaintiff States were likely to succeed on their claim that the requested use was outside the SNAP Act's program-administration and enforcement limits. If that conclusion ultimately produces effective relief, the program-specific safeguard has operated. The cross-cutting question is why comparable personal information should receive materially different purpose protection depending on the statute under which it was collected.

Cross-agency access can outpace a clear purpose decision

Pending cases involving tax records, personnel information, benefits records, and DOGE or other cross-agency access arrangements raise recurring questions about who may access a system, for what purpose, under which statutory exception, and with what remedy. Those matters remain source-development records unless and until a court or verified official record establishes the relevant facts. CIV-010 does not presume that access by a particular official or unit was unlawful.

The institutional manifestation is the recurring need to reconstruct purpose authority from different organic statutes, disclosure exceptions, routine-use notices, memoranda, executive directives, and remedial doctrines after an attempted secondary use has already begun.

Resulting Damage

The absence of a clear congressional-authorization rule can:

  1. deter people from applying for benefits, paying taxes, seeking services, reporting household information, or cooperating with public programs;
  2. allow an agency to convert a collection authority into a broader enforcement, intelligence, personnel, or political-use authority;
  3. shift sensitive policy choices from Congress to agency notices, interagency agreements, or executive directives;
  4. create uneven protection for similar personal information held under different statutes;
  5. make it difficult for affected people, courts, inspectors general, and Congress to determine whether a use is authorized before disclosure or matching occurs;
  6. preserve data longer than the authorized program purpose requires, increasing the opportunity for unrelated use; and
  7. leave monetary relief after disclosure as an inadequate substitute for preventing an unauthorized use.

Underlying Weakness

The Privacy Act is principally organized around records maintained in a “system of records” and disclosures from those systems. Its routine-use, law-enforcement, matching, exemption, and remedy provisions do not operate as an unqualified rule that every materially different use of personal data must first be explicitly authorized by Congress. Program-specific statutes then add protections, permissions, and exceptions that vary by dataset and agency.

The result is a purpose-limitation gap rather than a conclusion that all information sharing is improper. Congress may legitimately authorize secondary uses, including defined law-enforcement, emergency, audit, anti-fraud, oversight, archival, and research uses. The institutional question is who makes that choice and what safeguards accompany it.

Least-Complex Adequate Remedy

The primary vehicle should be a government-wide amendment to the Privacy Act providing that an agency may not use or disclose personal data for a materially different purpose unless an Act of Congress specifically authorizes that purpose.

The amendment should:

  1. define the authorized collection purpose and materially different secondary use;
  2. clarify that necessary administration of the congressionally authorized program is not a new purpose;
  3. provide that an executive order, interagency agreement, regulation, system-of-records notice, or agency-defined routine use cannot independently create secondary-use authority;
  4. permit Congress to authorize particular uses or carefully defined categories of use;
  5. require necessity, data minimization, access controls, logging, notice where compatible with legitimate operations, and independent review for authorized secondary uses;
  6. limit retention to periods justified by an authorized purpose while preserving expressly defined archival, evidentiary, legal-hold, audit, and similar duties;
  7. prohibit circumvention through contractors, shared systems, derived datasets, informal access, or transfers between components of the same department; and
  8. provide effective prospective relief capable of stopping an unauthorized use or disclosure before the injury becomes irreversible.

Because many federal statutes independently govern the collection, retention, matching, use, or disclosure of particular records, the bill will also require a structured conforming review. Program-specific amendments should identify any intended secondary uses, reconcile existing exceptions with the government-wide rule, and preserve stronger existing protections.

Proposed Legislation

  • Selected vehicle: A federal bill amending the Privacy Act and making necessary conforming amendments to program-specific personal-data statutes.
  • Current status: Pending initial statutory survey and drafting. Development must distinguish express statutory authorizations from agency-created permissions and must not silently repeal stronger tax, benefits, health, personnel, immigration, civil-rights, records, or archival protections.

Relationship to Adjacent Proposals

CIV-009 owns the instrument-and-authority question when a repurposed technical or temporary unit exercises cross-agency operational control or obtains systems access without adequate appointment, delegation, privacy, procurement, records, appropriations, and oversight safeguards. CIV-010 owns the separate purpose question: whether any agency or unit may use government-held personal data for a materially different purpose that Congress did not explicitly authorize.

DOM-009 owns surveillance acquisition and deployment. ELEC-001 owns interference with election administration. RIGHTS-001 owns coordinated uses of government authority affecting identity-based civil rights. REC-001 owns preservation and integrity of government records. Those proposals may supply manifestations or specialized safeguards, but CIV-010 is the primary home for the government-wide personal-data purpose limitation.

Budgetary Impact Statement

No reliable dollar estimate is available before the statute-by-statute review and bill draft. Likely implementation costs include data-inventory and purpose mapping, access-control changes, retention schedules, audit logs, privacy and inspector-general review, notice systems, training, and litigation or administrative review. Existing privacy, records, information-security, and inspector-general functions may absorb part of the work, but a government-wide conforming review and legacy-system changes could require material temporary and continuing resources.

Note: Preliminary ARRP assessment only; not a CBO, OMB, agency, or legislative-counsel score.

Proposal Scoring

Proposal Quality Score: 0 / 100 (Not Scored)
Adoption Friction: N/A
Required Electoral Environment: N/A
Development Priority: High

Internal Review Status: Foundation approved; initial statutory development pending
Last Internal Review: Horizon candidate admission and foundation decision
Scoring Standard: 2026-06-27.2; Scoring Basis: Current unscored status; Revision Review Needed: No
Next Review: Complete a statute-by-statute purpose, retention, disclosure, remedy, and constitutional review; then draft the Privacy Act and conforming amendments
Full Review History: CIV-010 review history

Annotation

Affirmative policy judgment. The congressional-authorization rule is an ARRP policy position, not a representation that present law already requires express authorization for every covered use. The proposal should continue to distinguish existing-law compliance disputes from the broader safeguard it asks Congress to enact.

Congressional choice preserved. The proposal does not prohibit Congress from authorizing a secondary use. It requires Congress—not an agency acting alone—to make that materially different purpose decision.

Administrative operation preserved. An agency does not create a new purpose merely by performing operations necessary to administer the program Congress authorized. The later bill must define this boundary sufficiently to prevent both administrative paralysis and conclusory claims that any desired use is “related.”

Reciprocal application. The same rule applies regardless of the administration, agency, enforcement objective, political beneficiary, or population whose information is held. The project uses “personal data” rather than “citizen data” because federal records concern citizens, lawful permanent residents, visa holders, applicants, taxpayers, household members, employees, and other people.

Source Notes

The initial litigation and source-verification questions are retained in CIV-010 source development. The first development pass should obtain controlling opinions and operative agency records; inventory the Privacy Act's collection, routine-use, matching, exemption, retention, and remedy provisions; identify major program-specific data statutes; and determine which conforming amendments are necessary without relying on allegations as adjudicated facts.