Ron Wyden

08/26/2026 | Press release | Distributed by Public on 08/26/2026 12:57

Wyden, Brown Seek GAO Investigation Into DOT Failure to Protect Airline Passenger Data

August 26, 2026

Wyden, Brown Seek GAO Investigation Into DOT Failure to Protect Airline Passenger Data

Following Major Privacy Incidents Affecting Hundreds of Millions of Air Travelers, Lawmakers Demand Answers on DOT Backtracking on Pledge to Act To Enforce Passenger Data Privacy and Security

Washington, D.C. - U.S. Senator Ron Wyden, D-Ore. and Ranking Member of the House Oversight Subcommittee on Cybersecurity, Information Technology, and Government Innovation Rep. Shontel Brown, D-Ohio., requested the Government Accountability Office (GAO) to investigate the Department of Transportation's (DOT) ongoing failure to protect passenger privacy using its authority to regulate the practices of commercial airlines and ticket agents.

DOT has had the sole authority to protect passenger data for more than 40 years, yet, according to a review by the Congressional Research Service, it has never taken a privacy enforcement action-even after major incidents affecting hundreds of millions of travelers. This inaction has left sensitive personal travel data vulnerable to corporate exploitation, government surveillance, and potential threats from foreign adversaries.

"DOT's abdication of its role as a privacy regulator has left the sensitive personal information of hundreds of millions of Americans exposed to corporate exploitation, warrantless government surveillance, and warrantless seizure of money and other property, " the lawmakers wrote in letter to Acting Comptroller General Orice W. Brown. "In addition to harming the public, DOT's regulatory inaction also potentially threatens national security. Travel data held by airlines and travel agencies may be of interest to foreign adversaries, who could exploit such information to track U.S. military, diplomatic, and other U.S. government personnel."

Historically, DOT has taken a reactive approach to airline privacy, relying on consumer complaints instead of proactively auditing airlines' privacy practices. In March 2024 Senator Wyden partnered with the DOT to launch a first-ever industry-wide review into the privacy practices of the nation's 10 largest airlines. More than two years later, DOT has not publicly released its findings or announced any enforcement actions.

The need for stronger DOT oversight is clear. For years, a data broker collectively owned by major U.S. airlines, the Airline Reporting Corporation (ARC) provided federal agencies access to roughly 722 million passenger travel records without warrants or judicial oversight. ARC shut down the program in November 2025, but DHS has since sought a replacement passenger-surveillance system.

Wyden and Brown asked the GAO to launch a comprehensive investigation into the DOT's systemic failure to fulfill its consumer privacy enforcement responsibilities, by answering the following questions:

  • Status of the 2024 Airline Privacy Review: Provide a full accounting of the status, findings, and disposition of the industry-wide review launched on March 21, 2024.

  • Audit of Agency Personnel and Technical Expertise: Identify the exact number of full-time personnel within the OACP currently dedicated exclusively to privacy enforcement, including the number of technologists.

  • Audit of Interagency Coordination on DEA Informants: Review the interagency coordination between DOT and the Department of Justice (DOJ) over airline employees selling passenger data to the Drug Enforcement Agency (DEA), including any delays and actions taken to hold airlines accountable.

  • Agency Response to Widespread Public Scandals: Evaluate whether DOT independently investigated ARC's sale of passenger records or took action only after congressional and media pressure led to the program's closure in November 2025.

  • Structural Nature of the Complaint-Driven Model: Examine why DOT relies on a complaint-driven model instead of routine privacy audits.

  • Assessment of Insider Threat Mitigation and Data Governance: Evaluate whether the DOT has established guidelines regarding airlines' protection of Passenger Name Record (PNR) databases against insider threats.

  • International Data Commitments: Explain how DOT's domestic privacy enforcement since July 2023 aligns with its commitments to the European Commission under the EU-U.S. Data Privacy Framework (DPF).

The lawmakers asked GAO to respond with legislative recommendations to strengthen DOT's enforcement authority and better protect travelers' privacy rights.

"If the DOT continues to neglect its domestic regulatory obligations, it risks undermining the integrity of this entire agreement, potentially collapsing transatlantic data flows and destroying vital economic benefits for U.S. companies," the law makers concluded.

A copy of the full letter sent to the GAO is available here.

###

Ron Wyden published this content on August 26, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 26, 2026 at 18:57 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]