DOGE Data Access Raises Privacy Questions as Federal Lawsuit Advances

Table of Contents

A federal lawsuit challenging the Department of Government Efficiency’s alleged access to sensitive information held by the Treasury Department and Office of Personnel Management can move forward after a Virginia judge rejected the government’s attempt to dismiss the case.

The decision does not determine that DOGE, the Treasury Department or OPM violated federal privacy law. It does, however, allow the plaintiffs to continue pursuing claims arising from the alleged disclosure of personal information belonging to federal employees and millions of other Americans.

The case could become an important test of whether unauthorized access to a government database constitutes a concrete privacy injury even when plaintiffs cannot show that their information was publicly released, stolen or used for identity theft.

Privacy Lawsuit Against DOGE Survives Dismissal

The Electronic Privacy Information Center, commonly known as EPIC, and an unnamed federal employee filed the lawsuit in February 2025. The federal employee is identified as “Doe 1” in court records.

The plaintiffs allege that the administration unlawfully gave DOGE personnel access to databases operated by the Treasury Department and OPM. According to the amended complaint, those systems contain extensive personally identifiable information involving federal workers, taxpayers and members of the public.

The lawsuit alleges violations of the Privacy Act, the Federal Information Security Modernization Act, the Internal Revenue Code and the Fifth Amendment right to informational privacy. The government disputes the allegations and maintains that the plaintiffs have not established an actionable injury or adequately stated their legal claims.

On 29 July 2026, Judge Rossie D. Alston Jr. of the U.S. District Court for the Eastern District of Virginia declined to dismiss the lawsuit.

The case is Electronic Privacy Information Center v. U.S. Office of Personnel Management, Case No. 1:25-cv-00255.

Government Argued That Database Access Was Too Abstract

A central issue in the case is whether allowing allegedly unauthorized personnel to access a database creates a sufficiently concrete injury for a federal lawsuit.

The administration argued that the possibility that DOGE personnel could access information concerning the plaintiffs was too abstract. Its position focused on the absence of allegations showing that the information had been publicly disclosed or used to commit fraud or another form of downstream harm.

That standing argument has become more difficult following an April 2026 ruling from the full U.S. Court of Appeals for the Fourth Circuit in a separate case concerning DOGE’s access to Social Security Administration records.

In that case, the Fourth Circuit concluded that allegedly unauthorized access to sensitive personal information could inflict a concrete injury comparable to the traditional privacy tort of intrusion upon seclusion.

The appellate court explained that an intrusion-upon-seclusion injury does not necessarily require public dissemination or subsequent misuse. The allegedly unjustified intrusion into private information can itself constitute the relevant harm.

The Fourth Circuit ultimately vacated the preliminary injunction restricting DOGE’s access to Social Security data, based in part on the standard governing that early form of relief. Nevertheless, the court rejected the argument that the plaintiffs necessarily lacked standing simply because their information had not been publicly released.

The Fourth Circuit’s April 2026 opinion became particularly important to the Virginia case because the Eastern District of Virginia sits within the Fourth Circuit.

Unauthorized Access May Be a Privacy Injury Without Public Disclosure

The most important aspect of the litigation may be the distinction between access and disclosure to the general public.

Organizations frequently view a privacy incident through the framework of a conventional data breach. They ask whether information was exfiltrated, published online, sold, used for identity theft or obtained by an outside attacker.

This case presents a different question: What happens when a person inside or affiliated with an organization allegedly receives access to personal information without a legitimate need or sufficient legal authorization?

The Fourth Circuit’s reasoning suggests that, at least in some circumstances, unauthorized internal access may create a concrete privacy injury even without evidence of public exposure.

The court compared access to sensitive databases with traditional examples of intrusion into private affairs, such as examining someone’s bank account, wallet, mail or personal documents without authorization.

For standing purposes, the fact that the information is stored in a database containing millions of records does not automatically make the alleged injury less personal. Each person may have an individual privacy interest in who is authorized to access his or her information.

What Information Was Allegedly Available?

The plaintiffs contend that the government systems at issue contain highly sensitive information about federal employees and members of the public.

Depending on the system and individual record, that information may include:

  • Names, addresses and dates of birth.
  • Social Security numbers and taxpayer information.
  • Banking and payment details.
  • Federal employment and personnel records.
  • Benefits and retirement information.
  • Information relating to government payments.
  • Other personal information maintained by OPM and the Treasury Department.

These remain allegations. The government has disputed the characterization of DOGE’s access and whether the plaintiffs have shown that their particular records were accessed improperly.

Additional information about the complaint and procedural history is available through EPIC’s case page.

The Decision Does Not Resolve the Merits

The denial of a motion to dismiss should not be treated as a final ruling that the government violated the law.

At this stage, the court determines whether the plaintiffs have alleged a legally sufficient case that may proceed. The plaintiffs must still support their allegations with evidence and prove that the challenged access violated the applicable statutes or constitutional protections.

The government can continue to contest whether DOGE personnel were authorized to access the information, whether any legally prohibited disclosure occurred, whether the cited laws permit the requested relief and whether the plaintiffs can prove entitlement to damages or an injunction.

The litigation may now move into discovery, where the parties could seek evidence concerning access permissions, personnel roles, system logs, security controls, training, agency authorizations and the specific data available to DOGE personnel.

Why Access Logs and Permission Controls Matter

The case highlights a central principle of data governance: protecting information involves more than preventing hackers from entering a system.

An organization must also control which employees, contractors and service providers can access personal information, why they can access it and how that access is monitored.

A defensible access-governance program should address:

  • Role-based access permissions.
  • Documented business justifications for access.
  • Least-privilege controls limiting access to necessary information.
  • Approval and review procedures for elevated permissions.
  • Logging of database access and administrative activity.
  • Periodic review and removal of unnecessary permissions.
  • Privacy and security training for authorized personnel.
  • Contractor and third-party access controls.
  • Procedures for investigating unusual access.
  • Retention of evidence showing who accessed information and when.

These controls are particularly important when new teams, contractors or outside specialists receive expedited access to systems containing sensitive information.

Broader Implications for Privacy Litigation

The DOGE litigation arrives as courts continue to define what constitutes a concrete privacy injury in the digital environment.

Defendants frequently argue that technical access, data collection or statutory violations are insufficient unless a plaintiff can show financial loss, identity theft, public disclosure or another tangible consequence.

The Fourth Circuit’s reasoning provides privacy plaintiffs with a different theory: unauthorized access to private information may resemble intrusion upon seclusion closely enough to establish standing, even when the information was not subsequently published.

That does not mean every allegation of database access will support a lawsuit. Plaintiffs must still establish that the access occurred, that it was unauthorized and that the alleged intrusion is sufficiently connected to a traditionally recognized harm.

Nevertheless, the ruling could influence disputes involving employee monitoring, healthcare records, financial databases, consumer profiles, government systems and other repositories of sensitive personal information.

The Compliance Lesson Extends Beyond Government

Although this case concerns federal agencies and DOGE, its operational lessons apply to private businesses as well.

Companies should not assume that personal information remains legally protected merely because it stays inside their technical environment. Giving an employee, contractor, analytics provider or software vendor unnecessary access can create privacy exposure even if no conventional cybersecurity breach occurs.

Organizations need to understand not only what personal information they collect, but also who can see it, what systems receive it, why access is permitted and whether logs can demonstrate that internal rules were followed.

The advancement of the DOGE lawsuit reinforces a simple but increasingly important principle: access itself matters. A privacy program must govern the collection, disclosure and use of personal information—and the permissions that determine who can reach it in the first place.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.