CDT Report Examines Privacy Risks in Expanding U.S. Government Data Sharing

Table of Contents

The Center for Democracy & Technology has released a technical explainer examining how U.S. government agencies share and consolidate personal data, with particular attention to the privacy, surveillance, and cybersecurity implications of moving beyond limited, purpose-specific exchanges. Titled “What is a Database? A Technical Guide to the Personal and Institutional Considerations of Government Data Consolidation,” a recent report by Hannah Quay-de la Vallee outlines both the longstanding rationale for targeted data sharing and the heightened risks that arise when agencies pursue broader consolidation of sensitive datasets.

For years, limited interagency data sharing has been accepted as a practical tool. It can reduce administrative burdens on both government staff and individuals, improve coordination of benefits and services, and help detect fraud, waste, and abuse. The CDT report acknowledges these benefits while arguing that recent federal efforts have shifted toward larger-scale consolidation of data held by federal, state, and local agencies—moves that depart from decades of bipartisan caution against the government amassing extensive personal information on Americans.

When Sharing Becomes Consolidation

The core distinction drawn in the report is between targeted, purpose-limited sharing and the creation of more comprehensive, multi-agency repositories. Targeted exchanges typically involve specific data elements needed for a defined administrative or enforcement function. Consolidation, by contrast, can enable data originally collected for one purpose to be combined, retained, and processed for others. According to the analysis, this expansion “may not comport with the expectations and consent of those who provided the data, violating their privacy and degrading trust in government agencies.”

Individuals who supply information to one agency—whether for tax administration, benefits eligibility, licensing, or law enforcement—generally do so under an understanding of how that information will be used. When datasets are later merged or made widely accessible across agencies without clear notice or renewed authorization, that original understanding is undermined. The report frames this mismatch as both a privacy harm and an erosion of institutional legitimacy.

Technical Design Choices and Risk

A central contribution of the CDT explainer is its focus on technical architecture. The risks of consolidation are not inevitable; they depend heavily on design decisions. Factors such as whether data remains siloed with strict access controls, whether unique identifiers enable easy linkage across systems, how long data is retained, and whether purpose limitations are enforced through technical means all influence the scale of potential harm.

Poorly designed consolidation can amplify several categories of risk. Privacy invasions become more likely when sensitive attributes from different contexts are combined. Surveillance capabilities expand if agencies can query comprehensive profiles rather than discrete records. Cybersecurity exposure grows because a single breach or unauthorized access point can expose far more information than a breach of an isolated system. The report emphasizes that understanding these technical levers is essential for policymakers weighing whether the operational benefits of broader sharing outweigh the corresponding dangers.

Institutional and Personal Stakes

Beyond individual privacy, the analysis addresses institutional considerations. Large-scale data repositories can create new points of failure, complicate oversight, and concentrate power in ways that are difficult to reverse once established. They may also encourage mission creep, as data collected for one legitimate purpose becomes available for secondary uses that were never contemplated—or consented to—at the time of collection.

The report situates these developments against a backdrop of expanding federal interest in administrative data held by states and localities. While some coordination can improve service delivery, the scale and ambition of recent initiatives raise questions about whether traditional safeguards—statutory purpose limitations, Privacy Act restrictions, and agency-specific data-sharing agreements—remain adequate.

Implications for Privacy Governance

For privacy professionals, compliance officers, and policymakers, the CDT analysis offers a framework for evaluating proposed data-sharing arrangements. Key questions include: Is the sharing narrowly tailored to a specific, documented purpose? Are technical and organizational controls in place to prevent secondary use? Do individuals receive meaningful notice? Can access be audited and limited? And does the architecture minimize the creation of comprehensive personal profiles?

The report does not reject all interagency data exchange. Instead, it argues for disciplined assessment of when consolidation’s risks exceed its benefits and for design choices that constrain those risks. In an environment where government agencies hold increasing volumes of sensitive personal information, the difference between limited, accountable sharing and broad consolidation carries significant consequences for both individual rights and public trust.

As federal and state entities continue to explore more integrated data practices, the technical and institutional considerations outlined by the Center for Democracy & Technology provide a timely reference point for evaluating whether new arrangements respect the expectations of the people whose data is at stake.

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.