

SUBSCRIBE TO OUR FREE NEWSLETTER
Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
5
#000000
#FFFFFF
To donate by check, phone, or other method, see our More Ways to Give page.


Daily news & progressive opinion—funded by the people, not the corporations—delivered straight to your inbox.
"Big Tech and Big Data companies like Thomson Reuters need to decide whether profiting from government surveillance is compatible with the values they claim to hold," said one tech watchdog.
More than two dozen watchdog organizations are calling on Congress to investigate reports that the data broker Thomson Reuters is making its investigative database available to US Immigration and Customs Enforcement, which they warn will make Americans vulnerable to Fourth Amendment violations.
Last month, documents unearthed by 404 Media revealed:
The Department of Homeland Security (DHS) plans to pay data broker giant Thomson Reuters $125 million for access to its databases of personal data—which includes peoples’ names, addresses, Social Security numbers, ethnicity, social media posts, and geolocation information—to help Immigration and Customs Enforcement (ICE) investigate what it describes as “voters fraud” and immigration fraud.
On Tuesday, a coalition of advocacy groups, including Public Citizen, ACLU, the Center for Democracy and Technology, Common Cause, the Leadership Conference on Civil and Human Rights, and the Electronic Privacy Information Center, sent a letter to members of the Senate Judiciary and Homeland Security committees warning about the deal.
"The reporting highlights a problem that has continued to grow in recent years: Federal agencies are purchasing access to commercially aggregated personal information that they could not otherwise obtain without judicial oversight," the letter says. "This growing practice threatens to erode the protections guaranteed by the Fourth Amendment and underscores the urgent need for Congress to close the data broker loophole."
Thomson Reuters is primarily known for its leading international news agency, but it is also a major data broker that sells access to its dozens of databases to businesses and governments.
ICE has been buying data from Thomson Reuters since 2008. But the Trump administration hopes to dramatically expand its access through a package of Thomson Reuters Special Services investigative products that includes CLEAR, which aggregates public and proprietary records such as addresses, phone and subscriber data, vehicle records, and publicly available web and social media information.
The package also includes license-plate and alerting tools capable of providing nationwide vehicle location information and real-time alerts based on last-known-location data.
While much of this data could be acquired through other means, the watchdog groups explained that "aggregating them into searchable investigative dossiers dramatically expands government surveillance capabilities, which further run the risk of being supercharged by the rapid growth and use of artificial intelligence by the federal government."
A DHS procurement document reviewed by 404 stated that Thomson Reuters "is the only contractor able to provide ICE with a continuous monitoring and alert service for millions of individuals and entities of interest; this is essential for national security purposes.”
Thomson Reuters has denied that selling CLEAR access presents a constitutional risk, stating earlier this year that "CLEAR does not contain the types of information that law enforcement traditionally need a warrant to obtain, and CLEAR does not include information about an individual’s citizenship or immigration status."
The letter from advocacy groups also notes that the use of this technology in voter fraud investigations, in addition to immigration and national security, "demonstrates the broad range of government functions now supported by commercially acquired surveillance tools."
The documents do not make clear how ICE plans to use the data from Thomson Reuters in a voter fraud investigation.
Trump has directed the federal government to use DHS citizenship and immigration records to identify suspected noncitizen voters and commanded states—in an order that has been blocked by a federal judge—to turn over information about their voters.
While the administration says the goal is to root out noncitizen voters, voting rights advocates have warned that many eligible voters are also at risk of being wrongly purged.
As 404 pointed out, news of the agreement with Thomson Reuters came "after President [Donald] Trump held a conspiracy-laden and unhinged press conference about election security" in July, "setting the stage for potentially undermining the legitimacy of the upcoming midterm elections."
The letter urges Congress to hold oversight hearings examining federal agencies' acquisition and use of commercially available information from data brokers, require transparency about what data agencies are purchasing and how it's being used, and examine whether existing law surrounding data purchasing adequately protects constitutional rights.
It also calls on the government to pass the Fourth Amendment Is Not For Sale Act, a bipartisan piece of legislation that would close the data broker loophole by preventing the government from buying data from private companies that it would ordinarily need a judicial warrant to obtain directly from an individual or company.
"Americans should not lose their Fourth Amendment rights simply because the government is willing to purchase its way around our rights," said JB Branch, the director of federal AI governance and technology policy at Public Citizen. "Big Tech and Big Data companies like Thomson Reuters need to decide whether profiting from government surveillance is compatible with the values they claim to hold.”
Just four major data broker breaches in recent years have cost US consumers over $20 billion, according to a Thursday report from a key leader in Congress that argues "additional action is needed to protect Americans from scams."
Sen. Maggie Hassan (D-NH), ranking member of the congressional Joint Economic Committee (JEC), launched a sweeping investigation into financial scams last July. As part of it, she's examined data brokers, which collect and sell individuals' personal information. These companies often operate with limited transparency, her report explains, making it "more difficult for individuals to secure their information online and, ultimately, protect themselves from the growing threat of scams."
"Data brokers, for example, can enable scams by making consumers' personal information available to bad actors, who can then use details like Social Security numbers, home addresses, or banking information to develop customized and convincing scams," the report explains. "In some cases, data brokers have allegedly sold this information directly to scammers; in others, cyber hacks of data brokers have exposed individuals' data to uncontrolled circulation online."
Last August, after Wired reported that some data brokers took steps to hide their opt-out pages, Hassan issued investigative requests to Comscore, Findem, IQVIA Digital, Telesign, and 6Sense Insights. The report states that all of the companies but Findem responded with "actions to make their opt-out options more accessible to consumers and other parties," which "included removing 'no index' code that had blocked opt-out pages from search engine results, adding opt-out links in more prominent locations, and publishing blog content explaining how people can exercise their privacy rights."
"Notably," the report continues, "Findem did not respond to the ranking member's requests or written outreach from committee staff and has not removed the 'no index' code from its opt-out page—raising serious concerns about its responsiveness to opt-out requests and commitment to data privacy."
Months after the report was first released, on May 15, the JEC announced that Findem had also "updated its data collection opt-out processes to make it easier for people to protect their personal data." The panel published a supplement about the update.
While recognizing the companies for their positive responses, Hassan's report also stresses that more must be done. For instance, she requested information about efforts "to audit or assess the visibility of opt-out options or the success rates of opt-out requests," and "only 6sense stated that it contracts with third-party auditors to conduct both of these assessments."
Highlighting the need for further action, Hassan's staff estimated that identity theft stemming from four large data broker breaches—Equifax in 2017, impacting 147 million US residents; Exactis in 2018, impacting 230 million; National Public in 2023, impacting 270 million; and TransUnion in 2025, impacting 4.4 million—cost American consumers $20.9 billion.
"As international criminal syndicates increasingly use scams to target Americans, data brokers shouldn't make it harder for people to protect themselves," Hassan said in a statement. "This report shows the scope of the threat that people face from data broker breaches and underscores the importance of protecting Americans' private data."
She added that "it is encouraging that after we launched our investigation, many companies took steps to improve opt-out options for Americans, which in turn can help more consumers keep their information out of the wrong hands."
As a related webpage from the Electronic Privacy Information Center details: "There is no federal law in the United States that adequately regulates the data broker industry. As a result, private companies invade our private lives, spy on our families, and gather our most intimate facts, on a mass scale, for profit. EPIC supports state and federal legislative efforts that set limits on data brokers’ collection, use, retention, and disclosure of personal data."
In recent years, members of Congress have introduced various legislative proposals aimed at reining in data brokers—including in the Security and Freedom Enhancement (SAFE) Act, introduced on Monday. The bipartisan bill would, among other things, close the so-called "data broker loophole" that, as Sens. Dick Durbin (D-Ill.) and Mike Lee (R-Utah) put it, "intelligence and law enforcement agencies use to buy their way around the Fourth Amendment" to the US Constitution.
There are some limits that have passed, including in Protecting Americans’ Data from Foreign Adversaries Act of 2024. Earlier this month, the Federal Trade Commission sent letters reminding 13 companies of their obligations to comply with the PADFAA, which "prohibits data brokers from selling, licensing, renting, trading, transferring, releasing, disclosing, providing access to, or otherwise making available personally identifiable sensitive data of a United States individual to any foreign adversary country or any entity that is controlled by a foreign adversary."
However, as Lartease Tiffith, an expert at American and George Mason universities, laid out in an article for Just Security last November, while Congress enacted the PADFAA "with the right goal," the law, as written, "could penalize legitimate US companies for routine global operations while failing to deliver the targeted national security tool Congress intended."
This article has been updated to include the announcement and supplement about Findem released on May 15.