Lawmakers Seek Probe of Warrantless Airline Data Use

WASHINGTON, U.S. - Sen. Ron Wyden and Rep. Shontel Brown want investigators to examine how airline passenger records reached federal agencies without court oversight.

By Bob Vidra 5 min read

Stay current with our airline news coverage.

Buying an airline ticket already requires handing over a tidy bundle of personal and payment information. Now two Democratic lawmakers want Congress’ watchdog to find out why some of those records were allegedly made available to federal agencies without warrants or court oversight.

Sen. Ron Wyden of Oregon and Rep. Shontel Brown of Ohio asked the Government Accountability Office on Wednesday to investigate the Department of Transportation’s handling of airline passenger privacy, according to Reuters.

The lawmakers allege that DOT has not brought a passenger-data privacy enforcement case in more than 40 years, even though the department can treat airlines’ mishandling of private consumer information as an unfair or deceptive practice carrying civil penalties. The GAO confirmed that it received their request.

Airline records allegedly reached DHS and the IRS

The request centers partly on the Airlines Reporting Corporation, or ARC, a data broker collectively owned by major U.S. airlines. Wyden and Brown alleged that ARC sold federal agencies access to a database containing roughly 722 million passenger travel records without warrants or court oversight, Reuters reported.

The alleged federal customers included the Department of Homeland Security and the IRS. ARC ended its government sales of passenger records in November of last year, according to Reuters. That did not necessarily close the book on federal demand for airline data, however. DHS issued a public request this year seeking contractors that could provide a replacement airline passenger surveillance system.

For travelers, that distinction matters. The dispute is not simply about an airline suffering a data breach or mishandling a loyalty account. It concerns records collected through ordinary air travel moving into government-accessible systems without the traditional step of obtaining a warrant.

“US DOT'S abdication of its role as a privacy regulator has left the sensitive personal information of hundreds of millions of Americans exposed to corporate exploitation, warrantless government surveillance, and warrantless seizure of money and other property,” said Ron Wyden, U.S. senator at U.S. Congress, and Shontel Brown, U.S. representative at U.S. Congress, according to Reuters.

Lawmakers question decades of DOT enforcement

DOT’s Office of Aviation Consumer Protection is responsible for investigating possible consumer privacy violations by airlines and ticket agents. Its work has generally focused on other passenger issues, while the department has said it receives relatively few airline privacy complaints and investigates concerns as they arise.

Wyden and Brown consider that reactive approach inadequate for the scale of modern airline data collection and sharing. They described DOT’s record as regulatory neglect and a systemic failure to carry out its consumer privacy responsibilities.

The lawmakers also cited a Congressional Research Service review that found no instance of DOT publicly pursuing an enforcement action or issuing civil penalties over consumer privacy violations involving airline data.

This isn’t the first time questions have surfaced about access to private passenger information. A 2016 Justice Department audit found that the Drug Enforcement Administration paid airline employees millions of dollars for access to some Americans’ private passenger data, Reuters reported.

Those findings add an uncomfortable wrinkle to the usual conversation about airline information. Travelers tend to think about data security in terms of hacked accounts, exposed credit card details or stolen loyalty points. Here, the concern is authorized commercial access and government purchasing, which can be much harder for an individual passenger to see or challenge.

A 2024 airline privacy review produced no public outcome

There has been at least one recent attempt to examine airline data practices. In 2024, then-Transportation Secretary Pete Buttigieg opened a review into how the 10 largest U.S. airlines collected and used passenger information.

According to Reuters, Wyden and Brown said DOT did not publish the airlines’ responses, announce findings or pursue enforcement after that review. From their perspective, the absence of a visible result reinforces the case for an outside examination by GAO.

A watchdog review could identify where DOT’s oversight has fallen short, examine how passenger records move from airlines and travel agencies through data brokers, and help Congress decide whether clearer privacy rules or new legislation are needed. The lawmakers specifically want legislative recommendations that could push DOT toward more active enforcement.

It is important to keep the status of the matter straight. The GAO has received the request, but the supplied information does not establish that the watchdog has completed an investigation or reached conclusions about wrongdoing. The claims involving DOT and ARC remain allegations raised by the lawmakers.

Why airline passengers should pay attention

This story doesn’t call for a frantic change in booking strategy. There’s no evidence here that buying directly from an airline, using a travel agency or skipping a frequent flyer number would prevent records from entering the systems under scrutiny. Pretending there’s a clever consumer workaround would offer false comfort.

The more useful step is to treat airline privacy as a consumer-protection issue, not just a box buried in a website policy. DOT has pointed to the relatively small number of direct privacy complaints it receives. Travelers concerned about the use of their records can document those concerns and submit them to the department rather than assuming someone else already has. A complaint may not unwind past data sharing, but a visible record of consumer concern is harder for a regulator to dismiss.

There’s also a basic accountability problem here. Airlines and travel intermediaries need substantial information to sell and manage tickets; passengers have limited practical ability to avoid providing it if they want to fly. That imbalance makes meaningful oversight more important, not less. When a regulator waits for individual complaints about data transfers that customers may never know occurred, the system starts to feel a little backward.

The requested GAO investigation could bring some welcome daylight to a murky part of air travel. Until then, travelers are left with a familiar and not especially satisfying reality: We can choose our seat, meal and loyalty program, but we may have far less say over where the record of that trip ultimately goes.

More travel news

Keep Exploring

Disney Cruise Lines

Disney Wish Charts a Course Back to New York

NEW YORK, United States - Disney Wish will sail seven New York voyages in fall 2027 as Disney Cruise Line expands across the Caribbean, Panama and Southeast Asia.

4 min read
 United Airlines aircraft on the taxiway at O'Hare International Airport

United Adds 10 New Routes in Record Global Expansion

Newark, United States - United Airlines is making its largest international expansion yet, targeting strong leisure demand with new routes to Europe and Asia.

4 min read
Global Wonders: UNESCO World Heritage Quiz
Quiz

Global Wonders: UNESCO World Heritage Quiz

Ready to flex your UNESCO knowledge? Dive into this 10-question quiz covering wo