{"id":7843,"date":"2014-08-21T09:19:39","date_gmt":"2014-08-21T16:19:39","guid":{"rendered":"http:\/\/papersplease.org\/wp\/?p=7843"},"modified":"2014-09-30T08:11:03","modified_gmt":"2014-09-30T15:11:03","slug":"foia-appeals-reveal-problems-with-pnr-data","status":"publish","type":"post","link":"https:\/\/papersplease.org\/wp\/2014\/08\/21\/foia-appeals-reveal-problems-with-pnr-data\/","title":{"rendered":"FOIA appeals reveal problems with PNR data"},"content":{"rendered":"<p>We&#8217;ve noticed a disturbing pattern in how the DHS, and specifically US Customs and Border Protection (CBP), has responded to people who have <a href=\"http:\/\/hasbrouck.org\/blog\/archives\/001607.html\">asked the DHS for its files<\/a> about themselves.<\/p>\n<p>Eventually &#8212; typically months later than the statutory deadline for responding to a FOIA request &#8212; CBP has sent the requester a file of information about their international travel, including a log of entries, exits, and borders crossings.<\/p>\n<p>But even when the requester has explicitly asked for the <a href=\"http:\/\/hasbrouck.org\/articles\/PNR.html\">Passenger Name Record<\/a> (PNR) data that CBP has obtained from their airline reservations, or has asked CBP for <a href=\"http:\/\/hasbrouck.org\/blog\/archives\/002058.html\">&#8220;all&#8221; its records about their travel<\/a>, or for all data about themselves from the CBP &#8220;Automated Targeting System&#8221; (most of which consist of CBP copies of PNRs), CBP has completely omitted PNR data &#8212; or any mention of it &#8212; from its response.<\/p>\n<p>People who don&#8217;t work in the air travel industry typically don&#8217;t know what PNRs look like. So it isn&#8217;t obvious to most recipients of these incomplete responses that what they&#8217;ve been given doesn&#8217;t include any PNR data. Only when these people showed us copies of the responses they received from CBP have we been able to point out, or confirm, that PNR data was completely absent from the initial CBP response.<\/p>\n<p>When these people have filed administrative appeals, specifically pointing out that their requests included PNR data, CBP has responded to their appeals by sending them redacted copies of CBPs mirror archive of airline PNRs, as contained in ATS.\u00a0 But there&#8217;s been no apology, and explanation in any of these responses to appeals of why the PNR data wasn&#8217;t included in the initial response. It seems likely that CBP didn&#8217;t even bother to search its PNR database in response to the initial requests, either out of gross negligence, gross incompetence, malice, and\/or bad faith. (CBP has refused to disclose how PNR data and other information in ATS is indexed, queried, or retrieved. Even though the Privacy Act requires this information to be published in the Federal Register, the judge hearing our lawsuit <a href=\"http:\/\/papersplease.org\/wp\/2012\/01\/24\/first-rulings-in-our-lawsuit-over-dhs-travel-records\/\">ruled that it was exempt from disclosure<\/a>.)<\/p>\n<p>We&#8217;ve seen this pattern even in responses to requests from journalist and public figures which, <a href=\"http:\/\/papersplease.org\/wp\/2010\/10\/29\/dhs-privacy-office-ordered-tsa-not-to-answer-our-foia-request\/\">according to DHS policy<\/a>, would have been subject to pre-release <a href=\"http:\/\/papersplease.org\/wp\/2010\/07\/30\/dhs-plays-politics-with-foia-requests\/\">review and approval by the DHS &#8220;front office&#8221;<\/a>.\u00a0 The DHS front office has been intimately involved in international disputes related to PNR data, and is fully aware of the existence of this component of DHS dossiers about innocent travelers. So the incomplete responses to FOIA requests can&#8217;t be blamed on low-level staff or a lack of oversight or awareness by senior officials.<\/p>\n<p>One of those high-profile cases was that of Cyrus Farivar, Senior Business Editor at Ars Technica.\u00a0 <a href=\"http:\/\/www.papersplease.org\/wp\/2014\/05\/27\/arstechnica-asks-dhs-for-pnr-data-but-gets-none-of-it\/\">As Mr. Farivar reported earlier this year<\/a>, CBP&#8217;s initial response included no PNR data, even though he specifically included PNR data in his request.\u00a0 After Mr. Farivar appealed, <a href=\"http:\/\/arstechnica.com\/tech-policy\/2014\/07\/ars-editor-learns-feds-have-his-old-ip-addresses-full-credit-card-numbers\/\">CBP gave him the PNR data he had originally requested<\/a>.<\/p>\n<p>There was nothing Mr. Farivar&#8217;s DHS file that we haven&#8217;t seen in other DHS copies of PNRs.\u00a0 But his <a href=\"http:\/\/arstechnica.com\/tech-policy\/2014\/07\/ars-editor-learns-feds-have-his-old-ip-addresses-full-credit-card-numbers\/\">report about what he received<\/a> highlights some of the problems with the contents of these DHS records.<\/p>\n<p><!--more-->Mr. Farivar found that his credit card numbers and other &#8220;sensitive security information&#8221; (using that phrase to refer to threats to individuals&#8217; security, not <a href=\"http:\/\/www.papersplease.org\/wp\/2013\/12\/19\/no-fly-trial-there-are-secrets-and-then-there-are-secrets\/\">the sense in which the TSA uses<\/a> it to hide its misdeeds) were being stored unencrypted in PNRs in airlines&#8217; <a href=\"http:\/\/hasbrouck.org\/articles\/PNR.html#CRS\">computerized reservation systems<\/a> and in the DHS mirror of PNR data:<\/p>\n<blockquote><p><a href=\"http:\/\/info.law.indiana.edu\/faculty-research\/faculty-staff\/profiles\/faculty\/cate-fred-h.shtml\">Fred Cate<\/a>, a law professor at Indiana University, said that my story raises a lot of\u00a0questions about\u00a0what the government is doing.<\/p>\n<p>\u201cWhy isn\u2019t the government complying with even the most basic  cybersecurity standards?\u201d Cate said. \u201cStoring and transmitting credit  card numbers without encryption has been found by the Federal Trade  Commission to be so obviously dangerous as to be \u2018unfair\u2019 to the public.  Why do transportation security officials not comply with even these  most basic standards?\u201d<\/p><\/blockquote>\n<p>Prof. Cate (and Mr. Farivar) could equally have asked why airlines and travel agencies don&#8217;t do so. Both airlines and travel agencies declined to respond to Mr., Farivar&#8217;s request for comment.<\/p>\n<p>Mr. Farivar also received PNR data showing clear violations of the data retention time limits in the <a href=\"https:\/\/www.dhs.gov\/sites\/default\/files\/publications\/privacy\/Reports\/dhsprivacy_PNR%20Agreement_12_14_2011.pdf\">non-binding DHS &#8220;agreement&#8221;\u00a0 with the European Union<\/a> regarding PNR data receieved from the EU:<\/p>\n<blockquote><p>CBP publicly states that PNR data is typically kept for five years  before being moved to \u201cdormant, non-operational status.\u201d But in my case,  my earliest PNR goes back to March 2005. A CBP spokesperson was unable  to explain this discrepancy.<\/p><\/blockquote>\n<p>That the violation of the data-retention provisions of the DHS-EU agreement was so flagrant also casts serious doubt on the <a href=\"http:\/\/papersplease.org\/wp\/2010\/04\/18\/dhs-update-still-misstates-compliance-with-eu-agreement-on-pnr-data\/\">reviews<\/a> that have been conducted of DHS compliance with the agreement. It seems likely that these reviews have been limited to comparing DHS claims of what it has done with the agreement. Even a cursory audit of actual PNR data from the DHS databases would have revealed these breaches of the &#8220;undertakings&#8221; made to the EU by the DHS.<\/p>\n<p>The PNR data disclosed by DHS to Mr. Farivar also included airline and travel agency business-process records including notes on his conversations with customer service call center staff.\u00a0 Julia Angwin, in her recent book <a href=\"http:\/\/juliaangwin.com\/dragnet-nation-available-now\/\">Dragnet Nation<\/a>, expressed <a href=\"http:\/\/hasbrouck.org\/blog\/archives\/002115.html\">similar concern<\/a> about the commingling of government and commercial data in the file of PNR data she obtained from CBP.<\/p>\n<p>That&#8217;s a routine and inevitable consequence of the DHS regulations and orders that require airlines to provide CBP with complete copies of any data that these companies include in PNRs for their own business purposes. ICAO&#8217;s white paper on government access and copying of PNR data, <a href=\"https:\/\/www.iata.org\/iata\/passenger-data-toolkit\/assets\/doc_library\/04-pnr\/New%20Doc%209944%201st%20Edition%20PNR.pdf\">Document 9944<\/a>, explicitly acknowledges that &#8220;Some innformation, such as the internal dialogue or communication between airline staff and reservation agents, may be stored in the PNR, in particular in the &#8216;General remarks&#8217; field. The remarks may include miscellaneous comments and shorthand.&#8221;<\/p>\n<p>PNRs are commercial records, and airlines and travel agencies use the <a href=\"http:\/\/hasbrouck.org\/articles\/PNR.html#CRS\">computerized reservation systems<\/a> in which PNRs are stored as their primary customer relationship management systems.\u00a0 There is little or no consciousness on the part of airlines, travel agencies, their contractors (such as ground handling companies) or their employees of data minimization principles, even though anything they include in a PNR goes directly and irretrievably into the passenger&#8217;s permanent file with the government.<\/p>\n<p>What should you look for in a CBP response to your request for its  file about you? If you&#8217;ve traveled internationally to or from the USA,  the CBP files about you typically contain <a href=\"http:\/\/hasbrouck.org\/blog\/archives\/001607.html#example\">at least two, and sometimes three, distinct types of records<\/a>:  (1) a summary log of entries, exits, and border crossings from the TECS  database, (2) &#8220;secondary inspection&#8221; or other notes recorded by border  inspectors about individual events in this log, also from TECS (these  detail pages aren&#8217;t always created, but can be even if you aren&#8217;t  subjected to secondary screening and nothing seemingly untoward  happens), and (3) copies of airline PNR data for each flight to, from,  or overflying the USA since CBP got access to that airline&#8217;s PNR hosting  system.<\/p>\n<p>Other DHS components may have files about your travels in the <a href=\"http:\/\/www.gpo.gov\/fdsys\/pkg\/FR-2011-07-06\/html\/2011-16807.htm\">DHS mirror copy<\/a> of the Terrorist Screening Database (TSDB) and in the TSA&#8217;s <a href=\"http:\/\/www.gpo.gov\/fdsys\/pkg\/FR-2010-05-19\/html\/2010-11917.htm\">Transportation Security Enforcement Record System<\/a> (TSERS), the latest version of the TSA&#8217;s own supplemental travel  blacklist\/watchlist. But these files are generally exempt form  disclosure under both the Privacy act and FOIA. DHS and TSA will  typically respond to requests for these records &#8212; if the bother to  respond at all, which they often don&#8217;t &#8212; <a href=\"http:\/\/papersplease.org\/wp\/2013\/05\/28\/tsa-glomar-response-to-request-for-terrorist-screening-database-records\/\">with a &#8220;Glomar&#8221; response<\/a> refusing to confirm or deny whether any such records even exist.<\/p>\n<p>If all you receive from CBP or DHS in response to a request for  records about yourself is a TECS log and maybe some secondary inspection  notes or TECS detail pages, and some of your exits or entries from or  to the USA were by air, CBPs response is incomplete, and you should  appeal.\u00a0 Every CBP response to a request like this that we have reviewed  has been incomplete in some way.\u00a0  In most cases, even when people  received some PNR data in an initial  CBP response, CBP has mysteriously  &#8220;found&#8221; more PNRs after they  appealed. So we recommend that you appeal  any initial CBP response, on the assumption (firmly supported by our  experience) that the initial response is likely to be incomplete.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We&#8217;ve noticed a disturbing pattern in how the DHS, and specifically US Customs and Border Protection (CBP), has responded to people who have asked the DHS for its files about themselves. Eventually &#8212; typically months later than the statutory deadline for responding to a FOIA request &#8212; CBP has sent the requester a file of [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2,5],"tags":[],"_links":{"self":[{"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/posts\/7843"}],"collection":[{"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/comments?post=7843"}],"version-history":[{"count":30,"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/posts\/7843\/revisions"}],"predecessor-version":[{"id":7896,"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/posts\/7843\/revisions\/7896"}],"wp:attachment":[{"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/media?parent=7843"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/categories?post=7843"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/papersplease.org\/wp\/wp-json\/wp\/v2\/tags?post=7843"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}