The U.S. Customs and Border Protection’s Office of Professional Responsibility (OPR) shared too much personally identifiable information (PII), putting its mission ahead of protecting sensitive personal data, according to a recent report from the Homeland Security inspector general.
Reviewed in response to a request from Sen. Tom Coburn, the OPR’s collection and storage of sensitive, potentially linkable employee information was not found to violate the Privacy Act of 1974 or Department of Homeland Security policies, but the agency’s sharing methods were questionable and require revision.
Investigating two cases of individuals training in countermeasure techniques for passing polygraph exams, the DHS Office of Inspector General (OIG) found instances where OPR staff didn’t appropriately document, protect or restrict further dissemination of potentially vulnerable information.
In one, the PII of up to 174 individuals was shared with 11 federal agencies.
And in the other, the PII of up to 4,825 individuals was repeatedly shared with 30 agencies.
“We believe the manner in which CBP OPR shared the sensitive PII showed a lack of regard for, and may have compromised these individuals’ privacy,” according to the report. “We attribute this to CBP OPR’s general belief that accomplishing its law enforcement mission takes precedence over its responsibility to protect individuals’ privacy.”
The DHS OIG goes on to recommend that CBP revise its privacy policies and require more specific training for employees, guidance that the CBP OPR says it will address. The agency has 90 days to provide the OIG with a written response that includes a corrective action plan and target completion date for each recommendation.
Read the full report on the OIG’s website.




