The Center for Democracy and Technology has been tracking agencies’ increased sharing with the Department of the Treasury’s Do Not Pay initiative. While CDT appreciates the role played by the Do Not Pay initiative in the effort to reduce improper payments by government agencies, contributing to a centralized collection of sensitive data must be approached with care and caution, particularly against the backdrop of the Trump Administration’s broader efforts to amass and consolidate vast amounts of personal information from a variety of federal and state programs, with little regard for privacy and security protections.
Consequently, CDT urges agencies to protect the personal data with which they have been entrusted by applying robust data minimization practices, enacting strong security protocols, limiting redisclosure, and mitigating data quality issues. Failing to do so may result in vulnerable individuals being wrongly denied critical supports and open them up to harms such as identity theft, as well as putting agencies at risk for legal and reputational harms if its data is used in ways that violate legal frameworks governing the privacy and use of that data, or do not comport with the intended purpose of collection.
To ensure people’s sensitive information is properly stewarded, CDT recommends that agencies sharing with the Do Not Pay initiative establish agreements that Treasury will protect agencies’ data by:
- Employing robust data minimization practices,
- Using strong security protocols,
- Adhering to redisclosure limitations, and
- Following clear processes for matching records across datasets.
Comments to individual agencies can be found below:
Facts Only
* The Center for Democracy and Technology has been tracking agency sharing with the Do Not Pay initiative.
* CDT expressed concern about contributing to a centralized collection of sensitive data.
* CDT urged agencies to protect entrusted personal data by applying robust data minimization practices.
* Agencies must enact strong security protocols.
* Agencies must limit redisclosure of data.
* Agencies must mitigate data quality issues.
* Failing to protect data may result in vulnerable individuals being wrongly denied supports or facing identity theft.
* Data misuse can expose agencies to legal and reputational harms if usage violates privacy laws or intended purposes.
* CDT recommends agencies establish agreements where the Treasury protects data by employing robust data minimization, strong security protocols, redisclosure limitations, and clear record matching processes.
Executive Summary
Full Take
Sentinel — Human
The text reads like a formal public comment or policy position statement, exhibiting the measured, conditional language typical of human advocacy writing rather than pure algorithmic generation.
