Resistance Survival Guide #314
Federal agencies can expand their collection of personal information without announcing the change in plain language. A new question may appear on a familiar form. A revised database may add biometric, location, health, immigration, financial, employment, household, or social media fields. An agency may also purchase access to information that it never collected directly.
These changes are not automatically unlawful or abusive. However, they deserve careful public scrutiny. The most reliable investigation compares multiple records, including forms, information collection requests, privacy notices, technical documentation, data dictionaries, contracts, and records retention schedules.
This Resistance Survival Guide explains how to identify new data fields, document when they appeared, determine why they were added, trace who can access them, and separate confirmed evidence from reasonable inference.
Why Federal Data Collection Changes Matter
A single new field can change the purpose of an entire government system. A program that once collected contact information may begin gathering precise location data. A benefits application may request information about household members who are not applying. An agency database may add fields for risk scores, identity verification results, immigration status, disability, medical history, or online activity.
The greatest privacy risk may not be the collection itself. The risk may come from combining information across databases, purchasing commercial data, expanding routine disclosures, lengthening retention periods, or allowing contractors to analyze the records for a new purpose.
Researchers should therefore ask five questions. What information is being collected? When did the collection begin? What legal authority supports it? Who can receive or access the information? How long can the government retain it?
Understand The Federal Disclosure System
Several different federal records may describe the same collection from different perspectives.
An Information Collection Request explains why an agency wants information from the public. The Reginfo Information Collection Review database contains collections reviewed by the Office of Management and Budget under the Paperwork Reduction Act. Continuing collections generally require renewed approval at least once every three years.
A Privacy Impact Assessment explains how identifiable information is collected, stored, protected, shared, and managed within an information technology system. Section 208 of the E Government Act requires an assessment when an agency develops or procures certain technology involving identifiable information or makes a substantial change to an existing system.
A System of Records Notice describes a federal records system when information is retrieved by a person’s name or another personal identifier. The notice can identify the categories of individuals covered, categories of records, sources of information, routine uses, storage methods, retention practices, and procedures for requesting access.
A records schedule establishes how long records may be retained and whether they must eventually be destroyed or transferred to the National Archives. A contract may reveal the vendor, software, analytical tools, data sources, and technical capabilities involved.
None of these records should be treated as complete on its own. The investigation becomes stronger when several records confirm the same change.
Step by Step Guide
Step One: Define The Collection You Are Investigating
Begin with a specific agency, program, form, database, mobile application, portal, or public service. Record every known name, acronym, form number, system number, OMB control number, contract number, and vendor name.
Create a research log with columns for the document title, agency, publication date, effective date, version number, source link, relevant language, and local filename. Add a separate column for conclusions and label each conclusion as confirmed, probable, possible, or unsupported.
Do not begin with a claim that the agency is secretly building a particular system. Begin with a neutral question, such as whether the categories of information collected by a named program have changed since a particular date.
Step Two: Collect Every Available Version Of The Form
Download the current form, its instructions, appendices, privacy statement, consent language, frequently asked questions, and supporting documents. Search the agency website, the Federal Register, Reginfo, GovInfo, archived agency pages, and public document repositories for earlier versions.
Look for revision dates, form numbers, OMB control numbers, expiration dates, document properties, filenames, and page counts. An unchanged title does not prove that the contents are unchanged.
Compare the versions field by field. Record questions that were added, removed, renamed, divided, combined, or changed from optional to required. Also note changes to checkboxes, upload requirements, identity verification procedures, signature language, consent statements, and warnings about information sharing.
A revised term can conceal a broader category. For example, “contact information” may later include device identifiers or location information. “Identity information” may expand to include facial images or verification scores. Quote the exact language and preserve both versions.
Step Three: Find The Information Collection Request
Search the Reginfo Information Collection Review database by agency, form title, OMB control number, program name, or a distinctive phrase from the form. Review both current and historical entries.
Open the complete Information Collection Request package whenever it is available. Examine the supporting statement, instruments, instructions, burden estimates, public comments, agency responses, legal authority, and any explanation of revisions.
Pay close attention to changes described as revisions, reinstatements, extensions, emergencies, pilots, demonstrations, or nonsubstantive changes. Compare the number of respondents, response frequency, affected population, estimated burden, and requested information.
A dramatic increase in respondents or burden hours may indicate a broader collection. However, burden estimates alone do not prove that additional personal data is being gathered. Confirm the change through the form or supporting documents.
Step Four: Search The Federal Register
Search the Federal Register using the agency name, program title, OMB control number, system name, form number, and several distinctive phrases.
Look for notices announcing proposed information collections, requests for public comment, emergency approvals, new systems of records, modified systems of records, matching programs, exemptions, and final rules.
Read the dates carefully. A notice may have a publication date, comment deadline, approval date, effective date, and later modification date. Build a timeline rather than relying on the date displayed at the top of the page.
When a comment period remains open, document the deadline and submission procedure. Effective public comments identify the specific collection, explain the privacy or civil rights concern, cite the relevant document, and request a precise correction or disclosure.
Step Five: Compare Privacy Impact Assessments
Search the agency website for its privacy office, Privacy Impact Assessment library, or privacy compliance reports. Search by system name, acronym, vendor, program, and technical function.
Compare the current assessment with every earlier version you can locate. Examine the sections describing the information collected, sources, purpose, access controls, information sharing, retention, notice, consent, individual access, and privacy risks.
Look for newly added sources such as commercial databases, state agencies, local law enforcement, social media, mobile devices, financial institutions, health systems, educational institutions, or other federal programs.
Also look for changes in purpose. Data originally collected to process an application may later be used for fraud detection, law enforcement, eligibility scoring, identity resolution, research, analytics, or training an automated system.
A missing or outdated assessment is a research lead, not automatic proof of a violation. Record the date of the latest available assessment and compare it with the dates of contracts, system modifications, and new form versions.
Step Six: Examine Systems Of Records Notices
Use the Federal Register’s Privacy Act notices collection to locate the relevant System of Records Notice.
Compare the current notice with earlier versions. Focus on the categories of individuals, categories of records, sources, purposes, routine uses, storage, retrieval methods, safeguards, retention, disposal, and exemptions.
A modified routine use may allow information to move to another agency, contractor, court, law enforcement body, or outside organization. A new category of individuals may bring witnesses, relatives, household members, associates, employees, applicants, or people merely mentioned in another person’s file into the system.
Do not assume that a routine use proves a disclosure occurred. It establishes an authorized category of disclosure. Evidence that a particular transfer actually happened requires additional records.
Step Seven: Locate Technical Documentation And Data Dictionaries
Search for data dictionaries, interface control documents, schema files, application programming interface documentation, system manuals, technical requirements, procurement attachments, validation rules, database diagrams, training manuals, and user guides.
A data dictionary may reveal fields that never appear on the public form. These can include internal identifiers, risk indicators, confidence scores, match results, status codes, device information, geolocation, referral sources, analyst notes, or links to other databases.
Compare field names, descriptions, permitted values, data types, and whether a field is required. Record any new field and determine whether it represents information supplied by a person, imported from another source, generated by the system, or inferred through analysis.
This distinction matters. A person may never provide a risk score, relationship prediction, or identity confidence value. The government or its contractor may create that information from other records.
Step Eight: Trace Contracts And Vendors
Search USAspending using the agency, program, vendor, system name, and technical terms connected to the collection. Search SAM.gov contract opportunities for solicitations, notices, statements of work, and award information.
Review the original award and every modification. A contract modification may add new data sources, storage capacity, analytical functions, identity tools, cloud services, artificial intelligence, data matching, or information sharing capabilities.
Search procurement documents for terms such as biometric, identity resolution, entity resolution, location intelligence, data enrichment, commercial data, behavioral analytics, risk scoring, facial recognition, link analysis, device identifier, social media, and record matching.
Do not equate a vendor’s advertised capabilities with the work it performed for an agency. The strongest evidence comes from statements of work, task orders, contract modifications, invoices, performance reports, or agency documentation connecting a capability to the specific program.
Step Nine: Check Retention And Disposal Rules
Search the National Archives Records Control Schedules repository by agency, record group, schedule number, program, and system name.
Compare older and newer schedules. Record how the schedule defines the records, when the retention period begins, how long temporary records may be kept, and whether permanent records must be transferred to the National Archives.
A change from short retention to long retention can significantly increase the consequences of collecting sensitive information. So can a trigger that delays the beginning of the retention period until a case closes, an account becomes inactive, or another event occurs.
Remember that agencies may use both agency specific schedules and General Records Schedules. The absence of a system name from an agency schedule does not prove that no retention authority exists.
Step Ten: Build A Change Matrix
Create a table with one row for each suspected change. Use columns for the old form, new form, Information Collection Request, Privacy Impact Assessment, System of Records Notice, data dictionary, contract, and retention schedule.
Write the exact language found in each source. Add publication dates and links. If one document says the system collects location information while another does not mention location information, record the discrepancy without assuming which document is correct.
A strong finding may show that a field appeared on a form, was described in an Information Collection Request, was added to a data dictionary, and was assigned a retention period. A weaker finding may rely only on a procurement document describing a possible capability.
Step Eleven: File Focused Records Requests
If critical documents are missing, submit a narrow Freedom of Information Act request. MuckRock is a nonprofit newsroom and transparency platform that helps the public file and track records requests.
Request identifiable records rather than asking the agency to answer broad questions. Useful targets may include prior form versions, data dictionaries, field definitions, Privacy Impact Assessments, privacy threshold analyses, System of Records Notice review documents, contract attachments, task orders, data sharing agreements, records schedules, change logs, and system release notes.
Provide names, numbers, date ranges, and likely custodians. Ask for records in their original electronic format when metadata or structured data matters. Request a fee waiver when the disclosure would contribute meaningfully to public understanding and explain how you plan to publish the findings.
Avoid requesting personal records about private individuals unless there is a compelling and lawful public interest. Redact sensitive personal information before publishing documents.
Step Twelve: Preserve The Evidence
Save each document with its original filename and record the download date, source address, publication date, and visible version number. Preserve the full file rather than relying only on screenshots.
Create a simple index explaining what each file is and where it came from. Keep an untouched original and a separate working copy for annotation. When possible, calculate a file hash so future researchers can verify that the document was not altered.
Archive public pages responsibly. Do not publish passwords, authentication tokens, personal identifiers, medical details, home addresses, or information that could expose vulnerable people.
Step Thirteen: Verify The Finding Before Publication
Confirm every major conclusion through at least two independent records whenever possible. Contact the agency privacy office, records officer, public affairs office, or program office with precise written questions.
Ask when the field was added, whether it is mandatory, what authority permits its collection, whether the information comes from the individual or another source, who can access it, whether it is shared, and how long it is retained.
Give the agency a reasonable opportunity to respond. Include its answer accurately. If it does not respond, state that clearly without implying that silence confirms the allegation.
Warning Signs That Deserve More Scrutiny
- A new personal data field appears without a corresponding revision to the public privacy notice.
- The current Privacy Impact Assessment predates a major technology contract or system modification.
- A System of Records Notice expands routine uses without clearly explaining the operational change.
- A public form collects fewer details than the associated data dictionary stores.
- A contractor is authorized to enrich agency records with commercial information.
- A collection described as voluntary becomes functionally necessary to receive a service or benefit.
- A pilot program expands nationally while its original privacy documentation remains unchanged.
- Retention shifts from a fixed period to an event that may never occur.
- The agency uses broad terms such as analytics, integrity, identity resolution, or fraud prevention without identifying the data sources or outputs involved.
These signs justify further investigation. None proves misconduct by itself.
How To Report The Findings Responsibly
Lead with the documented change. Identify the exact field, source, date, and system involved. Then explain the possible consequences.
Separate four categories in your reporting: what the documents explicitly establish, what the agency says, what experts believe the change could permit, and what remains unknown.
Avoid claiming that information was shared merely because sharing is authorized. Avoid claiming that a technology was deployed merely because it was purchased. Avoid describing inferred data as directly collected data. These distinctions protect the credibility of the investigation.
When publishing source documents, remove personal information that is not essential to the public interest. Privacy accountability should not create a new privacy injury.
What A Complete Investigation Should Establish
A complete investigation should identify the agency and program, the earlier and current collection, the newly added information, the date of the change, the stated legal authority, the operational purpose, the source of the information, the technology and contractors involved, the authorized recipients, and the retention period.
It should also identify unresolved questions. Federal data systems are complex, and the public record may remain incomplete even after extensive research. A transparent statement of uncertainty is stronger than an unsupported conclusion.
In Conclusion
Hidden changes in federal data collection often become visible only when researchers compare records that were published for different purposes. Forms reveal what people see. Information Collection Requests explain what agencies seek approval to collect. Privacy assessments describe how technology handles identifiable information. Systems of records notices describe covered records and authorized uses. Contracts reveal technical capabilities. Records schedules reveal how long the information may survive.
The goal is not to treat every change as proof of abuse. The goal is to create an accurate, reproducible record of what changed, why it changed, who can use the information, and what protections exist. Careful documentation turns a vague privacy concern into evidence that journalists, advocates, lawmakers, inspectors general, and affected communities can evaluate.
Sources
- Reginfo Information Collection Review
- Reginfo Information Collection Search
- Federal Register Privacy Act Notices
- Department of Justice E Government Act Guidance
- National Archives Records Control Schedules
- National Archives General Records Schedules
- USAspending Federal Award Search
- SAM.gov Contract Opportunities
- MuckRock Government Transparency Tools
