U.S. airlines try to hide the fact they sold your flight data to the U.S. Department of Homeland Security.


And pretty much everybody else.


__________________________


Project Counsel Media is a division of Luminative Media. We cover the areas of cyber security, digital technology, legal technology, media, and mobile technology.


About Luminative Media: our intention is to delve deeper into issues, at greater length and with more historical and social context, in order to illuminate pathways of thought that are not possible to pursue through the immediacy of daily media. For more on our vision please click on our logo:


________________


Our partners 404 Media and Wired Magazine have been given access to internal documents at the U.S. Department of Homeland Security (DHS). Some of the documents were obtained through a Freedom of Information request, and others through unnamed sources.


First off, the U.S.'s major airlines own a data broker that collects a massive amount of data about peoples' flights, including names, full addresses, specific flight itineraries, and personal financial information such as credit card numbers. The broker sells it to the government so agencies can look through it without a warrant.


On top of that, the documents shown to our media partners show the airlines telling DHS "it can't reveal where the data came from".


Yes, yes, yes. I know, I know. Data privacy died in the U.S. years ago and no law, no legislation will ever stop the government from getting whatever data it needs, especially in the age of Emperor Trump.


But we thought the following summary from our partners would still be of interest.


_________________


BY:


Angela Delvecchio

Attorney/Avvocato - U.S./Italy

Legal Affairs Reporter



Member of the Project Counsel Media team


__________________


10 June 2025 (Washington, DC) -- A data broker owned by the country’s major airlines, including Delta, American Airlines, and United, has been collecting U.S. travellers’ domestic flight records, selling access to them to Customs and Border Protection (CBP), and then as part of the contract told CBP to not reveal where the data came from, according to internal CBP documents obtained by 404 Media. The data includes passenger names, their full address, full flight itineraries, and financial details including credit card numbers.


CBP, a part of the Department of Homeland Security (DHS), says it needs this data to support state and local police to track "people of interest" across air travel around the country, a purchase that has alarmed civil liberties experts but has resulted ... so far ... in a 🤷‍♀️


The documents reveal for the first time in detail why at least one part of DHS purchased such information, and comes after Immigration and Customs Enforcement (ICE) detailed its own purchase of similar data.


The documents also show for the first time that the data broker, called the Airlines Reporting Corporation (ARC), tells government agencies "not to mention" where it sourced the flight data from.


ARC is owned and operated by at least 8 major U.S. airlines, other publicly released documents show. The company’s board of directors include representatives from Delta, Southwest, United, American Airlines, Alaska Airlines, JetBlue, and European airlines Lufthansa and Air France, and Canada’s Air Canada. More than 240 airlines depend on ARC for ticket settlement services.


ARC’s other lines of business include being the conduit between airlines and travel agencies, finding travel trends in data with other firms like Expedia, and fraud prevention, according to material on ARC’s YouTube channel and website. The sale of U.S. flyers’ travel information to the government is part of ARC’s Travel Intelligence Program (TIP).


A "Statement of Work" included in the newly obtained documents, which describes why an agency is buying a particular tool or capability, says CBP needs access to ARC’s TIP product “to support federal, state, and local law enforcement agencies to identify persons of interest’s U.S. domestic air travel ticketing information”.


The documents obtained by 404 Media also show ARC asking CBP to


“... not publicly identify vendor, or its employees, individually or collectively, as the source of the Reports unless the Customer is compelled to do so by a valid court order or subpoena and gives ARC immediate notice of same".


The "Statement of Work" also says that TIP can show a person’s paid intent to travel and tickets purchased through travel agencies in the U.S. and its territories. The data from the Travel Intelligence Program (TIP) will provide “visibility on a subject’s or person of interest’s domestic air travel ticketing information as well as tickets acquired through travel agencies in the U.S. and its territories,” the documents say. They add this data will be “crucial” in both administrative and criminal cases. 


A DHS Privacy Impact Assessment (PIA) available online says that TIP data is updated daily with the previous day’s ticket sales, and contains more than one billion records spanning 39 months of past and future travel. The document says TIP can be searched by name, credit card, or airline, but ARC contains data from ARC-accredited travel agencies, such as Expedia, and not flights booked directly with an airline:


“If the passenger buys a ticket directly from the airline, then the search done by ICE will not show up in an ARC report. But this information can be purchased through other sources".


The PIA notes the data impacts both U.S. and non-U.S. persons, meaning it does include information on U.S. citizens. Jake Laperruque, deputy director of the Center for Democracy & Technology's Security and Surveillance Project, who saw the documents, said:


“While obtaining domestic airline data - like many other transaction and purchase records - generally doesn't require a warrant, there's still supposed to go through a legal process that ensures independent oversight and limits data collection to records that will support an investigation.


But as we have seen and reported over the last 6-8 years, as with many other types of sensitive and revealing data, the government is intent on using data brokers to buy their way around important guardrails and limits, and those efforts have simply accelerated under Trump's current term".


CBP’s contract with ARC started in June 2024 and will extend to 2029, according to the documents. The CBP contract provides for tens of thousands of dollars in payments to ARC. It was difficult to compute the entire revenue stream but it may go into the millions of dollars.


On May 1st of this year, ICE published details about its own ARC data purchase - somewhat forced by 404 Media's FOIA requests. It would appear ARC’s services have also been purchased by the U.S. Secret Service, the SEC, the DEA, the Air Force, U.S. Marshals Service, TSA, and ATF. 404 Media was able to find all of the contracts by searching U.S. procurement databases.


Airlines contacted by 404 Media declined to comment, didn’t respond, or deferred to either ARC or the DHS instead. ARC declined to comment.


FYI: TIP was established after the Sept. 11 terrorist attacks to provide certain data to law enforcement for the purpose of national security matters and criminal investigations, but appears to have gone far beyond its original mandate. 


ARC has refused to answer oversight questions from Congress. As my boss, Greg Bufithis has said numerous time, "impunity reigns today".


As we have reported numerous time over the last 8+ years, U.S. law enforcement agencies have repeatedly turned to private companies to buy data rather than obtain it through legal processes such as search warrants or subpoenas. That includes location data harvested from smartphones, utility data, and internet backbone data.  


Overall it strikes me as yet another alarming example of how the "Big Data Surveillance Complex" is becoming the digital age version of the "Military-Industrial Complex”. It's clear the data broker loophole is deliberate and has pushed the government back towards a pernicious "collect it all!" mentality, gobbling up as much sensitive data as it can about all Americans by default.


A decade ago the public rejected that approach, and Congress passed surveillance reform legislation that (somewhat) banned domestic bulk collection. But that has died a slow death.


* * * * * * * * * * * * * * * 


For the URL link to this post, please click here


For some of our other recent posts, please click here



* * * * * * * * * * * * * * *