[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_c-31ELUka38A9fIf9vw2Y9zm2h7nhQowGkHR9nHPQQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"2f7ddf53-d178-48bb-b94c-8400f509a54d","ices-mass-dna-collection-raises-serious-data-protection-and-civil-liberties-concerns","036f9417-083d-429e-a037-3352835c3444","ICE's Mass DNA Collection Raises Serious Data Protection and Civil Liberties Concerns","ICE collected DNA from nearly 920,000 individuals in civil immigration custody in 2025, including children, and uploaded these profiles to the FBI's CODIS database—despite the vast majority having no criminal convictions. The root issue is a fundamental failure of data minimization and proportionality principles: sensitive biometric data is being collected at scale without adequate legal justification, consent frameworks, or sunset provisions. Indefinite retention of genetic information from non-criminal populations creates profound privacy risks, including potential misuse, data breaches, and function creep beyond the original stated purpose. This case demonstrates that government agencies with broad operational mandates can exploit gaps in existing data protection law when oversight mechanisms and enforceable privacy standards are weak or absent.","**Immediate policy and oversight actions:**\n- Establish a congressional moratorium on DNA collection from individuals with no criminal charges pending formal legal review.\n- Mandate independent audits of existing CODIS profiles contributed by ICE to assess legal compliance and necessity.\n- Require parental or guardian consent documentation before any biometric data is collected from minors.\n\n**Long-term data governance improvements:**\n- Enact clear statutory limits on biometric data retention periods, with mandatory expungement for non-convicted individuals.\n- Implement data minimization standards that prohibit collection of genetic material unless directly relevant to a specific criminal investigation.\n- Establish an independent privacy oversight board with authority to review and challenge executive agency data collection programs.\n\n**Detection and accountability measures:**\n- Require transparent public reporting on the volume, demographics, and legal basis for all government biometric data collections.\n- Create audit logging of all CODIS database queries linked to ICE-contributed profiles to detect unauthorized or mission-creep access.\n- Mandate privacy impact assessments (PIAs) before any expansion of biometric collection programs affecting vulnerable populations.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"NIST SP 800-188 (De-Identifying Government Datasets)","NIST Privacy Framework PR.DS-1 (Data-at-rest protection)","NIST SP 800-53 AP-1 (Authority to Collect)","NIST SP 800-53 AP-2 (Purpose Specification)","NIST SP 800-53 DI-1 (Data Quality)","NIST SP 800-53 IP-1 (Consent)","GDPR Article 5 (Data Minimization and Purpose Limitation)","GDPR Article 9 (Processing of Special Category Biometric Data)","GDPR Article 17 (Right to Erasure)","CIS Control 3 (Data Protection)","ITIL Service Design — Information Security Management","Privacy Act of 1974 (5 U.S.C. § 552a)","DNA Fingerprint Act of 2005 (review of scope and applicability)","published","2026-08-03T12:21:48.972784+00:00","2026-08-03T12:21:48.895+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.wired.com\u002Fstory\u002Fice-dna-collection-fbi-codis\u002F","ice-collected-nearly-1-million-people-s-dna-last-year-including-young-children-872d72","ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]