House Democrats target ICE, TSA data-sharing in new bill
House Democrats have introduced the "No TSA Data for ICE Act," which—per the Summary—would prohibit TSA from sharing personally identifiable information (PII) of flight passengers with ICE or CBP, bar DHS from purchasing traveler data from private-sector brokers, prohibit use of certain AI-powered…
Cabrillo Club
Editorial Team · August 5, 2026 · 5 min read
Cabrillo Club Insights
House Democrats target ICE, TSA data-sharing in new bill
Also in this intelligence package
Executive Summary
House Democrats have introduced the "No TSA Data for ICE Act," which—per the Summary—would prohibit TSA from sharing personally identifiable information (PII) of flight passengers with ICE or CBP, bar DHS (Department of Homeland Security) from purchasing traveler data from private-sector brokers, prohibit use of certain AI-powered facial recognition tools (example cited: Mobile Fortify), and restrict use of TSA PreCheck and Global Entry data for immigration enforcement purposes. This legislative proposal targets data flows and biometric/identity technologies used by DHS components and could materially change requirements and allowable use-cases for contractors that supply data-sharing systems, biometric surveillance technologies, AI/ML facial-recognition tools, and identity verification services.
Market segments named in the Tags and Summary that are most affected include Biometric Systems, Facial Recognition Technology, Identity Verification, Data Analytics, AI/Machine Learning, Information Sharing Systems, Border Security, and Transportation Security. The change described is significant for product capabilities and contracts that depend on sharing traveler PII or on processing that PII for immigration enforcement. Contractors should pay attention now to assess exposure, pause or re-architect features that enable prohibited sharing, and shape compliance and sales strategies (including positioning on privacy-preserving alternatives and applicable compliance regimes listed in the Tags).
Impact Matrix
Biometric Systems
- Risk Level: High
- Opportunity: Shift toward privacy-preserving biometric designs (on-device matching, de-identified templates) and non-immigration enforcement uses. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Audit biometric data flows to DHS/TSA/CBP/ICE; identify features that enable cross-agency PII sharing; prepare mitigation plans to disable or isolate those features; document alternative use-cases that comply with the legislation as described.
- Competitive Edge: Offer architected separations and attestations demonstrating how biometric systems prevent downstream PII sharing and satisfy Privacy Act / FISMA / NIST 800-53 / FedRAMP (Federal Risk and Authorization Management Program) / DHS 4300A concerns.
Identity Verification
- Risk Level: High
- Opportunity: Provide verification that minimizes PII exposure, verification-as-a-service models that preserve user privacy, and compliance-focused professional services. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Map identity verification data elements against the bill’s prohibitions (passenger PII and PreCheck/Global Entry data); plan product modifications or configurable modes that remove or anonymize prohibited outputs.
- Competitive Edge: Certify and market identity solutions with strong privacy-by-design controls and controls aligned to Privacy Act and listed compliance regimes.
Data Analytics
- Risk Level: High
- Opportunity: Reorient analytics offerings away from traveler-brokered data ingestion and toward anonymized/aggregate analytics or analytics that rely on DHS-approved data sources. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Inventory reliance on third-party traveler data; halt ingestion pipelines that would violate the bill’s prohibition; engage DHS program offices to understand allowable data sources.
- Competitive Edge: Build analytics pipelines that support differential privacy, strong access controls, and FedRAMP-compliant hosting to reassure buyers and transition work away from prohibited data purchases.
AI/Machine Learning
- Risk Level: Medium–High
- Opportunity: Adapt AI/ML models to operate without direct access to enumerated PII or to use synthetic/de-identified training data; offer model governance and compliance tooling. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Assess models that consume traveler PII or provide outputs used by immigration enforcement; prepare retraining or feature-removal plans; document privacy and governance controls.
- Competitive Edge: Provide explainability, model cards, and governance artifacts aligned to NIST/FISMA/FedRAMP expectations to win trust from DHS components seeking compliant AI solutions.
Border Security
- Risk Level: Medium
- Opportunity: Re-scope border security solutions to emphasize customs/immigration workflows that do not depend on TSA passenger PII sharing or commercial brokered data. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Coordinate with program offices to identify which border operations would be affected by restricted access to TSA PreCheck/Global Entry data; update system designs and SOPs accordingly.
- Competitive Edge: Position offerings to integrate lawful, permitted data sources and to document separation of duties between transportation security and immigration-enforcement functions.
Transportation Security
- Risk Level: Medium
- Opportunity: Provide TSA-facing solutions that enhance screening and risk-based security while avoiding outputs usable by immigration enforcement; provide auditability and privacy controls. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Review contracts supporting TSA systems to determine dependency on external data brokers and on sharing PII with ICE/CBP; prepare to implement role-based access and data use restrictions.
- Competitive Edge: Deliver configurable systems that allow TSA to preserve operational security objectives while enforcing strict data governance that prevents cross-use for immigration enforcement.
Information Sharing Systems
- Risk Level: High
- Opportunity: Redesign information-sharing architectures to enforce policy-based access controls, data minimization, and audit trails; pursue work to support segregation of data use per policy. Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Conduct an immediate inventory of information-sharing connectors and interfaces that send passenger PII to ICE/CBP or ingest brokered traveler data; plan technical and contractual changes to stop prohibited flows.
- Competitive Edge: Offer fine-grained access control, attribute-based access, and technical enforcement of legal/contractual data-use constraints mapped to Privacy Act and NIST 800-53 controls.
Facial Recognition Technology
- Risk Level: Critical
- Opportunity: Pivot to non-identifying biometric analytics, on-device verification, or consented/limited-use deployments not covered by the prohibited categories; provide alternatives to systems like the example cited (Mobile Fortify). Specific opportunities TBD pending solicitation language.
- Timeline: Timeline TBD pending source review.
- Action Required: Identify any deployed or proposed facial-recognition capabilities similar to the cited example and prepare plans to disable or redeploy them in ways that avoid the bill’s prohibitions; engage legal and program teams to assess contract compliance risk.
- Competitive Edge: Rapidly certify and demonstrate facial-recognition alternatives that operate in privacy-preserving modes and align with the listed compliance regimes to retain DHS market applicability.
Cross-Segment Implications
- Prohibition on sharing passenger PII with ICE/CBP and ban on purchasing traveler data from private brokers cuts across Information Sharing Systems, Data Analytics, and Identity Verification — forcing architectural changes that will cascade into AI/ML model inputs and biometric system designs.
- Restricting access to TSA PreCheck and Global Entry data for immigration enforcement creates operational separation requirements between Transportation Security and Border Security functions; contractors supporting both sides will need strong role separation and technical enforcement to avoid cross-use.
- A ban on certain AI-powered facial-recognition tools (example cited: Mobile Fortify) directly affects Facial Recognition Technology and Biometric Systems and will require retraining or replacement of models and re-scoping of AI/ML pipelines; this also affects downstream analytics and information-sharing systems that consume biometric match results.
- Compliance and procurement implications: contractors should align product controls and hosting to the compliance surfaces listed in the Tags (Privacy Act, FISMA, NIST 800-53, FedRAMP, DHS 4300A) and evaluate positioning on relevant contract vehicles if pursuing follow-on work.
Stop missing federal opportunities
Signals matches SAM.gov opportunities to your NAICS codes, tracks regulatory changes, and alerts you before competitors.
Start Free Trialor try our free Intelligence Dashboard→

Cabrillo Club
Editorial Team
Cabrillo Club is a defense technology company building AI-powered tools for government contractors. Our editorial team combines deep expertise in CMMC compliance, federal acquisition, and secure AI infrastructure to produce actionable guidance for the defense industrial base.