{"description":"Documents matching '\"data minimization\"'","count":41,"total_pages":3,"next_page_url":"https://www.federalregister.gov/api/v1/documents?conditions%5Bterm%5D=%22data+minimization%22&format=json&page=2","results":[{"title":"Designation of Database to the Do Not Pay Working System","type":"Notice","abstract":null,"document_number":"2025-18680","html_url":"https://www.federalregister.gov/documents/2025/09/26/2025-18680/designation-of-database-to-the-do-not-pay-working-system","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-09-26/pdf/2025-18680.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-18680.pdf?1758804309","publication_date":"2025-09-26","agencies":[{"raw_name":"OFFICE OF MANAGEMENT AND BUDGET","name":"Management and Budget Office","id":280,"url":"https://www.federalregister.gov/agencies/management-and-budget-office","json_url":"https://www.federalregister.gov/api/v1/agencies/280","parent_id":null,"slug":"management-and-budget-office"}],"excerpts":"information about the data involved; the roles of each involved entity; notice and opportunity to respond if a State Public Assistance Agency intends to reduce, suspend, terminate, or deny benefits as a result of information provided by Fiscal Service; and efforts for <span class=\"match\">data \n \n minimization</span>. The section of the notice under the heading “Do Not Pay Working System Privacy, Security, and Legal Implications” discusses privacy-related measures that Treasury reports apply to Do Not Pay, such as rules of behavior, dedicated resources for a privacy program, internal"},{"title":"Waiver of Computer Matching Agreements for Do Not Pay","type":"Notice","abstract":"Under the Do Not Pay statute, the Secretary of the Treasury (Secretary) may waive statutory computer matching requirements, in consultation with the Director of the Office of Management and Budget (OMB), where legally permissible. OMB has issued guidance for agencies which outlines waiver eligibility criteria and specifies conditions agencies must meet to obtain the waiver. On September 3, 2025, the Secretary authorized the issuance of a four-year waivers for eligible agencies engaging in matching programs with the Do Not Pay Initiative.","document_number":"2025-17382","html_url":"https://www.federalregister.gov/documents/2025/09/10/2025-17382/waiver-of-computer-matching-agreements-for-do-not-pay","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-09-10/pdf/2025-17382.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-17382.pdf?1757421914","publication_date":"2025-09-10","agencies":[{"raw_name":"DEPARTMENT OF THE TREASURY","name":"Treasury Department","id":497,"url":"https://www.federalregister.gov/agencies/treasury-department","json_url":"https://www.federalregister.gov/api/v1/agencies/497","parent_id":null,"slug":"treasury-department"},{"raw_name":"BUREAU OF THE FISCAL SERVICE","name":"Bureau of the Fiscal Service","id":196,"url":"https://www.federalregister.gov/agencies/bureau-of-the-fiscal-service","json_url":"https://www.federalregister.gov/api/v1/agencies/196","parent_id":497,"slug":"bureau-of-the-fiscal-service"}],"excerpts":"enter into a matching agreement, which is a written agreement specifying important details about the matching program. This requirement helps to ensure that the matching program is conducted in a manner that ensures accountability, due process, information quality, <span class=\"match\">data minimization</span>, security, and transparency. Congress, however, recognized a need for flexibility in how agencies implement these safeguards for matching programs conducted under Do Not Pay. PIIA states that “[t]he head of the agency operating the [Do Not Pay] Working System may, in"},{"title":"Designation of the Social Security Administration's Numerical Identification System (Numident) Into Do Not Pay","type":"Notice","abstract":"Pursuant to the Payment Integrity Information Act of 2019 (PIIA) (31 U.S.C. 3351 et seq.), the U.S. Department of Treasury (Treasury) operates the Do Not Pay Working System--a centralized portal through which agencies can search multiple databases to verify payment or award eligibility. Treasury, under a delegation from the Director of the Office of Management and Budget (OMB), is authorized to designate new databases for inclusion in the Do Not Pay Working System. Treasury is issuing this Notice of Proposed Designation to provide the public an opportunity to comment on the proposed designation of the Social Security Administration's Numerical Identification System (Numident) to the Do Not Pay Working System.","document_number":"2026-02630","html_url":"https://www.federalregister.gov/documents/2026/02/10/2026-02630/designation-of-the-social-security-administrations-numerical-identification-system-numident-into-do","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-02-10/pdf/2026-02630.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-02630.pdf?1770644719","publication_date":"2026-02-10","agencies":[{"raw_name":"DEPARTMENT OF THE TREASURY","name":"Treasury Department","id":497,"url":"https://www.federalregister.gov/agencies/treasury-department","json_url":"https://www.federalregister.gov/api/v1/agencies/497","parent_id":null,"slug":"treasury-department"}],"excerpts":"response codes indicating whether the submitted data element matches SSA's Numident records. For example, if a submitted SSN is not verified, Numident will not share the correct SSN with the Do Not Pay Working System. Accordingly, the exchange will be governed by strict <span class=\"match\">data minimization</span> principles: only the data necessary for verification is collected, retained for the shortest duration required, and used exclusively for payment integrity purposes. This method strengthens internal controls, supports federal privacy standards, and limits the exposure"},{"title":"Request for Information: Executive Branch Agency Handling of Commercially Available Information Containing Personally Identifiable Information","type":"Notice","abstract":"As part of its implementation of Executive order, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, the Office of Management and Budget (OMB) is requesting public input on issues related to Federal agency collection, processing, maintenance, use, sharing, dissemination, and disposition of commercially available information (CAI) containing personally identifiable information (PII).","document_number":"2024-23773","html_url":"https://www.federalregister.gov/documents/2024/10/16/2024-23773/request-for-information-executive-branch-agency-handling-of-commercially-available-information","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-10-16/pdf/2024-23773.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-23773.pdf?1728996319","publication_date":"2024-10-16","agencies":[{"raw_name":"OFFICE OF MANAGEMENT AND BUDGET","name":"Management and Budget Office","id":280,"url":"https://www.federalregister.gov/agencies/management-and-budget-office","json_url":"https://www.federalregister.gov/api/v1/agencies/280","parent_id":null,"slug":"management-and-budget-office"}],"excerpts":"CAI containing PII also can present privacy risks. For example, factors including the sensitivity and volume of PII contained in some CAI may exacerbate privacy risks and limit the application of key principles that are foundational to agency handling of PII, such as <span class=\"match\">data minimization</span>, transparency, and individual participation. As discussed in OMB Circular A-130, when considering the privacy risks associated with their handling of PII, agencies are responsible for evaluating the sensitivity of the data elements individually and when grouped together"},{"title":"Strengthening and Promoting Innovation in the Nation's Cybersecurity","type":"Presidential Document","abstract":null,"document_number":"2025-01470","html_url":"https://www.federalregister.gov/documents/2025/01/17/2025-01470/strengthening-and-promoting-innovation-in-the-nations-cybersecurity","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-17/pdf/2025-01470.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-01470.pdf?1737054015","publication_date":"2025-01-17","agencies":[{"raw_name":"EXECUTIVE OFFICE OF THE PRESIDENT","name":"Executive Office of the President","id":538,"url":"https://www.federalregister.gov/agencies/executive-office-of-the-president","json_url":"https://www.federalregister.gov/api/v1/agencies/538","parent_id":null,"slug":"executive-office-of-the-president"}],"excerpts":"strongly encourage the acceptance of digital identity documents to access public benefits programs that require identity verification, so long as it is done in a manner that preserves broad program access for vulnerable populations and supports the principles of privacy, <span class=\"match\">data minimization</span>, and interoperability.\n \n (i) Within 90 days of the date of this order, agencies with grantmaking authority are encouraged to consider, in coordination with OMB and the National Security Council staff, whether Federal grant funding is available to assist States in developing"},{"title":"Children's Online Privacy Protection Rule","type":"Rule","abstract":"The Federal Trade Commission amends the Children's Online Privacy Protection Rule (the \"Rule\"), consistent with the requirements of the Children's Online Privacy Protection Act. The amendments to the Rule, which are based on the FTC's review of public comments and its enforcement experience, include one new definition and modifications to several others, as well as updates to key provisions to respond to changes in technology and online practices. The amendments are intended to strengthen protection of personal information collected from children, and, where appropriate, to clarify and streamline the Rule since it was last amended in January 2013.","document_number":"2025-05904","html_url":"https://www.federalregister.gov/documents/2025/04/22/2025-05904/childrens-online-privacy-protection-rule","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-04-22/pdf/2025-05904.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-05904.pdf?1745239507","publication_date":"2025-04-22","agencies":[{"raw_name":"FEDERAL TRADE COMMISSION","name":"Federal Trade Commission","id":192,"url":"https://www.federalregister.gov/agencies/federal-trade-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/192","parent_id":null,"slug":"federal-trade-commission"}],"excerpts":"support for the Commission's proposed revisions to § 312.10.\n 577 \n \n The Center for Democracy and Technology, for example, stated that the proposed “additions to § 312.10 better emphasize operators' <span class=\"match\">data minimization</span> responsibilities.” \n 578 \n \n Consumer Reports similarly stated that the proposed revisions would both “ensure that the <span class=\"match\">data minimization</span> protections contemplated in § 312.7 extend beyond the collection phase so that operators may not use [children's] personal information for unexpected secondary purposes, like profiling or third-party"},{"title":"Notice of Availability of Security Requirements for Restricted Transactions Under Executive Order 14117","type":"Notice","abstract":"CISA is announcing publication of finalized security requirements for restricted transactions pursuant to Executive Order (E.O.) 14117, \"Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.\" In October 2024, CISA published proposed security requirements for restricted transactions which would apply to classes of restricted transactions identified in regulations issued by the Department of Justice (DOJ). CISA solicited comment on those proposed security requirements and considered that public feedback when developing the final security requirements. This notice also provides CISA's responses to the public comments received.","document_number":"2024-31479","html_url":"https://www.federalregister.gov/documents/2025/01/08/2024-31479/notice-of-availability-of-security-requirements-for-restricted-transactions-under-executive-order","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-08/pdf/2024-31479.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-31479.pdf?1735911917","publication_date":"2025-01-08","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"covered persons or countries of concern arguably takes the transaction out of the DOJ rule's definition of restricted transaction altogether.\n 25 \n \n Commenters noted, however, that CISA's security requirements were developed to suggest the efficacy of controls such as <span class=\"match\">data minimization</span>, masking, and privacy-enhancing techniques in mitigating the \n \n risk of access to covered data by covered persons or countries of concerns.\n \n \n \n 23 \n  \n See, e.g., \n Comment submitted by U.S. Chamber of Commerce, CISA-2024-0029-0017; Comment submitted by the Consumer"},{"title":"National Security Division; Provisions Regarding Access to Americans' Bulk Sensitive Personal Data and Government-Related Data by Countries of Concern","type":"Proposed Rule","abstract":"The Executive order of February 28, 2024, \"Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern\" (the Order), directs the Attorney General to issue regulations that prohibit or otherwise restrict United States persons from engaging in any acquisition, holding, use, transfer, transportation, or exportation of, or dealing in, any property in which a foreign country or national thereof has any interest (\"transaction\"), where the transaction: involves U.S. Government-related data or bulk U.S. sensitive personal data, as defined by final rules implementing the Order; falls within a class of transactions that has been determined by the Attorney General to pose an unacceptable risk to the national security of the United States because it may enable access by countries of concern or covered persons to Americans' bulk sensitive personal data or U.S. government-related data; and meets other criteria specified by the Order. This advance notice of proposed rulemaking (ANPRM) seeks public comment on various topics related to the implementation of the Order.","document_number":"2024-04594","html_url":"https://www.federalregister.gov/documents/2024/03/05/2024-04594/national-security-division-provisions-regarding-access-to-americans-bulk-sensitive-personal-data-and","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-03-05/pdf/2024-04594.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-04594.pdf?1709559927","publication_date":"2024-03-05","agencies":[{"raw_name":"DEPARTMENT OF JUSTICE","name":"Justice Department","id":268,"url":"https://www.federalregister.gov/agencies/justice-department","json_url":"https://www.federalregister.gov/api/v1/agencies/268","parent_id":null,"slug":"justice-department"}],"excerpts":"sensitive personal data or government-related data by countries of concern. As previewed in this ANPRM, the security requirements could include (1) organizational requirements (\n e.g., \n basic organizational cybersecurity posture), (2) transaction requirements (\n e.g., \n <span class=\"match\">data minimization</span> and masking, use of privacy-preserving technologies, requirements for information-technology systems to prevent unauthorized disclosure, and logical and physical access controls), and (3) compliance requirements (\n e.g., \n audits).\n 10 \n \n \n \n \n 10 \n  The Order contains"},{"title":"Drizly, LLC; Analysis of Proposed Consent Order To Aid Public Comment","type":"Notice","abstract":"The consent agreement in this matter settles alleged violations of federal law prohibiting unfair or deceptive acts or practices. The attached Analysis of Proposed Consent Order to Aid Public Comment describes both the allegations in the draft complaint and the terms of the consent order--embodied in the consent agreement-- that would settle these allegations.","document_number":"2022-23669","html_url":"https://www.federalregister.gov/documents/2022/11/01/2022-23669/drizly-llc-analysis-of-proposed-consent-order-to-aid-public-comment","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2022-11-01/pdf/2022-23669.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2022-23669.pdf?1667220320","publication_date":"2022-11-01","agencies":[{"raw_name":"FEDERAL TRADE COMMISSION","name":"Federal Trade Commission","id":192,"url":"https://www.federalregister.gov/agencies/federal-trade-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/192","parent_id":null,"slug":"federal-trade-commission"}],"excerpts":"and use of their information based on the service they've actually requested. I believe the agency is in a better position to effectuate this expectation than it is to anticipate, understand, and police every claim of reasonable business necessity. A consumer centered <span class=\"match\">data minimization</span> standard could work hand-in-hand with the kinds of disclosures and effective data security practices in this proposed order to protect Americans from the ongoing epidemic of data breaches, which are greatly exacerbated by overcollection of consumer information. \n I am"},{"title":"Provisions Pertaining to Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons","type":"Proposed Rule","abstract":"The Department of Justice proposes a rule to implement Executive Order 14117 of February 28, 2024 (Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government- Related Data by Countries of Concern), by prohibiting and restricting certain data transactions with certain countries or persons.","document_number":"2024-24582","html_url":"https://www.federalregister.gov/documents/2024/10/29/2024-24582/provisions-pertaining-to-preventing-access-to-us-sensitive-personal-data-and-government-related-data","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-10-29/pdf/2024-24582.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-24582.pdf?1729628118","publication_date":"2024-10-29","agencies":[{"raw_name":"DEPARTMENT OF JUSTICE","name":"Justice Department","id":268,"url":"https://www.federalregister.gov/agencies/justice-department","json_url":"https://www.federalregister.gov/api/v1/agencies/268","parent_id":null,"slug":"justice-department"}],"excerpts":"gov/2023/Mar/21/2003183448/-1/-1/0/ESF%20identity%20and%20access%20management%20recommended%20best%20practices%20for%20administrators%20pp-23-0248_508c.pdf \n [\n https://perma.cc/B7VP-4RWF \n ]; Mohammed Khan, \n <span class=\"match\">Data Minimization</span>—A Practical Approach, \n ISACA (Mar. 29, 2021), \n https://www.isaca.org/resources/news-and-trends/industry-news/2021/<span class=\"match\">data-minimization</span>-a-practical-approach \n [\n https://perma.cc/8APH-5E5A \n ]; Cybersec. &amp; Infrastructure Sec. Agency, \n Protecting Sensitive and Personal Information From Ransomware-Caused Data Breaches \n (n.d.), \n https://www"},{"title":"Ballot Mail for Federal Elections","type":"Rule","abstract":"The Postal Service is amending the Mailing Standards of the United States Postal Service, Domestic Mail Manual, regarding the transmission of mail-in or absentee ballots for federal elections pursuant to its rulemaking authority.","document_number":"2026-17238","html_url":"https://www.federalregister.gov/documents/2026/08/26/2026-17238/ballot-mail-for-federal-elections","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2026-08-26/pdf/2026-17238.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2026-17238.pdf?1787360408","publication_date":"2026-08-26","agencies":[{"raw_name":"POSTAL SERVICE","name":"Postal Service","id":410,"url":"https://www.federalregister.gov/agencies/postal-service","json_url":"https://www.federalregister.gov/api/v1/agencies/410","parent_id":null,"slug":"postal-service"}],"excerpts":"the Postal Service should evaluate less restrictive alternatives. For example commenters suggested: voluntary pilot programs, phased implementation after the 2026 election cycle or a capacity-adjusted implementation timeline, aggregate or post-mailing reconciliation, <span class=\"match\">data minimization</span>, hashed or non-voter-identifying records, safe harbors for minor or correctable defects, mandatory acceptance during Portal outages, \n \n making the data entry standards optional, and emergency escalation procedures for replacement ballots, late-added voters, court-ordered"},{"title":"Trade Regulation Rule on Commercial Surveillance and Data Security","type":"Proposed Rule","abstract":"The Federal Trade Commission (\"FTC\") is publishing this advance notice of proposed rulemaking (\"ANPR\") to request public comment on the prevalence of commercial surveillance and data security practices that harm consumers. Specifically, the Commission invites comment on whether it should implement new trade regulation rules or other regulatory alternatives concerning the ways in which companies collect, aggregate, protect, use, analyze, and retain consumer data, as well as transfer, share, sell, or otherwise monetize that data in ways that are unfair or deceptive.","document_number":"2022-17752","html_url":"https://www.federalregister.gov/documents/2022/08/22/2022-17752/trade-regulation-rule-on-commercial-surveillance-and-data-security","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2022-08-22/pdf/2022-17752.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2022-17752.pdf?1660913118","publication_date":"2022-08-22","agencies":[{"raw_name":"FEDERAL TRADE COMMISSION","name":"Federal Trade Commission","id":192,"url":"https://www.federalregister.gov/agencies/federal-trade-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/192","parent_id":null,"slug":"federal-trade-commission"}],"excerpts":"data security? \n 48. To what extent would <span class=\"match\">data minimization</span> requirements or purpose limitations unduly hamper algorithmic decision-making or other algorithmic learning-based processes or techniques? To what extent would the benefits of a <span class=\"match\">data minimization</span> or purpose limitation rule be out of proportion to the potential harms to consumers and companies of such a rule? \n 49. How administrable are <span class=\"match\">data minimization</span> requirements or purpose limitations given the scale of commercial surveillance practices, information asymmetries, and the institutional resources"},{"title":"Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons","type":"Rule","abstract":"The Department of Justice is issuing a final rule to implement Executive Order 14117 of February 28, 2024 (Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government- Related Data by Countries of Concern), by prohibiting and restricting certain data transactions with certain countries or persons.","document_number":"2024-31486","html_url":"https://www.federalregister.gov/documents/2025/01/08/2024-31486/preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-01-08/pdf/2024-31486.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-31486.pdf?1735911918","publication_date":"2025-01-08","agencies":[{"raw_name":"DEPARTMENT OF JUSTICE","name":"Justice Department","id":268,"url":"https://www.federalregister.gov/agencies/justice-department","json_url":"https://www.federalregister.gov/api/v1/agencies/268","parent_id":null,"slug":"justice-department"}],"excerpts":"post-quantum cryptography algorithms approved by the National Institute of Standards and Technology (“NIST”) to withstand quantum computer attacks. A few commenters opposed the inclusion of encrypted data based on the proposed CISA security requirements relating to <span class=\"match\">data minimization</span> and data masking strategies for restricted transactions. One commenter noted that the inclusion of encrypted data does not represent a carefully calibrated action and would curtail the usefulness of privacy-enhancing technologies (even though some of these were explicitly"},{"title":"Health Breach Notification Rule","type":"Rule","abstract":"The Federal Trade Commission (\"FTC\" or \"Commission\") is amending the Commission's Health Breach Notification Rule (the \"HBN Rule\" or the \"Rule\"). The HBN Rule requires vendors of personal health records (\"PHRs\") and related entities that are not covered by the Health Insurance Portability and Accountability Act (\"HIPAA\") to notify individuals, the FTC, and, in some cases, the media of a breach of unsecured personally identifiable health data.","document_number":"2024-10855","html_url":"https://www.federalregister.gov/documents/2024/05/30/2024-10855/health-breach-notification-rule","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-05-30/pdf/2024-10855.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-10855.pdf?1716986712","publication_date":"2024-05-30","agencies":[{"raw_name":"FEDERAL TRADE COMMISSION","name":"Federal Trade Commission","id":192,"url":"https://www.federalregister.gov/agencies/federal-trade-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/192","parent_id":null,"slug":"federal-trade-commission"}],"excerpts":"protect the safety or vital interests of an individual or react to a public health emergency; or to protect themselves against security incidents and fraud. In each of these situations, data protection laws typically invoke a variety of non-consent measures, including <span class=\"match\">data minimization</span>, transparency, notice to the end-user or the regulator, and opportunities to object.”); Chamber at 7.\n \n \n \n \n 168 \n  Confidentiality Coal. at 4-5; SIIA at 4; CHI at 7.\n \n \n \n \n 169 \n  CTA at 17.\n \n \n 3. The Commission Adopts the Proposed Changes to the Definition of"},{"title":"Children's Online Privacy Protection Rule","type":"Proposed Rule","abstract":"The Commission proposes to amend the Children's Online Privacy Protection Rule, consistent with the requirements of the Children's Online Privacy Protection Act. The proposed modifications are intended to respond to changes in technology and online practices, and where appropriate, to clarify and streamline the Rule. The proposed modifications, which are based on the FTC's review of public comments and its enforcement experience, are intended to clarify the scope of the Rule and/or strengthen its protection of personal information collected from children.","document_number":"2023-28569","html_url":"https://www.federalregister.gov/documents/2024/01/11/2023-28569/childrens-online-privacy-protection-rule","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-01-11/pdf/2023-28569.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-28569.pdf?1704903070","publication_date":"2024-01-11","agencies":[{"raw_name":"FEDERAL TRADE COMMISSION","name":"Federal Trade Commission","id":192,"url":"https://www.federalregister.gov/agencies/federal-trade-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/192","parent_id":null,"slug":"federal-trade-commission"}],"excerpts":"parents. For example, commenters expressed concern that requiring operators to obtain parental consent would require operators to collect additional personal information from parents, much of which is not necessary to provide the educational service, which contradicts <span class=\"match\">data minimization</span> principles.\n 236 \n \n One commenter argued that requiring parents to consent would lead to “consent fatigue,” \n 237 \n \n while another commenter explained that operators often do not have a direct touchpoint with parents that could facilitate the consent process.\n 238"},{"title":"Addressing the Homework Gap Through the E-Rate Program","type":"Proposed Rule","abstract":"In this document, the Federal Communications Commission (Commission) initiates a proceeding to address the ongoing remote learning needs of today's students, school staff, and library patrons through the E-Rate program and to ensure the millions who have benefitted from the Emergency Connectivity Fund program support do not fall back onto the wrong side of the digital divide once the program ends.","document_number":"2023-26033","html_url":"https://www.federalregister.gov/documents/2023/12/07/2023-26033/addressing-the-homework-gap-through-the-e-rate-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-12-07/pdf/2023-26033.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-26033.pdf?1701870318","publication_date":"2023-12-07","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"such surveys would be intended to elicit information from potentially lower-income children, families, and individuals)? If this requirement would create privacy risks for students, families, and patrons, how could the Commission mitigate those risks (\n e.g., \n via <span class=\"match\">data minimization</span>, anonymization, or deidentification)? For example, would it be possible for schools and libraries to conduct such surveys without collecting any personally identifiable information (PII) from \n \n students, staff, or patrons, and what burdens would such a collection place"},{"title":"Privacy, Equity, and Civil Rights Request for Comment","type":"Notice","abstract":"The National Telecommunications and Information Administration (NTIA) requests comments addressing issues at the intersection of privacy, equity, and civil rights. The comments, along with information gathered through the three listening sessions that NTIA held on this topic, will inform a report on whether and how commercial data practices can lead to disparate impacts and outcomes for marginalized or disadvantaged communities.","document_number":"2023-01088","html_url":"https://www.federalregister.gov/documents/2023/01/20/2023-01088/privacy-equity-and-civil-rights-request-for-comment","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-01-20/pdf/2023-01088.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-01088.pdf?1674135928","publication_date":"2023-01-20","agencies":[{"raw_name":"DEPARTMENT OF COMMERCE","name":"Commerce Department","id":54,"url":"https://www.federalregister.gov/agencies/commerce-department","json_url":"https://www.federalregister.gov/api/v1/agencies/54","parent_id":null,"slug":"commerce-department"},{"raw_name":"National Telecommunications and Information Administration","name":"National Telecommunications and Information Administration","id":373,"url":"https://www.federalregister.gov/agencies/national-telecommunications-and-information-administration","json_url":"https://www.federalregister.gov/api/v1/agencies/373","parent_id":54,"slug":"national-telecommunications-and-information-administration"}],"excerpts":"c. What kinds of protections might be appropriate to protect older adults from exploitative uses of their data? \n d. In considering equity-focused approaches to privacy reforms, how should legislators, regulators, and other stakeholders approach purpose limitations, <span class=\"match\">data minimization</span>, and data retention and deletion practices? \n e. Considering resources, strategic prioritization, legal capacities and constraints, and other factors, what can federal agencies currently do to better address harmful data collection and practices, particularly the impact"},{"title":"Required Rulemaking on Personal Financial Data Rights","type":"Rule","abstract":"The Consumer Financial Protection Bureau (CFPB) is issuing a final rule to carry out the personal financial data rights established by the Consumer Financial Protection Act of 2010 (CFPA). The final rule requires banks, credit unions, and other financial service providers to make consumers' data available upon request to consumers and authorized third parties in a secure and reliable manner; defines obligations for third parties accessing consumers' data, including important privacy protections; and promotes fair, open, and inclusive industry standards.","document_number":"2024-25079","html_url":"https://www.federalregister.gov/documents/2024/11/18/2024-25079/required-rulemaking-on-personal-financial-data-rights","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-11-18/pdf/2024-25079.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-25079.pdf?1731678320","publication_date":"2024-11-18","agencies":[{"raw_name":"Consumer Financial Protection Bureau","name":"Consumer Financial Protection Bureau","id":573,"url":"https://www.federalregister.gov/agencies/consumer-financial-protection-bureau","json_url":"https://www.federalregister.gov/api/v1/agencies/573","parent_id":null,"slug":"consumer-financial-protection-bureau"}],"excerpts":"interfaces.\n \n Data provider fees are not the appropriate means by which third parties' <span class=\"match\">data minimization</span> is incentivized and accomplished. Instead, third parties themselves must and should comply with part 1033's <span class=\"match\">data minimization</span> requirements. Section 1033.311(d) (discussed below) permits data providers to impose reasonable access caps, further undermining the appropriateness of permitting data providers to charge fees to third parties in order to achieve <span class=\"match\">data minimization</span> or, more broadly, to incentivize third parties to comply with part 1033. \n By its"},{"title":"Collection of Biometric Data From Aliens Upon Entry to and Departure From the United States","type":"Rule","abstract":"This final rule amends Department of Homeland Security (DHS) regulations to provide that DHS may require all aliens to be photographed when entering or exiting the United States, and may require non-exempt aliens to provide other biometrics. The final rule also amends the regulations to remove the references to pilot programs and the port limitation to permit collection of biometrics from aliens departing from airports, land ports, seaports, or any other authorized point of departure. In addition, DHS is requesting comments on the specific collection process as well as costs and benefits for new transportation modalities.","document_number":"2025-19655","html_url":"https://www.federalregister.gov/documents/2025/10/27/2025-19655/collection-of-biometric-data-from-aliens-upon-entry-to-and-departure-from-the-united-states","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2025-10-27/pdf/2025-19655.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2025-19655.pdf?1761309905","publication_date":"2025-10-27","agencies":[{"raw_name":"DEPARTMENT OF HOMELAND SECURITY","name":"Homeland Security Department","id":227,"url":"https://www.federalregister.gov/agencies/homeland-security-department","json_url":"https://www.federalregister.gov/api/v1/agencies/227","parent_id":null,"slug":"homeland-security-department"}],"excerpts":"assessment, align with Executive Order 14028, “Improving the Nation's Cybersecurity,” 86 FR 26633 (May 17, 2021), which highlights the need to strengthen collaboration between the private sector and the Federal Government.\n \n \n Furthermore, CBP is taking steps to promote <span class=\"match\">data minimization</span> and privacy protections by using an airline-generated alphanumeric unique ID (UID) to disassociate the biographic information associated with the new facial images. As CBP verifies the identity of the traveler, either through the automated TVS facial comparison process"},{"title":"Location-Based Routing for Wireless 911 Calls","type":"Rule","abstract":"The Federal Communications Commission (the FCC or Commission) adopted a Report and Order in PS Docket No. 18-64, FCC 24-4, on January 25, 2024, and released on January 26, 2024. This document is a summary of the Commission's Report and Order. The Report and Order adopted rules to more precisely route wireless 911 calls and Real-Time Texts (RTT) to Public Safety Answering Points (PSAPs), which can result in faster response times during emergencies. Wireless 911 calls have historically been routed to PSAPs based on the location of the cell tower that handles the call. Sometimes, however, the 911 call is routed to the wrong PSAP because the cell tower is not in the same jurisdiction as the 911 caller. This can happen, for instance, when an emergency call is placed near a county border. These misrouted 911 calls must be transferred from one PSAP to another, which consumes time and resources and can cause confusion and delay in emergency response. The Report and Order requires wireless providers to deploy technology that supports location-based routing, a method that relies on precise information about the location of the wireless caller's device, on their internet Protocol (IP)-based networks and to use location-based routing to route 911 voice calls and RTT communications to 911 originating on those networks when caller location is accurate and timely. The Report and Order provides six months for nationwide wireless providers to implement location-based routing for wireless 911 voice calls and provides 24 months for non-nationwide wireless providers to implement location-based routing of wireless 911 voice calls. The Report and Order provides 24 months for all wireless providers to implement location-based routing for RTT communications to 911.","document_number":"2024-03157","html_url":"https://www.federalregister.gov/documents/2024/03/13/2024-03157/location-based-routing-for-wireless-911-calls","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-03-13/pdf/2024-03157.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-03157.pdf?1709932520","publication_date":"2024-03-13","agencies":[{"raw_name":"FEDERAL COMMUNICATIONS COMMISSION","name":"Federal Communications Commission","id":161,"url":"https://www.federalregister.gov/agencies/federal-communications-commission","json_url":"https://www.federalregister.gov/api/v1/agencies/161","parent_id":null,"slug":"federal-communications-commission"}],"excerpts":"regulatory authority. We also decline EPIC's request to require CMRS and covered text providers to delete location data as outside the scope of this proceeding, as the notice of proposed rulemaking did not propose or seek comment on requirements for <span class=\"match\">data minimization</span>. We recognize <span class=\"match\">data minimization</span> as an important tool to protect the privacy and security of customers' information, and we encourage providers not to retain 911 location routing data longer than is necessary to fulfill the 911 purpose of the data or comply with applicable law. \n \n 105"}]}