"Privacy is about your ability to control what information you are making available to whom for what reason," Bethanne Barnes said.
Terry Gerton I’d like to start with having you explain for us what the Association of Public Data Users is. Who are they? What’s their mission?
Bethanne Barnes The Association of Public Data Users, or APDU for short, is a national network that links users of government data to the producers and the disseminators, the people who get it out into the world, in order to help folks really be informed about what those data are, and what the issues around collection, dissemination, preservation of data so that we’ve got access to it and what accurate interpretation of public data is.
Terry Gerton The Trump administration has made a lot of headlines over the last year in its use and sometimes release of government data. Let’s walk it back a little bit. If an agency is trying to design or redesign a public-facing government service, what’s first privacy question they ought to be thinking about?
Bethanne Barnes Well, the first thing they should be thinking about is, what data do we actually need from the public? What is the minimum amount of data that we need to be collecting in order to achieve this purpose? That’s not just a best-practice principle; it’s actually required by law. And that is important because when we’re talking about privacy, fundamentally, privacy is about your ability to control what information you are making available to whom for what reason.
Terry Gerton As more and more federal programs depend on data and data moving across agencies, from your perspective, then where do the biggest privacy risks show up when information starts to travel beyond the office where it was first collected?
Bethanne Barnes There are a number of different privacy risks that show up, both within the office where the data is collected and in other places. One of the big ones is actually notifying individuals or getting their consent for data to be used in new ways for new purposes by new agencies. And that shows up both in data transfers or data-sharing between agencies, as well as data being released to the public, or even internally within an agency if data is being used for a reason other than for why it was originally collected.
Terry Gerton Walk us through what that might look like in practice. We’re hearing some things about IRS data being shared with loan-making and grant-making agencies, for example. What would the process need to be for something like that?
Bethanne Barnes The first thing that an agency would need to do is look at what legal authorities it has to share those data with the requesting agency. Those authorities could be in a number of places. They could be the original program purpose for why they collected the data. They could have already gotten the consent of the people whose data that they collected to do that, in which case it would be OK. Or they could be looking at one of the many exceptions under the Privacy Act, which are additional legal justifications for why those data could be moving across agencies. In that case, they would still need to make a public record that they have the legal authority and ability to make that disclosure through something called the Systems of Records Notice. So the agency needs to be reviewing all of those sources to determine whether or not they can legally share it. And then depending on what authorities they’re using to move the data from one agency to another, there are a number of potential different requirements that they might need to adhere to in order to actually move those data, like enter into a computer-matching agreement, which is a very specialized kind of document, or a memorandum of understanding or other things. And all of those things need to be very carefully reviewed to make sure that the paperwork is in order, as well as the confines of the data, like they’re correctly identifying which data to be shared, what the security procedures and protections are so that the data can’t be hacked or inadvertently disclosed, and all of the other things that we expect a responsible party to do when they’re governing and taking care of our most sensitive data.
Terry Gerton I’m speaking with Bethanne Barnes. She’s a consultant for the Association of Public Data Users. Bethanne, you’ve just described a very complex architecture requiring people with highly experienced backgrounds to make sure that all of those I’s get dotted and T’s get crossed. But agencies are now experimenting with AI to analyze and route data. So what kind of new privacy risks come with that? Not just technically, but how decisions get made about people.
Bethanne Barnes There are so many new privacy risks that come up associated with the use of artificial intelligence. First, there’s the risk that the data that is already being collected is being run through various AI models to train those models on how they should be interpreting or responding to additional information. That data in some cases has been shown up or redisclosed inadvertently when people are asking questions of the model later on. That’s a really important concern. There’s also, when you’re using and consolidating data from multiple sources into one place, the risk that even if the data that’s included in one data set is not identifiable to the person, when you put together data from multiple different sources, it allows you to re-identify who that person is and maybe where they’re located, maybe what they like for breakfast, a whole number of different things that might be of interest and which you might not anticipate being known.
Terry Gerton You mentioned earlier that the Privacy Act was written in 1974. It doesn’t have anything in it about this AI era that we’re in. What are your biggest concerns right now about coverage and guardrails for data sharing?
Bethanne Barnes The Privacy Act of 1974 is really a foundational privacy law that provides guardrails for when and how the federal government handles and shares personal data. But its rules, and the shortcomings of those rules, are widely misunderstood and are being exploited or twisted right now to treat individuals unfairly. And in some cases, the Privacy Act was really forward-thinking, like it anticipated the use of facial recognition and tried to provide guardrails for it. But it couldn’t anticipate everything right? It’s more than 50 years old. And so now, there are concerns about gaps in what those rules are and how they’re covered. Many folks have concerns about the law enforcement-related exceptions and exemptions that might be enabling surveillance inappropriately. And there’s also a number of concerns about how we can hold the federal government responsible and accountable to making sure that the American people’s rights are protected and actually safeguarded.
Terry Gerton In that environment, the Association of Public Data Users has just put out some new materials to help people understand how these systems actually work. How do they help someone, inside or outside of government, see where their information might go and who might use it?
Bethanne Barnes There’s a series of four different resources. The first one is a primer on the Privacy Act of 1974. You have to know the basic rules before you can start really going into the details of how all of the other pieces work. And in that document, we really made an effort to keep it in plain language, and to highlight some of these negative spaces that you were just referring to in the law, Terry. So for example, if the law says these people are covered, that means these people or not. We also put together a couple of two-page briefs on some of the most commonly misunderstood aspects of the law, like the routine use exception ― read it, find out more. And on mixed systems, which are when the federal government is collecting data on people who are covered by the law and those who are not covered by the law. So how does that happen? And then finally, there’s a longer how-to guide on how to review a Systems of Records Notice, or SORN, which I know sounds like the most boring, bureaucratic thing to read, but I would like to make a pitch. I’m not going to lie, SORNs are pretty bureaucratic. In fact, I frequently call them the worst, most ineffective press release ever invented. But they are very important. They are telling the public what data is being collected about them, how it’s being used and shared, and how you can exercise your rights. And they’re very difficult to read. So we put together a detailed guide to help you go through that.
Terry Gerton Those sound like really helpful and important documents and resources. You’ve got a webinar coming up on April 15th. Is that to help people get a handle on the resources and use them better?
Bethanne Barnes Yes. On April 15th, we’re going to be walking through what these resources are at 2:00. You can register on the APDU website. And we’re planning on following up with some more detailed trainings in case folks want to go more in-depth on any of those topics.
Terry Gerton And give us that website one more time.
Bethanne Barnes Sure, that website is APDU.org.
Copyright © 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Better decisions depend on data, but only if people can actually use it | 0 | 8.89 | 25-06-2026 |
| 2 | What does mission-critical connectivity look like in an era of data-driven government? | 0 | 16.9 | 05-08-2026 |
| 3 | The rise of the splinternet? Data sovereignty risks and responses | 0 | 5.63 | 12-03-2026 |
| 4 | North Carolina rationalizes cyber tools by asking a simple question | 0 | 9.72 | 08-07-2026 |
| 5 | Digital IDs are shaking up how the government verifies identity | 0 | 7.97 | 28-07-2026 |
| 6 | Europäischer Data Act: Nutzer steuern künftig, wer ihre Daten nutzt | 0 | 5 | 09-12-2025 |
| 7 | Греф назвал бессмысленным ограничение доступа к данным | 0 | 0 | 10-11-2018 |
| 8 | Глава МВД заявил о необходимости дополнительных механизмов защиты персональных данных | 0 | 0 | 20-03-2023 |
| 9 | New OMB IT policy memo rings familiar, but signals major shifts | 0 | 8.1 | 08-04-2026 |
| 10 | Four questions to know your data protection competence | 0 | 6.55 | 06-08-2026 |