Is the TSA-ICE Passenger Data Sharing Agreement Legal?
- Authority
- Transportation Security Administration
- Rule type
- regulation
- Jurisdiction scope
- US federal
- Source text
- Read primary rule text ↗
The July 28, 2026 disclosure of a previously undisclosed May 2025 Memorandum of Agreement between TSA and ICE puts a narrow administrative-law question in front of a much larger immigration-enforcement controversy: whether TSA may use the Secure Flight apparatus, built and justified as counter-terrorism passenger screening, to help identify travelers for civil immigration enforcement. American Oversight says it obtained the MOA through FOIA litigation and that the agreement identifies the Secure Flight Final Rule—49 U.S.C. § 114 and 49 C.F.R. part 1560—as TSA’s legal basis for the arrangement.[1]

This Regulation & Ethics analysis is current as of July 30, 2026 and is not legal advice. Several claims remain source-dependent. The MOA text, 49 C.F.R. part 1560, the Secure Flight Privacy Impact Assessment, and any available testimony or docket materials should be checked directly before filing, advising a client, or treating the arrangement as finally characterized. That caution matters because the TSA-ICE passenger data sharing legal issues turn less on whether interagency data sharing is disfavored in the abstract, and more on whether this agency record can carry this use.
The point of entry is not whether ICE may enforce immigration law at airports, or whether TSA may ever cooperate with another agency. The point is narrower: can a rule promulgated to identify known or suspected terrorists authorize a passenger-data arrangement that reportedly helps ICE identify people with removal orders or immigration-status issues, without a rule amendment, a notice-and-comment explanation, or a public privacy update that says so?
The rule’s purpose does real work
Secure Flight is not just a data system with a broad airport-security label. By its own terms, 49 C.F.R. § 1560.1 describes the program’s purpose in counter-terrorism terms: identifying known or suspected terrorists, including through matching against the No Fly and Selectee lists, so TSA can prevent certain persons from boarding aircraft or subject others to enhanced screening. That purpose statement is the hinge. It is the language TSA used to justify collecting passenger information and placing the government, rather than the airlines, at the center of watchlist matching.
If the May 2025 MOA merely allowed TSA to notify ICE after a passenger independently produced a counter-terrorism watchlist match and ICE had a separate operational interest, the legal analysis would look different. The reported arrangement is not described that way. American Oversight’s account says the MOA permits sharing of passenger information with ICE and allows ICE to store passenger information in its own repository; it also says appendices identifying shared data elements remain heavily redacted.[1]
That is where the verbs matter. Secure Flight “screens” passengers to identify known or suspected terrorists. The TSA-ICE arrangement, as described, helps ICE “identify” people for immigration enforcement and may allow ICE to “store” passenger data after TSA’s screening function has done its work. A sworn or public assurance that TSA does not “send” information to ICE would not fully answer the administrative-law problem if the operative document lets ICE retain, access, or place the data in its own repository. The issue is operational control and authorized use, not the courier verb chosen for public testimony.
| Public authority or document | Stated or described function | Why it matters legally |
|---|---|---|
| 49 C.F.R. § 1560.1 | Secure Flight is framed around identifying known or suspected terrorists through passenger screening. | A civil immigration-enforcement lead is not the same statutory purpose unless TSA can point to additional authority or a lawful expansion. |
| May 2025 TSA-ICE MOA, as described by American Oversight | The agreement reportedly permits TSA-ICE sharing and ICE storage of passenger information, with key appendices still redacted.[1] | Retention and repository placement may create a different use from one-time TSA watchlist screening. |
| June 2025 Secure Flight PIA, as characterized in the available materials | The public privacy documentation appears to continue describing Secure Flight in counter-terrorism terms and not to disclose civil immigration-enforcement use. | If direct review confirms that omission, challengers have a record-based argument that the agency did not publicly account for the purpose shift. |
The strongest challenge therefore does not need to begin with the most dramatic arrest. It begins with the regulatory mismatch. TSA built a record for passenger watchlist matching against known or suspected terrorists. The MOA, as reported, uses the same screening machinery to produce or transmit information useful to civil immigration enforcement. If TSA’s cited authority is only Secure Flight, the agency must explain why that purpose statement reaches the ICE use. If it cannot, the agreement is vulnerable as action in excess of statutory authority and as unexplained agency action under the Administrative Procedure Act.
The privacy record may be as important as the MOA
The June 2025 Secure Flight Privacy Impact Assessment matters because it is the public document that should tell travelers, regulated entities, and reviewing courts what the program does with passenger data. Available materials indicate that the PIA continues to describe Secure Flight as counter-terrorism watchlist matching and does not appear to identify ICE civil immigration enforcement as a disclosed use. That point requires direct review of DHS/TSA/PIA-018 and its appendices before it is pleaded as fact, particularly because the underlying PDF materials require direct verification.
If the PIA was updated in June 2025 without disclosing a May 2025 TSA-ICE arrangement already in place, the omission becomes hard to treat as a clerical lag. It would suggest that the public-facing privacy record and the operational agreement moved on separate tracks. That is the kind of gap that supports an arbitrary-and-capricious theory: not because every privacy-document omission automatically voids an interagency agreement, but because an agency that changes a program’s function must supply a reasoned explanation and a record that matches the action taken.
The Privacy Act and E-Government Act issues should not be overstated on the current materials. A final assessment would need the applicable system-of-records notices, routine-use language, the full MOA, the PIA text, and any DHS privacy office analysis. But the available record already identifies a plausible defect: the government appears to have invoked a counter-terrorism passenger-screening authority while allowing data use or retention for a materially different enforcement mission.
Arrests show injury and scale, not illegality by themselves
Reuters reported on April 7, 2026 that ICE had arrested more than 800 people after tips from the U.S. airport security agency. The same investigation described the Angelina Lopez-Jimenez arrest at San Francisco International Airport, reporting that she was not a terrorism watchlist hit and had no criminal conviction.[2]
Those facts do not prove the MOA is unlawful. They do something more limited and more useful in litigation: they show that the arrangement is not hypothetical. If a traveler’s passenger data becomes an enforcement lead without a counter-terrorism watchlist match, the statutory-purpose question stops looking academic. The plaintiff’s theory can be tied to a concrete chain: TSA receives passenger information for Secure Flight screening; the screening or related process identifies an immigration-enforcement interest; ICE receives or retains information; an arrest follows.
That chain still leaves hard questions. Standing, causation, redressability, final agency action, and remedies would need to be pleaded with care. A person arrested at an airport may have an injury, but the challenge would still need to connect that injury to the legal defect in the MOA or TSA’s program administration. The Reuters facts are therefore best used as scale and injury context, not as a substitute for the textual comparison between Secure Flight’s stated purpose and the ICE use.
The transparency problem worsens if testimony and documents do not line up
American Oversight’s July 28 release says Acting TSA Administrator Ha Nguyen McNeill testified under oath in January 2026 that TSA does not “send the information to ICE.” The same release says the MOA allows ICE to store passenger data in its own repository.[1] That apparent conflict should be verified against the full transcript and the MOA text. If verified, it is not a small semantic problem. A court reviewing agency action will care whether the government publicly described the operative arrangement accurately.
A denial framed around whether TSA “sends” information may be technically crafted but still incomplete. If ICE can receive, access, retain, query, or store passenger information under the MOA, the practical consequence for the traveler is not resolved by saying TSA does not send it in a particular manner. Administrative law often turns on just this kind of mismatch between public description and operational authority.
The same caution applies to TSA Administrator nominee David Cummins’s July 2026 confirmation hearing. American Oversight characterizes his testimony as declining to explain the scope of the data-sharing arrangement.[1] A non-answer is not itself unlawful agency action. But in a record already marked by redactions, a purpose mismatch, and disputed verbs, it gives challengers a cleaner arbitrary-and-capricious story: the agency has not publicly reconciled what Secure Flight says it is for with what the MOA reportedly allows ICE to do.
Senators Alex Padilla and Adam Schiff launched an inquiry into TSA-ICE data sharing following the San Francisco airport arrest, adding congressional scrutiny to the regulatory picture.[3] That inquiry is not legal authority and should not be cited as though it establishes a statutory violation. It does, however, signal that the arrangement has become a live oversight risk, which matters for agencies and regulated entities deciding how much reliance to place on the current disclosure record.
What an APA or ultra vires challenge would likely emphasize
An ultra vires theory would likely be the cleanest version of the challenge. It would argue that TSA cannot take a program authorized and justified for counter-terrorism watchlist matching and, by interagency agreement, convert it into a civil immigration-enforcement tool. The question would be whether 49 U.S.C. § 114 and 49 C.F.R. part 1560 give TSA enough room to share or structure passenger screening data for ICE’s civil enforcement objectives. On the current record, that is a colorable mismatch.
The APA claim would overlap but not duplicate it. A challenger would likely argue that TSA acted in excess of statutory authority and acted arbitrarily and capriciously by failing to explain the purpose shift, failing to update public privacy materials, or failing to reconcile the MOA with prior descriptions of Secure Flight. The redacted appendices matter here. If the public cannot see which data elements are shared, how long ICE retains them, or what repository receives them, the agency’s explanation becomes harder to test.
The government would not be without defenses. TSA has broad aviation-security responsibilities, courts often give agencies room in security-adjacent data practices, and the government may argue that the MOA is an internal information-sharing arrangement rather than a rule requiring notice and comment. It may also point to other statutory authorities, system-of-records notices, routine uses, or law-enforcement exceptions that are not fully visible in the current public record. Those defenses are why the claim is vulnerable, not outcome-determinative.
Still, a broad security mission is not the same thing as a blank check to repurpose a specifically justified screening system. The sharper the record shows a move from terrorist-watchlist matching to civil removal-order identification, the more TSA will need a public legal theory that does more than invoke Secure Flight by name.
The IRS-ICE litigation is a roadmap, not a controlling answer
The closest comparison in the available materials is the IRS-ICE data-sharing litigation in Massachusetts. FedScoop reported in February 2026 that a federal judge blocked ICE from using IRS taxpayer data in enforcement, with the dispute centering on the repurposing of data collected for one statutory purpose for immigration enforcement.[4]
That comparison is useful because it gives practitioners a template: identify the purpose for which the data was collected, identify the later enforcement use, and test whether the agency completed the legal work required to bridge the two. It is not controlling on the TSA-ICE MOA. Taxpayer data, aviation-security data, IRS statutes, TSA statutes, Privacy Act notices, and the posture of an injunction are all materially different. Before relying on the Massachusetts precedent, counsel should verify the actual orders and docket materials rather than treating secondary reporting as the operative legal source.
The present litigation posture
As of July 30, 2026, the TSA-ICE MOA appears vulnerable because the authority reportedly cited for it was built around counter-terrorism watchlist matching, while the disclosed use points toward civil immigration enforcement. The best claims are likely to frame the arrangement as agency action in excess of statutory authority, arbitrary and capricious for failure to explain a purpose shift, and potentially defective under privacy-disclosure obligations if the June 2025 PIA did not disclose ICE use.
That is not a prediction that a court will invalidate the agreement. It is a litigation posture: a colorable statutory-purpose mismatch, a public record that appears incomplete, and several source documents requiring direct verification. The first serious filings should turn on the text of the MOA, the precise language of 49 C.F.R. part 1560, the Secure Flight PIA and related privacy notices, the McNeill and Cummins testimony, and any government explanation that attempts to connect civil immigration enforcement to the Secure Flight authority TSA chose to cite.
References
- American Oversight Obtains Previously Undisclosed TSA-ICE Agreement, American Oversight, July 28, 2026.
- ICE arrested more than 800 people after tips from US airport security agency, Reuters, April 7, 2026.
- Padilla, Schiff Launch Inquiry into TSA-ICE Data Sharing Following Alarming Arrest at San Francisco International Airport, Office of Senator Alex Padilla, July 2026.
- Federal judge blocks ICE from using IRS taxpayer data in enforcement, FedScoop, February 2026.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →