The US Department of Transportation (DOT) has completed its multi-year examination of data privacy practices at the country’s largest airlines, concluding that it found no violations of applicable laws or departmental policies. The decision means the carriers will avoid financial penalties despite concerns surrounding the handling and sale of access to a database containing approximately 722 million passenger travel records.
The review was launched in March 2024 under then-Transportation Secretary Pete Buttigieg, following growing scrutiny of how airlines, travel agencies, and third-party data processors handled sensitive passenger information. The investigation focused on the practices of the ten largest US airlines and examined allegations that passenger information had been made available to federal agencies through the Airlines Reporting Corporation (ARC).
DOT Finds No Privacy Violations Among Major US Airlines
According to the DOT’s findings, the airlines did not violate applicable laws or departmental policies. That conclusion has nevertheless generated criticism from lawmakers who argued that existing privacy protections were inadequate and that the review failed to address the broader implications of allowing government agencies to obtain extensive passenger information.
The controversy centers partly on the ARC, a major travel-industry data processor jointly owned by several large US airlines, including American Airlines, Delta Air Lines, JetBlue, Southwest Airlines, United Airlines, and Alaska Airlines. Because ARC processes more than $100 billion in US travel agency ticket sales each year, it has access to an enormous amount of commercial airline and passenger transaction data.
722 Million Passenger Records Raised Surveillance Concerns
Previous reporting indicated that ARC provided federal agencies access to a database containing approximately 722 million passenger travel records. Agencies reportedly involved included Customs and Border Protection (CBP), the Department of Homeland Security, and the Internal Revenue Service.
The sensitivity of the issue comes from the breadth of the information involved. Passenger records can include names, itineraries, and transaction-related information, potentially allowing authorities to build detailed pictures of individuals’ travel patterns. Senators also questioned whether such access should have required court oversight or warrants, particularly when the information was obtained outside conventional judicial processes.
The controversy became even more significant because lawmakers warned that extensive travel databases could potentially attract interest from foreign adversaries. Travel information can reveal business relationships, personal associations, movements, and other patterns that extend well beyond the basic purpose of booking an airline ticket.
ARC Travel Intelligence Program Faced Mounting Pressure
The ARC ultimately shut down its Travel Intelligence Program in November 2025, following pressure from privacy advocates and lawmakers. The program’s closure came after increasing concern about how commercial travel information could be used by government agencies and whether passengers had sufficient protections against such access.
Senator Ron Wyden was among the lawmakers criticizing the outcome of the DOT investigation. He argued that simply having privacy policies and employee training should not necessarily be considered sufficient protection when evidence suggests that passenger information may have been improperly accessed or exploited.
The dispute also highlights a difficult gap between what airlines are legally permitted to do and what passengers may reasonably expect when purchasing a ticket. Travelers generally provide information to complete a transaction, but the resulting records can have value far beyond the original booking.
Airlines Escape Fines Despite Continuing Privacy Debate
The DOT’s decision does not settle the larger debate over airline passenger data privacy. Instead, it establishes that the department found no actionable violations under the laws and policies within its review.
For the airlines, the immediate consequence is straightforward: they will avoid financial penalties over the practices examined. For passengers and lawmakers, however, questions remain about whether existing rules adequately protect the enormous amount of information generated every time someone books a flight.
The case demonstrates how modern air travel produces a vast digital trail. With hundreds of millions of records potentially available through commercial data systems, the controversy surrounding ARC shows that passenger privacy is no longer simply an airline customer-service issue. It has become a significant question involving government surveillance, corporate responsibility, data security, and the limits of access to personal travel information.









