After being troubled by delays and budget concerns for nearly a decade, the Homeland Advanced Recognition Technology (HART) program will become the US government’s largest biometric database when it launches in September. The program has also been plagued by privacy concerns raised by the Government Accountability Office (GAO), which has warned that HART has “gaps” in its privacy policies.
HART will be managed by the Department of Homeland Security (DHS) and will store and process biometric data such as digital fingerprints, iris scans, and faceprints that have been gathered by DHS and its various sub-agencies. According to DHS, government agencies may seek to access this data for national security reasons, law enforcement, immigration and border management, intelligence gathering, background investigations for national security positions, and certain positions of public trust.
While HART is set to complete “initial operating capability” in September 2026, the system is not scheduled to be fully completed until 2027. The system was originally announced in 2015 as a replacement for the legacy Automated Biometric Identification System (IDENT), which was originally developed in 1994 as a law enforcement system for collecting and processing biometric data from individuals apprehended by border security or immigration officials. In 2013, the DHS’ Office of Biometric Identity Management (OBIM) began plans to replace IDENT with HART. HART was set to become operational in December 2018 but was delayed numerous times due to budget concerns.
Since the initial announcement regarding the transition from IDENT to HART, the GAO and digital rights groups have raised concerns about the government upgrading and centralizing its repository of sensitive personal information of millions of Americas.
In February 2020, DHS published its original HART Privacy Impact Assessment to “assess and mitigate any potential privacy risks.” While the system wasn’t yet active, DHS said they “anticipated potential privacy risks associated with the privacy sensitive system” and “sought to proactively develop appropriate privacy safeguards to be implemented” throughout HART’s development.
In September 2023, the GAO released their own report detailing what it saw as “gaps” in privacy policies required by the Office of Management and Budget. The GAO said DHS implemented only five of twelve privacy requirements. GAO noted that the 2020 privacy impact assessment was “missing key information,” including on whose data will be stored in the system and the partners with whom the system will share the data.
The GAO report also said the HART program did not have “assurances that partners that provide information to the system will appropriately retain and dispose of personally identifiable information.” GAO concluded by stating that until DHS addressed these “privacy weaknesses,” there is no assurance that the personal data gathered on hundreds of millions of individuals will be “appropriately protected.”
In August 2024, DHS released an updated Privacy Impact Assessment for HART in an attempt to “clarify and address points raised by external oversight bodies.” The assessment provided answers to some of the questions posed by the 2023 GAO report, namely whose information will be stored and with whom it will be shared.
“HART will contain personally identifiable information, including biometric data and associated biographic information, on U.S. citizens, lawful permanent residents, and foreign nationals,” the assessment stated.
The report says biometric data held in HART may be shared with every agency of the DHS, including Customs and Border Protection (CBP), U.S. Immigration and Customs Enforcement (ICE), U.S. Secret Service (USSS), and the Transportation Security Administration (TSA), as well as other federal agencies such as the State Department, the Department of Justice (DOJ), and the Department of Defense (DOD). It also states that biometric data may be shared with “elements of the Intelligence Community (IC).”