Van Hollen Amendment to the Department of Homeland Security (DHS) Authorization Act for Fiscal Year 2008
The U.S. House of Representatives passed the Department of Homeland Security (DHS) Authorization Act for Fiscal Year 2008 (H.R. 1684), which included legislation authored by Congressman Chris Van Hollen (D-MD) that would require the DHS to take all necessary steps and use necessary funds to protect personal information of passengers who submit information online to the TSA's Travelers' Redress Inquiry program. The program was created by DHS in order to allow passengers who erroneously end up on TSA's "No Fly" list or the airport selectee list to begin the process of having their names removed. Van Hollen delivered the following statement upon introducing the legislation:
"In January of this year, the TSA launched a web site. Some of you may have seen it. It was called the Traveler Verification Identification Program, and it was designed to allow those passengers who were wrongfully identified on the no-fly lists or the airport selectee lists the opportunity to start the process of getting their names removed from that list.
"The way you did that was you go and you log onto the TSA web site and submit sensitive security information and personal information, like your Social Security number, the place and date of birth, your driver's license number and other personal identification numbers in order to demonstrate and prove to TSA that you were not a "person of concern'' on their slip. That was an important step forward, a positive list. I think we have all heard the stories about individuals who were wrongfully placed on that list or whose identifications were mistaken for somebody else.
"But right after the launch of that program, they had to shut it down. The TSA had to shut down the site because, as was reported in The Washington Post and the high-tech magazine Wired, it was determined that the information that individuals were entering onto the TSA web site was not secure, very personal types of information. Security experts found that the site lacked many of the basic measures necessary to protect personal information, no encryption devices, no other safeguards, and that the data being transferred to TSA was essentially vulnerable to being taken and used for identity theft and other purposes.
"After these concerns were brought to the attention of TSA, they had to bring down the web site. They put up another web site and program in February called the Travelers' Redress Inquiry Program.
"Now, the TSA has said that it has made the necessary adjustments to protect this very personal and confidential information from exposure and theft, but it is not clear that they have taken all the measures that are necessary, especially in light of the fact that only last week we found out that a hard drive containing the personal data of almost 100,000 TSA employees disappeared.
"Data security does not seem to have been taken seriously enough by the TSA. This amendment is designed to focus greater attention on that issue.
"This amendment is very simple. It requires TSA to take the necessary steps required to protect the personal information submitted online by passengers, by our constituents, when they are seeking to remove their names from the no-fly list, the selectee list or other related lists. It is designed to get at a very specific problem that has arisen in recent months, and I urge its adoption."