ICE Purchasing Credit Card Records from Data Brokers Raises Privacy Concerns
What Happened — Immigration and Customs Enforcement (ICE) has begun buying credit‑card account information from third‑party data brokers. The agency is acquiring the same personal and financial data that consumers provide when opening a credit‑card account, without any public disclosure of a legal basis or consumer consent.
Why It Matters for Compliance & Audit Readiness
- This illustrates a real‑world example of a third‑party data‑sharing relationship that can trigger SOC 2 CC5.5 (Privacy) and GDPR/CCPA obligations.
- Continuous‑compliance programs must be able to evidence lawful basis, consent management, and DSAR (Data Subject Access Request) readiness for any personal data obtained or shared.
- Verisq’s CookiePLUS capability provides the audit‑ready consent logs and DSAR workflow evidence needed to satisfy privacy controls in a SOC 2 audit.
Who Is Affected – Financial services firms, credit‑card issuers, and any organization that collects or shares consumer payment data.
Recommended Actions
- Map the data‑flow from credit‑card onboarding to any third‑party broker and document the lawful basis for processing.
- Verify that consent records are captured, stored, and can be produced on demand for audit or regulator review.
- Test DSAR procedures end‑to‑end, ensuring you can locate, retrieve, and delete or redact data held by brokers.
- Incorporate third‑party monitoring into your continuous‑control framework to detect unauthorized data purchases.
Source: Schneier on Security
Technical Notes – No vulnerability or exploit is disclosed; the risk stems from a privacy‑focused supply‑chain practice (data broker procurement). The activity leverages existing credit‑card data that is already stored by financial institutions and sold on secondary markets. Source: same as above