Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Organizations
  • Organizations
    • Agencies Obstructed Review of DOGE’s Adherence to Data Protection Rules, GAO Says
    • Administration’s ‘Secretive’ AI Cyber Testing Program Lacks Teeth, Senators Say
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Citing AI Hacking Incidents, Florida AG Asks Court to Enjoin OpenAI
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Irish Court Decision Clarifies Burden of Proof in GDPR Proceedings
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Newsom Signs Insurance Privacy Law in California
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Retailer Data Protection Guidance Released in New Zealand
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Telco’s ‘Rip-and-Replace’ Funding Plea Should Be Denied, FCC Tells Court
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Two Accreditation Organizations Chosen for FCC’s Cyber Trust Mark Program
    • You have 1 more complimentary views available this month. Log in if you are already a customer
  • Articles
  • Articles
  • Organizations
  • Organizations

    Cybersecurity Policy Report, Agencies Obstructed Review of DOGE’s Adherence to Data Protection Rules, GAO Says, (Sep 29, 2026)

    Organizations Mentioned:Consumer Financial Protection Bureau | Government Accountability Office

    By Tom Leithauser

    Several federal agencies refused to provide information to the Government Accountability Office for a probe into whether personnel from the Department of Government Efficiency (DOGE) adhered to privacy and cybersecurity standards in their work at the ...

    By Tom Leithauser

    Several federal agencies refused to provide information to the Government Accountability Office for a probe into whether personnel from the Department of Government Efficiency (DOGE) adhered to privacy and cybersecurity standards in their work at the agencies, GAO said in a report published today.

    The Consumer Financial Protection Bureau went so far as to accuse GAO of “serving at the behest of a few congressional members to harass and impede the CFPB and its efforts to implement the President’s agenda.”

    “It is the Bureau’s sincere hope that GAO will address CFPB’s concerns and arrest its efforts to produce bias and flawed materials,” CFPB Chief Legal Officer Mark Paoletta, currently the acting director of the agency, told GAO in a letter appended to the report.

    In a separate letter, Victoria Dorfman, CFPB’s general counsel, said GAO’s report “reads as of there was an inherently malicious intent among DOGE staff and their hosting agencies.”

    The Department of Education declined to cooperate with GAO, citing ongoing litigation, while the Securities and Exchange Commission expressed doubt about GAO’s authority to conduct the probe absent a formal request from a congressional committee or chair.

    The National Oceanic and Atmospheric Administration, Small Business Administration, and Department of Veterans Affairs “did not respond to our requests for information needed to determine agency controls for ensuring adherence to the IT security rules and the extent to which DOGE team members followed those rules,” GAO said.

    GAO defended its authority to conduct the audit. “GAO has the authority to carry out this work at each of these agencies in support of Congress and to obtain the requested information. In particular, GAO has ample statutory authority to conduct audit work on the initiative of the Comptroller General under 31 U.S.C. § 717(b)(1),” it said.

    “This authority has long supported work conducted in response to requests from ranking members of congressional committees as recognized over decades by Congress and numerous administrations,” it added.

    “In addition, the concerns raised by CFPB, Education and SEC—including pending litigation and the nature of the information—do not alter or diminish GAO’s statutory right to the requested information. Indeed, GAO has routinely obtained this kind of information from these and other agencies in the past on other cybersecurity audits,” it noted.

    GAO was asked by 17 congressional Democrats, many of them ranking members of committees, to review whether DOGE personnel accessed federal networks carelessly and without proper training or vetting, as alleged in numerous reports from last year (CPR, Sept. 25, 2005).

    The limited cooperation of the agencies under review led GAO to conclude that it couldn’t offer the public or Congress assurances that DOGE personnel properly handled personally identifiable information (PII) or protected agency data from hackers.

    “The security of these agency systems and data is vital to the economy, public confidence, and national security. In addition, many of these systems contain vast amounts of personally identifiable information (PII), thus making it imperative to protect the confidentiality, integrity, and availability of these systems and their data,” it said.

    “Without the ability to examine the requested information,” it added, “Congress and the public lack assurance that these agencies implemented controls needed to ensure DOGE team members appropriately secured information.”

    MainStory: TopStory FederalLegislation DataSecurity DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use