Federal Oversight Reveals Vulnerabilities in Transportation Data

A September 30, 2026, audit by the Office of Inspector General (OIG) has highlighted a paradox within the U.S. Department of Transportation (DOT). While the agency is largely compliant with the Geospatial Data Act of 2018 (GDA), systemic failures in data governance have created significant privacy risks.

Geospatial data—information tied to specific physical locations, including natural boundaries and man-made infrastructure—is the backbone of national safety monitoring. The DOT uses this data for everything from pipeline inspection planning to airport environment mapping.

The OIG findings indicate that while strategic goals are being met, a lack of prioritized funding and unclear administrative oversight have left several Geospatial Information Systems (GIS) without mandatory privacy protections.

The Framework of the Geospatial Data Act

Enacted on October 5, 2018, the GDA aims to eliminate wasteful duplication of geospatial activities across federal agencies while improving interagency collaboration. The Act mandates that "covered agencies" maintain strict oversight of how they collect and distribute location-based data.

The DOT holds two primary leadership roles under the Federal Geographic Data Committee (FGDC):

  • Lead Agency for the Transportation Theme: Managing data for all modes of travel for people and goods.
  • Co-Lead for the Address Theme: Overseeing data that defines fixed geographic locations via landmarks or postal delivery points.

Areas of Operational Success

The DOT demonstrated strong performance in 11 of its 12 applicable statutory mandates for fiscal year 2026. (A 13th requirement regarding data declassification does not apply as the DOT holds no classified geospatial data).

Strategic Modernization

In July 2025, the DOT launched its GIS Strategic Plan for 2026–2030. This roadmap aligns with the National Spatial Data Infrastructure (NSDI) goals for 2025–2035, focusing on:

  • Modernizing datasets for better interoperability.
  • Upskilling the geospatial workforce.
  • Establishing the DOT as a leader in spatial innovation.

Technical Standardization

The agency has successfully adopted global standards for its datasets, specifically ISO 19115-1:2014 and ISO 19139:2007. To ensure transparency, metadata regarding data accuracy and sources is hosted on the GeoPlatform, a cross-agency shared service.

Resource Management

The OIG confirmed that the DOT maintains effective data acquisition policies. Quality control reviews are performed by Operating Administrations (OAs), with final IT spend approval handled by the Chief Geospatial Information Officer to ensure federal funds yield high-quality data.

Critical Failures in Privacy Monitoring

The most severe findings involve the DOT's failure to protect personally identifiable information (PII) and sensitive geographic data. Federal law requires annual Privacy Continuous Monitoring (PCM) and a Privacy Threshold Assessment (PTA) before any system is authorized for operation.

An OIG review of 22 GIS systems revealed a breakdown in these safeguards:

System Issue Finding/Statistic
Systems lacking current approved PCM 5 of 22 systems
PCMs approved >1 year prior 3 systems
Last PCM review dated April 2024 1 system
High-impact system with expired PTA 1 system (expired March 2015)
Systems with zero privacy documentation 1 system

The discovery that a "high-impact system" had been operating with a Privacy Threshold Assessment that expired over a decade ago suggests a significant lapse in internal auditing and risk management.

Key Takeaways

  • High Overall Compliance: The DOT met 11 of 12 GDA mandates for FY2026.
  • Strategic Alignment: The agency is on track with its 2026–2030 GIS Strategic Plan and international ISO standards.
  • Privacy Breach Risk: Significant gaps in Privacy Continuous Monitoring (PCM) leave sensitive data vulnerable to public exposure.
  • Governance Failure: Some critical systems have operated for years—and in one case, over a decade—without updated privacy certifications.

FAQ

What is the Geospatial Data Act of 2018? It is a federal law designed to reduce waste and duplication of location-based data activities across government agencies while improving collaboration and oversight.

Why is the DOT's failure in privacy monitoring significant? Because geospatial data often contains sensitive information about infrastructure or individuals. Without continuous monitoring, this data could be leaked or accessed by unauthorized parties.

What is a Privacy Threshold Assessment (PTA)? A PTA is a mandatory review conducted by an agency and its Privacy Officer to determine if a new system creates privacy risks for individuals before that system is allowed to operate.

Recommended Read: