Image credit: US Department of Transportation
The US Department of Transportation (DOT) has ended its review of how the 10 largest U.S. airlines handle passenger data without finding any violations or taking any enforcement action, according to a September 4 DOT notice. The notice adds no new rules. It merely reminds airlines of obligations they already have, which means travelers' privacy protections are unchanged.
DOT opened the review in March 2024 and looked at how Alaska, Allegiant, American, Delta, Frontier, Hawaiian, JetBlue, Southwest, Spirit, and United collected, used, sold, shared, and protected passenger information between January 2022 and March 2024. It placed particular emphasis on employee privacy training and on preventing data breaches. DOT found that every airline has a training program for staff who handle passenger data, a readily available privacy policy, and systems to safeguard that data.
As the only federal regulator of airline privacy practices, DOT's authority rests on a ban on unfair or deceptive practices. In the closure notice, DOT lists three things it would treat as a violations: failing to follow a published privacy policy, failing to properly safeguard sensitive data, and misrepresenting data practices to customers. It also clarifies that airlines should be transparent about what they collect and whether they share it.
Pricing was also addressed. DOT says airlines should avoid setting prices based on who the customer is, a practice often called personalized pricing, where two travelers searching for the same seat could be shown different fares based on data collected about them. Federal law already bars airlines from discriminating against passengers by race, color, national origin, religion, sex, or disability. Reuters notes that Transportation Secretary Sean Duffy said last year he would quickly investigate any personalized pricing, and that Delta has repeatedly denied using AI to set individualized prices.
Read more: Is AI Charging You More for the Same Flight?
Critics say the review did not address their concerns.
In an August 26 letter to the Government Accountability Office, Sen. Ron Wyden (D-Ore.) and Rep. Shontel Brown (D-Ohio) wrote that DOT has never taken a privacy enforcement action in the four decades it has held sole authority, and that airlines' responses to the 2024 review were never made public .After the closure, Wyden told Reuters that DOT is treating a privacy policy and training as enough despite "clear evidence of privacy abuses."
Their letter points to two examples. The first is Airlines Reporting Corporation, a data broker owned by major U.S. airlines, which they say sold access to roughly 722 million passenger travel records to agencies including the Department of Homeland Security and the IRS without warrants or court oversight. ARC shut the program down in November 2025.
The second is a 2016 Justice Department inspector general audit that found the US Drug Enforcement Agency paid at least 19 airline employees for passenger itineraries, dates of birth, and seat numbers; the letter says a 2024 follow-up found the payments were continuing. DOT's closure notice does not mention either matter.
The DOT says its Office of Aviation Consumer Protection receives air travel complaints and uses them to spot trends and to investigate and bring cases against airlines and ticket agents. Concerns about airline security go to Transportation Security Administration, and questions about biometric screening go to Customs and Border Protection, because both agencies have separate authority over passenger information.