Court Rules
All enforcement actions
GuidanceLow RiskMultistate

DHS Expands SAVE Program to Include U.S. Citizens, Violating Privacy Act

U.S. Department of Homeland SecurityDecember 1, 2025California Attorney General

Summary

California Attorney General Rob Bonta co-led a coalition of 18 attorneys general in submitting a comment letter opposing the Department of Homeland Security's expansion of the Systematic Alien Verification for Entitlements (SAVE) program to include U.S.-born citizens. The coalition argues the expansion violates the Privacy Act of 1974, creates a massive surveillance database, increases data breach risks, and will lead to inaccurate verifications and denial of benefits.

Remedy

The coalition urges DHS to rescind the SAVE program expansion, arguing it violates the Privacy Act by adding records of natural-born citizens without consent and creates unacceptable privacy and security risks.

Corrective Notice

Contract Impact

In-house legal teams should review agreements between state/local government agencies (or other entities) and the Department of Homeland Security (DHS)/USCIS that involve the Systematic Alien Verification for Entitlements (SAVE) program. Focus on clauses governing data sharing scope, consent requirements, data breach notification, data retention schedules, and accuracy guarantees. Specific changes may be needed to limit data use to verified immigration status purposes only, incorporate explicit consent mechanisms for U.S.-born citizens, enhance breach notification protocols, ensure data minimization and retention limits, and add provisions to prevent repurposing data for surveillance or unrelated federal investigations.

Contract Search Terms

Systems of Record Notice (SORN)routine usesdata sharing agreementSocial Security numberdriver's license numberbiometric datadata breach notification clauseconsent mechanismdata retention schedulesurveillance database

Laws Cited

Privacy Act of 1974

Violation Types

Entity Details

Entity

U.S. Department of Homeland Security

Also known as: Department of Homeland Security

Industry

Other

Multistate Coalition

New YorkColoradoConnecticutDistrict of ColumbiaDelawareHawaiiIllinoisMaineMassachusettsMarylandMichiganMinnesotaNevadaNew MexicoOregonRhode IslandVermont

Official Sources

Source Evidence

Entity Name
"U.S. Department of Homeland Security’s (DHS)"
Laws Cited
"violates the Privacy Act of 1974"
Violation Types
"massive invasion of privacy that exposes millions of individuals to possible data breaches, pools vast swaths of sensitive data, and furthers the Administration’s efforts to create a national surveillance database"

Related Enforcement Actions

CT

U.S. Department of Homeland Security

Connecticut Attorney General William Tong joined a coalition of 21 attorneys general in submitting a comment letter opposing a DHS rule that allows certain affirmative asylum applications to be referred to removal proceedings without an asylum officer interview. The coalition argues the rule violates federal law and harms asylum seekers, including unaccompanied children; this was a policy opposition letter, not a privacy enforcement action.

VA

U.S. Department of Homeland Security

Attorney General Jay Jones joined a coalition of 26 states to sue the Trump administration over unlawful conditions attached to counterterrorism and emergency funding. The conditions would require states to share voter data with DHS and assist in immigration enforcement, which the coalition argues violates the Administrative Procedure Act and the Spending Clause.

OR

U.S. Department of Homeland Security

Other enforcement action: Oregon Attorney General Dan Rayfield, joined by 18 other states, sued the Trump Administration over its unlawful $100,000 fee for H-1B visa petitions. The lawsuit alleges that the policy violates the Administrative Procedure Act by exceeding congressional authority and bypassing required rulemaking procedures, harming educational institutions and employers.

CA

California

Governor Newsom signed the Expanding Privacy Rights Act (SB 923), expanding CCPA deletion rights to cover personal information obtained from third parties and requiring online-only businesses to offer an online method for submitting privacy requests. The law takes effect January 1, 2027, and allows businesses to maintain suppression lists to help keep deleted information from being reacquired.

CA

California State Legislature

The California Privacy Protection Agency announced that the California State Legislature approved the Expanding Privacy Rights Act (SB 923), which expands the CCPA's right to delete to cover all non-exempt personal information a business holds about a consumer, including data originally collected from third parties. The bill also requires online-only businesses with a direct relationship to consumers to provide online methods, such as webforms, for submitting access, deletion, and correction requests, and expressly permits businesses to retain suppression lists so deleted information stays deleted. The bill, authored by Senator Becker and sponsored by CalPrivacy, now goes to the Governor for consideration.

CA

Meta Platforms, Inc.

A bipartisan coalition of 33 state attorneys general, led by Minnesota AG Keith Ellison, began trial against Meta Platforms, Inc., alleging the company knowingly designed and deployed harmful features on Facebook and Instagram that drive children and teens to use the platforms compulsively, while falsely assuring parents and the public that its platforms were safe for young users. The states also allege Meta illegally collected personal information from children under 13 without parental consent, violating COPPA. The trial opened before Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California, with the states seeking monetary penalties and injunctive relief.