American Latest Airline To Admit To Sharing Passenger Data
American Airlines, like JetBlue and Northwest before it, reveals its passenger data was shared with third-party companies working on security systems.
Echoing privacy controversies faced by JetBlue and Northwest Airlines, American Airlines revealed that data on its passengers was given to third-party contractors so they could test aviation-security systems.
American said Friday that in June 2002, one of the airline's data-processing vendors, Airline Automation Inc., shared 1.2 million passenger records with four companies vying for contracts from the Transportation Security Administration. The four companies, Ascent Technology, HNC Software, Infoglide Software, and Lockheed Martin, were testing security systems for TSA as part of the government agency's effort to improve aviation security in response to 9/11.
"Our desire to assist TSA in the aftermath of the events of Sept. 11 was consistent with our focus on safety and security," an American Airlines spokesman said in a statement. "No passengers were harmed by the transfer of the data."
American Airlines says it authorized Airline Automation to give passenger records directly to TSA. Instead, the company claims Airline Automation gave the data to the four vendors. Airline Automation paints a slightly different picture. The company says it provided the data only after receiving authorization of American in May 2002 to release passenger data for security-testing purposes. An Airline Automation statement says the authorization from American made clear that Airline Automation was to receive written instructions from TSA concerning the details of the release of the data to be provided for testing.
Airline Automation says the four vendors involved signed confidentiality agreements and have returned or destroyed the passenger data as per those agreements.
American executives weren't immediately available for comment. Airline Automation declined to comment further, citing the possibility of an investigation by the Department of Homeland Security, which oversees TSA. Ascent Technologies did not respond to requests for an interview.
TSA is gathering information related to the situation and will provide it to Homeland Security chief privacy officer Nuala O'Connor Kelly, who will review whether the data was handled in accordance with U.S. privacy laws and procedures. "We'll follow the same protocol we did when investigating JetBlue," O'Connor Kelly says. She says she's not aware of any additional airlines facing similar scrutiny for privacy compliance.
Hofmann also noted that it's not clear whether a contractual relationship existed between TSA and the four vendors. American describes the vendors as "vying for contracts." Airline Automation's statement suggests a more established relationship. Whether these companies were formally engaged by TSA might have a bearing on whether the government agency violated its own rules. TSA declined to comment on the matter.
Now that three airlines appear to have shared data with organizations testing security systems, Hofmann says it's possible other airlines had similar arrangements with TSA or contractors: "I think this could be an industrywide phenomenon."
IT's Reputation: What the Data SaysInformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business really views IT's performance in delivering services - and, more important, powering innovation. Our results suggest IT leaders should worry less about whether they're getting enough resources and more about the relationships they have with business unit peers.
What The Business Really Thinks Of IT: 3 Hard TruthsThey say perception is reality. If so, many in-house IT departments have reason to worry. InformationWeek's IT Perception Survey seeks to quantify how IT thinks it's doing versus how the business views IT's performance in delivering services - and, more important, powering innovation. The news isn't great.
InformationWeek Must Reads Oct. 21, 2014InformationWeek's new Must Reads is a compendium of our best recent coverage of digital strategy. Learn why you should learn to embrace DevOps, how to avoid roadblocks for digital projects, what the five steps to API management are, and more.