DOT Meets Geospatial Data Act Mandates, but OIG Audit Reveals Critical Privacy and Confidentiality Gaps
The U.S. Department of Transportation (DOT) relies heavily on geospatial data—information explicitly tied to physical locations on Earth—to monitor national safety issues and manage transportation infrastructure. According to a September 2026 audit conducted by the Office of Inspector General (OIG), the Department successfully navigated the majority of its oversight requirements under the Geospatial Data Act of 2018 (GDA).
While the DOT fulfilled 11 of its 12 applicable statutory mandates for fiscal year 2026, the audit exposed a critical vulnerability in the agency’s overarching data governance. Driven by unclear administrative oversight and a lack of prioritized funding, the DOT failed to consistently track and protect privacy and confidentiality risks within its Geospatial Information Systems (GIS). These compliance gaps left several systems operating without the required continuous monitoring documentation, creating a substantial risk that sensitive geographic and personally identifiable information could be exposed to the public.
Mapping the Future: DOT’s Geospatial Triumphs and the Looming Privacy Challenge
The U.S. Department of Transportation (DOT) plays a critical role in managing the geographic and spatial data that keeps the nation moving. From mapping environments surrounding airports to planning pipeline inspections, geospatial data—information explicitly tied to locations on Earth, including constructed features, natural boundaries, and geographic identifiers—is vital for monitoring safety and responding to national transportation issues.
On September 30, 2026, the DOT’s Office of Inspector General (OIG) released a comprehensive audit assessing the Department’s compliance with the Geospatial Data Act of 2018 (GDA). The findings present a dual narrative: while the DOT has successfully implemented the vast majority of its overarching geospatial strategies and compliance requirements, significant gaps in continuous privacy monitoring leave sensitive data potentially exposed to the public.
Advertisement
Advertisement
The Mandate of the Geospatial Data Act
Congress enacted the GDA on October 5, 2018, with clear objectives: to minimize the duplication of geospatial activities across Federal agencies, reduce waste, improve interagency collaboration, and provide Congress with stronger oversight of Federal investments in geospatial data. The Act applies to “covered agencies,” which are executive departments like the DOT that collect, maintain, produce, or distribute geospatial data to fulfill their core missions.
Under the GDA framework, the Federal Geographic Data Committee (FGDC)—an interagency committee of Cabinet members—identifies specific agencies to lead various National Geospatial Data Asset data themes. The DOT was designated as the lead covered agency for the Transportation Theme, which encompasses data regarding all modes of travel allowing for the conveyance of goods and persons. Additionally, the DOT serves as the co-lead for the Address Theme, managing data elements that specify fixed geographic locations via landmarks, thoroughfares, or points of postal delivery.
Advertisement
Advertisement
To ensure accountability, the GDA requires the inspectors general of covered agencies to report to Congress at least once every two years on the status of their geospatial data operations. The recent OIG audit represents the fourth such review conducted since the GDA’s enactment.
Charting a Strong Course: Compliance and Strategic Wins
For fiscal year 2026, the OIG audit revealed that the DOT fulfilled 11 of its applicable GDA responsibilities and partially met one. The 13th requirement, which involves the declassification of data to contribute to the National Spatial Data Infrastructure (NSDI), does not currently apply to the DOT as it possesses no classified geospatial data, though the agency does maintain a process should the need arise in the future.
Advertisement
Advertisement
The DOT demonstrated robust performance across several key metrics:
- Strategic Planning: In July 2025, the DOT published its Geospatial Information Systems (GIS) Strategic Plan for fiscal years 2026 through 2030. This plan aligns with the NSDI’s 2025–2035 Strategic Plan and focuses on optimizing resources, modernizing datasets to ensure they are accessible and interoperable, establishing the DOT as an innovation leader, and building a highly skilled geospatial workforce.
- Standards and Metadata: The DOT successfully utilized standardized frameworks for its datasets, specifically adopting International Organization for Standardization (ISO) 19115-1:2014 and ISO 19139:2007 standards. Metadata—which details a dataset’s source, accuracy, vintage, and collection method—was thoroughly verified by the OIG and made available through the GeoPlatform. The GeoPlatform acts as a collaborative, cross-agency shared service designed to promote accountability, open government, and transparency.
- Quality and Resource Allocation: The DOT established effective policies for data acquisition, integrating steps where Operating Administrations (OAs) perform quality control reviews. Subsequently, the Chief Geospatial Information Officer reviews the IT spend plan to approve or deny acquisitions, ensuring the Department receives high-quality data from recipients of Federal funds. The OIG confirmed that the DOT allocates sufficient resources to fulfill its geospatial stewardship, despite noted budget constraints and staffing challenges.
The Blind Spot: Privacy and Confidentiality Gaps
Despite widespread success in strategy and data formatting, the DOT faltered in the critical area of privacy. The GDA explicitly requires covered agencies to protect personal privacy and maintain confidentiality in alignment with Federal law. According to internal DOT policy, each OA is required to conduct annual privacy risk assessments utilizing a Privacy Continuous Monitoring (PCM) template, which ensures system operations manage privacy risks consistently.
Furthermore, before any geospatial system is authorized to operate, the OA and its Privacy Officer must conduct a Privacy Threshold Assessment (PTA) to determine if the system creates privacy risks for individuals. The DOT Chief Privacy Officer (CPO) must approve this PTA, which then requires recertification at least every three years.
The OIG’s analysis of system documentation for 22 of the DOT’s GIS systems exposed concerning lapses:
Advertisement
Advertisement
- Five of the 22 systems lacked a current, approved PCM.
- Of those five, three had PCMs that were approved more than a year prior, and one system had not seen a PCM review since April 2024 (over two years before the audit’s completion).
- One GIS, notably categorized as a “high-impact system,” was operating with a PTA that had expired over a decade ago, in March 2015.
- An additional GIS possessed no required privacy documentation whatsoever, which agency officials attributed to the system being consolidated into a new framework currently in development.
Root Causes: Clarity and Funding Deficits
The OIG report highlights structural and administrative root causes for these security vulnerabilities. According to OA privacy officials, GIS personnel failed to maintain and update privacy documentation because they lacked clarity regarding the specific responsibilities of privacy oversight bodies. While the CPO reportedly sent direct notifications to responsible OA Privacy Officers requesting the completion of required paperwork, confusion remained.
Compounding the lack of role clarity was a distinct lack of financial prioritization. GIS system owners reported uncertainty regarding fiscal prioritization processes within their specific OAs. Ultimately, DOT and OA leadership did not elevate GIS privacy-related tasks to the level of a funded priority. This fundamental lack of dedicated resources directly restricted the OAs’ capacity to fulfill the DOT’s stringent privacy documentation mandates.
Real-World Implications and Future Directives
The consequences of overlooking continuous privacy monitoring in geospatial systems are not merely bureaucratic. By failing to follow required privacy procedures, OA GIS system owners risk exposing sensitive data and personally identifiable information to the public. Without proper risk management, these critical systems are left vulnerable to threats that could negatively disrupt transportation operations, such as the exposure of sensitive pipeline locations.
Because the OIG was concurrently conducting a separate, dedicated audit of the DOT’s overall privacy program during this review period, this specific GDA report did not issue any new recommendations to the Department. The DOT’s need to adequately track and protect its GIS privacy risks will be directly addressed through recommendations in that accompanying privacy program report, which heavily focuses on implementing data protection controls across all Operating Administrations.
Image: American Airlines and United Airlines
Advertisement