The U.S. Department of Transportation has closed its first industry-wide review of airline privacy practices without finding a violation or seeking penalties. The decision leaves travelers largely dependent on carriers’ published policies while lawmakers continue to question how passenger records are shared, sold and used for pricing.
A review ends with no enforcement action
The department’s Office of Aviation Consumer Protection said it evaluated the 10 largest U.S. airlines and found no breach of applicable law or departmental policy. Its September 4 closure notice ended the review with no further action, while reminding carriers to secure passenger information, follow their own privacy promises and avoid unlawful discrimination in dynamic pricing.
Reuters reported Monday that the department did not impose penalties and that its memo did not announce new regulations. The agency’s conclusion is narrower than a finding that every airline practice is optimal or risk-free: it means investigators said they did not identify a violation under the laws and policies they applied.
The review began in March 2024 under then-Transportation Secretary Pete Buttigieg. At launch, DOT said it would examine how Allegiant, Alaska, American, Delta, Frontier, Hawaiian, JetBlue, Southwest, Spirit and United collected, maintained, handled and used customer information. The department’s original announcement specifically identified data monetization, targeted advertising, third-party sharing, breach prevention and employee access as areas of interest.
DOT initially described the exercise as the first in a series of periodic reviews and said problematic evidence could lead to investigations, enforcement, guidance or rulemaking. The closure notice does not say when another industry review will occur, publish airline-by-airline findings or release the carriers’ responses. That limits the public’s ability to compare practices even though the department reached an industry-wide conclusion.
Why passenger data draws scrutiny
An airline reservation can connect a traveler’s name, contact details, payment information, itinerary, companions and loyalty account. Those records are necessary to issue tickets and operate flights, but they also can reveal sensitive patterns of movement. DOT says it can treat a carrier’s violation of its privacy commitments, unauthorized disclosure or inadequate security as an unfair or deceptive practice. Its consumer privacy guidance directs complaints about airlines and ticket agents to the aviation consumer office.
Congressional critics argue that a policy-based system is not enough. In August, Sen. Ron Wyden of Oregon and Rep. Shontel Brown of Ohio asked the Government Accountability Office to investigate DOT’s oversight. Their letter and public summary asked whether the department relies too heavily on consumer complaints, whether it has adequate standards for insider threats and how its enforcement record aligns with U.S. commitments on transatlantic data transfers.
The lawmakers also pointed to government access to travel records. They said a database operated by the Airline Reporting Corporation, which is owned by major airlines, had sold federal agencies access to a large body of passenger records without warrants or court supervision before ending that program in 2025. Reuters reported the same allegations and said the department did not immediately respond to questions about the closure memo.
Historical oversight findings show that insider access is not a hypothetical issue. A 2016 Justice Department inspector general audit found weaknesses in the Drug Enforcement Administration’s management of confidential sources, including commercial-airline employees who provided passenger information. A later inspector general notice again cited airline employees who supplied flight, itinerary and ticket data as sources. Those reports concern law-enforcement practices rather than a finding that an airline violated DOT rules, but they explain why employee access and disclosure controls remain central to the debate.
Personalized pricing remains a separate concern
The closure notice also warned carriers against unlawful discrimination in dynamic pricing. Airlines have long adjusted fares as demand, timing, route conditions and inventory change. The sharper privacy question is whether a carrier uses an individual traveler’s personal information to determine what that person is shown or charged.
Transportation Secretary Sean Duffy said last year that the department would investigate personalized pricing if evidence emerged, Reuters reported. Delta has repeatedly denied using artificial intelligence to set individualized fares. The department did not accuse Delta or another airline of that practice in its closure notice, and the notice does not ban ordinary demand-based revenue management.
What travelers can do
The review’s end does not create a new opt-out right or a uniform retention limit for passenger records. Travelers can still reduce unnecessary exposure by reviewing airline and booking-site privacy settings, declining optional marketing uses, using strong account passwords and removing stored payment methods when they are not needed. Consumers who believe an airline broke a stated privacy promise or disclosed information improperly can submit a complaint to DOT and preserve confirmations, screenshots and correspondence.
The next accountability step may come from GAO rather than DOT. Wyden and Brown requested legislative recommendations as well as an assessment of the agency’s enforcement structure. Until Congress or regulators adopt more specific rules, the practical standard remains fragmented: carriers must honor their own policies and avoid unfair or deceptive conduct, while travelers have limited visibility into the full path their reservation data can take.