Why It Matters

Congress and the public cannot be assured that sensitive government data was properly protected when Department of Government Efficiency (DOGE) teams accessed federal agency systems, according to a new audit by the U.S. Government Accountability Office (GAO). The systems involved held contracts, grants, human resources, and financial records, along with personally identifiable information (PII), yet the GAO found that multiple agencies either provided incomplete documentation or refused to respond to its requests entirely.

The Big Picture

The DOGE initiative was created by an executive order from President Trump to modernize federal technology and maximize government efficiency. That same order directed the heads of executive branch agencies to establish DOGE teams that would work alongside the U.S. DOGE Service (USDS).

The GAO reviewed six agencies: the Consumer Financial Protection Bureau (CFPB), the Department of Education, the National Oceanic and Atmospheric Administration (NOAA), the Securities and Exchange Commission (SEC), the Small Business Administration (SBA), and the Department of Veterans Affairs (VA). The review had two objectives: to describe which systems DOGE teams accessed and to evaluate whether agencies implemented controls ensuring those teams followed IT security rules.

Four of the six agencies, CFPB, Education, NOAA, and SEC, reported that their DOGE teams collectively had access to more than 23 systems. SBA and VA did not respond to GAO's requests for information on system access at all. Even among the four agencies that did respond, the GAO could not determine whether DOGE team members held specific system permissions or were authorized to take particular actions, such as viewing PII or modifying data, based on the information provided.

CFPB showed that six DOGE team members received a privacy briefing and four completed security training, but did not provide evidence that the remaining team members finished the required training. Education provided IT system rules of behavior documents signed by five of its six DOGE team members but did not respond to repeated GAO requests for the document signed by the sixth. SEC demonstrated that a background check was underway for one team member and had been conducted for another, but did not confirm whether that investigation was favorably adjudicated. SBA and VA did not respond to requests for information on controls at all.

The report stated plainly that the GAO has "ample statutory authority" to conduct this work and obtain the information it requested in support of Congress, and that the agencies' stated reasons for not fully responding "do not alter or diminish GAO's statutory right of access to this information." The GAO said it stands by the facts presented. The review was requested by members of Congress, who asked GAO to examine whether DOGE teams at multiple agencies appropriately protected the systems and information they accessed.

The Bottom Line

The audit found that both Congress and the public lack assurance that the six reviewed agencies implemented controls needed to ensure DOGE team members appropriately secured information, because the agencies did not respond to GAO's requests for the information needed to fully answer the questions posed by members of Congress.

With SBA and VA having provided no information at all, and with partial responses from the remaining four agencies, the GAO's ability to give Congress a full accounting of DOGE's data access remains constrained.

Access the Legis1 platform for comprehensive political news, data, and insights.

Spot something wrong? Report an issue with this article