All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
A selfie shared with friends could become a starting point for an ICE identity search.
A July 22 performance work statement shows that Immigration and Customs Enforcement (ICE) is seeking artificial intelligence capable of identifying people through facial images, device metadata, behavioral signals, commercial data, and even what the agency calls “passive environmental markers.” The document accompanied an ICE procurement listing on SAM.gov.[1][2]
The proposed system would serve 11,200 ICE users, process identities in bulk, and connect vast stores of public and commercial information with agency tools including Palantir and PenLink.
ICE also requires access to facial-recognition platforms that can search “large-scale image databases” and match faces across sources including “open-source media.”
For consumers, the power imbalance is stark.
You might share a photo for friends, family, or work, only for a government system to potentially use it to uncover their addresses, phone numbers, vehicles, relatives, and other personal records.
One search could span countless records
LexisNexis already links records into detailed profiles
Facial recognition can be wrong
Palantir could make the data actionable
You can reduce your exposure, but you can’t erase your face
ICE wants AI to rebuild your identity
ICE’s performance work statement calls for an AI-driven identification system that can combine known information with data that may not identify someone on its own. The listed signals include:
- Anonymized behavioral indicators
- Device metadata
- Network signatures
- Commercial telemetry data
- Passive environmental markers
The system would use pattern recognition and what ICE describes as a “multimodal correlation engine” to cross-reference those signals and infer an end user’s identity without relying on a single direct identifier.
The document does not explain precisely what commercial telemetry would be collected or whether the system could collect information about people who are not suspected of a crime.
In practical terms, the proposed system could make supposedly anonymous data less anonymous.
A device identifier may contain repeated locations, network activity, and other patterns that could potentially help connect that device to you, or someone you know.
One search could span countless records
The database would let agents search public records and other investigative material individually or in batches using information including:
- Names
- Dates of birth
- Addresses
- Phone numbers
- Social Security numbers
- License plates
- Vehicle identification numbers
- Aircraft tail numbers
The database would use entity resolution to decide which records refer to the same person and eliminate duplicates. It would also score results so that records considered more relevant or current appear first.
The required integration would make the database’s public and proprietary information available through ICE applications, including Palantir, PenLink, and ICE Data Analytics.
An isolated piece of information reveals only so much. Its surveillance value increases when a system can combine it with thousands of other records and infer relationships among people, businesses, assets, devices, and locations.
LexisNexis already links records into detailed profiles
Separately, ICE is seeking continued access to LexID and Accurint Virtual Crime Center, according to records reported by 404 Media. The outlet reports that ICE anticipates paying LexisNexis $6.7 million.
LexisNexis says its identity-linking technology draws from more than 82 billion public and proprietary records obtained from over 10,000 sources.
The company assigns a LexID number to the records it believes belong to one person or business. As new records are added, LexisNexis says the system can develop a more complete view of that identity and expose connections that might otherwise remain hidden.
Its Accurint product helps government agencies locate people, verify identities, find assets, and map connections among people, businesses, and locations.
The system is not infallible, though. LexisNexis acknowledges that its public-record and commercially available data “may contain errors.” The company cautions: “Before relying on any data, it should be independently verified.”
For consumers, correcting an error buried among billions of records can be nearly impossible — especially when they don’t know the profile exists. That lack of control is widespread: 68% of Americans say they have little to no control over their personal information online, according to an All About Cookies survey.
Facial recognition can be wrong
ICE describes its desired facial-recognition technology as capable of “high accuracy” matching, but the procurement does not identify the system, disclose its measured accuracy, or explain how agents would review possible matches.
That missing context is important.
The National Institute of Standards and Technology found that some facial-recognition algorithms produced false positives for Asian and Black faces at rates 10 to 100 times higher than for white faces. Results varied between algorithms, but NIST also found elevated false-positive rates for Black women in one-to-many searches (the type of matching ICE wants).
A false positive occurs when an algorithm incorrectly concludes that photos of two different people show the same person. In a consumer app, that might produce an inconvenient mistake.
But in an immigration investigation? It could place an innocent person at risk of deportation.
ICE’s Mobile Fortify facial-recognition app has already demonstrated the stakes. The system returned two different incorrect names after agents scanned the same woman, according to previous reporting from 404 Media.
Palantir could make the data actionable
The procurement requires the database to integrate with Palantir.
Palantir already supplies ICE with Enhanced Leads Identification and Targeting for Enforcement, or ELITE. The system can build dossiers on possible deportation targets, map their locations, and calculate a confidence score for an address, according to 404 Media’s earlier investigation.
Once connected with analytical and case-management software, it can help agents chart relationships, prioritize leads, locate assets, and decide where to focus enforcement activity.
You can reduce your exposure, but you can’t erase your face
No privacy setting can guarantee that facial-recognition software will never find your image. Your online photos may already have been copied, reposted, archived, or included in a database beyond your control.
You also can’t replace your face, but you can still make it harder to connect your face with the rest of your identity:
- Audit your public photos. Search your name online or use a free data exposure scan to find personal information tied to you. Reverse-image searches can also uncover exposed accounts or copies of your profile pictures.
- Make personal accounts private. Review older posts, tagged photos, follower lists, and profile-photo visibility rather than changing only the default setting for new posts.
- Remove unnecessary identifying details. Avoid placing a clear facial photo beside your full name, employer, address, phone number, or daily routine when that information does not need to be public.
- Turn off location access you don’t need. Review permissions for social media, photo, shopping, and weather apps. Disabling a geotag on a post does not necessarily prevent an app from collecting location data in the background.
- Avoid posting your location in real time. Delaying posts about travel, events, protests, or appointments can make it harder to connect your online activity with your immediate physical location.
- Protect private photo libraries. Use a unique password and multifactor authentication on social media, email, and cloud-storage accounts. More than 20,000 Instagram accounts were recently compromised through a flaw in Meta’s AI chat support system, while accounts protected by two-factor authentication largely blocked the attack.
- Opt out of people-search sites. The Federal Trade Commission recommends finding your profile on each service and following its opt-out process. Information can reappear, so check periodically.
- Request your LexisNexis file. Consumers can order a and dispute inaccurate information.
- Exercise applicable state privacy rights. LexisNexis offers a portal to request deletion, correction, or limits on certain data sales. That said, your available options depend on your state, and legal exemptions may allow some information to remain available.
A LexisNexis security freeze can still allow government access when the law recognizes the requester’s purpose. Opt-outs leave public records untouched, while the same information may remain available through other data brokers.
Consumers can shrink their digital footprint, but companies and government agencies still hold the advantage: They can build and search profiles that people may never see, challenge, or even know exist.
All About Cookies asked ICE, LexisNexis, Palantir, and PenLink about the system’s data practices, privacy safeguards, and potential use against people not suspected of crimes. None responded by publication.