HeadFlash

Privacy

ICE Pays LexisNexis $6.7M for Data Feeding Palantir Deportation Tools

ICE's new procurement reveals AI-driven vetting and facial recognition plans, while California moves to rein in workplace brain data and China tightens data officer rules.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

ICE to Pay LexisNexis $6.7 Million for Data Feeding Palantir Deportation Tools

Newly published procurement records show ICE plans to pay LexisNexis $6.7 million for continued access to data that can be fed into a Palantir platform. The data is intended to support ICE’s Enforcement and Removal Operations (ERO), the agency’s deportation-focused division. The records state the data will support all aspects of ICE screening, vetting, lead development, and criminal analysis, including identifying fraud before it materializes. The tools involved are LexID and Accurint Virtual Crime Center, which LexisNexis says draw on over 82 billion public and proprietary records from more than 10,000 sources.

The document also lists requirements for an AI-driven identification system that can infer the identity of the end user, and a facial recognition system capable of high-accuracy matching across diverse sources, including open-source media, in bulk. The database must interface via API with ICE applications, such as the Palantir platform, PenLink, and ICE Data Analytics. This news follows January revelations about ELITE, a Palantir-built system that helps ICE identify which neighborhoods to target by combining data from private suppliers and government agencies. It comes as ICE arrested more than 51,000 people in July, many at airports. LexisNexis, Palantir, and ICE did not immediately respond to requests for comment.

ICE to Pay LexisNexis Millions for Data to Feed to Palantir →

California Advances Neurotech and Brain Data Privacy Regulations

California lawmakers are advancing regulations on neurotechnology and brain data privacy. A bill restricting how employers use brain data has cleared the Assembly and advanced through the Senate, and another measure blocking the sale of brain data and other sensitive personal information is also progressing. New privacy agency rules taking effect in January will protect more people from businesses using AI to make significant decisions, including systems that utilize brain data. The technology gathers information via brain implants or sensors in earbuds, headbands, and AR headsets, with beneficial uses including helping paralyzed people speak and neurological disorder patients communicate.

Assemblymember Isaac Bryan is pushing Assembly Bill 1883, which prohibits employers from collecting brain data unless used for safety. The bill drew opposition from major employers, including local governments and groups representing hospitals and grocers, who argue it is too broad. A 2024 study found virtually all companies developing non-invasive brain-computer interface technology have poor privacy practices in their terms of service, and two-thirds allowed data sharing with third parties. Last year, a similar bill was vetoed by Gov. Gavin Newsom. California-based companies like Neuralink, Science Corporation, and Cognixion are developing the technology, while Meta is exploring integrating brain data into its smart glasses. Colorado, Connecticut, Montana, and Vermont already protect brain data to some extent.

Would you trust your boss with data about your brain? California moves to regulate neurotech →

China Draft Rules Require Data Officers Without Foreign Residency

China’s Cyberspace Administration published draft rules on August 10 requiring every large-scale personal-information processor to appoint a data compliance officer who holds Chinese nationality and has never held permanent residency or a long-term residence permit in any foreign country. Legal analysts said this standard goes further than China’s own regulations governing state secrets workers. The draft is open for public comment through September 7, 2026, and consolidates two earlier consultations. Qualification is based on scale: entities with more than 50 million registered users or 10 million monthly active users are candidates for formal designation, as are organizations whose data holdings could damage national security if compromised.

The draft requires appointment of a personal information protection officer (PIPO) from senior management with Chinese nationality, no foreign residency, professional knowledge, and more than five years of relevant experience. The PIPO has veto power over data-processing decisions and can report directly to regulators. The nationality filter also applies to data centers storing Chinese personal information. The draft builds on existing laws including the Personal Information Protection Law, which saw its first enforcement action against a foreign company in September 2025 when Dior was penalized for cross-border data transfer violations. Violations of data localization requirements can result in fines up to ¥50 million or 5% of annual revenue. Covered entities must provide data portability in a machine-readable format within 30 working days of a user request.

China Privacy Draft Sets Tougher Test Than China’s Own State Secrets Rules →