PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Minn. driver’s license data snoopers are difficult to track

Posted on January 8, 2013 by pogowasright.org

Eric Roper of The Star Tribune has been all over the problems with rampant misuse of the Minnesota driver’s license database.  In another report yesterday, he focused on the difficulties of finding out who is accessing citizen’s files:

The Minnesota Department of Public Safety, which oversees the driver’s license database, refuses to tell people the names of users — generally public employees — who have looked up their information. Perhaps the most high-profile citizen getting stonewalled by the state is Hennepin County Sheriff Rich Stanek, who is sparring with the department over what he believes were inappropriate queries into his driver’s license records…. Stanek learned in June that employees at 21 agencies, including his own office, had accessed his records over several years. Some of the queries came from as far away as Wells, Minn., a small town 117 miles south of Minneapolis that he has never visited. The Department of Public Safety would not provide him with the names of the users.

Part of the problem may lie in how the law is written. Roper reports:

Members of the public have rights under the Minnesota Data Practices Act to access government information about themselves.

But the public safety department told Stanek that provisions of the law governing undercover officers and security data prevented it from releasing the names.

In a separate letter a month later, the agency changed its legal reasoning for the refusal and instead cited an obscure section of the law concerning “electronic access data.”

In previous blog entries, I’ve expressed my serious concerns that the state is simply doing a godawful job of controlling and monitoring access to the database. If someone’s records can be accessed 200 times by police officers all over the state and the system never flagged the access as suspicious or worthy of investigation – and protection of the individual’s records – something is seriously wrong in Minnesota data protection.

In a statement, Department of Public Safety spokesman Bruce Gordon said protecting the database from misuse is a priority for the department.

He said the agency has begun random audits to catch inappropriate access and already does regular audits of the heaviest users.

“While we are able to provide the summary of an audit, the department has consistently withheld the names of those who have accessed the data based on Minnesota law, which says the data are private,” Gordon said.

Random audits are not sufficient. Nor is asking an agency to investigate itself for improper conduct of its employees the best way to clean house. The state needs to invest in a system that is constantly monitoring access and flagging inquiries based on some criteria. And employees who misuse the system need to be fired in a highly publicized move so that the word gets out that the state is serious about cracking down on misuse of the database.

Read more on Star Tribune.

Category: BreachesGovt

Post navigation

← Privacy czar tries to broker Internet surveillance bill solution
Parental Attitudes about Student Privacy Online →

Now more than ever

Search

Contact Me

Email: info@pogowasright.org

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim
  • Privacy matters to Canadians – Privacy Commissioner of Canada marks Privacy Awareness Week with release of latest survey results
  • Missouri Clinic Must Give State AG Minor Trans Care Information
  • Georgia hospital defeats data-tracking lawsuit
  • No Postal Service Data Sharing to Deport Immigrants
  • DOGE aims to pool federal data, putting personal information at risk
  • Privacy concerns swirl around HHS plan to build Medicare, Medicaid database on autism

RSS Recent Posts on DataBreaches.net

  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
©2025 PogoWasRight.org. All rights reserved.
Menu
  • About
  • Privacy