Comment from Persistence Analytics Group LLC

Persistence Analytics Group LLCSupportBusiness
Summary: Persistence Analytics Group LLC / United Grid supports the Department of Transportation's data security requirements for accessing confidential data. The commenter argues that the DOT should implement specific integrity requirements, including clear access justification, minimum necessary access, user verification, and robust cybersecurity controls to protect public trust and data integrity.
Comment on DOT-OST-2026-0727-0003 Agency Information Collection Activities: Data Security Requirements for Accessing Confidential Data Persistence Analytics Group LLC / United Grid submits this comment regarding DOT’s information collection activity related to data security requirements for accessing confidential data. PAG / United Grid supports strong data-security requirements for access to confidential transportation, infrastructure, safety, economic, operational, and federally held data. Confidential data can support better policy, research, safety analysis, infrastructure planning, and public accountability, but only if access is governed by clear, enforceable, and auditable controls. The key issue is not only whether confidential data can be accessed. The key issue is whether the assumptions behind that access are verified before data exposure, misuse, compliance failure, or public-trust damage occurs. DOT should ensure that any data-access framework includes the following implementation-integrity requirements: 1. Clear access justification Every request for confidential data should identify the purpose of access, the public or research value, the specific data needed, and why less sensitive data would not be sufficient. 2. Minimum necessary access Access should be limited to the smallest dataset, shortest duration, and narrowest group of authorized users necessary to complete the approved purpose. 3. User verification and accountability DOT should verify the identity, affiliation, role, and authorization of all users. Each user should be individually accountable for compliance, not shielded by generalized institutional access. 4. Cybersecurity controls Access should require appropriate safeguards, including secure storage, encryption, access logging, authentication, endpoint controls, incident reporting, and restrictions on transfer, copying, or external use. 5. Auditability DOT should maintain auditable records of who accessed what data, when, for what approved purpose, and whether the access remained within authorized limits. 6. Data-use boundaries Confidential data should not be reused, combined, redistributed, commercialized, published, or applied to unrelated purposes without express approval. 7. Breach and misuse procedures The collection should clearly define reporting duties, containment procedures, penalties, suspension rights, and corrective action if confidential data are misused or exposed. 8. Burden and clarity DOT should ensure that compliance requirements are clear, practical, and not unnecessarily burdensome for legitimate researchers, state and local agencies, small entities, or public-interest users. 9. Lifecycle controls Access should expire automatically unless renewed. DOT should require data return, destruction certification, or continued-use justification at the end of the approved period. 10. Public trust Because confidential data often involve sensitive transportation, safety, infrastructure, commercial, or operational information, DOT should treat data governance as a public-trust function, not merely an administrative form. PAG / United Grid recommends that DOT evaluate this information collection through a decision-grade evidence standard: * What data are being protected? * Who receives access? * What public value justifies the access? * What controls reduce misuse risk? * Who is accountable if controls fail? * What evidence proves compliance over time? The broader principle is simple: Confidential data access should not rely on assumed trust. It should rely on verified purpose, controlled access, auditable use, cybersecurity safeguards, and enforceable accountability. Data access can improve public decision-making, but only if the access framework protects the integrity of the data, the rights of affected parties, and the credibility of the institution granting access. Respectfully submitted, Neil P. Osnato Founder Persistence Analytics Group LLC | United Grid National Security & Infrastructure Risk Analytics Demand Durability | Grid Stress | Load Integrity SAM.gov registered UEI: D3VYU39H6DX9 D-U-N-S: 142849930 CAGE: 19T34 neil@persistenceanalyticsgroup.com 609-464-9055 https://persistenceanalyticsgroup.com/

View on Regulations.gov