Comment from Persistence Analytics Group LLC
Persistence Analytics Group LLCSupportBusiness
Summary: Persistence Analytics Group LLC / United Grid supports the Department of Transportation's data security requirements for accessing confidential data. The commenter argues that the DOT should implement specific integrity requirements, including clear access justification, minimum necessary access, user verification, and robust cybersecurity controls to protect public trust and data integrity.
Comment on DOT-OST-2026-0727-0003
Agency Information Collection Activities: Data Security Requirements for Accessing Confidential Data
Persistence Analytics Group LLC / United Grid submits this comment regarding DOT’s information collection activity related to data security requirements for accessing confidential data.
PAG / United Grid supports strong data-security requirements for access to confidential transportation, infrastructure, safety, economic, operational, and federally held data. Confidential data can support better policy, research, safety analysis, infrastructure planning, and public accountability, but only if access is governed by clear, enforceable, and auditable controls.
The key issue is not only whether confidential data can be accessed.
The key issue is whether the assumptions behind that access are verified before data exposure, misuse, compliance failure, or public-trust damage occurs.
DOT should ensure that any data-access framework includes the following implementation-integrity requirements:
1. Clear access justification
Every request for confidential data should identify the purpose of access, the public or research value, the specific data needed, and why less sensitive data would not be sufficient.
2. Minimum necessary access
Access should be limited to the smallest dataset, shortest duration, and narrowest group of authorized users necessary to complete the approved purpose.
3. User verification and accountability
DOT should verify the identity, affiliation, role, and authorization of all users. Each user should be individually accountable for compliance, not shielded by generalized institutional access.
4. Cybersecurity controls
Access should require appropriate safeguards, including secure storage, encryption, access logging, authentication, endpoint controls, incident reporting, and restrictions on transfer, copying, or external use.
5. Auditability
DOT should maintain auditable records of who accessed what data, when, for what approved purpose, and whether the access remained within authorized limits.
6. Data-use boundaries
Confidential data should not be reused, combined, redistributed, commercialized, published, or applied to unrelated purposes without express approval.
7. Breach and misuse procedures
The collection should clearly define reporting duties, containment procedures, penalties, suspension rights, and corrective action if confidential data are misused or exposed.
8. Burden and clarity
DOT should ensure that compliance requirements are clear, practical, and not unnecessarily burdensome for legitimate researchers, state and local agencies, small entities, or public-interest users.
9. Lifecycle controls
Access should expire automatically unless renewed. DOT should require data return, destruction certification, or continued-use justification at the end of the approved period.
10. Public trust
Because confidential data often involve sensitive transportation, safety, infrastructure, commercial, or operational information, DOT should treat data governance as a public-trust function, not merely an administrative form.
PAG / United Grid recommends that DOT evaluate this information collection through a decision-grade evidence standard:
* What data are being protected?
* Who receives access?
* What public value justifies the access?
* What controls reduce misuse risk?
* Who is accountable if controls fail?
* What evidence proves compliance over time?
The broader principle is simple:
Confidential data access should not rely on assumed trust.
It should rely on verified purpose, controlled access, auditable use, cybersecurity safeguards, and enforceable accountability.
Data access can improve public decision-making, but only if the access framework protects the integrity of the data, the rights of affected parties, and the credibility of the institution granting access.
Respectfully submitted,
Neil P. Osnato
Founder
Persistence Analytics Group LLC | United Grid
National Security & Infrastructure Risk Analytics
Demand Durability | Grid Stress | Load Integrity
SAM.gov registered
UEI: D3VYU39H6DX9
D-U-N-S: 142849930
CAGE: 19T34
neil@persistenceanalyticsgroup.com
609-464-9055
https://persistenceanalyticsgroup.com/