US Federal News Bureau

GAO: Agencies Failed to Provide Enough Information on DOGE Data Access

avatar

Written by: Tathagata Sen

Updated 6:26 PM EDT, September 29, 2026

post detail image

The Government Accountability Office (GAO) said it could not determine the extent of Department of Government Efficiency (DOGE) teams’ access to federal systems and data at six agencies, according to a September 29 report. The review covered DOGE access from March 2025 through September 2026.

GAO said the agencies did not provide enough information to determine the extent and level of that access or whether the systems and data were adequately protected.

According to FedScoop and NextGov/FCW, four of the six DOGE teams, across the Consumer Financial Protection Bureau (CFPB), Department of Education, Securities and Exchange Commission (SEC) and National Oceanic and Atmospheric Administration (NOAA), had access to more than 23 information systems collectively. The systems contained information related to human resources, finances, contracts and grants.

The Small Business Administration (SBA) and Department of Veterans Affairs (VA) did not provide the information GAO requested to identify which systems DOGE had accessed or the level of access granted.

Agencies Provided Limited Visibility Into Data Access

At Education, one DOGE team member had access to agency systems and its IT network, but the department did not provide details on the level of access, according to reporting on the GAO findings. At the SEC, GAO received some information about privacy and cybersecurity training but not enough to determine whether required training or controls were met for access to specific systems, including one used to manage contracts.

According to the reports, the CFPB provided information about DOGE access to its systems. Officials said DOGE was granted access to 19 systems, with one member able to view, modify and delete records in the primary HR system and three having full access to a Microsoft access-management system, but only limited documentation on privacy briefings and security training. 

The SBA did not identify the systems DOGE had accessed, while the VA did not provide a list of systems or the level of access granted.

Data Access Requires Clear Ownership and Controls

For chief data officers (CDOs), the report highlights a basic data governance requirement: organizations need visibility into who can access sensitive data, which systems they can access and what level of access they have. Without that information, data owners cannot fully assess whether appropriate controls are in place.

The findings also reinforce the need for clear accountability around data access. As agencies give employees, contractors or embedded teams access to information across organizational boundaries, CDOs need processes for documenting permissions, monitoring access and establishing responsibility for protecting the data.

GAO said that without the requested information, Congress and the public lacked assurance that the six agencies had implemented controls to ensure DOGE team members appropriately secured information.



Related Stories

Similar Topics
Artificial Intelligence
Data Management
Diversity
Testimonials
background imagebackground image
Community Network

Join Our Community

starElevate Your Personal Brand

starShape the Data Leadership Agenda

starBuild a Lasting Network

starExchange Knowledge & Experience

starStay Updated & Future-Ready

logo
Social media icon
Social media icon
Social media icon
Social media icon
About