Secure Flight Program
Federal RegisterOct 28, 2008
Ask Donna
What actually matters in this document.
Text
DEPARTMENT OF HOMELAND SECURITY
Transportation Security Administration
49 CFR Parts 1540, 1544, and 1560
[Docket No. TSA-2007-28572; Amendment Nos. 1540-9, 1544-8, and 1560-(New)]
RIN 1652-AA45
Secure Flight Program
AGENCY:
Transportation Security Administration, DHS.
ACTION:
Final rule.
SUMMARY:
The Intelligence Reform and Terrorism Prevention Act 2004 (IRTPA) requires the Department of Homeland Security (DHS) to assume from aircraft operators the function of conducting pre-flight comparisons of airline passenger information to Federal government watch lists for domestic flights and international flights to, from, and overflying the United States. The Transportation Security Administration (TSA) is issuing this final rule to implement that congressional mandate.
This final rule allows TSA to begin implementation of the Secure Flight program, under which TSA will receive passenger and certain non-traveler information, conduct watch list matching against the No Fly and Selectee portions of the Federal government's consolidated terrorist watch list, and transmit a boarding pass printing result back to aircraft operators. TSA will do so in a consistent and accurate manner while minimizing false matches and protecting personally identifiable information.
On August 23, 2007, U.S. Customs and Border Protection (CBP) published a final rule to implement pre-departure advance passenger and crew manifest requirements for international flights and voyages departing from or arriving in the United States using CBP's Advance Passenger Information System (APIS). These rules are related. After the compliance date of this Secure Flight final rule, aircraft operators will submit passenger information to DHS through a single DHS portal for both the Secure Flight and APIS programs. This will allow DHS to integrate the watch list matching component of APIS into Secure Flight, resulting in one DHS system responsible for watch list matching for aviation passengers.
DATES:
Effective December 29, 2008.
FOR FURTHER INFORMATION CONTACT:
Kevin Knott, Policy Manager, Secure Flight, Office of Transportation Threat Assessment and Credentialing, TSA-19, Transportation Security Administration, 601 South 12th Street, Arlington, VA 22202-4220, telephone (240) 568-5611.
SUPPLEMENTARY INFORMATION:
Availability of Rulemaking Documents
You can get an electronic copy using the Internet by—
(1) Searching the electronic Federal Docket Management System (FDMS) Web page at
http://www.regulations.gov
;
(2) Accessing the Government Printing Office's Web page at
http://www.gpoaccess.gov/fr/index.html
; or
(3) Visiting TSA's Security Regulations Web page at
http://www.tsa.gov
and accessing the link for “Research Center” at the top of the page.
In addition, copies are available by writing or calling the individual in the
FOR FURTHER INFORMATION CONTACT
section. Be sure to identify the docket number of this rulemaking.
Small Entity Inquiries
The Small Business Regulatory Enforcement Fairness Act (SBREFA) of 1996 requires TSA to comply with small entity requests for information and advice about compliance with statutes and regulations within TSA's jurisdiction. Any small entity that has a question regarding this document may contact the person listed in
FOR FURTHER INFORMATION CONTACT
. Persons can obtain further information regarding SBREFA on the Small Business Administration's Web page at
http://www.sba.gov/advo/laws/law_lib.html
.
Abbreviations and Terms Used in This Preamble
APIS—Advance Passenger Information System
ATSA—Aviation and Transportation Security Act of 2001
AOIP—Aircraft Operator Implementation Plan
CBP—U.S. Customs and Border Protection
DHS—Department of Homeland Security
2006 DHS Appropriations Act—Department of Homeland Security Appropriations Act, 2006
2007 DHS Appropriations Act—Department of Homeland Security Appropriations Act, 2007
DHS TRIP—Department of Homeland Security Traveler Redress Inquiry Program
FBI—Federal Bureau of Investigation
FISMA—Federal Information Security Management Act
GAO—Government Accountability Office
HSPD—Homeland Security Presidential Directive
IASTA—International Air Services Transit Agreement
IATA—International Air Transport Association
IRTPA—Intelligence Reform and Terrorism Prevention Act of 2004
NARA—National Archives and Records Administration
PNR—Passenger Name Record
PRI—Passenger Resolution Information
PIA—Privacy Impact Assessment
SFPD—Secure Flight Passenger Data
SSI—Sensitive Security Information
SORN—System of Records Notice
TSA—Transportation Security Administration
TSC—Terrorist Screening Center
TSDB—Terrorist Screening Database
VID—Verifying Identity Document
Outline of Final Rule
I. Background
II. Secure Flight Program Summary
A. Differences Between the Proposed Rule and the Final Rule
B. Secure Flight Passenger Data
C. 72-Hour Requirement
D. Instructions to Covered Aircraft Operators
E. Summary of Requirements
F. Implementation Phases of Secure Flight
1. Implementation of Secure Flight for Domestic Flights
2. Implementation of Secure Flight for Overflights and International Flights
G. Privacy Documents
H. The Watch List Matching Process Under Secure Flight
I. Operational Testing of Secure Flight
III. Response to Comments
A. Scope of the Rulemaking
1. Overflights and Foreign Air Carriers
2. Include Other Aircraft Operators in Secure Flight Program
B. Coordination with CBP and Other Government Agencies
C. Implementation and Compliance
D. Secure Flight Passenger Data (SFPD)
1. General
2. SFPD Is Not Passenger Name Record (PNR)
3. Date of Birth and Gender
4. Redress Number and Known Traveler Number
E. Watch List Matching Process
1. Transmission of SFPD
2. 72-Hour Requirement
3. Boarding Pass Issuance
4. Passenger Resolution
5. Use of the Terrorist Screening Database (TSDB)
6. Non-Traveling Individuals
7. General Comments
F. Privacy
1. General Comments
2. Required Privacy Notice
3. Privacy Impact Assessment (PIA)
4. Privacy Act Exemptions
5. System of Records Notice (SORN)
6. Retention of Data
7. Sharing of Data with Other Agencies
8. Collection and Use by Private Entities
G. Redress
H. Consolidated User Guide/Aircraft Operator Implementation Plan (AOIP)
I. Testing
J. Identification Requirements
K. Economic Comments
L. General Comments
M. Comments Beyond the Scope of the Rulemaking
IV. Rulemaking Analyses and Notices
A. Paperwork Reduction Act
B. Regulatory Impact Analysis
1. Regulatory Evaluation Summary
2. E.O. 12866 Assessment
3. Final Regulatory Flexibility Analysis (FRFA)
C. International Trade Impact Assessment
D. Unfunded Mandates Assessment
E. Executive Order 13132, Federalism
F. Environmental Analysis
G. Energy Impact
H. International Compatibility
List of Subjects
The Amendments
I. Background
TSA performs passenger and baggage screening at the Nation's commercial airports.
1
Covered aircraft operators currently supplement this security screening by performing passenger watch list matching using the Federal No Fly and Selectee portions of the consolidated terrorist watch list maintained by the Federal government, as required under security directives that TSA issued following the terrorist attacks of September 11, 2001. Covered aircraft operators also conduct this watch list matching process for non-traveling individuals authorized to enter the sterile area
2
of an airport within the United States in order to escort a passenger or for some other purpose approved by TSA.
1
See the Aviation and Transportation Security Act (ATSA) (Pub. L. 107-71, 115 Stat. 597, Nov. 19, 2001).
2
“Non-traveling individual” means as an individual to whom a covered aircraft operator or covered airport operator seeks to issue an authorization to enter the sterile area of an airport in order to escort a minor or a passenger with disabilities or for some other purpose permitted by TSA. It would not include employees or agents of airport or aircraft operators or other individuals whose access to a sterile area is governed by another TSA regulation or security directive. 49 CFR 1540.3.
“Sterile Area” means a portion of airport defined in the airport security program that provides passengers access to boarding aircraft and to which the access generally is controlled by TSA, or by an aircraft operator under part 1544 of this chapter or a foreign air carrier under part 1546 of this chapter, through the screening of persons and property. 49 CFR 1540.5.
Section 4012(a) of the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA) requires DHS to assume from air carriers the comparison of passenger information to the Selectee and No Fly Lists and to utilize all appropriate records in the consolidated and integrated watch list that the Federal Government maintains.
3
The final report of the National Commission on Terrorist Attacks Upon the United States (9/11 Commission Report) recommends that the watch list matching function “should be performed by TSA and it should utilize the larger set of watch lists maintained by the Federal government.” See 9/11 Commission Report at 393.
3
Pub. L. 108-458, 118 Stat. 3638, Dec. 17, 2004; 49 U.S.C. 44903(j)(2).
Consequently, pursuant to sec. 4012 (a) of the IRTPA, TSA issues this final rule to implement the Secure Flight program. Under the program, TSA will receive passenger and certain non-traveler information from aircraft operators. After conducting watch list matching, TSA will transmit boarding pass printing results based on watch list matching results back to aircraft operators.
II. Secure Flight Program Summary
This final rule will affect all covered flights operated by U.S. aircraft operators that are required to have a full program under 49 CFR 1544.101(a),
4
and covered flights operated by foreign air carriers that are required to have a security program under 49 CFR 1546.101(a) or (b). These aircraft operators generally are the passenger airlines that offer scheduled and public charter flights from commercial airports. This final rule refers to them as “covered U.S. aircraft operators” and “covered foreign air carriers” respectively, and “covered aircraft operators” collectively.
4
Covered U.S. aircraft operators who also operate flights under other security programs in 49 CFR 1544.101 may submit Secure Flight Passenger Data (SFPD) for their operations to TSA. 49 CFR 1560.101(a)(5).
TSA will assume the watch list matching function from aircraft operators to more effectively and consistently prevent certain known or suspected terrorists from boarding aircraft where they may jeopardize the lives of passengers and others. The Secure Flight program is designed to better focus enhanced passenger screening efforts on individuals likely to pose a threat to civil aviation, and to facilitate the secure and efficient travel of the vast majority of the traveling public by distinguishing them from individuals on the watch list.
In general, the Secure Flight program will compare passenger information only to the No Fly and Selectee List components of the Terrorist Screening Database (TSDB), which contains the Government's consolidated terrorist watch list, maintained by the Terrorist Screening Center (TSC).
5
In general, comparing passenger information against the No Fly and Selectee components of the TSDB during normal security circumstances will be satisfactory to counter the security threat versus using the entire TSDB. The No Fly and Selectee Lists are based on all the records in the TSDB and the No Fly and Selectee Lists represent the subset of names who meet the criteria of the No Fly and Selectee designations. However, as recommended by the 9/11 Commission and as required under the IRTPA, TSA may use “the larger set of watch lists maintained by the Federal government” when warranted by security considerations. For example, TSA may learn that flights on a particular route may be subject to increased security risk. Under this circumstance, TSA may decide to compare passenger information on some or all of the flights on that route against the full TSDB or other government databases, such as intelligence or law enforcement databases. Thus, TSA defines “watch list” for purposes of the Secure Flight program as the No Fly and Selectee List components of the Terrorist Screening Database maintained by the Terrorist Screening Center. For certain flights, the “watch list” may include the larger set of watch lists maintained by the Federal government as warranted by security considerations.
5
The TSC was established by the Attorney General in coordination with the Secretary of State, the Secretary of Homeland Security, the Director of the Central Intelligence Agency, the Secretary of the Treasury, and the Secretary of Defense. The Attorney General, acting through the Director of the Federal Bureau of Investigation (FBI), established the TSC pursuant to Homeland Security Presidential Directive 6 (HSPD-6), dated September 16, 2003, which required the Attorney General to establish an organization to consolidate the Federal government's approach to terrorism screening and provide for the appropriate and lawful use of terrorist information in screening processes.
After the Secure Flight program completes the comparison of passenger information, TSA will return to the covered aircraft operators the boarding pass printing result to allow the aircraft operators to begin the process for issuing boarding passes to passengers. The boarding pass printing result for each passenger will return one of the following instructions to the covered aircraft operator regarding that passenger: (1) The covered aircraft operator may issue an unrestricted boarding pass; (2) the aircraft operator may issue a boarding pass indicating that the passenger has been selected for enhanced screening; (3) or the covered aircraft operator may not issue a boarding pass to the passenger, and the passenger must come to the airport for resolution. If TSA instructs the covered aircraft operator not to issue a boarding pass to a passenger, the covered aircraft operator must comply with procedures in its security program for requesting the passenger to present a verifying identity document when the passenger checks in at the airport. The covered aircraft operator may issue a boarding pass to that passenger only after
receiving a boarding pass printing result indicating that the passenger is cleared or has been selected for enhanced screening.
The final rule covers all flights conducted by covered U.S. aircraft operators, as well as all flights conducted by a covered foreign air carrier arriving in or departing from the United States, or overflying the continental United States, defined as the lower contiguous 48 states. The final rule collectively refers to the flights conducted by U.S. carriers and covered international flights that are regulated under this final rule as “covered flights.”
IRTPA also requires DHS to assume from air carriers the task of comparing passenger information for international flights to or from the United States against the Federal government's consolidated and integrated terrorist watch list before departure of such flights. Initially, CBP will implement this requirement and conduct pre-departure watch list matching for international flights, through the Advance Passenger Information System (APIS). APIS is a widely used electronic data interchange system that commercial carriers with flights or vessel voyages arriving to or departing from the United States use to transmit electronically to CBP certain data on passengers and crew members. The former U.S. Customs Service, in cooperation with the former Immigration and Naturalization Service (INS) and the airline industry, developed APIS in 1988. On August 23, 2007, CBP published the Advance Electronic Transmission of Passenger and Crew Member Manifests for Commercial Aircraft and Vessels final rule (APIS Pre-Departure final rule) that requires air and vessel carriers to submit to CBP passenger manifest information before departure of a flight to or from the United States and for voyages from the United States to enable the DHS system to conduct watch list matching on passengers before they board an international flight or depart on certain voyages.
6
6
72 FR 48320 (Aug. 23, 2007).
In response to a substantial number of comments from the aviation industry, DHS has developed a unified approach to watch list matching for international and domestic passenger flights, to avoid unnecessary duplication of watch list matching efforts and resources and reduce the burden on aircraft operators. Pursuant to the APIS Pre-Departure final rule, the CBP system currently performs the watch list matching function for international flights to or from the United States as part of its overall screening of travelers. Ultimately, the watch list matching function for covered flights that are international air arrivals and departures will be transferred to TSA through the phased implementation of the Secure Flight rule. TSA will assume the aviation passenger watch list matching function for domestic and international passengers covered by this rule, while CBP will continue to conduct border enforcement functions. To streamline the transmission of passenger information, DHS has established one portal through which aircraft operators will send their passenger information for both programs and receive a printing result.
A. Differences Between the Proposed Rule and the Final Rule
Below is a table, which summarizes the difference between the proposed rule text in the Secure Flight NPRM and the rule text in this final rule.
Secure flight proposed rule
Secure flight final rule
Required Passenger Information in the SFPD (49 CFR 1540.107 and 1560.101)
1. Covered aircraft operators would be required to request individuals' date of birth and gender to transmit this information, if available, to TSA
1. Covered aircraft operators must collect individuals' date of birth and gender and transmit this information to TSA.
2. Individuals would not be required to provide their date of birth and gender
2. Individuals must provide their date of birth and gender.
Definition of Overflight (49 CFR 1560.3)
Overflights mean flights that overfly the continental United States
The final rule clarifies that continental United States does not include Hawaii or Alaska.
Request for and Transmission of SFPD (49 CFR 1560.101)
Covered aircraft operators would not be able to accept a reservation or request to enter the sterile area unless the individual provides his or her full name
Covered aircraft operators may accept a reservation without a full name, date of birth, or gender. For reservations made 72 hours prior to the scheduled time of departure for each covered flight, the covered aircraft operator may choose to collect full name, gender, and date of birth for each passenger when the reservation is made or at a time that is no later than 72 hours prior to the scheduled time of departure of the covered flight. For an individual that makes a reservation for a covered flight within 72 hours of the scheduled time of departure for the covered flight, the covered aircraft operator must collect the individual's full name, date of birth, and gender at the time of reservation. Covered aircraft operators may not transmit SFPD to TSA without these data elements.
Implementation Schedule (49 CFR 1560.101)
1. Covered aircraft operators would be required to request passenger information 60 days after the effective date of the final rule
Implementation schedule will be set forth in the AOIP.
2. Covered aircraft operators would be required to begin transmitting SFPD to TSA on the date set forth in their AOIP
Boarding Pass Issuance for a Covered International Flight that was Connected to a Non-Covered Flight (49 CFR 1560.105)
A covered aircraft operator may not issue a boarding pass for a covered international flight in conjunction with issuing a boarding pass for the non-covered flight unless the covered aircraft operator has obtained a boarding pass printing result from TSA permitting it to issue a boarding pass for the covered international flight
A covered aircraft operator may authorize the issuance of a boarding pass for a covered international flight in conjunction with issuing a boarding pass for the non-covered flight provided that the covered aircraft operator takes the required actions to confirm and to comply with the boarding pass printing result for the passenger prior to the passenger boarding the aircraft.
Presenting Verifying Identity Document (VID) (49 CFR 1560.105)
Covered aircraft operators must request VID from passengers for whom TSA has not provided a watch list matching result or has placed on inhibited status
The final rule clarifies that covered aircraft operators must request the VID from passengers at the airport. The VID may be presented at a kiosk that is capable of determining that the identification is a valid VID, authenticating the VID, and reading and transmitting passenger information from the VID.
Aircraft Operator Implementation Plan (49 CFR 1560.109)
Covered aircraft operators would be required to submit their AOIP to TSA within 30 days of the effective date of the final rule for approval. Once approved, the AOIP would be part of the covered aircraft operator's security program
TSA will provide the AOIP to each covered aircraft operator for them to adopt as an amendment to their security program.
B. Secure Flight Passenger Data
Under the Secure Flight program, TSA requires covered aircraft operators to collect information from passengers, transmit passenger information to TSA for watch list matching purposes, and process passengers in accordance with TSA boarding pass printing results regarding watch list matching results. 49 CFR 1560.101 and 1560.105. TSA defines this passenger information, along with other information summarized below, as Secure Flight Passenger Data (SFPD). See 49 CFR 1560.3.
For passengers on covered flights, TSA requires covered aircraft operators to request a passenger's full name, gender, date of birth, and Redress Number
7
(if available) or Known Traveler Number
8
(if available once the known traveler program is implemented). Even though covered aircraft operators are required to request all of the above data elements from passengers, passengers are only required to provide their full name, date of birth, and gender to allow TSA to perform watch list matching. TSA is not requiring individuals to provide the other data elements to aircraft operators. Covered aircraft operators must transmit to TSA the information provided by the passenger in response to the request described above.
7
A Redress Number is a unique number that DHS currently assigns to individuals who use the DHS Traveler Redress Inquiry Program (TRIP). Under the Secure Flight program, individuals will use the Redress Number in future correspondence with DHS and when making future travel reservations. The Redress Number is further discussed in the Secure Flight Information Collection Requirements section below. See § 1560.3.
8
A Known Traveler Number would be a unique number assigned to “known travelers” for whom the Federal government has already conducted a threat assessment and has determined do not pose a security threat. The Known Traveler Number is further discussed in the Secure Flight Information Collection Requirements section. See § 1560.3.
TSA notes that one of the changes between the NPRM and the final rule is the addition of this requirement that individuals are required to provide their date of birth and gender to aircraft operators. In the Secure Flight NPRM, TSA had discussed its legal authority for this rule, in general. See 72 FR 48357. With respect to this changed provision, TSA notes that it has legal authority to do so under § 4012 of the IRTPA. Section 4012 mandates that TSA obtain passenger information in order to assume the function of conducting watch list matching comparisons. In addition, TSA has broad authority to do so under the Aviation and Transportation Security Act (ATSA) (Pub. L. 107-71, Nov 19, 2001). Specifically, TSA can assess threats to transportation; enforce security-related regulations and requirements; oversee the implementation, and ensure the adequacy, of security measures at airports and other transportation facilities; require background checks for airport security screening personnel, individuals with access to secure areas of airports, and other transportation security personnel; and carry out such duties, and exercise such other powers, relating to transportation security as appropriate. See 49 U.S.C. 114(f)(2), (7), (11), (12), and (15). In conjunction with these provisions, TSA also has authority specifically for the Secure Flight Program. Under 49 U.S.C. 44903(j)(2)(C)(iv), the Assistant Secretary “shall require air carriers to supply the Assistant Secretary the passenger information needed to begin implementing the advanced passenger prescreening system.” Given that TSA is required to collect this information from air carriers, it follows that individuals must provide that information to air carriers. Air carriers would be unable to fulfill their obligation if there were not a corresponding obligation on individuals to provide their information to air carriers.
Covered aircraft operators also must transmit to TSA passport information, if available. Although TSA is not requiring covered aircraft operators to request passport information under this final rule, passengers may provide passport information pursuant to other travel requirements such as CBP APIS if a passenger is traveling abroad as part of the same reservation/itinerary. When passengers provide passport information to covered aircraft operators, the operators must transmit the passport information to a single DHS portal from which the appropriate information will be sent to TSA and CBP.
Additionally, covered aircraft operators must transmit to TSA certain non-personally identifiable information such as itinerary information and record locator numbers. This information will allow TSA to effectively prioritize watch list matching efforts, communicate with the covered aircraft operator, and facilitate an operational response, if necessary, to an individual who is on the watch list.
When a non-traveling individual seeks authorization from a covered
aircraft operator to enter an airport sterile area in the United States (such as to escort a minor or assist a passenger with a disability), covered aircraft operators must request from the non-traveler and transmit to TSA the same information requested from passengers. Non-travelers are only required to provide their full name, date of birth, and gender to allow TSA to perform watch list matching, as well as certain non-personally identifiable information, including the airport code for the sterile area in the U.S. to which the non-traveler seeks access.
The following chart details the information that TSA requires covered aircraft operators to request from passengers and certain non-traveling individuals, the information that those individuals are required to provide, and the information covered aircraft operators must transmit to TSA if available.
Information Collection Requirements for Secure Flight
Data elements
Covered aircraft
operators must
request from
passengers and
certain non-travelers
Passengers and
certain non-travelers must provide at time of reservation
Covered aircraft
operators must
transmit to TSA
if available
Full Name
X
X
X
Date of Birth
X
X
X
Gender
X
X
X
Redress Number or Known Traveler Number
X
X
Passport Information
9
X
Itinerary Information
10
X
Reservation Control Number
X
Record Sequence Number
X
Record Type
X
Passenger Update Indicator
X
Traveler Reference Number
X
C. 72-Hour Requirement
Under the Secure Flight program,
covered aircraft operators must transmit the SFPD that is available in their system, to TSA approximately 72 hours prior to the scheduled flight departure time. For reservations created within 72 hours of flight departure, covered aircraft operators must
submit SFPD as soon as it becomes available.
9
Passport information is the following information from a passenger's passport: (1) Passport number; (2) country of issuance; (3) expiration date; (4) gender; (5) full name. See § 1560.3.
10
Itinerary information is the following information about a covered flight: (1) Departure airport code; (2) aircraft operator; (3) departure date; (4) departure time; (5) arrival date; (6) scheduled arrival time; (7) arrival airport code; (8) flight number; (9) operating carrier (if available). For non-traveling individuals in the United States, the airport code for the sterile area to which the non-traveling individual seeks access. See § 1560.3.
D. Instructions to Covered Aircraft Operators
TSA matches the SFPD provided by covered aircraft operators against the watch list. Based on the watch list matching results, TSA will instruct a covered aircraft operator in its boarding pass printing result to process the individual in the normal manner, to identify the individual for enhanced screening at a security checkpoint, or to deny the individual transport or authorization to enter a U.S. airport's sterile area. To ensure the integrity of the boarding pass printing results and to prevent use of fraudulent boarding passes, TSA will also provide instructions for placing bar codes on the boarding passes in the future. TSA may provide instructions to the covered aircraft operators through an amendment to their security programs.
E. Summary of Requirements
A brief summary of the requirements in this final rule is presented below. A detailed explanation of these requirements and any applicable changes from the NPRM are provided in Section III, Response to Comments, of this final rule.
Requirements of Covered Aircraft Operators.
This final rule requires covered aircraft operators that conduct certain scheduled and public charter flights to:
• Adopt an Aircraft Operator Implementation Plan (AOIP). 49 CFR 1560.109(b).
• Conduct Operational Testing with TSA in accordance with their AOIP. 49 CFR 1560.109(a).
• Request full name, date of birth, gender, and Redress Number (if available) or Known Traveler Number (if implemented and available) from passengers and certain non-traveling individuals. 49 CFR 1560.101(a).
• Transmit full name, date of birth, and gender and any other available SFPD for passengers and non-traveling individuals seeking transport and/or authorization to enter a U.S. airport's sterile area, in accordance with the covered aircraft operator's AOIP, approximately 72 hours prior to the scheduled flight departure time. 49 CFR 1560.101(b).
• Make a privacy notice available on public Web sites and self-serve kiosks before collecting any personally identifiable information from passengers or non-traveling individuals. 49 CFR 1560.103.
• Request a verifying identity document (VID) at the airport in either of the following situations: (1) TSA has not informed the covered aircraft operator of the results of watch list matching for an individual by the time the individual attempts to check-in; or (2) if TSA informs the covered aircraft operator that an individual must be placed on inhibited status
11
and may not be issued a boarding pass or authorization to enter a U.S. airport's sterile area. A verifying identity document is one that has been issued by a U.S. Federal, State, or tribal government that: (1) Contains the individual's full name, photo, and date of birth; and (2) has not expired. 49 CFR 1560.3 and 1560.105(c).
11
“Inhibited status,” as defined in this rule, means the status of a passenger or non-traveling individual to whom TSA has instructed a covered aircraft operator or a covered airport operator not to issue a boarding pass or to provide access to the sterile area. See 49 CFR 1560.3.
• When necessary, submit information from the VID to TSA to resolve potential watch list matches. In some cases, TSA may also request that the covered aircraft operator communicate a physical description of the individual. See 49 CFR 1560.105(c).
• Not issue a boarding pass or permit an individual to board an aircraft or enter a sterile area in a U.S. airport that serves covered flights under this regulation until that individual provides a VID when requested under the circumstances described above, unless otherwise authorized by TSA. 49 CFR 1560.105(d).
• Comply with instructions from TSA to designate identified individuals for enhanced screening before boarding a covered flight or accessing a sterile area in a U.S. airport. 49 CFR 1560.105(b)(2).
• Place codes on boarding passes in accordance with TSA instructions to be set forth in the Consolidated User Guide in the future. 49 CFR 1560.105(b)(2) and (3).
Requirements of Individuals
• Individuals who wish to make a reservation on a covered flight or to access a sterile area must provide their full names, date of birth, and gender to the covered aircraft operators.
• Passengers and non-traveling individuals seeking access to a U.S. airport's sterile area, for whom TSA has not provided a watch list matching result or has provided inhibited status, must present a VID to the covered aircraft operator if they wish to board their flights. After presenting the VID, an individual may receive a boarding pass to board an aircraft or enter a sterile area if the aircraft operator receives a watch list matching result from TSA that permits the issuance of a boarding pass or authorization to enter a sterile area. 49 CFR 1540.107(c).
Government Redress Procedures Available to Individuals.
This final rule explains the redress procedures for individuals who believe they have been improperly or unfairly delayed or prohibited from boarding a flight as a result of the Secure Flight program. These individuals may seek assistance through the redress process by submitting certain personal information, as well as copies of certain identification documents, to the existing DHS Traveler Redress Inquiry Program (DHS TRIP).
12
The final rule explains the process the Federal government will use to review the information submitted and to provide a timely written response. 49 CFR part 1560, subpart C.
12
Information about DHS TRIP is available at
http://www.dhs.gov/trip.
F. Implementation Phases of Secure Flight
TSA will implement the Secure Flight program in two phases. The first phase includes covered flights between two domestic points in the United States. The second phase includes covered flights overflying the continental United States, covered flights to or from the United States, and all other flights (such as international point-to-point flights) operated by covered U.S. aircraft operators not covered in the first phase.
1. Implementation of Secure Flight for Domestic Flights
During the first phase of implementation, TSA will assume the watch list matching function for domestic flights conducted by covered U.S. aircraft operators, including those covered aircraft operators' private charter flight operations. TSA will conduct operational testing with such covered U.S. aircraft operators to ensure that the aircraft operators' systems are compatible with TSA's system. After successful operational testing with covered U.S. aircraft operators, TSA will assume the watch list matching function for domestic flights from those aircraft operators.
2. Implementation of Secure Flight for Overflights and International Flights
During the second phase of Secure Flight, TSA will require all covered aircraft operators to submit SFPD for covered flights that overfly the continental United States. The continental U.S. is defined as the contiguous lower 48 states and does not include Alaska or Hawaii. Flights that transit the airspace of the continental United States between two airports or locations in the same country, where that country is Canada or Mexico, are not included in this final rule. We discuss in further detail below the reason for excluding these flights from this final rule. Covered aircraft operators that are unsure whether a particular flight overflies the continental United States may ask TSA for a determination on whether the flight is an overflight.
The second phase of Secure Flight will also include international flights. Until TSA implements the Secure Flight program for international flights by covered U.S. and foreign aircraft operators, the CBP system will conduct pre-departure watch list matching for international flights under the APIS Pre-Departure final rule. This interim approach will allow DHS to more quickly address the threat of terrorism on flights arriving in and departing from the United States.
During the second phase of Secure Flight implementation, TSA will assume the watch list matching function for covered international flights from the CBP system. There are a few differences between TSA and CBP processes. Under the Secure Flight program, covered aircraft operators will need to request passenger information at the time of reservation or prior to transmitting the passenger's SFPD; this is not the case under the APIS Pre-Departure final rule. Also, as described below, TSA requires collection of different data elements (SFPD) under the Secure Flight program than CBP collects under the APIS regulations. For its border-control functions, which CBP will continue to perform under the APIS rule, the Department (through CBP) will continue to collect APIS data. Given this, and to provide a single point of contact, covered aircraft operators can transmit both APIS data and SFPD in a single transmission to the DHS portal, which will route information to TSA and CBP accordingly.
13
In turn, aircraft operators will receive one boarding pass printing result from DHS. The following table lists the data elements that CBP collects under its APIS regulations and that TSA will collect under the Secure Flight
14
program.
15
13
Covered aircraft operators may also submit Passenger Name Record information to CBP through this DHS portal.
14
All APIS data elements are required, except country of residence (which is not required for departure from the U.S.) and passport information (which is required only when a passport is required for travel).
15
Covered aircraft operators must provide data elements listed for Secure Flight to the extent they are available.
Data elements
APIS regulation (international flights)
14
Secure flight
regulation
15
Full Name
X
X
Date of Birth
X
X
Gender
X
X
Redress Number or Known Traveler Number
X*
Passport Number
X
X*
Passport Country of Issuance
X
X*
Passport Expiration Date
X
X*
Passenger Name Record Locator
X
International Air Transport Association (IATA) Foreign Airport Code—place of origination
X
X
IATA Code—Port of First Arrival
X
X
IATA Code of Final Foreign Port for In-transit Passengers
X
Airline Carrier Code
X
X
Flight Number
X
X
Date of Aircraft Departure
X
X
Time of Aircraft Departure
X
X
Date of Aircraft Arrival
X
X
Scheduled Time of Aircraft Arrival
X
X
Citizenship
X
Country of Residence
X
Status on Board Aircraft
X
Travel Document Type
X
Alien Registration Number
X
Address While in U.S.—(except for outbound flights, U.S. citizens, lawful permanent residents, crew and in-transit passengers)
X
Reservation Control Number
X
Record Sequence Number
X
Record Type
X
Passenger Update Indicator
X
Traveler Reference Number
X
* If available.
If passenger information that is required under this final rule resides in covered aircraft operators' systems, covered aircraft operators must transmit the SFPD information to TSA. Covered aircraft operators must submit this information, through the same DHS portal used for APIS submissions, approximately 72 hours before departure of a covered flight, or if a passenger books after this 72 hour mark, as soon as that information becomes available. Those that elect to transmit the SFPD and all manifest information required under the APIS Pre-Departure final rule at the same time would be able to send a single transmission to DHS for the Secure Flight and APIS Pre-Departure programs and would receive a single boarding pass printing result in return.
Additionally, for reservations made within 72 hours of the scheduled flight departure time, covered aircraft operators must submit SFPD as soon as the information becomes available. If the covered aircraft operator is also required and ready to transmit APIS information at that time, the covered aircraft operator is able to send one transmission for both Secure Flight and APIS Pre-Departure and will receive one boarding pass printing result. If the covered aircraft operator does not have full and complete APIS data as required under the APIS Pre-Departure rule, the covered aircraft operator must transmit the passenger information required for Secure Flight, at a minimum.
Covered aircraft operators will use the same portal to transmit SFPD to TSA and APIS data to CBP. TSA will need to conduct operational testing with the covered U.S. aircraft operators and covered foreign air carriers to confirm that the Secure Flight process operates properly from end-to-end with these carriers.
After TSA assumes responsibility for the watch list matching function under phase two of the Secure Flight program, the CBP system will no longer be responsible for pre-departure watch list matching or the issuance of related boarding pass printing results for covered flights based on watch list matching results. Consequently, covered aircraft operators will receive, and have to comply with, one result from DHS, via TSA, regarding the issuance of boarding passes to or the boarding of passengers on covered international flights. CBP will, however, continue to require carriers to provide APIS data to carry out its border enforcement mission.
In some international airports, passengers may transit from one international flight to another, where the flights are operated by different aircraft operators and only the second flight may be covered under this final rule. TSA understands that currently, in these situations, the aircraft operator operating the first flight may issue a boarding pass for both portions of the passenger's itinerary, including the flight to the United States. Under the Secure Flight program, TSA will not prevent the aircraft operator operating the first flight from issuing a boarding pass for the second flight. The covered aircraft operator whose flight will arrive in, or overfly the United States is responsible for preventing the boarding of passengers for whom TSA has returned an inhibited boarding pass printing result. Additionally, the covered aircraft operator should ensure that passengers for whom TSA has returned a Selectee boarding pass printing result are subjected to enhanced screening prior to boarding. Covered aircraft operators must also comply with measures in their security program to ensure that they have confirmed the boarding pass status of each passenger who receives a boarding pass for a covered flight under these circumstances. They may not rely on a lack of markings on a boarding pass issued by another aircraft operator; covered aircraft operators must take their direction from TSA.
G. Privacy Documents
TSA is committed to safeguarding individuals' privacy in conducting the Secure Flight program to the greatest extent possible. In conjunction with this final rule, TSA has published a Privacy Impact Assessment (PIA) and a Privacy Act System of Records Notice (SORN),
16
DHS/TSA 019. A final rule that explains the Privacy Act exemptions for the Secure Flight program was published in
the
Federal Register
.
17
These three documents outline how TSA collects, uses, stores, protects, retains, and shares personally identifiable information collected and used as part of the Secure Flight program. Furthermore, TSA has identified the privacy risks and mitigation measures that will be employed to reduce or eliminate privacy risks such as false positive matches or insufficient safeguards for the information. All three documents are available at
http://www.tsa.gov
.
16
72 FR 63711 (Nov. 9, 2007).
17
72 FR 63706 (Nov. 9, 2007).
H. The Watch List Matching Process Under Secure Flight
This Secure Flight final rule requires all covered aircraft operators to request the information discussed above from passengers on a covered flight and certain non-traveling individuals. The final rule, however, does not require all covered aircraft operators to begin transmitting that information to TSA at the same time. TSA will bring covered aircraft operators into the Secure Flight program in phases and require all covered aircraft operators to begin providing passenger and certain non-traveler information to TSA in accordance with the deadlines set forth in their approved AOIP, discussed further below.
TSA requires covered aircraft operators to transmit information to TSA approximately 72 hours in advance of departure unless one of the following occurs: The individual makes a reservation with the covered aircraft operators within 72 hours of the scheduled flight departure time; there are changes to the name, date of birth, gender, Redress Number, Known Traveler Number, or passport information on a reservation within 72 hours of the scheduled flight departure time; there are changes to a flight within 72 hours of the scheduled flight departure time; or the individual requests to enter a sterile area upon arrival at the airport. In such cases, TSA requires covered aircraft operators to send the required information to TSA as soon as it becomes available. TSA, in coordination with the TSC where necessary, will compare the passenger and certain non-traveler information obtained from each covered aircraft operator to information contained in the watch list. TSA will also compare passenger and certain non-traveler information to a list of individuals who have previously been distinguished from persons on the watch list.
If an automated comparison using the information transmitted to TSA indicates that the passenger is not a match to the watch list, TSA will notify the covered aircraft operator that check-in and boarding pass issuance for the individual can proceed normally. Such individuals will undergo standard passenger and baggage screening, which may include additional, random screening. If an automated comparison using the non-traveler information identifies a potential match to the watch list, the covered aircraft operator must not allow access to the sterile area for that individual unless further resolution procedures indicate otherwise or authorized by TSA.
TSA will complete the watch list matching process for, and permit covered aircraft operators to issue boarding passes to, the vast majority of passengers through this fully-automated initial comparison. If the automated comparison indicates a reasonably similar or exact match to a person on the watch list, TSA will inform the covered aircraft operator that the individual must be placed on inhibited status and consequently the covered aircraft operator may not issue a boarding pass or other authorization to enter the sterile area for that individual unless further resolution procedures indicate otherwise. If the SFPD for that individual contains sufficient data, a TSA analyst will review all available information to determine if the passenger appears to be the individual on the watch list. If necessary, the TSA analyst will check other classified and unclassified governmental terrorist, law enforcement, and intelligence databases, including databases maintained by the Department of Homeland Security, Department of Defense, National Counter Terrorism Center, and Federal Bureau of Investigation (FBI), in order to resolve the possible match between the individual and a person on the watch list.
This careful review process is intended to significantly reduce the number of false positive matches identified by the automated watch list check. If the TSA analyst determines that the individual is not a match to the watch list, TSA will inform the covered aircraft operator that the individual no longer has inhibited status, and the covered aircraft operator may issue a boarding pass or authorization to enter a sterile area to that individual. If the TSA analyst identifies a possible match between a passenger and an individual identified on the watch list, TSA will send the passenger information to TSC and request confirmation of the match.
The final rule provides that if TSA or TSC cannot determine from the information provided by the covered aircraft operator whether an individual is a match to the watch list prior to the individual's arrival at the airport or online check-in, it will be necessary for the individual to provide additional information at the airport. Pursuant to the procedures in the security program, the covered aircraft operator must request that the individual present a VID when he or she arrives at the airport. A VID must be an unexpired form of identification that was issued by a U.S. Federal, State, or tribal government, and contains the individual's full name, photo, and date of birth, or an unexpired passport issued by a foreign government. TSA may also authorize other types of identity documents that may be used as a VID. TSA will notify the public when it authorizes another type of identity document that may be used as a VID. TSA may use one or more of the following methods to notify the public: A notice published in the
Federal Register
; a public affairs announcement; and an announcement on TSA's Web site. This requirement would not replace current requirements that covered aircraft operators request all passengers and non-traveling individuals to provide identification, such as at check-in or at the screening checkpoint.
Covered aircraft operators must follow the procedures in its security program for requesting and reviewing a VID from an individual. Examples of such procedures are that the covered aircraft operator may request that the individual present a VID: (1) To an agent at a ticket counter; and (2) at a self-serve kiosk that is capable of determining that the identification is a valid VID, authenticating the VID, and reading and transmitting passenger information from the VID. Covered aircraft operators may also submit a request to TSA for approval of other procedures for requesting and accepting a VID through the security program amendment process in § 1544.105(b).
Once the individual provides a VID to the covered aircraft operator or swipes the VID at a kiosk, the aircraft operator must update the passenger's SFPD with the additional information from the individual's VID and transmit it to TSA. There may be occasions where the aircraft operator will need to call TSA. In such cases, the aircraft operator may be asked to provide additional identifying information, such as a physical description referred to as “Passenger Resolution Information” (PRI), that TSA may need to complete the watch list matching process, in coordination with the TSC, and provide the aircraft operator with watch list matching results for that individual.
Covered aircraft operators will not submit this PRI to TSA electronically. Rather, an aircraft operator will provide this information over the telephone to TSA.
Where warranted, TSA may notify another Federal agency or other public, private, or foreign government entity as appropriate to initiate an operational response to a potential watch list match.
18
TSA will provide the agency or entity with sufficient information about the passenger and his or her itinerary to facilitate coordination of the operational response. TSA may also notify the Federal Security Director, Federal Air Marshals, or other law enforcement personnel responsible for airport security to facilitate a timely law enforcement response to an individual identified in the watch list. Further inquiry by law enforcement may, for example, help resolve a situation of mistaken identity or confirm a determination made in the matching process that an individual should be denied boarding or entry to a sterile area.
18
For the types of public and private entities that TSA may notify, see “Routine Uses of Records Maintained in the System, Including Categories of Users and Purpose of Such Uses” in the
Federal Register
notice entitled, “Privacy Act of 1974: System of Records; Secure Flight Records.” 72 FR 63711 (Nov. 9, 2007).
If TSA determines that the passenger is a match to the Selectee List, TSA will notify the covered aircraft operator that the passenger and his or her baggage must be identified for enhanced screening by TSA. If TSA determines that the passenger is a match to the No Fly List, the covered aircraft operator must not issue a boarding pass to the passenger unless authorized by TSA.
In the preamble to the Secure Flight NPRM, TSA described the resolution process for the potential matches to the No Fly List but did not discuss a resolution process for potential matches to the Selectee List.
19
Because it is an important security measure to confirm whether a passenger is an individual on the Selectee List, TSA is applying the same resolution process for potential matches to the Selectee List as it applies to potential matches to the No Fly List. This resolution process will reduce the number of passengers who may be misidentified as a match to the Selectee List and will allow these passengers to enter the sterile area without undergoing enhanced screening for Selectees. (This does not ensure that such passengers will not always avoid enhanced screening. Random procedures employed by TSA result in enhanced screening.) TSA may also authorize alternate resolution procedures in a covered aircraft operator's security program to address unique circumstances.
19
72 FR 48356, 48365-66 (Aug. 23, 2007).
The Secure Flight NPRM also proposed that passengers with an inhibited status would present their VID to the agent at the airport ticket counter. See proposed § 1560.105(b)(1). TSA is revising the rule text to state that covered aircraft operators must request VIDs from individuals at the airport. The language change will allow a covered aircraft operator the flexibility to request and accept VID at the ticket counter, at a self-serve kiosk, or through other processes or technology that the covered aircraft operator may develop, subject to TSA approval.
I. Operational Testing of Secure Flight
As part of the implementation of the Secure Flight program, TSA will conduct operational testing of TSA's capabilities to interact with and perform watch list matching for each covered aircraft operator shortly after the effective date of this final rule and before assuming the watch list matching function from each covered aircraft operator. During the operational testing for each covered aircraft operator, the covered aircraft operator will establish data transmission connections to TSA through an established DHS portal, and TSA will test its ability to receive passenger and non-traveler information, conduct watch list matching and transmit watch list matching results back to the aircraft operator in real time. Operational testing will allow TSA to refine program operations and ensure that TSA will be able to effectively conduct watch list matching for passengers and non-traveling individuals of each covered aircraft operator before TSA assumes the watch list matching function.
Covered U.S. aircraft operators will continue to match passengers against the watch lists for domestic flights under current procedures during their operational test phase and will maintain responsibility for denying issuance of boarding passes or identifying individuals for enhanced screening as a result of their own watch list matching determinations. If, during operational testing, TSA identifies a match to the No Fly or Selectee Lists that a covered aircraft operator has not identified, TSA may identify such passengers to the TSC and the covered aircraft operator for appropriate action. Once TSA officially notifies a carrier that they have successfully completed testing and that TSA has assumed the watch list matching function from a covered aircraft operator, the aircraft operator will discontinue conducting watch list comparisons for passengers and non-traveling individuals.
For international flights, covered U.S. aircraft operators must follow the CBP result in accordance with the APIS Pre-Departure final rule until TSA informs the covered U.S. aircraft operator that it will assume the watch list matching function. Foreign air carriers must also follow the CBP system boarding pass printing results in accordance with the APIS Pre-Departure final rule during operational testing and until TSA informs the covered foreign air carriers that TSA will assume the watch list matching function.
TSA will provide prior written notification to each covered aircraft operator of the date on which it will assume the watch list matching function from that covered aircraft operator. Because operational testing will begin with covered aircraft operators in phases, TSA will transition to implementation in phases as well and may continue operational testing with some covered aircraft operators while beginning implementation with others.
III. Response to Comments
TSA received 337 comments on the Secure Flight NPRM. These comments were submitted by a broad cross-section of parties with an interest in the function of conducting preflight comparisons of airline passenger information to Federal government watch lists for international and domestic flights. Commenters included domestic aircraft operators, foreign air carriers, privacy advocacy groups, and travel agency organizations. These comments are addressed below, and are organized by major issue.
A. Scope of the Rulemaking
Comment:
Many commenters argued that the Secure Flight program is unconstitutional and infringes on an individual's freedom of movement, assembly, and right to travel. A commenter also argued that the Secure Flight program violates Article 12 of the International Covenant on Civil and Political Rights (ICCPR) because it restricts “liberty of movement.”
TSA Response:
TSA disagrees with the comments. The Government may place reasonable restrictions on the right to travel in order to protect compelling interests; in this case, transportation and national security. The Secure Flight program does not deny individuals their right to travel or other constitutional rights. Courts have consistently held that travelers do not have a constitutional right to travel by a single mode or the most convenient form of
travel. The Secure Flight program would only regulate one mode of travel (aviation) and would not impose any restriction on other modes of travel. Thus, Secure Flight does not unlawfully infringe or restrict individuals' freedom of movement or assembly. Also, the Secure Flight regulations are reasonable and are not onerous or unduly burdensome to individuals.
Additionally, Article 12 of the ICCPR does not apply to laws that are necessary to protect national security. Because the purpose of the Secure Flight program is to protect national security, Article 12 would not apply even if the Secure Flight program did somehow restrict liberty of movement.
1. Overflights and Foreign Air Carriers
Comment:
Several commenters expressed concern about the Federal government collecting information in the case of overflights from individuals who have no intention of entering the United States. Several commenters argued that including overflights within the scope of Secure Flight may violate international treaties such as the Convention on International Civil Aviation (Chicago Convention).
TSA Response:
U.S. regulations currently require aircraft touching ground in the United States to deny transportation to any passenger appearing on the U.S. No Fly List. The Secure Flight program will extend application of this rule to aircraft that only fly through U.S. airspace, without actually touching ground in the United States. The international legal bases under which a State might deny overflight to aircraft that fail to comply with the State's security-based regulations are outlined below.
Although international law recognizes the general right of overflight,
20
it also recognizes a State's right to regulate aircraft entering into, within or departing from its territory. Moreover, the Chicago Convention expressly recognizes that each State has sovereignty over its airspace.
20
For example, the Chicago Convention, Article 5 and the International Air Services Transit Agreement (IASTA), Article I, Section 1.
The Chicago Convention, the International Air Services Transit Agreement (IASTA), and the U.S. model open skies agreement all contain provisions requiring aircraft in U.S. territory to comply with a broad array of U.S. laws and regulations. Article 11 of the Chicago Convention requires compliance with “the laws and regulations of a contracting State relating to the admission to or departure from its territory of aircraft engaged in international air navigation, or to the operation and navigation of such aircraft while within its territory.” Similarly, Article 13 requires compliance with a State's laws and regulations “as to the admission to or departure from its territory of passengers, crew or cargo of aircraft * * * upon entrance into or departure from, or while within the territory of that State.” These Chicago Convention obligations are incorporated by reference in Article I, Section 2, of IASTA, and are restated in Article 5 of the model open skies agreement.
The domestic laws and regulations with which compliance is mandated are defined broadly and may include security-based measures, such as Secure Flight. This is reinforced by the security provisions in most U.S. bilateral air services agreements. Those provisions generally obligate our bilateral partners to observe and assist the U.S. Government in its enforcement of U.S. security-based regulations. For instance, Article 7 of the U.S. model open skies agreement obligates each party to observe the “security provisions required by the other party for entry into, for departure from, and while within the territory of that other [p]arty, and to take adequate measures to protect aircraft and to inspect passengers * * * prior to and during boarding or loading.” Model Article 7 also imposes specific obligations on our bilateral partners to assist in preventing unlawful acts against the safety of aircraft, and “to address any other threat to security of civil air navigation.”
Moreover, in the event that an airline fails to comply with the laws and regulations with which compliance is mandated, both IASTA and most U.S. bilateral agreements grant a State the option of revoking or denying that airline's operating authorizations or technical permissions. Under Article I, Section 5, of IASTA, each State reserves the “right to withhold or revoke a certificate or permit to an air transport enterprise of another State * * * in case of failure of such air transport enterprise to comply with the laws of the State over which it operates.” Similar rights exist in almost all U.S. bilateral agreements. For example, Article 4 of the U.S. model open skies agreement provides that either party may “revoke, suspend or limit the operating authorizations or technical permissions” of an airline of the other party in the event that that airline has failed to comply with the laws and regulations with which compliance is mandated.
Accordingly, TSA's Secure Flight program does not violate international treaties, such as the Chicago Convention, and is entirely consistent with and is buttressed by international and bilateral agreements.
Comment:
TSA received several comments opposed to including overflights in the scope of the final rule. Some commenters argued that overflights are an overextension of the Secure Flight mission. Other commenters suggested that overflights will cause costly system and operational changes for flights that did not require collection of APIS data or SFPD previously. Another commenter suggested that it would not be possible for third party agents to know if data collection was required for a particular flight since they do not have any knowledge of which flights qualify as an overflight.
TSA Response:
Flights that overfly the United States have the potential to cause harm within the United States due their proximity to sensitive areas that may be potential terrorist targets such as major metropolitan areas and critical infrastructure. The Secure Flight program will provide TSA the ability to determine whether a passenger on an overflight poses a potential threat to national or transportation security. TSA acknowledges that there are costs associated with including overflights within the scope of Secure Flight but believes that the security benefit justifies the cost. If a covered aircraft operator is unsure whether a particular flight overflies the United States, TSA will provide assistance in determining whether that flight is an overflight. The covered aircraft operator will be responsible for informing their third party agents of the flights that are overflights.
Comment:
Several commenters raised concerns regarding unplanned overflights. Commenters provided examples of situations such as diversions for weather, emergency, medical, or mechanical reasons when a flight may be diverted into U.S. airspace. These commenters suggested that TSA not require data collection for unplanned overflights.
TSA Response:
As stated above, TSA will assist covered aircraft operators in determining which flights are overflights. TSA is not likely to consider flights that occasionally overfly the United States due to weather diversions or emergencies to be overflights.
Comment:
Several commenters indicated concern that this provision may set a precedent for other countries to invoke overflight data collection requirements that would be costly to implement and present an inconvenience to U.S. passengers.
TSA Response:
The Federal government understands that countries have a legitimate interest in protecting their territory from potential threats from overflights. DHS will work and coordinate with the governments of those countries to determine data collection requirements that would enhance security.
Comment:
TSA received several comments about exemptions to the overflight provision. A commenter requested that any geographic exceptions to the Secure Flight final rule allow for the designation of low-risk areas to be consistent with the overall purpose of security and to take into account the risk associated with diverting air traffic to lower risk geographic areas. Another commenter expressed support for any efforts to decrease the number of flights this would apply to, based on selected geographic areas.
TSA Response:
This final rule allows the Assistant Secretary (Transportation Security Administration) to exempt certain overflights from the Secure Flight program. In determining whether to exempt a particular flight or category of flights, TSA will take into consideration the security implications of exempting such flights, including the geographic locations of the overflights.
Comment:
One commenter questioned why flights that are not subject to this final rule, for example those flights that overfly the U.S. with an origin and destination in Canada, pose less of a risk to U.S. aviation security than a flight originating in Canada and flying to another destination, for example the Caribbean. One commenter sought confirmation that all airlines overflying U.S. territory would be subject to the same requirements, irrespective of their nationality. The Canadian Embassy requested that all flights to, from, and within Canada that overfly the U.S. be exempt from the Secure Flight final rule in light of the security initiatives that Canada has in place and the security cooperation between Canada and the United States.
TSA Response:
Flights between two Canadian locations or between two Mexican locations that overfly the United States are likely to merely skirt the border with the United States or enter U.S. airspace only for a brief period of time. This provision applies to all covered aircraft operators regardless of their country of nationality. All covered aircraft operators must comply with the Secure Flight rule for all other flights that overfly the continental United States, regardless of nationality.
TSA is not exempting all overflights that originate from Canada, because most international flights originating from Canada overfly a significant portion of the United States. As stated above, TSA has determined that conducting watch list matching of passengers on these flights is an important security measure to protect national and transportation security.
However, the Assistant Secretary may exempt categories of flights that overfly the United States as provided in § 1560.3. TSA will consider requests to exempt certain categories of flights and will consider all the applicable factors, including the security risks and the benefits from doing so. For instance, TSA will consider whether the country requesting the exemption applies a no fly list system to flights that may affect the security of the United States, whether that no fly list system will provide robust protection from persons who may endanger the flights, and whether the requesting country sufficiently shares information with the United States.
Comment:
Some commenters expressed support for the limitation of the overflight provision to the continental United States. However, the Canadian Embassy and other commenters requested clarification of the definition of “continental United States” as it applies to the overflight provision of the Secure Flight final rule.
TSA Response:
TSA agrees that the definition should be clarified. The definition of “overflying the continental United States” in this final rule has additional language that clearly states that the continental United States includes the lower 48 states and does not include Alaska or Hawaii.
2. Include Other Aircraft Operators in Secure Flight Program
Comment:
TSA received one comment from an individual who suggested that TSA include all-cargo operators within the scope of the Secure Flight rule, because many all-cargo aircraft operators also transport individuals who are not flight crew members, such as couriers and animal handlers. The commenter was concerned that these individuals may be foreign nationals, and they frequently sit immediately outside the flight deck on these all-cargo flights.
TSA Response:
During development of the Secure Flight program, TSA determined that the scope of the initial Secure Flight implementation phases should include only those aircraft operators that are required to have a full security program under 49 CFR 1544.101(a), and foreign air carriers that are required to have a security program under 49 CFR 1546.101(a) or (b). These aircraft operators are the passenger airlines that offer scheduled and/or public charter flights from commercial airports. TSA has decided to limit the scope of the Secure Flight final rule to these aircraft operators in order first to focus on those areas that raise the most aviation security concerns. After successful implementation of the original population of covered aircraft operators, TSA will consider broadening Secure Flight's scope to include other categories of aircraft operators. In the interim, the all-cargo operators must conduct watch list matching for these individuals.
Comment:
A commenter requested TSA modify the Secure Flight final rule to accommodate the processes of private charter carriers.
TSA Response:
In the Secure Flight NPRM, TSA proposed to limit the scope of the Secure Flight program to U.S. aircraft operators that are required to have a full security program under 49 CFR 1544.101(a), and covered flights operated by foreign air carriers that are required to have a security program under 49 CFR 1546.101(a) or (b). Many U.S. aircraft operators also operate private charter operations that are subject to the requirements in 49 CFR 1544.101(f), which include requiring aircraft operators to conduct watch list matching of the passengers. TSA recognizes that it may be more efficient for the covered U.S. aircraft operators to submit the names of passengers on their private charters to Secure Flight for watch list matching. Consequently, the definition of covered flight includes private charter flights operated by covered U.S. aircraft operators. TSA intends to implement Secure Flight for other private charter flights through future rulemakings.
Comment:
One commenter requested that TSA require foreign air carriers conducting private charter passenger operations to and from the United States to adopt and carry out a security program. Alternatively, the commenter requested that TSA include foreign operators of private charter flights within the scope of the Secure Flight program instead of the existing TSA/FAA airspace waiver procedures for flights entering, departing, or overflying U.S. airspace.
TSA Response:
TSA appreciates the comments received concerning aircraft operators covered under this final rule. TSA did not propose, however, to require foreign air carriers not currently subject to an existing security program to adopt a security program or to apply the Secure Flight requirements on these foreign air carriers as part of this Secure Flight rulemaking.
However, foreign air carriers operating flights to and from the United States are subject to the APIS Pre-Departure final rule under which DHS will perform watch list matching of the passengers on their flights.
Comment:
TSA received several comments from aircraft operators arguing that airlines do not have the ability to impose Secure Flight requirements on travel agents and other third parties. A commenter suggested the government should mandate travel agencies to collect full name in the reservation and place a privacy notice on associated Web sites.
TSA Response:
TSA disagrees that covered aircraft operators are unable to require travel agents and other third parties that sell tickets for their flights to collect the necessary passenger information. Because aircraft operators control the inventory of seats on their airplanes, TSA believes that it is reasonable to expect that aircraft operators will include in their agreements with third party agents who sell tickets on the aircraft operator's behalf a requirement to collect the necessary data for the aircraft operator to comply with this rule.
Additionally, the requirement to include the Privacy Act Statement on Web sites only applies to Web sites where passenger information is collected to create the SFPD that will be sent to TSA. Third-party Web sites that provide information about their services but do not collect passenger information that create SFPD do not need to post the Privacy Act Statement.
Comment:
A commenter agreed with TSA's definition of a non-traveling individual, which does not include employees or agents of an airport or aircraft operator.
TSA Response:
TSA appreciates the commenter's support of Secure Flight's definition of a non-traveling individual.
Comment:
TSA received some comments urging TSA to include watch list matching of covered aircraft operators' employees and other employees that must undergo watch list matching within the scope of Secure Flight. Similarly, a few carriers requested clarification on whether TSA plans to perform this function.
TSA Response:
TSA agrees that comparing the names of covered aircraft operators' employees and other employees against the watch list is an important layer of security and that the Federal government should assume the responsibility for conducting the watch list matching for this population. TSA has decided to focus the Secure Flight program on watch list matching of passengers as part of this final rule. TSA plans to assume responsibility for watch list matching of employees. TSA has begun the process by conducting watch list matching for certain persons at commercial airports.
B. Coordination With CBP and Other Government Agencies
TSA received several comments expressing support for both the Secure Flight and APIS Pre-Departure programs. Several commenters indicated their support for the shift of responsibility for passenger watch list matching from the air carriers and CBP to TSA. TSA received several comments expressing support for the “One DHS Solution” approach proposed for the Secure Flight and CBP APIS Pre-Departure programs whereby covered aircraft operators would send passenger information through one portal for both programs.
Comment:
One commenter requested that DHS and other agencies coordinate Secure Flight's requirements with other U.S. and non-U.S. government data collection requirements.
TSA Response:
DHS oversaw the development of the Consolidated User Guide to standardize requirements and minimize the impact to covered aircraft operators for implementation of both the Secure Flight and the APIS Pre-Departure programs. DHS will continue to work and coordinate with other Federal government agencies and other countries to develop and implement common data collection requirements to address the security concerns of the Federal government and the governments of other countries.
Comment:
TSA received a comment expressing concern that CBP and covered aircraft operators would be required to act upon TSA's watch list matching results without a process in place for quality assurance and review.
TSA Response:
TSA will implement a number of quality control measures as part of the Secure Flight program to ensure that the processes and procedures for watch list matching and returning results to covered aircraft operators are accurate and timely. TSA cannot provide further detail as to the control measures in place as they are Sensitive Security Information (SSI).
21
However, TSA is confident that these measures will ensure the accuracy of the program.
21
“Sensitive Security Information” or “SSI” is information obtained or developed in the conduct of security activities, the disclosure of which would constitute an unwarranted invasion of privacy, reveal trade secrets or privileged or confidential information, or be detrimental to the security of transportation. The protection of SSI is governed by 49 CFR part 1520.
Comment:
TSA received several comments expressing concern and requesting clarification on the differences in requirements for the APIS Pre-Departure final rule and Secure Flight NPRM. They questioned the need to send TSA SFPD 72 hours before the flight departure while APIS Pre-Departure requires batch transmission no later than 30 minutes before the securing of the aircraft door or APIS Quick Query (AQQ) transmission up to the securing of the aircraft door.
TSA Response:
From the perspective of covered aircraft operators, there are two major differences from APIS Pre-Departure and Secure Flight. First, TSA and CBP require different sets of data elements for their respective programs with some identical data elements. The chart above in section II of this final rule, Secure Flight Program Summary, compares the required and optional data elements for each program. Additionally, the timing of the transmission of the data elements is different for each program. As explained above in section II of this final rule, Secure Flight Program Summary, TSA will require covered aircraft operators to transmit all available SFPD 72 hours before the scheduled departure of the flight and for reservations made within 72 hours, and other SPFD as soon as they become available. Under the APIS Pre-Departure rule, CBP requires commercial air carriers to transmit APIS information 30 minutes before the securing of the aircraft door if the transmission is a batch transmission and up to the securing of the aircraft doors for AQQ transmissions.
While both rules will be used in our nation's fight against terrorism, the two rules have somewhat different purposes. The purpose of the APIS rule is to protect our nation's borders by evaluating the risk associated with passengers entering or leaving the United States. Generally, CBP conducts this analysis prior to passengers arriving in or departing the United States, to ensure more efficient and expeditious processing of legitimate travelers. By the time passengers arrive into the United States, CBP has completed its analysis and determined the appropriate operational response when the passengers present themselves to the CBP officer.
The purpose of the Secure Flight program is to protect aviation security by conducting watch list matching of the names of passengers and non-travelers. TSA must complete its watch list matching prior to the individuals' receiving a boarding pass or
authorization to enter a sterile area. Many passengers prefer to obtain their boarding passes 24 hours before departure. By receiving the SFPD 72 hours before departure, TSA will be able to allow the majority of passengers to obtain their boarding passes 24 hours in advance.
DHS' goal is to consolidate the watch list matching process into the Secure Flight program, including the timing of the transmission of passenger information for watch list matching. The watch list matching component of the APIS Pre-Departure final rule is an interim solution until such time that the Secure Flight program can assume responsibility for watch list matching for international flights. Although CBP requires that aircraft operators send batch transmission no later than 30 minutes before the securing of the aircraft doors, it allows and encourages aircraft operators to transmit the passenger information as early as 72 hours before the flight. As stated below in the excerpt from the APIS Pre-Departure final rule, CBP and DHS recognized that earlier transmission of the data benefits the aircraft operators and the passengers, including reducing the risk that passengers may miss their flights while TSA conducts further analysis.
Advance transmissions will enable earlier vetting by CBP and earlier issuance of boarding passes by carriers if warranted by vetting results, relieving the pressure that a high volume of later transmitted data could have on the carriers' operations. DHS believes that earlier transmissions, though not required, would be to the carriers' advantage and encourages carriers to adopt it as a best business practice.
In addition, carriers have requested that CBP allow manifest data transmissions as early as 72 hours prior to departure. CBP agrees that such early transmissions, which DHS encourages carriers to adopt as a best business practice, would generate early vetting results, subject to later validation by the carrier (swiping of passport or other travel document or examination of document by carrier personnel), and allow early issuance of boarding passes, resulting in fewer passengers to be vetted within the 30-minute window and a reduced risk of passengers missing their flights while further vetting is conducted. APIS Pre-Departure final rule, 72 FR at 48323, 48329.
Comment:
Some commenters suggested that TSA did not fulfill the aim of the “One DHS Solution,” because Secure Flight would create a process for watch list matching that differs from the process already under implementation by the airlines for APIS Pre-Departure programs and systems. These commenters suggested that the Secure Flight requirements would obstruct processing recently put into place and require further investments by the covered aircraft operators to update systems and processes. Several aircraft operators requested that Secure Flight further align the two programs. Specifically, aircraft operators suggested that Secure Flight require the same data elements and data transmission timeframe as APIS in order to avoid the time and cost associated with updating their systems twice. Several commenters also requested that TSA align requirements with CBP so that aircraft operators are only required to submit one data transmission to DHS and receive one response in return.
TSA Response:
TSA has worked with CBP to align the Secure Flight and APIS Pre-Departure programs and systems. TSA and CBP jointly created the Consolidated User Guide to standardize requirements and minimize the impact to aircraft operators. In the Consolidated User Guide, TSA provided additional clarification that describes the technical and operational guidance for both programs.
Under the CBP APIS Pre-Departure final rule, aircraft operators are required to send APIS data for international flights to CBP. Secure Flight requires that covered aircraft operators provide SFPD to TSA as outlined in this final rule.
Secure Flight will not necessarily require multiple data transmissions to and responses from DHS. Covered aircraft operators may transmit both APIS data and SFPD in a single transmission to the DHS portal, which will route information to TSA and CBP as appropriate. These covered aircraft operators will receive a single boarding pass printing result in return.
CBP described the procedures for when aircraft operators submit APIS data prior to a passenger's presenting his or her travel document at the airport in its APIS Pre-Departure final rule:
[T]he CBP system has the ability to accept certain passenger data up to 72 hours in advance, including APIS data. Such very early transmissions would be more likely under either of the batch transmission options, as AQQ transmissions are more likely to occur in closer proximity to the time or day of the flight. However, as mentioned previously, any early “cleared” vetting result obtained in this process is considered provisional by CBP until the passport or other travel document is validated, either by the swiping of the travel document's machine-readable zone or through manual verification by the carrier. Successful validation by the carrier of any passenger holding a provisional boarding pass as herein described (i.e., based on early data transmission and early receipt of a “cleared” response) requires that the APIS passenger data checked during validation be identical to the passenger data transmitted early to obtain the boarding pass. Where the data transmitted differs from data presented at validation, the carrier must transmit the new data and obtain vetting clearance on that data. Until that occurs, the carrier may not allow the passenger to board. 72 FR at 43822.
Additionally, for reservations made within 72 hours of scheduled flight departure time, covered aircraft operators must transmit SFPD as soon as possible. If the covered aircraft operator is also ready to transmit APIS information at that time, the covered aircraft operator will be able to send one transmission for both Secure Flight and APIS and will receive one boarding pass printing result. If the covered aircraft operator is not ready to transmit passenger data under the APIS Pre-Departure final rule at the same time, the covered aircraft operator must transmit the passenger information separately for Secure Flight and APIS.
Once TSA assumes responsibility under Secure Flight for the watch list matching function for the majority of passengers covered by the APIS Pre-Departure final rule, the CBP system will no longer be responsible for pre-departure watch list matching or the issuance of related boarding pass printing results for covered flights. Consequently, covered aircraft operators will receive, and will have to comply with, one result from DHS through TSA regarding the issuance of boarding passes to, or the boarding of passengers on, covered international flights. CBP will, however, continue to require carriers to provide APIS data to carry out its border enforcement mission, and the timing of that transmission will follow that of the Secure Flight program, rather than APIS.
Comment:
TSA received several comments indicating confusion regarding how aircraft operators will determine the final boarding pass printing result and which program, APIS or Secure Flight, will provide that result throughout different phases of the program.
TSA Response:
DHS plans to implement watch list matching in stages. Initially, the CBP system will take over watch list matching for all commercial flights into and out of the United States through the APIS Pre-Departure program, and aircraft operators will continue to conduct watch list matching for domestic flights. In the first phase of Secure Flight, TSA will conduct watch list matching for all covered U.S. aircraft operators' domestic flights under the Secure Flight Program. The CBP system will continue to
conduct watch list matching for international flights into and out of the United States.
In the second phase of Secure Flight, TSA will begin to conduct watch list matching for covered aircraft operators' flights that overfly the continental United States. Also in phase two, watch list matching for the remaining covered aircraft operator international flights will be transitioned from the CBP system to TSA under the Secure Flight program. During phase two, if an itinerary contains an international flight on a foreign-based aircraft operator covered by the APIS Pre-Departure final rule with a connecting domestic code share flight on a covered U.S.-based aircraft operator, the aircraft operator will transmit one set of data to DHS and receive one boarding pass printing result. The aircraft operator must comply with this boarding pass printing result. As discussed above, the timing of the aircraft operator's transmission of data to DHS will follow CBP's schedule under the APIS Pre-Departure final rule, until such time as Secure Flight assumes responsibility for international flights under phase two.
C. Implementation and Compliance
Comment:
TSA received several comments objecting to the NPRM's requirement that covered aircraft operators comply with the rule within 60 days after the Secure Flight final rule's effective date, or 120 days after publication of the final rule in the
Federal Register
. TSA also received comments that 30 days after the effective date for submission of the AOIP does not provide covered aircraft operators with sufficient time to develop the AOIP. Several commenters proposed various alternatives. Many commenters suggested that Secure Flight align its compliance schedule with CBP's APIS Pre-Departure final rule, which is 180 days from publication of the final rule in the
Federal Register
. Another commenter suggested that TSA provide an 18-month compliance schedule for covered aircraft operators.
TSA Response:
Based on the comments received on this issue, TSA agrees that full implementation of the collection and data transmission requirements in § 1560.101 within 120 days of publication of this final rule in the
Federal Register
may be difficult, if not impossible, for several covered aircraft operators. Consequently, TSA is changing the implementation timing requirements in § 1560.101 to allow for greater flexibility in implementing the various elements of the Secure Flight program.
Also, TSA is modifying the AOIP adoption process that was originally proposed in the NPRM. Because the primary purpose of the AOIP is to set forth a schedule for compliance with elements of the Secure Flight program for each covered aircraft operator, TSA believes that it is appropriate for TSA, rather than the covered aircraft operator, to develop the AOIP. Therefore, under the final rule, TSA will assume responsibility for drafting the AOIP for each covered aircraft operator and will notify each covered aircraft operator of the proposed AOIP for the covered aircraft operator.
After receiving the proposed AOIP from TSA, the covered aircraft operator will have 30 days to submit written comments on the proposed AOIP to TSA's designated official. This designated official will review the covered aircraft operator's comments and other relevant materials. After consideration of the written submission, the designated official will notify the covered aircraft operator of the AOIP. The AOIP will be effective not less than 30 days after notice is given, unless the covered aircraft operator petitions the designated official or the Assistant Secretary for reconsideration of the AOIP. In no case will an AOIP become effective prior to the effective date of the final rule. When TSA sends the covered aircraft operator their final AOIP, the covered aircraft operator may petition the designated official or the Assistant Secretary for reconsideration of the AOIP no later than 15 days before its effective date. A timely reconsideration petition will stay the effective date of the AOIP. TSA will amend, affirm, or withdraw the AOIP within 30 days of receipt of the petition for reconsideration.
Many commenters stated that TSA did not provide sufficient time for covered aircraft operators and third party agents to make all the necessary technological and process changes to satisfy the requirements of the Secure Flight program. To address this concern, TSA is not requiring covered aircraft operators to be capable of collecting and transmitting all of the SFPD elements at the same time. Instead, TSA will allow them to implement the individual SFPD elements in phases. TSA is not specifying in the rule text the dates by which covered aircraft operators must be capable of collecting and transmitting the different data elements in the SFPD. The covered aircraft operator's AOIP will set forth these specific dates. By including the specific implementation dates in the AOIP, TSA and covered aircraft operators will have flexibility to develop a compliance schedule that satisfies TSA's security needs to implement Secure Flight expeditiously while taking into account the covered aircraft operators' operations and technology.
The first SFPD element that covered aircraft operators will likely be able to provide is a passenger's full name. Because covered aircraft operators and third party agents currently collect the name as part of their business practice, TSA expects that they will have little difficulty collecting and transmitting full name within 120 days of publication of this final rule in the
Federal Register
. Covered aircraft operators will implement the other SFPD elements such as gender and date of birth in subsequent months in accordance with the AOIP. This approach will allow covered aircraft operators to make their technological changes gradually. However, covered aircraft operators may choose to make all their system changes for the Secure Flight program at the same time provided that the covered aircraft operators are capable of collecting and transmitting the full name within 120 days of publication of the final rule in the
Federal Register
.
TSA anticipates that covered aircraft operators will be capable of collecting and transmitting all of the SFPD elements within nine months of final rule publication in the
Federal Register
, because many covered aircraft operators have already made changes to comply with CBP's APIS Pre-Departure data submission requirements. TSA expects that these covered aircraft operators would be able to use much of the data submission and formatting system functions that they already execute. A small number of covered U.S. aircraft operators do not have international flights and, therefore, did not have to make any changes to comply with the APIS Pre-Departure final rule. TSA anticipates that the majority of the remaining covered U.S. aircraft operators that do not have international routes will use the web-based alternative data transfer mechanism. TSA will assist all covered aircraft operators in their efforts to comply with the Secure Flight requirements.
The AOIP also will set forth the implementation schedule for other aspects of the Secure Flight program such as when the covered aircraft operators will begin transmitting SFPD for covered international flights. Establishing the implementation schedule within the AOIP framework allows for some flexibility with implementation dates, taking into consideration both TSA security needs
and the covered aircraft operators' technological capabilities.
Comment:
TSA received several comments regarding the Secure Flight implementation phases. One commenter requested clarification as to when foreign air carriers and international flights would be covered in the second phase. One aircraft operator requested a single implementation date for Secure Flight on the ground that it would be less expensive for the aircraft operators than the proposed phased implementation. Many aircraft operators offered suggested implementation timeframes and strategies, including a suggestion to “pilot” Secure Flight with one or two covered foreign air carriers in order to work out any software and operational issues.
TSA Response:
TSA will conduct extensive testing to confirm and validate the Secure Flight watch list matching results, including benchmark testing with voluntary aircraft operators and a period of parallel testing with covered aircraft operators. TSA plans to resolve software and operational issues during the various phases of testing with participating aircraft operators and will only implement Secure Flight once these issues are resolved. TSA and covered aircraft operators will conduct the extensive testing prior to TSA assuming responsibility for watch list matching and may face operational issues in implementing Secure Flight after testing. Consequently, TSA believes that Secure Flight should be implemented in phases to ensure that the implementation process occurs as smoothly as possible and to minimize disruption of covered aircraft operators' operations and inconvenience to their passengers.
TSA will begin by implementing Secure Flight for U.S. domestic flights operated by aircraft operators required to have a full security program under 49 CFR 1544.101(a) after a period of parallel testing with all covered aircraft operators. The second implementation phase will include covered aircraft operators' flights that overfly the continental United States. TSA will determine the timing of implementing Secure Flight for covered flights that fly to and from the United States after TSA assumes the watch list matching responsibilities for covered U.S. aircraft operators' covered domestic flights. The exact implementation dates for covered aircraft operators will be in their AOIP.
Comment:
One commenter observed that TSA developed the Secure Flight program tailored for covered U.S. aircraft operators. The commenter is concerned that TSA, in developing Secure Flight, did not take into account the different systems that foreign air carriers use for their reservation and document control systems.
TSA Response:
TSA is aware of the existing differences between international and domestic systems and business processes. Secure Flight is working with covered foreign carriers to determine the best way to address these differences during the implementation of the Secure Flight program.
Comment:
TSA received one comment that stated, “Airlines should be given not less than 60 days notice of the known traveler collection requirement and that travel agents should receive no less than 55 days notice. This approach gives the airlines an ample five days to communicate the requirement to travel agents.”
TSA Response:
TSA understands the concern regarding the coordination of aircraft operator and travel agent systems to allow for entry of the Known Traveler Number. TSA believes that any programming that is required to comply with the Secure Flight implementation should be sufficient to capture Known Traveler Number when it becomes available. Thus, TSA believes that 30 days' notice should be sufficient notification for the inclusion of the Known Traveler Number.
D. Secure Flight Passenger Data (SFPD)
1. General
Comment:
One commenter stated that the U.S. government failed to demonstrate how the scope of the information being required is necessary to carry out the mandate of the Secure Flight program.
TSA Response:
TSA has chosen a limited data set for use in watch list matching. Based on automated watch list matching test results, TSA has determined that it will be able to complete watch list matching for the vast majority of individuals based on full name, date of birth, and gender. As discussed below, the additional data elements may clear individuals whose names indicate that they are potential matches to individuals on the watch list. The data elements in the SFPD will help prevent passenger misidentification and will allow TSA to more effectively and consistently prevent certain known or suspected terrorists from boarding aircraft.
Comment:
A commenter stated that the Redress Number, the Known Traveler Number, the Reservation Control Number, the Record Sequence Number, Record type, Passenger update indicator, and the Traveler Reference Number are passenger identifier codes that are used to access subsets of individual passenger information and are most used for customer service purposes such as special needs request. The commenter questioned the need for TSA to obtain these subsets of individual passenger information.
TSA Response:
TSA will use the Redress Number and the Known Traveler Number to attempt to distinguish a person who has been identified as a potential match to the watch list from an individual on the watch list. TSA will use the other numbers listed in the comment to manage the SFPD as they are transmitted to and from TSA and are processed through Secure Flight to ensure that results are matched correctly with the appropriate SFPD and that results are transmitted to covered aircraft operators timely and accurately. Under the Secure Flight program, covered aircraft operators will transmit or “push” SFPD to TSA and TSA will not access or “pull” information from the covered aircraft operators” systems. Thus, TSA will not use the numbers to pull the subsets of individual passenger information from the covered aircraft operators' systems.
Comment:
TSA received one comment expressing a concern that domestic passengers may be required to submit the same data that is required for international flights.
TSA Response:
TSA will require covered aircraft operators to request a passenger's full name, gender, date of birth, and Redress or Known Traveler Number (if known). Unlike flights subject to APIS Pre-Departure, TSA will not require covered aircraft operators to request or collect passport information from individuals. However, if covered aircraft operators collect passport information for passengers, then they must transmit that information to TSA. For example, if a passenger has a flight itinerary that includes a domestic flight that connects to an international flight, the passenger may provide passport information along with his or her full name, date of birth, and gender when he or she purchases a ticket for the domestic and international flights. In this situation, the covered aircraft operator must transmit the passport information to TSA along with the other data elements in the SFPD.
Comment:
TSA received several comments requesting clarification of the term “passenger,” and whether the term includes crew members who are not on duty.
TSA Response:
TSA is changing the definition of “passenger” as proposed in the Secure Flight NPRM to exclude employees of aircraft operators who are identified as crew members on the
manifest for that flight. TSA's Crew Vetting program conducts watch list matching of individuals who are on the manifest as crew members.
22
The Secure Flight program will conduct watch list matching of all other employees, including crew members traveling as passengers and not identified as crew on the manifest.
22
The Crew Vetting program vets airline crews entering, departing, or flying over U.S. airspace against terrorist-related information to determine if they are a potential threat to the aviation system. It uses computerized risk analysis and manual review of automated vetting results and matching analysis (Vetting Operations) to assess and evaluate potential threats of terrorists posing as cleared aviation or other transportation system personnel. The Crew Vetting program maintains a 24/7 operations center to receive and analyze Flight Crew Manifests (FCM) and Master Crew List (MCL) from the airlines throughout a 24-hour period. These individuals are then vetted against the various watchlists to identify potential security threats prior to an aircraft receiving authorization for departure.
Comment:
A commenter was concerned about Secure Flight's impact on travelers engaged in unique religious and cultural activities.
TSA Response:
TSA appreciates and respects both religious and cultural diversity. As such, the Secure Flight program will match travelers to entries on the TSDB without prejudice, placing no specific emphasis on any particular religion. With this approach, the limited information that individuals must provide, and the ability of the Secure Flight program to respond to last minute SFPD transmissions, the Secure Flight program is not likely to impact unique religious and cultural activities.
Comment:
Several commenters requested clarification on the requirement for an aircraft operator to validate the underlying accuracy of the collected passenger information on covered domestic flights or non-traveler information.
TSA Response:
The Secure Flight final rule mandates that covered aircraft operators request SFPD, but that they need not validate the accuracy of that information beyond rules currently governing verifications of biographic data of international passengers. TSA would not hold a covered aircraft operator responsible or subject the aircraft operator to enforcement action if the information provided by a passenger is found to be inaccurate unless the covered aircraft operator knowingly provided the inaccurate information to TSA.
Comment:
TSA received one comment that requested clarification on how to record consumer refusals to provide optional SFPD.
TSA Response:
TSA does not require a record of an individual's refusal to provide optional elements of the SFPD when the covered aircraft operator initially requests the information.
Comment:
A commenter expressed concern that TSA may change the required data elements in the SFPD after operational testing because covered aircraft operators will have already made system changes based on this final rule by the time they undergo operational testing.
TSA Response:
TSA understands this concern based on the Secure Flight NPRM. The SFPD elements in this final rule will not change as a result of operational testing.
Comment:
Several comments requested that TSA clarify SFPD transmission requirements and the format for full name, date of birth, and gender in the final rule. Several commenters requested that all formats be standardized to ensure ease of collection and transmission to TSA.
TSA Response:
TSA developed transmission requirements and the standard formats for the SFPD elements in the Consolidated User Guide. TSA will provide the Consolidated User Guide to all covered aircraft operators.
2. SFPD Is Not Passenger Name Record (PNR)
Comment:
TSA received comments expressing concern about the potential improper use of a Passenger Name Record (PNR). Many commenters mistakenly believed that SFPD is PNR or a subset of PNR. TSA also received a comment stating that PNR is already provided to CBP 72 hours prior to departure and should be sufficient for extraction by TSA for Secure Flight watch list matching.
TSA Response:
TSA is not requiring covered aircraft operators to submit PNR, and TSA will not have direct access to PNR. Instead, TSA is requiring covered aircraft operators to submit SFPD which is a separate set of data elements. Covered aircraft operators may chose to extract the data elements from the PNR to create the SFPD for operational reasons. TSA, however, is not mandating that they do so nor is it mandating where covered aircraft operators store SFPD. Covered aircraft operators may choose to create a separate system to collect and store SFPD. CBP has access to PNR under a separate regulatory requirement.
Comment:
A commenter expressed concern that TSA will require covered aircraft operators to include an individual's nationality in the PNR that would be transmitted to the Secure Flight program.
TSA Response:
As stated above, TSA is not requiring covered aircraft operators to include any information in the PNR or to send PNR to the Secure Flight program. Furthermore, TSA is not requiring covered aircraft operators to request or to collect an individual's nationality.
3. Date of Birth and Gender
Comment:
TSA received several comments regarding the inclusion of date of birth and gender as SFPD elements. Some commenters supported date of birth and gender becoming mandatory data elements. One commenter argued that unless TSA mandates the collection of this additional information, many passengers would not be cleared by TSA. Another commenter supported making both elements mandatory, but objected to collecting this data at the time of booking. Other commenters opposed TSA requiring individuals to provide date of birth and gender. Another commenter sought clarification on whether individuals must provide any information other than full name.
TSA Response:
Through careful consideration of the public comments and both privacy and security concerns, TSA has concluded that it will require full name, date of birth, and gender from individuals under § 1540.107(b). It is expected that these data elements in combination will be sufficient to conduct watch list matching for the vast majority of individuals and to distinguish more persons from individuals on the watch list as part of the automated process reducing instances of misidentification. Reducing misidentification is an important program goal mandated by Congress and collection of all three data elements is an important step in reaching that goal.
23
23
Section 518(a) of the Department of Homeland Security Appropriations Act, 2006, Pub. L. 109-90 (Oct. 18, 2005) (2006 DHS Appropriations Act), requires DHS to certify and purports to require GAO to report that TSA satisfies 10 conditions before TSA may deploy Secure Flight other than on a test basis. One of the conditions is the Secure Flight system “will not produce a large number of false positives that will result in a significant number of passengers being treated mistakenly * * *.”
Cf. INS
v.
Chadha,
462 U.S. 919 (1983).
Comment:
TSA received several comments requesting that TSA require covered aircraft operators only to request date of birth and gender if a person is not cleared by submitting only their full name.
TSA Response:
TSA believes that by requiring the airlines to ask for and passengers to provide the data elements at time of original submission, TSA can make a determination about the boarding pass printing result quickly and efficiently. There would be no need
for a second transmission that may necessitate the individual going to the ticket counter.
Comment:
TSA received one comment requesting that TSA eliminate the gender requirement from SFPD information and instead require passengers to submit information regarding their ethnicity, race, or national origin.
TSA Response:
Many names are gender neutral. Additionally, names not derived from the Latin alphabet, when translated into English, do not generally denote gender. Providing information on gender will reduce the number of false positive watch list matches, because the information will distinguish persons who have the same or similar name. Consequently, TSA is including gender as a required element of the SFPD, which covered aircraft operators must request from individuals and which individuals must provide to the covered aircraft operator.
TSA disagrees that ethnicity, race, or national origin should be included in SFPD information provided by passengers of covered aircraft operators and certain non-travelers seeking access to the sterile area of a U.S. airport. Secure Flight matches names of passengers to entries on the TSDB without prejudice or regard to an individual's race, ethnicity, or national origin.
4. Redress Number and Known Traveler Number
Comment:
TSA received several comments requesting that the final rule clarify the handling of Redress Numbers and Known Traveler Numbers. Some commenters expressed opposition to the Secure Flight requirement for requesting these two numbers.
TSA Response:
Individuals who believe they have been incorrectly delayed, identified for enhanced screening, denied boarding, or denied access to a U.S. airport's sterile area may apply for redress through DHS TRIP. DHS will assign a unique Redress Number to each individual who uses DHS TRIP. Individuals who have already undergone TSA's redress process do not need to use DHS TRIP to reapply for redress once the Secure Flight program is operational. Individuals will be less likely to be delayed by misidentification as a match to the watch list if they provide their Redress Number at the time they make a flight reservation or request access to a U.S. airport's sterile area. While TSA requires that each covered aircraft operator request a Redress Number, TSA does not require individuals to provide a Redress Number when making a reservation for a covered flight.
TSA intends to develop and implement the Known Traveler Number as part of the Secure Flight program. Like the Redress Number, the Known Traveler Number is a unique number assigned to “known travelers” for whom the Federal government has already conducted terrorist security threat assessments and has determined do not pose a terrorist security threat. The Known Traveler Number may draw upon information from programs such as the Transportation Worker Identification Card program. Once TSA has determined the details of the Known Traveler Number program, it will inform covered aircraft operators that they must begin to request and transmit the number, if provided by the individual. The covered aircraft operators must do so in the time specified in their AOIP.
Similar to other optional information, TSA will not compel individuals to provide a Redress Number or a Known Traveler Number upon request from the aircraft operator. Without either of these numbers, the individual may be more likely to experience delays, be subjected to enhanced screening, be denied boarding, or be denied access to a U.S. airport's sterile area.
Comment:
TSA received several comments indicating support for the development and implementation of the Known Traveler Number. TSA also received several comments against the requirement for Known Traveler Number as they claim it would be redundant. Several commenters also suggested integration of the Known Traveler Number with existing registered traveler schemes and with future plans between the U.S. and other foreign governments. They suggested that TSA relate Known Traveler Numbers for other groups of individuals, including those with national security clearances or members of the U.S. or foreign governments. Another commenter suggested that the name of the Known Traveler Number be changed to “Cleared Passenger Number” to more accurately identify those individuals who participate in the program.
TSA Response:
TSA assures these commenters that all possible solutions for the Known Traveler Number will be considered during development efforts. At this time, however, TSA is unable to comment on whether the Known Traveler Number will be fully integrated with existing credentialing programs or future domestic or international programs. Although “Cleared Passenger Number” is a possible alternate name, TSA prefers “Known Traveler Number” because the number is assigned to individuals “known” to the government through the credentialing program. Finally, TSA has not determined which individuals or programs will be included under the Known Traveler Number but will continue to consider the proposed inclusion of certain groups.
Comment:
A commenter questioned whether or not TSA would continue to conduct watch list matching for known travelers. The commenter argued that if this watch list matching does occur, it would be redundant and unnecessary.
TSA Response:
TSA intends to continue to conduct watch list matching for individuals who provide a Known Traveler Number for covered flights to ensure that the individuals' Known Travel Numbers have not expired or been revoked.
Comment:
A covered aircraft operator stated that it will not be able to request the Known Traveler Number from passengers who made their reservation before TSA issued the 30-day written notice to them.
TSA Response:
TSA will not require covered aircraft operators to request the Known Traveler Number for reservations made before TSA implements the Known Traveler Number program.
Comment:
TSA received several comments regarding the requirement in proposed § 1560.101(a) prohibiting covered aircraft operators from accepting a reservation from an individual who did not provide all the required information at the time of booking. The commenters provided examples such as when an individual or a tour operator is making a reservation for a large group and does not have access to every individual's full name or passport information.
TSA Response:
The reason for proposed § 1560.101(a) was to ensure that the Secure Flight program receives full names to conduct effective watch list matching. TSA does not intend for the Secure Flight program to impact current business practices regarding the blocking of group space without complete passenger information. TSA is changing the language in proposed § 1560.101(a) to provide that covered aircraft operators may not submit a SFPD for an individual until the individual provides his or her full name, date of birth, and gender; the regulation does not prohibit covered aircraft operators from accepting a reservation without a full name, date of birth, and gender. Once a covered aircraft operator receives the full name, date of birth, and gender associated with the blocked or group space, the aircraft
operator must transmit that SFPD to TSA in accordance with this final rule. Additionally, TSA has designed the data transmission processes to receive changes and updates to these data elements.
This change will still ensure that individuals do not receive a boarding pass or authorization to enter a sterile area without TSA's conducting watch list matching based on a full name, date of birth, and gender at a minimum. Also, the only data elements that passengers must provide are full name, date of birth, and gender; other optional information, such as passport information, does not need to be included as part of the SFPD.
E. Watch List Matching Process
1. Transmission of SFPD
Comment:
Numerous airlines commented that Secure Flight requires data not currently contained in the airlines' systems or incorporated in the UN-EDIFACT message standards. The UN-EDIFACT is the international electronic data interchange (EDI) standard developed under the United Nations for inter-industry electronic interchange of business transactions. Many commenters expressed concern that the requirements for collection and transmission of SFPD do not follow international standards.
TSA Response:
TSA recognizes that programming will be required to add additional data to airline systems, but TSA has diligently limited the data requested to the minimum required to support the security processes and to provide the transactional support required for airlines to apply the boarding pass printing result provided by Secure Flight. As part of the implementation of APIS Pre-Departure, CBP has defined the additional fields for UN-EDIFACT transmissions and the Secure Flight program will use that message format. DHS has identified and harmonized the modifications to UN-EDIFACT messaging standards for these additional data with those required for APIS Pre-Departure systems. TSA will coordinate with the appropriate worldwide standards bodies, as required.
Comment:
Several commenters expressed concern that Secure Flight would be unable to efficiently process the transactions resulting from airline passenger travel, especially during periods of irregular operations and passenger re-accommodation.
TSA Response:
TSA understands the need for Secure Flight to efficiently process transactions, especially during periods of irregular operations and passenger re-accommodations. In developing Secure Flight, TSA has accounted for the additional transmission volume associated with changes in passenger travel information, resolution of boarding pass printing results, and changes caused by irregular operations or passenger re-accommodation. All of these factors contributed to the design decision to require that covered aircraft operators provide available SFPD 72 hours in advance of flight departure. This advance booking information allows Secure Flight to increase real time resources available to respond to off schedule operations and passenger re-accommodation and to process SFPD for passengers who make reservations within 72 hours of the scheduled departure of the flight.
Comment:
One aircraft operator commented that TSA should not dictate when, and from which system, the airline sends SFPD to TSA.
TSA Response:
TSA does not specify the system from which a covered aircraft operator must transmit SFPD, and covered aircraft operators may choose the appropriate system from which to transmit SFPD. However, obtaining passenger data in advance is an integral part of the Secure Flight watch list matching process; it is designed to optimize the number of boarding pass printing results available to the covered aircraft operator prior to passenger check-in. The rule specifies that a covered aircraft operator must submit the SFPD to TSA beginning 72 hours before departure or as soon as it becomes available.
Comment:
Several airlines expressed concern that the Secure Flight response time would adversely affect their passenger check-in processes and levels of customer service.
TSA Response:
Secure Flight's requirement for advance transmission of SFPD is designed to provide a boarding pass printing result prior to passenger check-in. Secure Flight has made considerable investments to ensure a prompt response.
Comment:
Several airlines and airline associations expressed concern that even a short outage of the Secure Flight system would severely impact airline operations.
TSA Response:
TSA designed Secure Flight technical operations with geographic and component redundancy to provide for continuous, uninterrupted operations. Covered aircraft operators will receive boarding pass printing results for a majority of passengers beginning 72 hours before flight departure. TSA believes the number of individuals affected by a significant short term outage with multiple redundancy failures would be comparatively small and likely limited to those passengers making last minute reservations or changes. The Consolidated User Guide includes a comprehensive plan to address processes and procedures for outages.
2. 72-Hour Requirement
Comment:
TSA received several comments about the requirement to submit SFPD to Secure Flight beginning 72 hours before departure and the potential impact to travelers who make last minute reservations or changes.
TSA Response:
Secure Flight will perform watch list matching on all reservations for covered flights operated by covered aircraft operators regardless of when the reservation is made. TSA is not requiring that individuals make their reservations or purchase tickets 72 hours or more before departure. In this final rule, TSA describes two scenarios whereby a covered aircraft operator must submit SFPD to Secure Flight. The first is when a covered aircraft operator accepts a reservation with a full name, date of birth, and gender earlier than 72 hours before departure. In this situation, the covered aircraft operator must transmit the SFPD to Secure Flight 72 hours in advance of departure. The second scenario occurs when a covered aircraft operator accepts a reservation within 72 hours of departure, updates a TSA-requested SFPD within 72 hours of departure, changes a flight within 72 hours of the departure time, or seeks to authorize individuals to enter a sterile area upon arrival at the airport. For those reservations or requests, the covered aircraft operator must transmit the SFPD to Secure Flight as soon as the SFPD is available.
Comment:
TSA received several comments from covered aircraft operators who indicated that they have two systems: A reservation system and a departure control system (DCS). These commenters, predominantly covered foreign air carriers, are concerned that Secure Flight does not take into account that their reservations system does not store all SFPD elements and that their DCS often captures SFPD elements at check-in when the individual's passport is swiped. Several comments noted that covered aircraft operators would incur costs to program their reservation systems to accept SFPD. Some covered aircraft operators indicated that they cannot transmit UN-EDIFACT messages from their reservations system; they can only be transmitted from their DCS. Many commenters also expressed concern that TSA will return a boarding pass printing result to the incorrect
system, and passengers may experience difficulties in obtaining a boarding pass.
TSA Response:
TSA understands the concerns raised by these covered aircraft operators. The Secure Flight program is developing a solution for covered aircraft operators that have separate reservations systems and DCS as described in the comments. The solution will support the covered aircraft operators' systems as well as the transmission and boarding pass printing requirements in this final rule.
Comment:
TSA received several comments questioning TSA's requirement that SFPD transmission begin 72 hours in advance considering that CBP is willing to accept data up to departure time.
TSA Response:
TSA considered a number of factors in determining that covered aircraft operators should submit SFPD to TSA beginning 72 hours before departure time. The CBP system will conduct watch list matching only for covered flights that involve a flight to or from the United States. When TSA assumes watch list matching, the Secure Flight program will conduct the watch list matching for (1) all flights conducted by U.S. aircraft operators (including flights between two international points); (2) flights operated by foreign air carriers that fly to or from the United States or overfly the United States; and (3) non-travelers who are seeking authorization to enter a sterile area. While TSA believes that the automated process alone for vetting this significantly larger population of travelers may not take 72 hours, several factors that suggest a 72-hour lead time is appropriate. These include the volume of data involved, the increase in records requiring a manual review due to a potential match or an insufficient amount of information to differentiate someone from an individual on the watch list, and the time required to coordinate an operational response when necessary.
By requiring covered aircraft operators to transmit available SFPD 72 hours prior to departure, TSA will be able to prioritize SFPD by departure time. This prioritization will permit TSA to return boarding pass printing results for the vast majority of passengers in time for them to print their boarding passes 24 hours in advance of their flights while also returning boarding pass printing results for individuals who make reservations within 72 hours of the scheduled departure in time for them to obtain their boarding passes prior to the scheduled departure.
TSA understands that a certain amount of expense is involved in making programming changes for Secure Flight. TSA believes, however, that the security benefit to covered aircraft operators and passengers is such that the 72 hour requirement is a necessity.
Comment:
A few commenters expressed concern that there will still be a number of changes to reservations within the 72 hour period that will require messaging back and forth between the covered aircraft operator and TSA. The commenters suggest that reducing the time from 72 hours to something less than 72 hours will reduce the need for such messages.
TSA Response:
TSA believes that, on average, an overwhelming majority of reservations become stable at 72 hours before departure time. However, TSA understands that there are still some reservations that continue to change within the 72 hour period. As explained above, TSA believes that the security benefits to covered aircraft operators and passengers of providing SFPD for passengers who have made their reservations more than 72 hours before departure time are important enough to require this timeframe.
3. Boarding Pass Issuance
Comment:
Several commenters argued that prohibiting covered aircraft operators from issuing a boarding pass until they receive a boarding pass printing result from TSA would unnecessarily impact the check-in of connecting passengers, specifically those inbound to the United States who are connecting/transferring through airports outside of the United States.
TSA Response:
In the United States, the boarding pass is used to designate to personnel at the security checkpoint whether passengers are permitted to enter the sterile areas and whether passengers must first undergo enhanced screening. TSA recognizes that, outside the United States, access and enhanced screening are determined by the applicable operating authority of the airport. In some international airports, passengers may transit from one international flight to another where the flights are operated by different aircraft operators; only the second flight would be covered under this final rule. TSA understands that currently, in these situations, the aircraft operator operating the first, non-covered flight may issue a boarding pass for both legs of the passenger's itinerary, including the covered flight to the United States.
Accordingly, TSA has modified § 1560.105(b) to allow for the issuance of connecting boarding passes inbound to the United States for connecting passengers without complying with the requirements regarding boarding pass printing result in § 1560.105(b). Under the Secure Flight program, the aircraft operator operating the first, non-covered flight is able to issue a boarding pass for the second, covered flight without obtaining a boarding pass printing result from TSA. The second aircraft operator, however, must submit SFPD or APIS data to DHS and confirm the boarding pass printing results prior to permitting the passenger to board the aircraft for the covered flight. The covered aircraft operator must comply with the measures in its security program to prevent the boarding of any individual who is identified as a No Fly match by TSA and to ensure that any passenger TSA identifies as a Selectee undergoes enhanced screening prior to boarding the aircraft. These conditions mitigate the security vulnerability associated with issuance of a boarding pass for covered flights outside of the Secure Flight program. These provisions will also apply to passengers whose connecting flight is a covered overflight.
Comment:
One aircraft operator recommended that TSA eliminate the requirement for applying the Secure Flight requirements on subsequent connecting flights.
TSA Response:
TSA believes that the elimination of the watch list matching requirements on subsequent connecting flights is inconsistent with the security mandate of Secure Flight. One of the benefits of the Secure Flight program is that any update to the watch list will be compared against all active SFPD. This update comparison will allow TSA and the covered aircraft operators to take appropriate action regarding any passenger whose status changes during his or her travel.
Comment:
A commenter requested that TSA clarify the provision “that carriers can choose to designate a more restrictive boarding pass status in conjunction with other TSA or aircraft operator procedures.” Secure Flight NPRM at 48374.
TSA Response:
Covered aircraft operators must designate passengers for enhanced security screening for reasons unrelated to watch list matching pursuant to a TSA security directive such as the Computer Assisted Passenger Prescreening System (CAPPS). TSA will continue to require aircraft operators to conduct these programs once Secure Flight is implemented and a passenger may receive a more restrictive boarding pass status based on the results of these other programs. Also, TSA recognizes that covered aircraft operators may designate a more restrictive boarding pass status
based on their own policies and procedures.
Comment:
A few commenters supported the implementation of bar codes on boarding passes to authenticate the boarding passes, because it will enhance security in the sterile area. Another commenter stated that the inability to authenticate boarding passes minimizes the benefits of the Secure Flight program. The commenter argues that Secure Flight should not be implemented until this security issue is adequately addressed.
TSA Response:
As one commenter noted, bar codes on the boarding pass will address the security issue of altered or fraudulent boarding passes. TSA is developing the protocols and standards for placing a bar code on boarding passes and the requirement for covered aircraft operators to place the code on their boarding passes is part of this final rule in §§ 1560.105(b) and (c). When TSA updates the Consolidated User Guide with the protocols and standards for the code, covered aircraft operators must implement this requirement in accordance with their AOIP.
Comment:
Several airlines requested additional clarification on the bar code requirements. Some commenters raised concerns that bar code requirements would be costly to implement. Many commenters suggested that TSA take advantage of existing bar code standards such as the International Air Transport Association standards and business processes. The commenters also requested more information about how TSA would intend to use the bar code in addition to any verification procedure.
TSA Response:
TSA recognizes the importance and potential impact of requiring bar codes to be placed on boarding passes. As stated above, TSA believes that bar codes are an important security measure to authenticate boarding passes. TSA is continuing to research new and existing technologies to develop a technologically sound solution that meets the TSA mission and budgetary requirements and minimizes impacts to aircraft operators. TSA will take into consideration the IATA bar code standard in developing its protocols and standards to determine the most effective solution that meets the TSA mission.
Comment:
Several commenters noted that the airline industry was seeking alternatives to the traditional paper boarding pass. They expressed concern that Secure Flight would hinder innovation in this respect.
TSA Response:
Secure Flight uses “boarding pass” to refer to an entitlement for aircraft enplanement issued by an aircraft operator. TSA will consider alternative means of conveying that boarding entitlement, subject to specific requirements like bar coded information. This final rule refers to the issuance of “a boarding pass or other authorization” thereby providing for alternatives to paper boarding passes.
Comment:
TSA received comments suggesting that TSA should inform passengers and non-traveling individuals of their boarding status at the checkpoint, rather than send boarding pass printing results to the covered aircraft operators.
TSA Response:
TSA believes that moving this process from the individual aircraft operators to the security checkpoint will create unacceptably long lines at the checkpoint, will cause unnecessarily lengthy delays for individuals who are not a potential match to the No Fly or Selectee lists, and will cause travelers to miss flights.
Comment:
TSA received comments requesting that TSA not include in the Secure Flight program a provision for enhanced screening of randomly selected cleared passengers.
TSA Response:
TSA believes that randomly selecting individuals for enhanced screening is an important layer of security and adds unpredictability to the screening process. While the current CAPPS program includes a random selection element, TSA does not anticipate that Secure Flight will initially include a random selection element. TSA may, however, include a random selection element to Secure Flight as part of its continuous efforts to review and improve its screening procedures.
Comment:
One aircraft operator commented that the Secure Flight Service Center should be adequately and continuously staffed.
TSA Response:
The Secure Flight Service Center will be staffed 24-hours a day, 7-days a week to receive telephone calls from covered aircraft operators' staff and assist in the clearance of inhibited passengers. If additional information such as a physical description is required, covered aircraft operators' staff would provide that information during a conversation with Secure Flight Service Center personnel.
Comment:
Several commenters suggested that TSA expand the period in which boarding passes can be issued to a period greater than 24 hours prior to scheduled flight departure.
TSA Response:
While TSA appreciates that covered aircraft operators and passengers would prefer greater advance boarding pass issuance, expansion of the advance time period for boarding pass issuance increases the potential that changes to the watch list will not be correctly reflected in the traveler's boarding pass. This potential for inaccurate boarding passes may create additional security and operation exposure. Therefore, TSA does not plan to expand the authority to issue boarding passes beyond 24 hours prior to the scheduled flight departure.
Comment:
A commenter objected to a perceived restriction to issuance of a “single boarding pass.”
TSA Response:
The Secure Flight NPRM and final rule contain no restriction on the issuance of duplicate or replacement boarding passes. The rule provides for a “single boarding pass printing result” in those cases in which a passenger itinerary would result in a watch list evaluation by both TSA and CBP.
4. Passenger Resolution
Comment:
TSA received several comments requesting further information about the provision of PRI by aircraft operators for those passengers to whom TSA has provided an inhibited boarding pass printing result. A few commenters question the need for this requirement. Some commenters suggested that TSA should not require the PRI to be transmitted electronically or it should be eliminated altogether.
TSA Response:
TSA may require covered aircraft operators to provide PRI for individuals who have been identified as a potential match to the watch list. Without the PRI, individuals for whom TSA has returned an inhibited status result will not be able to obtain a boarding pass, because TSA would not have the means to distinguish that individual from the individual on the watch list.
In the event that it is necessary to collect additional information when there is a potential watch list match, including certain physical description information about the passenger, the covered aircraft operator will contact the Secure Flight Service Center and provide the information. Covered aircraft operators will provide PRI, including physical description information, to TSA only via a telephone call to the Secure Flight Service Center. TSA is not requiring PRI to be transmitted electronically.
Comment:
TSA received one comment asking if a foreign passport is the only foreign document that is acceptable to TSA for VID purposes.
TSA Response:
The definition of VID in § 1560.3 includes a valid, unexpired passport issued by a foreign government. TSA has determined that,
at this time, an unexpired foreign passport is the only document issued by a foreign government that can serve as a VID. This is because the process of issuing the passport involves procedures for verifying the identity of the individual. Also, passports universally contain required identifying information, such as full name, date of birth, and a photograph of the individual. TSA, however, may authorize covered aircraft operators to accept other foreign documents as valid VIDs.
5. Use of the Terrorist Screening Database (TSDB)
Comment:
Several commenters expressed a concern that the watch lists used by Secure Flight contain errors and inaccuracies. One of these commenters further stated that using the watch lists would not expedite the pre-boarding process or improve transportation security.
TSA Response:
TSA seeks to ensure that data used in the watch list matching process is as thorough, accurate, and current as possible. TSA has worked with the Terrorist Screening Center (TSC) to review the No Fly list name by name, and many names have been removed; a similar process for Selectee names is ongoing. TSA continues to be committed to eliminating erroneous and out-of-date information from the watch list matching process. DHS TRIP will facilitate the redress process for Secure Flight. DHS TRIP provides the opportunity for individuals who believe that they have been delayed or prohibited from boarding or denied entry to the airport sterile area as the result of the Secure Flight program to seek redress and relief.
Comment:
TSA has received several comments on the proposed requirement to use a larger subset list in the Terrorist Screening Database (TSDB) when the threat level changes in a particular airport, airline, and/or region in the United States. The commenters were concerned that the use of a larger list to select a particular group of travelers would be based solely on nationality.
TSA Response:
During normal Secure Flight operations, the watch list check will consist of the No Fly and Selectee components of the TSDB. TSA will only use a larger list when warranted for security purposes, such as intelligence that terrorists are targeting a specific route. The decision to use the larger list will not be based on nationality.
Comment:
TSA received one comment expressing concern that TSA's use of the watch list would result in individuals with criminal records being arrested.
TSA Response:
The watch list identifies individuals with a nexus to terrorism. We believe that the commenter's concern about those with criminal records without a nexus to terrorism is a misunderstanding of the mission of Secure Flight.
6. Non-Traveling Individuals
Comment:
TSA received several comments regarding the issuance of gate passes for non-traveling individuals and the collection of these individuals' data for Secure Flight purposes. Many international carriers expressed a concern that their systems are not capable of capturing such data and asserted that the function of collecting non-traveler data and issuing gate passes should remain in the hands of airports or other authorities. A commenter suggested that TSA provide a manual alternative for covered aircraft operators to provide the non-traveler information to Secure Flight. Furthermore, several foreign air carriers believe it is outside of the purview of TSA's authority to require such data collection and submission for airports outside of the United States. Commenters also argued that submission of information for non-travelers should be the responsibility of airport authorities.
TSA Response:
TSA is clarifying that the requirement to submit information on non-travelers seeking entry to a sterile area is limited to airports within the United States. Moreover, TSA recognizes that covered aircraft operators' systems for collecting non-traveler information vary. Thus, while covered aircraft operators may create an SFPD for the non-traveler in their systems and submit the information in the same manner that they submit SFPD for passengers, they are not required to do so. They may instead opt to submit the information in a manner that is consistent with their particular system and business practices for collecting non-traveler information. TSA also is developing an alternative method for covered aircraft operators to submit information for non-travelers through the internet.
Comment:
A commenter expressed concern that the Secure Flight NPRM fails to adequately address the needs of non-travelers to be quickly provided access to an airport's sterile area, because it will be difficult for the covered aircraft operator to advise non-travelers that they must provide their personal information 72 hours in advance.
TSA Response:
Covered aircraft operators may submit a non-traveler's information to TSA at any time before departure or whenever that individual wishes to access the sterile area. Furthermore, aircraft operators also have the option of using the alternative data transfer mechanism, such as a web-based alternative, for non-travelers who must be vetted and need a response quickly.
7. General Comments
Comment:
TSA received a number of comments about Secure Flight's ability to reduce false positives. TSA received a comment that suggested that the only improvement as a result of implementing Secure Flight is that a significant effort has been made to reduce false positives. Another commenter suggested that better use of a “cleared list” in the existing process alone would be sufficient to reduce false positives. One commenter questioned the capability of the Secure Flight watch list matching process to distinguish between similar sounding names, and argued that this could result in more false positives. Another commenter suggested that travelers who have been previously misidentified (false positives) would benefit from enrollment in the Registered Traveler program.
TSA Response:
TSA agrees that a significant benefit of Secure Flight watch list matching is the expected outcome of relatively few misidentified passengers (or false positive matches). We disagree with those comments that suggest TSA retain the current system. In addition to meeting the IRPTA requirement that the government assume watch list matching from the airlines, we believe that Secure Flight brings needed consistency to the watch list matching process that does not exist currently, including more consistent application of the cleared list. With this consistency, there is the expected outcome of a low number of false positive matches.
Comment:
A commenter expressed concern that the Secure Flight NPRM does not state that Secure Flight will supersede any current TSA security directives that require carriers to match their passengers against the watch lists. The commenter feels that this leaves carriers unable to comply with both conflicting regulations.
TSA Response:
TSA will update security directives and programs to make them consistent with the Secure Flight regulation.
Comment:
The commenter asks what the procedures will be for law enforcement officials to question an
individual who is a potential match to the No Fly List in a foreign country.
TSA Response:
Today, foreign air carriers perform watch list matching and contact the TSA Office of Intelligence (OI) to resolve any potential No Fly matches. In the future, foreign air carriers will contact the Secure Flight Service Center to resolve any potential No Fly matches. Secure Flight does not change existing procedures related to law enforcement officials' involvement in questioning individuals.
Comment:
A commenter asked what procedures will be in place to ensure other airlines are alerted when an identified No Fly passenger has attempted to purchase a ticket on an airline within a certain region.
TSA Response:
TSA is sensitive to the commenter's concern about an identified No Fly individual attempting to purchase a ticket from one carrier after being refused by another. One of the benefits of Secure Flight is the consistency it will provide. In this scenario, TSA will send an inhibited response back to the covered aircraft operator when that operator submits the SFPD for the individual.
Comment:
TSA received a comment requesting that the Secure Flight final rule not require repetitive requests for information for subsequent flights by the same passenger.
TSA Response:
TSA requires covered aircraft operators to request passenger information and to submit a SFPD for each passenger on every covered flight. Covered aircraft operators may program their systems to store passenger information for future use to alleviate the burden on passengers to input the passenger information every time they make a reservation or purchase a ticket. Covered aircraft operators may also program their systems to automatically use the stored information to populate the SFPD data fields for future flights. TSA is not mandating that covered aircraft operators program their systems in this manner. If they choose, however, to use systems that automatically populate the fields in their reservation system, TSA is requiring covered aircraft operators to submit passenger information that is automatically entered into the SFPD.
F. Privacy
1. General Comments
Comment:
TSA received comments stating that U.S. carriers should not be subjected to conflicting privacy data requirements between the U.S. Government and foreign governments.
TSA Response:
SFPD is security data provided pursuant to government directive and typically exempted from data privacy requirements around the world.
Comment:
Several commenters expressed a concern with the Federal government collecting any data from U.S. citizens flying domestically.
TSA Response:
The threat to aviation security exists for both domestic and international flights and watch list matching of passengers on these flights is an important security measure. TSA has carefully selected the minimal personal information that TSA believes is necessary to conduct effective watch list matching for aviation security and is collecting it only for watch list matching purposes.
2. Required Privacy Notice
Comment:
TSA received several comments objecting to providing the privacy notice outlined in this final rule.
TSA Response:
While TSA appreciates the concerns posed by these commenters, TSA has deemed sufficient privacy notice to passengers a key element of the program in order to ensure passengers are adequately aware that their data will be shared with the government. TSA will also develop a public awareness campaign to educate the traveling public regarding information collection and TSA's use of that information.
Comment:
TSA received several comments suggesting that TSA take into account that privacy notices are already a requirement of European law and the wording is provided by data protection agencies in European Union (EU) Member States.
TSA Response:
This final rule requires covered aircraft operators to use specific language to provide the complete privacy notice, unless TSA approves alternative language. For instance, if a governmental entity or entities develops a common privacy notice for use for international flights, that common privacy notice may be approved for use in lieu of the privacy notice specified in this final rule. Individuals who wish further information with respect to TSA's privacy policies should refer to TSA's Web site. The proposed privacy notice requirement applies to all passengers who travel and who will be screened by Secure Flight, not just individuals traveling to/from EU member states.
The privacy notice in this final rule does not affect the covered aircraft operators' responsibilities under other countries' laws or regulations regarding notice and consent. In addition to the requirements in 49 CFR 1560.103, covered aircraft operators should comply with any notice and consent requirements of other countries, such as Canada, in which they operate.
Comment:
TSA received several comments expressing a concern that enforcing third parties' inclusion of a privacy notice on their Web sites or elsewhere cannot be controlled by covered aircraft operators.
TSA Response:
TSA believes that privacy is an important component of the Secure Flight program. Because of its importance, TSA is requiring covered aircraft operators to post the privacy notice on their Web sites and on Web sites of third parties if the third party's Web site is capable of creating a reservation for the covered aircraft operator's reservation system. This comment is closely related to comments indicating that covered aircraft operators cannot require third parties to collect the required SFPD when they sell tickets for the covered aircraft operators' flights. As stated above in response to this comment, TSA believes that it is reasonable to expect that covered aircraft operators will include a requirement that the third parties post the privacy notice on their Web sites in agreements with third parties that have Web sites capable of making a reservation for covered aircraft operators' reservation systems.
Comment:
A commenter argued that the privacy notice must be provided to individuals prior to collection of SFPD.
TSA Response:
TSA seeks to have the privacy notice provided through a layered approach to reach the greatest number of passengers practicable. TSA is requiring covered aircraft operators to make the privacy notice available on their Web sites and to ensure that third parties that maintain Web sites capable of making a reservation for the covered aircraft operators' reservation system also make the privacy notice available on their Web sites. TSA will also post the privacy notice on its Web site. TSA believes that making the privacy notice available on Web sites is the most cost-effective and efficient method for providing notice. Requiring covered aircraft operators to provide the privacy notice for individuals who make reservations via the telephone, through a travel agent, and via other non-internet based methods would be costly and burdensome.
Comment:
TSA received a comment requesting clarification on how covered aircraft operators should comply with the privacy notice requirement. The comment stated that the NPRM did not provide any guidance regarding how to manage the display and traveler acknowledgement of the privacy notice, when the privacy notice is required to
be shown (one time or during each subsequent reservation made by that traveler) and, where the notice must be shown.
TSA Response:
The PIA TSA published in conjunction with the NPRM as well as this final rule explains that, prior to collecting information from an individual through a Web site or an airport kiosk, a covered aircraft operator must make the privacy notice available to the individual. The aircraft operator can achieve this by posting the privacy notice on its Web site or by providing a link to the TSA Web site.
TSA requested comments from the public on how a privacy notice could be provided during the collection of information through means not identified in section 1560.103 of the NPRM, but did not receive any.
3. Privacy Impact Assessment (PIA)
Comment:
A commenter stated that DHS must address the privacy implications of the Secure Flight program and ensure that it remains within the scope of the Intelligence Reform and Terrorism Prevention Act of 2004 (IRTPA).
TSA Response:
In conjunction with this final rule, DHS is publishing a Privacy Impact Assessment on the DHS Web site at
http://www.dhs.gov
which assesses the privacy impacts of the final rule. TSA will also post the Privacy Impact Assessment on the TSA Web site at
http://www.tsa.gov.
TSA has designed Secure Flight to implement the Fair Information Principles and the Privacy Act
24
to the greatest extent possible. TSA will collect the minimum amount of personal information necessary to conduct effective watch list matching, adding more consistency and efficiency to the process by minimizing false positives and negatives while preventing known and suspected terrorists from boarding an airplane, and will provide notice and choice where possible.
24
5 U.S.C. 552a.
Comment:
TSA received several comments expressing concern about the requirement that covered aircraft operators submit passenger information stored in their system even though the passenger did not provide the information when he or she made the reservation. One commenter suggested that this requirement is not voluntary submission of personal data and TSA should not require SFPD to be collected in this manner.
TSA Response:
The requirement to transmit passenger information that is stored but not provided at the time of reservation is limited to covered aircraft operators that program their systems to automatically use the stored information to populate the SFPD dat
This text is long and has been trimmed here. Open the source document for the complete record.
This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.