Advertisement

Secret Service reveals new surveillance system amid slowdown in privacy impact assessments

The Helix tool, which combines surveillance video, facial recognition tech and license plate data to monitor potential threats, is one of just a few PIAs posted by the agency this year.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
A U.S. Secret Service Uniformed Division officer assigned to the Special Operations Division K-9 Unit patrols outside the perimeter of the White House as Ukrainian President Volodymyr Zelenskyy meets with U.S. President Donald Trump on July 28, 2026 in Washington, DC. (Photo by Kevin Carter/Getty Images)

The Department of Homeland Security’s chief privacy officer has greenlit a Secret Service surveillance system that’s fueling law enforcement operations, according to a privacy impact assessment published last week. 

The platform, called Helix, aggregates surveillance video, facial recognition tech and license plate data coming from security cameras at protected locations and existing image repositories. The Secret Service uses the tool to monitor sensitive areas, such as the White House complex and around the Capitol, for potential threats. 

As required by law, federal agencies must conduct a privacy impact assessment when an agency intends to identify U.S. citizens in conjunction with other data elements, according to DHS’s website. But they also typically occur before an agency develops or procures IT systems that collect, maintain or disseminate information from or about members of the public. 

“HELIX uses information in identifiable form (including video of individuals, facial images and biometric templates, license plate numbers, and associated time and location metadata) from multiple source systems and applies advanced analytics to link and analyze that data in a single environment, increasing the privacy impact beyond the original collections and necessitating a detailed assessment of risks and mitigations,” the Secret Service said in its explanation of why a PIA was necessary. 

Advertisement

A Secret Service spokesperson said the system itself is not necessarily a “new” addition to the DHS unit’s portfolio, but the agency is “continually adapting, modernizing, and integrating new technology.” 

The agency did not respond directly to a question about when the system was first deployed. 

“The U.S. Secret Service uses a variety of advanced systems at our protective sites in Washington, DC, including the White House complex and in the Naval Observatory,” the spokesperson said in an emailed statement to FedScoop. “We are unable to discuss specific means and methods used to conduct our protective operations.” 

The Secret Service recognized a number of risks associated with its Helix platform in the published PIA. Many of those risks are “partially mitigated,” per the DHS component. But privacy advocates aren’t as convinced. 

As outlined in the assessment, the Helix system has access to surveillance footage featuring members of the general public present on “adjacent public streets, sidewalks, parks and entrances/exits.”

Advertisement

“I want to know what resolution are these cameras, how far out are they getting high-quality resolution imagery of any given person,” said Patrick Eddington, senior fellow in homeland security and civil liberties at the Cato Institute. “The Secret Service could use cameras that have pan and tilt capabilities on multi-story structures. The privacy implications aren’t just at the street level.”

The Secret Service said facial recognition is “only” performed on people of interest, a category which is created and manually uploaded by the group’s Protective Intelligence and Assessment Division.

“The city is often the site of demonstrations,” Eddington said. “If you’re showing up to protest, are you now a person of interest?”

A more precise definition of what makes someone a person of interest is not provided in the PIA, a source of concern for the experts that spoke with FedScoop about the system. 

“On the one hand, the Secret Service has a really legitimate job to do,” said Rachel Levinson-Waldman, director of the Brennan Center’s Liberty and National Security Program. “On the flip side, we’re living in a time when federal law enforcement functions are being weaponized.”

Advertisement

“I worry about opportunities for misuse or for an overly broad interpretation,” Levinson-Waldman added. 

Sources also raised questions about whether the system would be independently audited, how often and for what purposes.

System activity within the platform — including user login, export actions and certain data requests — is logged and “subject to review to detect potential misuse and authorized access,” per the assessment. But the PIA did not provide information about how audits will be conducted. 

The Secret Service recognized that false matches are a risk that carries broader consequences when used in a system like Helix, though the agency said it’s a risk that “given the purpose of the collection cannot be fully mitigated.” 

Said Eddington: “I’m not aware of any facial recognition technology system that right now is 100% accurate.” 

Advertisement

Individuals are unlikely to be able to request access to their data stored in Helix because of the law enforcement purpose behind the system, nor are there direct mechanisms to contest how data is processed. 

These risks are “partially mitigated” by public notice of surveillance via the published assessment and signage at certain protected facilities, the Secret Service said. The group also said the system does not collect audio or Social Security numbers and most sensitive information is managed in other systems with their own access and amendment frameworks. 

The DHS unit pointed to several other risks, such as increased potential of tracking patterns of movement and behavior, and revealing detailed information about an individual’s activities.

Overall, the Secret Service offered few enforceable remedies to the risks identified in the assessment. 

“The fixes lean almost entirely on internal levers, policy, training, role-based access,” said Tom Bowman, policy counsel for the Center for Democracy & Technology’s Security and Surveillance Project. “It’s valuable as a disclosure, but pretty weak as an actual check.”

Advertisement

PIA pulse check 

As DHS has built out its surveillance apparatus this year, the agency has been met with criticism, in part, due to lagging transparency and accountability measures. 

The Helix privacy impact assessment is one of just a few that have been posted this year. 

“Helix is not a rogue dragnet that’s dressed up in legal language,” Bowman said, pointing to relatively short retention windows and a more narrowed use case by surveillance standards. 

“It’s a little bit like a kid who’s done their homework in a year when the rest of the class has stopped,” Bowman added. “You should be asking: Where’s everybody else’s homework?”

Advertisement

The latest update to the PIA category covering AI, machine learning and data analytics was April 2025. The most recent update to the categories covering IT and cybersecurity, as well as information-sharing and biometrics, was around the same time period. 

Helix was the only PIA published or updated this year in the category pertaining to law enforcement and surveillance tools. Prior to its publication, the last update came in September 2025. 

Besides the Helix addition, DHS appears to have updated — to some degree — one PIA and added two others this year. 

The PIA landing page for Immigration and Customs Enforcement’s immigration bond management lifecycle says it was updated at the end of January, though it’s unclear what actually changed. An assessment was approved in April for Customs and Border Protection’s new national customs automation program, which uses a third-party commercial software platform to collect trade data containing PII. The Transportation Security Administration also had a PIA approved in June that covered its crewmember access point program that will start once its predecessor is phased out this year. 

The agency has retired another four PIAs so far in 2026. 

Advertisement

“The number of PIAs has basically plummeted since this administration came into office,” Levinson-Waldman said. 

PIAs are not a perfect, bulletproof accountability lever, but they do serve as a critical tool for transparency and their absence is notable. 

“A reasonably modest, reasonably documented system shows up in a year when the paperwork machine has pretty much otherwise gone quiet,” Bowman said. “That’s one part that should probably keep people up at night — the concern is less this system than the systems that are getting built with none.”

Latest Podcasts