Executive Order 14385 — Protecting the National Security and Welfare of the United States and Its Citizens From Criminal Actors and Other Public Safety Threats
Table of Contents: Executive summary and principal findings; Text and immediate legal footing of EO 14385; What the order formally requires versus how it operates in practice; Policy mechanisms and administrative pathways the order triggers; Who benefits and who bears the costs; Institutional, constitutional, regulatory, and economic implications; Litigation exposure, legal durability, and reversal pathways; Implementation feasibility, agency capacity, and budget effects; Second‑order consequences, risks, and likely abuses; Corruption and self‑dealing scenarios (speculative); Conclusion and urgent recommendations.
Executive summary and principal findings
Executive Order 14385, signed February 6, 2026, commands the Attorney General to provide the Department of Homeland Security (DHS) “access, for purposes related to DHS’s screening and vetting missions and to the maximum extent permitted by law, to criminal history record information (CHRI) available to or maintained by the Department of Justice.” The Order also authorizes DHS to exchange felony conviction records with Visa Waiver Program (VWP) states, nations that have entered into “Preventing and Combating Serious Crime” or similar agreements with the United States, and “other trusted allies,” on a reciprocal, agreement‑by‑agreement basis that the EO describes as subject to privacy safeguards. The White House and the Federal Register text are consistent and clear as primary sources. (whitehouse.gov)
The EO’s text is short and framed as administrative coordination, but its practical reach is expansive. By directing DOJ to give DHS the CHRI it “may provide” under existing law and by greenlighting reciprocal exchanges with foreign partners, the Order attempts to institutionalize broad federated and international access to sensitive criminal records for immigration screening. The Order is not itself a statute and explicitly disclaims creating judicially enforceable rights; nevertheless, its central commands push agencies to stretch regulatory and intergovernmental authorities and to operationalize cross‑system data sharing that raises acute privacy, civil‑liberties, and geopolitical risks. (public-inspection.federalregister.gov)
This report finds that the Order is functionally designed to expand executive capacity to aggregate, analyze, and share CHRI for immigration and border screening, and to press foreign partners into reciprocal data arrangements as a condition of program participation or favor. That expansion will benefit federal immigration and enforcement actors and political constituencies prioritizing heightened immigration enforcement. It will impose costs on immigrants and travelers, on privacy and civil‑liberty norms, on historically over‑policed communities, and on allied nations whose citizens may be subject to intrusive U.S. queries. The EO is exposed to predictable legal challenge under the Privacy Act, the Administrative Procedure Act (APA), statutory limits governing CHRI dissemination (including Title 28 and the CJIS framework), and constitutional doctrines when implementation chills protected speech or association. Prior administrative drives to centralize and access Americans’ personal data have prompted litigation and have been enjoined in other contexts; the legal architecture that regulates CHRI is complex and will constrain—but not necessarily prevent—the EO’s operational ambitions. (public-inspection.federalregister.gov)
Text and immediate legal footing of EO 14385
The Executive Order is two substantive paragraphs long in its operative sections. Section 2 orders the Attorney General to grant DHS access to CHRI in DOJ custody “to the maximum extent permitted by law” for DHS screening and vetting missions. Section 3 authorizes the Secretary of Homeland Security to exchange CHRI with VWP countries and other “trusted allies” on the basis of reciprocity and under DHS agreements that “contain appropriate safeguards” to protect United States persons and other individuals, and to use that information “for the sole purpose of screening travelers and immigrants seeking to enter or stay” in partner countries. The EO cites 6 U.S.C. 122(a)(2) as part of its authority and otherwise leaves agencies to effectuate the directives “consistent with applicable law and subject to the availability of appropriations.” The published Federal Register entry is the authoritative text. (public-inspection.federalregister.gov)
That statutory citation (6 U.S.C. 122(a)(2)) ties the Order to existing DHS missions, but it does not supplant detailed statutory and regulatory regimes that govern criminal history data dissemination. Federal criminal history records are primarily governed by the Attorney General’s authorities and by a matrix of statutory provisions, DOJ regulations, and FBI Criminal Justice Information Services (CJIS) policies—principally 28 U.S.C. § 534 (DOJ authority to maintain and exchange criminal identification and related records), Title 28 of the Code of Federal Regulations (Part 20) governing CHRI dissemination, the CJIS Security Policy, and the National Crime Prevention and Privacy Compact. These instruments condition who may receive CHRI, for which purposes, and under what technical and audit requirements. Any DOJ or FBI change to longstanding dissemination practices will need to be reconciled with these preexisting constraints. (fbi.gov)
What the order formally states and how it operates in practice
Formally, EO 14385 reads as an inter‑agency instruction requiring DOJ to make available criminal history records to DHS for civil‑administrative screening missions and permitting DHS to negotiate reciprocal exchanges with foreign partners. On paper the EO repeatedly conditions action on existing lawful authority, on reciprocity for foreign exchanges, and on “appropriate safeguards.” The White House version reiterates the administration’s framing that the measures are limited to border security and public safety purposes. (whitehouse.gov)
In practice, however, the EO performs three distinct functions. First, it acts as a high‑level political signal that pressure‑tests the boundaries of DOJ and FBI dissemination policies by urging maximum sharing “permitted by law.” That signaling changes institutional incentives: DOJ and FBI lawyers will be incentivized to reinterpret Part 20 and CJIS guidance more liberally; DHS will accelerate requests and resource commitments; and partner states will face diplomatic pressure to accept or reciprocate data exchanges as a condition of program inclusion or preferred treatment. Second, the EO lowers the political cost for DHS to seek programmatic access to CHRI and to use CHRI across an expanded set of immigration screening adjudications, making routine previously exceptional uses. Third, the EO creates operational pressure to craft interlocking memoranda of understanding (MOUs), technical interfaces, auditing protocols, and contract vehicles for private vendors that will materially alter who touches sensitive data and under what security regimes. These real‑world processes often exceed the cautious constraints suggested by the EO’s text and by the CJIS rules; prior federal pushes to centralize data produced both expanded access and recurring compliance and auditing crises. (fbi.gov)
Policy language decoded and the mechanisms the order sets in motion
The EO’s operative phrase “to the maximum extent permitted by law” is the pivot. That phrase operates as a directive to agency counsel to maximize permissible sharing under current statutory and regulatory doctrines, and to minimize conservative readings that protect privacy. In administrative practice this language will generate internal legal memoranda asserting broad statutory constructions, written justifications to permit expanded CHRI use (for example asserting that “screening and vetting” fall within established immigration and national‑security exceptions), and requests to alter or expand the functional definitions used by CJIS and FBI systems about authorized purposes. The CJIS system requires authorized purpose statements, originating agency identifiers, and technical security agreements. Translating the EO into practice therefore entails procurement work, new ORI codes and audit trails, revisions to system of records notices under the Privacy Act if user scope changes, and likely interagency memoranda that recast DHS roles as “criminal‑justice purpose” actors for CHRI. The DOJ and FBI possess both statutory levers and regulatory discretion that can be deployed; the EO’s plain function is to push them in that direction. (fbi.gov)
Beyond domestic sharing, Section 3’s international exchange authorization incentivizes DHS to negotiate CHRI‑sharing MOUs with VWP members and other “trusted allies.” The VWP already embeds information‑sharing expectations and has historically required Preventing and Combating Serious Crime (PCSC) or equivalent agreements, but those agreements have long suffered from asymmetric capability and reciprocity problems. Converting political pressure into binding foreign‑agency data access agreements will involve conditioning program membership or operational privileges on partner nations’ acceptance of U.S. queries, technical compatibility with FBI systems, or direct bilateral access. Such arrangements risk expanding U.S. access to partner police databases and, conversely, enabling foreign governments to seek deeper U.S. access to U.S. data—or to raise human‑rights and privacy concerns for migrants and asylum seekers in partner states whose records are more porous or politically manipulated. The operational mechanism thus becomes both data diplomacy and technical integration—each with its own legal and compliance constraints. (everycrsreport.com)
Who benefits and who bears the costs
The beneficiaries are intellectually simple to identify: DHS and its component enforcement elements (CBP, USCIS, ICE), DOJ and FBI programs that trade or monetize enforcement cooperation, contractors building the interfaces and analytics (identity verification, biometric matching, database integration), and political constituencies that reward stricter immigration enforcement. Allies amenable to U.S. technical standards and whose political systems privilege cooperation may gain leverage and diplomatic capital. These actors will secure augmented data flows that expand surveillance, enforcement efficiencies, and control over border management decisions.
The costs fall on multiple fronts. For noncitizens and travelers, the expansion of CHRI access and the internationalization of felony records increases the risk of misclassification, detention, denial of admission, and expedited removals on the basis of incomplete, inaccurately transcribed, or foreign‑system convictions that cannot be reliably adjudicated in U.S. administrative processes. For citizens and lawful residents whose records may appear in CHRI exchanges (for example where a U.S. person’s name or identifiers are mistakenly matched), the privacy and redress costs are significant; CHRI systems are error‑prone and state practices for record correction vary considerably. For civil liberties and minority communities, broader CHRI use is likely to deepen discriminatory enforcement, amplify pretextual stops, and chill associational and expressive activities when activist or migrant communities understand their records are more likely to be queried internationally or used in immigration adjudications. For allied states, these arrangements risk export of U.S. policing standards and data practices that may conflict with partner privacy or human‑rights norms. For the public fisc, costs will include engineering, contracting, compliance auditing, CIS system upgrades, training, and legal defense against litigation. (fbi.gov)
Institutional, constitutional, and regulatory implications
Institutionally, EO 14385 centralizes a policy preference for maximal interagency and international data sharing. It encourages legal reinterpretation rather than legislative change, pushing agencies to use existing statutory regimes as permissive scaffolding. That strategy is familiar: when Congress is politically blocked, Administrations use executive direction to remodel administrative practice. The Order therefore risks reconfiguring the baseline operating assumptions of DOJ and DHS and effectively expands executive capacity to assemble cross‑domain datasets without new statutory authorization. Where agencies move forward by administrative rule or contractual arrangements with private vendors to operationalize broad CHRI exchange, the move will court sustained oversight and litigation. (fbi.gov)
Constitutionally, the most immediate risks are tied to privacy, due process, and the potential for viewpoint or association‑based chilling effects where CHRI becomes a vehicle for immigration denial or law enforcement surveillance of political actors. While the Fourth Amendment’s protections are centered on search and seizure doctrines, expansive data sharing that facilitates administrative deprivation of liberty (detention or removal) without adequate procedural safeguards raises serious Fifth Amendment due‑process questions. The Order’s nonjudicial remedy waiver clause—“not intended to, and does not, create any right or benefit enforceable at law”—does not insulate implementing agency acts from constitutional or statutory challenge, particularly where agencies engage in rule‑making or change system of records notices under the Privacy Act. (public-inspection.federalregister.gov)
Regulatory implications run to the heart of DOJ/FBI CJIS controls. Title 28 CFR Part 20 circumscribes dissemination of CHRI, limiting access to criminal justice agencies and specifying permissible noncriminal uses and audit obligations. The CJIS Security Policy imposes strict security and audit obligations for technical participants. To expand DHS access and permit foreign exchanges that are deeper than prior practice, the agencies will likely have to create new CJIS user ORIs, establish security addenda, prepare privacy impact assessments, and possibly amend system of records notices pursuant to the Privacy Act. Each of these steps triggers notice, comment, or inter‑agency clearance and thus becomes a potential litigation flashpoint under the APA if agencies are found to have circumvented procedural requirements. (fbi.gov)
Litigation exposure, legal durability, and reversal pathways
EO 14385 is susceptible to several predictable legal attack vectors. Plaintiffs can plausibly bring APA claims where agency implementations constitute “significant” rule changes without required notice and comment, or where agencies fail to prepare system of records notices and adequate Privacy Act compliance. Privacy Act challenges may arise if interagency sharing is broadened without required notice and limits. Constitutional claims under the Fifth Amendment may be litigated where administrative uses of CHRI produce deprivation without adequate process, or where enforcement disproportionately targets protected classes. The administration’s prior data‑centralization efforts have already produced litigation and injunctions in related domains, demonstrating a litigation environment predisposed to challenge such expansions. In other recent cases involving aggressive executive action, courts have issued preliminary relief when plaintiffs demonstrated likelihood of constitutional and statutory harms. These precedents make litigation a realistic and likely check on administrative overreach, even if courts ultimately allow some forms of sharing. (democracydocket.com)
A subsequent administration that sought to reverse EO 14385 can do so through multiple concrete pathways. The simplest and fastest is to rescind the Executive Order and to instruct agencies to suspend any new MOUs or technical integrations. Rescission would not automatically unwind already‑executed agreements or technical changes, so subsequent actions should include revoking agency directives, terminating MOUs that exceed statutory authority, directing the FBI and DOJ to freeze new CHRI dissemination authorizations, and directing DHS to halt foreign CHRI exchanges pending statutory authorization. Longer‑term reversal tools include withdrawing appropriations for new interfaces, reasserting conservative CJIS access standards, and supporting litigation defenses that protect privacy. Congress can also pass targeted legislation to block certain disclosures or to require judicial warrants or specific statutory procedures before CHRI can be used for immigration removal. Each of these pathways has precedent and is viable; legal undoing will require coordinated executive, legislative, and—if necessary—judicial steps. (fbi.gov)
Implementation feasibility, agency capacity, and procedural requirements
Operationalizing the EO implicates significant technical, personnel, and compliance tasks. The FBI’s CJIS and associated systems (IAFIS/NGI, NCIC, Interstate Identification Index) are not open, frictionless databases that can be simply “switched” to grant new access. They require originating agency identifiers (ORIs), security addenda, CJIS security vetting of personnel, defined authorized purposes, and auditable interfaces. DHS entities seeking CHRI must obtain CJIS authorization, implement robust information security controls, and accept periodic audits. Where private contractors are used to build or host interfaces, careful contracting and security addenda must be negotiated and monitored. These processes take months to years depending on scale. The EO places the fiscal and publishing cost for itself on DHS, but significant upfront funds will be required to engineer secure, compliant interfaces and to staff expanded vetting operations. DHS has previously estimated large costs for biometrics collection, processing, and system upgrades in other rulemakings, indicating the potential scale of fiscal impact. (fbi.gov)
Procedurally, many concrete steps implicated by the EO will trigger statutorily imposed administrative obligations. System of records changes under the Privacy Act require public notice and an opportunity for comment where systems of records are significantly changed. Substantive rules to implement new statutory or regulatory obligations require notice and comment unless agencies claim an exception for matters of national security—an exception that will itself be litigated if overused. Agencies are also required to coordinate with OMB on privacy and data‑sharing policies, to prepare privacy impact assessments, and to consult with Congress in circumstances where statutory authority or appropriations may be implicated. Failure to follow those procedural guardrails is a predictable basis for successful litigation. (law.justia.com)
Fiscal and economic impacts (quantification where possible) and resource implications
EO 14385’s text contains one narrow fiscal allocation clause—the costs for publication of the Order shall be borne by DHS—but it does not estimate the realoperational fiscal consequences. Quantifying full budgetary impact requires modeling expenditures for system integration, personnel, CJIS compliance, contracting, audits, training, and legal defense against likely litigation. Historic DHS rulemakings and biometric initiatives provide useful analogues: the DHS rulemaking on biometrics and employment authorization included detailed, multi‑billion dollar estimates and revealed that major biometric and screening changes can involve tens of millions to billions of dollars in additional program costs when aggregated across operations, travel, and processing burdens. These precedents show the EO could easily create multi‑year, multi‑hundred‑million dollar—potentially multi‑billion dollar—commitments if DHS opts for broad implementation across immigration adjudications and if a network of international exchanges is pursued. Moreover, indirect economic costs will include delays and processing backlogs that translate into higher administrative costs, potential labor market impacts where work authorization is delayed or denied, and the need for state and local actors to process or respond to federal requests. The EO’s narrow publication cost clause is therefore materially misleading as an indicator of the action’s fiscal modesty. (regulations.justia.com)
Anticipated second‑order effects, unintended consequences, and spillovers
Several predictable second‑order effects should be anticipated. First, data asymmetry: the U.S. may press partners to provide detailed police and conviction data while refusing broad reciprocal access or judicial protections, creating inequities and diplomatic friction. European partners in particular have resisted unconditional reciprocity because of privacy protections—and past negotiations over VWP reciprocity have stalled over precisely these imbalances. Second, error cascades: CHRI systems contain transcription errors, differences in conviction nomenclature, and jurisdictional disparities that when ported into immigration decisionmaking produce erroneous denials, detention, or removal risks. Third, geopolitical misuse: where the U.S. relies on partner states with weak rule-of-law or repressive record‑keeping, the lists exchanged could be weaponized by partner regimes to target dissidents who might be mistaken for criminal actors, or conversely, the U.S. could become complicit in foreign human‑rights abuses through data sharing. Fourth, expanding databases incentivize mission creep: once agencies build the technical means to aggregate and match records at scale, political pressure to use those capabilities for additional enforcement or domestic surveillance tasks will follow. Finally, market distortions will flow to private contractors who build and operate interoperability and analytics layers; this creates new rent‑seeking incentives and privatized surveillance ecosystems that are inherently difficult to oversee. These second‑order dynamics are not speculative: advocacy groups and independent trackers have repeatedly warned against federal demands for access to partner police databases and have documented the risky incentives that follow. (statewatch.org)
Harms and risks with specificity and substantiation
The most acute harms are concrete and measurable. Administrative denials of admission and expedited removals that rely on foreign conviction data are immediate harms that can be counted in denied entries and removal orders. CHRI misidentification produces wrongful detentions; even short detentions impose economic harms in lost wages and legal costs and inflict reputational and psychological injuries. The expansion of CHRI exchange will disproportionally affect migrants from countries with aggressive policing, weak record‑correction mechanisms, or where convictions are politically motivated—making certain nationalities or ethnic groups more vulnerable to administrative exclusion. The erosion of privacy norms for U.S. citizens is also measurable: broader CHRI queries increase the risk that U.S. persons will have their names checked against foreign databases and erroneously flagged, creating secondary burdens in administrative clearance times and litigation to correct records. The cumulative threat to democratic safeguards—where executive power is used to build large, searchable datasets about millions of individuals with limited independent oversight—adds systemic risk that may be realized in political weaponization of data or in chilling of civil society. These are not abstract possibilities but predictable outcomes of a policy that normalizes expansive data sharing for enforcement purposes. (fbi.gov)
Downstream developments in the policy area and relevant precedents
This EO sits in a pattern of recent executive actions pushing for broader inter‑agency data access and foreign data exchanges tied to immigration and national‑security imperatives. Prior rulemakings and EOs have similarly prioritized data centralization, biometrics expansion, and foreign data agreements. For example, DHS rulemakings late in 2025 and in 2026 on biometric collection and refugee/asylum processing show the department’s trajectory toward automated foreign CHRI queries for adjudications and highlight large fiscal and administrative footprints. Advocacy groups have already sued to block federal data centralization projects in related domains, and civil‑liberties organizations have flagged the same risks EO 14385 advances. These downstream developments demonstrate both implementational feasibility (agency willingness to invest) and litigation risk (civil‑society readiness to sue). In short, EO 14385 is part of a sustained push rather than an isolated incident, and the same actors, processes, and legal battlegrounds will shape its aftermath. (regulations.justia.com)
Corruption, bribery, and self‑dealing: speculative worst‑case scenarios
Executive power over sensitive data, procurement, and foreign arrangement leverage creates fertile ground for corruption if institutional safeguards are eroded. One plausible path to self‑dealing is the creation of no‑bid or sole‑source contracts to build CHRI interconnectivity platforms and analytics layers where decisionmakers award lucrative contracts to firms connected to officials, their families, or political allies. A narrow set of contractors could win multi-year, multi‑hundred‑million dollar service agreements without transparent procurement if the administration asserts national‑security exceptions. These contractors could then subcontract to shell companies or distribute kickbacks in the form of consulting fees, board seats, or equity stakes to officials or their relatives. Alternatively, foreign MOUs awarding privileged access could be conditioned informally on procurement relationships or post‑MOU business favors to foreign entities that are intermediaries for U.S. firms or officials’ associates. Another form of political corruption is the instrumentalized use of CHRI data to harm political opponents—selectively leaking derogatory criminal records, flagging opponents for administrative actions, or prioritizing enforcement against politically inconvenient groups under the veneer of “screening.” The EO’s design—delegating large discretion to DOJ and DHS and encouraging private contracts for technical work—creates multiple attractive vectors for bribery, embezzlement, nepotism, and transactional diplomacy if oversight is weak. The worst conceivable abuses include funneling no‑bid contracts tied to MOUs into private entities controlled by insiders, awarding foreign‑access privileges in exchange for campaign or personal favors, and using enriched datasets to pursue targeted political retribution—each of which would be criminal, corrosive of democratic norms, and difficult to unwind absent robust oversight and criminal enforcement. These are hypothetical but realistic abuses that follow logically from the convergence of concentrated executive discretion, opaque procurement, private contractor dependence, and cross‑border bargains the EO implicitly encourages. (fbi.gov)
Conclusion and urgent recommendations
Executive Order 14385 is presented as a narrow administrative coordination measure, but in context it is a strategic lever to expand executive authority over sensitive criminal records domestically and internationally. Its plain wording funnels agencies toward maximal sharing, and its practical effect will be to create durable technical, diplomatic, and contractual architectures that normalize expanded surveillance of migrants, travelers, and—through misidentification risks—U.S. persons. The harms to privacy, due process, and vulnerable communities are real and measurable; litigation and legislative pushback are likely and sensible checks.
Urgent recommendations for opponents and for any subsequent administration seeking to mitigate harm include immediate suspension of new MOUs and technical integrations pending Privacy Act and CJIS review; imposing a moratorium on new procurement related to CHRI exchange unless subject to transparent competitive processes; requiring public Privacy Impact Assessments and system of records notices before any new dissemination begins; instituting external audits and Congress‑mandated reporting on any data transfers and on error‑correction mechanisms; and, where appropriate, rescinding the EO and restoring conservative CJIS access standards. Congress should consider clarifying statutory limits on domestic and foreign CHRI dissemination and demanding express legislative authorization for any international exchanges that exceed current Compact or VWP frameworks. Civil society should be resourced to litigate procedural defects promptly, and federal courts should insist on the procedural safeguards the Privacy Act and APA require. The stakes—privacy, rule of law, and protection against the weaponization of personal data—are too high to be resolved through opaque, accelerated implementation. (public-inspection.federalregister.gov)
This report has relied on the Executive Order as published in the Federal Register and on official White House text for the EO’s language, and it has situated the Order against primary statutory and regulatory materials governing criminal history data, the FBI CJIS framework, Visa Waiver Program policy, and recent agency and civil‑society responses to related federal data‑access initiatives. The analysis identifies probable administrative pathways by which the EO will be operationalized, quantifies the categories of fiscal exposure and social cost, and maps realistic legal and political avenues to reverse or constrain unlawful or harmful implementation. The described harms are grounded in regulatory text and in contemporaneous reporting and oversight litigation that document both the administration’s track of similar actions and the predictable legal friction those actions create. (public-inspection.federalregister.gov)