Skip to main content

Treasury to End Dragnet Data Collection Under the Corporate Transparency Act

In a final rule issued today, the U.S. Department of the Treasury announced that it will no longer mandate detailed disclosure of American companies under the Corporate Transparency Act (CTA). Furthermore, the data the government already has will be deleted. This is a major policy win for privacy for all Americans. Only collection of foreign companies’ information will be enforced.

NTUF’s Taxpayer Defense Center argued in the Eleventh Circuit, on podcasts, in op-eds, and with People United for Privacy Foundation in a policy paper that the law had constitutional problems. Our sister organization, National Taxpayers Union, expressly called for the repeal of the CTA.

The CTA became law in January 2021 as a rider buried within the must-pass 2020 National Defense Authorization Act. The law demanded disclosure of “beneficial owners” of various corporate entities, including limited liability companies (LLCs), homeowners associations, and others. Overseeing this was the Financial Crimes Enforcement Network (FinCEN), the agency at Treasury specifically tasked with being a clearing house of information for law enforcement to share data. In other words, not only was sensitive financial information to be collected, the system was designed to share it widely.

Financial records are deeply personal, but the CTA provides none of the protections typically associated with tax information disclosed to the Internal Revenue Service. Indeed, that’s because the very purpose of the CTA is to gather and disseminate large quantities of financial information among multiple departments of the government. While the CTA specifically exempts nonprofit organizations from having to disclose their donor lists, making the donors themselves register their activities is simply one extra step to achieve the same ends. This is not mere hyperbole: it has happened before in cases ranging from civil rights groups to police officers in Boston. The Supreme Court has long protected the privacy of financial information because it protects the privacy of association. The CTA is a dangerous tool to hand the federal government.

The law generated lawsuits across the country, and was poised to be heard by the Supreme Court soon. Already the government had backed away from strict enforcement of the law. More than a year ago, Treasury announced the suspension of enforcement of the CTA against U.S. citizens and companies. Instead, only foreign companies would have to report under the CTA. Now the Treasury has issued a final rule ending the collection of data of American “beneficial owners” and deleting the information it already collected.

To be sure, supporters of the CTA pointed out in regulatory comments that the Treasury should not undo what Congress called to be collected. Certainly, after the recent landmark decision of Loper Bright Enterprises v. Raimondo, the courts will no longer defer to an agency’s interpretation of its governing statutes. (NTUF’s Taxpayer Defense Center was also involved in the Loper Bright case, including an amicus brief before the U.S. Supreme Court.)

In answer, the final rule points to the broad powers Congress granted the Secretary of the Treasury to exempt types of organizations from the CTA’s reporting requirements, citing powers granted in 31 U.S.C. § 5336(a)(11)(B)(xxiv). That provision allows for the Secretary of the Treasury to set aside reporting requirements if the U.S. Attorney General and the Secretary of Homeland Security agree that the information is not needed “in the public interest” and would not be “highly useful in national security, intelligence, and law enforcement agency efforts.” The Treasury’s rulemaking asserts that only foreign companies pose any significant risk of national security, intelligence, or law enforcement matters, and, conversely, the burdens on Americans to comply with the law are too great. The aim is to focus on those few areas where trouble may lurk, rather than collect financial information on Americans.

As for the data already collected, FinCEN agreed with critics of the CTA that “the values of privacy, information security, and the trust of the public all argue for the removal” of the data already collected. So, in 180 days, FinCEN will work with the National Archives and Records Administration to sweep the database of anyone who is reasonably suspected of being an American—for example if someone used a U.S. passport or driver’s license to register with the database. There will be no need for U.S. companies or U.S. citizens to specifically contact FinCEN for deleting the data; it will be automatic. (FinCEN also “does not intend to provide any acknowledgement or confirmation of the deletion of a U.S. company or U.S. person’s” data collected pursuant to the CTA.).

This final rule marks a significant restriction of a law that had the potential for a lot of abuse of Americans’ privacy. Given the repeated leaks and disclosures of private financial information, NTUF’s Taxpayer Defense Center is suing the IRS to stop other collection of donor information to nonprofits. While today’s regulation is a good first step, the battle is far from over to protect financial privacy.