The U.S. Department of Transportation (DOT) has concluded its review of data privacy practices among major airlines without levying any penalties, according to a memo dated September 4. The review, initiated during the Biden administration, examined how the top 10 carriers handle passenger data amid concerns over potential misuse and inadequate protections.

The DOT’s internal memo—reported on October 6—indicates that the department conducted a comprehensive assessment of the airlines’ compliance with relevant laws and policies governing consumer data privacy. Ultimately, the agency found no violations that warranted enforcement actions or penalties.

This decision comes despite expressions of concern from several lawmakers who argued that some airlines failed to adequately safeguard personal information and may have exploited it for purposes beyond customers’ consent. While the DOT has not publicly commented on the outcome, the memorandum asserts that the investigation did not uncover any legal breaches.

The airlines under review represent the largest sector of U.S. passenger carriers, highlighting the scope of data collection practices in the aviation industry. Issues surrounding airline data privacy have attracted increasing scrutiny amid growing awareness of how personal information is collected, stored, and potentially shared.

The closing of the inquiry without sanctions underscores the challenges regulators face in balancing consumer privacy protections with industry practices and existing legal frameworks. It also reflects the current state of federal oversight in this area, where regulators assess compliance based primarily on statutory and policy criteria.

As travelers continue to rely heavily on digital tools and services provided by airlines, questions remain about the sufficiency of privacy safeguards and transparency. The investigation’s conclusion leaves open the possibility for future regulatory attention should new evidence emerge or standards evolve.