Procurement
DHS fusion centers tap GSA schedules for commercial data-broker feeds
Public procurement records show state and local fusion centers, funded in part through the Department of Homeland Security, have used General Services Administration contract vehicles to buy location, identity, and open-source data from commercial brokers. Officials describe the purchases as support for threat analysis; inspectors general and civil-liberties offices have flagged gaps in oversight of how those datasets are stored and shared.
The Department of Homeland Security’s network of fusion centers sits at the junction of federal grant money, state fusion-center operations, and commercial data markets. According to publicly posted GSA schedules and DHS grant guidance, those centers have used government-wide acquisition contracts to obtain feeds from data brokers rather than building every collection capability in-house.
Fusion centers were established after the 2001 attacks to pool federal, state, and local information. DHS’s Office of Intelligence and Analysis provides training, personnel, and grant support. The record shows that operational data often arrives through commercial vendors listed on GSA Multiple Award Schedules, including special item numbers covering information technology, professional services, and data analytics.
GSA schedules allow agencies and eligible state and local entities to order from pre-negotiated catalogs. Data-broker products on those catalogs have included aggregated location histories, identity-resolution services, vehicle and property records, and social-media monitoring tools marketed as open-source intelligence. Public price lists and past award notices do not always name the end user as a fusion center; they name a state homeland-security office, a fusion-center host agency, or a city police department that participates in the fusion-center program.
DHS grant documents, including Homeland Security Grant Program notices, have listed information-sharing and analytic tools among allowable costs. Inspectors general have repeatedly noted that grant recipients must follow federal privacy and civil-liberties requirements, yet the same reports have described uneven documentation of how commercial datasets are ingested, retained, and disseminated across fusion-center partners.
The Government Accountability Office has, in public reports on fusion centers and information sharing, described a patchwork of systems. According to those reports, centers vary in whether they treat broker-sourced data as law-enforcement records, intelligence products, or administrative files. That classification affects audit trails, retention schedules, and access by federal partners.
Civil-liberties offices within DHS have published assessments of fusion-center privacy policies. Those assessments, according to the published record, have found that some centers rely on vendor terms of service rather than agency-specific collection limitations when purchasing bulk commercial data. Officials have said the purchases fill gaps where traditional investigative process would be slower or legally unavailable for non-criminal threat assessment.
Data brokers selling on GSA schedules typically describe their products as derived from publicly available sources, consumer transactions, or licensed third-party databases. Privacy advocates and some members of Congress have argued that the volume and persistence of those datasets can reconstruct movements and associations at a scale that warrants the same scrutiny as government collection. DHS public statements have emphasized that fusion centers operate under state law and that commercial purchases are subject to existing procurement and privacy rules.
Procurement dockets show task orders and blanket purchase agreements rather than single headline contracts. A typical pattern, according to award notices, is a state emergency-management agency or fusion-center host using a GSA schedule holder as a reseller or integrator. The integrator then delivers dashboards, APIs, or batch files to analysts. Because GSA awards are often indefinite-delivery, the public file may list a ceiling amount without itemizing each fusion-center drawdown.
Inspector General work at DHS has previously examined fusion-center performance, grant management, and information-sharing protocols. Those reviews have not uniformly audited every commercial data feed. Where they have touched vendor data, they have pointed to incomplete inventories of systems of records and to inconsistent application of the Fair Information Practice Principles that DHS policy documents cite.
The Federal Acquisition Regulation and GSA ordering guides require that orders stay within the scope of the schedule. Scope disputes occasionally appear in bid protests or IG letters when a “data analytics” line item is used for continuous monitoring products. Public protest records are sparse for fusion-center-specific buys, in part because many orders fall below protest thresholds or are placed by state entities using federal schedules under cooperative purchasing.
Congress has, in authorization and appropriations report language, directed DHS to improve transparency around fusion-center activities and to coordinate with the Privacy and Civil Liberties Oversight Board on broader commercial-data questions. Those directives sit alongside separate debates over federal law-enforcement purchases of location data without a warrant. Fusion-center buys are often framed by officials as analytic support rather than as a substitute for court process, a distinction that civil-liberties groups dispute when the same vendor products appear in both criminal and intelligence workflows.
State fusion-center annual reports, where published, sometimes list “commercial databases” or “OSINT tools” among resources without naming brokers. Budget line items for “information technology” or “intelligence analysis support” can mask the share going to data-as-a-service. GSA Advantage listings remain the more consistent public window into what is available for order, even when the actual buyer is a fusion-center partner rather than DHS headquarters.
Oversight bodies have recommended inventories of commercial data sources, clearer rules on downstream sharing with federal partners, and training so that analysts understand the provenance and error rates of broker data. DHS components have stated that they continue to update privacy impact assessments and that fusion centers remain state-led. The procurement trail on GSA schedules, according to the public record, continues to be one of the few durable documents showing that commercial data markets are part of the fusion-center supply chain.
Whether those buys constitute a durable intelligence capability or a stopgap until better government systems exist is a policy argument the public docket does not settle. What the schedules, grant notices, and IG reports do show is a regularized path: eligibility under cooperative purchasing, a catalog of broker products, and fusion-center demand for identity, location, and open-source feeds paid in part with homeland-security funds. Further specificity would require award-level detail that agencies have not uniformly posted, not a classified annex.
The Times desk notes that living officials’ positions are paraphrased from public testimony, grant guidance, and published IG and GAO reports. No classified document is cited or claimed.