Who runs the federal web, and what quietly changes.

Filing gaps

Federal sites that collect personal information are required to publish a Privacy Impact Assessment (E-Gov Act §208) and, for a system of records, a System of Records Notice (Privacy Act). This page lists sites where, as of the date shown, a published filing could not be found — with the collection evidence and the exact searches run, so anyone can re-check. Every entry here has been reviewed by a human before publication. We state what was and wasn’t found; we never assert illegality.

hightrumprx.govNo published PIA/SORN found as of 2026-07-02
PIA — none foundSORN — none found

FACT: No Federal Register notice returned by any of the ten searches above contains the terms 'TrumpRx' or 'trumprx.gov', and none of the retrieved SORN/PIA-adjacent documents (e.g., the generic 'Privacy Act of 1974; System of Records' notices, HHS OMB information-collection notices) are titled or described in a way that plainly names or scopes this specific site/program. INFERENCE: This suggests no publicly indexed PIA or SORN in the Federal Register explicitly covers trumprx.gov's third-party tracker data collection, but it is possible (a) the site/program is too new for Federal Register indexing, (b) a PIA exists only on an agency's own privacy program page (PIAs are not always published in the Federal Register — they are frequently posted directly to agency 'privacy.[agency].gov' pages instead), or (c) the underlying program is covered under a broader pre-existing HHS/CMS SORN not surfaced by these keyword searches. FACT: The domain 'trumprx.gov' and its ownership/operating agency were not independently confirmed via authoritative agency sources in this session — this assessment relies solely on Federal Register API search results plus the user-supplied domain/URL/tracker evidence. Given PIAs often are NOT filed in the Federal Register (unlike SORNs, which are a statutory Privacy Act publication requirement), the absence of a Federal-Register-indexed PIA is weaker evidence of an actual gap than the absence of a SORN. Confidence is moderate (0.55) reflecting the real possibility of an off-Federal-Register PIA that this tool cannot detect, and reflecting uncertainty since 'TrumpRx' as a named federal system may be very recently launched and not yet reflected in FR indexing.

Collection evidence
  • 1 third-party trackers
Searches run
  • TrumpRx
  • TrumpRx Privacy Impact Assessment
  • TrumpRx System of Records
  • Department of Health and Human Services drug pricing website System of Records Notice
  • direct-to-consumer drug purchasing portal HHS privacy
  • trumprx.gov
  • Most Favored Nation drug pricing website privacy impact assessment
  • HHS Privacy Act System of Records 2026-01236
  • TrumpRx (agency filter: health-and-human-services-department)
  • prescription drug affordability website consumer data collection notice
Sources checked
  • federalregister.gov/api

Reviewer note: Per CISA's public .gov registry, trumprx.gov is registered to the Executive Office of the President (White House Office); the site was built by its National Design Studio, while the underlying drug-pricing program is administered with HHS/CMS. As of 2026-07-05, no Privacy Impact Assessment (E-Gov Act §208) or System of Records Notice (Privacy Act) for the site was found in the Federal Register or the CMS PIA inventory; the site does publish an on-page privacy policy (last updated 2026-06-11) disclosing location/email collection and sharing with Cloudflare and AWS, but that notice is not itself a PIA or SORN. Because courts (Armstrong v. EOP) and DOJ OPCL treat EOP components whose sole function is to advise and assist the President as non-'agencies,' a PIA/SORN obligation may not attach to an EOP-operated site, so this absence is a documented observation, not a proven omission. The Guardian and The Drey Dossier separately reported PostHog plus an in-house tracker across the four NDS sites, portions of which were removed after 2026-06-04 press questions. Re-verify: https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv | https://trumprx.gov/privacy-policy | https://security.cms.gov/pia | https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition/definitions

highrealfood.govNo published PIA/SORN found as of 2026-07-02
PIA — none foundSORN — none found

FACT: All targeted Federal Register searches (domain name, generic program name, agency-qualified names, and generic 'System of Records'/'Privacy Impact Assessment' phrasing) returned either zero results or a set of clearly unrelated Privacy Act SORNs/PIA-adjacent notices (e.g., FDA drug program collections) with no textual link to 'realfood.gov' or a 'RealFood' program. INFERENCE: Because no SORN or PIA document specifically named or evidently covering a 'realfood.gov' site or program surfaced in the Federal Register, and no linked privacy notice was found on the site itself per the collection evidence, it is likely no PIA/SORN filing exists that plainly covers this specific site's third-party tracker collection — but this cannot be fully confirmed since (a) the operating agency for realfood.gov could not be identified from search results, and (b) some agencies host PIAs only on their own agency privacy pages rather than in the Federal Register, which this tool does not search. Confidence is moderate rather than high due to this coverage limitation of the search tool itself (Federal Register API does not index agency-hosted PIA PDF repositories).

Collection evidence
  • 1 third-party trackers
  • no linked privacy notice
Searches run
  • realfood.gov
  • RealFood program privacy impact assessment
  • System of Records Notice food program third-party trackers
  • Privacy Impact Assessment realfood
  • realfood
  • USDA RealFood initiative
  • FDA RealFood website privacy
Sources checked
  • federalregister.gov/api

Reviewer note: realfood.gov is registered to the Executive Office of the President / White House Office (CISA dotgov-data) — the same registrant as ndstudio.gov and trumprx.gov — and its footer credits the National Design Studio; its content mirrors the USDA/HHS Dietary Guidelines, but the registrant is EOP, not USDA/HHS. As of 2026-07-05 the live homepage links no privacy notice, and no Privacy Impact Assessment or System of Records Notice for realfood.gov was found in the USDA PIA inventory or the Federal Register. Because courts hold that EOP components whose sole function is to advise and assist the President are generally not "agencies" under the Privacy Act / E-Gov Act §208 (DOJ OPCL; Kissinger; Armstrong), whether a PIA/SORN duty attaches is legally unsettled — so this is recorded as "no published filing was found," not as a proven violation. The Guardian and The Drey Dossier independently report realfood.gov among NDS sites that ran reverse-proxied analytics without such filings. Re-verify: https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv ; https://realfood.gov/ ; https://www.usda.gov/privacy-policy/privacy-impact-assessments ; https://www.justice.gov/opcl/overview-privacy-act-1974-2020-edition/definitions

notabletrumpaccounts.govFiling appears incomplete as of 2026-07-02
PIA — none foundSORN — none found

FACT: Federal Register search returned two IRS 'Agency Information Collection Activities' (Paperwork Reduction Act) notices explicitly referencing 'Trump Account Election(s)' and 'Trump Account Contribution Information' (documents 2025-24257 and 2026-08228). These are PRA information-collection comment requests tied to the Trump Accounts tax/savings program administered via IRS/Treasury, not PIAs or SORNs, and they concern account-election/contribution paperwork, not the trumpaccounts.gov website's technical/analytics data collection. FACT: Several generically titled 'Privacy Act of 1974; System of Records' notices appear repeatedly in searches (e.g., 2026-07514, 2026-08114, 2026-09339, 2026-00809, 2026-06606, 2026-12596, 2026-01444) but their titles alone do not identify agency or subject matter, so it cannot be confirmed whether any of these SORNs cover the Trump Accounts program or the trumpaccounts.gov site specifically; this is treated as unresolved/inconclusive rather than confirmed coverage. INFERENCE: No search returned a PIA or SORN whose title or metadata explicitly names 'trumpaccounts.gov,' the Trump Accounts web portal, or describes web analytics/session-replay/third-party tracker data collection on that site. Given the observed evidence (session replay, third-party trackers, no linked privacy notice) and the absence of any Federal Register filing plainly covering the website's own PII collection mechanisms, the collection appears to lack a clearly matching, publicly identifiable PIA/SORN as of this search — classified as no_filing with moderate confidence, since the ambiguous generic SORN titles could not be ruled in or out without full-text access.

Collection evidence
  • session replay detected
  • 2 third-party trackers
  • no linked privacy notice
Searches run
  • Trump Accounts
  • trumpaccounts.gov
  • Trump Accounts Privacy Impact Assessment
  • Trump Accounts System of Records Notice
  • Department of Treasury Trump Accounts children savings
  • IRS Privacy Act System of Records Trump Account
  • Bureau of the Fiscal Service Trump Account website privacy
  • Treasury.gov Trump Accounts Privacy Impact Assessment web tracking
  • One Big Beautiful Bill Trump Account IRS system of records
Sources checked
  • federalregister.gov/api

Reviewer note: As of 2026-07-05, trumpaccounts.gov is the public front door for the Treasury/IRS Trump Accounts program (P.L. 119-21 §70204); the site itself was built and is operated by the White House National Design Studio, an Executive Office of the President office (The Guardian, 2026-06-28). Treasury filed privacy paperwork for the PROGRAM — a Trump Accounts Program (TAP) Privacy & Civil Liberties Impact Assessment dated 2026-04-15 and a TAP System of Records Notice (Federal Register 2026-07514, 2026-04-17) — but the SORN's records are account-holder PII retrieved by SSN/account number, and neither filing describes the site's third-party analytics, session-replay, or visitor-IP collection. No published PIA/SORN covering the WEBSITE's web-tracking was found after checking the Federal Register API, Treasury's DO PCLIA inventory, and Treasury/IRS privacy pages. Correct classification: incomplete_filing (the canonical 'Trump Accounts case'). Observation about published filings, not a legal conclusion. Before publishing: open the TAP PCLIA PDF from the inventory to confirm it doesn't name the site analytics, and eyeball the live page for a privacy link (homepage 403s automated fetch; 'no linked privacy notice' rests on Daylight's own capture). Re-verify: SORN text https://www.federalregister.gov/documents/full_text/text/2026/04/17/2026-07514.txt · Treasury PCLIA inventory https://home.treasury.gov/footer/privacy-act/privacy-and-civil-liberties-impact-assessments/do-pclia · TD 81-08 https://home.treasury.gov/about/general-information/orders-and-directives/td81-08 — [researched by Claude, 2026-07-05]

highusadf.govNo published PIA/SORN found as of 2026-07-02
PIA — none foundSORN — none found

FACT: Multiple targeted Federal Register API queries (by keyword, by agency slug variants 'african-development-foundation' and 'u-s-african-development-foundation', and by combined terms like 'Privacy Act', 'System of Records', 'Privacy Impact Assessment') returned no documents issued by or clearly attributable to the U.S. African Development Foundation (USADF) concerning a Privacy Act System of Records Notice or an E-Gov Act Privacy Impact Assessment. All returned hits were from unrelated agencies (Dept. of Education, NSF, NOAA, SEC, OPM, etc.), indicating the search terms did not surface a USADF-specific filing in the Federal Register's notice corpus. INFERENCE: This absence suggests USADF may not have a Federal-Register-published SORN or PIA specifically indexed under these search terms, but it is possible (a) USADF publishes its PIAs only on its own website (as many small agencies do, since only SORNs are legally required to appear in the Federal Register, not PIAs) rather than filing them federally, (b) the agency name is indexed differently in the Federal Register's agency taxonomy than the slugs tried, or (c) a relevant SORN exists under a very old document number/title not surfaced by these keyword queries. No public-knowledge claim is being made about USADF's actual privacy program beyond what the tool returned; this is a negative result based solely on Federal Register API searches and should be independently re-verified by checking usadf.gov's own privacy policy page and the DOJ's government-wide SORN compilation, which are outside the scope of the tool used here. Given the observed collection (email via form; 3rd-party trackers) is a common, lower-sensitivity PII pattern, absence of a dedicated SORN/PIA is not itself evidence of wrongdoing, per instructions not to assert illegality.

Collection evidence
  • 3 third-party trackers
  • collects PII via form: email
Searches run
  • African Development Foundation System of Records
  • African Development Foundation Privacy Impact Assessment
  • USADF Privacy Act System of Records Notice
  • usadf.gov privacy
  • agency:african-development-foundation Privacy Act
  • U.S. African Development Foundation notice of a new system of records
  • African Development Foundation grants applicants records notice
  • agency:u-s-african-development-foundation privacy
  • "African Development Foundation" Privacy Act system of records
Sources checked
  • federalregister.gov/api

Reviewer note: usadf.gov is operated by the U.S. African Development Foundation, a small independent federal agency (CISA dotgov registry). Its Floodlight capture shows third-party analytics (Google Analytics, property UA-199072212-1, served from google-analytics.com) and an email-collecting contact form. As of 2026-07-05, no Privacy Impact Assessment covering the site's web measurement was found on the agency's own pages (/privacy, /oversight) or via site search, and no Privacy Act System of Records Notice appears in the agency's Federal Register history (115 documents, all board-meeting notices and general rules; zero SORNs). A general Privacy Notice/Privacy Program page exists at usadf.gov/privacy, but its full text is script-rendered and could not be read from static HTML; a privacy notice is not a PIA or SORN. Separately, the registry lists usadf.gov's security contact as akash@ndstudio.gov, an apex registered to the Executive Office of the President, unlike sibling apex adf.gov, which uses an in-agency contact. Re-verify: https://www.usadf.gov/privacy | https://www.federalregister.gov/agencies/african-development-foundation | https://raw.githubusercontent.com/cisagov/dotgov-data/main/current-federal.csv

Redtape — filing gaps · Daylight