There’s a lot going on here, and I’m no fan of CBP but this is pretty much a low-grade by the book contractor failure here. They receive training on all of these things, and have gone through a lengthy award and due diligence process and then all it takes is one person thinking “hey I think I’ll take a sample dataset back to my Dev laptop to test things.” Could be a newbie or a senior - who knows, but it’s happened before.
Go after CBP for constitutionality of collection, for working outside of borders where they are legally not allowed to work, etc, but in this case I’d say let’s not blow things too out of proportion.
Remember when OMB lost hundreds of thousands of detailed compromising personal background check reports with all the identifying information including biometrics? This sounds like some port of entry data you could get with a camera in public.
Further: they are not absolving themselves. They are probably working their asses off right now to make sure this never happens again but somebody is going to pay for credit protection and insurance, and it should be the contractor that ignored their contract and all sensible security policy. So, there is is in the press release.
Lastly: I don’t think GDPR fixes this. Government (especially intel community and law enforcement) keeps the data as long as their record schedules allow.
Thankfully, laws about breaches required them to reveal this to us within a certain time. Privacy Officers have really hard jobs. To do them well is hard and thankless. Glad this one stuck to the law.