Comment on FR Doc # 2026-09158
Her YangOpposeIndividual
Summary: The commenter argues that the proposed rule is insufficient because it lacks specific technical requirements for encryption, data integrity, and multi-factor authentication. They suggest that the rule should either mandate strict adherence to federal PII standards or prohibit the electronic storage of these records entirely to prevent hacking and data theft.
This rule isn't thorough enough with respect to the technical aspects of data storage and transmission. For example, it doesn't specify what encryption and data integrity algorithms are required for data at rest and data in transit if the FFL wants to store records offsite. It doesn't go into any detail about requiring MFA for data access. Since ATF forms contain PII and there are already federal standards for the handling of PII, I think all FFLs should be required to conform to these federal standards if they're storing records in electronic form. This includes running FIPS-compliant software modules and implementing strong procedural and technical controls. Either that, or don't store this data in electronic form at all. The theft or compromise of this electronic information through hacking or phising would be devastating to gun owners and is an unacceptable risk.