Civic / Privacy / Digital Rights

The Architecture of Inference: Registry-Equivalent Knowledge in the Age of Ubiquitous Data

Report summary

The proliferation of digital ecosystems has fundamentally altered the paradigm of information collection. Historically, for a government or large corporation to maintain a comprehensive list of individuals possessing a certain trait—be it political affiliation, religious belief, or the ownership of

Status
Research archive item
Category
Civic / Privacy / Digital Rights
Length
6,050 words
Reading time
28 minutes
Report type
architecture

Key topics

  • Civic / Privacy / Digital Rights
  • Civic
  • Privacy
  • Digital Rights
  • AI
  • Runtime
  • Research Archive
  • Audit
  • Architecture

Research provenance

Archive status
Research archive item
Content identity
sha256:3ee167ee58c70937e062921968fc19a3f21707cbfec130acb4a49f28bcba5c2a

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

The proliferation of digital ecosystems has fundamentally altered the paradigm of information collection. Historically, for a government or large corporation to maintain a comprehensive list of individuals possessing a certain trait—be it political affiliation, religious belief, or the ownership of specific assets—it required the overt construction of a centralized database. Such databases, colloquially known as registries, have long been the subject of fierce legal, constitutional, and social debate. In democratic societies, explicit registries of constitutionally protected or socially sensitive activities are often strictly regulated or outright prohibited by statute. However, the modern data economy does not require explicit collection to achieve absolute visibility. Through the aggregation of commercial data brokers, machine-learning entity resolution, probabilistic inference, and cross-dataset correlation, actors can now construct profiles that mirror the granularity and comprehensiveness of a forbidden database. This phenomenon can be defined as "registry-equivalent knowledge." By fusing disparate, individually innocuous, and legally permissible datasets, algorithms can deduce sensitive attributes with profound accuracy. This report investigates the technical mechanics, legal frameworks, and constitutional implications of registry-equivalent knowledge. Utilizing firearm ownership in the United States as a primary case study, the research demonstrates how multiple lawful datasets could produce a sensitive inferred category without any database explicitly containing that field. Furthermore, the analysis examines the treatment of inferred data under European and American privacy laws, the limitations of the Fourth Amendment's mosaic theory, and the chilling effects such capabilities project onto constitutionally protected activities.

Defining Registry-Equivalent Knowledge

Registry-equivalent knowledge is the capability to reconstruct a prohibited or highly restricted centralized database through the probabilistic fusion of decentralized, non-restricted data streams. A traditional registry relies on deterministic, self-reported, or officially recorded data explicitly stored under a defined schema (e.g., Name, Address, Firearm Serial Number, Medical Diagnosis). In contrast, registry-equivalent knowledge relies on inferential logic. It does not store the sensitive attribute directly; rather, it stores the statistical probability that an entity possesses the sensitive attribute, derived from behavioral, transactional, biometric, and locational proxies. The creation of registry-equivalent knowledge represents a shift from surveillance by collection to surveillance by inference. When legal frameworks prohibit the state from explicitly asking a question or recording an answer, this inferential architecture allows the state—or corporate actors operating in unregulated commercial spaces—to deduce the answer with a degree of certainty that makes the legal prohibition functionally obsolete. This raises profound questions about whether statutory bans on data collection hold any weight if the same insights can be purchased from a commercial data broker or assembled algorithmically.

The Technical Architecture of Inference

To comprehend how registry-equivalent knowledge is generated, it is necessary to examine the underlying mechanisms of modern data science. The process relies on record linkage, entity resolution, data fusion, and probabilistic classification.

Record Linkage and the Fellegi-Sunter Model

At the core of data fusion is record linkage—the statistical process of identifying records in disparate datasets that refer to the same real-world entity. When unique, deterministic identifiers (like a Social Security Number or a standardized national ID) are absent, obscured, or legally protected, data scientists must rely on probabilistic matching. The foundational mathematics for probabilistic record linkage were formalized in 1969 by Ivan Fellegi and Alan Sunter1. The Fellegi-Sunter model provides a statistical framework for calculating the likelihood that two records match based on the agreement or disagreement of various attributes, such as names, birth dates, or geographic locations3. The model relies on two critical probabilities:

1. The m-probability: The likelihood that a matching variable agrees given that the two records truly belong to the same entity (accounting for typographical errors or variations in spelling)5.

2. The u-probability: The likelihood that a matching variable agrees by pure chance given that the records actually belong to different entities (accounting for common names like "John Smith")5.

By applying the Expectation-Maximization (EM) algorithm, modern machine learning models can estimate these parameters iteratively without requiring manually labeled training data2. The EM algorithm iterates back and forth between calculating the expected match status of record pairs and maximizing the log-likelihood of the observed data, automatically calibrating the weights of different variables6. This allows an algorithm to ingest a massive database of property records, a dataset of advertising identifiers, and a dataset of consumer purchases, stitching them into a single, cohesive identity profile with calculable precision and recall metrics5.

Entity Resolution and Data Fusion

Modern entity resolution engines build upon the Fellegi-Sunter framework by incorporating machine learning and graph analytics to handle massive, unstructured data silos. Entity resolution connects disparate data sources to uncover non-obvious relationships, moving beyond simple deduplication to understand how different digital shadows tether back to a single physical person1. Once an entity is resolved, data fusion layers multidimensional data streams onto the identity.

Data StreamMechanism of CollectionRole in the Inferential Mosaic
Mobile Advertising Identifiers (MAIDs)Unique alphanumeric strings generated by mobile operating systems, harvested by apps, and sold by data brokers.Acts as the primary digital anchor, tracking the device across cyberspace and physical space8.
Location HistoriesPrecise GPS pings collected by weather, navigation, and lifestyle applications.Establishes spatial patterns, dwell times, and visits to sensitive locations (e.g., clinics, places of worship)9.
Payment InformationTransactional metadata, often scrubbed of names but retaining timestamps, Merchant Category Codes (MCC), and zip codes.Reveals economic priorities, identifying purchases of specific goods (e.g., tactical gear, medical supplies)11.
Social GraphsNetwork connections mapping digital communications, social media interactions, and co-location data.Identifies ideological affiliations, organizational memberships, and peer groups.
Automated License Plate Readers (ALPRs)High-speed optical character recognition cameras capturing vehicle plates, timestamps, and geographic coordinates.Tracks vehicular movement across jurisdictions, building a comprehensive map of public travel13.
Facial RecognitionBiometric scanning applied to public cameras, social media scraping, or security checkpoints.Anchors anonymous physical presence to specific digital identities, overcoming the obfuscation of device-less travel11.
Property RecordsOpen-source municipal tax and deed registries.Links vehicles, names, and digital identifiers back to a physical domicile11.

Probabilistic Classification

With a fused, multidimensional dataset, machine learning classifiers (such as random forests, support vector machines, or deep neural networks) are deployed to predict a specific target variable. The algorithm searches for latent, complex patterns in the proxy data. If a specific cluster of behaviors—such as visiting specific GPS coordinates, purchasing from specific merchant categories, and associating with specific social networks—correlates highly with a known outcome, the algorithm assigns a probability score to the individual. If the probability score exceeds a predetermined threshold, the individual is classified as possessing the sensitive attribute. The resulting output is a synthetic registry. To a nontechnical observer, the process is akin to identifying an invisible object by meticulously mapping the negative space around it. The object itself is never directly observed, but its precise shape, size, and location are undeniably confirmed by the contours of the surrounding data.

Case Study: Firearm Ownership and the Decentralization Illusion

Firearm ownership in the United States provides the most robust case study for analyzing registry-equivalent knowledge. It exists at the intersection of explicit statutory prohibition, fierce political debate, and highly patterned consumer behavior, making it an ideal candidate for inferential modeling.

Statutory Prohibitions and ATF Limitations

Federal law strictly prohibits the creation of a national registry of modern, non-NFA (National Firearms Act) firearms. The Firearm Owners' Protection Act (FOPA) of 1986 and 18 U.S.C. § 926(a) explicitly forbid the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) from establishing any centralized, searchable database of gun owners17. Furthermore, annual congressional appropriations riders historically restrict the consolidation or centralization of Federal Firearms Licensee (FFL) records, ensuring that the architecture of firearm ownership data remains purposefully fractured18. To comply with these restrictions, the United States tracing system is intentionally decentralized. When an individual purchases a firearm from a commercial dealer, they complete an ATF Form 4473, which records their identity and the firearm's serial number20. Crucially, this form remains with the FFL. The ATF can only trace a crime gun by executing a manual chain-of-commerce search: querying the manufacturer to identify the wholesaler, querying the wholesaler to identify the retail dealer, and finally demanding the dealer pull the specific Form 4473 to identify the first retail purchaser19. This process is facilitated by eTrace, a web-based system that allows law enforcement agencies to submit trace requests to the ATF's National Tracing Center (NTC)20. However, eTrace is strictly limited by statute; it is designed to trace a specific firearm serial number forward to a purchaser, but it cannot be used to search a specific purchaser's name backward to find all firearms they own. The system is built to answer "Who bought this specific gun?" rather than "How many guns does this specific person own?"

Out-of-Business Records and the Push for Digitization

The decentralization illusion is challenged when an FFL goes out of business. By law, out-of-business records must be transferred to the ATF's National Tracing Center19. The volume of these records is staggering. The ATF utilizes the Out-of-Business Records Imaging System (OBRIS) and Access 2000 to manage these files, digitizing tens of millions of records annually17. Recent regulatory actions have intensified the debate over whether this constitutes a creeping registry. A 2022 ATF final rule required FFLs to retain transaction records indefinitely, reversing a previous rule that allowed the destruction of records after 20 years18. The indefinite retention mandate resulted in a massive influx of data to the NTC. Facing administrative burdens and political backlash, the ATF recently proposed reducing this retention period to 20 or 30 years22. Statistical data maintained by the NTC indicates that in recent years, approximately 94% of completed crime gun traces rely on records up to 30 years old, with rapidly diminishing returns for older records22. Despite these retention debates and the massive digitization efforts through OBRIS, the ATF maintains that the digitized records remain non-searchable by purchaser name, thus complying with 18 U.S.C. § 926(a)17.

Reconstructing the Registry: A Hypothetical Architecture

Because the government is prohibited from maintaining a centralized, name-searchable database of Form 4473s, one might assume firearm ownership remains entirely private. However, utilizing commercial data brokers and machine learning, a registry-equivalent database can be constructed entirely outside the purview of the ATF and 18 U.S.C. § 926\. Consider a hypothetical fusion of five lawful, commercially available datasets:

1. ALPR Data: Automated license plate readers capture a vehicle's plate entering the parking lot of an outdoor shooting range every second Saturday of the month, establishing a regular cadence of visitation13.

2. Location Data Brokers: Companies aggregating mobile app GPS data record a specific mobile advertising identifier (MAID) dwelling at a hunting and tactical supply store for forty-five minutes, and subsequently dwelling at the same coordinates as the aforementioned shooting range8.

3. Financial Metadata: A consumer data broker provides aggregated credit card transaction histories showing regular purchases under Merchant Category Code (MCC) 5999 (Miscellaneous Retail Stores) that corresponds temporally with the MAID's visits to the tactical supply store11.

4. Facial Recognition: Images scraped from a public social media page for a local gun show run through a commercial facial recognition engine anchor the anonymous MAID to a verified physical identity13.

5. Property Records: Open-source public property records link the vehicle's registration address to the individual, confirming the residential anchor point11.

An entity resolution algorithm applies the Fellegi-Sunter model to link the ALPR plate data, the property address, and the mobile MAID into a unified digital entity. Next, a probabilistic classifier evaluates the behavioral pattern: regular dwell time at a shooting range \+ corresponding dwell time at a tactical store \+ temporal financial transactions \+ facial recognition at a gun show \+ social graph connections to hunting organizations. The algorithm determines with 98.4% confidence that the individual residing at the resolved address owns a firearm. This inference is appended to the individual's digital profile as a structured data point. If this architecture is applied to a population of 330 million people, the resulting database is a functional, highly accurate national registry of firearm owners. Importantly, this synthetic registry contains zero Form 4473s, utilizes zero ATF trace data, and breaches zero statutory provisions under 18 U.S.C. § 926\. It is built entirely from legally traded commercial surveillance data, effectively bypassing the legislative ban on government collection by substituting it with algorithmic deduction.

The legal treatment of inferred data compared to explicitly collected data is one of the most pressing frontiers in global privacy law. Can a government or corporation be legally restricted based on what its algorithms think they know, rather than what they explicitly ask?

The European Approach: Strict Protection of Inferences

The European Union has taken a decisive, preemptive stance on derived and inferred attributes through the General Data Protection Regulation (GDPR). Article 9 of the GDPR prohibits the processing of "special categories" of personal data, which encompass racial or ethnic origin, political opinions, religious or philosophical beliefs, biometric data, health data, and sexual orientation25. Crucially, European jurisprudence has established that the mechanism of collection is irrelevant; if an algorithm infers a sensitive trait, that inference itself constitutes special category data. The Court of Justice of the European Union (CJEU) has solidified this doctrine through three landmark rulings:

1. **Case C-184/20 (OT v Vyriausioji tarnybinės etikos komisija):** The CJEU evaluated a Lithuanian law requiring public officials to declare conflicts of interest, including the name of their spouse or cohabiting partner. The Court ruled that publishing a partner's name, which could indirectly disclose the declarant's sexual orientation, constituted the processing of sensitive data26. The Court clarified that any "intellectual operation involving comparison or deduction" that reveals a protected characteristic triggers strict Article 9 protections29.

2. **Case C-252/21 (Meta Platforms v Bundeskartellamt):** The CJEU held that browsing data combined with off-platform tracking that allows a social network to profile a user's sensitive interests qualifies as sensitive data processing, severely limiting the ability of platforms to infer protected categories without explicit consent29.

3. **Case C-21/23 (Lindenapotheke):** The Court determined that simply ordering a non-prescription product from an online pharmacy allows for the deduction of health data. The CJEU ruled that this triggers special category protections regardless of the controller's intent to process health data, the probability of the deduction, or even the accuracy of the inference25.

Under the European framework, registry-equivalent knowledge of sensitive categories is tightly restricted. The law protects the insight, not just the raw data input.

The United States Approach: Emerging State Frameworks

In the United States, federal privacy law is heavily sectoral (e.g., HIPAA for healthcare, GLBA for finance), leaving commercial data brokering and algorithmic profiling largely unregulated at the national level. However, state-level regulations are beginning to address the threat of inferences. The California Privacy Rights Act (CPRA), which amended the California Consumer Privacy Act (CCPA), is the most advanced domestic framework. The CPRA explicitly defines "personal information" to include "inferences drawn from any of the information identified in this subdivision to create a profile about a consumer reflecting the consumer's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes"11. Furthermore, the CPRA introduced a new category of "sensitive personal information" (SPI), which includes precise geolocation, racial/ethnic origin, religious beliefs, genetic data, biometric identifiers, and contents of communications12. Consumers have the affirmative right to limit the use and disclosure of their SPI11. Despite this, a regulatory gray area persists: if a data broker uses non-sensitive data (like standard purchasing habits) to infer a sensitive trait (like religious belief), does that inferred trait automatically become SPI requiring opt-in consent? The California Privacy Protection Agency (CPPA) regulations suggest that profiling based on inferred sensitive traits requires stringent oversight, but the application remains heavily debated35.

The Federal Trade Commission and Sensitive Locations

At the federal level, the Federal Trade Commission (FTC) has aggressively utilized Section 5 of the FTC Act (prohibiting unfair and deceptive acts or practices) to target data brokers generating registry-equivalent knowledge through precise location data. In enforcement actions against data brokers Kochava, Outlogic (formerly X-Mode Social), and InMarket, the FTC alleged that selling precise location data that reveals consumers' visits to sensitive locations—such as reproductive health clinics, places of worship, domestic violence shelters, and military installations—constitutes an unfair privacy invasion8. In the Kochava case, a federal judge in Idaho denied the company's motion to dismiss, validating the FTC's argument that the unconsented sale of data allowing downstream actors to infer highly sensitive medical or religious behavior causes substantial consumer injury9. The FTC's settlements now mandate strict "sensitive location data programs" designed to filter out and prevent the inference of sensitive associations, establishing a de facto federal prohibition against tracking individuals to constitutionally or medically sensitive coordinates9.

Jurisdiction / FrameworkTreatment of Inferred Sensitive DataLegal Mechanism / Precedent
European Union (GDPR)Treated identically to explicitly collected sensitive data.CJEU Cases C-184/20, C-252/21, and C-21/23 (Deduction triggers Art. 9\)28.
California (CPRA)"Inferences" explicitly included in the definition of personal data.Cal. Civ. Code § 1798.140(v); Right to limit the use of SPI31.
US Federal Trade CommissionActionable if tracking sensitive locations causes consumer harm.FTC v. Kochava; FTC v. Outlogic; FTC v. InMarket (Section 5 unfairness)8.
US Federal GovernmentLaw enforcement can legally purchase inferred profiles from data brokers.Third-Party Doctrine; pending Fourth Amendment Is Not For Sale Act40.

The Data Broker Loophole and the Fourth Amendment Is Not For Sale Act

While European law shields the inference, and the FTC is beginning to target commercial brokers, the United States government exploits a unique legal loophole: the state can simply purchase registry-equivalent knowledge. Because the Fourth Amendment traditionally restricts state action (unreasonable searches and seizures), data voluntarily shared with third parties (e.g., app developers, cell providers) historically lost its constitutional protection under the "third-party doctrine." Consequently, law enforcement and intelligence agencies can purchase inferred registries, location histories, and behavioral profiles directly from commercial data brokers without securing a warrant. Legislative efforts, most notably the proposed "Fourth Amendment Is Not For Sale Act," attempt to close this loophole40. The Act, which passed the US House of Representatives in 2024 but stalled in the Senate, would prohibit the government from purchasing commercially available data that would otherwise require a warrant to obtain directly from a primary provider40. If enacted, it would fundamentally cripple the government's ability to bypass statutory registry bans by outsourcing surveillance to the private sector.

Constitutional Implications: Mosaic Theory and Chilling Effects

If the government utilizes artificial intelligence and commercial data fusion to build synthetic registries of constitutionally protected behaviors, it engages several complex constitutional doctrines spanning the First, Second, and Fourth Amendments.

The Fourth Amendment and the Mosaic Theory

The traditional Fourth Amendment standard, rooted in Katz v. United States, asks whether an individual has a reasonable expectation of privacy that society is prepared to recognize as legitimate. For decades, courts held that individuals have no expectation of privacy in their public movements. Therefore, following a suspect on a public highway, or snapping a photograph of a license plate, was not considered a search (e.g., United States v. Knotts). However, the proliferation of digital surveillance birthed the "Mosaic Theory." First articulated in the concurring opinions of United States v. Jones (which addressed GPS tracking) and subsequently solidified in Carpenter v. United States (which addressed historical cell-site location information), the mosaic theory posits that while one isolated data point (one tile) may not violate a privacy expectation, the aggregation of prolonged, continuous data points creates a comprehensive mosaic of a person's life, thereby constituting a search requiring a warrant13. The application of the mosaic theory to registry-equivalent knowledge is profound, particularly concerning ALPRs and location fusion. In Commonwealth v. McCarthy, the Massachusetts Supreme Judicial Court analyzed whether the use of ALPRs on the Bourne and Sagamore bridges to track a drug suspect constituted a search13. The Court held that while the limited, fixed-point use in that specific case did not violate the Fourth Amendment, a sufficiently dense network of ALPRs that captured the "whole of \[a person's\] public movements" would implicate constitutional protections13. Similarly, in State v. Baptiste, a Florida appellate court held that an ALPR "hit" provides objective, reasonable suspicion for an investigatory stop, further validating the operational reliance on automated data systems46. Registry-equivalent knowledge operates entirely on the premise of a mosaic. By fusing location, payment, and social data to deduce firearm ownership or religious affiliation, the synthetic registry represents the ultimate digital mosaic—a comprehensive reconstruction of private life built from public or semi-public tiles. If Carpenter protects the sum of one's public movements, courts may eventually hold that the Fourth Amendment protects the sum of one's commercial data when used by the state to deduce sensitive traits.

The First and Second Amendments: The Chilling-Effect Doctrine

Beyond the Fourth Amendment, registry-equivalent knowledge threatens fundamental rights of association, expression, and bearing arms. In the landmark case NAACP v. Alabama (1958), the Supreme Court ruled that the state could not compel the NAACP to reveal its membership list. The Court recognized that exposing members would subject them to harassment, economic reprisal, and physical threats, thereby exerting a "chilling effect" on their First Amendment right to freedom of association17. If a government agency—or a hostile corporate actor—can use AI to infer with 95% accuracy the membership of a controversial political organization, a labor union, or a gun rights advocacy group, the chilling effect is functionally identical to the state seizing a membership list. Individuals, aware that their seemingly innocuous public data can be fused to profile their ideological or constitutional activities, will inevitably self-censor. They may leave their mobile devices at home when visiting a gun range, obscure their license plates, or alter their purchasing habits to avoid algorithmic detection17. This structural alteration of behavior out of fear of algorithmic profiling results in a profound chilling effect on the exercise of Second and First Amendment rights.

Error Rates, Bias, and the Perils of Probabilistic Classification

A critical vulnerability in the architecture of registry-equivalent knowledge is that it is fundamentally probabilistic, not deterministic. Explicit registries, despite occasional administrative errors, represent a binary legal truth: an individual is either documented on the registry, or they are not. Synthetic registries represent a statistical likelihood7. The Fellegi-Sunter model, entity resolution engines, and downstream machine learning classifiers rely heavily on confidence thresholds4. If an entity resolution algorithm connects an ALPR read of a borrowed vehicle to the vehicle's registered owner rather than the actual driver, the algorithm commits a linkage error (a false positive)3. If a classifier deduces that anyone visiting a specific hardware store and subscribing to certain magazines is a firearm owner, it will inadvertently flag non-owners whose behavioral patterns mirror those of owners.

MetricDefinitionImplication in Registry-Equivalent Knowledge
PrecisionThe percentage of positive predictions that are actually correct.High precision means few false positives. In surveillance, low precision leads to the harassment of innocent individuals1.
RecallThe percentage of actual positive cases that the model successfully identifies.High recall means few false negatives. In surveillance, maximizing recall often requires lowering thresholds, inherently reducing precision1.
Linkage ErrorErroneously merging two distinct entities (false match) or failing to merge records belonging to the same entity (missed match).A false match can append highly sensitive, stigmatizing, or legally perilous attributes to the wrong digital profile1.

In commercial advertising, a false positive means a consumer receives an irrelevant advertisement—a harmless inefficiency. However, in a government, intelligence, or law enforcement context, a false positive carries devastating, potentially fatal consequences. If law enforcement utilizes a probabilistically generated registry to assess the threat level of an individual before executing a search warrant, a linkage error could result in a heavily armed tactical response against an unarmed, misidentified citizen. Furthermore, the algorithms driving these inferences often suffer from systemic training biases. If data brokers have deeper penetration in low-income urban areas, or if policing technologies like ALPRs and facial recognition are disproportionately deployed in minority neighborhoods, the synthetic registry will disproportionately surveil, classify, and potentially misclassify those groups, embedding systemic bias into an opaque inferential matrix.

Counterarguments and Policy Tradeoffs

The strongest arguments against prohibiting or heavily regulating registry-equivalent knowledge center on public safety, the realities of modern commerce, and strict statutory interpretation.

1. The Public Observation Defense: Proponents argue that registry-equivalent knowledge does not violate the Fourth Amendment because it relies exclusively on data voluntarily shared with third parties or observable in the public square. If a person chooses to carry a tracking device to a public gun range, post their face on social media, and swipe a credit card on a third-party payment network, they have willingly surrendered their expectation of privacy.

2. Investigative Efficiency and National Security: Law enforcement and intelligence agencies argue that data fusion is essential for modern security. In a world where transnational criminal organizations and domestic extremists utilize sophisticated digital networks, probabilistic inference allows investigators to connect disparate clues rapidly. Banning the algorithmic fusion of lawful data restricts police to analog methodologies in a digital era, severely hampering counter-terrorism and organized crime investigations.

3. The "Not a Registry" Statutory Defense: From a strict textualist perspective, a probabilistic database is simply not a registry. 18 U.S.C. § 926 prohibits the ATF from maintaining a centralized database of firearm records17. A commercial database estimating the probability of firearm ownership based on location data contains no official records, no serial numbers, and no definitive proof. Therefore, it does not violate the letter of the law.

Policymakers face a delicate tradeoff: preserving the utility of data analytics for security and commerce while protecting citizens from algorithmic panopticons. If governments wish to prevent the creation of synthetic registries, they must update privacy laws to explicitly address the mechanism of inference, moving beyond the regulation of raw data collection.

Possible Statutory Language Addressing Inferred Sensitive Data

Current United States federal laws focus almost entirely on the point of collection (what data is explicitly gathered) rather than the point of inference (what the data reveals). To effectively regulate registry-equivalent knowledge, statutory language must bridge this gap, borrowing conceptually from the CJEU's interpretation of GDPR Article 9 and the CPRA's inclusion of profiling. Proposed Statutory Language for Inferred Sensitive Data:

"For the purposes of this Act, 'Sensitive Personal Information' shall include any data, whether explicitly collected, indirectly derived, or probabilistically inferred, that is utilized by a covered entity, data broker, or government agency to identify, classify, or profile an individual based on a protected characteristic, constitutionally protected activity, or legally restricted category.

If a covered entity utilizes algorithmic data fusion, entity resolution, or cross-dataset correlation to deduce a sensitive attribute with a statistical confidence exceeding a reasonable threshold, the resulting inference shall be classified as Sensitive Personal Information. Such inferred data shall be subject to all statutory prohibitions, minimization requirements, opt-in consent mandates, and audit protocols applicable to the direct, explicit collection of said sensitive attribute."

Such language shifts the regulatory burden from the input to the output. If a synthetic registry functions like an explicit registry, it is regulated like an explicit registry.

Fact and Speculation Analysis

In the rapidly evolving field of data surveillance, it is vital to separate empirically verifiable realities from future projections or theoretical capabilities.

Ten Factual Claims (Strongly Supported)

1. Federal law (18 U.S.C. § 926 and FOPA) strictly prohibits the ATF from creating a centralized, searchable national registry of firearms and firearm owners17.

2. The ATF currently receives and processes tens of millions of out-of-business firearm transaction records annually through its Out-of-Business Records Imaging System (OBRIS)18.

3. The Fellegi-Sunter model, formalized in 1969, remains a foundational mathematical framework for probabilistic record linkage and entity resolution today1.

4. The Expectation-Maximization (EM) algorithm is actively used in probabilistic linkage to estimate match probabilities (m and u probabilities) without requiring labeled training datasets6.

5. The Court of Justice of the European Union (CJEU) has ruled in multiple cases (e.g., C-184/20 and C-252/21) that personal data indirectly revealing sensitive traits through deduction constitutes the processing of special category data under GDPR Article 927.

6. The California Privacy Rights Act (CPRA) explicitly includes "inferences drawn" from other data to create a consumer profile within its definition of protected personal information11.

7. The Federal Trade Commission has taken legal action against commercial data brokers (such as Kochava and Outlogic) for selling precise mobile location data that tracks consumer visits to sensitive locations without affirmative express consent8.

8. Carpenter v. United States established that the aggregation of historical cell-site location information constitutes a search under the Fourth Amendment, cementing the "mosaic theory" in modern jurisprudence44.

9. In Commonwealth v. McCarthy, the Massachusetts Supreme Judicial Court acknowledged the mosaic theory's applicability to automated license plate readers (ALPRs), though it found the specific limited use in that case did not violate the Fourth Amendment13.

10. The proposed "Fourth Amendment Is Not For Sale Act," which aims to restrict the government's ability to purchase commercially available data that would otherwise require a warrant, passed the US House of Representatives in 2024 but has not passed the Senate40.

Ten Speculative Claims (To Be Labeled as Projections/Theories)

1. Speculation: Within the next decade, commercial entity resolution engines will achieve a high enough degree of accuracy that the US government will entirely abandon efforts to build internal explicit registries, relying solely on commercial data licensing.

2. Speculation: Probabilistic inference of firearm ownership will eventually be used by health and life insurance algorithms to adjust premium rates based on the statistical likelihood of household firearm accidents.

3. Speculation: The Supreme Court will eventually rule that the government's purchase of commercially inferred sensitive attributes (registry-equivalent knowledge) violates the Fourth Amendment under an expanded application of the mosaic theory.

4. Speculation: The chilling effect of synthetic registries will lead to a measurable decrease in physical attendance at politically or socially sensitive public gatherings, as citizens realize leaving their smartphones at home does not defeat ALPR and facial recognition fusion.

5. Speculation: The widespread digitizing of ATF out-of-business records, combined with advanced optical character recognition (OCR) and machine learning, is currently being used to quietly build a de facto centralized registry, despite agency claims that the system is not searchable by name.

6. Speculation: Data brokers will successfully evade FTC enforcement actions regarding "sensitive locations" by shifting from selling raw GPS data to selling pre-packaged, abstracted "lifestyle scores" that mathematically obscure the underlying geographic inputs.

7. Speculation: European data protection authorities will eventually fine major ad-tech companies specifically for the accuracy of their inferential models, penalizing them because their predictive algorithms are too proficient at guessing protected Article 9 characteristics.

8. Speculation: The reliance on probabilistic matching (Fellegi-Sunter) for law enforcement threat assessments will result in a statistically significant increase in false-positive tactical raids on misidentified citizens.

9. Speculation: State legislatures will pass "algorithmic shield laws" that explicitly immunize commercial data brokers from liability for inferences drawn by their downstream clients, so long as the broker only provided raw, anonymized data.

10. Speculation: To counter registry-equivalent knowledge, a new consumer market of "data poisoning" services will emerge, designed to generate false digital footprints (e.g., fake GPS pings, randomized synthetic purchases) to deliberately lower the confidence scores of entity resolution algorithms profiling the user.

Conclusion

Registry-equivalent knowledge represents a profound challenge to traditional legal and constitutional paradigms. Statutes written in the 20th century, such as 18 U.S.C. § 926, were designed to prevent the state from writing names on a list. They are fundamentally ill-equipped to prevent the state—or the commercial actors supplying it—from using advanced entity resolution, the Fellegi-Sunter model, and probabilistic classification to deduce the very information they are forbidden from collecting. The algorithmic fusion of mobile ad identifiers, location histories, ALPR data, facial recognition, and financial metadata allows for the synthetic reconstruction of registries tracking firearm ownership, religious affiliation, political ideology, and health statuses. While European courts have aggressively interpreted inference as a form of regulated collection, United States frameworks remain fractured, relying on emerging state laws like the CPRA and targeted FTC enforcement to hold the line against inferential surveillance. If the mosaic theory of the Fourth Amendment and the chilling-effect doctrine of the First Amendment are not updated to address the reality of algorithmic deduction, explicit statutory prohibitions against government registries will be rendered entirely ceremonial in the face of ubiquitous data fusion.

Works cited

1. Record linkage \- Wikipedia, https://en.wikipedia.org/wiki/Record\_linkage

2. Machine Learning, Information Retrieval, and Record Linkage, https://www.niss.org/sites/default/files/winkler.pdf

3. Improving Probabilistic Record Linkage Using Statistical Prediction, https://dspace.library.uu.nl/server/api/core/bitstreams/1cbfd0c3-c9e6-4ba6-9aa0-8a426291c581/content

4. Probabilistic Record Linkage Using Pretrained Text Embeddings, https://joeornstein.github.io/publications/fuzzylink.pdf

5. Why Probabilistic Linkage is More Accurate than Fuzzy Matching or, https://medium.com/data-science/why-probabilistic-linkage-is-more-accurate-than-fuzzy-matching-or-term-frequency-based-approaches-15a28c733e73

6. Developing standard tools for data linkage: February 2021, https://www.ons.gov.uk/methodology/methodologicalpublications/generalmethodology/onsworkingpaperseries/developingstandardtoolsfordatalinkagefebruary2021

7. Estimating parameters for probabilistic linkage of privacy-preserved, https://pmc.ncbi.nlm.nih.gov/articles/PMC5504757/

8. FTC settles with data broker Kochava over sale of sensitive location, https://www.whitecase.com/insight-alert/ftc-settles-data-broker-kochava-over-sale-sensitive-location-data-key-takeaways

9. FTC Bars Kochava from Selling Sensitive Location Data, https://www.gtlaw-dataprivacydish.com/2026/05/ftc-bars-kochava-from-selling-sensitive-location-data/

10. FTC Announces Proposed Consent Orders Related to Location Data, https://www.insideprivacy.com/uncategorized/ftc-announces-proposed-consent-orders-related-to-location-data/

11. California Consumer Privacy Act (CCPA), https://oag.ca.gov/privacy/ccpa

12. Frequently Asked Questions (FAQs) \- California Privacy Protection, https://cppa.ca.gov/faq.html

13. Commonwealth v. McCarthy \- Massachusetts Case Law, https://law.justia.com/cases/massachusetts/supreme-court/2020/sjc-12750.html

14. Regulation of Automatic License Plate Readers in Virginia, https://scholarship.richmond.edu/cgi/viewcontent.cgi?article=1462\&context=jolt

15. COMMONWEALTH vs. NELSON MORA (and two companion cases )., https://law.justia.com/cases/massachusetts/supreme-court/volumes/485/485mass360.html

16. Understanding Sensitive Personal Information \- Transcend.io, https://transcend.io/blog/sensitive-personal-information

17. The Debate Over the ATF Digitizing Gun Sales Records from Out-of, https://firearmsresearchcenter.org/working\_papers/the-debate-over-the-atf-digitizing-gun-sales-records-from-out-of-business-firearms-dealers/

18. The Debate Over the ATF Digitizing Gun Sales Records from Out-of, https://firearmsresearchcenter.org/wp-content/uploads/2024/08/2024-04\_Del-Schlangen.pdf

19. Statutory Federal Gun Registry Prohibitions and ATF Record, https://www.everycrsreport.com/reports/IF12057.html

20. Modernize \- ATF, https://www.atf.gov/rules-and-regulations/atf-launches-new-era-reform/modernize

21. Maintaining Records of Gun Sales \- Giffords Law Center, https://giffords.org/lawcenter/gun-laws/policy-areas/gun-sales/maintaining-records/

22. Firearm Records Retention Periods \- Federal Register, https://www.federalregister.gov/documents/2026/05/06/2026-08929/firearm-records-retention-periods

23. Firearm Records Retention Periods (RIN 1140-AA95) \- ATF, https://www.atf.gov/rules-and-regulations/rulemaking-notices/firearm-records-retention-periods-rin-1140-aa95

24. Rep. Clyde Urges ATF to Limit Firearm Record Retention and, https://clyde.house.gov/news/documentsingle.aspx?DocumentID=3708

25. Explaining special category data \- PPC Land, https://ppc.land/explaining-special-category-data/

26. Are you processing 'Special Category' data by way of inference? A, https://www.considerati.com/publications/gdpr-special-category-data.html

27. Art. 9 GDPR: What counts as special categories of personal data?, https://www.dsn-group.com/privacy-notes/art-9-gdpr-what-counts-as-special-categories-of-personal-data-5837752

28. Processing Special Category Personal Data Without Knowing it, https://www.urmconsulting.com/blog/are-you-processing-special-category-personal-data-without-knowing-it

29. “Sensitive data” under the CJEU's spotlight: practical implications, https://connectontech.bakermckenzie.com/sensitive-data-under-the-cjeus-spotlight-practical-implications/

30. EU: CJEU's landmark decision in Meta vs Bundeskartellamt, https://privacymatters.dlapiper.com/2023/07/eu-cjeus-landmark-decision-in-meta-vs-bundeskartellamt/

31. Navigating the California Consumer Privacy Act: 30+ Essential FAQs, https://www.jacksonlewis.com/insights/navigating-california-consumer-privacy-act-30-essential-faqs-covered-businesses-including-clarifying-regulations-effective-1126

32. California Consumer Privacy Act of 2018, https://cppa.ca.gov/regulations/pdf/ccpa\_statute.pdf

33. Text of the CPRA \- Californians for Consumer Privacy, https://www.caprivacy.org/cpra-text/

34. What is CPRA Sensitive Personal Information and How to Handle it?, https://www.cookieyes.com/blog/cpra-sensitive-personal-information/

35. Understanding the CPRA and Marketing Compliance, https://blog.clickpointsoftware.com/understanding-the-cpra-and-marketing-compliance

36. Brain power: Piecing together CCPA's opt in, out requirements for, https://iapp.org/news/a/brain-power-piecing-together-ccpa-s-opt-in-out-requirements-for-sensitive-personal-information

37. Recent Enforcement Actions Signal FTC Focus on Protecting, https://www.wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/20240209-recent-enforcement-actions-signal-ftc-focus-on-protecting-location-data

38. Settlement Resolves FTC Lawsuit Against Kochava Over Sale of, https://www.hipaajournal.com/ftcs-amended-complaint-against-kochava-survives-motion-to-dismiss/

39. FTC to Ban Kochava and Subsidiary from Selling Sensitive Location, https://www.ftc.gov/news-events/news/press-releases/2026/05/ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data

40. Fact Sheet: Closing the Data Broker Loophole, https://www.pogo.org/fact-sheets/fact-sheet-closing-the-data-broker-loophole

41. After House Passes Fourth Amendment Is Not For Sale Act, ACLU, https://www.aclu.org/press-releases/house-passes-fourth-amendment-is-not-for-sale-act

42. The SAFE Act is an Imperfect Vehicle for Real Section 702 Reform, https://www.eff.org/deeplinks/2026/03/safe-act-imperfect-vehicle-real-section-702-reform

43. House passes bill to limit personal data purchases by law, https://cyberscoop.com/house-passes-4th-amendment-is-not-for-sale-act/

44. THE INTERSECTION OF AUTOMATED LICENSE PLATE READERS, https://mckinneylaw.iu.edu/practice/law-reviews/ilr/pdf/vol58p449.pdf

45. SJC Rules On The Use Of Automatic License Plate Reader Data In, https://www.wgbh.org/news/local/2020-04-21/sjc-rules-on-the-use-of-automatic-license-plate-reader-data-in-criminal-cases

46. Automatic License Plate Readers \- ALPR Camera, https://www.drug2go.com/blog/automatic-license-plate-readers-alpr-video/

47. Candid Traffic Cameras: Why Illinois's Automated License Plate, https://huskiecommons.lib.niu.edu/cgi/viewcontent.cgi?article=1929\&context=niulr