← All 142 executive actions

Federal Judge Ruled IRS Violated Taxpayer Privacy Law Over 42,000 Times by Sharing Addresses with ICE

Legal Feb 26, 2026
Our Analysis: Concerning

A federal judge found the IRS violated one of the strictest confidentiality statutes in federal law approximately 42,695 times when it shared taxpayer addresses with immigration enforcement without verifying that ICE had provided valid identifying information as required by law. The ruling reinforced an earlier November 2025 injunction blocking the data-sharing arrangement, though a separate D.C. Circuit panel ruled two days earlier that a different challenge to the program was unlikely to succeed, leaving the legal landscape fractured. Multiple senior IRS officials—including the acting commissioner, chief privacy officer, chief financial officer, and acting general counsel—resigned or were forced out over objections to the arrangement, an extraordinary internal revolt that underscores the severity of the policy departure.

Details

On February 26, 2026, U.S. District Judge Colleen Kollar-Kotelly ruled that the Internal Revenue Service violated Section 6103 of the Internal Revenue Code—one of the strictest taxpayer confidentiality laws in federal statute—approximately 42,695 times when it shared confidential taxpayer addresses with Immigration and Customs Enforcement.

The ruling was based on a declaration filed earlier in February by IRS Chief Risk and Control Officer Dottie Romo, which revealed that out of 1.28 million names ICE submitted to the IRS, the agency matched and shared 47,289 taxpayer addresses. Of those, only 4,594 (9.7%) were properly matched by address as required by law. The remaining 42,695 (90.3%) were matched through Taxpayer Identification Number (TIN) matching—a process the judge found violated the statute's requirement that the requesting agency provide the taxpayer's address before receiving confidential information.

The Legal Requirement

Under Section 6103(i)(2) of the Internal Revenue Code, before the IRS can disclose a taxpayer's address, the requesting agency must first provide the IRS with the name and address of the person whose records it seeks. This requirement exists to ensure that the government can access confidential tax records only for individuals it has already specifically identified—preventing fishing expeditions through taxpayer data.

Kollar-Kotelly found that ICE failed to meet this standard in the vast majority of its requests. According to the Romo declaration, thousands of ICE requests contained addresses that were incomplete or fictitious, featuring entries such as "Failed to Provide," "Unknown Address," or simply "NA NA." In other cases, addresses were missing street names or numbers, or ICE listed jails and detention facilities without including the building's street location.

The judge used pointed language to describe the IRS's verification standard, writing that under the government's process, ICE could have submitted a request with an address like "Don't Care 12345" or simply "00000" and still received a taxpayer's home address.

Background: The Data-Sharing Agreement

The arrangement traces to a Memorandum of Understanding signed on April 7, 2025, by Treasury Secretary Scott Bessent and Homeland Security Secretary Kristi Noem. The MOU allowed ICE to submit names and addresses of individuals with final orders of removal to the IRS for cross-verification against tax records, ostensibly to support criminal investigations related to immigration enforcement.

The agreement represented a dramatic departure from decades of IRS practice, which historically maintained strict taxpayer confidentiality and kept tax data separate from immigration enforcement. The taxpayer privacy protections at issue were enacted after the Watergate scandal revealed that President Nixon had misused tax data during his administration.

Internal Resistance and Departures

The MOU triggered an extraordinary wave of resignations at the IRS. Acting Commissioner Melanie Krause—Trump's own appointee, who had been the IRS's third leader in 2025—resigned on April 8, 2025, over the agreement. Chief Privacy Officer Kathleen Walters, Chief Financial Officer Teresa Hunter, and Chief Risk Officer Mike Wetklow also departed in connection with the data-sharing arrangement. Treasury Secretary Bessent ultimately signed the MOU himself after other officials declined.

In July 2025, ProPublica reported that the acting IRS general counsel, Andrew De Mello, refused to approve a subsequent ICE request for the addresses of 7.3 million taxpayers, citing multiple legal "deficiencies." Two days after his refusal, on June 27, De Mello was forced out of his position. De Mello had previously been installed after his predecessor was replaced for similarly resisting the data-sharing push. In total, the departures included approximately 50 senior IRS IT executives in addition to multiple acting commissioners, the chief information officer, and other senior leadership.

The August 2025 Data Transfer

On August 7, 2025, the IRS disclosed the last known addresses of approximately 47,289 taxpayers to ICE in response to ICE's request covering 1.28 million individuals. ICE's request was based on a single Assistant Director's representation that he was "personally and directly engaged" in more than one million simultaneous criminal investigations—a claim former IRS officials called "a fantasy." Historically, law enforcement requests for IRS data rarely involved more than a dozen people at a time.

Litigation Timeline

The legal challenges to the data-sharing arrangement have played out across multiple cases:

Center for Taxpayer Rights v. IRS (D.D.C.): Filed in February 2025 by the Center for Taxpayer Rights, Main Street Alliance, and two federal employee unions, represented by Democracy Forward. On November 21, 2025, Judge Kollar-Kotelly issued a 94-page ruling finding a "substantial likelihood" that the data-sharing violated Section 6103 and the Administrative Procedure Act, and issued a preliminary injunction blocking further data transfers. The February 26, 2026, ruling finding 42,695 violations arose in this same case. The government is appealing.

Centro de Trabajadores Unidos v. Bessent (D.C. Circuit): A separate suit by immigrant advocacy organizations. On February 24, 2026—two days before the 42,695-violation ruling—a three-judge D.C. Circuit panel denied the groups' request for a preliminary injunction, with Judge Harry T. Edwards writing they were "unlikely to succeed on the merits" because the address information being shared was not covered by the IRS privacy statute. The panel—composed entirely of Democratic appointees (Chief Judge Sri Srinivasan and Judge Patricia Millett, both Obama appointees, and Senior Judge Edwards, a Carter appointee)—treated the MOU as a nonbinding policy statement not subject to APA review. However, the court explicitly declined to rule on the legality of the underlying IRS-ICE implementation agreement.

Massachusetts case: On February 5, 2026, U.S. District Judge Indira Talwani separately blocked DHS, ICE, and their agents from using any return information obtained through the MOU for immigration enforcement, and ordered ICE to provide an accounting of the data.

As of the February 26 ruling, two separate preliminary injunctions remain in place blocking the agencies from conducting massive data transfers and barring ICE from acting on IRS data already in its possession.

Administration Response

DHS has defended the data-sharing agreement as essential to immigration enforcement, stating: "Information sharing across agencies is essential to identify who is in our country, including violent criminals, determine what public safety and terror threats may exist so we can neutralize them, scrub these individuals from voter rolls, and identify what public benefits these aliens are using at taxpayer expense."

Attorney General Pam Bondi called the D.C. Circuit's February 24 ruling "a crucial victory for President Trump's agenda to Make America Safe Again."

Neither the IRS nor the Treasury Department responded to requests for comment on the February 26 ruling finding 42,695 violations.

Congressional Response

Senate Finance Committee Ranking Member Ron Wyden (D-OR) stated that the scheme officials "cooked up to hand taxpayer data over to ICE is flawed and dangerous" and warned that "everybody who's had their hands on the IRS-ICE data sharing agreement and the illegal transmission of this taxpayer data ought to save their records and be ready for the criminal investigations and lawsuits headed their way sooner or later."

Senators Alex Padilla (D-CA) and Wyden, joined by other Senate Democrats, had previously demanded answers from Treasury and DHS, warning that the flawed data-sharing system created "the extraordinarily troubling likelihood that in some significant, unknown number of cases, the IRS not only provided return information to ICE in violation of strict taxpayer privacy laws, but it also provided information about the wrong taxpayers."

Expert Analysis

Nina Olson, founder of the Center for Taxpayer Rights and the plaintiff in the lead case, said the ruling confirmed that "the IRS has an unlawful policy that violates the Internal Revenue Code's protections." She emphasized there was no precedent to her knowledge of a judge finding tens of thousands of simultaneous violations of federal taxpayer confidentiality law.

Tom Bowman, policy counsel for the Center for Democracy & Technology, called it "a stark reminder of why safeguards for sensitive data are so critical," adding that "the improper sharing of taxpayer data is unsafe, unlawful, and subject to serious criminal penalties."

The Tax Policy Center has warned that even if the agreement's stated goal is to locate individuals without legal status, it may have downstream consequences for the fiscal health of the country, effective governance, and the well-being of U.S. citizens and lawful residents who may be swept up in the data-sharing.

Historical Context

The scale of the data sharing was unprecedented. In 2023, the IRS reported no disclosures to DHS. In total that year, the agency reported 75,647 disclosures across all federal law enforcement agencies combined. The 47,289 addresses shared with ICE in a single week in August 2025 approached the annual total for all agencies—and ICE's original request for 1.28 million records dwarfed anything in the IRS's history. A subsequent request for 7.3 million records was even larger.