The National Security Agency routinely fails to notify employees of their rights under whistleblower protection laws when they sign non-disclosure agreements, the agency’s inspector general concluded in a report released this week.
Although the NSA is not technically covered by the Whistleblower Protection Enhancement Act, Congress has mandated since 1988 through annual appropriations bills that the agency adhere to most of its provisions. The primary exception involves matters enforced by the U.S. Office of Special Counsel, which lacks jurisdiction over counterintelligence and foreign intelligence issues.
According to the inspector general’s review, most of the NSA’s non-disclosure agreements lack the statutorily required references to federal whistleblower protections. Consequently, employees “may not be aware” of their right to report violations of law, waste, fraud, or abuse.
“We identified five unique NSA-developed NDAs,” the report states. “One of the five NDAs, NSA’s Security Agreement, did not include the current required whistleblower provisions but did include language related to whistleblower protections and had some statutory references. The remaining four NDAs made no mention of whistleblower protections.” The watchdog also identified five additional agreements that, while not explicitly titled as NDAs, implied non-disclosure obligations and similarly omitted the required protective language.
The findings arrive as the Trump administration weighs a standardized non-disclosure agreement for government-wide use—a proposal that has drawn bipartisan criticism for its potential to chill legitimate reporting of misconduct. Critics include Senator Chuck Grassley (R-Iowa), who requested the inspector general’s investigation.
The audit further revealed that the process for granting NSA employees access to “compartmented information” incorporates additional non-disclosure provisions that also lack the mandated whistleblower protection language.
“The subject matter experts we spoke with explained that individual offices develop their own access agreement brief sheets using a template, and an affiliate’s acknowledgement of one of these electronic brief sheets serves as the nondisclosure agreement,” the report notes. “In interviews with SMEs, two opened brief sheets of their own and noted that the required provisions were not present. We reviewed the template and noted that it lacked inclusion of the required whistleblower protection provisions.”
The inspector general recommended establishing a formal process to ensure all non-disclosure policies, forms, and agreements contain the legally mandated whistleblower protection language, and assigning responsibility for compliance to a specific agency official.
The NSA concurred with the recommendations and stated it plans to assign compliance oversight to the agency’s chief of staff.
Also Read
- Log Cabin Republicans Rebrand as ‘LGB’ Organization, End Transgender Advocacy
- PDD Holdings Stock Slips on Lackluster Q2 Earnings
- Poll Shows Plummeting U.S. Support for Iran Conflict as Trump’s Approval Hits Historic Low
- Ukraine’s Allies Vow Continued Military Support, Prioritize Air Defense Amid Escalating Russian Strikes


