What Is CJIS Information? Access, Protection, and Penalties

CJIS information is the criminal justice data collected, stored, and shared through the FBI’s Criminal Justice Information Services Division. It includes fingerprints and other biometrics, rap sheets, wanted-person and stolen-property records, incident reports, and background-check results. Access is restricted to law enforcement, courts, corrections, and vetted non-criminal justice users who have both legal authority and a work-related need for the data, and everyone who handles it, including private contractors, must pass a fingerprint-based background check and follow the FBI’s CJIS Security Policy.

What Counts as CJIS Information

Criminal Justice Information, or CJI, is the umbrella term the FBI uses for the sensitive data flowing through its systems. The CJIS Security Policy breaks it into several categories.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5

  • Biometric data: fingerprints, palm prints, iris scans, and facial images used to identify individuals.
  • Identity history data: a person’s recorded criminal or civil events, such as arrests, convictions, and dispositions.
  • Biographic data: personal details about individuals connected to a case, even if they have no criminal record themselves.
  • Property data: information about vehicles, firearms, or other property tied to criminal activity, particularly when linked to personally identifiable information.
  • Case and incident history: details about past criminal incidents, investigations, and their outcomes.

Criminal History Record Information (CHRI) is the subset most people picture when they hear “rap sheet.” It tracks a person’s interactions with the criminal justice system from arrest through final disposition and is treated as protected information until released through an authorized channel like a court proceeding.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5

Where the Data Lives

The term “CJIS information” usually points to data housed in one of a handful of national systems, each handling a different piece of criminal justice work.2Federal Bureau of Investigation. Criminal Justice Information Services (CJIS)

The National Crime Information Center (NCIC) is the real-time lookup backbone. It holds files on wanted persons, missing persons, stolen property, gang members, sex offenders, protection orders, and more. When an officer runs a plate or a name during a traffic stop, the query usually hits NCIC.

Next Generation Identification (NGI) is the FBI’s biometric system. It handles fingerprints with better than 99.6 percent matching accuracy and also supports palm prints, iris scans, and facial recognition searches against more than 30 million criminal mug shot photos. Two NGI features are worth knowing. The Repository for Individuals of Special Concern (RISC) lets officers run a mobile fingerprint check and get results in under 10 seconds against wants, warrants, the immigration violator file, convicted sex offenders, and suspected terrorist lists. The Rap Back service lets authorized agencies subscribe to ongoing monitoring of a person’s criminal history so they receive an automatic alert if that person is later arrested, instead of having to re-run background checks periodically.3FBI. Next Generation Identification (NGI)

The National Instant Criminal Background Check System (NICS) supports firearm transfer decisions. When a licensed dealer runs a check on a buyer, NICS searches the NCIC, the Interstate Identification Index, and the NICS Index, which contains prohibiting records that may not appear elsewhere. Federal law bars firearm transfers to categories such as people convicted of crimes punishable by more than a year in prison, fugitives, people subject to certain domestic violence restraining orders, and individuals adjudicated as mentally incompetent, among others.4FBI: NICS Index. NICS Index

The National Data Exchange (N-DEx) fills a gap the others leave open. While NCIC holds structured records like warrants and stolen property entries, N-DEx houses narrative documents: incident and arrest reports, booking records, pretrial investigations, supervised release reports, calls for service, and field contact records. Its value is linking seemingly unrelated records across jurisdictions.5FBI. National Data Exchange (N-DEx)

Who Can Access CJIS Information

Access hinges on two principles that work together. “Right to know” means you have legal authority to receive the information, typically established by statute, executive order, or a formal agreement. “Need to know” means the information is actually necessary for the specific task you’re performing. Having one without the other is not enough.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5

Criminal Justice Agencies

Federal, state, local, and tribal law enforcement agencies, along with courts and correctional facilities, are the primary users. They query CJIS systems directly for investigations, warrant checks, booking, sentencing, and supervision. Everyone who touches the data, from the detective running a query to the records clerk processing an arrest report, must pass a fingerprint-based background check and complete security awareness training before getting access.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5

Non-Criminal Justice Agencies

Employers, licensing boards, and similar organizations can access criminal history data for purposes like hiring decisions, professional licensing, immigration proceedings, and security clearances. To qualify, the agency must be authorized by federal law, a state statute approved by the U.S. Attorney General, or an executive order. Government non-criminal justice agencies sign a Management Control Agreement with a criminal justice agency, keeping control over the criminal justice function with the criminal justice agency. Private non-criminal justice agencies, such as banks running checks on employees who handle cash, enter into a similar written agreement with the appropriate state authority.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5

All non-criminal justice agencies that receive CJI must comply with the full CJIS Security Policy. The same background check, training, and data-handling requirements that apply to a police department also apply to a county school board running fingerprint checks on teachers.

Contractors and Cloud Providers

Private contractors who build, maintain, or support systems that touch CJI must sign the CJIS Security Addendum, a standardized agreement approved by the Attorney General. The addendum limits how the contractor can use the data, requires the same background checks and training that apply to government employees, and subjects the contractor to the same audit scrutiny as any local user agency. Untrained or uncertified contractor employees cannot access CJI or any system where CJI might be viewable. New contractor operators must pass a certification exam within six months of assignment and recertify every two years.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5

Cloud providers face additional restrictions. CJI can only be stored in cloud environments physically located within the United States, U.S. territories, tribal lands, or Canada, and only under the legal authority of an agency belonging to the CJIS Advisory Policy Board. Metadata derived from unencrypted CJI must be protected the same way as the CJI itself and cannot be used for advertising or commercial purposes. In a software-as-a-service arrangement, the cloud provider must not have unescorted access to unencrypted CJI, and encryption keys should remain outside the provider’s control.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5

How CJIS Information Is Protected

The CJIS Security Policy is the rulebook that governs every entity handling CJI. Version 6.0, released in December 2024, is the current edition.6FBI. CJIS Security Policy v6.0 It draws on federal law, FBI directives, and guidance from the National Institute of Standards and Technology, and it applies to everyone who touches CJI, whether a sheriff’s office, a state DMV, or a private IT firm under contract.2Federal Bureau of Investigation. Criminal Justice Information Services (CJIS)

Facilities that process or store CJI must have controlled access points, surveillance systems, and visitor logs. On the digital side, every user gets a unique identifier, and multi-factor authentication is required to access systems containing CJI.

Encryption is mandatory for CJI both in transit and at rest whenever the data is outside a physically secure location. For data in transit, the policy requires FIPS 140-3 certified cryptographic modules or AES encryption with at least 128-bit key strength. For data at rest, the minimum jumps to 256-bit key strength.1Federal Bureau of Investigation (FBI). CJIS Security Policy v5.9.5 The higher bar for stored data reflects the greater risk: data sitting on a server is exposed for longer than data moving across a network.

Penalties for Misusing CJIS Information

Improper access, use, or sharing of CHRI or NCIC data can result in administrative sanctions up to and including termination of an agency’s access to CJIS services. The user agreement between each CJIS Systems Agency and the FBI spells out the standards, audit processes, and sanctions that govern use of the systems.7LSP.org. CJIS Security Policy v6.0 For an agency that depends on NCIC for daily operations, losing that access is a serious consequence.

Individuals who misuse CJIS systems can also face federal prosecution under the Computer Fraud and Abuse Act. Intentionally accessing a federal government computer without authorization, or exceeding authorized access to obtain government information, carries up to one year in prison for a first offense. If the access was for commercial gain, to further another crime, or involved information worth more than $5,000, the maximum rises to five years. A second conviction pushes the ceiling to ten years.8Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection With Computers

These aren’t hypothetical risks. Officers have been prosecuted for running personal queries, looking up ex-partners, or selling criminal history data. Audit logs track every query, so misuse is one of the easier law enforcement crimes to catch.

How to See and Correct Your Own CJIS Record

You don’t have to be a law enforcement officer to see what CJIS has on you. Any individual can request their own FBI Identity History Summary, the FBI’s version of your criminal record. The process costs $18, requires submitting a fingerprint card either electronically at a participating U.S. Post Office or by mail, and results typically arrive by first-class mail. Electronic submissions may receive an electronic response.9Federal Bureau of Investigation. Identity History Summary Checks Frequently Asked Questions

If your record contains errors, you can challenge it at no additional cost. You’ll need to clearly identify the information you believe is wrong and include supporting documentation. The FBI processes challenges in the order received, with an average response time of about 45 days.9Federal Bureau of Investigation. Identity History Summary Checks Frequently Asked Questions

Corrections often need to flow from the bottom up. The agency that originally submitted the inaccurate data, usually a local or state law enforcement agency, is responsible for keeping its records complete, accurate, and current. Federal regulations require agencies to submit disposition information within 120 days of the disposition and to notify all criminal justice agencies that received the incorrect data once a correction is made.10eCFR. 28 CFR 20.37 – Responsibility for Accuracy, Completeness, Currency, and Integrity In practice, you may need to contact both the FBI and the originating agency to get an error fully resolved. Missing dispositions, where an arrest shows up but the case dismissal doesn’t, are the most common problem and the one most likely to cause issues on a background check.