# Operational Activity and the Common Rule
**Entity class:** Regulatory structure
**Domains:** Human-subjects protection / public-health surveillance / intelligence and homeland security
## Definition
The revised Common Rule (2018), codified for HHS at 45 CFR 46.102 and adopted by DHS at 6 CFR 46.102, lists activities **deemed not to be research** for purposes of that regulation. Two of the exclusions match the two halves of [[wiki/CVE-CVE Convergence|CVE-CVE Convergence]]: clause **(l)(2)**, public health surveillance activities conducted, supported, requested, ordered, required, or authorized by a public health authority; and clause **(l)(4)**, authorized operational activities, as determined by each agency, in support of intelligence, homeland security, defense, or other national security missions.
## The governance seam
The exclusions remove Common Rule and IRB requirements; other governance continues to apply. HHS states that other laws, regulations, and policies may govern public-health surveillance, and Executive Order 12333 §2.10 requires that [[wiki/Intelligence Community|Intelligence Community]] research on human subjects follow HHS guidelines with documented informed consent. WHO's surveillance-ethics guidance describes surveillance as continuous and generally outside discrete research-ethics review, calling for continuous oversight and scrutiny of security reuse. The structure is a seam: an operational loop and a research study can use analytically identical techniques while occupying different oversight regimes. At the seam a person's status is assigned as a research subject or as an operational entity.
## Evidence ledger
- **Established:** the (l)(2) and (l)(4) exclusions; agency-level determination of operational activity; EO 12333 §2.10; HHS and WHO guidance on continuing oversight.
- **Unresolved:** the content and count of agency (l)(4) determinations covering predictive security activities, which administrative records and FOIA can reach.
## Relationships
- **convergence it formalizes:** [[wiki/CVE-CVE Convergence|CVE-CVE Convergence]], [[wiki/Countering Violent Extremism|Countering Violent Extremism]], and [[wiki/Biosurveillance|Biosurveillance]].
- **oversight:** [[wiki/Intelligence Oversight|Intelligence Oversight]] and [[wiki/Privacy and Civil Liberties|Privacy and Civil Liberties]].
- **consequence:** [[wiki/Legibility-Gated Redress|Legibility-Gated Redress]] and [[wiki/The Second Error Function|The Second Error Function]].
- **analysis:** [[research/Harms Incurred While Bringing Preventive Systems Online|Harms Incurred While Bringing Preventive Systems Online]].
- **collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
## Sources / Provenance
- [45 CFR 46.102 — Definitions, eCFR](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-A/part-46/subpart-A/section-46.102) (accessed 2026-09-23).
- [6 CFR 46.102 — Definitions, DHS](https://ecfr.io/Title-6/Section-46.102) (accessed 2026-09-23).
- [HHS OHRP — Draft Guidance on Activities Deemed Not to Be Research: Public Health Surveillance](https://www.hhs.gov/ohrp/regulations-and-policy/requests-for-comments/draft-guidance-activities-deemed-not-be-research-public-health-surveillance/index.html).
- [Executive Order 12333, National Archives](https://www.archives.gov/federal-register/codification/executive-order/12333.html) (1981, as amended).
- [WHO Guidelines on Ethical Issues in Public Health Surveillance](https://iris.who.int/bitstream/handle/10665/255721/9789241512657-eng.pdf) (2017).
**As of:** 2026-09-23