# Operational Activity and the Common Rule **Entity class:** Regulatory structure **Domains:** Human-subjects protection / public-health surveillance / intelligence and homeland security ## Definition The revised Common Rule (2018), codified for HHS at 45 CFR 46.102 and adopted by DHS at 6 CFR 46.102, lists activities **deemed not to be research** for purposes of that regulation. Two of the exclusions match the two halves of [[wiki/CVE-CVE Convergence|CVE-CVE Convergence]]: clause **(l)(2)**, public health surveillance activities conducted, supported, requested, ordered, required, or authorized by a public health authority; and clause **(l)(4)**, authorized operational activities, as determined by each agency, in support of intelligence, homeland security, defense, or other national security missions. ## The governance seam The exclusions remove Common Rule and IRB requirements; other governance continues to apply. HHS states that other laws, regulations, and policies may govern public-health surveillance, and Executive Order 12333 §2.10 requires that [[wiki/Intelligence Community|Intelligence Community]] research on human subjects follow HHS guidelines with documented informed consent. WHO's surveillance-ethics guidance describes surveillance as continuous and generally outside discrete research-ethics review, calling for continuous oversight and scrutiny of security reuse. The structure is a seam: an operational loop and a research study can use analytically identical techniques while occupying different oversight regimes. At the seam a person's status is assigned as a research subject or as an operational entity. ## Evidence ledger - **Established:** the (l)(2) and (l)(4) exclusions; agency-level determination of operational activity; EO 12333 §2.10; HHS and WHO guidance on continuing oversight. - **Unresolved:** the content and count of agency (l)(4) determinations covering predictive security activities, which administrative records and FOIA can reach. ## Relationships - **convergence it formalizes:** [[wiki/CVE-CVE Convergence|CVE-CVE Convergence]], [[wiki/Countering Violent Extremism|Countering Violent Extremism]], and [[wiki/Biosurveillance|Biosurveillance]]. - **oversight:** [[wiki/Intelligence Oversight|Intelligence Oversight]] and [[wiki/Privacy and Civil Liberties|Privacy and Civil Liberties]]. - **consequence:** [[wiki/Legibility-Gated Redress|Legibility-Gated Redress]] and [[wiki/The Second Error Function|The Second Error Function]]. - **analysis:** [[research/Harms Incurred While Bringing Preventive Systems Online|Harms Incurred While Bringing Preventive Systems Online]]. - **collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]]. ## Sources / Provenance - [45 CFR 46.102 — Definitions, eCFR](https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-A/part-46/subpart-A/section-46.102) (accessed 2026-09-23). - [6 CFR 46.102 — Definitions, DHS](https://ecfr.io/Title-6/Section-46.102) (accessed 2026-09-23). - [HHS OHRP — Draft Guidance on Activities Deemed Not to Be Research: Public Health Surveillance](https://www.hhs.gov/ohrp/regulations-and-policy/requests-for-comments/draft-guidance-activities-deemed-not-be-research-public-health-surveillance/index.html). - [Executive Order 12333, National Archives](https://www.archives.gov/federal-register/codification/executive-order/12333.html) (1981, as amended). - [WHO Guidelines on Ethical Issues in Public Health Surveillance](https://iris.who.int/bitstream/handle/10665/255721/9789241512657-eng.pdf) (2017). **As of:** 2026-09-23