"The automated query can be based on: * Identity information included in the application or in travel documents, such as name, date of birth, national ID number, and/or * the fingerprint of an individual."
Sounds like they could send requests to that computer system just based on publicly available information on a person like name and date of birth, even if the person never applied for a visa or tried to enter the US.
But yeah, it does sound that way, but certainly not clear cut to me what the situation is. I.e. does the agreement involve clauses about what to do if this is abused? Do we have a way to detect if theyre using this on non-travellers? Etc.
A couple of counterexamples:
Italy's "fiscal code" is generated with a simple algorithm which can be executed manually:
https://en.wikipedia.org/wiki/Italian_fiscal_code
Sweden's "personal identity number" is public information and can be looked up by anyone:
https://en.wikipedia.org/wiki/Personal_identity_number_(Swed...
This also means a person’s Belgian RRN can change.
It's not clear how it is supposed to work in detail. But it sounds like it could be implemented in a way that makes illegitimate queries possible. It doesn't sound like they want to really ensure that you can catch those.