All US agencies with counterterrorism programs that collect or “mine” personal data — such as phone, medical and travel records or Web sites visited — should be required to systematically evaluate the programs’ effectiveness, lawfulness, and impacts on privacy, says a new report from the National Research Council.