Micron Document

PANOPTICON brennan data broker loophole
page 3 / 11


A 2018 Supreme Court decision began to chip away at this unworkable doctrine. In Carpenter v. United States, the Court held that police must have a warrant to obtain seven days’ worth of historical cell-site location records. Specifically, the Court found that individuals have a reasonable expectation of privacy in their cell phone location data because that data reflects the “whole of their physical movements,” which in turn can reveal the most intimate details of their private lives. The Court also recognized that cell phone location information “is not truly ‘shared’ as one normally understands the term,” because cell phones are “indispensable to participation in modern society” and they collect location information automatically. Although the Court declined to explain how its holding might be applied to other types of information, it made clear that the Fourth Amendment protects highly sensitive information conveyed through the use of essential technologies, and that the government must have a warrant to obtain such data.

Nonetheless, several government agencies have argued that the Carpenter decision applies only to the specific type of location data at issue in that case (i.e., historical cell-site location information), and that Fourth Amendment protections apply only when the government compels companies to disclose information, not when private companies sell or voluntarily disclose information to law enforcement. Based on these purported distinctions, agencies are continuing to purchase cell phone location data — without a warrant or any other legal process — in large volumes. The Supreme Court presumably will clarify Carpenter’s applicability in due time, but for now, government agencies are relying heavily on data purchases to sidestep the Fourth Amendment’s central safeguard against abusive policing: the requirement that police obtain a warrant from a judge before invading a reasonable expectation of privacy.

Statutory Protections: Loopholes in the Electronic Communications Privacy Act

In the 1980s and 1990s, Congress sought to extend some protections to information held by third parties, but the resulting patchwork of statutes does not sufficiently safeguard privacy today. Critically, the United States lacks a comprehensive data privacy law. Instead, a piecemeal statutory structure — consisting of an outdated communications privacy law and sector-specific data protection laws — protects certain types of personal information from certain privacy intrusions while leaving other types of data and intrusions unregulated.

In 1986, Congress passed the Electronic Communications Privacy Act (ECPA) to protect the privacy of Americans’ communications in an era of new and emerging communications technologies. As part of ECPA, the Stored Communications Act (SCA) restricts certain private companies from voluntarily revealing digital communications or information about those communications to the government.

Much of ECPA was ahead of its time, but the statute today fails to address many issues created by technologies that were unimaginable to Congress in the 1980s. Specifically, the law applies only to communications-related information held by two categories of service providers:

- providers of an electronic communication service (ECS), defined as “any service which provides to users thereof the ability to send or receive wire or electronic communications” (i.e., phone and messaging services, social media platforms, and other forms of internet-based messaging); and

- providers of a remote computing service (RCS), defined as the “provision to the public of computer storage or processing services by means of an electronic communications system” (i.e., data storage and processing services).

Applied today, ECPA covers phone companies, internet service providers, providers of email and text messaging services, and social media platforms (apart from messages that are “readily accessible to the general public”). However, it does not cover third-party data brokers or many app developers that collect and maintain personal information.

Subject to certain exceptions, ECS and RCS providers may not voluntarily disclose the contents of communications to anyone, including the government. The term contents includes “any information concerning the substance, purport, or meaning” of a communication. With respect to non-contents information, ECS and RCS providers may not voluntarily disclose “record[s] or other information pertaining to a subscriber to or customer of such service . . . to any government entity.” This non-contents category is divided into two subgroups: subscriber information (e.g., name, address, and phone number) and other non-contents information (e.g., traffic or transactional information or other communications-related metadata, often referred to simply as communications metadata).

Section 2703 of the SCA conveys the specific legal process that the government must follow to obtain customer information held by an ECS or RCS. The process differs depending on the type of information sought. For example, when the government seeks to obtain the actual contents of electronic communications, generally it must obtain a probable cause warrant. But for some types of non-contents information, the government may obtain a court order based on “specific and articulable facts showing that there are reasonable grounds to believe” that the information is “relevant and material to an ongoing criminal investigation” — a less stringent standard than the probable cause requirement for a search warrant. And for other types of non-contents information (including subscriber information), the government may issue a subpoena, which requires no court approval or order.