|
|
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
FLAG
Reporting unit
1 A
Encl J
G
ORGLOCN
has established
subordinate
reporting units
from own
resources.
FORDV
Country of
1 A
Encl O
G
MEQLOCN
origin of
delivery vehicles
identified in
field MEQPT
under the
control of non-
U.S. forces (e.g.,
NATO or
Canadian) but
reported by U.S.
forces.
GCMD
UIC of the
6 AN
Encl H
G
LOSING,
major command
RPTNORG
gaining the unit
as a result of a
transfer.
HOGEO
GEOLOC code
4 AN
Encl J
G
ORGLOCN
for the
permanent
location of the
unit.
INTR1
UIC of a unified
6 AN
Encl H
G
GAINING,
command,
RPTNORG,
service major
TRANSFER
command,
defense agency,
or unified
command
component
having an
interest in the
reporting unit.
INTR2
Same as INTR1.
6 AN
Encl H
G
SAME AS INTR1
INTR3
Same as INTR1.
6 AN
Encl H
G
SAME AS INTR1
INTR4
Same as INTR1.
6 AN
Encl H
G
SAME AS INTR1
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-11
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
LABEL
Field within a
1-8 AN
Encl L
G
LABEL,
set upon which
REMARKS
remarks are to
be made.
LIM
Service-imposed
1 N
Encl N
G
CATLIMIT,
limitation on
OVERALL
any or all of the
measured
resource areas
preventing the
unit from
attaining an
overall category
level of C-1 for
the type of
report identified
in field TREAD.
LNAME
Official long
1-55
Encl G
G
BIDE
name of the
ANS
organization.
MAJOR
Major unit as
1 A
Encl G
G
BIDE
defined by the
Service,
command, or
agency
establishing the
unit.
MBCMD
UIC of the
6 AN
Encl K
G
RESERVES
major command
the unit will
transfer to
during
mobilization.
MDATE
Number of days
4 AN
Encl K
G
RESERVES
from
mobilization
day (M-day) the
unit is
scheduled to be
mobilized.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-12
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
MEORC
Number of
1-3 N
Encl O
G
MEQLOCN
items in MEQPT
with a
conventional
weapon delivery
capability,
operationally
ready and in
possession of
the unit.
MEORD
Number of
1-3 N
Encl O
G
MEQLOCN
items in MEQPT
with a nuclear
and
conventional
weapons
delivery
capability,
operationally
ready and in
the physical
possession of
the unit at its
present
location.
MEORN
Number of
1-3 N
Encl O
G
MEQLOCN
items in
MEQPT,
operationally
ready for
nuclear
employment
and in the
physical
possession of
the unit at its
recent location.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-13
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
MEORO
Number of items
1-3 N
Encl O
G
MEQLOCN
in MEQPT with
no designated
weapon delivery
capability,
operationally
ready and in
physical
possession of the
unit at its
present location.
MEPSA
Number of
1-3 N
Encl O
G
MEQLOCN
MEQPT items
authorized to the
unit under its
respective service
documents.
MEPSD
Number of
1-3 N
Encl O
G
MEQLOCN
MEQPT items
under the
OPCON of the
unit at its
present location.
MEQPT
Major equipment
1-13
Encl O and
G
MEQLOCN
item.
AN
Q
MEREC
Primary and
2-6 A
Encl O and
G
MEQLOCN
additional (up to
Q
two)
reconnaissance
capability codes,
in priority
sequence, for the
item in MEQPT.
Use
“Reconnaissance
Capability
Codes.”
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-14
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
METAL
Number of
1-3 N
Encl O
G
MEQLOCN
MEQPT items
allocated
(rather than
authorized) to
the unit for its
assigned
mission.
MJCOM
UIC of the
6 AN
Encl G
G
BIDE
unified
command,
major
command, or
CSA the RPTOR
is assigned to
for
administration.
MODEL
Equipment
13 AN
Encl Q
G
MEQPT
model.
MODFG
Unit’s reported
1 A
Encl E
G
SHIPLOCN
position as a
modified
location.
MONOR
UIC of the
6 AN
Encl G
G
BIDE
organization
monitoring the
identity and
status of the
foreign or
international
unit.
NDEST
Port name.
1-20
Encl E
G
SHIPLOCN
ANS
NEDSC
Ship’s
16 AN
Encl E
G
SHIPLOCN
destination
when the field
NDEST
contains
geographic
coordinates.
NTASK
Operational
4-16
Encl E
G
SHIPLOCN
organization a
ANS
ship is assigned
to (example:
TG60.1).
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-15
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
NUCIN
Code for a
1 A
Encl J
G
ORGLOCN
nuclear-capable
unit.
OPCON
Code indicating
6 AN
Encl J
G
ORGLOCN
the UIC of the
organization
exercising
operational C2
of the reporting
unit.
PCTEF
Current percent
1-3 N
Encl J
G
ORGLOCN
of effectiveness
of the
organization.
PEGEO
GEOLOC code
4 AN
Encl M
G
PERSTREN
representing
the location of a
unit’s
personnel.
PICDA
Date of change
8 N
Encl M
G
PERSTREN
of personnel
information.
Personnel data
report date.
PLETD
Indicates the
Encl E
G
SHIPLOCN
Zulu date and
time to the
nearest full
hour of the
estimated time
of departure
from the
present
location.
POINT
Geographic
16 AN
Encl J
G
ORGLOCN
coordinates
expressed in
latitude and
longitude.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-16
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
POSTR
Number of
1-5 N
Encl M
G
PERSTREN
personnel
physically
present, USA
operating
strength at the
location
specified in
PEGEO, or
embarked
onboard the
ship specified in
PEGEO.
PREAD
Contains the
5N
Encl O
G
MEQLOCN
percentage of
Wartime
Equipment
Readiness
based on the
unit's total
required
equipment
divided by
equipment
possessed.
PRGEO
Geographic
4 AN
Encl D, E, J
G
ORGLOCN,
location where
MEQLOCN,
the unit is
SHIPLOCN
presently
located.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-17
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
PRRAT
Measured
1 N
Encl N
G
OVERALL
resource area
for personnel
for the type of
report identified
in TREAD.
Determine the
percent of the
structured
strength
achieved by the
available
strength and
applying that
percent to the
criteria for
strength and
criteria MOS.
PRRES
Primary reason
3 AN
Encl N
G
PERSONEL,
the personnel
OVERALL
measured
resource area
level is not P-1.
PUIC
UIC of the
6 AN
Encl J
G
ORGLOCN
parent
organization
from whose
organic
resources the
reported unit
was formed.
RDATE
Scheduled date
8 N
Encl K
G
RESERVES
of release from
EAD of the RC
unit.
READY
Current overall
1 N
Encl N
G
OVERALL
category level.
REASN
Primary reason
1 AN
Encl N
G
OVERALL
a unit or
resource area is
not assessed as
C-1.
REMARKS
Remarks text.
1-2000
Encl L
G
REMARKS
ANS
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-18
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
REVAL
Code identifying
1 A
Encl G
G
BIDE
the validation of
the unit
registration by
the appropriate
service, unified
command, or
CSA. Use the
following codes:
"R” for RC, "G"
for National
Guard
Component,
and "X" for
Regular
Component.
RICDA
“As of" date of
8 N
Encl N
G
OVERALL
any addition
change or
replacement of
category level
data concerning
this unit.
RPTOR
UIC of the
6 AN
Encl H
G
GAINING,
organization
RPTNORG,
designated by a
TRANSFER
major command
to submit
GSORTS status
reports.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-19
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
SBFLG
Code reflecting
1 AN
Encl E, F,
G
RPTNORG,
the relationship
M
SHIPLOCN,
between the
PERSTREN,
reporting unit
and the
organization
identified in
SBUIC. Codes
are E - Ship
has unit on
board, D - Ship
has unit
equipment on
board, T - Ship
has personnel
deployed, and
P - Ship has
conventional
plan equipment
deployed.
SBRPT
UIC of the unit
6 AN
Encl H
G
GAINING
designated by a
RPTNORG
major command
TRANSFER
to submit
GSORTS
reports.
SCLAS
Security
1 A
Encl D and
G
SORTUNIT,
classification of
G
BIDE
the entire report
(SORTUNIT set)
or the
classification of
unit (BIDE set).
SECRN
Secondary
3 AN
Encl N
G
OVERALL
reason the
organization is
currently not C-
1 for the type of
report identified
in field TREAD.
SECUR
Security
1 A
Encls G, H,
G
All tables and
classification of
I, J, K, L,
USMTF sets
the table or set.
M, N and O
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-20
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
SECURE
Security
1 AN
Encl Q
G
MEQPT
classification of
the equipment.
SERV
Unique code
1 AN
Encl G
G
BIDE
representing a
branch of
Service.
STRUC
Number of
1-5 N
Encl M
G
PERSTREN
personnel
established as
the structured
strength of the
organization.
TDATE
Effective date of
8 N
Encl H
G
LOSING,
transfer is a
TRANSFER,
specific date
RPTNORG
mutually agreed
upon by the
losing and
gaining unified
command.
TDEPS
Number of
1-5 N
Encl M
G
PERSTREN
personnel
required to
deploy or be
employed as
identified by the
UTC tasked to
the organization
plan or order in
a specific
emergency or
crisis situation.
This data
element is only
reported by
USAF and
USMC.
TECON
Control code
6 AN
Encl O
G
MEQLOCN
representing the
location of the
major
equipment in
field MEQPT.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-21
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
TEGE0
Geographic
4 AN
Encl O
G
MEQLOCN
location code
where a unit's
equipment is
temporarily
located.
TERRN
Tertiary reason
3 AN
Encl N
G
OVERALL
organization not
C-1 for the type
of report
identified in
field TREAD.
TIME
Header DTG of
8 AN
Encl D
G
SORTUNIT
the message
that last
updated a
specific table.
TPERS
Type of
2 A
Encl M
G
PERSTREN
personnel about
which unit
personnel
strength data
are reported.
TPSN
Code indicating
5-7 N
Encl G
G
BIDE
groups of like-
type USA
organizations.
TREAD
Type of report
5 AN
Encl N
G
OVERALL
being reported.
TRGEO
Geographic
4 AN
Encl H
G
LOSING,
location code
RPTNORG
where the
organization will
be located upon
arrival.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-22
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
TRRAT
Measured
1 N
Encl R
G
TRAINING,
resource area
OVERALL
level for
training.
Indicates the
measured
resource area
level for training
for the type of
report identified
in field TREAD.
TRRES
Reason the
3 AN
Encl N
G
TRAINING,
measured
OVERALL
resource area
level for training
is not C-1 for
the type of
report identified
in field TREAD.
UDC
Component
3 AN
Encl G
G
BIDE
general status
and primary
mission for
which the
organization
was established.
UIC
Contains the
6 AN
Encl F
G
RPTDUIC
unit
identification
code.
ULC
Size or level of
1-3 AN
Encl G
G
BIDE
an organization
where control or
authority over
the reporting
unit is
exercised.
UTC
Contains a valid
5 AN
Encl G
G
BIDE
Unit Type Code.
Table 57. GSORTS SORTSREP Data Elements (Cont.)
S-23
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
ACFTA
Aircraft
1-3 N
Ref m
AF
SPARES,
availability
AFSPECAP
percentage.
ARUSD
Aircraft spares
1 A
Ref m
AF
SPARES,
assessment
AFSPECAP
area converted
percentage
driver.
CADAF
Known or
8 N
Ref m
AF
SUBFCAST,
estimated date
SUBOVRAL
of the forecasted
change in the
overall C-level.
CARAF
Forecasted
1 N
Ref m
AF
SUBFCAST,
overall C-level
SUBOVRAL
the unit expects
to attain by the
date reported in
CADAF.
CPASG
Number of
1-5 N
Ref m
AF
AFPERDAT,
personnel with
AFPERTNG
critical Air Force
Special Codes
(AFSC) assigned
or attached for
stationary units
or the number
of personnel
with critical
AFSC's assigned
or attached
required by the
UTC package for
units with
tasking
requiring
deployment as
the first phase
of their mission.
Table 58. SORTSREPAF Data Elements
S-24
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
CPAUR
Number of
1-5 N
Ref m
AF
AFPERDAT,
personnel with
AFPERTNG
critical AFSC's
authorized for
stationary units
or the number
of personnel
with critical
AFSC's required
by the UTC
package for
units with
tasking
requiring
deployment as
the first phase
of their mission.
CPAVL
Number of
1-5 N
Ref m
AF
AFPERDAT,
personnel
AFPERTNG
assigned or
attached to the
reporting unit
with a critical
AFSC as their
duty available to
support the
measured unit's
mission within
the DOC
response time.
DCNDY
Deployment
5 AN
Ref m
AF
PACKAGE
task number,
departure
control number,
or the
deployment
control number.
DOCID
DOC
4 AN
Ref m
AF
AFPERDAT,
identification for
AFPERTNG
the RPTOR.
DOCNR
DOC tasking
1 AN
Ref m
AF
AFPERDAT,
about which
AFTNGDAT,
associated
EQCONDAT,
status data are
EQSOHDAT,
to be reported.
SUBOVRAL
Table 58. SORTSREPAF Data Elements (Cont.)
S-25
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
DTASK
Indicator of
1 AN
Ref m
AF
PACKAGE
whether an UTC
is listed on the
unit's DOC
statement or
not.
EQRED
Percentage of
1-3 N
Ref m
AF
EQCONDAT,
wartime
AFEQUIP
required
support
equipment
possessed that
can be mission
ready and
available in the
unit's response
time.
EQREE
Percentage of
1-3 N
Ref m
AF
EQCONDAT,
wartime
AFEQUIP
required combat
essential
equipment
possessed that
can be mission
ready and
available in the
unit's response
time.
EQRET
Estimated
8 N
Ref m
AF
PACKAGE
return date of
the UTC.
EQSEE
Percentage of
1-3 N
Ref m
AF
EQCONDAT,
wartime-
AFEQUIP
required
combat-
essential
equipment
possessed.
EQSSE
Percentage of
1-3 N
Ref m
AF
EQCONDAT,
wartime-
AFEQUIP
required
support
equipment and
supplies
possessed.
Table 58. SORTSREPAF Data Elements (Cont.)
S-26
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
ERRAF
Measured
1N
Ref m
AF
SUBOVRAL
resource area
C-level for
equipment
condition.
ERREF
Reason the
3 AN
Ref m
AF
SUBOVRAL
measured
resource area
level for
equipment
condition is
not 1.
ERSA
Percentage of
1-3 N
Ref m
AF
EQCONDAT,
one category of
AFEQUIP
equipment
condition
measured
resource area.
Repeatable 1-9
times.
ESRAF
Measured
1 N
Ref m
AF
SUBEQSOH,
resource area
SUBOVRAL
level for
equipment and
supplies
on-hand.
ESREF
Reason the
3 AN
Ref m
AF
SUBEQSOH,
measured
SUBOVRAL
resource area
level for
equipment and
supplies is
not 1.
ESSA
Percentage of
1-3 N
Ref m
AF
EQSOHDAT,
one category of
AFEQUIP
equipment and
supplies.
Repeatable 1-9
times.
Table 58. SORTSREPAF Data Elements (Cont.)
S-27
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
GCCLA
Indicates the
1-2N
Ref m
AF
AFSPECAP
number of
crews trained to
the graduated
combat
capability
level A.
GCCLB
Indicates the
1-2N
Ref m
AF
AFSPECAP
number of
crews trained to
the graduated
combat
capability
level B.
GEOGR
Indicates the
6 AN
Ref m
AF
PACKAGE
geographic
location or UIC
of the ship on
which the UTC
is presently
located.
LIMF
Service-imposed
1 N
Ref m
AF
SUBCATLM,
limitation on
SUBOVRAL
any or all of the
measured
resource area
preventing the
unit from
attaining an
overall category
level of C-1.
MEARD
Number of
1-3 N
Ref m
AF
EQSOHDAT,
MEQPT items
AFEQUIP
authorized or
required to
accomplish the
unit's wartime
mission.
MEASG
Number of
1-3N
Ref m
AF
EQSOHDAT,
MEQPT items
AFEQUIP
assigned to the
unit. This is
not used to
compute the
unit's C-level.
Table 58. SORTSREPAF Data Elements (Cont.)
S-28
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
MEMRA
Number of
3 N
Ref m
AF
EQSOHDAT,
aircraft or
AFEQUIP
missiles mission
ready and
available within
the unit's DOC
response time.
MEPOS
Number of
1-3 N
Ref m
AF
EQSOHDAT,
MEQPT items
AFEQUIP
presently
possessed by
the measured
unit.
MISSION
USAF mission
69 AN
Ref m
AF
DOCID
code.
PEQFR
Indicates the
Ref m
AF
PACKAGE
actual or
forecasted date
the major
end-item of
equipment will
be operational.
PEQS
Identifies the
1- 13 AN
Ref m
AF
PACKAGE
major
equipment
about which
associated
status data are
to be reported.
PERTC
Percentage of
1-3 N
Ref m
AF
AFPERDAT,
wartime-
AFPERTNG
required critical
personnel
available.
PERTP
Percentage of
1-3 N
Ref m
AF
AFPERDAT,
wartime
AFPERTNG
required total
personnel
available.
PRRAF
Measured
1 N
Ref m
AF
SUBPERS,
resource area
SUBOVRAL
C-level for
personnel.
Table 58. SORTSREPAF Data Elements (Cont.)
S-29
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
PRREF
Reason the
3 AN
Refm
AF
SUBPERS,
personnel
SUBOVRAL
measured
resource area
level is not P-1.
PRSA
Indicates the
3 N
Ref m
AF
AFPERTNG
percentage of
personnel
condition
measured
resource area,
repeatable for
up to nine
categories.
READF
Degree to which
1 N
Ref m
AF
SUBOVRAL
the unit is
capable of
performing its
secondary or
subordinate
wartime
mission.
REASF
Measured
1 A
Ref m
AF
SUBOVRAL
resource area,
C-level, or other
reason that
most
significantly
describes the
reason the
organization is
not C-1.
RESPF
Unit response
5 AN
Ref m
AF
SUBOVRAL
time for
secondary or
subordinate
DOCs.
Table 58. SORTSREPAF Data Elements (Cont.)
S-30
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
RICDF
"As of" date of
8 AN
Ref m
AF
SUBOVRAL
any addition,
change, or
replacement of
resources and
training data for
the unit's
secondary or
subordinate
wartime
mission.
RLIMF
Primary reason
1 A
Ref m
AF
SUBCATLM,
that the C-level
SUBOVRAL
of the unit is
limited.
SDOC
Secondary or
4 AN
Ref m
AF
SUBOVRAL
subordinate
DOC.
SECRF
Secondary
3 AN
Ref m
AF
SUBOVRAL
reason the unit
is not C-1.
SEDY
Indicates the
1 AN
Ref m
AF
PACKAGE
operational
status of the
support
equipment
associated to a
major piece of
equipment.
SEQFR
Indicates the
Ref m
AF
PACKAGE
actual or
forecast date
the support
equipment for
the major
equipment will
be operational.
SMAA
Contains the
1-2 N
Ref m
AF
3SPECAP,
Service for
AFSPECAP
which the code
is valid.
Table 58. SORTSREPAF Data Elements (Cont.)
S-31
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
SMAC
Indicates the
1-2 N
Ref m
AF
3SPECAP,
number of
AFSPECAP
formed crews
and personnel
who are
qualified and
mission ready in
the respective
utilization field
or special
mission
capability and
who are
available within
the unit's DOC
response time.
SMCC
Identifies the
1-2 N
Ref m
AF
3SPECAP,
special mission
AFSPECAP
capability being
reported by the
unit.
SMRA
Indicates the
1-2 N
Ref m
AF
3SPECAP,
number of
AFSPECAP
aircraft
configured for
the special
mission
capability as
required by an
OPLAN or other
tasking
document.
SMRC
Indicates the
1-2 N
Ref m
AF
3SPECAP,
number of
AFSPECAP
required crews
and personnel
in each field or
mission area or
qualification.
SORTE
Percentage of
1- 3 N
Ref m
AF
SPARES,
sortie capability.
AFSPECAP
Table 58. SORTSREPAF Data Elements (Cont.)
S-32
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
TCARQ
Number of
1-3 N
Ref m
AF
AFTNGDAT,
authorized or
AFPERTNG
required crews
used to
compute the
unit's training
C-level.
TCRAS
Number of
1-3 N
Ref m
AF
AFTNGDAT,
complete crews
AFPERTNG
derived from
individual
crewmembers
assigned to the
unit.
TCRAV
Number of
1-3 N
Ref m
AF
AFTNGDAT,
available
AFPERTNG
mission-ready
crews used to
compute the
unit's training
C-level
(METHOD "B").
TEAFR
Indicates the
Ref m
AF
PACKAGE
actual or
forecast date
the team
assigned to
support the
UTC is
satisfactory.
TEDY
Indicates the
1 A
Ref m
AF
PACKAGE
status of the
personnel
assigned to the
UTC.
TERRF
Tertiary reason
3 AN
Ref m
AF
SUBOVRAL
the unit is not
C-1.
TMTHD
Method used to
1 A
Ref m
AF
AFTNGDAT,
compute the
AFPERTNG
training
measured area.
This field must
contain either a
“B” or “C.”
Table 58. SORTSREPAF Data Elements (Cont.)
S-33
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
TPASG
Number of
1-5 N
Ref m
AF
AFPERDAT,
people who have
AFPERTNG
signed into the
unit and not
signed out on a
PCS move or are
attached to the
unit in a TDY
status.
TPAUT
Number of
1-5 N
Ref m
AF
AFPERDAT,
personnel
AFPERTNG
authorized by
the organization
UMD for
generation units
and the number
of personnel
required by UTC
packages
against which
the unit deploys
for mobility
units.
TPAVL
Total number of
1-5 N
Ref m
AF
AFPERDAT,
personnel who
AFPERTNG
are available
within the unit’s
DOC response
time and
assigned to fill
wartime
requirements.
TRRAF
Measured
1 N
Ref m
AF
SUBTNG,
resource area
SUBOVRAL
C-level for
training.
TRREF
Reason the
3 AN
Ref m
AF
SUBTNG,
measured
SUBOVERAL
resource area
level training is
not C-1.
TRSA
Training sub-
1N
Ref m
AF
AFTNGDAT,
area percentage,
AFPERTNG
repeatable 1-9
times.
Table 58. SORTSREPAF Data Elements (Cont.)
S-34
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
TRUTC
Percentage of
1-3 N
Ref m
AF
AFTNGDAT,
authorized or
AFPERTNG
required crews
that are formed,
mission ready
and available.
UTCFR
Element
Encl m
AF
PACKAGE
indicates the
actual or
forecasted date
the UTC will be
operational or
deployable or
the date that
the UTC was
deployed.
WRSK
Percentage of
1-3 N
Ref m
AF
SPARES,
required
AFSPECAP
WRSK/BLSS
on-hand.
Table 58. SORTSREPAF Data Elements (Cont.)
Label
Descriptor
Format
Reference
Source
Set
DOR
Date-of-rank of
8 N
Ref l
N
UNITCDR
the individual
identified in
RANK.
LINEAL
Lineal
1-9 AN
Ref l
N
UNITCDR
precedence
number of the
individual
identified in
RANK.
NAME
Name of the
1-38 AN
Ref l
N
UNITCDR
individual who
is identified in
field RANK.
PRJATT
Forecasted
8 AN
Ref l
N
PRMAR
rating date.
PRJSTAT
Projected status
1 N
Ref l
N
PRMAR
of the reported
unit.
Table 59. SORTSREPNV Data Elements
S-35
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
PRI
Code indicating
3 AN
Ref l
N
PRMAR
the primary
reason the unit
is not M-1.
PRMSN
Primary
3 AN
Ref l
N
PRMAR
mission code.
RANK
Abbreviated
4 AN
Ref l
N
UNITCDR
rank of the
commander,
commanding
officer, or
officer-in-
charge.
RATE
Readiness
1 N
Ref l
N
PRMAR
rating level.
SEC
Code indicating
3 AN
Ref l
N
PRMAR
the secondary
reason the unit
is not M-1.
SPCAP
Special
3 AN
Ref l
N
SPCAP
capabilities
code.
TER
Code indicating
3 AN
Ref l
N
PRMAR
the tertiary
reason the unit
is not M-1.
TYPE
Mission Area
1 AN
Ref l
N
PRMAR
Type that may
be C (Coast
Guard), N
(Navy), or O
(Other).
Table 59. SORTSREPNV Data Elements (Cont.)
S-36
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
AGRASGD
Number of
3 N
Ref k
A
ACTGURES
Active Duty,
Guard, and
Reserve
soldiers
assigned full
time U.S. Army
Reserve (USAR)
(Title 10), Army
National Guard
(ARNG) (Title
32), assigned
to active duty.
ALO
Authorized
1 N
Ref k
A
ARMYRPT
level of
organization
code.
ASGD
Number of
4 N
Ref k
A
2ADDSKIL
assigned
personnel with
the additional
skill identifier
for the
associated
record.
APERT
Percentage of
1-3 N
Ref k
A
PERSDATA
USA personnel
turnover.
ARGO
Reserve
2 AN
Ref k
A
ABIDE
Command or
General Officer
Command to
which the
USAR UIC is
assigned or
attached.
ASGMT
Command of
2 AN
Ref k
A
ABIDE
assignment of
each USA unit.
Table 60. SORTSREPAR Data Elements
S-37
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
ASI
Additional Skill
3 AN
Ref k
A
2ADDSKIL
Identifier (ASI)
indicates a
special skill, in
addition to a
skill identified
by a personnel
occupational
specialty code.
ASPER
Assigned
1-3 N
Ref k
A
PERSDATA
strength of a
USA reporting
unit in percent.
AUTH
Authorized
1-4 N
Ref k
A
2PSPER,
strength for
2ADDSKIL
this data.
AUTH LIC
Language
2 AN
Ref k
A
2LANGUAGE
indicator code
authorized.
AVAIL
Available
5 N
Ref k
A
2PSPER
strength for
this data.
AVNCD
Code that
1 A
Ref k
A
ABIDE
identifies
aviation units
for USA Unit
Status Report
(USR) reporting
purposes.
AVPER
Available
1-3 N
Ref k
A
PERSDATA
strength of a
USA reporting
unit in percent.
C5
Field indicating
2 N
Ref k
A
READYSEG
the
subordinate
units reporting
C-5. Only
reported in a
USA composite
report.
Table 60. SORTSREPAR Data Elements (Cont.)
S-38
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
CCNUM
Identifies the
6 N
Ref k
A
READYSEG
unit's C2
number except
for composite
reports.
COMPEOH
Code for the
1 AN
Ref k
A
ROUNDOUT
composite unit
equipment-on-
hand category
level.
COMPER
Composite unit
1 AN
Ref k
A
ROUNDOUT
personnel
category level
code.
COMPOVAL
Composite unit
1 AN
Ref k
A
ROUNDOUT
overall category
level code.
COMPPER
Composite unit
1 AN
Ref k
A
ROUNDOUT
personnel
category level
code.
COMPTR
Composite unit
1 AN
Ref k
A
ROUNDOUT
training
category level
code.
DAMPL
Department of
5 N
Ref k
A
ABIDE
(note - The
U.S. Army
DAMPL field
Master Priority
is no longer
List code for
being used
allocation of
by the
personnel and
Army)
equipment for
the reported
unit.
DE
Sequence
2 N
Ref k
A
LABELID,
number of the
PRRES,
reported
2ERCFOUR2,
information.
PSPER,
2PIERRAT,
2EOHSHRT,
2LANGAGE,
2ADDSKIL,
2EOHSHRT,
2PIESTAT,
2ERCERRT
Table 60. SORTSREPAR Data Elements (Cont.)
S-39
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
EHRD1
Number of
1-3 N
Ref k
A
EQOHDATA
lines at level 1.
EHRD2
Number of
1-3 N
Ref k
A
EQOHDATA
lines at level 2.
EHRD3
Number of
1-3 N
Ref k
A
EQOHDATA
lines at level 3.
EHRD4
Number of
1-3 N
Ref k
A
EQOHDATA
lines at level 4.
EHRDN
Number of
1-3 N
Ref k
A
EQOHDATA
reportable
equipment line
items.
EQLIN
Equipment line
6 AN
Ref k
A
2EOHSHRT
item number.
ERAAUTH
Number of
3 N
Ref k
A
2ERCFOUR
Code A items
authorized.
ERCA4LN
Equipment or
6 AN
Ref k
A
2ERCFOUR
pacing item
line item
number.
ERCAOH
Number of
3 N
Ref k
A
2ERCFOUR
Code A items
on-hand.
ERCAREQ
Number of
3 N
Ref k
A
2ERCFOUR
Code A items
required.
FEMASGD
Number of
4 N
Ref k
A
FEMALE
females
assigned.
FEMPREG
Number of
4 N
Ref k
A
FEMALE
pregnant
females
assigned.
FUAC
Defined
1-2 A
Ref k
A
ABIDE, UNIT
functional area
for which the
UIC
assignment
and
registration is
requested.
GRADE
Assigned
5 N
Ref k
A
2PSPER
strength for
this data.
Table 60. SORTSREPAR Data Elements (Cont.)
S-40
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
ITAAD
Designated
2 AN
Ref k
A
ABIDE
installation
with ITAAD
capability for
the reported
unit.
ITAEM
Code
1 AN
Ref k
A
TRAINDAT
indicating the
availability of
training
materiel
indicator.
ITAFL
Code
1 AN
Ref k
A
TRAINDAT
indicating the
availability of
fuel.
ITAFT
Code indicating
1 AN
Ref k
A
TRAINDAT
the availability
of funds for
training.
ITAQL
Code indicating
1 AN
Ref k
A
TRAINDAT
the availability
of qualified
leaders for
training.
ITATA
Code indicating
1 AN
Ref k
A
TRAINDAT
the availability
of ammunition
for training.
ITATF
Code indicating
1 AN
Ref k
A
TRAINDAT
the availability
of training
areas or
facilities.
ITATM
Code indicating
1 AN
Ref k
A
TRAINDAT
the availability
of time/flying
hours.
ITAVS
Code indicating
1 AN
Ref k
A
TRAINDAT
the assigned
strength
shortfall
indicator.
Table 60. SORTSREPAR Data Elements (Cont.)
S-41
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
ITAVTRNG
Code indicating
1 AN
Ref k
A
TRAINDAT
the status of
aviator training
indicator.
ITSDR
Code indicating
1 AN
Ref k
A
TRAINDAT
special duty
requirements.
LIC
Code for the
1 A
Ref k
A
ABIDE
logistics
circumstances
for the reported
unit.
LICASGD
Number of
2 N
Ref k
A
2LANGAGE
personnel
assigned to the
unit who
possess the
language
indicator code
of the
associated
record.
LICMOS
Language
3 AN
Ref k
A
2LANGUAGE
indicator code
MOS.
LICQUAL
Number of
2 N
Ref k
A
2LANGAGE
personnel
qualified in the
language
indicator code
of the
associated
record.
LICQUAL
Number of
2 N
Ref k
A
2LANGAGE
personnel
required
possessing the
language
indicator code
of the
associated
record.
Table 60. SORTSREPAR Data Elements (Cont.)
S-42
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
MACOM
Acronym of the
6 AN
Ref k
A
ABIDE
reported unit's
major Army
command.
MAE
Mission
3 N
Ref k
A
READYSEG
accomplishment
estimate
percentage.
MOS
Military
5 AN
Ref k
A
2RQPER
occupational
specialty code
for the reported
data.
MSPER
Available MOS
1-3 N
Ref k
A
PERSDATA
trained
percentage of
personnel.
MTOE
Mobilization
10 AN
Ref k
A
READYSEG
table of
equipment or
the TDA
number for the
unit.
NRDY
NATO
1 A
Ref k
A
ABIDE
readiness code
for the reported
unit.
OBFC
Code for force
2 AN
Ref k
A
UNIT
objective.
ODATE
Effective date
6 N
Ref k
A
ABIDE
of the
organization's
status change.
OESTS
Code indicating
1 A
Ref k
A
ABIDE
the current
status of the
reported unit.
PACING
Pacing item
1 A
Ref k
A
ABIDE
unit indicator
code for the
reported unit.
PCTBEDDP
Percentage of
3 N
Ref k
A
READYSEG
operational
beds
deployable.
Table 60. SORTSREPAR Data Elements (Cont.)
S-43
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
PERRY
Percentage of
1-3 N
Ref k
A
EQMCRDAT
on-hand
equipment
mission
capable.
PIEMC
Percentage of
1-3 N
Ref k
A
EQMCRDAT
on-hand
pacing items
mission
capable.
PIRAT
C-level for the
1 N
Ref k
A
EQOHDATA
lowest pacing
item.
PPA
Code
2 AN
Ref k
A
ABIDE
identifying the
automatic data
processing
activity
operating USA
Personnel
Information
System for the
reported unit.
PROAVAL
Number of
3 N
Ref k
A
PROFIS
professional
officer fillers
available.
PROFREQ
Number of
3 N
Ref k
A
PROFIS
professional
officer fillers
required.
PUID
Code for the
1 N
Ref k
A
ARMYRPT
reported unit's
parent unit
QTYAUTH
Quantity
3 N
Ref k
A
2EOHSHRT
authorized for
this item.
QTYOH
Quantity of the
3 N
Ref k
A
2EOHSHRT
equipment
item on-hand.
QTYREQ
Quantity of the
3 N
Ref k
A
2EOHSHRT
equipment
item required.
Table 60. SORTSREPAR Data Elements (Cont.)
S-44
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
RAFF
UIC of the
6 AN
Ref k
A
ABIDE
regiment with
which the
reported unit is
affiliated.
REQ
Required
5 N
Ref k
A
2PSPER,
strength for
2RQPER,
this data.
2ADDSKILL
ROBCO
Requirement
4 AN
Ref k
A
ABIDE
objective code
for the reported
unit.
RUEOH
Roundout unit
1 AN
Ref k
A
ROUNDOUT
equipment on
hand level
code.
RUER
Roundout unit
1 AN
Ref k
A
ROUNDOUT
equipment
condition
category level
code.
RUNAME
Name of the
12 AN
Ref k
A
ROUNDOUT
roundout unit.
RUOVAL
Roundout unit
1 AN
Ref k
A
ROUNDOUT
overall C-level
code.
RUPER
Roundout unit
1 AN
Ref k
A
ROUNDOUT
personnel
category level
code.
RUTR
Roundout unit
1 AN
Ref k
A
ROUNDOUT
training
category level
code.
SBRPT2
UIC of U.S.
6 AN
Ref k
A
ABIDE
Army alternate
reporting
organization
designated by
the RPTOR to
submit
GSORTS
reports.
Table 60. SORTSREPAR Data Elements (Cont.)
S-45
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
SEQKEY
Assigned
4 N
Ref k
A
ABIDE
sequence sort
key number for
the USR for the
reported unit.
SGPER
Available
1-3 N
Ref k
A
PERSDATA
senior grade
percentage.
SRC
Standard
12 ANS
Ref k
A
ABIDE
requirement
code that is
integral to the
reported unit.
STATC
Personnel
2 AN
Ref k
A
ABIDE
status code
that classifies
the reported
unit.
TAADS
Code indicating
1 A
Ref k
A
ABIDE
the reported
unit is
supported by
an
authorization
document.
TAPFOR
Code indicating
4 AN
Ref k
A
ABIDE
USA reporting
installation
FORSTAT for
the reported
unit.
TPSNCD
Troop program
1 A
Ref k
A
ABIDE
sequence
number
identifier code
for the reported
unit.
Table 60. SORTSREPAR Data Elements (Cont.)
S-46
Enclosure S
CJCSM 3150.02B
25 March 2011
Label
Descriptor
Format
Reference
Source
Set
TWRC1
Number of
2 AN
Ref k
A
TRAINDAT
days required
to complete
training to
overcome
training
shortfall.
ZIP
ZIP code or
9 AN
Ref k
A
ABIDE
APO designator
for the reported
unit.
Table 60. SORTSREPAR Data Elements (Cont.)
S-47
Enclosure S
CJCSM 3150.02B
25 March 2011
(INTENTIONALLY BLANK)
S-48
Enclosure S
CJCSM 3150.02B
25 March 2011
ENCLOSURE T
REFERENCES
a. DOD Manual 8910.1-M, 30 June 1998, “DOD Procedures for Management
of Information Requirements”
b. Title 10 United States Code
c. CJCSI 3401.02 Series, “Force Readiness Reporting”
d. Global Command and Control, User Review Panel Charter, 26 February
1998
e. CJCSI 5714.01 Series, “Policy for the Release of Joint Information”
f. DOD Manual 5000.12M, "Manual for Standard Data Elements”
g. AR 71-32, 3 March 1997, “Force Development and Documentation -
Consolidated Policies”
h. AR 25-70, 5 March 1998, “Troop Program Sequence Number”
i. Military Standard 6040, 5 July 1996,
“United States Message Text
Formatting (USMTF) Program”
j. AR 220-1 15 April 2010, “ Unit Status Reporting and Force Registration”
k. NTTP 1-03.3 (REV A), October 2003, “Status of Resources and Training
System”
l. AFI 10-201, 13 April 2006, “Status of Resources and Training System.”
m. DOD Directive 7730.65, 3 June 2002, “Department of Defense Readiness
Reporting System (DRRS)”
n. MCO P3000.13D, 17 Apr 2002, "Marine Corps Status of Resources and
Training System (SORTS) Standing Operating Procedures"
o. DODI 7730.65, 3 June 2002, “Department of Defense Readiness Reporting System
(DRRS)”
p. DOD Directive 5400.4, “Provision of Information to Congress”
T-1
Enclosure T
CJCSM 3150.02B
25 March 2011
(INTENTIONALLY BLANK)
T-2
Enclosure T
CJCSM 3150.02B
25 March 2011
GLOSSARY
PART I - ACRONYMS AND ABBREVIATIONS
ACGEO
Extended Active Duty Location
ACITY
Extended Active Duty Activity
ACTIV
Current Status and Activity Code
ADATE
Extended Active Duty Date
ADCON
administrative control
ADS
Authoritative Data Source
AFSC
Air Force Specialty Code
AFSORTSDET
USAF SORTS Data-Entry Tool
AMCC
Ashore Mobile Contingency Communications
AMPN
Amplification
ANAME
Abbreviated Organization Name field
APO
Army Post Office
ARRDT
Destination Arrival Date
ASGD
Assigned Strength
ASW
antisubmarine warfare
ATACH
Attached Command Unit Identification Code
AUTH
Authorized Strength
BIDE
basic identity data element
C2
command and control
C4I
command, control, communications, computers and
intelligence
C-level
category level
CADAT
Forecasted Date of Change
CARAT
Forecasted Category Level Change
CATLIMIT
Category Level Limitation
CBCOM
Combined Command Code
CBD
Chemical, Biological Defense
CBDRT
chemical, biological, radiological, and nuclear defense
readiness training
COAFF
Country or International Affiliation Field
COCOM
combatant command (command authority)
CONPLAN
operation plan in concept format
COSAL
consolidated shipboard allowance list
CREAL
Primary Duty Crew Allocated
CREWA
Primary Duty Crews Authorized
CREWF
Primary Duty Crews - Formed
CRMRC
Primary Duty Crews Mission-Ready - Conventional
CRMRD
Primary Duty Crews Mission-Ready - Dual
CRMRN
Primary Duty Crews Mission-Ready -Nuclear
GL-1
Glossary
CJCSM 3150.02B
25 March 2011
CRMRO
Primary Duty Crews Mission-Ready - Other
CRO
Command Reporting Organization
CS
combat support
CSA
combat support agency
CSERV
combatant command or Service command code
CSS
combat service support
CXMRS
Checked-Out of the Movement Reporting System
DECL
Downgrade and Declassification
DEPS
Deployable Strength
DETA
Estimated Time of Arrival at Destination
DEFCON
Defense Readiness Condition
DEPDT
Origin Departure Date
DEPLOY
Deployment Status
DFCON
Defense Condition
DISA
Defense Information Systems Agency
DMDC
Defense Manpower Data Center
DOD
Department of Defense
DRRS
Defense Readiness Reporting System
DTG
Date-Time Group
EAD
extended active duty
EMBRK
Organization Embarked
EQCONDN
Equipment Condition Level
EQSUPPLY
Equipment and Supplies-on-Hand Level (set)
ERRAT
Measured Resource Area Level for Equipment Condition
ERRES
Primary Reason R-Level not R-1
ESORTS
Enhanced Status of Resources and Training System
ESRAT
Equipment and Supplies-on-Hand
ESRES
Primary Reason S-Level Not S-1
EXER
Exercise Identifier
FLAG
Organic Unit Established
FORDV
Equipment Foreign Origin
FORECAST
Forecasted Category Level
FTP
file transfer protocol
GAINING
Gaining Command
GCCS-J
Global Command and Control System - Joint
GCCS-M
Global Command and Control System - Maritime
GCC RWG
Global Command and Control Readiness Working Group
GCMD
Gaining Command
GEOFILE
geolocation code file
GEOLOC
geographic location code
GENTEXT
General Text
GL-2
Glossary
CJCSM 3150.02B
25 March 2011
GMT
Greenwich Mean Time
GSORTS
Global Status of Resources and Training System
HOGEO
Home Location Code
HQDA
Headquarters, Department of the Army
HQMC
Headquarters, U.S. Marine Corps
IAW
in accordance with
IFF
identification, friend or foe
IMA
individual mobilization augmentee
IMRL
Individual material readiness list
INT
Intermediate Command
INTR
Interested Command
JOPES
Joint Operation Planning and Execution System
LABEL
Data Element Label
LIM
Category Level Limitation
LNAME
Organization Long Name
LOSING
Losing Organization set
MAGTF
Marine Air-Ground Task Force
MAJOR
Major Unit Indicator field
MAW
Marine air wing
MBCMD
Mobilization Command
MDATE
Scheduled Mobilization Day
MEB
Marine Expeditionary Brigade
MECAP
Major Equipment Capability Indicator Code
MECL
Major Equipment Functional Classification Code
MEE
Mission Essential Equipment
MEF
Marine Expeditionary Force
MENAM
major equipment name
MEORC
Major Equipment Operationally Ready - Conventional
MEORD
Major Equipment Operationally Ready - Dual
MEORN
Major Equipment Operationally Ready - Nuclear
MEORO
Major Equipment Operationally Ready - Other
MEPSA
Major Equipment Authorized
MEPSD
Major Equipment Possessed
MEQLOCN
Major Equipment and Crew Status
MEQPT
Major Equipment Identification
MEREC
Major Equipment - - Reconnaissance Capability
MEREP
Major Equipment Identification Report
METAL
Major Equipment Allocated
MEU
Marine expeditionary unit
MHG
MEF Headquarters Group
GL-3
Glossary
CJCSM 3150.02B
25 March 2011
MJCOM
Major Command Code
MLG
Marine Logistics Group
MODFG
Modified Location Flag
MODLOC
modified location
MONOR
Monitoring Organization Code
MSC
Military Sealift Command
MSC
Major Subordinate Command
MSGID
Message Identifier
NARR
Narrative
NATO
North Atlantic Treaty Organization
NBC
Naval Boat Command
NDEST
Naval Destination
NEC
Navy enlisted classification
NETUSR-MC
Marine Corps input tool for DRRS-MC
NEWLOC
New Location
NEWTREAD
New Type Report
NMCC
National Military Command Center
NMP
Naval management program
NORAD
North American Aerospace Defense Command
NTASK
Navy Task Organization Number
NUCIN
Nuclear Capability Indicator
OPCON
operational control
OPER
Operation Identifier
OPLAN
operation plan
OPTAR
operating target
ORGLOCN
organization and location
OSD
Office of the Secretary of Defense
OVERALL
Overall C-level
OVRRD
Override Sequence Number
P-level
personnel level
PC-ASORTS
Personal Computer-Army SORTS
PCS
permanent change of station
PCTEF
percent effective
PEGEO
personnel geographic location code
PEI
Principal End Items
PERSONEL
Personnel Level (set)
PERSTREN
Personnel Strength
PICDA
Date of Change of Personnel Information
PLETD
Estimated Time of Departure From Present Location
PMA
primary mission area
POINT
Geographic Coordinates
POSTR
Possessed Strength
GL-4
Glossary
CJCSM 3150.02B
25 March 2011
PRRAT
Measured Area Level for Personnel
PRRES
Primary Reason P-Level Not P-1
PRGEO
Present Location Code
PSA
post shakedown availability
PSYOP
psychological operations
PUIC
Parent Organization's Unit Identifier Code
R-level
equipment condition level
RAS-IT
Readiness Assessment System Input Tool
RAS-OT
Readiness Assessment System Output Tool
RDATE
Release Date From Extended Active Duty
READY
Current Overall Category Level
REASN
Primary Reason Unit Is Not C-1
RECON
reconnaissance
REVAL
Registration Validity field
RICDA
date of change of category information
RLIM
Reason for Category Level Limitation
ROH
regular overhaul
RPTDUIC
Reported Unit Identification
RPTNORG
Reporting Organization
RPTOR
reporting organization field in RPTNORG set
S-level
equipment and supplies-on-hand level
SAR
search and rescue
SBRPT
Subordinate Reporting Organization
SCLAS
Security Classification of the Entire Report
SDLM
scheduled depot level maintenance
SECRN
Secondary Reason Organization Not C-1
SECFOR
Security Force
SEQNO
Sequence Number of Report
SHIPLOCN
Ship Location
SIF
selective identification feature
SIMA
ship intermediate maintenance availability
SIOP
Single Integrated Operational Plan
SIPRNET
Secret Internet Protocol Routing Network
SORTS
Status of Resources and Training System
SORTSREP
GSORTS Report
SORTSREPAF
GSORTS Report (USAF)
SORTSREPAR
GSORTS Report (USA)
SORTSREPNV
GSORTS Report (USN)
SORTUNIT
Originator Identification
SRA
selected restrained availability
SSBN
fleet ballistic missile submarine
SSN
attack submarine; nuclear
STRUC
Structured Strength
GL-5
Glossary
CJCSM 3150.02B
25 March 2011
T-level
training level
TAD
Temporary Additional Duty
TASS
Tactical Automated Switch System
TARGT
Targeted Command Unit Identification Code
TDA
Table of Distributions and Allowances
TDATE
Effective Date of Transfer
TDEPS
Tasked Deployable Strength
TDY
temporary duty
T/E
Table of Equipment
TEGEO
temporary location code
TERRN
Tertiary Reason Organization Not C-1
T/O
Table of Organization
TPERS
Type of Personnel
TPSN
Troop Program Sequence Number
TRAINING
Training Level
TRANSFER
Unit Transfer set
TREAD
Type of Report
TRGEO
Destination Location
TRMS
Type Commanders’ Readiness Management System
TRRAT
Measured Resource Area Level for Training field
TRRES
Primary Reason T-Level Not T-1
UDC
Unit Descriptor Code
UIC
Unit Identification Code
ULC
Unit Level Code
URP
User Review Panel
USA
United States Army
USAF
United States Air Force
USCG
United States Coast Guard
USELMNORAD
U.S. Element, North American Aerospace Defense Command
USER
User/Monitor Indicator
USMC
United States Marine Corps
USMTF
United States Message Text Format
USN
United States Navy
USR
Unit Status Report
USSOCOM
United States Special Operations Command
UTC
Unit Type Code
UTR
Unit T/E Requirement
VALID
Validation Transaction
YNSK
Yeoman Storekeeper
GL-6
Glossary
CJCSM 3150.02B
25 March 2011
PART II - TERMS AND DEFINITIONS
See CJCSI 3401.02, “Force Readiness Reporting” for a full list of terms and
definitions.
attachment. 1) The placement of units or personnel in an organization where
such placement is relatively temporary. 2) The detailing of individuals to
specific functions where such functions are secondary or relatively temporary;
e.g., attached for quarters and rations; attached for flying duty.
composite report. A report submitted by a major unit providing an overall
assessment based on condition of subordinate measured units and their ability
to operate together.
detachment. 1) A part of a unit separated from its main organization for duty
elsewhere.
2) A temporary military or naval unit formed from other units or
parts of units.
end-item. A final combination of end products, component parts and/or
materials that is ready for its intended use; e.g., ship, tank, mobile machine
shop, aircraft.
fully mission capable. Material condition of an aircraft or training device
indicating that it can perform all of its missions.
intermediate command report. A report submitted by a Marine Corps major
command providing an overall assessment based on subordinate units
assigned.
modified location (MODLOC). Modified unit location in an established fleet
operating area or a circle not to exceed 100 nautical miles for a specified
latitude and longitude. MODLOC is restricted to at-sea operations and must
be terminated prior to entry into port.
provisional unit. A Service- or combatant command-directed temporary
assembly of personnel and equipment organized for a limited period of time for
accomplishment of a specific mission.
SORTSREP. A unit Global Status of Resources and Training System Report
submitted by a USMC, foreign or joint unit.
SORTSREPAF. A unit Global Status of Resources and Training System Report
submitted by a USAF unit.
GL-7
Glossary
CJCSM 3150.02B
25 March 2011
SORTSREPAR. A unit Global Status of Resources and Training System Report
submitted by a USA unit.
SORTSREPNV. A unit Global Status of Resources and Training System Report
submitted by a USN or USCG unit.
Wartime Table of Organization. The Service or joint manpower document
specifying the personnel requirements
GL-8
Glossary
Searching and
Seizing Computers
and Obtaining
Electronic Evidence
H. Marshall Jarrett
in Criminal
Director, EOUSA
Investigations
Michael W. Bailie
Director, OLE
Computer Crime and
Intellectual Property Section
Criminal Division
OLE
Litigation
Series
Ed Hagen
Assistant Director,
OLE
Nathan Judish
Published by
Computer Crime
Office of Legal Education
and Intellectual
Executive Office for
Property Section
United States Attorneys
Te Office of Legal Education intends that this book be used by
Federal prosecutors for training and law enforcement purposes
and makes no public release of it. Individuals receiving the book
in training are reminded to treat it confidentially.
Te contents of this book provide internal suggestions to
Department of Justice attorneys. Nothing in it is intended to
create any substantive or procedural rights, privileges, or benefits
enforceable in any administrative, civil, or criminal matter by
any prospective or actual witnesses or parties. See United States v.
Caceres, 440 U.S. 741 (1979).
Table of Contents
Preface and Acknowledgements
vii
Introduction
ix
Chapter 1. Searching and Seizing Computers
Without a Warrant
1
A.
Introduction
1
B.
Te Fourth Amendment’s “Reasonable Expectation of Privacy”
in Cases Involving Computers
2
1. General Principles
2
2. Reasonable Expectation of Privacy in Computers
as Storage Devices
2
3. Reasonable Expectation of Privacy and Tird-Party Possession
6
4. Private Searches
10
5. Use of Specialized Technology to Obtain Information
14
C.
Exceptions to the Warrant Requirement in Cases
Involving Computers
15
1. Consent
15
2. Exigent Circumstances
27
3. Search Incident to a Lawful Arrest
31
4. Plain View
34
5. Inventory Searches
37
6. Border Searches
38
7. Probation and Parole
40
D. Special Case: Workplace Searches
42
1. Private-Sector Workplace Searches
42
2. Public-Sector Workplace Searches
45
E.
International Issues
56
Chapter 2. Searching and Seizing Computers
With a Warrant
61
A. Introduction
61
B. Devising a Search Strategy
61
C. Drafting the Affidavit, Application, and Warrant
63
1. Include Facts Establishing Probable Cause
63
2. Describe With Particularity the Tings to be Seized
69
iii
3. Establishing the Necessity for Imaging and
Off-Site Examination
76
4. Do Not Place Limitations on the Forensic Techniques
Tat May Be Used To Search
79
5. Seeking Authorization for Delayed Notification Search Warrants
83
6. Multiple Warrants in Network Searches
84
D. Forensic Analysis
86
1. Te Two-Stage Search
86
2. Searching Among Commingled Records
87
3. Analysis Using Forensic Software
89
4. Changes of Focus and the Need for New Warrants
90
5. Permissible Time Period for Examining Seized Media
91
6. Contents of Rule 41(f ) Inventory Filed With the Court
95
E.
Challenges to the Search Process
96
1. Challenges Based on “Flagrant Disregard”
96
2. Motions for Return of Property
98
F.
Legal Limitations on the Use of Search Warrants
to Search Computers
100
1. Journalists and Authors: the Privacy Protection Act
101
2. Privileged Documents
109
3. Other Disinterested Tird Parties
111
4. Communications Service Providers: the SCA
112
Chapter 3. The Stored Communications Act
115
A. Introduction
115
B. Providers of Electronic Communication Service vs.
Remote Computing Service
117
1. Electronic Communication Service
117
2. Remote Computing Service
119
C. Classifying Types of Information Held by Service Providers
120
1. Basic Subscriber and Session Information Listed
in 18 U.S.C. § 2703(c)(2)
121
2. Records or Other Information Pertaining
to a Customer or Subscriber
122
3. Contents and “Electronic Storage”
122
4. Illustration of the SCA’s Classifications in the Email Context
125
D. Compelled Disclosure Under the SCA
127
1. Subpoena
128
iv
Searching and Seizing Computers
2. Subpoena with Prior Notice to the Subscriber or Customer
129
3. Section 2703(d) Order
130
4.
2703(d) Order with Prior Notice to the Subscriber or Customer...132
5. Search Warrant
133
E.
Voluntary Disclosure
135
F.
Quick Reference Guide
138
G.
Working with Network Providers: Preservation of Evidence,
Preventing Disclosure to Subjects, Cable Act Issues,
and Reimbursement
139
1. Preservation of Evidence under 18 U.S.C. § 2703(f )
139
2. Orders Not to Disclose the Existence of a Warrant,
Subpoena, or Court Order
140
3. Te Cable Act, 47 U.S.C. § 551
141
4. Reimbursement
142
H. Constitutional Considerations
144
I.
Remedies
147
1. Suppression
147
2. Civil Actions and Disclosures
148
Chapter 4. Electronic Surveillance in Communications
Networks
151
A. Introduction
151
B. Content vs. Addressing Information
151
C. Te Pen/Trap Statute, 18 U.S.C. §§ 3121-3127
153
1. Definition of Pen Register and Trap and Trace Device
153
2. Pen/Trap Orders: Application, Issuance, Service, and Reporting
154
3. Emergency Pen/Traps
158
4. Te Pen/Trap Statute and Cell-Site Information
159
D. Te Wiretap Statute (“Title III”), 18 U.S.C. §§ 2510-2522
161
1. Introduction: Te General Prohibition
161
2. Key Phrases
162
3. Exceptions to Title III’s Prohibition
167
E. Remedies For Violations of Title III and the Pen/Trap Statute
183
1. Suppression Remedies
183
2. Defenses to Civil and Criminal Actions
188
Contents
v
Chapter 5. Evidence
191
A. Introduction
191
B. Hearsay
191
1. Hearsay vs. Non-Hearsay Computer Records
192
2. Confrontation Clause
196
C. Authentication
197
1. Authentication of Computer-Stored Records
198
2. Authentication of Records Created by a Computer Process
200
3. Common Challenges to Authenticity
202
D. Other Issues
205
1. Te Best Evidence Rule
205
2. Computer Printouts as “Summaries”
207
Appendices
A. Sample Network Banner Language
209
B. Sample 18 U.S.C. § 2703(d) Application and Order
213
C. Sample Language for Preservation Requests
under 18 U.S.C. § 2703(f )
225
D. Sample Pen Register/Trap and Trace Application and Order
227
E. Sample Subpoena Language
239
F. Sample Premises Computer Search Warrant Affidavit
241
G. Sample Letter for Provider Monitoring
251
H. Sample Authorization for Monitoring of Computer
Trespasser Activity
253
I. Sample Email Account Search Warrant Affidavit
255
J. Sample Consent Form for Computer Search
263
Table of Cases
265
Index
281
vi
Searching and Seizing Computers
Preface and
Acknowledgements
Tis publication (the Manual) is the third edition of “Searching and Seizing
Computers and Obtaining Electronic Evidence in Criminal Investigations” and
updates the previous version published in September 2002. During this seven-
year period, case law related to electronic evidence has developed significantly.
Of particular note has been the development of topics such as the procedures for
warrants used to search and seize computers, the procedures for obtaining cell
phone location information, and the procedures for the compelled disclosure
of the content of electronic communications. In addition, as possession of
electronic devices has become the norm, courts have had the opportunity in a
large number of cases to address questions such as the application of the search
incident to arrest doctrine to electronic devices.
Nathan Judish took primary responsibility for the revisions in this Manual,
under the supervision of Richard Downing. Tim O’Shea and Jared Strauss
took responsibility for revising Chapters 1 and 5, Josh Goldfoot for revising
Chapter 2, Michelle Kane for revising Chapter 3, and Jenny Ellickson for
revising Chapter 4. Scott Eltringham provided critical support to the editing
and publishing of this Manual. Further assistance was provided by
(in
alphabetical order): Mysti Degani, Michael DuBose, Mark Eckenwiler, John
Lynch, Jaikumar Ramaswamy, Betty Shave, Joe Springsteen, and Mick Stawasz.
Tis edition continues to owe a debt to Orin S. Kerr, principal author of the
2001 edition. Te editors would also like to thank the members of the CHIP
working group.
Tis manual is intended as assistance, not authority. Te research, analysis,
and conclusions herein reflect current thinking on difficult and dynamic areas
of the law; they do not represent the official position of the Department of
Justice or any other agency. Tis manual has no regulatory effect, confers no
rights or remedies, and does not have the force of law or a U.S. Department of
Justice directive. See United States v. Caceres, 440 U.S. 741 (1979).
Electronic copies of this document are available from the Computer
Crime and Intellectual Property Section’s website, www.cybercrime.gov. Te
electronic version will be periodically updated, and prosecutors and agents are
advised to check the website’s version for the latest developments. Inquiries,
vii
comments, and corrections should be directed to Nathan Judish at (202) 514-
1026. Requests for paper copies or written correspondence may be honored
only when made by law enforcement officials or by public institutions. Such
requests should be sent to the following address:
Attn: Search and Seizure Manual
Computer Crime and Intellectual Property Section
10th & Constitution Ave., NW
John C. Keeney Bldg., Suite 600
Washington, DC 20530
viii
Searching and Seizing Computers
Introduction
Computers and the Internet have entered the mainstream of American
life. Millions of Americans spend hours every day using computers and mobile
devices to send and receive email, surf the Internet, maintain databases, and
participate in countless other activities.
Unfortunately, those who commit crimes have not missed the information
revolution. Criminals use mobile phones, laptop computers, and network
servers in the course of committing their crimes. In some cases, computers
provide the means of committing crime. For example, the Internet can be used
to deliver a death threat via email; to launch hacker attacks against a vulnerable
computer network, to disseminate computer viruses, or to transmit images
of child pornography. In other cases, computers merely serve as convenient
storage devices for evidence of crime. For example, a drug dealer might keep a
list of who owes him money in a file stored in his desktop computer at home,
or a money laundering operation might retain false financial records in a file on
a network server. Indeed, virtually every class of crime can involve some form
of digital evidence.
Te dramatic increase in computer-related crime requires prosecutors and
law enforcement agents to understand how to obtain electronic evidence stored
in computers. Electronic records such as computer network logs, email, word
processing files, and image files increasingly provide the government with
important (and sometimes essential) evidence in criminal cases. Te purpose of
this publication is to provide Federal law enforcement agents and prosecutors
with systematic guidance that can help them understand the legal issues that
arise when they seek electronic evidence in criminal investigations.
Te law governing electronic evidence in criminal investigations has two
primary sources: the Fourth Amendment to the U.S. Constitution, and the
statutory privacy laws codified at 18 U.S.C. §§ 2510-22, 18 U.S.C. §§ 2701-
12, and 18 U.S.C. §§ 3121-27. Although constitutional and statutory issues
overlap in some cases, most situations present either a constitutional issue under
the Fourth Amendment or a statutory issue under these three statutes. Tis
manual reflects that division: Chapters 1 and 2 address the Fourth Amendment
law of search and seizure, and Chapters 3 and 4 focus on the statutory issues,
which arise mostly in cases involving computer networks and the Internet.
ix
Chapter 1 explains the restrictions that the Fourth Amendment places
on the warrantless search and seizure of computers and computer data. Te
chapter begins by explaining how the courts apply the “reasonable expectation
of privacy” test to computers, turns next to how the exceptions to the warrant
requirement apply in cases involving computers, and concludes with a
comprehensive discussion of the difficult Fourth Amendment issues raised
by warrantless workplace searches of computers. Questions addressed in this
chapter include: When does the government need a search warrant to search
and seize a suspect’s computer? Can an investigator search without a warrant
through a suspect’s mobile phone seized incident to arrest? Does the government
need a warrant to search a government employee’s desktop computer located in
the employee’s office?
Chapter 2 discusses the law that governs the search and seizure of computers
pursuant to search warrants. Te chapter begins by briefly addressing the
different roles computers can play in criminal offenses and the goals investigators
and prosecutors should keep in mind when drafting search warrants. It then
addresses issues that arise in drafting search warrants, in the forensic analysis
of computers seized pursuant to warrants, and in post-seizure challenges to
the search process. Finally, it addresses special limitations on the use of search
warrants to search computers, such as the limitations imposed by the Privacy
Protection Act, 42 U.S.C. § 2000aa. Questions addressed in the chapter include:
How should prosecutors draft search warrant language so that it complies with
the particularity requirement of the Fourth Amendment and Rule 41 of the
Federal Rules of Criminal Procedure? What are the time requirements for
the review of computers seized pursuant to a search warrant? What is the law
governing when the government must search and return seized computers?
Te focus of Chapter 31 is the Stored Communications Act, 18 U.S.C. §§
2701-12 (“SCA”). Te SCA governs how investigators can obtain stored account
records and contents from network service providers, including Internet service
providers (“ISPs”), telephone companies, and cell phone service providers. SCA
issues arise often in cases involving the Internet: when investigators seek stored
information concerning Internet accounts from providers of Internet service,
1 In previous versions of this Manual, the SCA was referred to as the Electronic
Communications Privacy Act. Te SCA was included as Title II of the Electronic
Communications Privacy Act of 1986 (“ECPA”), but ECPA itself also included amendments
to the Wiretap Act and created the Pen Register and Trap and Trace Devices statute addressed
in Chapter 4. See Pub. L. No. 99-508, 100 Stat. 1848 (1986). In this Manual, “the SCA” will
refer to 18 U.S.C. §§ 2701-12, and “ECPA” will refer to the 1986 statute.
x
Searching and Seizing Computers
they must comply with the statute. Topics covered in this section include: How
can the government obtain email and account logs from ISPs? When does
the government need to obtain a search warrant, as opposed to an 18 U.S.C.
§ 2703(d) order or a subpoena? When can providers disclose email and records
to the government voluntarily? What remedies will courts impose when the
SCA has been violated?
Chapter 4 reviews the legal framework that governs electronic surveillance,
with particular emphasis on how the statutes apply to surveillance on
communications networks. In particular, the chapter discusses the Wiretap
Act, 18 U.S.C. §§ 2510-22 (referred to here as “Title III”), as well as the
Pen Register and Trap and Trace Devices statute, 18 U.S.C. §§ 3121-27.
Tese statutes govern when and how the government can conduct real-time
surveillance, such as monitoring a computer hacker’s activity as he breaks into
a government computer network. Topics addressed in this chapter include:
When can victims of computer crime monitor unauthorized intrusions into
their networks and disclose that information to law enforcement? Can network
“banners” generate consent to monitoring? How can the government obtain a
pen register/trap and trace order that permits the government to collect packet
header information from Internet communications? What remedies will courts
impose when the electronic surveillance statutes have been violated?
Of course, the issues discussed in Chapters 1 through 4 can overlap in
actual cases. An investigation into computer hacking may begin with obtaining
stored records from an ISP according to Chapter 3, move next to an electronic
surveillance phase implicating Chapter 4, and then conclude with a search of
the suspect’s residence and a seizure of his computers according to Chapters 1
and 2. In other cases, agents and prosecutors must understand issues raised in
multiple chapters not just in the same case, but at the same time. For example,
an investigation into workplace misconduct by a government employee may
implicate all of Chapters 1 through 4. Investigators may want to obtain the
employee’s email from the government network server (implicating the SCA,
discussed in Chapter 3); may wish to monitor the employee’s use of the
telephone or Internet in real-time (raising surveillance issues from Chapter 4);
and may need to search the employee’s desktop computer in his office for clues
of the misconduct (raising search and seizure issues from Chapters 1 and 2).
Because the constitutional and statutory regimes can overlap in certain cases,
agents and prosecutors will need to understand not only all of the legal issues
covered in Chapters 1 through 4, but will also need to understand the precise
nature of the information to be gathered in their particular cases.
Introduction
xi
Chapters 1 through 4 are followed by Chapter 5, which discusses evidentiary
issues that arise frequently in computer-related cases. Prosecutors should always
be concerned with admissibility issues that may arise in court proceedings.
Chapter 5 addresses both hearsay and Confrontation Clause issues associated
with computer records. It then discusses authentication of computer-stored
records and records created by computer processes, including common
challenges to authenticity, such as claims that computer records have been
tampered with. It also discusses the best evidence rule and the use of summaries
containing electronic evidence. Questions addressed in this chapter include:
When are computer-generated records not hearsay? How can the contents of
a website be authenticated? Tis Manual then concludes with appendices that
offer sample forms, letters, and orders.
Computer crime investigations raise many novel issues. Agents and
prosecutors who need more detailed advice can rely on several resources for
further assistance. At the federal district level, every United States Attorney’s
Office has at least one Assistant United States Attorney who has been
designated as a Computer Hacking and Intellectual Property
(“CHIP”)
attorney. Every CHIP attorney receives extensive training in computer crime
issues and is primarily responsible for providing expertise relating to the topics
covered in this manual within his or her district. CHIPs may be reached in
their district offices. Further, several sections within the Criminal Division of
the United States Department of Justice in Washington, D.C., have expertise
in computer-related fields. Te Office of International Affairs ((202) 514-
0000) provides expertise in the many computer crime investigations that raise
international issues. Te Office of Enforcement Operations ((202) 514-6809)
provides expertise in the wiretapping laws and other privacy statutes discussed
in Chapters 3 and 4. Also, the Child Exploitation and Obscenity Section
((202) 514-5780) provides expertise in computer-related cases involving child
pornography and child exploitation.
Finally, agents and prosecutors are always welcome to contact the
Computer Crime and Intellectual Property Section (“CCIPS”) directly both
for general advice and specific case-related assistance. During regular business
hours, a CCIPS attorney is on duty to answer questions and provide assistance
to agents and prosecutors on the topics covered in this document, as well as
other matters that arise in computer crime cases. Te main number for CCIPS
is
(202) 514-1026. After hours, CCIPS can be reached through the Justice
Command Center at (202) 514-5000.
xii
Searching and Seizing Computers
Chapter 1
Searching and Seizing
Computers Without a Warrant
A. Introduction
Te Fourth Amendment limits the ability of government agents to search for
and seize evidence without a warrant. Tis chapter explains the constitutional
limits of warrantless searches and seizures in cases involving computers.
Te Fourth Amendment states:
Te right of the people to be secure in their persons, houses,
papers, and effects, against unreasonable searches and seizures,
shall not be violated, and no Warrants shall issue, but upon
probable cause, supported by Oath or affirmation, and
particularly describing the place to be searched, and the persons
or things to be seized.
According to the Supreme Court, a “‘seizure’ of property occurs when there
is some meaningful interference with an individual’s possessory interests in
that property,” United States v. Jacobsen, 466 U.S. 109, 113 (1984), and the
Court has also characterized the interception of intangible communications as
a seizure. See Berger v. New York, 388 U.S. 41, 59-60 (1967). Furthermore, the
Court has held that a “‘search’ occurs when an expectation of privacy that society
is prepared to consider reasonable is infringed.” Jacobsen, 466 U.S. at 113. If
the government’s conduct does not violate a person’s “reasonable expectation
of privacy,” then formally it does not constitute a Fourth Amendment “search”
and no warrant is required. See Illinois v. Andreas, 463 U.S. 765, 771 (1983).
In addition, a warrantless search that violates a person’s reasonable expectation
of privacy will nonetheless be constitutional if it falls within an established
exception to the warrant requirement. See Illinois v. Rodriguez, 497 U.S. 177,
185-86 (1990). Accordingly, investigators must consider two issues when
asking whether a government search of a computer requires a warrant. First,
does the search violate a reasonable expectation of privacy? And if so, is the
search nonetheless permissible because it falls within an exception to the
warrant requirement?
B. Te Fourth Amendment’s “Reasonable Expectation
of Privacy” in Cases Involving Computers
1. General Principles
A search is constitutional if it does not violate a person’s “reasonable” or
“legitimate” expectation of privacy. Katz v. United States, 389 U.S. 347, 361
(1967) (Harlan, J., concurring). Tis inquiry embraces two discrete questions:
first, whether the individual’s conduct reflects “an actual (subjective) expectation
of privacy,” and second, whether the individual’s subjective expectation of
privacy is “one that society is prepared to recognize as ‘reasonable.’” Id. at 361.
In most cases, the difficulty of contesting a defendant’s subjective expectation
of privacy focuses the analysis on the objective aspect of the Katz test, i.e.,
whether the individual’s expectation of privacy was reasonable.
No bright line rule indicates whether an expectation of privacy is
constitutionally reasonable. See O’Connor v. Ortega, 480 U.S. 709, 715 (1987).
For example, the Supreme Court has held that a person has a reasonable
expectation of privacy in property located inside a person’s home, see Payton
v. New York, 445 U.S. 573, 589-90 (1980); in “the relative heat of various
rooms in the home” revealed through the use of a thermal imager, see Kyllo v.
United States, 533 U.S. 27, 34-35 (2001); in conversations taking place in an
enclosed phone booth, see Katz, 389 U.S. at 352; and in the contents of opaque
containers, see United States v. Ross, 456 U.S. 798, 822-23 (1982). In contrast, a
person does not have a reasonable expectation of privacy in activities conducted
in open fields, see Oliver v. United States, 466 U.S. 170, 177 (1984); in garbage
deposited at the outskirts of real property, see California v. Greenwood, 486
U.S. 35, 40-41 (1988); or in a stranger’s house that the person has entered
without the owner’s consent in order to commit a theft, see Rakas v. Illinois,
439 U.S. 128, 143 n.12 (1978).
2. Reasonable Expectation of Privacy in Computers
as Storage Devices
To determine whether an individual has a reasonable
expectation of privacy in information stored in a computer,
Searching and Seizing Computers
it helps to treat the computer like a closed container such as
a briefcase or file cabinet. The Fourth Amendment generally
prohibits law enforcement from accessing and viewing
information stored in a computer if it would be prohibited
from opening a closed container and examining its contents in
the same situation.
Te most basic Fourth Amendment question in computer cases asks
whether an individual enjoys a reasonable expectation of privacy in electronic
information stored within computers (or other electronic storage devices)
under the individual’s control. For example, do individuals have a reasonable
expectation of privacy in the contents of their laptop computers, USB drives,
or cell phones? If the answer is “yes,” then the government ordinarily must
obtain a warrant, or fall within an exception to the warrant requirement, before
it accesses the information stored inside.
When confronted with this issue, courts have analogized the expectation
of privacy in a computer to the expectation of privacy in closed containers
such as suitcases, footlockers, or briefcases. Because individuals generally retain
a reasonable expectation of privacy in the contents of closed containers, see
United States v. Ross, 456 U.S. 798, 822-23 (1982), they also generally retain
a reasonable expectation of privacy in data held within electronic storage
devices. Accordingly, accessing information stored in a computer ordinarily
will implicate the owner’s reasonable expectation of privacy in the information.
See United States v. Heckenkamp, 482 F.3d 1142, 1146 (9th Cir. 2007) (finding
reasonable expectation of privacy in a personal computer); United States v.
Buckner, 473 F.3d 551, 554 n.2 (4th Cir. 2007) (same); United States v. Lifshitz,
369 F.3d 173, 190 (2d Cir. 2004) (“Individuals generally possess a reasonable
expectation of privacy in their home computers.”); Trulock v. Freeh, 275 F.3d
391, 403 (4th Cir. 2001); United States v. Al-Marri, 230 F. Supp. 2d 535, 541
(S.D.N.Y. 2002) (“Courts have uniformly agreed that computers should be
treated as if they were closed containers.”); United States v. Reyes, 922 F. Supp.
818, 832-33 (S.D.N.Y. 1996) (finding reasonable expectation of privacy in
data stored in a pager); United States v. Lynch, 908 F. Supp. 284, 287 (D.V.I.
1995) (same); United States v. Chan, 830 F. Supp. 531, 535 (N.D. Cal. 1993)
(same); see also United States v. Andrus, 483 F.3d 711, 718 (10th Cir. 2007) (“A
personal computer is often a repository for private information the computer’s
1. Without a Warrant
owner does not intend to share with others. For most people, their computers
are their most private spaces.” (internal quotation omitted)).1
Although courts have generally agreed that electronic storage devices can be
analogized to closed containers, they have reached differing conclusions about
whether a computer or other storage device should be classified as a single closed
container or whether each individual file stored within a computer or storage
device should be treated as a separate closed container. In two cases, the Fifth
Circuit determined that a computer disk containing multiple files is a single
container for Fourth Amendment purposes. First, in United States v. Runyan,
275 F.3d 449, 464-65 (5th Cir. 2001), in which private parties had searched
certain files and found child pornography, the Fifth Circuit held that the police
did not exceed the scope of the private search when they examined additional
files on any disk that had been, in part, privately searched. Analogizing a disk
to a closed container, the court explained that “police do not exceed the private
search when they examine more items within a closed container than did the
private searchers.” Id. at 464. In a subsequent case, the Fifth Circuit held that
when a warrantless search of a portion of a computer and zip disk had been
justified, the defendant no longer retained any reasonable expectation of privacy
in the remaining contents of the computer and disk, and thus a comprehensive
search by law enforcement personnel did not violate the Fourth Amendment.
See United States v. Slanina, 283 F.3d 670, 680 (5th Cir. 2002), vacated on other
grounds, 537 U.S. 802 (2002), aff’d, 359 F.3d 356, 358 (5th Cir. 2004). See
also People v. Emerson, 766 N.Y.S.2d 482, 488 (N.Y. Sup. Ct. 2003) (adopting
intermediate position of treating computer folders rather than individual files
as closed containers); United States v. Beusch, 596 F.2d 871, 876-77 (9th Cir.
1979) (holding that when a physical ledger contains some information that
falls within the scope of a warrant, law enforcement may seize the entire ledger,
rather than individual responsive pages).
1 Although courts have analogized electronic storage devices to closed containers, some
courts have also noted characteristics of computers which distinguish them from other
closed containers. In United States v. Walser, 275 F.3d 981, 986 (10th Cir. 2001), the Tenth
Circuit observed that “[t]he advent of the electronic age and . . . the development of desktop
computers that are able to hold the equivalent of a library’s worth of information, go beyond
the established categories of constitutional doctrine. Analogies to other physical objects, such
as dressers or file cabinets, do not often inform the situations we now face as judges when
applying search and seizure law.” See also United States v. Stierhoff, 477 F. Supp. 2d 423, 445
(D.R.I. 2007) (“analogizing a computer file to a closed container is a logical, if not entirely
accurate, starting point for addressing the plain view doctrine’s application to computer
files”).
Searching and Seizing Computers
Other appellate courts have treated individual computer files as separate
entities, at least in the search warrant context. See, e.g., Guest v. Leis, 255 F.3d
325, 335 (6th Cir. 2001) (approving off-site review of a computer to “separate
relevant files from unrelated files”). Similarly, the Tenth Circuit has refused
to allow such exhaustive searches of a computer’s hard drive in the absence of
a warrant or some exception to the warrant requirement. See United States v.
Carey, 172 F.3d 1268, 1273-75 (10th Cir. 1999) (ruling that agent exceeded
the scope of a warrant to search for evidence of drug sales when he “abandoned
that search” and instead searched for evidence of child pornography for five
hours). In particular, the Tenth Circuit cautioned in a later case that “[b]ecause
computers can hold so much information touching on many different areas of
a person’s life, there is greater potential for the ‘intermingling’ of documents
and a consequent invasion of privacy when police execute a search for evidence
on a computer.” United States v. Walser, 275 F.3d 981, 986 (10th Cir. 2001).
Although individuals generally retain a reasonable expectation of privacy
in computers under their control, special circumstances may eliminate that
expectation. For example, an individual will not retain a reasonable expectation
of privacy in information that the person has made openly available. See Katz v.
United States, 389 U.S. 347, 351 (1967) (“What a person knowingly exposes to
the public, even in his own home or office, is not a subject of Fourth Amendment
protection.”); Wilson v. Moreau, 440 F. Supp. 2d 81, 104 (D.R.I. 2006) (finding
no expectation of privacy in documents user stored on computers available for
public use in a public library); United States v. Gines-Perez, 214 F. Supp. 2d
205, 224-26 (D.P.R. 2002) (finding no reasonable expectation of privacy in
information placed on the Internet); United States v. Butler, 151 F. Supp. 2d
82, 83-84 (D. Me. 2001) (finding no reasonable expectation of privacy in hard
drives of shared university computers). Tus, several courts have held that a
defendant has no reasonable expectation of privacy in files shared freely with
others. See United States v. King, 509 F.3d 1338, 1341-42 (11th Cir. 2007)
(holding that defendant did not have a legitimate expectation of privacy in the
contents of a “shared drive” of his laptop while it was connected to a network);
United States v. Barrows, 481 F.3d 1246, 1249 (10th Cir. 2007) (holding
no reasonable expectation of privacy exists where defendant networked his
computer “for the express purpose of sharing files”); United States v. Stults, 2007
WL 4284721, at *1 (D. Neb. Dec. 3, 2007) (finding no reasonable expectation
of privacy in computer files that the defendant made available using a peer-to-
peer file sharing program). Similarly, in United States v. David, 756 F. Supp.
1385 (D. Nev. 1991), agents looking over the defendant’s shoulder read the
1. Without a Warrant
defendant’s password from the screen as the defendant typed his password
into a handheld computer. Te court found no Fourth Amendment violation
in obtaining the password because the defendant did not enjoy a reasonable
expectation of privacy “in the display that appeared on the screen.” Id. at 1390.
See also United States v. Gorshkov, 2001 WL 1024026, at *2 (W.D. Wash. May
23, 2001) (holding that defendant did not have a reasonable expectation of
privacy in use of a private computer network when undercover federal agents
looked over his shoulder, when he did not own the computer he used, and
when he knew that the system administrator could monitor his activities).
Nor will individuals generally enjoy a reasonable expectation of privacy in the
contents of computers they have stolen or obtained by fraud. See United States
v. Caymen, 404 F.3d 1196, 1200 (9th Cir. 2005); United States v. Lyons, 992
F.2d 1029, 1031-32 (10th Cir. 1993).
3. Reasonable Expectation of Privacy and Tird-Party Possession
Individuals who retain a reasonable expectation of privacy in stored
electronic information under their control may lose Fourth Amendment
protections when they relinquish that control to third parties. For example,
an individual may offer a container of electronic information to a third party
by bringing a malfunctioning computer to a repair shop or by shipping
a floppy diskette in the mail to a friend. Alternatively, a user may transmit
information to third parties electronically, such as by sending data across the
Internet, or a user may leave information on a shared computer network.
When law enforcement agents learn of information possessed by third parties
that may provide evidence of a crime, they may wish to inspect it. Whether
the Fourth Amendment requires them to obtain a warrant before examining
the information depends in part upon whether the third-party possession has
eliminated the individual’s reasonable expectation of privacy.2
To analyze third-party possession issues, it helps first to distinguish between
possession by a carrier in the course of transmission to an intended recipient
and subsequent possession by the intended recipient. For example, if A hires B
to carry a package to C, A’s reasonable expectation of privacy in the contents
of the package during the time that B carries the package on its way to C may
be different than A’s reasonable expectation of privacy after C has received the
2 Regardless of whether an individual retains a reasonable expectation of privacy in an item
or information held by a third party, the third party may disclose the item or information to
the government provided the third party has common authority over the item or information.
See United States v. Young, 350 F.3d 1302, 1308-09 (11th Cir. 2003); Section C.1.b, infra.
Searching and Seizing Computers
package. During transmission, contents generally retain Fourth Amendment
protection. Te government ordinarily may not examine the contents of a
closed container in the course of transmission without a warrant. Government
intrusion and examination of the contents ordinarily violates the reasonable
expectation of privacy of both the sender and receiver. See United States v.
Villarreal, 963 F.2d 770, 774 (5th Cir. 1992). But see United States v. Young,
350 F.3d 1302, 1308 (11th Cir. 2003) (holding that Federal Express’s terms of
service, which allowed it to access customers’ packages, eliminated customer’s
reasonable expectation of privacy in package); United States v. Walker, 20 F.
Supp. 2d 971, 973-74 (S.D.W.Va. 1998) (concluding that packages sent
to an alias in furtherance of a criminal scheme do not support a reasonable
expectation of privacy). Tis rule applies regardless of whether the carrier is
owned by the government or a private company. Compare Ex Parte Jackson, 96
U.S. (6 Otto) 727, 733 (1877) (public carrier), with Walter v. United States,
447 U.S. 649, 651 (1980) (private carrier).
Government acquisition of an intangible electronic signal in the course
of transmission may also implicate the Fourth Amendment. See Berger v. New
York, 388 U.S. 41, 58-60 (1967) (applying the Fourth Amendment to a wire
communication in the context of a wiretap). Te boundaries of the Fourth
Amendment in such cases remain hazy, however, because Congress addressed
the Fourth Amendment concerns identified in Berger by passing Title III
of the Omnibus Crime Control and Safe Streets Act of 1968 (“Title III”),
18 U.S.C. §§ 2510-2522. Title III, which is discussed fully in Chapter
4, provides a comprehensive statutory framework that regulates real-time
monitoring of wire and electronic communications. Its scope encompasses,
and in many significant ways exceeds, the protection offered by the Fourth
Amendment. See United States v. Torres, 751 F.2d 875, 884 (7th Cir. 1984);
Chandler v. United States Army, 125 F.3d 1296, 1298 (9th Cir. 1997). As a
practical matter, then, the monitoring of wire and electronic communications
in the course of transmission generally raises many statutory questions, but few
constitutional ones. See generally Chapter 4.
Individuals lose Fourth Amendment protection in their
computer files if they relinquish control of the files.
Ordinarily, once an item has been received by the intended recipient, the
sender’s reasonable expectation of privacy in the item terminates. See United
States v. King, 55 F.3d 1193, 1196 (6th Cir. 1995) (sender’s expectation of
1. Without a Warrant
privacy in letter “terminates upon delivery”). More generally, the Supreme
Court has repeatedly held that the Fourth Amendment is not violated when
information revealed to a third party is disclosed by the third party to the
government, regardless of any subjective expectation that the third parties will
keep the information confidential. For example, in United States v. Miller, 425
U.S. 435, 443 (1976), the Court held that the Fourth Amendment does not
protect bank account information that account holders divulge to their banks.
By placing information under the control of a third party, the Court stated, an
account holder assumes the risk that the information will be conveyed to the
government. Id. According to the Court, “the Fourth Amendment does not
prohibit the obtaining of information revealed to a third party and conveyed
by him to Government authorities, even if the information is revealed on the
assumption that it will be used only for a limited purpose and the confidence
placed in the third party will not be betrayed.” Id. (citing Hoffa v. United States,
385 U.S. 293, 302 (1966)). See also SEC v. Jerry T. O’Brien, Inc., 467 U.S. 735,
743 (1984) (“when a person communicates information to a third party . . .
he cannot object if the third party conveys that information or records thereof
to law enforcement authorities”); Smith v. Maryland, 442 U.S. 735, 743-44
(1979) (finding no reasonable expectation of privacy in phone numbers dialed
by owner of a telephone because act of dialing the number effectively tells
the number to the phone company); Couch v. United States, 409 U.S. 322,
335 (1973) (holding that government may subpoena accountant for client
information given to accountant by client because client retains no reasonable
expectation of privacy in information given to accountant).
Courts have applied these principles to electronic communications. For
example, in United States v. Horowitz, 806 F.2d 1222 (4th Cir. 1986), the
defendant emailed confidential pricing information relating to his employer to
his employer’s competitor. After the FBI searched the competitor’s computers
and found the pricing information, the defendant claimed that the search
violated his Fourth Amendment rights. Te Fourth Circuit disagreed, holding
that the defendant relinquished his interest in and control over the information
by sending it to the competitor for the competitor’s future use. See id. at 1224-
26. See also Guest v. Leis, 255 F.3d 325, 333 (6th Cir. 2001) (stating that sender
of email “would lose a legitimate expectation of privacy in an e-mail that had
already reached its recipient; at this moment, the e-mailer would be analogous
to a letter-writer, whose ‘expectation of privacy ordinarily terminates upon
delivery’ of the letter”); United States v. Meriwether, 917 F.2d 955, 959 (6th
Cir. 1990) (defendant had no reasonable expectation of privacy in message
Searching and Seizing Computers
sent to a pager); United States v. Charbonneau, 979 F. Supp. 1177, 1184 (S.D.
Ohio 1997) (stating that a sender of an email “cannot be afforded a reasonable
expectation of privacy once that message is received.”).
Defendants will occasionally raise a Fourth Amendment challenge
to the acquisition of account records and subscriber information held by
Internet service providers where law enforcement obtained the records using
less process than a search warrant. As discussed in Chapter 3.D, the Stored
Communications Act permits the government to obtain transactional records
with an “articulable facts” court order and specified subscriber information
with a subpoena. See 18 U.S.C. §§ 2701-2712. Tese statutory procedures
comply with the Fourth Amendment because customers of communication
service providers do not have a reasonable expectation of privacy in customer
account records maintained by and for the provider’s business. See United
States v. Perrine, 518 F.3d 1196, 1204 (10th Cir. 2008) (“Every federal court to
address this issue has held that subscriber information provided to an internet
provider is not protected by the Fourth Amendment’s privacy expectation.”);
Guest v. Leis, 255 F.3d 325, 336 (6th Cir. 2001) (finding no Fourth Amendment
protection for network account holder’s basic subscriber information obtained
from communication service provider).3 Tis rule accords with prior cases
finding no Fourth Amendment protection in customer account records. See,
e.g., United States v. Fregoso, 60 F.3d 1314, 1321 (8th Cir. 1995) (telephone
records); In re Grand Jury Proceedings, 827 F.2d 301, 302-03 (8th Cir. 1987)
(Western Union customer records). Similarly, use of a pen register to capture
email to/from address information or Internet Protocol addresses of websites
provided to an Internet service provider for routing communications does not
implicate the Fourth Amendment. See United States v. Forrester, 512 F.3d 500,
510 (9th Cir. 2008) (email and Internet users have no reasonable expectation
of privacy in to/from addresses of their messages or in IP addresses of websites
visited).
Although an individual normally loses a reasonable expectation of privacy
in an item delivered to a recipient, there is an exception to this rule when
the individual can reasonably expect to retain control over the item and its
3 Tese cases do not resolve whether an individual maintains a reasonable expectation of
privacy in the contents of email in his own email account stored with a provider. See Quon
v. Arch Wireless Operating Co., 529 F.3d 892, 904-08 (9th Cir. 2008) (finding reasonable
expectation of privacy in pager messages stored by provider of communication service); Wilson
v. Moreau, 440 F. Supp. 2d 81, 108 (D.R.I. 2006) (finding reasonable expectation of privacy
in content of Yahoo! email account).
1. Without a Warrant
contents. When a person leaves a package with a third party for temporary
safekeeping, for example, she usually retains control of the package and thus
retains a reasonable expectation of privacy in its contents. See, e.g., United States
v. James, 353 F.3d 606, 614 (8th Cir. 2003) (finding that defendant retained
Fourth Amendment rights in sealed envelope containing computer disks which
he had left with a friend for storage); United States v. Most, 876 F.2d 191, 197-
98 (D.C. Cir. 1989) (finding reasonable expectation of privacy in contents of
plastic bag left with grocery store clerk); United States v. Barry, 853 F.2d 1479,
1481-83 (8th Cir. 1988) (finding reasonable expectation of privacy in locked
suitcase stored at airport baggage counter); United States v. Presler, 610 F.2d
1206, 1213-14 (4th Cir. 1979) (finding reasonable expectation of privacy in
locked briefcases stored with defendant’s friend for safekeeping).
In some cases, the sender may initially retain a right to control the third
party’s possession, but may lose that right over time. Te general rule is that
the sender’s Fourth Amendment rights dissipate as the sender’s right to control
the third party’s possession diminishes. For example, in United States v. Poulsen,
41 F.3d 1330 (9th Cir. 1994), overruled on other grounds, United States v. W. R.
Grace, 526 F.3d 499 (9th Cir. 2008) (en banc) computer hacker Kevin Poulsen
left computer tapes in a locker at a commercial storage facility but neglected
to pay rent for the locker. Following a warrantless search of the facility, the
government sought to use the tapes against Poulsen. Te Ninth Circuit held
that the search did not violate Poulsen’s reasonable expectation of privacy
because under state law Poulsen’s failure to pay rent extinguished his right to
access the tapes. See id. at 1337. See also United States v. Allen, 106 F.3d 695,
699 (6th Cir. 1997) (“Once a hotel guest’s rental period has expired or been
lawfully terminated, the guest does not have a legitimate expectation of privacy
in the hotel room.” (internal quotation marks omitted)).
4. Private Searches
Te Fourth Amendment “is wholly inapplicable to a search or seizure, even
an unreasonable one, effected by a private individual not acting as an agent of
the Government or with the participation or knowledge of any governmental
official.” United States v. Jacobsen, 466 U.S. 109, 113 (1984) (internal quotation
marks omitted). As a result, no violation of the Fourth Amendment occurs
when a private individual acting on his own accord conducts a search and
makes the results available to law enforcement. See id. According to Jacobsen,
agents who learn of evidence via a private search can reenact the original private
search without violating any reasonable expectation of privacy. What the agents
10
Searching and Seizing Computers
cannot do without a warrant is “exceed[] the scope of the private search.” Id.
at 115. See also United States v. Miller, 152 F.3d 813, 815-16 (8th Cir. 1998);
United States v. Donnes, 947 F.2d 1430, 1434 (10th Cir. 1991). But see United
States v. Allen, 106 F.3d 695, 699 (6th Cir. 1997) (stating in dicta that Jacobsen
does not permit law enforcement to reenact a private search of a private home
or residence). Tis standard requires agents to limit their investigation to the
scope of the private search when searching without a warrant after a private
search has occurred. Where agents exceed the scope of the private warrantless
search, any evidence uncovered may be vulnerable to a motion to suppress.
Private individuals often find contraband or other incriminating evidence
on computers and bring that information to law enforcement, and the private
search doctrine applies in these cases. In one common scenario, an individual
leaves his computer with a repair technician. Te technician discovers images
of child pornography on the computer, contacts law enforcement, and shows
those images to law enforcement. Courts have agreed that such searches by
repairmen prior to their contact with law enforcement are private searches and
do not implicate the Fourth Amendment. See United States v. Grimes, 244
F.3d 375, 383 (5th Cir. 2001); United States v. Hall, 142 F.3d 988, 993 (7th
Cir. 1998); United States v. Anderson, 2007 WL 1121319 at *5-6 (N.D. Ind.
Apr. 16, 2007); United States v. Grant, 434 F. Supp. 2d 735, 744-45 (D. Neb.
2006); United States v. Caron, 2004 WL 438685, at *4-5 (D. Me. Mar. 9,
2004); see also United States v. Kennedy, 81 F. Supp. 2d 1103, 1112 (D. Kan.
2000) (concluding that searches of defendant’s computer over the Internet by
an anonymous caller and employees of a private ISP did not violate Fourth
Amendment because there was no evidence that the government was involved
in the search).
One private search question that arises in computer cases is whether law
enforcement agents must limit themselves to only files examined by the repair
technician or whether all data on a particular storage device is within the scope
of the initial private search. Te Fifth Circuit has taken an expansive approach
to this question. See United States v. Runyan, 275 F.3d 449, 464-65 (5th Cir.
2001) (police did not exceed the scope of a private search when they examined
more files on privately searched disks than had the private searchers). Under
this approach, a third-party search of a single file on a computer allows a
warrantless search by law enforcement of the computer’s entire contents. See id.
Other courts, however, may not follow the Fifth Circuit’s approach and instead
rule that government searchers can view only those files whose contents were
1. Without a Warrant
11
revealed in the private search. See United States v. Barth, 26 F. Supp. 2d 929,
937 (W.D. Tex. 1998) (holding, in a pre-Runyan case, that agents who viewed
more files than private searcher exceeded the scope of the private search). Even
if courts follow the more restrictive approach, the information gleaned from
the private search will often provide the probable cause needed to obtain a
warrant for a further search.4
Importantly, the fact that the person conducting a search is not a government
employee does not always mean that the search is
“private” for Fourth
Amendment purposes. A search by a private party will be considered a Fourth
Amendment government search “if the private party act[s] as an instrument
or agent of the Government.” Skinner v. Railway Labor Executives’ Ass’n, 489
U.S. 602, 614 (1989). Te Supreme Court has offered little guidance on when
private conduct can be attributed to the government; the Court has merely
stated that this question “necessarily turns on the degree of the Government’s
participation in the private party’s activities, . . . a question that can only be
resolved ‘in light of all the circumstances.’” Id. at 614-15 (quoting Coolidge v.
New Hampshire, 403 U.S. 443, 487 (1971)).
In the absence of a more definitive standard, the various federal Courts of
Appeals have adopted a range of approaches for distinguishing between private
and government searches. About half of the circuits apply a “totality of the
circumstances” approach that examines three factors: whether the government
knows of or acquiesces in the intrusive conduct; whether the party performing
the search intends to assist law enforcement efforts at the time of the search;
and whether the government affirmatively encourages, initiates, or instigates
the private action. See, e.g., United States v. Pervaz, 118 F.3d 1, 6 (1st Cir.
1997); United States v. Smythe, 84 F.3d 1240, 1242-43 (10th Cir. 1996);
United States v. McAllister, 18 F.3d 1412, 1417-18 (7th Cir. 1994); United
States v. Malbrough, 922 F.2d 458, 462 (8th Cir. 1990). Tis test draws a line
4 After viewing evidence of a crime stored on a computer, agents may need to seize the
computer temporarily to ensure the integrity and availability of the evidence before they can
obtain a warrant to search the contents of the computer. See, e.g., Hall, 142 F.3d at 994-95;
United States v. Grosenheider, 200 F.3d 321, 330 n.10 (5th Cir. 2000). Te Fourth Amendment
permits agents to seize a computer temporarily so long as they have probable cause to believe
that it contains evidence of a crime, the agents seek a warrant expeditiously, and the duration
of the warrantless seizure is not “unreasonable” given the totality of the circumstances. See
Illinois v. McArthur, 531 U.S. 326, 332-34 (2001); United States v. Place, 462 U.S. 696, 701
(1983); United States v. Martin, 157 F.3d 46, 54 (2d Cir. 1998); United States v. Licata, 761
F.2d 537, 540-42 (9th Cir. 1985).
12
Searching and Seizing Computers
between situations where the government is a mere knowing witness to the
search and those where the government is an active participant or driving
force. However, this line can be difficult to discern. For example, in United
States v. Smith, 383 F.3d 700 (8th Cir. 2004), police detectives participating
in “parcel interdiction” at Federal Express removed a suspicious package from
a conveyer belt, submitted it to a canine sniff, and delivered the package to
the Federal Express manager, telling the manager that “if she wanted to open
it that would be fine.” However, because the police did not actually ask or
order the manager to open the package, and because there was no evidence
that the manager felt obligated to open the package, the Court found that the
manager was not a “government agent” for Fourth Amendment purposes. Id.
at 705. See also United States v. Momoh, 427 F.3d 137, 141-42 (1st Cir. 2005)
(DHL employee’s desire to comply with FAA regulations did not make her a
government agent absent “affirmative encouragement”). By contrast, in United
States v. Souza, 223 F.3d 1197 (10th Cir. 2000), the Court found that a UPS
employee was a government agent. In Souza, the police identified and removed
the package from the conveyer belt, submitted it to a canine sniff, and told
the UPS employee that they suspected it contained drugs. Te police then
told the employee that they could not tell her to open the package, but they
pointed to it and said “but there it is on the floor.” Id. at 1200. Te employee
began to open the package, but when she had difficulty, the police assisted
her. While the officers’ actual aid in opening the package made this an easy
case, the Court’s analysis suggests that the officers’ other actions—identifying
the package and encouraging the employee to open it—might have made the
employee a government agent, particularly without evidence that the employee
had an independent motivation to open it. See id. at 1202.
Other circuits have adopted more rule-like tests that focus on only the first
two factors. See, e.g., United States v. Miller, 688 F.2d 652, 657 (9th Cir. 1982)
(holding that private action counts as government conduct if, at the time of the
search, the government knew of or acquiesced in the intrusive conduct, and the
party performing the search intended to assist law enforcement efforts); United
States v. Paige, 136 F.3d 1012, 1017 (5th Cir. 1998) (same); United States v.
Lambert, 771 F.2d 83, 89 (6th Cir. 1985) (holding that a private individual is a
state actor for Fourth Amendment purposes if the police instigated, encouraged,
or participated in the search, and the individual engaged in the search with the
intent of assisting the police in their investigative efforts).
1. Without a Warrant
13
Two noteworthy private search cases involve an individual who hacked
into computers of child pornographers for the purpose of collecting and
disclosing evidence of their crimes. Te hacker, who refused to identify himself
or meet directly with law enforcement, emailed the incriminating evidence to
law enforcement. In both cases, the evidence was admissible because when it
was gathered, the individual was not an agent of law enforcement. In the first
case, United States v. Steiger, 318 F.3d 1039 (11th Cir. 2003), the court had
little difficulty in determining that the search did not implicate the Fourth
Amendment. Because the relevant searches by the hacker took place before the
hacker contacted law enforcement, the hacker was not acting as a government
agent, and the private search doctrine applied. See id. at 1045. In the Steiger case,
a law enforcement agent thanked the anonymous hacker, assured him he would
not be prosecuted, and expressed willingness to receive other information from
him. Approximately a year later (and seven months after his last previous contact
with law enforcement), the hacker provided to law enforcement information
he had illegally obtained from another child pornographer, which gave rise
to United States v. Jarrett, 338 F.3d 339 (4th Cir. 2003). In Jarrett, the court
ruled that although “the Government operated close to the line,” the contacts
in Steiger between the hacker and law enforcement did not create an agency
relationship that carried forward to Jarrett. Id. at 346-47. Moreover, although
the government created an agency relationship through further contacts with
the hacker during the second investigation, that agency relationship arose after
the relevant private search and disclosure. See id. at 346. Tus, the hacker’s
private search in Jarrett did not violate the Fourth Amendment.
5. Use of Specialized Technology to Obtain Information
Te government’s use of innovative technology to obtain information
about a target can implicate the Fourth Amendment. See Kyllo v. United States,
533 U.S. 27 (2001). In Kyllo, the Supreme Court held that the warrantless
use of a thermal imager to reveal the relative amount of heat released from
the various rooms of a suspect’s home constituted a search that violated the
Fourth Amendment. In particular, the Court held that where law enforcement
“uses a device that is not in general public use, to explore details of the home
that would previously have been unknowable without a physical intrusion, the
surveillance is a ‘search’ and is presumptively unreasonable without a warrant.”
Id. at 40. Whether a technology falls within the scope of the Kyllo rule depends
on at least two factors. First, the use of technology should not implicate Kyllo if
the technology is in “general public use,” see id. at 34, 39 n.6, although courts
14
Searching and Seizing Computers
have not yet defined the standard for determining whether a given technology
meets this requirement. Second, the Supreme Court restricted its holding in
Kyllo to the use of technology that reveals information about the interior of the
home. See id. at 40 (“We have said that the Fourth Amendment draws a firm
line at the entrance to the house.” (internal quotation marks omitted)).
Defendants have occasionally—and unsuccessfully—invoked Kyllo in cases
in which the government used cell tower information or an electronic device
to locate a cell phone. For example, in United States v. Bermudez, 2006 WL
3197181 (S.D. Ind. June 30, 2006), aff’d 509 F.3d 820 (7th Cir. 2007), the
court rejected a Kyllo challenge to the use of an electronic device to locate a
cell phone because cell phones are used to transmit signals to parties outside
a home. In rejecting the defendant’s Kyllo argument, the court explained that
“the cell phone signals were knowingly exposed to a third-party, to wit, the cell
phone company.” Id. at *13.
C. Exceptions to the Warrant Requirement in Cases
Involving Computers
Warrantless searches that intrude upon a reasonable expectation of privacy
will comply with the Fourth Amendment if they fall within an established
exception to the warrant requirement. Cases involving computers often
raise questions relating to how these “established” exceptions apply to new
technologies.
1. Consent
Agents may search a place or object without a warrant or even probable
cause if a person with authority has voluntarily consented to the search. See
Schneckloth v. Bustamonte, 412 U.S. 218, 219 (1973). Te authority to consent
may be actual or apparent. See United States v. Buckner, 473 F.3d 551, 555 (4th
Cir. 2007). Te consent may be explicit or implicit. See United States v. Milian-
Rodriguez, 759 F.2d 1558, 1563-64 (11th Cir. 1985). Whether consent was
voluntarily given is a question of fact that the court must decide by considering
the totality of the circumstances. While no single aspect controls the result,
the Supreme Court has identified the following important factors: the age,
education, intelligence, physical and mental condition of the person giving
consent; whether the person was under arrest; and whether the person had
been advised of his right to refuse consent. See Schneckloth, 412 U.S. at 226-
1. Without a Warrant
15
27. Te government carries the burden of proving that consent was voluntary.
See United States v. Matlock, 415 U.S. 164, 177 (1974); Buckner, 473 F.3d at
554.
In computer crime cases, two consent issues arise particularly often. First,
when does a search exceed the scope of consent? For example, when a target
consents to the search of a location, to what extent does the consent authorize
the retrieval of information stored in computers at the location? Second, who
is the proper party to consent to a search? Do roommates, friends, and parents
have the authority to consent to a search of another person’s computer files?5
Finally, consent to search may be revoked “prior to the time the search
is completed.” United States v. Lattimore, 87 F.3d 647, 651 (4th Cir. 1996)
(quoting 3 Wayne R. LaFave, Search and Seizure § 8.2(f ), at 674 (3d ed.
1996)). When agents obtain consent to remove computers for off-site review
and analysis, the time required for review can be substantial. In such cases,
law enforcement should keep in mind that before incriminating evidence is
found, the consent may be revoked. In cases involving physical documents
obtained by consent, courts have allowed the government to keep copies of
the documents made by the government prior to the revocation of consent,
but they have forced the government to return copies made after consent was
revoked. See Mason v. Pulliam, 557 F.2d 426, 429 (5th Cir. 1977); Vaughn v.
Baldwin, 950 F.2d 331, 334 (6th Cir. 1991). Tere is little reason for courts
to distinguish copying paper documents from copying hard drives, and one
district court recently stated that a defendant who revoked the consent to
search his computer retained no reasonable expectation of privacy in a mirror
image copy of his hard drive made by the FBI. See United States v. Megahed,
2009 WL 722481, at *3 (M.D. Fla. Mar. 18, 2009).
a. Scope of Consent
“Te scope of a consent to search is generally defined by its expressed object,
and is limited by the breadth of the consent given.” United States v. Pena, 143
F.3d 1363, 1368 (10th Cir. 1998) (internal quotation marks omitted). Te
standard for measuring the scope of consent under the Fourth Amendment
is objective reasonableness: “[W]hat would the typical reasonable person have
understood by the exchange between the [agent] and the [person granting
consent]?” Florida v. Jimeno, 500 U.S. 248, 251 (1991). Tis requires a fact-
5 Consent by employers and co-employees is discussed separately in the workplace search
section of this chapter. See Chapter 1.D.
16
Searching and Seizing Computers
intensive inquiry into whether it was reasonable for the agent to believe that
the scope of consent included the items searched. Id. Of course, when the
limits of the consent are clearly given, either before or during the search, agents
must respect these bounds. See Vaughn v. Baldwin, 950 F.2d 331, 333-34 (6th
Cir. 1991).
Computer cases often raise the question of whether general consent to
search a location or item implicitly includes consent to access the memory
of electronic storage devices encountered during the search. In such cases,
courts look to whether the particular circumstances of the agents’ request for
consent implicitly or explicitly limited the scope of the search to a particular
type, scope, or duration. Because this approach ultimately relies on fact-driven
notions of common sense, results reached in published opinions have hinged
upon subtle (if not entirely inscrutable) distinctions. Compare United States v.
Reyes, 922 F. Supp. 818, 834 (S.D.N.Y. 1996) (consent to “look inside” a car
included consent to retrieve numbers stored inside pagers found in car’s back
seat), with United States v. Blas, 1990 WL 265179, at *20 (E.D. Wis. Dec.
4, 1990) (consent to “look at” a pager did not include consent to activate
pager and retrieve numbers, because looking at pager could be construed to
mean “what the device is, or how small it is, or what brand of pager it may
be”). See also United States v. Carey, 172 F.3d 1268, 1274 (10th Cir. 1999)
(reading written consent form extremely narrowly, so that consent to seizure
of “any property” under the defendant’s control and to “a complete search of
the premises and property” at the defendant’s address merely permitted the
agents to seize the defendant’s computer from his apartment, not to search the
computer off-site because it was no longer located at the defendant’s address);
United States v. Tucker, 305 F.3d 1193, 1202 (10th Cir. 2002) (allowing
computer search pursuant to parole agreement allowing search of “any other
property under [defendant’s] control”); United States v. Lemmons, 282 F.3d
920, 924-25 (7th Cir. 2002) (defendant expanded initial consent to search
of cameras and recordings to include computer files when he invited officer
to look at computer and failed to object to officer’s search for pornographic
images). Prosecutors can strengthen their argument that the scope of consent
included consent to search electronic storage devices by relying on analogous
cases involving closed containers. See, e.g., United States v. Al-Marri, 230 F.
Supp. 2d 535, 540-41 (S.D.N.Y. 2002) (upholding search of computer in
residence and citing principle that separate consent to search closed container
in fixed premises is unnecessary); United States v. Galante, 1995 WL 507249,
at *3 (S.D.N.Y. Aug. 25, 1995) (general consent to search car included consent
1. Without a Warrant
17
to have officer access memory of cellular telephone found in the car, in light of
circuit precedent involving closed containers); Reyes, 922 F. Supp. at 834.
When agents obtain consent for one reason but then conduct a search for
another reason, they should be careful to make sure that the scope of consent
encompasses their actual search. For example, in United States v. Turner, 169
F.3d 84 (1st Cir. 1999), the First Circuit suppressed images of child pornography
found on computers after agents procured the defendant’s consent to search
his property for other evidence. In Turner, detectives searching for physical
evidence of an attempted sexual assault obtained written consent to search the
defendant’s “premises” and “personal property.” Before the defendant signed
the consent form, the detectives discovered a large knife and blood stains in
his apartment, and they explained to him that they were looking for more
evidence of the assault that the suspect might have left behind. See id. at 85-86.
While several agents searched for physical evidence, one detective searched the
contents of the defendant’s personal computer and discovered stored images of
child pornography. Te defendant was thereafter charged with possessing child
pornography. On interlocutory appeal, the First Circuit held that the search
of the computer exceeded the scope of consent and suppressed the evidence.
According to the Court, the detectives’ statements that they were looking for
signs of the assault limited the scope of consent to the kind of physical evidence
that an intruder might have left behind. See id. at 88. By transforming the
search for physical evidence into a search for computer files, the detective
exceeded the scope of consent. See id.; see also Carey, 172 F.3d at 1277
(Baldock, J., concurring) (concluding that agents exceeded scope of consent
by searching computer after defendant signed broadly-worded written consent
form, because agents told defendant that they were looking for drugs and drug-
related items rather than computer files containing child pornography) (citing
Turner). Of course, as with other scope-of-consent cases, cases analyzing the
reason for a search are fact specific, and courts’ interpretations of the scope of
consent are not always narrow. See United States v. Marshall, 348 F.3d 281,
287-88 (1st Cir. 2003) (finding that consent to search for “stolen items” did
not preclude seizing and viewing video tapes where video equipment, but not
video tapes, were reported stolen); United States v. Raney, 342 F.3d 551, 556-
58 (7th Cir. 2003) (finding consent to search for “materials in the nature of ”
child exploitation and child erotica was broad enough to encompass search of
homemade adult pornography where the defendant had expressed an intent to
make similar homemade pornography with a minor).
18
Searching and Seizing Computers
Finally, the scope of consent usually relates to the target item, location, and
purpose of the search, rather than the search methodology used. For example,
in United States v. Brooks, 427 F.3d 1246 (10th Cir. 2005), an agent received
permission to conduct a “complete search” of the defendant’s computer for
child pornography. Te agent explained that he would use a “pre-search” disk
to find and display image files, allowing the agent to easily ascertain whether
any images contained child pornography. Id. at 1248. When the disk, for
unexplained reasons, failed to function, the agent conducted a manual search
for image files, eventually discovering several pieces of child pornography. Id.
Although the agent ultimately used a different search methodology than the
one he described to the defendant, the Court approved the manual search
because it did not exceed the scope of the described disk search. Id. at 1249-50.
See also United States v. Long, 425 F.3d 482, 487 (7th Cir. 2005) (finding that
agent’s use of “sophisticated” Encase forensic software did not exceed scope of
consent to search laptop).
It is a good practice for agents to use written consent forms that
state explicitly that the scope of consent includes consent to
search computers and other electronic storage devices.
Because the decisions evaluating the scope of consent to search computers
have reached sometimes unpredictable results, investigators should indicate the
scope of the search explicitly when obtaining a suspect’s consent to search a
computer. Moreover, investigators who have seized a computer based on consent
and who have developed probable cause may consider obviating concerns with
either the scope of consent or revocation of consent by obtaining a search
warrant. For a sample consent to search form, see Appendix J.
b. Tird-Party Consent
i.
General Principles
It is common for several people to use or own the same computer equipment.
If any one of those people gives permission to search for data, agents may
generally rely on that consent, so long as the person has authority over the
computer. In such cases, all users have assumed the risk that a co-user might
discover everything in the computer and might also permit law enforcement to
search this “common area” as well.
Te watershed case in this area is United States v. Matlock, 415 U.S. 164
(1974). In Matlock, the Supreme Court stated that one who has “common
1. Without a Warrant
19
authority” over premises or effects may consent to a search even if an absent
co-user objects. Id. at 171. According to the Court, the common authority that
establishes the right of third-party consent requires
mutual use of the property by persons generally having joint
access or control for most purposes, so that it is reasonable to
recognize that any of the co-inhabitants has the right to permit
the inspection in his own right and that the others have assumed
the risk that one of their number might permit the common
area to be searched.
Id. at 171 n.7.
Under the Matlock approach, a private third party may consent to a search
of property under the third party’s joint access or control. Agents may view
what the third party may see without violating any reasonable expectation of
privacy so long as they limit the search to the zone of the consenting third
party’s common authority. See United States v. Jacobsen, 466 U.S. 109, 119-20
(1984) (noting that the Fourth Amendment is not violated when a private third
party invites the government to view the contents of a package under the third
party’s control). Tis rule often requires agents to inquire into third parties’
rights of access before conducting a consent search and to draw lines between
those areas that fall within the third party’s common authority and those areas
outside of the third party’s control. See United States v. Block, 590 F.2d 535,
541 (4th Cir. 1978) (holding that a mother could consent to a general search
of her 23-year-old son’s room, but could not consent to a search of a locked
footlocker found in the room).
Co-users of a computer will generally have the ability to consent to a
search of its files under Matlock. See United States v. Smith, 27 F. Supp. 2d
1111, 1115-16 (C.D. Ill. 1998) (concluding that a woman could consent to a
search of her boyfriend’s computer located in their house and noting that the
boyfriend had not password-protected his files). However, when an individual
protects her files with passwords and has not shared the passwords with others
who also use the computer, the Fourth Circuit has held that the authority
of those other users to consent to search of the computer will not extend to
the password-protected files. See Trulock v. Freeh, 275 F.3d 391, 403 (4th
Cir. 2001) (analogizing password-protected files to locked footlockers inside
a bedroom, which the court had previously held to be outside the scope of
common authority consent). Nevertheless, specific facts may overcome an
20
Searching and Seizing Computers
|
||
|
|
|