Military reference books and manuals (2009-2023, Volume 3) - page 34

 

  Index      Manuals     Military reference books and manuals (2009-2023, Volume 3)

 

Search            copyright infringement  

 

   

 

   

 

Content      ..     32      33      34      35     ..

 

 

 

Military reference books and manuals (2009-2023, Volume 3) - page 34

 

 

1. Journalists and Authors: the Privacy Protection Act
When agents have reason to believe that a search may result
in a seizure of materials relating to First Amendment activities
such as publishing or posting materials on the Internet, they must
consider the effect of the Privacy Protection Act (“PPA”), 42 U.S.C.
§ 2000aa. Every federal computer search that implicates the
PPA must be approved by the Justice Department, coordinated
through CCIPS at (202) 514-1026.
Under the Privacy Protection Act (“PPA”), 42 U.S.C. § 2000aa, law
enforcement must take special steps when planning a search that agents have
reason to believe may result in the seizure of certain materials that relate to
the freedom of expression. Federal law enforcement searches that implicate
the PPA must be pre-approved by a Deputy Assistant Attorney General of the
Criminal Division. Te Computer Crime and Intellectual Property Section
serves as the contact point for all such searches involving computers and should
be contacted directly at (202) 514-1026.
a. A Brief History of the Privacy Protection Act
When deciphering the inscrutable text of the PPA, it can be helpful to
understand the context in which it was enacted. Before the Supreme Court
decided Warden v. Hayden, 387 U.S. 294, 309 (1967), law enforcement officers
could not obtain search warrants to search for and seize “mere evidence” of
crime. Warrants were permitted only to seize contraband, instrumentalities,
or fruits of crime. See Boyd v. United States, 116 U.S. 616 (1886). In Hayden,
the Court reversed course and held that the Fourth Amendment permitted
the government to obtain search warrants to seize mere evidence. Tis ruling
set the stage for a collision between law enforcement and the press. Because
journalists and reporters often collect evidence of criminal activity in the course
of developing news stories, they frequently possess “mere evidence” of crime
that may prove useful to law enforcement investigations. By freeing the Fourth
Amendment from Boyd’s restrictive regime, Hayden created the possibility that
law enforcement could use search warrants to target the press for evidence
of crime it had collected in the course of investigating and reporting news
stories.
It did not take long for such a search to occur. On April 12, 1971, the
District Attorney’s Office in Santa Clara County, California obtained a search
warrant to search the offices of Te Stanford Daily, a Stanford University
2. With a Warrant
101
student newspaper. Te DA’s office was investigating a violent clash between
the police and demonstrators that had occurred at the Stanford University
Hospital three days earlier. Te Stanford Daily had covered the incident, and
published a special edition featuring photographs of the clash. Believing that
the newspaper probably had more photographs of the clash that could help the
police identify the demonstrators, the police obtained a warrant and sent four
police officers to search the newspaper’s office for further evidence that could
assist the investigation. Te officers found nothing. A month later, however, the
Stanford Daily and its editors brought a civil suit against the police claiming
that the search had violated their First and Fourth Amendment rights. Te
case ultimately reached the Supreme Court, and in Zurcher v. Stanford Daily,
436 U.S. 547 (1978), the Court rejected the newspaper’s claims. Although the
Court noted that “the Fourth Amendment does not prevent or advise against
legislative or executive efforts to establish nonconstitutional protections” for
searches of the press, it held that neither the Fourth nor First Amendment
prohibited such searches. Id. at 567.
Congress passed the PPA in 1980 in response to Stanford Daily. According
to the Senate Report, the PPA protected “the press and certain other persons
not suspected of committing a crime with protections not provided currently
by the Fourth Amendment.” S. Rep. No. 96-874, at 4 (1980), reprinted in
1980 U.S.C.C.A.N. 3950. Te statute was intended to grant publishers
certain statutory rights to discourage law enforcement officers from targeting
publishers simply because they often gathered “mere evidence” of crime. As the
legislative history indicates:
Te purpose of this statute is to limit searches for materials
held by persons involved in First Amendment activities who
are themselves not suspected of participation in the criminal
activity for which the materials are sought, and not to limit
the ability of law enforcement officers to search for and seize
materials held by those suspected of committing the crime
under investigation.
Id. at 11.
b. Te Terms of the Privacy Protection Act
Subject to certain exceptions, the PPA makes it unlawful for a
government officer “to search for or seize” materials when:
102
Searching and Seizing Computers
(a)thematerials are “work productmaterials” prepared, produced,
authored, or created “in anticipation of communicating such
materials to the public,” 42 U.S.C. § 2000aa-7(b)(1);
(b) the materials include the “mental impressions, conclusions,
or theories” of their creator, 42 U.S.C. § 2000aa-7(b)(3); and
(c) the materials are possessed for the purpose of communicating
the material to the public by a person “reasonably believed
to have a purpose to disseminate to the public” some form
of
“public communication,” 42 U.S.C. §§ 2000aa-7(b)(3),
2000aa(a);
or
(a) the materials are
“documentary materials” that contain
“information,” 42 U.S.C. § 2000aa-7(a); and
(b) the materials are possessed by a person “in connection with
a purpose to disseminate to the public” some form of “public
communication.” 42 U.S.C. §§ 2000aa(b), 2000aa-7(a).
In these situations, the government is required to use a subpoena or other
compulsory process rather than use a search warrant, unless a PPA exception
applies.
Te PPA protects a broad set of actors. It is not limited to journalists: it
has been used by a publisher of role-playing games, see Steve Jackson Games,
Inc. v. Secret Service, 816 F. Supp. 432 (W.D. Tex. 1993), and a publisher of
an “internet-based journal,” although the latter’s claim was dismissed on other
grounds. See Mink v. Suthers, 482 F.3d 1244, 1257-58 (10th Cir. 2007).
Te PPA contains several important exceptions:
Contraband. Te PPA does not apply to “contraband or the fruits of a crime
or things otherwise criminally possessed, or property designed or intended for
use, or which is or has been used as, the means of committing a criminal
offense.” 42 U.S.C. § 2000aa-7(a), (b).
Criminal suspect. Te PPA does not apply if “there is probable cause to believe
that the person possessing such materials has committed or is committing the
criminal offense to which the materials relate,” although the statute sets forth a
further exception to this exception in certain circumstances where the offense
“consists of the receipt, possession, communication, or withholding” of the
2. With a Warrant
103
targeted materials. See 42 U.S.C. §§ 2000aa(a)(1), 2000aa(b)(1); Guest v. Leis,
255 F.3d 325, 342 (6th Cir. 2001); DePugh v. Sutton, 917 F. Supp. 690, 696
(W.D. Mo. 1996) (“Te P.P.A. clearly allows the government to depart from
the requirements of the Act in those instances in which the person suspected
of a crime is in possession of documents related to the crime.”). Materials may
“relate” to an offense even when the relations are somewhat remote. For example,
in S.H.A.R.K. v. Metro Parks Serving Summit County, 499 F.3d 553 (6th Cir.
2007), animal rights activists placed hidden cameras on trees to document
planned extermination of deer. Te removal (and seizure) of those cameras did
not violate the PPA, because the cameras were “related” to the crime of trespass
necessary to place them there in the first place. Id. at 567.
Emergency. Te PPA does not apply if there is reason to believe that the
immediate seizure of such materials is necessary to prevent death or serious
bodily injury. See 42 U.S.C. §§ 2000aa(a)(2), 2000aa(b)(2).
Subpoena would be inadequate. Te PPA does not apply in a search for or
seizure of “documentary materials” as defined by § 2000aa-7(a), if a subpoena
has proven inadequate or there is reason to believe that a subpoena would not
result in the production of the materials, see 42 U.S.C. § 2000aa(b)(3)-(4).
One court held this exception was met when an incriminating videotape was
in the possession of a person who was friends with the person whom the tape
would incriminate. See Berglund v. City of Maplewood, 173 F. Supp. 2d 935,
949-50 (D. Minn. 2001).
Importantly, these exceptions are exceptions to the PPA only, not to Fourth
Amendment protections in general. When a PPA exception applies, it means
only that the government may apply for a warrant - it does not mean that the
government may proceed to search without a warrant. See DePugh v. Sutton,
917 F. Supp. 690, 696 (W.D. Mo. 1996).
Violations of the PPA do not result in suppression of the evidence, see 42
U.S.C. § 2000aa-6(d), but can result in civil damages against the sovereign
whose officers or employees execute the search. See § 2000aa-6(a), (e); Davis
v. Gracey, 111 F.3d 1472, 1482 (10th Cir. 1997) (dismissing PPA suit against
municipal officers in their personal capacities because such suits must be filed
only against the “government entity” unless the government entity has not
waived sovereign immunity). If State officers or employees violate the PPA
and the state does not waive its sovereign immunity and is thus immune from
suit, see Barnes v. State of Missouri, 960 F.2d 63, 65 (8th Cir. 1992), individual
104
Searching and Seizing Computers
State officers or employees may be held liable for acts within the scope or under
the color of their employment, subject to a reasonable good faith defense. See
§ 2000aa-6(a)(2),(b).
c. Application of the PPA to Computer Searches and Seizures
PPA issues frequently arise in computer cases for two reasons that would
have been difficult to foresee when Congress enacted it in 1980. First, the
use of personal computers for publishing and the Internet has dramatically
expanded the scope of who is “involved in First Amendment activities.” Today,
anyone with a computer and access to the Internet may be a publisher who
possesses PPA-protected materials on his or her computer.
Te second reason that PPA issues arise frequently in computer cases is
that the language of the statute does not explicitly rule out liability following
incidental seizures of PPA-protected materials, and such seizures may result
when agents search for and seize computer-stored contraband or evidence
of crime that is commingled with PPA-protected materials. For example,
investigations into illegal businesses that publish images of child pornography
over the Internet have revealed that such businesses frequently support other
publishing materials (such as drafts of adult pornography) that may be PPA-
protected. Seizing the computer for the contraband necessarily results in the
seizure of the PPA-protected materials, because the contraband is commingled
with PPA-protected materials on the business’s computers. If the PPA were
interpreted to forbid such seizures, the statute would not merely deter law
enforcement from targeting innocent publishers for their evidence, but also
would bar the search and seizure of a criminal suspect’s computer if the
computer included PPA-protected materials, even incidentally.
Te legislative history and text of the PPA indicate that Congress probably
intended the PPA to apply only when law enforcement intentionally targeted
First Amendment material that related to a crime, as in Zurcher v. Stanford
Daily, 436 U.S. 547 (1978). For example, the “suspect exception” eliminates
PPA liability when “there is probable cause to believe that the person possessing
such materials has committed or is committing the criminal offense to which
the materials relate,”
42 U.S.C. § 2000aa(a)(1), § 2000aa(b)(1) (emphasis
added). Tis text indicates that Congress believed that PPA-protected materials
would necessarily relate to a criminal offense, as when investigators target the
materials as evidence. When agents collaterally seize PPA-protected materials
because they are commingled on a computer with other materials properly
2. With a Warrant
105
targeted by law enforcement, however, the PPA-protected materials might not
necessarily relate to any crime at all. For example, the PPA-protected materials
might be drafts of a horticulture newsletter that just happen to sit on the same
hard drive as images of child pornography or records of a fraud scheme.
Te Sixth Circuit has explicitly ruled that the incidental seizure of PPA-
protected material commingled on a suspect’s computer with evidence of a
crime does not give rise to PPA liability. Guest v. Leis, 255 F.3d 325 (6th Cir.
2001), involved two lawsuits brought against the Sheriff’s Department in
Hamilton County, Ohio. Te suits arose from the seizures of two servers that
had been used to host bulletin board systems suspected of housing evidence
and contraband relating to obscenity, phone tapping, child pornography, credit
card theft, and software piracy. Te Sixth Circuit noted that “when police
execute a search warrant for documents on a computer, it will often be difficult
or impossible (particularly without the cooperation of the owner) to separate
the offending materials from other ‘innocent’ material on the computer” at
the site of the search. Id. at 341-42. Given these pragmatic concerns, the
court refused to find PPA-liability for incidental seizures; to construe the PPA
otherwise would “prevent police in many cases from seizing evidence located on
a computer.” Id. at 342. Instead, the court held that “when protected materials
are commingled on a criminal suspect’s computer with criminal evidence that
is unprotected by the act, we will not find liability under the PPA for seizure
of the PPA-protected materials.” Id. Te Guest court cautioned, however, that
although the incidental seizure of PPA-related work-product and documentary
materials did not violate the Act, the subsequent search of such material was
probably forbidden. Id.
Te Sixth Circuit’s decision in Guest verifies that the suspect exception works
as the legislature intended: limiting the scope of PPA protection to “the press
and certain other persons not suspected of committing a crime.” S. Rep. No.
96-874, at 4 (1980), reprinted in 1980 U.S.C.C.A.N. 3950. At least one other
court has also reached this result by broadly interpreting the suspect exception’s
phrase “to which materials relate” when an inadvertent seizure of commingled
matter occurs. See United States v. Hunter, 13 F. Supp. 2d 574, 582 (D. Vt.
1998) (concluding that materials for weekly legal newsletter published by the
defendant from his law office “relate” to the defendant’s alleged involvement
in his client’s drug crimes when the former was inadvertently seized in a search
for evidence of the latter). See also S.H.A.R.K. v. Metro Parks Serving Summit
County, 499 F.3d 553, 567 (6th Cir. 2007) (seizure of video cameras placed
106
Searching and Seizing Computers
by trespassers did not violate PPA because cameras were related to the crime
of trespass); Carpa v. Smith, 2000 WL 189678, at *1 (9th Cir. Feb. 15, 2000)
(“[T]he Privacy Protection Act . . . does not apply to criminal suspects.”).
Te Sixth Circuit’s decision in Guest does not address the commingling
issue when the owner of the seized computer is not a suspect. In the only
published decision to date directly addressing this issue, a district court held
the United States Secret Service liable for the inadvertent seizure of PPA-
protected materials. See Steve Jackson Games, Inc. v. Secret Service, 816 F. Supp.
432 (W.D. Tex. 1993), aff’d on other grounds, 36 F.3d 457 (5th Cir. 1994).2
Steve Jackson Games, Inc. (“SJG”) was primarily a publisher of role-playing
games, but it also operated a network of thirteen computers that provided its
customers with email, published information about SJG products, and stored
drafts of upcoming publications. Believing that the system administrator of
SJG’s computers had stored evidence of crimes, the Secret Service obtained a
warrant and seized two of the thirteen computers connected to SJG’s network,
in addition to other materials. Te Secret Service did not know that SJG’s
computers contained publishing materials until the day after the search.
However, the Secret Service did not return the computers it seized until months
later. At no time did the Secret Service believe that SJG itself was involved in
the crime under investigation.
Te district court in Steve Jackson Games ruled that the Secret Service
violated the PPA; unfortunately, the exact contours of the court’s reasoning are
difficult to discern. For example, the court did not explain exactly which of the
materials the Secret Service seized were covered by the PPA; instead, the court
merely recited the property that had been seized, and concluded that some PPA-
protected materials “were obtained” during the search. Id. at 440. Similarly, the
court indicated that the search of SJG and the initial seizure of its property did
not violate the PPA, but that the Secret Service’s continued retention of SJG’s
property after it learned of SJG’s publisher status, and despite a request by SJG
for return of the property, was the true source of the PPA violation - something
that the statute itself does not appear to contemplate. See id. at 441. Te court
also suggested that it might have ruled differently if the Secret Service had
2 Te Steve Jackson Games litigation raised many important issues involving the PPA and
the SCA before the district court. On appeal, however, the only issue raised was “a very narrow
one: whether the seizure of a computer on which is stored private E-mail that has been sent
to an electronic bulletin board, but not yet read (retrieved) by the recipients, constitutes an
‘intercept’ proscribed by 18 U.S.C. § 2511(1)(a).” Steve Jackson Games, 36 F.3d at 460. Tis
issue is discussed in the electronic surveillance chapter. See Chapter 4, infra.
2. With a Warrant
107
made “copies of all information seized” and returned the hardware as soon as
possible, but did not answer whether in fact it would have reached a different
result in such case. Id.
Incidental seizure of PPA-protected materials on a non-suspect’s computer
continues to be an uncertain area of the law, in part because PPA issues are
infrequently litigated. As a practical matter, agents can often avoid the seizure
of PPA-protected materials on a non-suspect’s computer by using a subpoena
or process under the SCA to require the non-suspect to produce the desired
information, as described in Chapter 3. To date, no other court has followed
the PPA approach of Steve Jackson Games. See, e.g., State v. One (1) Pioneer
CD-ROM Changer, 891 P.2d 600, 607 (Okla. App. 1994) (questioning the
apparent premise of Steve Jackson Games that the seizure of computer equipment
could violate the PPA merely because the equipment “also contained or was
used to disseminate potential ‘documentary materials’”). Moreover, even if
courts eventually refuse to restrict the PPA to cases in which law enforcement
intentionally seizes from a non-suspect First Amendment material that is merely
evidence of a crime, courts may conclude that other PPA exceptions, such as
the “contraband or fruits of a crime” exception, should be read as broadly as the
Guest court read the suspect exception.
Te additional handful of federal courts that have resolved civil suits filed
under the PPA have ruled against the plaintiffs with little substantive analysis.
See, e.g., Davis v. Gracey, 111 F.3d 1472, 1482 (10th Cir. 1997) (dismissing
for lack of jurisdiction PPA suit improperly filed against municipal employees
in their personal capacities); Berglund v. City of Maplewood, 173 F. Supp. 2d
935, 949-50 (D. Minn. 2001) (holding that the police seizure of a defendant’s
videotape fell under the “criminal suspect” and “destruction of evidence”
exceptions to the PPA because the tape might have contained documentary
evidence of the defendant’s disorderly conduct); DePugh v. Sutton, 917 F. Supp.
690, 696-97 (W.D. Mo. 1996) (rejecting pro se PPA challenge to seizure of
materials relating to child pornography because there was probable cause to
believe that the person possessing the materials committed the criminal offense
to which the materials related), aff’d, 104 F.3d 363 (8th Cir. 1996); Powell
v. Tordoff, 911 F. Supp. 1184, 1189-90 (N.D. Iowa 1995) (dismissing PPA
claim because plaintiff did not have standing to challenge search and seizure
under the Fourth Amendment). See also Lambert v. Polk County, 723 F. Supp.
128, 132 (S.D. Iowa 1989) (rejecting PPA claim after police seized videotape
108
Searching and Seizing Computers
because officers could not reasonably believe that the owner of the tape had a
purpose to disseminate the material to the public).
Agents and prosecutors who have reason to believe that a computer search
may implicate the PPA should contact the Computer Crime and Intellectual
Property Section at
(202)
514-1026 or the CHIP in their district
(see
Introduction, p. xii) for more specific guidance.
2. Privileged Documents
Agents must exercise special care when planning a computer search that
may result in the seizure of legally privileged documents such as medical records
or attorney-client communications. Two issues must be considered. First,
agents should make sure that the search will not violate the Attorney General’s
regulations relating to obtaining confidential information from disinterested
third parties. Second, agents should devise a strategy for reviewing the seized
computer files following the search so that no breach of a privilege occurs.
a. Te Attorney General’s Regulations Relating to Searches
of Disinterested Tird Party Lawyers, Physicians, and Clergymen
Agents should be very careful if they plan to search the office of a doctor,
lawyer, or member of the clergy who is not implicated in the crime under
investigation. At Congress’s direction, the Attorney General has issued
guidelines for federal officers who want to obtain documentary materials from
such disinterested third parties. See 42 U.S.C. § 2000aa-11(a); 28 C.F.R.
§ 59.4(b). Under these rules, federal law enforcement officers should not
use a search warrant to obtain documentary materials believed to be in the
private possession of a disinterested third party physician, lawyer, or clergyman
where the material sought or likely to be reviewed during the execution of the
warrant contains confidential information on patients, clients, or parishioners.
28 C.F.R. § 59.4(b). Te regulation does contain a narrow exception. A search
warrant can be used if using less intrusive means would substantially jeopardize
the availability or usefulness of the materials sought; access to the documentary
materials appears to be of substantial importance to the investigation; and the
application for the warrant has been recommended by the U.S. Attorney and
approved by the appropriate Deputy Assistant Attorney General. See 28 C.F.R.
§ 59.4(b)(1) and (2).
When planning to search the offices of a lawyer under investigation, agents
should follow the guidelines offered in the United States Attorneys’ Manual,
2. With a Warrant
109
and should consult OEO at (202) 514-6809. See generally United States
Attorneys’ Manual, § 9-13.420 (1997).
b. Strategies for Reviewing Privileged Computer Files
Agents contemplating a search that may result in the seizure
of legally privileged computer files should devise a post-seizure
strategy for screening out the privileged files and should describe
that strategy in the affidavit.
When agents seize a computer that contains legally privileged files, a
trustworthy third party must examine the computer to determine which files
contain privileged material. After reviewing the files, the third party will offer
those files that are not privileged to the prosecution team. Preferred practices
for determining who will comb through the files vary widely among different
courts. In general, however, there are three options. First, the court itself may
review the files in camera. Second, the presiding judge may appoint a neutral
third party known as a “special master” to the task of reviewing the files.
Tird, a team of prosecutors or agents who are not working on the case may
form a “filter team” or “taint team” to help execute the search and review the
files afterwards. Te filter team sets up a so-called “ethical wall” between the
evidence and the prosecution team, permitting only unprivileged files to pass
over the wall.
Because a single computer can store millions of files, judges will undertake
in camera review of computer files only rarely. See Black v. United States,
172 F.R.D. 511, 516-17 (S.D. Fla. 1997) (accepting in camera review given
unusual circumstances); United States v. Skeddle, 989 F. Supp. 890, 893 (N.D.
Ohio 1997) (declining in camera review). Instead, the typical choice is between
using a filter team and a special master. Most prosecutors will prefer to use a
filter team if the court consents. A filter team can usually review the seized
computer files fairly quickly, whereas special masters often take several years to
complete their review. See Black, 172 F.R.D. at 514 n.4. On the other hand,
some courts have expressed discomfort with filter teams. See In re Grand Jury
Subpoenas, 454 F.3d 511, 522-23 (6th Cir. 2006) (approving of use of filter
teams in connection with search warrants while disapproving of their use in
connection with grand jury subpoenas); United States v. Neill, 952 F. Supp.
834, 841 (D.D.C. 1997); United States v. Hunter, 13 F. Supp. 2d 574, 583 n.2
(D. Vt. 1998) (stating that review by a magistrate judge or special master “may
110
Searching and Seizing Computers
be preferable” to reliance on a filter team) (citing In re Search Warrant, 153
F.R.D. 55, 59 (S.D.N.Y. 1994)).
Although no single standard has emerged, courts have generally indicated
that evidence screened by a filter team will be admissible only if the government
shows that its procedures adequately protected the defendants’ rights and no
prejudice occurred. See, e.g., Neill, 952 F. Supp. at 840-42; Hunter, 13 F.
Supp. 2d at 583. One approach to limit the amount of potentially privileged
material in dispute is to have defense counsel review the output of the filter
team to identify those documents for which counsel intends to raise a claim
of privilege. Files thus identified that do not seem relevant to the investigation
need not be litigated. Although this approach may not be appropriate in every
case, magistrates may appreciate the fact that defense counsel has been given
the chance to identify potential claims before the material is provided to the
prosecution team.
In unusual circumstances, the court may conclude that a filter team would
be inadequate and may appoint a special master to review the files. See, e.g.,
United States v. Abbell, 914 F. Supp. 519 (S.D. Fla. 1995); DeMassa v. Nunez,
747 F.2d 1283 (9th Cir. 1984). In any event, the reviewing authority will
almost certainly need a neutral technical expert to assist in sorting, identifying,
and analyzing digital evidence for the reviewing process.
3. Other Disinterested Tird Parties
In addition to the more specific restrictions on using a search warrant to
obtain information from disinterested publishers, lawyers, physicians, and
clergymen, Department of Justice policy favors the use of a subpoena or other
less intrusive means to obtain evidence from disinterested third parties, unless
use of those less intrusive means would substantially jeopardize the availability
or usefulness of the materials sought. See 28 C.F.R. § 59.4(a)(1); United States
Attorneys’ Manual, § 9-19.210. Except in emergencies, the application for
such a warrant must be authorized by an attorney for the government. See 28
C.F.R. § 59.4(a)(2); United States Attorneys’ Manual, § 9-19.210. Importantly,
however, failure to comply with this policy “may not be litigated, and a court
may not entertain such an issue as the basis for the suppression or exclusion of
evidence.” 28 C.F.R. § 59.5(b).
2. With a Warrant
111
4. Communications Service Providers: the SCA
When a search may result in the incidental seizure of network
accounts belonging to innocent third parties, agents should take
every step to protect the integrity of the third party accounts.
One category of disinterested third party often encountered in the
computer context is Internet service providers. Te Stored Communications
Act (“SCA”), 18 U.S.C. §§ 2701-2712, governs law enforcement access to the
contents of electronic communications stored by third-party service providers.
See Chapter 3, infra (discussing the SCA). In most cases, law enforcement
officials should use the compulsory process provisions of § 2703 to compel
a service provider to disclose information; when possible, law enforcement
officials should avoid physical execution of a Rule 41 search warrant on service
providers. When law enforcement officers execute a Rule 41 search warrant
on an Internet service provider and seize the accounts of customers and
subscribers, those customers and subscribers may bring civil actions claiming
that the search violated the SCA. In addition, the SCA has a criminal provision
that prohibits unauthorized access to electronic or wire communications in
“electronic storage.” See 18 U.S.C. § 2701; Chapter 3, infra (discussing the
definition of “electronic storage”).
Te text of the SCA does not appear to contemplate civil liability for
searches and seizures authorized by valid Rule 41 search warrants: the SCA
expressly authorizes government access to stored communications pursuant to
a warrant issued under the Federal Rules of Criminal Procedure, see 18 U.S.C.
§ 2703(a), (b), (c)(1)(A); Davis v. Gracey, 111 F.3d 1472, 1483 (10th Cir.
1997), and the criminal prohibition of § 2701 does not apply when access
is authorized under § 2703. See 18 U.S.C. § 2701(c)(3). Nonetheless, Steve
Jackson Games, Inc. v. Secret Service, 816 F. Supp. 432 (W.D. Tex. 1993), raised
the concern that a search executed pursuant to a valid warrant might violate
the SCA. In Steve Jackson Games, the district court held the Secret Service
liable under the SCA after it seized, reviewed, and (in some cases) deleted
stored electronic communications seized pursuant to a valid search warrant.
See id. at 442-43. Te court’s holding appears to be rooted in the mistaken
belief that the SCA requires that search warrants also comply with 18 U.S.C.
§ 2703(d) and the various notice requirements of § 2703. See id. In fact, the
SCA makes quite clear that § 2703(d) and the notice requirements of § 2703
112
Searching and Seizing Computers
are implicated only when law enforcement does not obtain a search warrant.3
Compare
18 U.S.C.
§ 2703(b)(1)(A), with
18 U.S.C.
§ 2703(b)(1)(B).
Further, objectively reasonable good faith reliance on a warrant, court order,
or statutory authorization is a complete defense to an SCA violation. See 18
U.S.C. § 2707(e). Compare Gracey, 111 F.3d at 1484 (applying good faith
defense because seizure of stored communications incidental to a valid search
was objectively reasonable), with Steve Jackson Games, 816 F. Supp. at 443
(stating without explanation that the court “declines to find this defense”).
Te best way to square the result in Steve Jackson Games with the plain
language of the SCA is to exercise great caution when agents need to execute
searches of Internet service providers and other third-parties holding stored
wire or electronic communications. In every computer search, agents should
strive to avoid unwarranted intrusions into private areas, and searches of
service providers are no different. See Andresen v. Maryland, 427 U.S. 463,
482 n.11 (1976) (“responsible officials, including judicial officials, must
take care to assure that [searches] are conducted in a manner that minimizes
unwarranted intrusions upon privacy.”). In most cases, investigators will want
to avoid a wholesale search and seizure of the provider’s computers by relying
instead on compulsory process served on the provider consistent with the
SCA. When investigators have no choice but to execute the search, such as
where the service provider lacks the ability or will to comply with compulsory
process or is suspected of involvement in the criminal conduct, agents must
search the provider’s computers themselves. Because each of the provider’s
computers might contain records relating to users who are wholly unrelated
to the criminal investigation, special procedures designed to uphold those
users’ privacy interests may be appropriate. For example, agents might inform
the magistrate judge in the search warrant affidavit that they will take steps
to ensure the confidentiality of the accounts and not expose their contents
to human inspection. Safeguarding the accounts of innocent persons absent
specific reasons to believe that evidence may be stored in the persons’ accounts
3 Tis raises a fundamental distinction overlooked in Steve Jackson Games: the difference
between a search warrant issued under Rule 41 that law enforcement executes with a physical
search, and a search warrant issued under the SCA that law enforcement executes by compelling
a provider of electronic communication service or remote computing service to disclose the
contents of a subscriber’s network account. Although both are search warrants, they are different
in practice. Tis distinction is especially important when a court concludes that the SCA was
violated and then must determine the remedy because there is no statutory suppression for
nonconstitutional violations of the SCA. See 18 U.S.C. § 2708; Chapter 3.I, infra (discussing
remedies for violations of the SCA).
2. With a Warrant
113
should satisfy the concerns expressed in Steve Jackson Games. Compare Steve
Jackson Games, 816 F. Supp. at 441 (finding SCA liability where agents read
the private communications of customers not involved in the crime “and
thereafter deleted or destroyed some communications either intentionally or
accidentally”), with Gracey, 111 F.3d at 1483 (declining to find SCA liability
in seizure where “[p]laintiffs have not alleged that the officers attempted to
access or read the seized e-mail, and the officers disclaimed any interest in
doing so”).
114
Searching and Seizing Computers
Chapter 3
Te Stored Communications Act
A. Introduction
The SCA regulates how the government can obtain stored
account information from network service providers such
as ISPs. Whenever agents or prosecutors seek stored email,
account records, or subscriber information from a network
service provider, they must comply with the SCA. The SCA’s
classifications are summarized in the chart that appears in Section
F of this chapter.
Te Stored Communications Act, 18 U.S.C. §§ 2701-2712 (“SCA”),
sets forth a system of statutory privacy rights for customers and subscribers
of computer network service providers.1 Tere are three main substantive
components to this system, which serves to protect and regulate the privacy
interests of network users with respect to government, network service
providers, and the world at large. First, § 2703 creates a code of criminal
procedure that federal and state law enforcement officers must follow to
compel disclosure of stored communications from network service providers.
Second, § 2702 regulates voluntary disclosure by network service providers
of customer communications and records, both to government and non-
government entities. Tird, § 2701 prohibits unlawful access to certain stored
communications; anyone who obtains, alters, or prevents authorized access to
those communications is subject to criminal penalties.
Te structure of the SCA reflects a series of classifications that indicate the
drafters’ judgments about what kinds of information implicate greater or lesser
privacy interests. For example, the drafters saw greater privacy interests in the
1 Te SCA is sometimes referred to as the Electronic Communications Privacy Act. Te
SCA was included as Title II of the Electronic Communications Privacy Act of 1986 (“ECPA”),
but ECPA itself also included amendments to the Wiretap Act and created the Pen Register
and Trap and Trace Devices statute addressed in Chapter 4. See Pub. L. No. 99-508, 100 Stat.
1848 (1986). Although 18 U.S.C. § 2701-2712 is referred to as the “Stored Communications
Act” here and elsewhere, the phrase “Stored Communications Act” appears nowhere in the
language of the statute.
115
content of stored emails than in subscriber account information. Similarly,
the drafters believed that computing services available “to the public” required
more strict regulation than services not available to the public.
(Perhaps
this judgment reflects the view that providers available to the public are not
likely to have close relationships with their customers, and therefore might
have less incentive to protect their customers’ privacy.) To protect the array of
privacy interests identified by its drafters, the SCA offers varying degrees of
legal protection depending on the perceived importance of the privacy interest
involved. Some information can be obtained from providers with a subpoena;
other information requires a special court order; and still other information
requires a search warrant. In addition, some types of legal process require notice
to the subscriber, while other types do not.
Agents and prosecutors must apply the various classifications devised by
the SCA’s drafters to the facts of each case to figure out the proper procedure
for obtaining the information sought. First, they must classify the network
service provider (e.g., does the provider provide “electronic communication
service,” “remote computing service,” or neither). Next, they must classify the
information sought (e.g., is the information content “in electronic storage,”
content held by a remote computing service, a non-content record pertaining
to a subscriber, or other information enumerated by the SCA). Tird, they
must consider whether they are seeking to compel disclosure or seeking to
accept information disclosed voluntarily by the provider. If they seek compelled
disclosure, they need to determine whether they need a search warrant, a
2703(d) court order, or a subpoena to compel the disclosure. If they are seeking
to accept information voluntarily disclosed, they must determine whether the
statute permits the disclosure. Te chart contained in Section F of this chapter
provides a useful way to apply these distinctions in practice.
Te organization of this chapter will follow the SCA’s various classifications.
Section B explains the SCA’s classification structure, which distinguishes between
providers of “electronic communication service” and providers of “remote
computing service.” Section C explains the different kinds of information that
providers can divulge, such as content “in electronic storage” and “records . .
. pertaining to a subscriber.” Section D explains the legal process that agents
and prosecutors must follow to compel a provider to disclose information.
Section E looks at the flip side of this problem and explains when providers
may voluntarily disclose account information. A summary chart appears in
Section F. Section G discusses important issues that may arise when agents
116
Searching and Seizing Computers
obtain records from network providers: steps to preserve evidence, steps to
prevent disclosure to subjects, Cable Act issues, and reimbursement to providers.
Section H discusses the Fourth Amendment’s application to stored electronic
communications. Finally, Section I discusses the remedies that courts may
impose following violations of the SCA.
B. Providers of Electronic Communication Service vs.
Remote Computing Service
Te SCA protects communications held by two defined classes of network
service providers: providers of
“electronic communication service,” see 18
U.S.C. § 2510(15), and providers of “remote computing service,” see 18
U.S.C. § 2711(2). Careful examination of the definitions of these two terms is
necessary to understand how to apply the SCA.
1. Electronic Communication Service
An electronic communication service (“ECS”) is “any service which provides
to users thereof the ability to send or receive wire or electronic communications.”
18 U.S.C. § 2510(15). (For a discussion of the definitions of wire and electronic
communications, see Chapter 4.D.2.) For example, “telephone companies and
electronic mail companies” generally act as ECS providers. See S. Rep. No.
99-541 (1986), reprinted in 1986 U.S.C.C.A.N. 3555, 3568; Quon v. Arch
Wireless Operating Co., 529 F.3d 892, 900-03 (9th Cir. 2008) (text messaging
service provider is an ECS); In re Application of United States, 509 F. Supp. 2d
76, 79 (D. Mass. 2007) (cell phone service provider is an ECS); Kaufman v.
Nest Seekers, LLC, 2006 WL 2807177, at *5 (S.D.N.Y. Sept. 26, 2006) (host
of electronic bulletin board is ECS); Freedman v. America Online, Inc., 325 F.
Supp. 2d 638, 643 n.4 (E.D. Va. 2004) (AOL is an ECS).
Any company or government entity that provides others with the means
to communicate electronically can be a “provider of electronic communication
service” relating to the communications it provides, regardless of the entity’s
primary business or function. See Fraser v. Nationwide Mut. Ins. Co., 352 F.3d
107, 114-15 (3d Cir. 2004) (insurance company that provided email service
to employees is an ECS); Bohach v. City of Reno, 932 F. Supp. 1232, 1236 (D.
Nev. 1996) (city providing pager service to its police officers was a provider
of ECS); United States v. Mullins, 992 F.2d 1472, 1478 (9th Cir. 1993)
(airline that provides travel agents with computerized travel reservation system
3. Stored Communications Act
117
accessed through separate computer terminals can be a provider of ECS). In
In re Application of United States, 349 F.3d 1132, 1138-41 (9th Cir. 2003), the
Ninth Circuit held that a company operating a system that enabled drivers to
communicate with designated call centers over a cellular telephone network
was an ECS, though it also noted that the situation would have been entirely
different “if the Company merely used wire communication as an incident to
providing some other service, as is the case with a street-front shop that requires
potential customers to speak into an intercom device before permitting entry,
or a ‘drive-thru’ restaurant that allows customers to place orders via a two-way
intercom located beside the drive-up lane.” Id. at 1141 n.19.
A provider cannot provide ECS with respect to a communication if the
service did not provide the ability to send or receive that communication. See Sega
Enterprises Ltd. v. MAPHIA, 948 F. Supp. 923, 930-31 (N.D. Cal. 1996) (video
game manufacturer that accessed private email of users of another company’s
bulletin board service was not a provider of electronic communication service);
State Wide Photocopy, Corp. v. Tokai Fin. Servs., Inc., 909 F. Supp. 137, 145
(S.D.N.Y. 1995) (financing company that used fax machines and computers
but did not provide the ability to send or receive communications was not
provider of electronic communication service).
Significantly, a mere user of ECS provided by another is not a provider
of ECS. For example, a commercial website is not a provider of ECS, even
though it may send and receive electronic communications from customers.
In Crowley v. CyberSource Corp., 166 F. Supp. 2d 1263, 1270 (N.D. Cal.
2001), the plaintiff argued that Amazon.com (to whom plaintiff sent his name,
credit card number, and other identification information) was an electronic
communications service provider because “without recipients such as Amazon.
com, users would have no ability to send electronic information.” Te court
rejected this argument, holding that Amazon was properly characterized as
a user rather than a provider of ECS. See id. See also United States v. Steiger,
318 F.3d 1039, 1049 (11th Cir. 2003) (a home computer connected to the
Internet is not an ECS); In re Jetblue Airways Corp. Privacy Litigation, 379 F.
Supp. 2d 299, 309-10 (E.D.N.Y. 2005) (airline that operated website that
enabled it to communicate with customers was not an ECS); Dyer v. Northwest
Airlines Corp., 334 F. Supp. 2d 1196, 1199 (D.N.D. 2004) (ECS “does not
encompass businesses selling traditional products or services online”); In re
Doubleclick Inc. Privacy Litigation, 154 F. Supp. 2d 497, 508-09 (S.D.N.Y.
2001) (distinguishing ISPs that provide ECS from websites that are users of
118
Searching and Seizing Computers
ECS). However, “an online business or retailer may be considered an electronic
communication service provider if the business has a website that offers
customers the ability to send messages or communications to third parties.”
Becker v. Toca, 2008 WL 4443050, at *4 (E.D. La. Sept. 26, 2008).
2. Remote Computing Service
Te term “remote computing service” (“RCS”) is defined by 18 U.S.C.
§ 2711(2) as “the provision to the public of computer storage or processing
services by means of an electronic communications system.” An “electronic
communications system” is “any wire, radio, electromagnetic, photooptical
or photoelectronic facilities for the transmission of wire or electronic
communications, and any computer facilities or related electronic equipment
for the electronic storage of such communications.” 18 U.S.C. § 2510(14).
Roughly speaking, a remote computing service is provided by an off-site
computer that stores or processes data for a customer. See S. Rep. No. 99-541
(1986), reprinted in 1986 U.S.C.C.A.N. 3555, 3564-65. For example, a service
provider that allows customers to use its computing facilities in “essentially a
time-sharing arrangement” provides an RCS. H.R. Rep. No. 99-647, at 23
(1986). A server that allows users to store data for future retrieval also provides
an RCS. See Steve Jackson Games, Inc. v. United States Secret Service, 816 F.
Supp. 432, 442-43 (W.D. Tex. 1993) (provider of bulletin board services
was a remote computing service), aff’d on other grounds, 36 F.3d 457 (5th
Cir. 1994). Importantly, an entity that operates a website and its associated
servers is not an RCS, unless of course the entity offers a storage or processing
service through the website. For example, an airline may compile and store
passenger information and itineraries through its website, but these functions
are incidental to providing airline reservation service, not data storage and
processing service; they do not convert the airline into an RCS. See In re Jetblue
Airways Corp. Privacy Litigation, 379 F. Supp. 2d at 310; see also United States
v. Standefer, 2007 WL 2301760, at *5 (S.D. Cal. Aug. 8, 2007) (holding that
e-gold payment website was not an RCS because e-gold customers did not use
the website “to simply store electronic data” or to “outsource tasks,” but instead
used e-gold “to transfer gold ownership to other users”).
Under the definition provided by § 2711(2), a service can only be a “remote
computing service” if it is available “to the public.” Services are available to
the public if they are available to any member of the general population who
complies with the requisite procedures and pays any requisite fees. For example,
3. Stored Communications Act
119
Verizon is a provider to the public: anyone can obtain a Verizon account. (It
may seem odd at first that a service can charge a fee but still be considered
available “to the public,” but this approach mirrors commercial relationships
in the physical world. For example, movie theaters are open “to the public”
because anyone can buy a ticket and see a show, even though tickets are not
free.) In contrast, providers whose services are available only to those with a
special relationship with the provider do not provide service to the public.
For example, an employer that provides email accounts to its employees will
not be an RCS with respect to those employees, because such email accounts
are not available to the public. See Andersen Consulting LLP v. UOP, 991 F.
Supp. 1041, 1043 (N.D. Ill. 1998) (interpreting the “to the public” clause in §
2702(a) to exclude an internal email system that was made available to a hired
contractor but was not available to “any member of the community at large”).
In Quon v. Arch Wireless Operating Co., the Ninth Circuit held that a text
messaging service provider was an ECS and therefore not an RCS. See Quon,
529 F.3d at 902-03. However, this “either/or” approach to ECS and RCS is
contrary to the language of the statute and its legislative history. Te definitions
of ECS and RCS are independent of each other, and therefore nothing prevents
a service provider from providing both forms of service to a single customer. In
addition, an email service provider is certainly an ECS, but the House report on
the SCA also stated that an email stored after transmission would be protected
by a provision of the SCA that protects contents of communications stored
by an RCS. See H.R. Rep. No. 99-647, at 65 (1986). One subsequent court
has rejected the Ninth Circuit’s analysis in Quon and stated that a provider
“may be deemed to provide both an ECS and an RCS to the same customer.”
Flagg, v. City of Detroit, 252 F.R.D. 346, 362 (E.D. Mich. 2008). Te key
to determining whether the provider is an ECS or RCS is to ask what role
the provider has played and is playing with respect to the communication in
question.
C. Classifying Types of Information Held
by Service Providers
Network service providers can store different kinds of information relating
to an individual customer or subscriber. Consider the range of information
that an ISP may typically store regarding one of its customers. It may have
the customer’s subscriber information, such as name, address, and credit card
120
Searching and Seizing Computers
number. It may have logs revealing when the customer logged on and off the
service, the IP addresses assigned to the customer, and other more detailed logs
pertaining to what the customer did while online. Te ISP may also have the
customer’s opened, unopened, draft, and sent emails.
When agents and prosecutors wish to obtain such records, they must be
able to classify these types of information using the language of the SCA. Te
SCA breaks the information down into three categories: (1) contents; (2) non-
content records and other information pertaining to a subscriber or customer;
and (3) basic subscriber and session information, which is a subset of non-
content records and is specifically enumerated in 18 U.S.C. § 2703(c)(2). See
18 U.S.C. §§ 2510(8), 2703. In addition, as described below, the SCA creates
substantially different protections for contents in “electronic storage” in an
ECS and contents stored by a provider of RCS.
1. Basic Subscriber and Session Information Listed
in 18 U.S.C. § 2703(c)(2)
Section 2703(c)(2) lists the categories of basic subscriber and session
information:
(A) name; (B) address; (C) local and long distance telephone
connection records, or records of session times and durations;
(D) length of service (including start date) and types of service
utilized; (E) telephone or instrument number or other subscriber
number or identity, including any temporarily assigned network
address; and (F) means and source of payment for such service
(including any credit card or bank account number)[.]
In general, the items in this list relate to the identity of a subscriber, his
relationship with his service provider, and his basic session connection records.
In the Internet context, “any temporarily assigned network address” includes
the IP address used by a customer for a particular session. For example, for a
webmail service, the IP address used by a customer accessing her email account
constitutes a “temporarily assigned network address.” Tis list does not include
other, more extensive transaction-related records, such as logging information
revealing the email addresses of persons with whom a customer corresponded.
3. Stored Communications Act
121
2. Records or Other Information Pertaining
to a Customer or Subscriber
Section 2703(c)(1) covers a second type of information: “a record or other
information pertaining to a subscriber to or customer of such service (not
including the contents of communications).” Tis is a catch-all category that
includes all records that are not contents, including basic subscriber and session
information described in the previous section. As one court explained, “a record
means something stored or archived. Te term information is synonymous
with data.” In re United States, 509 F. Supp. 2d 76, 80 (D. Mass. 2007).
Common examples of “record[s] . . . pertaining to a subscriber” include
transactional records, such as account logs that record account usage; cell-site
data for cellular telephone calls; and email addresses of other individuals with
whom the account holder has corresponded. See H.R. Rep. No. 103-827, at
10, 17, 31 (1994), reprinted in 1994 U.S.C.C.A.N. 3489, 3490, 3497, 3511.
See also In re Application of United States, 509 F. Supp. 76, 80 (D. Mass. 2007)
(historical cell-site information fall within scope of § 2703(c)(1)); United States
v. Allen, 53 M.J. 402, 409 (C.A.A.F. 2000) (concluding that “a log identifying
the date, time, user, and detailed internet address of sites accessed” by a user
constituted “a record or other information pertaining to a subscriber or customer
of such service” under the SCA); Hill v. MCI WorldCom Commc’ns, Inc., 120
F. Supp. 2d 1194, 1195-96 (S.D. Iowa 2000) (concluding that the “names,
addresses, and phone numbers of parties . . . called” constituted “a record or
other information pertaining to a subscriber or customer of such service,”
not contents, for a telephone account); Jessup-Morgan v. America Online, Inc.,
20 F. Supp. 2d 1105, 1108 (E.D. Mich. 1998) (holding that a customer’s
identification information is a “record or other information pertaining to a
subscriber” rather than contents). According to the legislative history of the
1994 amendments to § 2703(c), the purpose of separating the basic subscriber
and session information from other non-content records was to distinguish
basic subscriber and session information from more revealing transactional
information that could contain a “person’s entire on-line profile.” H.R. Rep.
No. 103-827, at 17, 31-32 (1994), reprinted in 1994 U.S.C.C.A.N. 3489,
3497, 3511-12.
3. Contents and “Electronic Storage”
Te contents of a network account are the actual files (including email)
stored in the account. See 18 U.S.C. § 2510(8) (“‘contents,’ when used with
122
Searching and Seizing Computers
respect to any wire, oral, or electronic communication, includes any information
concerning the substance, purport, or meaning of that communication”). For
example, stored emails or voice mails are “contents,” as are word processing
files stored in employee network accounts. Te subject lines of emails are also
contents. Cf. Brown v. Waddell, 50 F.3d 285, 292 (4th Cir. 1995) (noting
that numerical pager messages allow “an unlimited range of number-coded
substantive messages” in the course of holding that the interception of pager
messages requires compliance with Title III).
Te SCA further divides contents into two categories: contents in
“electronic storage” held by a provider of electronic communication service,
and contents stored by a remote computing service. (In addition, contents that
fall outside of these two categories are not protected by the SCA.) Importantly,
“electronic storage” is a statutorily defined term. It does not simply mean
storage of information by electronic means. Instead, “electronic storage” is “(A)
any temporary, intermediate storage of a wire or electronic communication
incidental to the electronic transmission thereof; and (B) any storage of such
communication by an electronic communication service for purposes of backup
protection of such communication.” 18 U.S.C. § 2510(17). Moreover, the
definition of “electronic storage” is important because, as explained in Section
D below, contents in “electronic storage” for less than 181 days can be obtained
only with a warrant.
Unfortunately, as a result of the Ninth Circuit’s decision in Teofel v.
Farey-Jones, 359 F.3d 1066 (9th Cir. 2004), there is now a split between two
interpretations of “electronic storage”—a traditional narrow interpretation and
an expansive interpretation supplied by the Ninth Circuit. Both interpretations
are discussed below. As a practical matter, federal law enforcement within the
Ninth Circuit is bound by the Ninth Circuit’s decision in Teofel, but law
enforcement elsewhere may continue to apply the traditional interpretation of
“electronic storage.”
As traditionally understood, “electronic storage” refers only to temporary
storage made in the course of transmission by a service provider and to
backups of such intermediate communications made by the service provider
to ensure system integrity. It does not include post-transmission storage of
communications. For example, email that has been received by a recipient’s
service provider but has not yet been accessed by the recipient is in “electronic
storage.” See Steve Jackson Games, Inc. v. United States Secret Service, 36 F.3d
457, 461 (5th Cir. 1994). At that stage, the communication is stored as a
3. Stored Communications Act
123
temporary and intermediate measure pending the recipient’s retrieval of the
communication from the service provider. Once the recipient retrieves the
email, however, the communication reaches its final destination. If the recipient
chooses to retain a copy of the accessed communication, the copy will not be
in “temporary, intermediate storage” and is not stored incident to transmission.
See Fraser v. Nationwide Mut. Ins. Co., 352 F.3d 107, 114 (3d Cir. 2004) (stating
that email in post-transmission storage was not in “temporary, intermediate
storage”). By the same reasoning, if the sender of an email maintains a copy
of the sent email, the copy will not be in “electronic storage.” Messages posted
to an electronic “bulletin board” or similar service are also not in “electronic
storage” because the website on which they are posted is the final destination
for the information. See Snow v. DirecTV, Inc., 2005 WL 1226158, at *3 (M.D.
Fla. May 9, 2005), adopted by 2005 WL 1266435 (M.D. Fla. May 27, 2005),
aff’d on other grounds, 450 F.3d 1314 (11th Cir. 2006).
Furthermore, the “backup” component of the definition of “electronic
storage” refers to copies made by an ISP to ensure system integrity. As one
district court explained, the backup component “protects the communication
in the event the system crashes before transmission is complete. Te phrase
‘for purposes of backup protection of such communication’ in the statutory
definition makes clear that messages that are in post-transmission storage,
after transmission is complete, are not covered by part (B) of the definition of
‘electronic storage.’” Fraser v. Nationwide Mut. Ins. Co., 135 F. Supp. 2d 623, 636
(E.D. Pa. 2001), aff’d in part on other grounds 352 F.3d 107, 114 (3d Cir. 2004)
(affirming the SCA portion of the district court’s ruling on other grounds);
see also United States v. Weaver, 2009 WL 2163478, at *4 (C.D. Ill. July 15,
2009) (interpreting “electronic storage” to exclude previously sent email stored
by web-based email service provider); In re Doubleclick Inc. Privacy Litigation,
154 F. Supp. 2d 497, 511-13 (S.D.N.Y. 2001) (emphasizing that “electronic
storage” should have a narrow interpretation based on statutory language and
legislative intent and holding that cookies fall outside of the definition of
“electronic storage” because of their “long-term residence on plaintiffs’ hard
drives”); H.R. Rep. No. 99-647, at 65 (1986) (noting congressional intent
that opened email left on a provider’s system be covered by provisions of the
SCA relating to remote computing services, rather than provisions relating to
communications in “electronic storage”).
Tis narrow interpretation of “electronic storage” was rejected by the Ninth
Circuit in Teofel v. Farey-Jones, 359 F.3d 1066 (9th Cir. 2004), in which
124
Searching and Seizing Computers
the court held that email messages were in “electronic storage” regardless of
whether they had been previously accessed, because it concluded that retrieved
email fell within the backup portion of the definition of “electronic storage.”
Id. at 1075-77. Although the Ninth Circuit did not dispute that previously
accessed email was not in temporary, intermediate storage within the meaning
of § 2510(17)(A), it insisted that a previously accessed email message fell
within the scope of the “backup” portion of the definition of “electronic
storage,” because such a message “functions as a ‘backup’ for the user.” Id. at
1075. However, CCIPS has consistently argued that the Ninth Circuit’s broad
interpretation of the “backup” portion of the definition of “electronic storage”
should be rejected. Tere is no way for a service provider to determine whether
a previously opened email on its servers is a backup for a copy of the email
stored by a user on his computer, as the service provider simply cannot know
whether the underlying email remains stored on the user’s computer. Essentially,
the Ninth Circuit’s reasoning in Teofel confuses “backup protection” with
ordinary storage of a file.
Although prosecutors within the Ninth Circuit are bound by Teofel,
law enforcement elsewhere may continue to apply the traditional narrow
interpretation of “electronic storage,” even when the data sought is within the
Ninth Circuit. Recent lower court decisions addressing the scope of “electronic
storage” have split between the traditional interpretation and the Teofel
approach. Compare United States v. Weaver, 2009 WL 2163478, at *4 (C.D.
Ill. July 15, 2009) (rejecting Teofel), and Bansal v. Russ, 513 F. Supp. 2d 264,
276 (E.D. Pa. 2007) (holding that access to opened email in account held by
non-public service provider did not violate the SCA), with Bailey v. Bailey,
2008 WL 324156, at *6 (E.D. Mich. Feb. 6, 2008) (endorsing Teofel), and
Cardinal Health 414, Inc. v. Adams, 482 F. Supp. 2d 967, 976 n.2 (M.D.
Tenn. 2008) (same). Prosecutors confronted with Teofel-related issues should
consult CCIPS at (202) 514-1026 for further assistance.
4. Illustration of the SCA’s Classifications in the Email Context
An example illustrates how the SCA’s categories work in practice outside
the Ninth Circuit, where Teofel does not apply. Imagine that Joe sends an
email from his account at work (“joe@goodcompany.com”) to the personal
account of his friend Jane (“jane@localisp.com”). Te email will stream across
the Internet until it reaches the servers of Jane’s Internet service provider, here
the fictional LocalISP. When the message first arrives at LocalISP, LocalISP is a
provider of ECS with respect to that message. Before Jane accesses LocalISP and
3. Stored Communications Act
125
retrieves the message, Joe’s email is in “electronic storage.” Once Jane retrieves
Joe’s email, she can either delete the message from LocalISP’s server or else
leave the message stored there. If Jane chooses to store the email with LocalISP,
LocalISP is now a provider of RCS (and not ECS) with respect to the email
sent by Joe. Te role of LocalISP has changed from a transmitter of Joe’s email
to a storage facility for a file stored remotely for Jane by a provider of RCS.
Next imagine that Jane responds to Joe’s email. Jane’s return email to Joe
will stream across the Internet to the servers of Joe’s employer, Good Company.
Before Joe retrieves the email from Good Company’s servers, Good Company
is a provider of ECS with respect to Jane’s email (just like LocalISP was with
respect to Joe’s original email before Jane accessed it). When Joe accesses
Jane’s email message and the communication reaches its destination (Joe),
Good Company ceases to be a provider of ECS with respect to that email
(just as LocalISP ceased to be a provider of ECS with respect to Joe’s original
email when Jane accessed it). Unlike LocalISP, however, Good Company does
not become a provider of RCS if Joe decides to store the opened email on
Good Company’s server. Rather, for purposes of this specific message, Good
Company is a provider of neither ECS nor RCS. Good Company does not
provide RCS because it does not provide services to the public. See 18 U.S.C.
§ 2711(2) (“[T]he term ‘remote computing service’ means the provision to
the public of computer storage or processing services by means of an electronic
communications system.” (emphasis added)); Andersen Consulting, 991 F.
Supp. at 1043. Because Good Company provides neither ECS nor RCS with
respect to the opened email in Joe’s account, the SCA no longer regulates access
to this email, and such access is governed solely by the Fourth Amendment.
Functionally speaking, the opened email in Joe’s account drops out of the
SCA.
Finally, consider the status of the other copies of the emails in this scenario:
Jane has downloaded a copy of Joe’s email from LocalISP’s server to her personal
computer at home, and Joe has downloaded a copy of Jane’s email from Good
Company’s server to his office desktop computer at work. Te SCA governs
neither. Although these computers contain copies of emails, these copies are
not stored on the server of a third-party provider of RCS or ECS, and therefore
the SCA does not apply. Access to the copies of the communications stored in
Jane’s personal computer at home and Joe’s office computer at work is governed
solely by the Fourth Amendment. See generally Chapters 1 and 2.
126
Searching and Seizing Computers
As this example indicates, a single provider can simultaneously provide
ECS with regard to some communications and RCS with regard to others,
or ECS with regard to some communications and neither ECS nor RCS with
regard to others. A chart illustrating these issues appears in Section F of this
chapter. Sample language that agents may use appears in Appendices B, E, and
F.
D. Compelled Disclosure Under the SCA
Section 2703 articulates the steps that the government must take to compel
providers to disclose the contents of stored wire or electronic communications
(including email and voice mail) and other information such as account records
and basic subscriber and session information.
Section 2703 offers five mechanisms that a “government entity” can use to
compel a provider to disclose certain kinds of information. Te five mechanisms
are as follows:
1) Subpoena;
2) Subpoena with prior notice to the subscriber or customer;
3) § 2703(d) court order;
4) § 2703(d) court order with prior notice to the subscriber or customer;
and
5) Search warrant.
One feature of the compelled disclosure provisions of the SCA is that
greater process generally includes access to information that cannot be obtained
with lesser process. Tus, a 2703(d) court order can compel everything that
a subpoena can compel (plus additional information), and a search warrant
can compel the production of everything that a 2703(d) order can compel
(and then some). As a result, the additional work required to satisfy a higher
threshold will often be justified because it can authorize a broader disclosure.
Note, however, the notice requirement must be considered separately under
this analysis: a subpoena with notice to the subscriber can be used to compel
information not available using a 2703(d) order without subscriber notice.
Two circumstances allow the government to compel disclosure of information
under the SCA without a subpoena. First, when investigating telemarketing
fraud, law enforcement may submit a written request to a service provider for
3. Stored Communications Act
127
the name, address, and place of business of a subscriber or customer engaged in
telemarketing. See 18 U.S.C. § 2703(c)(1)(D). Second, the government may
compel a service provider to disclose non-content information pertaining to
a customer or subscriber when the government has obtained the customer or
subscriber’s consent. See 18 U.S.C. § 2703(c)(1)(C).
1. Subpoena
Te SCA permits the government to compel disclosure of the basic
subscriber and session information (discussed above in Section C.1) listed in
18 U.S.C. § 2703(c)(2) using a subpoena:
(A) name; (B) address; (C) local and long distance telephone
connection records, or records of session times and durations;
(D) length of service (including start date) and types of service
utilized; (E) telephone or instrument number or other subscriber
number or identity, including any temporarily assigned network
address; and (F) means and source of payment for such service
(including any credit card or bank account number)[.]
18 U.S.C. § 2703(c)(2).
Agents can also use a subpoena to obtain information that is outside
the scope of the SCA. Te hypothetical email exchange between Jane and
Joe discussed in Section C of this chapter provides a useful example: Good
Company provided neither
“remote computing service” nor
“electronic
communication service” with respect to the opened email on Good Company’s
server. Accordingly, § 2703 does not impose any requirements on its disclosure,
and investigators can issue a subpoena compelling Good Company to divulge
the communication just as they would if the SCA did not exist. Similarly,
information relating or belonging to a person who is neither a “customer”
nor a “subscriber” is not protected by the SCA and may be obtained using a
subpoena according to the same rationale. Cf. Organizacion JD Ltda. v. United
States Dep’t of Justice, 124 F.3d 354, 359-61 (2d Cir. 1997) (discussing the
scope of the word “customer” as used in the SCA).
Te legal threshold for issuing a subpoena is low. See United States v. Morton
Salt Co., 338 U.S. 632, 642-43 (1950). Investigators may obtain disclosure
pursuant to § 2703(c)(2) using any federal or state grand jury or trial subpoena
or an administrative subpoena authorized by a federal or state statute. See 18
U.S.C. § 2703(c)(2). For example, subpoenas authorized by the Inspector
128
Searching and Seizing Computers
General Act may be used. See 5 U.S.C. app. 3 § 6(a)(4). Of course, evidence
obtained in response to a federal grand jury subpoena must be protected from
disclosure pursuant to Fed. R. Crim. P. 6(e). At least one court has held that
a pre-trial discovery subpoena issued in a civil case pursuant to Fed. R. Civ. P.
45 is inadequate. See FTC v. Netscape Commc’ns Corp., 196 F.R.D. 559, 561
(N.D. Cal. 2000) (holding that civil discovery subpoena did not fall within the
meaning of “trial subpoena”). Sample subpoena language appears in Appendix
E.
2. Subpoena with Prior Notice to the Subscriber or Customer
Agents who obtain a subpoena and either give prior notice to the subscriber
or comply with the delayed notice provisions of § 2705(a) may obtain:
1) everything that can be obtained using a subpoena without
notice;
2) “the contents of a wire or electronic communication that
has been in electronic storage in an electronic communications
system for more than one hundred and eighty days.” 18 U.S.C.
§ 2703(a); and
3) “the contents of any wire or electronic communication” held
by a provider of remote computing service “on behalf of . . . a
subscriber or customer of such remote computing service.” 18
U.S.C. § 2703(b)(1)(B)(i), § 2703(b)(2).
Outside the Ninth Circuit (which is now governed by Teofel), this third
category will include opened and sent email. Agents outside of the Ninth
Circuit can therefore obtain such email (and other stored electronic or wire
communications in “electronic storage” more than 180 days) using a subpoena,
provided they comply with the SCA’s notice provisions. However, in light of
Teofel, some service providers may be reluctant to produce opened or sent
email less than 181 days old without a warrant. Prosecutors moving to compel
compliance with a subpoena for such email should contact CCIPS at (202)
514-1026 for assistance. In the Ninth Circuit, agents can continue to subpoena
communications that have been in “electronic storage” over 180 days.
Te notice provisions can be satisfied by giving the customer or subscriber
“prior notice” of the disclosure. See 18 U.S.C. § 2703(b)(1)(B). However,
18 U.S.C. § 2705(a)(1)(B) permits notice to be delayed for ninety days
“upon the execution of a written certification of a supervisory official that
3. Stored Communications Act
129
there is reason to believe that notification of the existence of the subpoena
may have an adverse result.” 18 U.S.C. § 2705(a)(1)(B). Both “supervisory
official” and “adverse result” are specifically defined terms for the purpose of
delaying notice. See 18 U.S.C. § 2705(a)(2) (defining “adverse result”); 18
U.S.C. § 2705(a)(6) (defining “supervisory official”). Tis provision of the
SCA provides a permissible way for the government to delay notice to the
customer or subscriber when notice would jeopardize a pending investigation
or endanger the life or physical safety of an individual. Te government may
extend the delay of notice for additional 90-day periods through additional
certifications that meet the “adverse result” standard of section 2705(b). See
18 U.S.C. § 2705(a)(4). Upon expiration of the delayed notice period, the
statute requires the government to send a copy of the request or process along
with a letter explaining the delayed notice to the customer or subscriber. See 18
U.S.C. § 2705(a)(5).
3. Section 2703(d) Order
Agents need a § 2703(d) court order to obtain most account logs
and most transactional records.
Agents who obtain a court order under 18 U.S.C. § 2703(d) may obtain:
1) anything that can be obtained using a subpoena without
notice; and
2) all
“record[s] or other information pertaining to a
subscriber to or customer of such service (not including the
contents of communications [held by providers of electronic
communications service and remote computing service]).” 18
U.S.C. § 2703(c)(1).
A court order authorized by 18 U.S.C. § 2703(d) may be issued by any
federal magistrate, district court, or equivalent state court judge. See 18 U.S.C.
§§ 2703(d), 2711(3). To obtain such an order,
the governmental entity [must] offer[] specific and articulable
facts showing that there are reasonable grounds to believe that
the contents of a wire or electronic communication, or the
records or other information sought, are relevant and material
to an ongoing criminal investigation.
18 U.S.C. § 2703(d).
130
Searching and Seizing Computers
Tis standard does not permit law enforcement merely to certify that it
has specific and articulable facts that would satisfy such a showing. Rather, the
government must actually offer those facts to the court in the application for
the order. See United States v. Kennedy, 81 F. Supp. 2d 1103, 1109-10 (D. Kan.
2000) (concluding that a conclusory application for a 2703(d) order “did not
meet the requirements of the statute.”). As the Tenth Circuit has noted, the
“specific and articulable facts” standard of 2703(d) “derives from the Supreme
Court’s decision in [Terry v. Ohio, 392 U.S. 1 (1968)].” United States v. Perrine,
518 F.3d 1196, 1202 (10th Cir. 2008). Te House Report accompanying the
1994 amendment to section 2703(d) included the following analysis:
Tis section imposes an intermediate standard to protect
on-line transactional records. It is a standard higher than a
subpoena, but not a probable cause warrant. Te intent of
raising the standard for access to transactional data is to guard
against “fishing expeditions” by law enforcement. Under the
intermediate standard, the court must find, based on law
enforcement’s showing of facts, that there are specific and
articulable grounds to believe that the records are relevant and
material to an ongoing criminal investigation.
H.R. Rep. No. 102-827, at 31-32 (1994), reprinted in 1994 U.S.C.C.A.N.
3489, 3511-12 (quoted in full in Kennedy, 81 F. Supp. 2d at 1109 n.8). As a
practical matter, a short factual summary of the investigation and the role that
the records will serve in advancing the investigation should satisfy this criterion.
A more in-depth explanation may be necessary in particularly complex cases. A
sample § 2703(d) application and order appears in Appendix B.
Section 2703(d) orders issued by federal courts have effect outside the
district of the issuing court. Te SCA permits a judge to enter 2703(d) orders
compelling providers to disclose information even if the judge does not sit
in the district in which the information is stored. See 18 U.S.C. § 2703(d)
(stating that “any court that is a court of competent jurisdiction” may issue a
2703(d) order) (emphasis added); 18 U.S.C. § 2711(3) (stating that “‘court of
competent jurisdiction’ has the meaning assigned by section 3127, and includes
any Federal court within that definition, without geographical limitation”); 18
U.S.C. § 3127(2) (defining “court of competent jurisdiction”).
Section 2703(d) orders may also be issued by state courts. See 18 U.S.C.
§§ 2711(3), 3127(2)(B) (defining “court of competent jurisdiction” to include
3. Stored Communications Act
131
“a court of general criminal jurisdiction of a State authorized by the law of
that State to enter orders authorizing the use of a pen register or a trap and
trace device”). However, the statute provides that when a state governmental
entity seeks a 2703(d) order, the order “shall not issue if prohibited by the law
of such State.” 18 U.S.C. § 2703(d). Moreover, although the statute explicitly
allows federal courts to issue 2703(d) orders to providers outside of the court’s
district, it is silent on whether state courts have such authority.
4.
2703(d) Order with Prior Notice to the Subscriber or Customer
Investigators can obtain everything associated with an account
except for unopened email or voicemail stored with a provider
for 180 days or less using a 2703(d) court order that complies
with the notice provisions of § 2705.
Agents who obtain a court order under 18 U.S.C. § 2703(d), and either
give prior notice to the subscriber or else comply with the delayed notice
provisions of § 2705(a), may obtain:
1) everything that can be obtained using a § 2703(d) court
order without notice;
2) “the contents of a wire or electronic communication that
has been in electronic storage in an electronic communications
system for more than one hundred and eighty days,” 18 U.S.C.
§ 2703(a); and
3) “the contents of any wire or electronic communication” held
by a provider of remote computing service “on behalf of . . . a
subscriber or customer of such remote computing service.” 18
U.S.C. § 2703(b)(1)(B)(ii), § 2703(b)(2).
As a practical matter, except in the Ninth Circuit, this means that the
government can use a 2703(d) order that complies with the prior notice
provisions of § 2703(b)(1)(B) to obtain the full contents of a subscriber’s
account except unopened email and voicemail that have been in the account
for 180 days or less. In the Ninth Circuit, which is governed by Teofel, agents
can continue to use 2703(d) orders to obtain communications in “electronic
storage” over
180 days. Following Teofel, some providers have resisted
producing email content less than 181 days old in response to a 2703(d) order,
even when the 2703(d) order is issued by a court outside the Ninth Circuit.
132
Searching and Seizing Computers
Prosecutors encountering this problem should contact CCIPS at (202) 514-
1026 for assistance.
As an alternative to giving prior notice, law enforcement can obtain an order
delaying notice for up to ninety days when notice would seriously jeopardize the
investigation. See 18 U.S.C. § 2705(a). In such cases, prosecutors generally will
obtain this order by including an appropriate request in the 2703(d) application
and proposed order; sample language appears in Appendix B. Prosecutors may
also apply to the court for extensions of the delay. See 18 U.S.C. § 2705(a)(4).
Te legal standards for obtaining a court order delaying notice mirror the
standards for certified delayed notice by a supervisory official. See Section D.2.,
supra. Te applicant must satisfy the court that “there is reason to believe that
notification of the existence of the court order may . . . endanger[] the life or
physical safety of an individual; [lead to] flight from prosecution; [lead to]
destruction of or tampering with evidence; [lead to] intimidation of potential
witnesses; or . . . otherwise seriously jeopardiz[e] an investigation or unduly
delay[] a trial.” 18 U.S.C. §§ 2705(a)(1)(A), 2705(a)(2). Te applicant must
satisfy this standard anew in every application for an extension of the delayed
notice.
5. Search Warrant
Investigators can obtain everything associated with an account
with a search warrant. The SCA does not require the government
to notify the customer or subscriber when it obtains information
from a provider using a search warrant.
Agents who obtain a search warrant under § 2703 may obtain:
1) everything that can be obtained using a § 2703(d) court
order with notice; and
2) “the contents of a wire or electronic communication, that is
in electronic storage in an electronic communications system for
one hundred and eighty days or less.” 18 U.S.C. § 2703(a).
In other words, agents can obtain any content or non-content information
pertaining to an account by obtaining a search warrant “issued using the
procedures described in” Fed. R. Crim. P. 41. 18 U.S.C. § 2703(a).
Search warrants issued under § 2703 have several noteworthy procedural
features. First, although most search warrants obtained under Rule 41 are
3. Stored Communications Act
133
limited to “a search of property . . . within the district” of the authorizing
magistrate judge, search warrants under § 2703 may be issued by a federal
“court with jurisdiction over the offense under investigation,” even for records
held in another district. See United States v. Berkos, 543 F.3d 392, 396-98 (7th
Cir. 2008); In re Search of Yahoo, Inc., 2007 WL 1539971, at *6 (D. Ariz.
May 21, 2007); In Re Search Warrant, 2005 WL 3844032, at *5-6 (M.D. Fla.
2006) (“Congress intended ‘jurisdiction’ to mean something akin to territorial
jurisdiction”). State courts may also issue warrants under § 2703, but the
statute does not give these warrants effect outside the limits of the courts’
territorial jurisdiction. Second, obtaining a search warrant obviates the need
to give notice to the subscriber. See 18 U.S.C. § 2703(b)(1)(A); Fed. R. Crim.
P. 41(f )(1)(C).
Tird, investigators ordinarily do not themselves search through the
provider’s computers in search of the materials described in the warrant.
Instead, investigators serve the warrant on the provider as they would a
subpoena, and the provider produces the material specified in the warrant. See
18 U.S.C. § 2703(g) (stating that the presence of an officer is not required for
service or execution of a § 2703 warrant); United States v. Bach, 310 F.3d 1063,
1068 (8th Cir. 2002) (finding search of email by ISP without presence of law
enforcement did not violate Fourth Amendment).
Fourth, a two-step process is often used to obtain the content of
communications under a § 2703 warrant. First, the warrant directs the service
provider to produce all email from within the specified account or accounts.
Second, the warrant authorizes law enforcement to review the information
produced to identify and copy information that falls within the scope of the
particularized “items to be seized” under the warrant.
Otherwise, as a practical matter, § 2703 search warrants are obtained much
like Rule 41 search warrants. As with a typical Rule 41 warrant, investigators
must draft an affidavit and a proposed warrant that complies with Rule 41.
134
Searching and Seizing Computers
E. Voluntary Disclosure
Providers of services not available “to the public” may freely
disclose both contents and other records relating to stored
communications. The SCA imposes restrictions on voluntary
disclosures by providers of services to the public, but it also
includes exceptions to those restrictions.
Te voluntary disclosure provisions of the SCA appear in 18 U.S.C.
§ 2702. Tese provisions govern when a provider of RCS or ECS can disclose
contents and other information voluntarily, both to the government and
non-government entities. If the provider may disclose the information to the
government and is willing to do so voluntarily, law enforcement does not need
to obtain a legal order to compel the disclosure. If the provider either may not
or will not disclose the information, agents must rely on compelled disclosure
provisions and obtain the appropriate legal orders.
When considering whether a provider of RCS or ECS can disclose
contents or records, the first question is whether the relevant service offered by
the provider is available “to the public.” See Section B, above. If the provider
does not provide the applicable service “to the public,” then the SCA does not
place any restrictions on disclosure. See 18 U.S.C. § 2702(a). For example,
in Andersen Consulting LLP v. UOP, 991 F. Supp. 1041 (N.D. Ill. 1998), the
petroleum company UOP hired the consulting firm Andersen Consulting and
gave Andersen employees accounts on UOP’s computer network. After the
relationship between UOP and Andersen soured, UOP disclosed to the Wall
Street Journal emails that Andersen employees had left on the UOP network.
Andersen sued, claiming that the disclosure of its contents by the provider
UOP had violated the SCA. Te district court rejected the suit on the ground
that UOP did not provide an electronic communication service to the public:
[G]iving Andersen access to [UOP’s] e-mail system is not
equivalent to providing e-mail to the public. Andersen was
hired by UOP to do a project and as such, was given access
to UOP’s e-mail system similar to UOP employees. Andersen
was not any member of the community at large, but a hired
contractor.
Id. at 1043. Because UOP did not provide services to the public, the SCA did
not prohibit disclosure of contents belonging to UOP’s “subscribers.” See id.
3. Stored Communications Act
135
If the services offered by the provider are available to the public, then the
SCA forbids both the disclosure of contents to any third party and the disclosure
of other records to any governmental entity unless a statutory exception applies.
Even a public provider may disclose customers’ non-content records freely to any
person other than a government entity. See 18 U.S.C. §§ 2702(a)(3), (c)(6).
Section 2702(b) contains exceptions for disclosure of contents, and § 2702(c)
contains exceptions for disclosure of other customer records.
Te SCA allows the voluntary disclosure of contents when:
1) the disclosure is made to the intended recipient of the
communication, with the consent of the sender or intended
recipient, to a forwarding address, or pursuant to specified legal
process, § 2702(b)(1)-(4);
2) in the case of a remote computing service, the disclosure is
made with the consent of a subscriber, § 2702(b)(3);2
3) the disclosure “may be necessarily incident to the rendition
of the service or to the protection of the rights or property of
the provider of that service,” § 2702(b)(5);
4) the disclosure is submitted “to the National Center for
Missing and Exploited Children, in connection with a report
submitted thereto under section 2258A,” § 2702(b)(6);
5) the disclosure is made to a law enforcement agency “if
the contents . . . were inadvertently obtained by the service
provider . . . [and] appear to pertain to the commission of a
crime,” § 2702(b)(7); or
6) the disclosure is made to a governmental entity, “if the
provider, in good faith, believes that an emergency involving
danger of death or serious physical injury to any person requires
disclosure without delay of communications relating to the
emergency.” § 2702(b)(8).
Te SCA provides for the voluntary disclosure of non-content customer
records by a provider to a governmental entity when:
2 See also Quon, 529 F.3d at 900-03 (holding that text messaging service provider did not
provide remote computing service and thus could not disclose users’ communications to the
city that subscribed to its service).
136
Searching and Seizing Computers
1) the disclosure is made “with the lawful consent of the
customer or subscriber,” or “as otherwise authorized in section
2703,” § 2702(c)(1)-(2);
2) the disclosure “may be necessarily incident to the rendition
of the service or to the protection of the rights or property of
the provider of that service,” § 2702(c)(3);
3) the disclosure is made to a governmental entity, “if the
provider, in good faith, believes that an emergency involving
danger of death or serious physical injury to any person
requires disclosure without delay of information relating to the
emergency,” § 2702(c)(4); or
4) the disclosure is made “to the National Center for Missing
and Exploited Children, in connection with a report submitted
thereto under section 2258A.” § 2702(c)(5).
In general, these exceptions permit disclosure by a provider to the public
when the needs of public safety and of service providers themselves outweigh
privacy concerns of customers, or else when disclosure is unlikely to pose a
serious threat to privacy interests.
3. Stored Communications Act
137
F. Quick Reference Guide
Voluntary Disclosure
How to Compel Disclosure
Allowed?
Public Provider
Non-Public
Public Provider
Non-Public
Basic subscriber,
No, unless
Yes
Subpoena;
Subpoena;
session, and billing
§2702(c)
2703(d) order;
2703(d) order;
information•
exception applies
or search
or search
warrant
warrant
§ 2702(a)(3)
§ 2702(a)(3)
§ 2703(c)(2)
§ 2703(c)(2)
Other
No, unless
Yes
2703(d) order or
2703(d) order or
transactional and
§2702(c)
search warrant
search warrant
account records
exception applies
§ 2702(a)(3)
§ 2702(a)(3)
§ 2703(c)(1)
§ 2703(c)(1)
Retrieved
No, unless
Yes
Subpoena with
Subpoena;
communications
§ 2702(b)
notice; 2703(d)
SCA does not
and the content of
exception applies
order with
apply*
other stored files#
notice; or search
warrant*
§ 2702(a)(2)
§ 2702(a)(2)
§ 2703(b)
§ 2711(2)
Unretrieved
No, unless
Yes
Subpoena with
Subpoena with
communications,
§ 2702(b)
notice; 2703(d)
notice; 2703(d)
including email
exception applies
order with
order with
and voice mail (in
notice; or search
notice; or search
electronic storage
warrant
warrant
more than 180
days)
§ 2702(a)(1)
§ 2702(a)(1)
§ 2703(a), (b)
§ 2703(a), (b)
Unretrieved
No, unless
Yes
Search warrant
Search warrant
communications,
§ 2702(b)
including email
exception applies
and voice mail (in
electronic storage
180 days or less)
§ 2702(a)(1)
§ 2702(a)(1)
§ 2703(a)
§ 2703(a)
• See 18 U.S.C. § 2703(c)(2) for listing of information covered. This information includes local
and long distance telephone connection records and records of session times and durations as
well as IP addresses assigned to the user during the Internet connections.
† Includes the content of voice communications.
* For investigations occurring in the Ninth Circuit, Theofel v. Farey-Jones, 359 F.3d 1066 (9th Cir.
2004), requires use of a search warrant unless the communications have been in storage for
more than 180 days. Some providers follow Theofel even outside the Ninth Circuit; contact
CCIPS at (202) 514-1026 if you have an appropriate case to litigate this issue.
138
Searching and Seizing Computers
G. Working with Network Providers: Preservation of
Evidence, Preventing Disclosure to Subjects, Cable
Act Issues, and Reimbursement
Law enforcement officials who procure records under the SCA quickly
learn the importance of communicating with network service providers.
Communication is necessary because every network provider works differently.
Some providers retain very complete records for a long period of time; others
retain few records, or even none. Some providers can comply easily with law
enforcement requests for information; others struggle to comply with even
simple requests. Tese differences result from varied philosophies, resources,
hardware, and software among network service providers. Because of these
differences, it is often advisable for agents to communicate with a network
service provider (or review the provider’s law enforcement compliance guide)
to learn how the provider operates before obtaining a legal order that compels
the provider to act.
Te SCA contains two provisions designed to aid law enforcement officials
working with network service providers. When used properly, these provisions
help ensure that providers will not delete needed records or notify others about
the investigation.
1. Preservation of Evidence under 18 U.S.C. § 2703(f )
Agents may direct providers to preserve existing records pending
the issuance of compulsory legal process. Such requests have no
prospective effect, however.
In general, no law regulates how long network service providers must
retain account records in the United States. Some providers retain records for
months, others for hours, and others not at all. As a result, some evidence may
be destroyed or lost before law enforcement can obtain the appropriate legal
order compelling disclosure. For example, suppose that a crime occurs on Day
1, agents learn of the crime on Day 28, begin work on a search warrant on Day
29, and obtain the warrant on Day 32, only to learn that the network service
provider deleted the records in the ordinary course of business on Day 30. To
minimize the risk that evidence will be lost, the SCA permits the government
to direct providers to “freeze” stored records and communications pursuant to
18 U.S.C. § 2703(f ). Specifically, § 2703(f )(1) states:
3. Stored Communications Act
139
A provider of wire or electronic communication services or a
remote computing service, upon the request of a governmental
entity, shall take all necessary steps to preserve records and
other evidence in its possession pending the issuance of a court
order or other process.
Tere is no legally prescribed format for § 2703(f ) requests. While a simple
phone call should be adequate, a fax or an email is safer practice because it both
provides a paper record and guards against misunderstanding. Upon receipt
of the government’s request, the provider must retain the records for 90 days,
renewable for another 90-day period upon a government request. See 18 U.S.C.
§ 2703(f )(2). A sample § 2703(f ) letter appears in Appendix C.
Agents who send § 2703(f ) letters to network service providers should be
aware of two limitations. First, § 2703(f ) letters should not be used prospectively
to order providers to preserve records not yet created. If agents want providers
to record information about future electronic communications, they should
comply with the electronic surveillance statutes discussed in Chapter 4.
A second limitation of § 2703(f ) is that some providers may be unable
to comply effectively with § 2703(f ) requests, or they may be unable to
comply without taking actions that potentially could alert a suspect. In such
a situation, the agent must weigh the benefit of preservation against the risk
of alerting the subscriber. Te key here is effective communication: agents
should communicate with the network service provider before ordering the
provider to take steps that may have unintended adverse effects. Investigators
with questions about a provider’s practices may also contact CCIPS at (202)
514-1026 for further assistance.
2. Orders Not to Disclose the Existence of a Warrant,
Subpoena, or Court Order
Section § 2705(b) states:
A governmental entity acting under section 2703, when it
is not required to notify the subscriber or customer under
section 2703(b)(1), or to the extent that it may delay such
notice pursuant to subsection (a) of this section, may apply
to a court for an order commanding a provider of electronic
communications service or remote computing service to whom
a warrant, subpoena, or court order is directed, for such period
140
Searching and Seizing Computers
as the court deems appropriate, not to notify any other person
of the existence of the warrant, subpoena, or court order. Te
court shall enter such an order if it determines that there is
reason to believe that notification of the existence of the
warrant, subpoena, or court order will result in—
(1) endangering the life or physical safety of an individual;
(2) flight from prosecution;
(3) destruction of or tampering with evidence;
(4) intimidation of potential witnesses; or
(5) otherwise seriously jeopardizing an investigation or unduly
delaying a trial.
18 U.S.C. § 2705(b).
Tis language permits agents to apply for a court order directing network
service providers not to disclose the existence of legal process whenever the
government itself has no legal duty to notify the customer or subscriber of the
process. If the relevant process is a 2703(d) order or 2703 warrant, agents can
simply include appropriate language in the application and proposed order or
warrant. If agents instead seek to compel the disclosure of information using a
subpoena, they must apply separately for this order.
3. Te Cable Act, 47 U.S.C. § 551
The Cable Act restricts government access to cable operator
records only when the records relate to ordinary cable services. It
does not restrict government access to records relating to Internet
access or telephone service provided by a cable operator.
In 1984, Congress passed the Cable Communications Policy Act (“the
Cable Act”), 47 U.S.C. § 521 et seq. Originally, 47 U.S.C. § 551 set forth
a restrictive system of rules governing law enforcement access to records
possessed by a cable company. Under these rules, even a search warrant was
insufficient to gain access to cable company records. Te government could
obtain “personally identifiable information concerning a cable subscriber” only
by overcoming a heavy burden of proof at an in-court adversary proceeding, as
specified in 47 U.S.C. § 551(h).
3. Stored Communications Act
141
After the 1984 passage of the Cable Act, cable companies began to provide
Internet access and telephone service. Some cable companies asserted that
the stringent disclosure restrictions of the Cable Act governed not only their
provision of traditional cable programming services, but also their provision of
Internet and telephone services. Congress responded by amending the Cable
Act to specify that its disclosure restrictions apply only to records revealing
what ordinary cable television programming a customer purchases, such as
particular premium channels or “pay per view” shows. See USA-PATRIOT
Act § 211, 115 Stat. 272, 283-84 (2001). In particular, cable operators may
disclose subscriber information to the government pursuant to the SCA, Title
III, and the Pen/Trap statute, except for “records revealing cable subscriber
selection of video programming.” 47 U.S.C. § 551(c)(2)(D). Records revealing
subscriber selection of video programming remain subject to the restrictions of
47 U.S.C. § 551(h).3
4. Reimbursement
When a government entity obtains information pursuant to the
SCA, the network provider may be entitled to reimbursement for
its reasonable costs incurred in supplying the information.
In general, persons and entities are not entitled to reimbursement for
complying with federal legal process unless there is specific federal statutory
authorization. See Blair v. United States, 250 U.S. 273, 281 (1919) (discussing
possibility of reimbursement for grand jury testimony). “It is beyond dispute
that there is in fact a public obligation to provide evidence . . . and that this
obligation persists no matter how financially burdensome it may be.” Hurtado
v. United States, 410 U.S. 578, 589 (1973) (stating that the Fifth Amendment
does not require compensation for the performance of a public duty). However,
in many (but not all) circumstances, the SCA requires government entities
obtaining the contents of communications, records, or other information
pursuant to the SCA to reimburse the disclosing person or entity. See 18 U.S.C.
§ 2706.
Section 2706 generally obligates government entities “obtaining the contents
of communications, records, or other information under section 2702, 2703,
or 2704” to pay the service provider “a fee for reimbursement for such costs
3 Te Satellite Home Viewer Extension and Reauthorization Act of 2004 (SHVERA) was
based on the original Cable Act and contains nearly identical provisions governing disclosure
of customer records by satellite television providers. See 47 U.S.C. § 338(i).
142
Searching and Seizing Computers
as are reasonably necessary and which have been directly incurred in searching
for, assembling, reproducing, or otherwise providing such information.” 18
U.S.C. § 2706(a). Significantly, this section only requires reimbursement when
the government actually obtains communication content, records, or other
information. Tus, the government is not required to pay for costs incurred by
a provider in responding to a 2703(f ) preservation letter unless the government
later obtains the preserved records.
Te amount of the fee required under § 2706(a) “shall be as mutually
agreed by the governmental entity and the person or entity providing the
information, or, in the absence of agreement, shall be as determined by the
court.” 18 U.S.C. § 2706(b). In practice, if the service provider seeks what
appears to be unreasonably high reimbursement costs, the government should
demand a detailed accounting of costs incurred by activity. A cost accounting
will help ensure that the provider is not seeking reimbursement for indirect
costs or activities that were not reasonably necessary to the production.
In addition, the SCA contains a reimbursement exception that precludes
reimbursement in specific circumstances. Te reimbursement requirement
“does not apply with respect to records or other information maintained by
a communications common carrier that relate to telephone toll records and
telephone listings obtained under section 2703,” unless a court determines
that the information sought by the government is “unusually voluminous” or
“caused an undue burden on the provider.” 18 U.S.C. § 2706(c).
Te reimbursement exception of § 2706(c) applies only to records and
other information “maintained by” a communications common carrier. In
Ameritech Corp. v. McCann, 403 F.3d 908, 912 (7th Cir. 2005), the Seventh
Circuit held that reports of who placed calls to a specified customer were not
“maintained by” Ameritech. Ameritech’s computer system recorded calls made
by a customer, but it did not automatically keep or generate a list of the calls
made to a customer. Compiling such a list required substantial computation
time. According to the court, Ameritech “maintains” bills and equivalent
statements, and the government can therefore get such “raw information”
for free. However, when the government requires Ameritech to create a
report, the government must provide compensation. Prosecutors outside the
Seventh Circuit are not bound by Ameritech, and there is a reasonably strong
argument that its interpretation of § 2706(c) is flawed. Under this alternative
interpretation, any information stored by a carrier is “maintained by” the
3. Stored Communications Act
143
carrier, and questions regarding the difficulty of producing information can be
evaluated under the “undue burden” standard of § 2706(c).
H. Constitutional Considerations
Defendants sometimes raise constitutional challenges to compelled
disclosure of information from communication service providers. Tey
typically argue that use of a 2703(d) order or a subpoena (rather than a
warrant) to compel disclosure of information violated the Fourth Amendment.
Tese claims fail for two reasons. First, the defendant may have no reasonable
expectation of privacy in the information obtained from the service provider.
Second, the Fourth Amendment generally permits the government to compel
a provider to disclose information in an account when the provider has access
to and control over the targeted information, regardless of whether the account
user has a reasonable expectation of privacy in the targeted information.
It is now well established that a customer or subscriber has no reasonable
expectation of privacy in her subscriber information or transactional records.
In United States v. Miller, 425 U.S. 435 (1976), the Supreme Court held that a
defendant had no reasonable expectation of privacy in his bank records because
the records were not his “private papers” but were “the business records of the
banks” in which the defendant could “assert neither ownership nor possession.”
Id. at 440. Te Court explained that “the Fourth Amendment does not prohibit
the obtaining of information revealed to a third party and conveyed by him
to Government authorities.” Id. at 443 (citing Hoffa v. United States, 385 U.S.
293, 302 (1966)). Te Court relied upon the principles of Miller in Smith v.
Maryland, 442 U.S. 735 (1979), in which it held that a defendant had no
reasonable expectation of privacy in dialed telephone numbers obtained from
the phone company. Id. at 745-46.
Courts have now extended this Miller/Smith analysis to network accounts,
holding that individuals retain no Fourth Amendment privacy interest in
subscriber information and transactional records. See United States v. Perrine,
518 F.3d 1196, 1204 (10th Cir. 2008) (“Every federal court to address this
issue has held that subscriber information provided to an internet provider
is not protected by the Fourth Amendment’s privacy expectation.”); United
States v. Forrester, 512 F.3d 500, 510 (9th Cir. 2008) (email and Internet users
have no reasonable expectation of privacy in source or destination addresses
of email or the IP addresses of websites visited); Guest v. Leis, 255 F.3d 325,
144
Searching and Seizing Computers
336 (6th Cir. 2001) (finding no Fourth Amendment protection for network
account holders’ subscriber information obtained from communication service
provider).
In contrast, whether a user has a reasonable expectation of privacy in the
contents of communications stored in her account will depend on the facts and
circumstances associated with the account. In Quon v. Arch Wireless Operating
Co., 529 F.3d 892, 906 (9th Cir. 2008), the Ninth Circuit rejected “a monolithic
view of text message users’ reasonable expectation of privacy,” explaining that
“this is necessarily a context-sensitive inquiry.” Compare Quon, 529 F.3d at
906-08 (finding reasonable expectation of privacy in pager messages based
on an “informal policy that the text messages would not be audited”), and
Wilson v. Moreau, 440 F. Supp. 2d 81, 108 (D.R.I. 2006) (finding reasonable
expectation of privacy in content of Yahoo! email account), aff’d, 492 F.3d
50 (1st Cir. 2007), with Biby v. Board of Regents, 419 F.3d 845, 850-51 (8th
Cir. 2005) (university policy stating that computer files and emails may be
searched in response to litigation discovery requests eliminated computer user’s
reasonable expectation of privacy) and Guest v. Leis, 255 F.3d 325, 333 (6th
Cir. 2001) (finding that disclaimer on private bulletin board service defeated
expectation of privacy in postings). See also United States v. Young, 350 F.3d
1302, 1307-08 (11th Cir. 2003) (Federal Express customer had no reasonable
expectation of privacy in the contents of a package based on terms of service
authorizing Federal Express to inspect packages).
Critically, however, even if a user has a reasonable expectation of privacy
in an item, a subpoena may be used to compel the production of the item,
provided the subpoena is reasonable. See United States v. Palmer, 536 F.2d
1278, 1281-82 (9th Cir. 1976). Te Fourth Amendment imposes a probable
cause requirement only on the issuance of warrants. See U.S. Const. amend.-
IV (“and no Warrants shall issue, but upon probable cause). A century of
Supreme Court case law demonstrates that reasonable subpoenas comply with
the Fourth Amendment. See Wilson v. United States, 221 U.S. 361, 376 (1911)
(“there is no unreasonable search and seizure when a [subpoena], suitably
specific and properly limited in its scope, calls for the production of documents
which, as against their lawful owner to whom the writ is directed, the party
procuring its issuance is entitled to have produced”); Oklahoma Press Publ’g
Co. v. Walling, 327 U.S. 186, 208 (1946); United States v. Dionisio, 410 U.S.
1, 9-12 (1973); Donovan v. Lone Steer, Inc., 464 U.S. 408, 414-15 (1984).
Te rule for when a subpoena is reasonable and thus complies with the Fourth
3. Stored Communications Act
145
Amendment is also well-established: “the Fourth Amendment requires that the
subpoena be sufficiently limited in scope, relevant in purpose, and specific in
directive so that compliance will not be unreasonably burdensome.” Donovan,
464 U.S. at 415 (quoting See v. City of Seattle, 387 U.S. 541, 549 (1967)).
Finally, the Fourth Amendment does not require that notice be given to the
target of an investigation in third-party subpoena cases. See SEC v. Jerry T.
O’Brien, Inc., 467 U.S. 735, 743, 749-51 (1984).
In general, the cases indicate that the government may compel an entity to
disclose any item that is within its control and that it may access. See United States
v. Barr, 605 F. Supp. 114, 119 (S.D.N.Y. 1985) (subpoena served on private
third-party mail service for the defendant’s mail in the third party’s possession);
Schwimmer v. United States, 232 F.2d 855, 861-63 (8th Cir. 1956) (subpoena
served on third-party storage facility for the defendant’s private papers in the
third party’s possession); Newfield v. Ryan, 91 F.2d 700, 702-05 (5th Cir. 1937)
(subpoena served on telegraph company for copies of defendants’ telegrams in
the telegraph company’s possession). Tis rule is supported both by the rule
that a party with “joint access or control for most purposes” may consent to
a search, see United States v. Matlock, 415 U.S. 164, 171 n.7 (1974), and also
by the rule that “the Fourth Amendment does not prohibit the obtaining of
information revealed to a third party and conveyed by him to Government
authorities.” Miller, 425 U.S. at 443.
As a practical matter, there is good reason to believe that network service
providers will typically have sufficient access to and control over stored
communications on their networks to produce the communications in response
to compulsory process. Terms of service used by network service providers often
establish that the provider has authority to access and disclose subscriber email.
For example, at the time of this writing, Yahoo!’s terms of service confirm its
right in its “sole discretion to pre-screen, refuse, or remove any Content that
is available via the Yahoo! Services,” as well as to access and disclose email to
comply with legal process. Terms of service similar to Yahoo!’s were sufficient
to establish Federal Express’s common authority over the contents of a package
in Young: the Eleventh Circuit concluded that because Federal Express retained
the right to inspect packages, it had authority to consent to a government
request to search the package without a warrant. Young, 350 F.3d at 1309. See
generally Warshak v. United States, 532 F.3d 521, 527 (6th Cir. 2008) (en banc)
(noting the range of terms of service used by different providers). In addition,
service providers typically exercise actual authority to access the content of
146
Searching and Seizing Computers
communications stored on their networks. Major providers regularly screen for
spam, malicious code, and child pornography. Some, such as Gmail, screen the
content of email in order to target advertising at the account holder.
CCIPS has assisted many prosecutors facing constitutional challenges to
the SCA, and prosecutors confronted with such challenges are encouraged to
consult with CCIPS at (202) 514-1026 for further assistance.
I.
Remedies
Suppression is not a remedy for nonconstitutional SCA violations. However,
the SCA does create a cause of action for civil damages.
1. Suppression
Te SCA does not provide a suppression remedy. See 18 U.S.C. § 2708
(“Te [damages] remedies and sanctions described in this chapter are the
only judicial remedies and sanctions for nonconstitutional violations of this
chapter.”). Accordingly, nonconstitutional violations of the SCA do not result
in suppression of the evidence. See United States v. Perrine, 518 F.3d 1196,
1202 (10th Cir. 2008) (“[V]iolations of the ECPA do not warrant exclusion
of evidence.”); United States v. Steiger, 318 F.3d 1039, 1049 (11th Cir. 2003);
United States v. Smith, 155 F.3d 1051, 1056 (9th Cir. 1998) (“[T]he Stored
Communications Act expressly rules out exclusion as a remedy”); United States
v. Ferguson, 508 F. Supp. 2d 7, 10 (D.D.C. 2007); United States v. Sherr, 400
F. Supp. 2d 843, 848 (D. Md. 2005); United States v. Kennedy, 81 F. Supp. 2d
1103, 1110 (D. Kan. 2000) (“[S]uppression is not a remedy contemplated
under the ECPA.”); United States v. Hambrick, 55 F. Supp. 2d 504, 507 (W.D.
Va. 1999) (“Congress did not provide for suppression where a party obtains
stored data or transactional records in violation of the Act.”), aff’d, 225 F.3d
656, 2000 WL 1062039 (4th Cir. 2000) (unpublished); United States v. Reyes,
922 F. Supp. 818, 837-38 (S.D.N.Y. 1996) (“Exclusion of the evidence is not
an available remedy for this violation of the ECPA
Te remedy for violation
of [18 U.S.C. § 2701-11] lies in a civil action.”).
As discussed previously in Section H, defendants occasionally have
claimed that section 2703’s procedures for compelled disclosure violate the
Fourth Amendment. However, even if a court were to hold section 2703
unconstitutional in some circumstances, suppression would likely not be a
proper remedy. In Illinois v. Krull, 480 U.S. 340, 349 (1987), the Supreme
3. Stored Communications Act
147
Court held that the exclusionary rule did not apply to evidence obtained in
“objectively reasonable reliance on a statute.” Reliance on section 2703 likely
satisfies this standard, as the only decision thus far to have held section 2703
unconstitutional was reversed on appeal. See Warshak v. United States, 532 F.3d
521 (6th Cir. 2008) (en banc). In addition, when a defendant moves to suppress
based on a claim that the SCA’s procedures are unconstitutional, the court may
conclude that the government’s reliance on the SCA was objectively reasonable
and deny the suppression motion without ruling on the constitutionality of
the SCA. See Krull, 480 U.S. at 357 n.13; United States v. Vanness, 342 F.3d
1093, 1098 (10th Cir. 2003). Courts have adopted this approach in two cases
in which the defendants argued that the SCA was unconstitutional. See United
States v. Warshak, 2007 WL 4410237, at *5 (S.D. Ohio Dec. 13, 2007); United
States v. Ferguson, 508 F. Supp. 2d 7, 9-10 (D.D.C. 2007).
2. Civil Actions and Disclosures
Although the SCA does not provide a suppression remedy for statutory
violations, it does provide for civil damages (including, in some cases, punitive
damages), as well as the prospect of disciplinary actions against officers and
employees of the United States who have engaged in willful violations of the
statute. See, e.g., Freedman v. American Online, Inc., 303 F. Supp. 2d 121 (D.
Conn. 2004) (granting summary judgment on liability under the SCA against
police officers who served on AOL a purported search warrant that had not been
signed by a judge). Te Ninth Circuit has held that the SCA does not impose
secondary liability for aiding and abetting an SCA violation or conspiring to
violate the SCA. See Freeman v. DirecTV, Inc., 457 F.3d 1001, 1006 (9th Cir.
2006). Tus, liability under the SCA for a violation of the voluntary disclosure
provisions of section 2702 is limited to service providers. See id. at 1006.
Liability and discipline can result not only from violations of the rules
already described in this chapter, but also from the improper disclosure of some
kinds of SCA-related information. Information that is obtained pursuant to §
2703 and that qualifies as a “record” under 5 U.S.C. § 552a(a) can be disclosed
by an officer or governmental entity only “in the proper performance of the
official functions of the officer or governmental entity making the disclosure.”
18 U.S.C. § 2707(g). Other disclosures of such information by an officer or
governmental entity are unlawful unless the information has been previously
and lawfully disclosed to the public. See id.
148
Searching and Seizing Computers
Te SCA includes separate provisions for suits against the United States
and suits against any other person or entity. Section 2707 permits a “person
aggrieved” by SCA violations that result from knowing or intentional conduct
to bring a civil action against the “person or entity, other than the United States,
which engaged in that violation.” 18 U.S.C. § 2707(a). Relief can include
money damages no less than $1,000 per person, equitable or declaratory relief,
and a reasonable attorney’s fee plus other reasonable litigation costs. 18 U.S.C.
§ 2707(b), (c). Willful or intentional violations can also result in punitive
damages, see § 2707(c), and employees of the United States may be subject to
disciplinary action for willful or intentional violations. See § 2707(d). A good
faith reliance on a court order or warrant, grand jury subpoena, legislative
authorization, or statutory authorization provides a complete defense to any
civil or criminal action brought under the SCA. See § 2707(e). Qualified
immunity may also be available. See Chapter 4.E.2.
Suits against the United States may be brought under 18 U.S.C. § 2712
for willful violations of the SCA, Title III, or specified sections of the Foreign
Intelligence Surveillance Act of 1978, 50 U.S.C. § 1801 et seq. Tis section
authorizes courts to award actual damages or $10,000, whichever is greater,
and reasonable litigation costs. Section 2712 also defines procedures for suits
against the United States and a process for staying proceedings when civil
litigation would adversely affect a related investigation or criminal prosecution.
See 18 U.S.C. § 2712 (b), (e).
3. Stored Communications Act
149
150
Searching and Seizing Computers
Chapter 4
Electronic Surveillance in
Communications Networks
A. Introduction
Criminal investigations often involve real-time electronic surveillance. In
computer crime cases, agents may want to monitor a hacker as he breaks into a
victim computer system or set up a “cloned” email account to monitor a suspect
sending or receiving child pornography. In cases involving cellular telephones,
agents may wish to obtain “cell-site” location information for a suspect’s cellular
telephone to determine the suspect’s approximate location at the time of a call.
Agents may wish to wiretap a suspect’s telephone or learn whom the suspect
has called. Tis chapter explains how the electronic surveillance statutes apply
to criminal investigations involving computers and also discusses how to obtain
cell-site location information for cellular phones.
Real-time electronic surveillance in federal criminal investigations is
governed primarily by two statutes. Te first is the federal Wiretap Act, 18
U.S.C. §§ 2510-2522, first passed as Title III of the Omnibus Crime Control
and Safe Streets Act of 1968 (and generally known as “Title III”). Te second
statute is the Pen Registers and Trap and Trace Devices chapter of Title 18
(“the Pen/Trap statute”), 18 U.S.C. §§
3121-3127, first passed as part of the
Electronic Communications Privacy Act of 1986. Failure to comply with these
statutes may result in civil and criminal liability, and in the case of Title III,
may also result in suppression of evidence.
B. Content vs. Addressing Information
In general, the Pen/Trap statute regulates the collection of
addressing and other non-content information for wire and
electronic communications. Title III regulates the collection of
actual content of wire and electronic communications.
151
Title III and the Pen/Trap statute regulate access to different types of
information. Title III permits the government to obtain the contents of wire
and electronic communications in transmission. In contrast, the Pen/Trap
statute concerns the real-time collection of addressing and other non-content
information relating to those communications. See 18 U.S.C. § 2511(2)(h)(i)
(stating that it is not a violation of Title III to use a pen register or trap and
trace device); United States Telecom Ass’n v. FCC, 227 F.3d 450, 453-54 (D.C.
Cir. 2000) (contrasting pen registers and Title III intercept devices); Brown v.
Waddell, 50 F.3d 285, 289-94 (4th Cir. 1995) (same).
Te difference between addressing information and content is clear for
telephone calls. Te addressing information is the phone numbers of the
originating and receiving telephones. Te content of the communication is the
actual conversation between the parties to the call.
Te distinction between addressing information and content also applies
to Internet communications. For example, when computers on the Internet
communicate with each other, they break down messages into discrete chunks
known as packets and then send each packet out to its intended destination.
Every packet contains addressing information in the header of the packet
(much like the “to” and “from” addresses on an envelope), followed by
the payload of the packet, which contains the contents (much like a letter
inside an envelope). Te Pen/Trap statute permits law enforcement to obtain
the addressing information of Internet communications much as it would
addressing information for traditional phone calls. However, collecting the
entire packet ordinarily implicates Title III. Te primary difference between an
Internet pen/trap device and an Internet Title III intercept device is that the
former is designed to capture and retain only addressing information, while the
latter is designed to capture and retain the entire packet.
Te same distinction applies to Internet email. Every Internet email message
consists of a set of headers that contain addressing and routing information
generated by the mail program, followed by the actual contents of the message
authored by the sender. Te addressing and routing information includes
the email address of the sender and recipient, as well as information about
when and where the message was sent on its way (roughly analogous to the
postmark on a letter). See United States v. Forrester, 512 F.3d 500, 510 (9th
Cir. 2008) (email to/from addresses and IP addresses constitute addressing
information). Te Pen/Trap statute permits law enforcement to obtain the
header information of Internet emails (except for the subject line, which can
152
Searching and Seizing Computers
contain content) using a court order, just like it permits law enforcement to
obtain addressing information for phone calls and individual Internet packets
using a court order. Conversely, the interception of email contents, including
the subject line, requires compliance with the strict dictates of Title III.
In some circumstances, questions may arise regarding whether particular
components of network communications contain content. See In re Application
of United States, 396 F. Supp. 2d 45, 49 (D. Mass. 2005) (asserting that uniform
resource locators (“URLs”) may contain content); In re Pharmatrak, Inc. Privacy
Litigation, 329 F.3d 9, 16 (1st Cir. 2003) (noting that user-entered search terms
are sometimes appended to the query string of the URL for the search results
page). Because of these and other issues, the United States Attorneys’ Manual
currently requires prior consultation with CCIPS before a pen/trap may be
used to collect all or part of a URL. See United States Attorneys’ Manual § 9-
7.500. Prosecutors who have other questions about whether a particular type
of information constitutes contents may contact CCIPS for assistance at (202)
514-1026.
C. Te Pen/Trap Statute, 18 U.S.C. §§ 3121-3127
Te Pen/Trap statute authorizes a government attorney to apply to a
court for an order authorizing the installation of a pen register and/or trap
and trace device if “the information likely to be obtained is relevant to an
ongoing criminal investigation.” 18 U.S.C. § 3122(b)(2). In rough terms, a
pen register records outgoing addressing information (such as a number dialed
from a monitored telephone), and a trap and trace device records incoming
addressing information (such as caller ID information). Te Pen/Trap statute
applies to a wide range of communication technologies, including computer
network communications. See In re Application of United States, 416 F. Supp.
2d 13, 16 (D.D.C. 2006).
1. Definition of Pen Register and Trap and Trace Device
Te Pen/Trap statute defines pen registers and trap and trace devices
broadly. As defined in 18 U.S.C. § 3127(3), a “pen register” is
a device or process which records or decodes dialing, routing,
addressing,orsignalinginformationtransmittedby aninstrument
or facility from which a wire or electronic communication is
4. Electronic Surveillance
153
transmitted, provided, however, that such information shall
not include the contents of any communication
Te definition of pen register further excludes devices or processes used for
billing or cost accounting. See 18 U.S.C. § 3127(3). Te statute defines a “trap
and trace device” as
a device or process which captures the incoming electronic
or other impulses which identify the originating number or
other dialing, routing, addressing, and signaling information
reasonably likely to identify the source of a wire or electronic
communication, provided, however that such information shall
not include the contents of any communication.
18 U.S.C. § 3127(4). Because Internet headers contain both “to” and “from”
information, a device that reads the entire header (minus the subject line in the
case of email headers) is both a pen register and a trap and trace device, and it
is commonly referred to as a pen/trap device.
Te breadth of these definitions results from the scope of their components.
First, “an instrument or facility from which a wire or electronic communication
is transmitted” encompasses a wide variety of communications technologies,
including a non-mobile telephone, a cellular telephone, an Internet user
account, an email account, or an IP address. Second, the definitions’ inclusion
of all “dialing, routing, addressing, [and/or] signaling information” encompasses
almost all non-content information in a communication. Tird, because the
definitions of a pen register and a trap and trace device include both a “device”
and a “process,” the statute covers software as well as physical devices. Because
the definitions are written in broad, technology-neutral language, prosecutors
or agents may have questions about whether particular devices constitute pen
registers or trap and trace devices, and they should direct any such questions to
CCIPS at (202) 514-1026, OEO at (202) 514-6809, or their local CHIP (see
Introduction, p. xii)
2. Pen/Trap Orders: Application, Issuance, Service, and Reporting
To obtain a pen/trap order, applicants must identify themselves, identify
the law enforcement agency conducting the investigation, and then certify
their belief that the information likely to be obtained is relevant to an
ongoing criminal investigation being conducted by the agency. See 18 U.S.C.
§ 3122(b)(1)-(2). Te issuing court must have jurisdiction over the offense being
154
Searching and Seizing Computers
investigated. See 18 U.S.C. § 3122(a); 18 U.S.C. § 3127(2)(A). So long as the
application contains these elements, the statute obligates the court to authorize
the installation and use of a pen/trap device anywhere in the United States. See
18 U.S.C. § 3123(a)(1). Te court will not conduct an “independent judicial
inquiry into the veracity of the attested facts.” In re Application of United States,
846 F. Supp. 1555, 1559 (M.D. Fla. 1994). See also United States v. Fregoso, 60
F.3d 1314, 1320 (8th Cir. 1995) (“Te judicial role in approving use of trap
and trace devices is ministerial in nature.”).
A federal pen/trap order can have effect outside the district of the issuing
court. In the case of a federal applicant, the order “appl[ies] to any person
or entity providing wire or electronic communication service in the United
States whose assistance may facilitate the execution of the order.” 18 U.S.C.
§ 3123(a)(1). For example, a federal prosecutor may obtain an order to trace
telephone calls made to a particular telephone. Te order applies not only to
the local carrier serving that line, but also to other providers (such as long-
distance carriers and regional carriers in other parts of the country) in the
United States through whom calls are placed to the target telephone. Similarly,
in the Internet context, a federal prosecutor may obtain an order to trace
communications sent to a particular victim computer or IP address. If a hacker
is routing communications through a chain of intermediate pass-through
computers, the order would apply to each computer in the United States in the
chain from the victim to the source of the communications.
Te Pen/Trap statute does not require an applicant for a pen/trap order to
describe precisely what types of “dialing, routing, addressing, [and/or] signaling
information” he or she seeks to obtain. Although one magistrate has ruled that
an Internet pen/trap order should contain a list of categories of information
that may not be collected, such as email subject lines, see In re Application of
United States, 396 F. Supp. 2d 45, 49 (D. Mass. 2005), this requirement is
not supported by the statute. One later district court held that such a “do not
collect” list is unnecessary. See In re Application of United States, 416 F. Supp.
2d 13, 18 (D.D.C. 2006) (approving Internet pen/trap order seeking specified
non-content information, such as originating IP addresses).
Te government must also use “technology reasonably available to it” to avoid
recording or decoding the contents of any wire or electronic communications.
18 U.S.C. § 3121(c). When there is no way to avoid the inadvertent collection
of content through the use of reasonably available technology, DOJ policy
requires that the government may not use any inadvertently collected content
4. Electronic Surveillance
155
in its investigation. However, a few courts have gone beyond the statute’s
requirement that the government use technology reasonable available to it to
avoid collecting content. Citing the exclusion of contents from the definitions
of pen register and trap and trace device, these courts have stated or implied
that the government cannot use pen/trap devices that might collect any
content at all. See In re Application of the United States, 2007 WL 3036849,
at *8-9 (S. D. Tex. 2007) (“[T]he Pen Register Statute does not permit the
Government simply to minimize the effects of its collection of unauthorized
content, but instead prohibits the collection of content in the first place.”); In
re Application of United States, 416 F. Supp. 2d 13, 17 (D.D.C. 2006) (“[T]he
Government must ensure that the process used to obtain information about
email communications excludes the contents of those communications.”).
Courts have been particularly likely to take this position in the context of phone
pen/trap devices that would collect “post-cut-through dialed digits” because
this data can include content that cannot be separated out using reasonably
available technology.1 See In re Applications of United States, 515 F. Supp. 2d
325, 339 (E.D.N.Y. 2007); In re Application of United States, 441 F. Supp.
2d 816, 827 (S.D. Tex. 2006); In re Application of United States, 2007 WL
3036849, at *8-*9 (S. D. Tex. 2007). Because this area of the law is developing
rapidly, prosecutors or agents may have questions about current trends, and
they may direct any such questions to Mark Eckenwiler, Associate Director, of
OEO at (202) 514-6809, CCIPS at (202) 514-1026, or their local CHIP (see
Introduction, p. xii)
A pen/trap order may authorize the installation and use of a pen/trap device
for up to sixty days and may be extended for additional sixty-day periods. See
18 U.S.C. § 3123(c). Te order should direct the provider not to disclose the
existence of the pen/trap or the investigation “to any . . . person, unless or
until otherwise ordered by the court,” 18 U.S.C. § 3123(d)(2), and may order
providers of wire or electronic communications service, landlords, custodians,
or other persons to furnish all “information, facilities, and technical assistance”
necessary to install pen/trap devices unobtrusively and with a minimum of
1 “Post-cut-through dialed digits” are digits dialed after the initial call set-up is complete.
Such digits can be non-content telephone numbers, “such as when a subject places a calling
card, credit card, or collect call by first dialing a long-distance carrier access number and then,
after the initial call is ‘cut through,’ dialing the telephone number of the destination party.”
United States Telecom Ass’n v. FCC, 227 F.3d 450, 462 (D.C. Cir. 2000). Such digits can also be
content. “For example, subjects calling automated banking services enter account numbers.
When calling voicemail systems, they enter passwords. When calling pagers, they dial digits
that convey actual messages.” Id.
156
Searching and Seizing Computers
interference with services.
18 U.S.C. § 3124(a), (b). Providers and other
persons who are ordered to assist with the installation of pen/trap devices under
§ 3124 can receive reasonable compensation for reasonable expenses incurred
in providing facilities or technical assistance to law enforcement. See 18 U.S.C.
§ 3124(c). A provider’s good faith reliance on a pen/trap order provides a
complete defense to any civil or criminal action arising from its assistance in
accordance with the order. See 18 U.S.C. § 3124(d), (e).
Te Pen/Trap statute does not require the pen/trap application or order to
specify all of the providers subject to the order, although the order must specify
“the identity, if known, of the person to whom is leased or in whose name
is listed the telephone line or other facility to which the pen register or trap
and trace device is to be attached or applied.” See 18 U.S.C. § 3123(b)(1)(A).
To receive a provider’s assistance, an investigator simply needs to serve the
provider with the order. Upon the provider’s request, law enforcement must
also provide “written or electronic certification” that the order applies to the
provider. See 18 U.S.C. § 3123(a)(1). Tere are strong practical motivations
for this relatively informal process. When prosecutors apply for a pen/trap
order, they usually will not know the identity of upstream providers in the
chain of communications covered by the order. If law enforcement personnel
were required to return to court each time they discovered the identity of a new
provider, investigations would be delayed significantly.
Te Pen/Trap statute requires record keeping and reporting when law
enforcement officers install their own pen/trap device on a packet-switched data
network of a provider of electronic communications service to the public. See
18 U.S.C. § 3123(a)(3). In such cases, the agency must maintain a record that
identifies: (1) the identity of the officers who installed the device or accessed
it to obtain information; (2) the dates and times the device was installed,
uninstalled, and accessed to obtain information; (3) the configuration of the
device at the time of installation and any subsequent modifications thereof;
and (4) the information collected by the device. See 18 U.S.C. § 3123(a)(3)(A).
Tis record must be provided to the court within thirty days after termination
of the pen/trap order (including any extensions thereof ). See 18 U.S.C. §
3123(a)(3)(B).
Importantly, the limited judicial review of pen/trap orders coexists with a
strong enforcement mechanism for violations of the statute. See 18 U.S.C. §
3121(d) (providing criminal penalties for violations of the Pen/Trap statute).
As one court has explained,
4. Electronic Surveillance
157
[t]he salient purpose of requiring the application to the court
for an order is to affix personal responsibility for the veracity of
the application (i.e., to ensure that the attesting United States
Attorney is readily identifiable and legally qualified) and to
confirm that the United States Attorney has sworn that the
required investigation is in progress
As a form of deterrence
and as a guarantee of compliance, the statute provides . . . for a
term of imprisonment and a fine as punishment for a violation
[of the statute].
In re Application of United States, 846 F. Supp. 1555, 1559 (M.D. Fla. 1994).
Te Pen/Trap statute also grants providers of electronic or wire
communication service broad authority to use pen/trap devices on their own
networks without a court order. 18 U.S.C. § 3121(b) states that providers may
use pen/trap devices without a court order
(1) relating to the operation, maintenance, and testing of a wire
or electronic communication service or to the protection of
the rights or property of such provider, or to the protection of
users of that service from abuse of service or unlawful use of
service; or
(2) to record the fact that a wire or electronic communication
was initiated or completed in order to protect such provider,
another provider furnishing service toward the completion
of the wire communication, or a user of that service, from
fraudulent, unlawful or abusive use of service; or
(3) where the consent of the user of that service has been
obtained.
18 U.S.C. § 3121(b).
3. Emergency Pen/Traps
Te Pen/Trap statute authorizes the installation and use of a pen/trap without
a court order in emergency situations involving: (1) immediate danger of death
or serious bodily injury to any person; (2) conspiratorial activities characteristic
of organized crime; (3) an immediate threat to a national security interest; or
(4) an ongoing attack on a protected computer (as defined in 18 U.S.C. §
1030(e)(2)) that constitutes a crime punishable by a term of imprisonment
158
Searching and Seizing Computers
greater than one year. See 18 U.S.C. § 3125(a)(1). Te installation and use
of an emergency pen/trap requires approval at least at the Deputy Assistant
Attorney General level, or by the principal prosecuting attorney of any state
or subdivision thereof who is acting pursuant to a state statute. See 18 U.S.C.
§ 3125(a). In order to authorize an emergency pen/trap, the relevant official
must reasonably determine that (1) a specified emergency situation requires
the installation and use of the pen/trap device before an order authorizing
such installation and use can, with due diligence, be obtained, and (2) there
are grounds upon which a pen/trap order could be entered to authorize the
installation and use. See 18 U.S.C. § 3125(a). For assistance in seeking an
emergency pen/trap authorization during regular business hours, contact OEO
at (202) 514-6809 and ask to speak to a supervisor in the electronic surveillance
unit. Outside of regular business hours, contact the DOJ Command Center at
(202) 514-5000.
A court order authorizing the installation and use of the emergency pen/
trap device must be sought within 48 hours after its installation and use. See 18
U.S.C. § 3125(a), (c). In the absence of such an order, the use of the emergency
pen/trap device must immediately terminate when the earliest of these events
occurs: (i) the information sought is obtained, (ii) the application for the order
is denied, or (iii) 48 hours have lapsed since the installation of the pen/trap
device. 18 U.S.C. § 3125(b).
4. Te Pen/Trap Statute and Cell-Site Information
Cell-site data identifies the antenna tower and, in some cases, the 120-
degree face of the tower to which a cell phone is connected at the beginning
and end of each call made or received by a cell phone. “Tese towers can be up
to 10 or more miles apart in rural areas and may be up to a half-mile or more
apart even in urban areas.” In re Application of United States, 405 F. Supp. 2d
435, 449 (S.D.N.Y. 2005). Tus, at best, this data reveals the neighborhood
in which a cell phone user is located at the time a call starts and at the time it
terminates; it does not provide continuous tracking and is not a virtual map
of a cell phone user’s movements. Despite its relative lack of precision, cell-site
information is an important investigatory tool that can help law enforcement
determine where to establish physical surveillance and locate kidnapping
victims, fugitives, and targets of criminal investigations. Tis section discusses
using the combined authority of the Pen/Trap statute and 18 U.S.C. § 2703(d)
to obtain prospective cell-site data. For a discussion of how to obtain historical
cell-site data, see Chapter 3.
4. Electronic Surveillance
159
In most districts, investigators may obtain prospective cell-site information
through an application that satisfies both the Pen/Trap statute and 18 U.S.C.
§ 2703(d). Te rationale behind this “hybrid” use of the Pen/Trap statute
and § 2703(d) is as follows. Cell-site data is “dialing, routing, addressing,
or signaling information,” and therefore 18 U.S.C. § 3121(a) requires the
government to obtain a pen/trap order to acquire this information. However,
the Communications Assistance for Law Enforcement Act of 1994 (“CALEA”)
precludes the government from relying “solely” on the authority of the Pen/
Trap statute to obtain cell-site data for a cell phone subscriber. 47 U.S.C. §
1002(a). Tus, some additional authority is required to obtain prospective cell-
site information. Section 2703(d) provides this authority because, as discussed
in Chapter 3, supra, it authorizes the government to use a court order to obtain
all non-content information pertaining to a customer or subscriber of an
electronic communication service.
When seeking a hybrid order for prospective cell-site information,
prosecutors must satisfy the requirements of both the Pen/Trap statute and 18
U.S.C. § 2703(d). Tis application should contain: (i) a government attorney’s
affirmation “that the information likely to be obtained is relevant to an ongoing
criminal investigation,” 18 U.S.C. § 3122, and (ii) a further demonstration by
the government attorney of “specific and articulable facts showing that there
are reasonable grounds to believe that the contents of a wire or electronic
communication, or the records or other information sought, are relevant and
material to an ongoing criminal investigation.” 18 U.S.C. § 2703(d). Hybrid
orders otherwise generally follow the procedures for pen/trap orders.
District courts and magistrate judges have split on whether hybrid orders
may be used to compel disclosure of prospective cell-site information. Compare
In re Application of United States,
2008 WL 5082506 (E.D.N.Y. 2008)
(upholding hybrid orders for cell-site information), In re Application of United
States, 460 F. Supp. 2d. 448, 462 (S.D.N.Y. 2006) (same), and In re Application
of United States, 433 F. Supp. 2d 804, 806 (S.D. Tex. 2006) (same), with In
re Application of United States, 416 F. Supp. 2d 390, 396-97 (D. Md. 2006)
(rejecting hybrid orders), and In re Application of United States, 396 F. Supp.
2d 294, 327 (E.D.N.Y. 2005) (same). Courts that have rejected hybrid orders
for prospective cell-site information have generally required the government to
obtain a warrant to compel its disclosure. See, e.g., In re Application of United
States, 416 F. Supp. 2d at 397. Most of these courts have not held that a
warrant is constitutionally required to obtain prospective cell-site information.
160
Searching and Seizing Computers
Instead, they have held that as a matter of statutory construction, the Pen/Trap
statute and 18 U.S.C. § 2703(d) cannot be used to obtain prospective cell-
site information, and that Rule 41 can be used because it “governs any matter
in which the government seeks judicial authorization to engage in certain
investigative activities.” In re Application of United States, 396 F. Supp. 2d at
322. Because this area of the law is developing rapidly, prosecutors or agents
may have questions about current trends in different districts, and they should
direct any such questions to John Lynch, Deputy Chief for Computer Crime,
of CCIPS at (202) 514-1026, Mark Eckenwiler, Associate Director, of OEO at
(202) 514-6809, or their local CHIP (see Introduction, p. xii)
D. Te Wiretap Statute (“Title III”),
18 U.S.C. §§ 2510-2522
1. Introduction: Te General Prohibition
Since its enactment in 1968 and amendment in 1986, Title III has provided
the statutory framework that governs real-time electronic surveillance of the
contents of communications. When agents want to wiretap a suspect’s phone,
monitor a hacker breaking into a computer system, or accept the fruits of
wiretapping by a private citizen who has discovered evidence of a crime, the
agents first must consider the implications of Title III.
Te structure of Title III is surprisingly simple. Te statute’s drafters assumed
that every private communication could be modeled as a two-way exchange
between two participating parties, such as a telephone call between A and B.
At a fundamental level, the statute prohibits using an electronic, mechanical,
or other device to intercept private wire, oral, or electronic communications
between the parties unless one of several statutory exceptions applies. See 18
U.S.C. §§ 2510(4), 2511(1). Importantly, this prohibition is quite broad.
Unlike some privacy laws that regulate only certain cases or specific places,
Title III expansively prohibits eavesdropping (subject to certain exceptions and
interstate requirements) essentially everywhere by anyone in the United States.
Whether investigators want to conduct surveillance at a home, at a workplace,
in government offices, in prison, or on the Internet, they must almost invariably
make sure that the monitoring complies with Title III’s prohibitions.
Te questions that agents and prosecutors must ask to ensure compliance
with Title III are straightforward, at least in form:
4. Electronic Surveillance
161
1) Is the communication to be monitored one of the protected
communications defined in 18 U.S.C. § 2510?
2) Will the proposed surveillance lead to an “interception” of
the communications?
3) If the answer to the first two questions is “yes,” does a
statutory exception apply that permits the interception?
2. Key Phrases
Title III broadly prohibits the “interception” of “oral communications,” “wire
communications,” and “electronic communications.” Tese phrases are defined
by the statute. See 18 U.S.C. §§ 2510(1), (2), (4), (12). In computer crime
cases, agents and prosecutors planning electronic surveillance must understand
the definition of “wire communication,” “electronic communication,” and
“intercept.” Surveillance of oral communications rarely arises in computer
crime cases and will not be addressed directly here. Agents and prosecutors
requiring assistance in cases involving oral communications should contact
OEO at (202) 514-6809.
“Wire communication”
In general, telephone conversations are wire communications.
Title III defines “wire communication” as
any aural transfer made in whole or in part though the use of
facilities for the transmission of communications by the aid
of wire, cable, or other like connection between the point of
origin and the point of reception (including the use of such
connection in a switching station) furnished or operated by
any person engaged in providing or operating such facilities for
the transmission of interstate or foreign communications or
communications affecting interstate or foreign commerce.
18 U.S.C. § 2510(1).
Within this complicated definition, the most important requirement is
that the content of the communication must include the human voice. See
§ 2510(18) (defining “aural transfer” as “a transfer containing the human
voice at any point between and including the point of origin and the point
of reception”). If a communication does not contain a human voice, either
162
Searching and Seizing Computers
alone or in a group conversation, then it is not a wire communication. See S.
Rep. No. 99-541, at 12 (1986), reprinted in 1986 U.S.C.C.A.N. 3555; United
States v. Torres, 751 F.2d 875, 885-86 (7th Cir. 1984) (concluding that “silent
television surveillance” cannot lead to an interception of wire communications
under Title III because no aural acquisition occurs).
Te additional requirement that wire communications must be sent “in
whole or in part . . . by the aid of wire, cable, or other like connection” presents
a fairly low hurdle. So long as the signal travels through wire at some point along
its route between the point of origin and the point of reception, the requirement
is satisfied. For example, all voice telephone transmissions, including those
from satellite signals and cellular phones, qualify as wire communications. See
H.R. Rep. No. 99-647, at 35 (1986). Because such transmissions are carried
by wire within switching stations, they are expressly included in the definition
of wire communication. See In re Application of United States, 349 F.3d 1132,
1138 n.12 (9th Cir. 2003) (cell phone communications are considered wire
communications under Title III). Importantly, the presence of wires inside
equipment at the sending or receiving end of a communication (such as an
individual cellular phone) does not satisfy the requirement that a communication
be sent “in part” by wire. Te wire must transmit the communication “to a
significant extent” along the path of transmission, outside of the equipment that
sends or receives the communication. H.R. Rep. No. 99-647, at 35 (1986).
“Electronic communication”
Most Internet communications (including email) are electronic
communications.
Title III originally covered only wire and oral communications, but
Congress amended it in 1986 to include “electronic communications,” defined
as
any transfer of signs, signals, writing, images, sounds, data, or
intelligence of any nature transmitted in whole or in part by a
wire, radio, electromagnetic, photoelectronic or photooptical
system that affects interstate or foreign commerce, but does
not include—
(A) any wire or oral communication;
(B) any communication made through a tone-only paging
device;
4. Electronic Surveillance
163
(C) any communication from a tracking device . . . ; or
(D) electronic funds transfer information stored by a financial
institution in a communications system used for the electronic
storage and transfer of funds.
18 U.S.C. § 2510(12).
As the definition suggests, “electronic communication” is a broad, catch-all
category. See United States v. Herring, 993 F.2d 784, 787 (11th Cir. 1993). “As a
rule, a communication is an electronic communication if it is neither carried by
sound waves nor can fairly be characterized as one containing the human voice
(carried in part by wire).” H.R. Rep. No. 99-647, at 35 (1986). Most electric or
electronic signals that do not fit the definition of wire communications qualify as
electronic communications. For example, almost all Internet communications
qualify as electronic communications. See, e.g., Konop v. Hawaiian Airlines,
Inc., 302 F.3d 868, 876 (9th Cir. 2002) (“document” transmitted from web
server); In re Application of United States, 416 F. Supp. 2d 13, 16 (D.D.C. 2006)
(“there can be no doubt that [§ 2510(12)] is broad enough to encompass email
communications and other similar signals transmitted over the Internet”).
However, at least one district court has held that transmissions that occur
within a single computer—such as the transmission of keystrokes from the
keyboard to the central processing unit—are not “electronic communications”
within the meaning of Title III. See United States v. Ropp, 347 F. Supp. 2d 831
(C.D. Cal. 2004). In Ropp, the defendant placed a piece of hardware between
the victim’s computer and her keyboard that recorded the signals transmitted
between the two. Id. at 831. Te court found that the acquired communications
were not
“electronic communications” because
“the communications in
question involved preparation of emails and other communications, but
were not themselves emails or any other communication at the time of the
interception.” Id. at 835 n.1. Because the court found that the typing was
a communication within the victim’s own computer, it reasoned that “[a]t
the time of interception, [the communications] no more affected interstate
commerce than a letter, placed in a stamped envelope, that has not yet been
mailed.” Id. Te court further stated that the acquired keystrokes could not be
an “electronic communication” under Title III because these transmissions were
not made by a “system that affects interstate or foreign commerce.” Id. at 837.
In the court’s view, a computer is not a “system that affects interstate or foreign
commerce” simply by virtue of the fact that it is connected to the Internet or to
164
Searching and Seizing Computers
another external network at the time of the electronic transmission; rather, the
relevant inquiry is whether the computer’s network connection was involved
in the transmission. See id. at 837-38. At least one court has criticized Ropp on
the ground that it “seems to read the statute as requiring the communication
to be traveling in interstate commerce, rather than merely ‘affecting’ interstate
commerce.” Potter v. Havlicek, 2007 WL 539534, at *8 (S.D. Ohio Feb. 14,
2007). Te court explained that “keystrokes that send a message off into
interstate commerce ‘affect’ interstate commerce.” Id.
Notwithstanding the Ropp decision, investigators should use caution
whenever they acquire the contents of communications on computers or internal
networks in real time. For additional discussion of the statute and relevant
legislative history as it relates to the meaning of “electronic communication,”
see U.S. Department of Justice, Prosecuting Computer Crimes (Office of Legal
Education 2007), section II.A.4. Agents and prosecutors may call CCIPS at
(202) 514-1026, OEO at (202) 514-6809, or the CHIP within their district
(see Introduction, p. xii) for additional guidance in specific cases.
“Intercept”
The structure and language of the SCA and Title III require that
the term “intercept” be applied only to communications acquired
contemporaneously with their transmission.
Title III defines
“intercept” as
“the aural or other acquisition of the
contents of any wire, electronic, or oral communication through the use of any
electronic, mechanical, or other device.” 18 U.S.C. § 2510(4). Te statutory
definition of
“intercept” does not explicitly require that the
“acquisition”
of the communication be contemporaneous with the transmission of the
communication. However, a contemporaneity requirement is necessary to
maintain the proper relationship between Title III and the SCA’s restrictions
on access to stored communications. Otherwise, for example, a Title III order
could be required to obtain unretrieved email from a service provider.
Most courts have held that both wire and electronic communications are
“intercepted” within the meaning of Title III only when such communications
are acquired contemporaneously with their transmission. An individual who
obtains access to a stored copy of the communication does not “intercept” the
communication. See, e.g., Steve Jackson Games, Inc. v. United States Secret Service,
36 F.3d 457, 460-63 (5th Cir. 1994) (access to stored email communications);
4. Electronic Surveillance
165
Fraser v. Nationwide Mut. Ins. Co., 352 F.3d 107, 113-14 (3d Cir. 2003)
(same); Konop v. Hawaiian Airlines, Inc., 302 F.3d 868, 876-79 (9th Cir. 2002)
(website); United States v. Steiger, 318 F.3d 1039, 1047-50 (11th Cir. 2003)
(files stored on hard drive); United States v. Mercado-Nava, 486 F. Supp. 2d
1271, 1279 (D. Kan. 2007) (numbers stored in cell phone); United States v.
Jones, 451 F. Supp. 2d 71, 75 (D.D.C. 2006) (text messages); United States v.
Reyes, 922 F. Supp. 818, 836-37 (S.D.N.Y. 1996) (pager communications);
Bohach v. City of Reno, 932 F. Supp. 1232, 1235-36 (D. Nev. 1996) (same).
However, the First Circuit has suggested that the contemporaneity requirement,
which was developed during the era of telephone wiretaps, “may not be apt
to address issues involving the application of the Wiretap Act to electronic
communications.” United States v. Councilman, 418 F.3d 67, 79-80 (1st Cir.
2005) (en banc) (citing In re Pharmatrak, Inc. Privacy Litigation, 329 F.3d
9, 21 (1st Cir. 2003)); see also Potter v. Havlicek, 2007 WL 539534, at *6-
7 (S.D. Ohio Feb. 14, 2007) (finding “substantial likelihood” that the Sixth
Circuit will find the contemporaneity requirement does not apply to electronic
communications).
Notably, there is some disagreement between circuits about whether
a computer communication is “intercepted” within the meaning of Title
III if it is acquired while in “electronic storage,” as defined in 18 U.S.C. §
2510(17). Te Ninth Circuit has held that in order for a communication to
be “intercepted” within the meaning of Title III, “it must be acquired during
transmission, not while it is in electronic storage.” See Konop, 302 F.3d at 878.
Te unstated implication of this holding is that communications in electronic
storage are necessarily not in transmission. Te First Circuit has held, however,
that email messages are intercepted within the meaning of Title III when
they are acquired while in “transient electronic storage that is intrinsic to the
communication process.” United States v. Councilman, 418 F.3d 67, 85 (1st
Cir. 2005) (en banc). In so holding, the court suggested that an electronic
communication can be in “electronic storage” and in transmission at the
same time. See id. at 79. Exactly how close in time an acquisition must be to
a transmission remains an open question. It is clear that “contemporaneous”
does not mean “simultaneous.” However, the Eleventh Circuit suggested that
“contemporaneous” must equate with a communication “in flight.” United
States v. Steiger, 318 F.3d 1039, 1050 (11th Cir. 2003). By contrast, the First
Circuit held the contemporaneity requirement could be read simply to exclude
acquisitions “made a substantial amount of time after material was put into
166
Searching and Seizing Computers
electronic storage.” In re Pharmatrak, Inc. Privacy Litigation, 329 F.3d 9, 21
(1st Cir. 2003).
3. Exceptions to Title III’s Prohibition
Title III broadly prohibits the intentional interception, use, or disclosure2 of
wire and electronic communications unless a statutory exception applies. See 18
U.S.C. § 2511(1). In general, this prohibition bars third parties (including the
government) from wiretapping telephones and installing electronic “sniffers”
that read Internet traffic.
Te breadth of Title III’s prohibition means that the legality of most
surveillance techniques under Title III depends upon the applicability of a
statutory exception. Title III contains dozens of exceptions that may or may not
apply in hundreds of different situations. In cases involving computer crimes
or computer evidence, however, seven exceptions are especially pertinent:
a. interception pursuant to a § 2518 court order;
b. the ‘consent’ exceptions, § 2511(2)(c)-(d);
c. the ‘provider’ exception, § 2511(2)(a)(i);
d. the ‘computer trespasser’ exception, § 2511(2)(i);
e. the ‘extension telephone’ exception, § 2510(5)(a);
f. the
‘inadvertently obtained criminal evidence’ exception,
§ 2511(3)(b)(iv); and
g. the ‘accessible to the public’ exception, § 2511(2)(g)(i).
a. Interception Authorized by a Title III Order, 18 U.S.C. § 2518
Title III permits law enforcement to intercept wire and electronic
communications pursuant to a court order under 18 U.S.C. § 2518 (a “Title
III order”). High-level Justice Department approval is required for federal
Title III applications, by statute in the case of wire communications, see 18
U.S.C. § 2516(1), and by Justice Department policy in the case of electronic
communications (except for numeric pagers). See United States Attorneys’
Manual § 9-7.100. When authorized by the Justice Department and signed by
2 As the focus of this manual is obtaining electronic evidence, prohibited
“use”
and “disclosure” are beyond the scope of this manual. Use and disclosure of intercepted
communications are discussed in chapter 2 of CCIPS’s Prosecuting Computer Crimes (Office of
Legal Education 2007) and part XI of OEO’s Electronic Surveillance Manual (2005 ed.).
4. Electronic Surveillance
167
a United States district court or court of appeals judge, a Title III order permits
law enforcement to intercept communications for up to thirty days. See 18
U.S.C. § 2518(5).
Title III imposes several formidable requirements that must be satisfied
before investigators can obtain a Title III order. See 18 U.S.C. §§ 2516-2518.
Most importantly, the application for the order must show probable cause to
believe that the interception will reveal evidence of a predicate felony offense
listed in § 2516. See § 2518(3)(a)-(b). For federal agents, the predicate felony
offense must be one of the crimes specifically enumerated in § 2516(1)(a)-(s)
to intercept wire communications, or any federal felony to intercept electronic
communications. See 18 U.S.C. § 2516(3). Te predicate crimes for state
investigations are listed in 18 U.S.C. § 2516(2). Te application for a Title
III order also (1) must show that normal investigative procedures have been
tried and failed, or reasonably appear to be unlikely to succeed or to be too
dangerous, see § 2518(1)(c); and (2) must show that the surveillance will be
conducted in a way that minimizes the interception of communications that
do not provide evidence of a crime. See § 2518(5).
For comprehensive guidance on the requirements of 18 U.S.C. § 2518,
agents and prosecutors should consult the Electronic Surveillance Unit of
OEO at (202) 514-6809.
b. Consent of a Party to the Communication,
18 U.S.C. § 2511(2)(c)-(d)
Te consent exceptions under paragraphs 2511(2)(c) and (d) are perhaps
the most frequently used exceptions to Title III’s general prohibition on
intercepting communications. Te first consent exception applies to those
acting under color of law:
It shall not be unlawful under this chapter for a person acting
under color of law to intercept a wire, oral, or electronic
communication, where such person is a party to the
communication or one of the parties to the communication
has given prior consent to such interception.
18 U.S.C. § 2511(2)(c). Under Title III, government employees are not
“acting under color of law” merely because they are government employees.
See Tomas v. Pearl, 998 F.2d 447, 451 (7th Cir. 1993). Whether a person is
acting under color of law under Title III depends on whether the individual
168
Searching and Seizing Computers
was acting at the government’s direction when conducting the interception. See
United States v. Andreas, 216 F.3d 645, 660 (7th Cir. 2000); United States v.
Craig, 573 F.2d 455, 476 (7th Cir. 1977); see also Obron Atlantic Corp. v. Barr,
990 F.2d 861, 864 (6th Cir. 1993); United States v. Tousant, 619 F.2d 810, 813
(9th Cir. 1980).
Te second consent exception applies more generally:
It shall not be unlawful under this chapter for a person
not acting under color of law to intercept a wire, oral, or
electronic communication where such person is a party
to the communication or where one of the parties to the
communication has given prior consent to such interception
unless such communication is intercepted for the purpose of
committing any criminal or tortious act in violation of the
Constitution or laws of the United States or of any State.
18 U.S.C. § 2511(2)(d). A criminal or tortious purpose must be a purpose
other than merely to intercept the communication to which the individual is
a party. See Roberts v. Americable Int’l, Inc., 883 F. Supp. 499, 503 (E.D. Cal.
1995).
In general, both of these provisions authorize the interception of
communications when one of the parties to the communication consents
to the interception.3 For example, if an undercover government agent or
informant records a telephone conversation between herself and a suspect, her
consent to the recording authorizes the interception.4 See, e.g., Obron Atlantic
Corp. v. Barr, 990 F.2d 861, 863-64 (6th Cir. 1993) (relying on § 2511(2)(c)).
Similarly, if a private person records her own telephone conversations with
others, her consent authorizes the interception unless the commission of a
criminal or tortious act was at least a determinative factor in her motivation
for intercepting the communication. See United States v. Cassiere, 4 F.3d 1006,
1021 (1st Cir. 1993) (interpreting § 2511(2)(d)).
Courts have provided additional guidance about who constitutes a “party.”
For example, a police officer executing a warrant who answers the phone and
3 State surveillance laws may differ. Some states forbid the interception of communications
unless all parties consent.
4 DOJ policy sets forth certain approval requirements for consensual interception of
oral communications. See United States Attorneys’ Manual § 9-7.302 (citing 2002 Attorney
General Guidelines). Approval from OEO is required in certain sensitive circumstances; AUSA
approval is required at a minimum.
4. Electronic Surveillance
169
pretends to be the defendant is a party to the communication. See United States
v. Campagnuolo, 592 F.2d 852, 863 (5th Cir. 1979). At least one court has held
that someone whose presence is known to other communicants may be a party,
even if the communicants do not address her, nor she them. See United States
v. Tzakis, 736 F.2d 867, 871-72 (2d Cir. 1984).
Consent under subsections 2511(2)(c) and (d) may be express or implied.
See United States v. Amen, 831 F.2d 373, 378 (2d Cir. 1987). Te key to
establishing implied consent in most cases is showing that the consenting party
received actual notice of the monitoring and used the monitored system anyway.
See United States v. Workman, 80 F.3d 688, 693 (2d Cir. 1996); Griggs-Ryan v.
Smith, 904 F.2d 112, 116-17 (1st Cir. 1990) (“[I]mplied consent is consent
in fact which is inferred from surrounding circumstances indicating that the
party knowingly agreed to the surveillance.”) (internal quotations omitted);
Berry v. Funk, 146 F.3d 1003, 1011 (D.C. Cir. 1998) (“Without actual notice,
consent can only be implied when the surrounding circumstances convincingly
show that the party knew about and consented to the interception.”) (internal
quotation marks omitted). However, consent must be “actual” rather than
“constructive.” See In re Pharmatrak, Inc. Privacy Litigation, 329 F.3d 9, 19-20
(1st Cir. 2003) (citing cases). Proof of notice to the party generally supports the
conclusion that the party knew of the monitoring. See Workman, 80 F.3d. at
693; but see Deal v. Spears, 980 F.2d 1153, 1157 (8th Cir. 1992) (finding lack
of consent despite notice of possibility of monitoring). Absent proof of notice,
the government must “convincingly” show that the party knew about the
interception based on surrounding circumstances in order to support a finding
of implied consent. United States v. Lanoue, 71 F.3d 966, 981 (1st Cir. 1995),
abrogated on other grounds by United States v. Watts, 519 U.S. 148 (1997). Mere
knowledge of the capability of monitoring does not imply consent. Watkins v.
L. M. Berry & Co., 704 F.2d 577, 581 (11th Cir. 1983).
i.
Bannering and Consent
Monitoring use of a computer network does not violate Title III
after users view an appropriate network banner informing them
that use of the network constitutes consent to monitoring.
In computer cases, a network banner alerting the user that communications
on the network are monitored and intercepted may be used to demonstrate that
a user consented to intercepting communications on that network. A banner is
a posted notice informing users as they log on to a network that their use may
170
Searching and Seizing Computers
be monitored, and that subsequent use of the system constitutes consent to
the monitoring. Often, a user must click to consent to the terms of the banner
before gaining further access to the system; such a user has explicitly consented
to the monitoring of her communications. Even if no clicking is required,
a user who sees the banner before logging on to the network has received
notice of the monitoring. By using the network in light of the notice, the user
impliedly consents to monitoring pursuant to 18 U.S.C. § 2511(2)(c)-(d).
Numerous courts have held that explicit notices that prison telephones would
be monitored generated consent to monitor inmates’ calls. See United States
v. Conley, 531 F.3d 56, 58-59 (1st Cir. 2008); United States v. Verdin-Garcia,
516 F.3d 884, 894-95 (10th Cir. 2008); United States v. Workman, 80 F.3d
688, 693-94 (2d Cir. 1996); United States v. Amen, 831 F.2d 373, 379 (2d Cir.
1987). In the computer context, one court rejected an employee’s challenge to
his employer’s remote monitoring of his Internet activity based on a banner
authorizing the employer to “monitor communications transmitted” by the
employee. United States v. Greiner, 2007 WL 2261642, at *1 (9th Cir. 2007).
Te scope of consent generated by a banner generally depends on the
banner’s language: network banners are not “one size fits all.” A narrowly worded
banner may authorize only some kinds of monitoring; a broadly worded banner
may permit monitoring in many circumstances for many reasons. For example,
a sensitive Department of Defense computer network might require a broad
banner, while a state university network used by professors and students could
use a narrow one. Appendix A contains several sample banners that reflect a
range of approaches to network monitoring.
In addition to banners, there are also other ways to show that a computer
user has impliedly consented to monitoring of network activity. For example,
terms of service agreements and computer use policies may contain language
showing that network users have consented to monitoring. See, e.g., United
States v. Angevine, 281 F.3d 1130, 1132-34 (10th Cir. 2002) (university’s
computer use policy stated, inter alia, that the university would periodically
monitor network traffic); United States v. Simons, 206 F.3d 392, 398 (4th Cir.
2000) (government employer’s Internet usage policy stated that employer would
periodically monitor users’ Internet access as deemed appropriate); Borninski v.
Williamson, 2005 WL 1206872, at *13 (N.D. Tex. May 17, 2005) (employee
signed Application for Internet Access, which stated that use of system implied
consent to monitoring).
4. Electronic Surveillance
171
ii. Who is a “Party to the Communication” in a Network Intrusion?
Sections 2511(2)(c) and (d) permit any “person” who is a “party to the
communication” to consent to monitoring of that communication. In the case
of wire communications, a “party to the communication” is usually easy to
identify. For example, either conversant in a two-way telephone conversation
is a party to the communication. See, e.g., United States v. Davis, 1 F.3d 1014,
1016 (10th Cir. 1993). In a computer network environment, by contrast, the
simple framework of a two-way communication between two parties may
break down. When a hacker launches an attack against a computer network,
for example, he may route the attack through a handful of compromised
computer systems before directing the attack at a final victim. At times, the
ultimate destination of the hacker’s communications may be unclear. Finding
a “person” who is a “party to the communication”—other than the hacker
himself, of course—can therefore be difficult. Because of these difficulties,
agents and prosecutors should adopt a cautious approach to the “party to the
communication” consent exception. In hacking cases, the computer trespasser
exception discussed in subsection (d) below may provide a more certain basis
for monitoring communications.
Te owner of a computer system may satisfy the
“party to the
communication” language when a user sends a command or communication to
the owner’s system. See United States v. Mullins, 992 F.2d 1472, 1478 (9th Cir.
1993) (stating that the consent exception of § 2511(2)(d) authorizes monitoring
of computer system misuse because the owner of the computer system is a
party to the communication); United States v. Seidlitz, 589 F.2d 152, 158 (4th
Cir. 1978) (concluding in dicta that a company that leased and maintained a
compromised computer system was “for all intents and purposes a party to the
communications” when company employees intercepted intrusions into the
system from an unauthorized user using a supervisor’s hijacked account).
c. Te Provider Exception, 18 U.S.C. § 2511(2)(a)(i)
Employees or agents of communications service providers may
intercept and disclose communications to protect the providers’
rights or property. For example, system administrators of
computer networks generally may monitor hackers intruding
into their networks and then disclose the fruits of monitoring to
law enforcement without violating Title III. This privilege belongs
to the provider alone, however, and cannot be exercised by law
172
Searching and Seizing Computers
enforcement. Once the provider has communicated with law
enforcement, the computer trespasser exception may provide a
surer basis for monitoring by law enforcement.
Title III permits
an operator of a switchboard, or an officer, employee, or agent
of a provider of wire or electronic communication service,
whose facilities are used in the transmission of a wire or
electronic communication, to intercept, disclose, or use that
communication in the normal course of his employment while
engaged in any activity which is a necessary incident to the
rendition of his service or to the protection of the rights or
property of the provider of that service, except that a provider
of wire communication service to the public shall not utilize
service observing or random monitoring except for mechanical
or service quality control checks.
18 U.S.C. § 2511(2)(a)(i).
Te “rights or property of the provider” clause of § 2511(2)(a)(i) grants
providers the right “to intercept and monitor [communications] placed over
their facilities in order to combat fraud and theft of service.” United States v.
Villanueva, 32 F. Supp. 2d 635, 639 (S.D.N.Y. 1998). For example, employees
of a cellular phone company may intercept communications from an illegally
“cloned” cell phone in the course of locating its source. See United States v.
Pervaz, 118 F.3d 1, 5 (1st Cir. 1997). Te exception also permits providers
to monitor misuse of a system in order to protect the system from damage or
invasions of privacy. For example, system administrators can track intruders
within their networks in order to prevent further damage. See Mullins, 992 F.2d
at 1478 (need to monitor misuse of computer system justified interception of
electronic communications pursuant to § 2511(2)(a)(i)).
Importantly, the rights and property clause of the provider exception does
not permit providers to conduct unlimited monitoring. See United States v. Auler,
539 F.2d 642, 646 (7th Cir. 1976). Instead, the exception permits providers
and their agents to conduct reasonable monitoring that balances the providers’
needs to protect their rights and property with their subscribers’ right to privacy
in their communications. See United States v. Harvey, 540 F.2d 1345, 1351
(8th Cir. 1976) (“Te federal courts . . . have construed the statute to impose
a standard of reasonableness upon the investigating communication carrier.”);
4. Electronic Surveillance
173
United States v. Councilman, 418 F.3d 67, 82 (1st Cir. 2005) (“indisputable”
that provider exception did not permit provider to read customer email when
done in the hope of gaining a commercial advantage).
Tus, providers investigating unauthorized use of their systems have
broad authority to monitor and disclose evidence of unauthorized use under
§ 2511(2)(a)(i), but should attempt to tailor their monitoring and disclosure
to that which is reasonably related to the purpose of the monitoring. See, e.g.,
United States v. Freeman, 524 F.2d 337, 341 (7th Cir. 1975) (phone company
investigating use of illegal devices designed to steal long-distance service acted
permissibly under § 2511(2)(a)(i) when it intercepted the first two minutes
of every illegal conversation but did not intercept legitimately authorized
communications). Expressed another way, there should be a “substantial nexus”
between the monitoring and the threat to the provider’s rights or property.
United States v. McLaren, 957 F. Supp. 215, 219 (M.D. Fla. 1997); see also
Bubis v. United States, 384 F.2d 643, 648 (9th Cir. 1967) (interpreting Title
III’s predecessor statute, 47 U.S.C. § 605, and holding impermissible provider
monitoring to convict blue box user of interstate transmission of wagering
information).
Agents and prosecutors should refrain from using the provider exception to
satisfy law enforcement needs that lack a substantial nexus with the protection
of the provider’s rights and property. Although the exception permits providers
to intercept and disclose communications to law enforcement to protect
their rights or property, see Harvey, 540 F.2d at 1352, it does not permit law
enforcement officers to direct or ask system administrators to monitor for law
enforcement purposes. Where a service provider supplies a communication
to law enforcement that was intercepted pursuant to the rights and property
exception, courts have scrutinized whether the service provider was acting as
an agent of the government when intercepting communications. For example,
in McClelland v. McGrath, 31 F. Supp. 2d 616 (N.D. Ill. 1998), a user of a
cloned cellular telephone sued police officers for allegedly violating Title III
by asking the telephone company to intercept his calls in connection with a
kidnapping investigation. In denying in part the officers’ motion for summary
judgment, the district court found that a genuine issue of material fact existed
as to whether the phone company was impermissibly acting as the government’s
agent when it intercepted the plaintiff’s call. See id. at 618-19. Te court held
that the officers were not free to ask or direct the service provider to intercept
any phone calls or disclose their contents without complying with the judicial
174
Searching and Seizing Computers
authorization provisions of Title III, regardless of whether the service provider
was entitled to intercept those calls on its own initiative. See id.; see also
United States v. McLaren, 957 F. Supp. at 218-19. However, if the provider’s
interception of communications pursuant to the rights and property clause
preceded law enforcement’s involvement in the matter, no agency existed at the
time of the interception, and the provider exception applies. See United States
v. Pervaz, 118 F.3d 1, 5-6 (1st Cir. 1997).
In light of such difficulties, agents and prosecutors should adopt a cautious
approach to accepting the fruits of future monitoring conducted by providers
under the provider exception. (As discussed below, law enforcement may be
able to avoid this problem by reliance on the computer trespasser exception.)
Law enforcement agents generally should feel free to accept the fruits of
monitoring that a provider collected pursuant to § 2511(2)(a)(i) prior to
communicating with law enforcement about the suspected criminal activity.
After law enforcement and the provider have communicated with each other,
however, the cautious approach is to only accept the fruits of a provider’s
monitoring if certain criteria have been met that indicate that the provider
is monitoring and disclosing to protect its rights or property. Tese criteria
are:
(1) the provider’s rights and property are clearly implicated, and the
provider affirmatively wishes both to intercept and to disclose to protect its
rights or property, (2) law enforcement verifies that the provider’s intercepting
and disclosure was motivated by the provider’s wish to protect its rights or
property, rather than to assist law enforcement, (3) law enforcement has not
tasked, directed, requested, or coached the monitoring for law enforcement
purposes, and (4) law enforcement does not participate in or control the actual
monitoring that occurs. Although not required by law, it is highly recommended
that agents obtain a written document from the private provider indicating the
provider’s understanding of its rights and its desire to monitor and disclose
to protect its rights or property. Review by a CHIP or CCIPS attorney is also
recommended. By following these procedures, agents can greatly reduce the
risk that any provider monitoring and disclosure will exceed the acceptable
limits of § 2511(2)(a)(i). A sample provider letter appears in Appendix G.
Te computer trespasser exception, discussed in subsection (d) below,
was created in part to enable law enforcement to avoid the need to rely on
prospective monitoring by a provider under the rights and property exception.
It is important for agents and prosecutors to keep in mind that the computer
trespasser exception will in certain cases offer a more reliable basis than
4. Electronic Surveillance
175
the provider exception for monitoring an intruder once the provider has
communicated with law enforcement.
Law enforcement involvement in provider monitoring of
government networks creates special problems. Because the lines
of authority often blur, law enforcement agents should exercise
special care.
Te rationale of the provider exception presupposes that a sharp line exists
between providers and law enforcement officers. Under this scheme, providers
are concerned with protecting their networks from abuse, and law enforcement
officers are concerned with investigating crime and prosecuting wrongdoers.
Tis line can seem to break down, however, when the network to be protected
belongs to an agency or branch of the government. For example, federal
government entities such as NASA, the Postal Service, and the military services
have both massive computer networks and considerable law enforcement
presences (within both military criminal investigative services and civilian
agencies’ Inspectors General offices). Because law enforcement officers and
system administrators within the government generally consider themselves
united in having their agency’s best interests in mind, it is possible that law
enforcement agents will consider relying upon provider monitoring, justifying
it under the protection of the provider’s “rights or property.” Although the courts
have not addressed the viability of this theory of provider monitoring, such an
interpretation, at least in its broadest form, may be difficult to reconcile with
some of the cases interpreting the provider exception. See, e.g., McLaren, 957
F. Supp. at 219. CCIPS counsels a cautious approach: agents and prosecutors
should assume that the courts interpreting § 2511(2)(a)(i) in the government
network context will enforce the same boundary between law enforcement and
provider interests that they have enforced in the case of private networks. See,
e.g., United States v. Savage, 564 F.2d 728, 731 (5th Cir. 1977); McClelland,
31 F. Supp. 2d at 619. Accordingly, a high degree of caution is appropriate
when law enforcement agents wish to accept the fruits of monitoring under
the provider exception from a government provider. Agents and prosecutors
may call CCIPS at (202) 514-1026 or the CHIP within their district (see
Introduction, p. xii) for additional guidance in specific cases.
Te “normal course of his employment” and “necessary to the rendition of
his service” clauses of § 2511(2)(a)(i) provide additional contexts in which the
provider exception applies. Courts have held that the first of these exceptions
authorizes a business to receive email sent to an account provided by the business
176
Searching and Seizing Computers
to a former employee or to an account associated with a newly acquired business.
See Freedom Calls Found. v. Bukstel, 2006 WL 845509, at *27 (E.D.N.Y. 2006)
(employer entitled in the normal course of business to intercept emails sent
to account of former employee because, inter alia, “monitoring is necessary
to ensure that . . . email messages are answered in a timely fashion”); Ideal
Aerosmith, Inc. v. Acutronic USA, Inc., 2007 WL 4394447, at *5-6 (E.D. Pa.
2007) (corporation entitled in the normal course of business to intercept emails
sent to business it acquired). Te “necessary to the rendition of his service” clause
permits providers to intercept, use, or disclose communications in the ordinary
course of business when the interception is unavoidable. See United States v.
New York Tel. Co., 434 U.S. 159, 168 n.13 (1977) (noting that § 2511(2)(a)(i)
“excludes all normal telephone company business practices” from the prohibition
of Title III). Tese cases generally arose when analog phone lines were in use.
For example, a switchboard operator may briefly overhear conversations when
connecting calls. See, e.g., Savage, 564 F.2d at 731-32; Adams v. Sumner, 39
F.3d 933, 935 (9th Cir. 1994). Similarly, repairmen may overhear snippets of
conversations in the course of repairs. See United States v. Ross, 713 F.2d 389,
392 (8th Cir. 1983). Tese cases concerning wire communications suggest that
the “necessary incident to the rendition of his service” language would likewise
permit a system administrator to intercept communications in the course of
repairing or maintaining a computer network.5
d. Te Computer Trespasser Exception, 18 U.S.C. § 2511(2)(i)
Title III allows victims of computer attacks to authorize persons “acting
under color of law”6 to monitor trespassers on their computer systems.
Specifically, the computer trespasser exception provides:
It shall not be unlawful under this chapter for a person
acting under color of law to intercept the wire or electronic
communications of a computer trespasser transmitted to,
through, or from the protected computer, if—
5 Te final clause of § 2511(2)(a)(i), which prohibits public telephone companies from
conducting “service observing or random monitoring” unrelated to quality control, limits
random monitoring by phone companies to interception designed to ensure that the
company’s equipment is in good working order. See 1 James G. Carr, Te Law of Electronic
Surveillance, § 3:41, at 3-92 (2007). Tis clause has no application to non-voice computer
network transmissions.
­
6 A person acts under “color of law” within the meaning of the computer trespasser
exception when he or she acts under the government’s direction when conducting the
interception. See supra Section D.3.b.
4. Electronic Surveillance
177
(I) the owner or operator of the protected computer authorizes
the interception of the computer trespasser’s communications
on the protected computer;
(II) the person acting under color of law is lawfully engaged in
an investigation;
(III) the person acting under color of law has reasonable
grounds to believe that the contents of the computer trespasser’s
communications will be relevant to the investigation; and
(IV) such interception does not acquire communications other
than those transmitted to or from the computer trespasser.
18 U.S.C. § 2511(2)(i).
A “computer trespasser” is defined in 18 U.S.C. § 2510(21) to include any
person who accesses a “protected computer”7 without authorization, provided
the person is not “known by the owner or operator of the protected computer
to have an existing contractual relationship with the owner or operator of the
protected computer for access to all or part of the protected computer.”
Under this exception, law enforcement—or a private party acting at the
direction of law enforcement—may intercept the communications of a computer
trespasser transmitted to, through, or from a protected computer. Before
interception can occur, the four requirements found in § 2511(2)(i)(I)-(IV)
must be met. Under the first of these requirements, the owner or operator of the
computer must authorize the interception. In general, although not specifically
required by Title III, it is good practice for investigators to seek written consent
for the interception from the computer’s owner or a high-level agent of that
owner. Under § 2511(2)(i)(IV), investigators may not invoke the computer
trespasser exception unless they are able to avoid intercepting communications
of authorized users. Critically, however, the computer trespasser exception may
be used in combination with other authorities, such as the consent exception
of § 2511(2)(d) and the provider exception of § 2511(2)(a)(I), and in such
cases it may be permissible for investigators to also intercept communications
of authorized users. For example, if all non-trespassing users of a network have
7 Almost any computer connected to the Internet will be a “protected computer.” See 18
U.S.C. § 2510(20) (defining “protected computer” to have “the meaning set forth in section
1030”); 18 U.S.C. § 1030(e)(2) (defining “protected computer” to include any computer used
in or affecting interstate or foreign commerce or communication, as well as most computers
used by the United States government or financial institutions).
178
Searching and Seizing Computers
consented to the monitoring their communications by law enforcement, and if
the computer trespasser exception can be used to monitor the communications
of all trespassers on the network, then law enforcement will be able to monitor
all network communications. Similarly, a provider who has monitored its
system to protect its rights and property under § 2511(2)(a)(i), and who has
subsequently contacted law enforcement to report some criminal activity, may
continue to monitor the criminal activity of trespassers on its system under the
direction of law enforcement using the computer trespasser exception. In such
circumstances, the provider will then be acting under color of law as an agent
of the government.
e. Te Extension Telephone Exception, 18 U.S.C. § 2510(5)(a)
As a result of Title III’s “extension telephone” exception, the statute is not
violated by the use of
any telephone or telegraph instrument, equipment or facility,
or any component thereof, (i) furnished to the subscriber or
user by a provider of wire or electronic communication service
in the ordinary course of its business and being used by the
subscriber or user in the ordinary course of its business or
furnished by such subscriber or user for connection to the
facilities of such service and used in the ordinary course of its
business; or (ii) being used by a provider of wire or electronic
communication service in the ordinary course of its business,
or by an investigative or law enforcement officer in the ordinary
course of his duties.8
18 U.S.C. § 2510(5)(a). Congress intended this exception to have a fairly
narrow application: the exception was designed to permit businesses to monitor
by way of an “extension telephone” the performance of their employees who
spoke on the phone to customers. Te “extension telephone” exception makes
clear that when a phone company furnishes an employer with an extension
telephone for a legitimate work-related purpose, the employer’s monitoring of
employees using the extension phone for legitimate work-related purposes does
not violate Title III. See Briggs v. Am. Air Filter Co., 630 F.2d 414, 418 (5th Cir.
8 Unlike other Title III exceptions, the extension telephone exception is technically a
limit on the statutory definition of “intercept.” See 18 U.S.C. § 2510(4)-(5). However, the
provision acts just like other exceptions to Title III monitoring that authorize interception in
certain circumstances.
4. Electronic Surveillance
179
1980) (reviewing legislative history of Title III); Watkins v. L.M. Berry & Co.,
704 F.2d 577, 582 (11th Cir. 1983) (applying exception to permit monitoring
of sales representatives); James v. Newspaper Agency Corp., 591 F.2d 579, 581
(10th Cir. 1979) (applying exception to permit monitoring of newspaper
employees’ conversations with customers).
Te case law interpreting the extension telephone exception is notably
erratic, largely owing to the ambiguity of the phrase “ordinary course of
business.” Some courts have interpreted “ordinary course of business” broadly
to mean “within the scope of a person’s legitimate concern,” and have applied
the extension telephone exception to contexts such as intra-family disputes.
See, e.g., Simpson v. Simpson, 490 F.2d 803, 809 (5th Cir. 1974) (holding that
husband did not violate Title III by recording wife’s phone calls), overruled in
11th Cir. by Glazner v. Glazner, 347 F.3d 1212, 1214-16 (11th Cir. 2003);
Anonymous v. Anonymous, 558 F.2d 677, 678-79 (2d Cir. 1977) (holding
that husband did not violate Title III in recording wife’s conversations with
their daughter in his custody). Other courts have rejected this broad reading,
and have implicitly or explicitly excluded surreptitious activity from conduct
within the “ordinary course of business.” See, e.g., Adams v. City of Battle Creek,
250 F.3d 980, 984 (6th Cir. 2001) (“[M]onitoring in the ordinary course of
business requires notice to the person or persons being monitored.”); Kempf v.
Kempf, 868 F.2d 970, 973 (8th Cir. 1989) (holding that Title III prohibits all
wiretapping activities unless specifically excepted and that the Act does not have
an express exception for interspousal wiretapping); United States v. Harpel, 493
F.2d 346, 351 (10th Cir. 1974) (“We hold as a matter of law that a telephone
extension used without authorization or consent to surreptitiously record a
private telephone conversation is not used in the ordinary course of business.”);
Pritchard v. Pritchard, 732 F.2d 372, 374 (4th Cir. 1984) (rejecting view that
§ 2510(5)(a) exempts interspousal wiretapping from Title III liability). Some
of the courts that have embraced the narrower construction of the extension
telephone exception have stressed that it permits only limited work-related
monitoring by employers. See, e.g., Deal v. Spears, 980 F.2d 1153, 1158 (8th Cir.
1992) (holding that employer monitoring of employee was not authorized by
the extension telephone exception in part because the scope of the interception
was broader than that normally required in the ordinary course of business).
Tere is also some ambiguity as to whether and how the extension telephone
exception would apply in the computer context because the provision’s reference
to “any telephone or telegraph instrument, equipment or facility” is not entirely
180
Searching and Seizing Computers

 

 

 

 

 

 

 

Content      ..     32      33      34      35     ..