|
Imagine the government claiming it can open a box of your old letters without a warrant simply because you kept them for more than six months. Absurd? Under a Reagan-era federal law, that is roughly the legal logic applied to your emails. The Electronic Communications Privacy Act (ECPA), passed in 1986, was a landmark bill that established guardrails for the government’s treatment of private communications in the emerging digital world. At that time, emails were usually downloaded to a personal computer and deleted from servers. That law thus contained a loophole that allowed government agencies to obtain stored electronic communications more than 180 days old without a warrant. One tech provider warns that today that “Gmail will NOT automatically delete your old emails after any timeframe. Messages from 5, 10, or even 20 years ago will sit in your account forever unless you manually remove them.” Technology changed. The law didn’t. That is why PPSA applauds Reps. Warren Davidson (R-OH) and Suzan DelBene (D-WA) and Sens. Mike Lee (R-UT) and Ron Wyden (D-OR), for updating the law with the bipartisan Email Privacy Act. The bill would require the government to obtain a warrant before accessing the contents of Americans’ emails and other stored electronic communications, regardless of how long they have been stored. It would also permit service providers to notify customers when the government seeks their information, unless a court orders otherwise. “The Fourth Amendment is clear: the government must get a warrant before searching an individual’s private property, including written communications,” Rep. Davidson said. Sen. Lee similarly noted that “Americans should not lose their Fourth Amendment protections simply because their private communications are stored with a third-party provider.” They are exactly right. Our emails can contain medical information, financial records, family conversations, political discussions, and the intimate details of our daily lives. The idea that constitutional protection should diminish after 180 days is a relic of the dial-up era. This bill also demonstrates that privacy reform remains one of the few issues capable of bringing together serious conservatives and progressives. These legislators deserve our praise for recognizing a simple principle: a private communication does not become government property as it ages. Congress should pass the Email Privacy Act and apply the Fourth Amendment to the reality of 21st century technology. The U.S. Supreme Court’s landmark decision in Chatrie v. United States settled one important question while raising another that Congress can no longer ignore. If the government needs a warrant to compel Google to disclose Americans’ location records, why should it be able to sidestep that requirement by buying the same records from a data broker? Chatrie’s Principles In a 6-3 opinion, the Court held that Americans retain a reasonable expectation of privacy in detailed cellphone location records, even when those records are held by a third party such as Google. Police therefore conduct a Fourth Amendment search when they compel disclosure of that information through a geofence warrant. In writing the majority opinion, Justice Elena Kagan recognized a simple truth about modern life: carrying a smartphone inevitably generates an extraordinarily revealing record of where we go, whom we visit, who our romantic partners are, which churches we attend, what political rallies we join, and countless other intimate details. Americans do not surrender their constitutional privacy merely because technology companies necessarily store that information. But if that is true, an obvious question follows: Why allow the federal government to simply purchase the very same information from a commercial data broker? The Data Broker Loophole Today, at least a dozen federal agencies have acknowledged buying commercially available personal data. These include the FBI, the Drug Enforcement Administration, the IRS, the Department of Homeland Security, the Department of Defense, and elements of the intelligence community. Instead of obtaining a warrant approved by a judge, these agencies often obtain access simply by writing a check. This practice has become known as the “data broker loophole,” a gaping privacy vulnerability that turns the Fourth Amendment inside out. Suppose police could not constitutionally enter your home without a warrant, but could legally pay your neighbor to climb through the window and photograph every room. Few Americans would believe the Constitution permits such an end-run around judicial oversight. Yet that is effectively what has developed in the digital age. Commercial data brokers aggregate astonishing quantities of personal information collected by smartphone apps, advertisers, financial transactions, connected vehicles, and countless online services. These databases can map a person’s movements, habits, religious observance, medical concerns, political associations, and relationships with extraordinary precision. Agencies can often acquire such data without ever demonstrating probable cause to a court. Now, Chatrie pokes holes through the government’s thin rationale by holding that highly revealing location histories remain constitutionally protected even when maintained by private companies. If the Constitution bars the government from compelling disclosure without a warrant, Congress should not permit agencies to obtain the same information merely because a private intermediary has placed it on the market. The bipartisan Fourth Amendment Is Not for Sale Act would close this loophole by requiring government agencies to obtain a warrant before acquiring sensitive commercially available data. The core provisions of that legislation should be incorporated into Section 702 of the Foreign Intelligence Surveillance Act when it comes up for reauthorization. The Supreme Court now recognizes that Americans possess a reasonable expectation of privacy in the digital trails their smartphones inevitably create. Congress should finish the job by closing the data-broker loophole when it reauthorizes Section 702. Jacqueline McNeill of Fayetteville, North Carolina, was driving home from the grocery store – with chicken to prepare for her goddaughter’s funeral, no less – when multiple police cruisers cornered her white Nissan Versa in the parking lot of a convenience store. “I felt like the moment I stepped out of my car,” she later told Tyler Dukes of Raleigh’s The News & Observer, “I was automatically guilty.” The second-grade teacher was arrested on the spot for a drive-by shooting. Jacqueline wasn’t guilty of anything, but that didn’t stop her from becoming a victim of automated license plate readers (ALPRs). Days before, these roadside cameras had spotted a car similar to hers in the vicinity of a shooting. As with so many other surveillance systems, police used this image in place of critical thinking, as visual proof when it was nothing of the sort. And now this far-less-than-foolproof technology – with the privacy protections of a rusted colander – is about to get a massive injection of mission creep. One of the makers of ALPR technology is Leonardo (pro tip before clicking: you might want to decline all cookies). According to Ian Wright of CarBuzz, the company’s SignalTrace technology “is set to move ALPR cameras from just car-tracking to people-tracking devices.” In plain language, that means tracking drivers’ and passengers’ smartphones, vehicle infotainment systems, and any other Bluetooth-capable device – all linked to your license plate or someone else’s. Worse, our devices are uniquely and individually identifiable. In the absence of robust legislation designed to bolster our Fourth Amendment rights, the only thing that can prevent them from being used as straight-up spy tools by authorities is end-to-end encryption. Wright reports the SignalTrace product sheet promises to “create a unique, trackable ‘electronic fingerprint’ for investigative use.” But wait, there’s more! The surveillance dragnet Leonardo is creating includes RFID tags (they’re everywhere, including key cards), pet microchips (so much for taking your dog along on errands), tablets, fitness trackers, tire pressure sensors, and… you get the idea. If there’s a kicker in all of this, it is another passage Wright quotes from the SignalTrace product sheet, which boasts that it “stores device and correlation data securely … for future queries and analysis.” The dystopian quantum leap, Wright notes, is that once implemented, ALPR systems will transition from identifying vehicles to identifying occupants. All of this data will be unbound by time, stored in a permanently searchable database – just in case we need to be retroactively suspected of something that may or may not have been legal once upon a time and that we may or may not have done in a car that we may or may not have been driving (or simply riding in). Calling Steven Spielberg: We just found the sequel to Minority Report. What could go wrong? To name a few risks: false positives; arrests of innocent people; police officers using ALPR systems for stalking and intimidation; and the collection of massive amounts of personal data by for-profit corporations ready, willing, and able to sell that information to any and all comers, including the government. Add to these risks hacking by cybercriminals and bad-faith state actors. It’s all coming to a technocratic authoritarian surveillance state near you. Because of her false arrest that day, Jacqueline McNeill never made it to her goddaughter’s funeral. She also largely avoided driving her Nissan before eventually selling it. And who can blame her? Where you go and who you meet are some of the most revealing facts about you. Does this intimate information deserve to be included within the Fourth Amendment’s protections against “unreasonable searches and seizures”? This question has new force in the wake of the U.S. Supreme Court’s landmark decision in Chatrie v. United States. That ruling strengthened constitutional protection for one form of Americans’ location history – the records of our movements generated by our cellphones and held by third parties like Google. A case before the Fourth Circuit Court of Appeals, Schmidt v. City of Norfolk, extends this concept to the city’s use of automatic license plate readers (ALPRs) in that Virginia city. The plaintiffs demonstrate that Norfolk’s network of cameras continuously photographs them and their vehicles, stores that information, and allows police to reconstruct weeks of their travel history without a warrant. That case, once seen as a bit of a stretch by many legal observers, suddenly looks much more viable after Chatrie. In Chatrie, Justice Elena Kagan wrote the Court’s majority opinion that declared that Americans retain a reasonable expectation of privacy in their location information, even when it is held by a third party. The Court emphasized that the Fourth Amendment must protect citizens against “too permeating police surveillance” and rejected the idea that privacy disappears merely because modern technology records information shared with companies. Those same principles extend naturally to ALPR systems. As PPSA explained in our amicus brief before the Fourth Circuit, the constitutional issue is not whether a single license plate can be seen on a public road. It is the government’s ability to aggregate thousands – or millions – of those observations into a searchable database capable of reconstructing “the whole of a person's physical movements.” The brief warns: “The relevant constitutional question here is whether the government used surveillance technology to collect and aggregate location records that allow retrospective reconstruction of a person's movements. ALPR databases do exactly that.” These retrospective insights go well beyond license plate readers. Modern surveillance increasingly depends on collecting seemingly innocuous bits of location information – from the apps on our cellphones, cellphone records, GPS and vehicle tracking, facial recognition hits, drone footage, and our personal information sold by data brokers to the government. These can all be combined into a detailed dossier on any individual. Each data point may appear harmless. Together, they reveal where we sleep, worship, seek medical care, attend political meetings, and with whom we associate. PPSA's brief argues that this is exactly the type of technological transformation the Supreme Court warned about: “What matters for the Fourth Amendment is the state's use of technology to convert innumerable public-facing moments into a searchable log of a person’s life, not the innocuous nature of any single data point taken alone.” Chatrie may ultimately be remembered not simply as the geofence warrant case, but as the decision that reaffirmed a broader constitutional principle for a host of pervasive forms of surveillance. If that principle is faithfully applied, courts will soon have to ask difficult questions not just about geofence warrants, but about ALPR networks, facial recognition systems, AI-enabled camera platforms, and every other technology that enables the government to reconstruct the movements of ordinary citizens without first obtaining a warrant. The fuse has been lit. Now comes the hard work of ensuring that the Fourth Amendment keeps pace with 21st-century surveillance. The government has yet to respond to a Freedom of Information Act (FOIA) request filed in 2024 by the Cato Institute seeking records on abuses of Section 702 of the Foreign Intelligence Surveillance Act. Court records reveal, however, that the FBI is withholding 39,650 pages responsive to that FOIA request. This should be a matter of vital interest to Congress. Section 702 is a surveillance authority that allows the government to spy on foreign threats on foreign soil, but has been used widely in recent years to warrantlessly spy on millions of Americans whose communications are “incidentally” caught up in the National Security Agency’s global trawl. So you would think that almost 40,000 pages on possible FBI violations of Section 702 would be at the forefront of the debate over whether to add guardrails and reforms as Section 702 faces reauthorization. But Congress has been supine while the FBI promises to release only a meager 128 pages in August. The Privacy and Civil Liberties Oversight Board, which could add clarity to the FBI’s actions, has also been sidelined by the administration. Patrick Eddington, a Cato fellow, wrote: “Congress is being asked to extend, without a warrant requirement, a surveillance program whose compliance record cannot be independently verified, whose oversight bodies have been deliberately disabled, and whose custodians have shown a personal willingness to turn its tools on the press.” The latter is a matter of particular concern. The previous year saw a rise in “sensitive warrantless searches,” or queries that involve political and religious figures or organizations, as well as journalists. When will Congress get curious and demand the information needed to inform the Section 702 debate? Wells v. State of Texas The U.S. Supreme Court’s decision Monday in Chatrie v. United States marked the biggest advance in digital privacy since Carpenter v. United States in 2018. By recognizing that Americans retain a reasonable expectation of privacy in digital location tracking, such as Google’s Location History records, the Court closed a major loophole in Fourth Amendment law. But Chatrie is unlikely to be the final word. Like Carpenter before it, the decision is likely to spark a renewed struggle over how to apply this precedent. One case worth watching is Wells v. State of Texas, which the Supreme Court Tuesday remanded to the Texas Court of Criminal Appeals. The facts are straightforward. In 2018, Dallas police investigating a fatal robbery obtained a geofence warrant directing Google to identify every device that had been present within a defined area around the crime scene during a 25-minute period in the early morning hours. The warrant eventually led investigators to Aaron Wells, who was convicted of capital murder. What makes Wells noteworthy is not the crime but the court's fractured reasoning. Like the Fourth Circuit in Chatrie itself, the Texas Court of Criminal Appeals produced no clear majority rationale. Four judges assumed that obtaining Google's location history constituted a Fourth Amendment search but upheld the warrant because it was supported by probable cause and was – in the language of the Fourth Amendment – sufficiently “particular” about what would be seized. Two of those judges separately explained that the geofence warrant did not involve a constitutional search at all, relying on theories that users surrender their privacy by sharing information with Google. Three other judges concluded that no search occurred for most of the data sought by the warrant. But they further explained that no probable cause existed either because the police obtained a warrant with only the location where a crime occurred, not a suspect. One judge dissented without opinion, and another did not participate. That division matters because Chatrie resolved the question about whether a search occurred, highlighting the importance of the remaining disagreement about the Fourth Amendment’s probable cause and particularity requirements. On that question, the Wells court was divided 4-3, with one justice dissenting but not explaining the basis for his dissent. Now after Chatrie, courts must focus on these difficult questions that divided the Texas Court of Criminal Appeals. In essence, courts will now focus on how broad is too broad. How many innocent people may be swept into an investigation before a warrant becomes the digital equivalent of the general warrants the Fourth Amendment was written to forbid? Those are not academic questions. Geofence warrants have already been used in investigations ranging from bank robberies to protests, and each new case forces courts to balance legitimate law enforcement needs against the privacy rights of countless bystanders whose only “crime” was being nearby. Carpenter reshaped surveillance law for nearly a decade. Chatrie promises to do the same. "Custom-house officers may enter our houses, when they please ... may break locks, bars, and everything in their way; whether they break through malice or revenge, no man, no court can inquire." |
Categories
All
|
RSS Feed