Senators push for update to electronic privacy law

Cloud-based data and mobile-phone location information need to have the same protections as other data, lawmakers say

A 24-year-old law setting the rules on how law enforcement agencies can obtain electronic records needs to be updated because it's out of step with modern technology and privacy expectations, U.S. Senator Patrick Leahy said Wednesday.

Changes to the Electronic Communications Privacy Act (ECPA) will be a priority for the Senate Judiciary Committee, the Vermont Democrat and committee chairman said.

An update to ECPA is needed because Web-based e-mail messages, information stored in cloud-computing environments and mobile-phone location information don't enjoy the same legal protections from government snooping as other types of digital data, several committee members said during a hearing Wednesday.

"The content of a single e-mail could be subject to as many as four different levels of privacy protections under ECPA, depending on where it is stored, and when it is sent," Leahy said. "There are also no clear standards under that law for how and under what circumstances the government can access cell phone, or other mobile location information when investigating crime or national security matters."

Critics of ECPA have called the law confusing and inconsistent.

The U.S. Department of Justice has asserted that under ECPA, federal agents do not need a court-issued warrant to request the contents of e-mail on Web- or cloud-based services, even though agents would need a warrant to see an e-mail stored on a laptop or a document stored in a file cabinet, critics have noted. The ECPA also doesn't require a warrant for unopened e-mail stored with a vendor for longer than 180 days, although law enforcement agencies would need court approval to access unopened e-mail less than 180 days old.

In addition, under the law, police need a warrant to track a suspect by GPS, but not to track a suspect using less precise cell tower location information.

A rewrite of the ECPA would help law enforcement agencies by clearing up confusion about the rules, said James Dempsey, vice president for public policy at the Center for Democracy and Technology (CDT), a digital rights group. A balance between law enforcement needs and privacy that ECPA established in 1986 has been lost, he said.

"Nineteen eight-six was light years ago in Internet time," he added. "Powerful new technologies create and store more and more information about our daily lives and permit the government to conduct surveillance in ways or at a depth and precision that were simply impossible 24 years ago."

While ECPA has been amended 18 times, in most cases, the changes expanded police access to electronic records, Dempsey said. Congress has never completed a comprehensive examination of the law, he said.

Several tech vendors and civil liberties groups launched the Digital Due Process Coalition in March to push for changes to ECPA. Members of the coalition include the CDT, Google, Hewlett-Packard and AT&T.

Microsoft General Counsel Brad Smith and several senators also called for changes to the law. But representatives of the DOJ and the U.S. Department of Commerce called on Congress to carefully consider any changes. ECPA helps law enforcement agents track terrorists, computer hackers, drug traffickers and other criminals, said James Baker, associate deputy attorney general at the DOJ.

In some investigations, quick access to information such as mobile-phone tracking data can save lives, Baker said.

"We urge Congress to proceed with caution, and to avoid amendments that would disrupt the fundamental balance between privacy protection and public safety," he said. "Congress should refrain from making changes that would impair the government's ability to obtain critical information necessary to build criminal, national security and cyber-investigations, particularly if those changes would not provide any appreciable or meaningful improvement in privacy protection."

But Baker also said that President Barack Obama's administration didn't have any immediate recommendations on how to change ECPA. Leahy and Senator Sheldon Whitehouse, a Rhode Island Democrat, said they were frustrated that two Obama administration witnesses offered no proposals for improving the law.

"It's getting a little late to come before a congressional committee and not have a point of view, unless they want to be out of the debate and be commentators," Whitehouse said.

Leahy said he doubts that Congress can finish ECPA reform during this session. If Democrats retain the Senate majority in November's elections, Leahy would return as Judiciary Committee chairman. Leahy promised to push the issue in coming months.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags privacycloud computingmobileregulationinternetGooglelegislationtelecommunicationHewlett-Packardat&tPatrick LeahyBrad SmithJames BakerJames Dempsey

More about C2CDTCounselCPA AustraliaDepartment of JusticeDOJGoogleHewlett-Packard AustraliaIDGIslandMicrosoftWikipedia

Show Comments
[]