← Back to context

Comment by edot

11 hours ago

I get what you're saying, but "the company reviews each request for data it gets to ensure it is legal" just sounds like something a judge should do, no?

>but "the company reviews each request for data it gets to ensure it is legal" just sounds like something a judge should do, no?

No, unless you're arguing that the government should be barred from even making voluntary requests at all? I'm not sure I'd agree with that either though, there's plenty of times where a government request really is just an honest "request" for pure info, like a poll or survey or something on how a program is working and any feedback participants want to give. Though of course it's also easy to see how things like 3rd party doctrine have expanded in effect over time and gotten badly abused, particularly in combination with other levers government has. Perhaps that doctrine should be abolished and the government shouldn't be able to make "voluntary requests" for anything that'd touch on a criminal or civil investigation (so they'd still be able to ask for surveys and the like), but that'd require some careful consideration. Or maybe there are some reasonable limits in terms of data automatically and unavoidably collected (like cellular location) vs data voluntarily shared.

Regardless however, if the government wants to compel somebody to comply, well that's literally what a warrant (or court order) is for right? If the government chooses not to involve a judge in a request for data that'd require a warrant to force, then yeah of course the private party they're asking gets to decide whether to voluntarily go along with that or not. That's the trade.

  • > No, unless you're arguing that the government should be barred from even making voluntary requests at all?

    IMHO the third-party doctrine is an area where legislators ought to be passing laws to broaden constitutional protections, in suitably nuanced way, to keep up with the times. In the modern age, people reveal a great deal of information about themselves to third parties in the course of carrying out mundane tasks.

    The idea that fourth amendment protections apply to physical mail, but not to e-mail [1] doesn't really make much sense.

    Unfortunately this is the sort of thing change that really needs to come from legislators, and the legislative process isn't very effective at the moment.

    [1] except for the 0.1% of people who self-host their own e-mail server in their own home

> ...but "the company reviews each request for data it gets to ensure it is legal" just sounds like something a judge should do, no?

This is assuming the first pass is before a judge. They're circumventing this by going straight to the companies, as noted by the following blurbs:

> This time, DHS utilized a different method that didn’t require approval from a judge, only a sign-off from a DHS official.

and

> It also instructed the recipients of the summons to keep it secret.

In most cases, a company's legal team will attempt to validate the legality of a request because, if they just acquiesce, it becomes a legal problem for them to turn over data without that validation of legality - which can have financial repercussions.

In those cases, the government most often will not (and cannot) step in to save them from the financial blowback (i.e.: the government got what it wanted; it's not their problem, now).

Company legal departments should absolutely review requests and make sure they're legal before handing over data.

If they suspect the request isn't legal, they can refuse it, and then it can be escalated to a judge.

Are you suggesting that every request should go through a judge before it gets sent to a company? That would be great, but even then, different judges interpret laws differently, so a company will still do a legal review before deciding whether or not to comply.