CDT FISA Issue Brief: A Warrant Rule for US Person Queries Would Not Prevent Victim-Focused Queries

A critical reform to Section 702 of the Foreign Intelligence Surveillance Act (“FISA 702”) that Congress is considering is a warrant rule for US person queries: To run queries for Americans’ communications obtained via FISA 702, the government would first need to obtain the same type of warrant that would be required for direct collection of those communications.[1] Such a warrant could be obtained under multiple authorities, including FISA Title I (based on probable cause that the target is an agent of a foreign power) and the Wiretap Act (based on probable cause that the surveillance will return evidence of a specified crime). The government has emphasized that some of its US person queries are conducted on identifiers associated with victims of foreign plots, and claimed it would be impossible to run victim queries if a warrant rule is imposed. This is untrue.

A Warrant Rule Would Not Prohibit Victim-Focused Queries as a Matter of Law

Critics of reform have claimed that a warrant rule would make it legally impossible to run queries on the identifiers of individuals not suspected of wrongdoing (such as victims). Earlier this year assistant director of the FBI’s Directorate of Intelligence Tonya Ugoretz argued that for queries of cyberattack victims, “because the … U.S. person [whose] information that we are querying is not the target of investigation, we would not be able to meet the standard for a warrant.” The President’s Intelligence Advisory Board report on FISA 702 similarly claimed that prior victim-focused queries would have been impossible with a warrant rule “because there would have been no probable cause that the user of the U.S. selector was a foreign power or agent of a foreign power.” An intelligence community issue brief also implied that all victim queries would be blocked because “the IC may not have probable cause to believe the U.S. person is a foreign power or agent of a foreign power.”

These claims that a warrant requirement would preclude victim-focused queries are inaccurate as a matter of law. 18 USC 2518—the Wiretap Act rule for obtaining a warrant that could be used as a model for a warrant requirement for US person queries—requires a judge to determine that a particular crime has occurred, and that “there is probable cause for belief that particular communications concerning that offense will be obtained through such interception.” Thus, a warrant rule would not require that the subjects of all queries be targets of investigations or suspected agents of foreign powers. Victims’ identifiers could be queried on as well, so long as the government could show a judge there was probable cause that such a query would return evidence of a specifically enumerated offense; existence of a victim means there is a crime for which evidence can be sought.

The Department of Justice Has Repeatedly Obtained Warrants for Victim-Focused Searches

The claim that it is impossible to obtain warrants focused on victims is also disproven by precedent. The Department of Justice has repeatedly received court approval for search warrants that pertain to victims:

These cases make clear that obtaining a warrant for victim-focused searches is neither impossible nor even a novel concept for the Department of Justice. It has repeatedly engaged in this practice, and could do so in obtaining a warrant for FISA 702 US person queries.

Many Victim Queries Could Be Exempt From Warrant Requirements

All warrant rules contain limited but reasonable exceptions, such as when individuals consent to a search or in exigent circumstances. These exceptions would also apply to a warrant requirement for US person queries. In discussing victim queries, the government has emphasized scenarios such as cyberattacks on infrastructure and plots to kidnap or assassinate US government officials. Such scenarios could often be addressed by obtaining the consent of the victim. For example, after the Colonial Pipeline hack, the FBI could have obtained consent to run a query of communications collected under Section 702 with the company name, IP address, or other company identifiers as a selector as it undertook its investigation.

A Consistent Warrant Rule Is Critical to Preventing AbuseHaving a consistent warrant rule for US person queries of FISA 702 data—including for victim-focused queries—is not just feasible, it is also essential to preventing misconduct. Some of America’s worst surveillance abuses were conducted under the pretext of protecting victims, including surveillance of Dr. Martin Luthor King Jr. and other civil rights leaders and nefarious COINTELPRO activities. Additionally, improper US person queries—such as of a sitting Congressman—have been justified as seeking to determine if the American was the target of a foreign influence operation. There will certainly be instances where the government seeks to conduct queries on the identifiers of victims for legitimate reasons, and it should be able to do so based on a probable cause showing that such queries will return evidence, in emergencies, or with the consent of the victim. But a blanket exemption would needlessly open the door to misconduct.

[1] This issue brief generally refers to “US person queries” as shorthand for queries for communications content, which we believe should require a warrant. The government also conducts queries that return communications metadata rather than content – under proposed reforms, such queries would not require a warrant, and could be made with court approval based on the lower standard that is required for compelled disclosure of metadata.