At Last: EPCA Reform Bill to Move Forward with Markup
Consider the vast amount of sensitive information we all store in the cloud. Many years’ worth of emails and text messages shared with family, friends, and coworkers. Back ups of every digital photo – allowing users to revisit memories of anniversaries, kids’ birthday celebrations, and other special moments at any time, from any device. The same is true of other important documents, from sensitive work memos viewed and edited by other coworkers to copies of health records. Maybe even a copy of your just-filed tax return.
Thirty years ago, when the Electronic Communications Privacy Act (ECPA) was enacted, it was a forward-looking statute addressing a brand new technology – email and computer storage. Since that time it has become a crazy patchwork of protections – many of them inadequate. Whether a document is stored on your desktop or in the cloud, whether an email has been opened or not, and whether an email is older or younger than 180 days are by no means indicative of the level of privacy users expect that data to have. The Email Privacy Act would fix all these problems. With 314 cosponsors, it is the most popular bill in the House and the result of more than eight years of efforts to reform ECPA.
Today, the House Judiciary Committee finally moved forward with a markup of the Manager’s Substitute to the Email Privacy Act (H.R. 699), which will amend ECPA so that, with limited exceptions, law enforcement officials will be required to obtain a warrant based on probable cause before searching and seizing data stored in the cloud. It is supported by more than 50 civil society groups, trade associations and companies big and small, and passed the committee by a unanimous vote of 28–0.
The Manager’s Substitute is a compromise where the committee balanced the goals of supporters with those of law enforcement. The bill does not achieve all of the reforms CDT had hoped for. Notably, the Amendment removes a provision that would have required the government to provide notice to the customer when a warrant for their data is served on their provider — an important protection for users against dubious data search and seizure requests. However, the Amendment still preserves providers’ ability to provide such notice, unless the government can successfully demonstrate that disclosure will likely result in one or several enumerated harms (such as destruction of evidence or seriously jeopardizing an investigation).
What did not make its way into the Amendment is just as important. We are particularly pleased that the Amendment did not contain a carve-out for civil agencies. Such a carve-out would have undermined the very purpose of the bill, giving government broad new access to private communications at much lower standards.
We have waited long enough for the law that protects our internet communications to reflect the vast technological changes that have taken place in the past thirty years. CDT hopes that this vote is the beginning of a broader ECPA reform push and ultimately new privacy protections for every American.
Coalition Urges Senate Not to Let Companies Waive Financial Regulations for AI
CDT joined AI Now Institute, American Civil Liberties Union, and several organizations dedicated to tech policy, consumer protection, and civil rights in a letter to Senate leadership and the Senate Banking, Housing, and Urban Affairs Committee opposing the “AI Innovation Labs” language in Sec. 10509 of the CLARITY Act.
CDT-led Coalition Calls for Transparency for White House AI Framework
CDT and Americans for Responsible Innovation led a broad, bipartisan coalition of over two dozen civil society groups in calling on the White House to release its Framework for review of frontier AI models.
CDT Amicus Brief Calls on Fourth Circuit to Rein In Geofence Warrants
Earlier this year the Supreme Court ruled in Chatrie v United States that the Fourth Amendment protected all cell phone location information, which CDT lauded as a landmark decision, but sent the case back down to the Fourth Circuit to assess the propriety of the geofence warrant at issue.
CDT and Partners Post Floor Alert Opposing CA SB 1013 Automated License Plate Readers Bill
The best way to ensure that Automated License Plate Readers are not abused is to limit the retention of stored data and to keep loopholes to lawful process closed. CA SB 1013 is a step in the wrong direction, and we urge the California legislature to reject this approach.