Article

User Data for Investigations: Who Is Sharing?

Jan 01, 0001

Fraud examiners, whether working in law enforcement or the private sector, know that their investigations can benefit from the vast amount of data stored by Internet service providers (ISPs). User-created content such as photographs, messages, and personal status updates help examiners discover motives, incriminating statements, conflicts of interest, and much more.

May 2013

By Jacob Parks, J.D., CFE

 

Fraud examiners, whether working in law enforcement or the private sector, know that their investigations can benefit from the vast amount of data stored by Internet service providers (ISPs). User-created content such as photographs, messages and personal status updates help examiners discover motives, incriminating statements, conflicts of interest and much more. Additionally, location-tracking by ISPs is becoming more and more common. For years law enforcement went to great efforts to follow or plant tracking devices on criminal suspects. Now, mobile devices with locating applications functionally serve as voluntary tracking devices, once a warrant is obtained. And the amount of data from ISPs and their users is only going to grow.

 

The issue is how fraud examiners, in their respective roles, can access this information legally and ethically. There are many competing values when it comes to data stored online, including privacy rights versus criminal justice. Due to the rapid evolution of online data and the reactive development of relevant laws, the boundaries are not always clear. The procedure for obtaining user data from an ISP is often dependent on the company’s policies, and some are more likely to cooperate than others. Likewise, users of ISPs will have different attitudes with respect to their privacy.

 

Government Investigations 

Investigations into online data by law enforcement and other government actors are legally murky. Constitutional protections against unreasonable search and seizure are largely defined by a person’s reasonable expectation of privacy in the area searched, and how much privacy a person can expect in online information stored by a social networking site such as Facebook is arguable. Moreover, that expectation is likely different for other types of ISPs, such as telecommunications providers. What is clear is that compelled disclosure of user communications from ISPs requires a warrant based on probable cause, but some ISPs provide such information to enforcement agencies without a warrant.

 

In April, the Electronic Frontier Foundation (EFF) released the third edition of its Online Service Providers’ Privacy and Transparency Practices Regarding Government Access to User Data report (available here), which is of interest to several groups. First, consumer privacy advocates would like to know how major online services are handling user data when law enforcement comes knocking. The image of online service providers is also at stake, as reports such as this one affect how users gauge the protection of their privacy with these companies. On the flip side, the report informs government investigators what level of cooperation to expect when dealing with certain online service providers, as well as overall trends in these types of companies. 

 

The report evaluates specific providers based on six criteria:

Whether the company requires a warrant before providing content of user communications 

Whether the company provides notice to users regarding government data requests 

Whether the company publishes transparency reports on how often it provides user data to law enforcement 

To what extent the company publishes law enforcement guidelines detailing how it handles law enforcement requests for user data 

To what extent the company fights against overbroad evidence requests in court 

Whether the company lobbies for users’ privacy rights in legislatures 

 

 

 

When comparing the EFF’s 2013 ratings to previous years, the general trend is that companies are either conforming to more of the criteria evaluated by the EFF or are at least not losing the “stars” that they previously obtained. For example, Dropbox went from having one out of four stars in 2011 to 5 out of 6 stars in 2013 (the EFF’s rating system added the warrants and law enforcement guidelines categories in 2013). Similarly, the largest social networking sites in the evaluation—Facebook, LinkedIn, and Twitter—gained a higher number of stars over the course of each year in the three editions.

 

Perhaps through a combination of pressure from consumers and influence from models of conduct such as this one produced by the EFF, large social networks and search ISPs (with the exception of Yahoo!) are trending toward protecting user privacy from law enforcement requests. However, it is important to note that the wireless phone service providers — AT&T and Verizon — have stayed with policies that favor cooperation with law enforcement; these companies did not obtain a higher number of stars than they received in 2011. The latter trend might be due to the fact that enforcement agencies such as the Department of Justice have historically entered into immunity agreements with wireless providers regarding wiretapping operations. Communications are to some degree shifting to newer ISPs such as social networks and voice-over-Internet providers, leaving traditional wiretapping methods less relevant than they were only a few years ago.

 

However, ISPs might have less control in how they respond to law enforcement requests in the future. The FBI and other enforcement agencies are voicing complaints that the government’s ability to wiretap suspected criminals is falling behind technology. As the EFF report demonstrates, several ISPs other than traditional wireless providers are making it difficult for government agencies to obtain information. Many ISPs end up failing to provide the requested information because they do not have a mechanism to intercept the desired communications (e.g., capturing a peer-to-peer webcam conversation). The White House is considering submitting to Congress an FBI proposal that would fine ISPs daily for failing to comply with wiretap orders. Internet privacy advocates and some ISPs are resisting such proposals, so the final outcome is not certain at this point.

 

Private Investigations 

The issue of ISPs sharing user communications with non-governmental parties is simpler than the rules for law enforcement: the answer is no. Under the Stored Communications Act, ISPs are prohibited from providing user communication information to non-governmental parties, even in response to a civil subpoena. While basic account information (i.e., not communications) might be available by subpoena under some circumstances, these instances are rare.

 

Yet, private litigants still request and obtain users’ ISP information in investigations and through discovery processes in litigation. In most cases, the person sharing the information is the user. There are three basic ways to obtain this information as a non-government party. First, the information that an ISP user publicly displays (e.g., a public tweet from Twitter or a status update on a public Facebook account) is fair game because the user has no reasonable expectation of privacy to these communications. Therefore, claims of invasion of privacy would not be effective. Additionally, a user might have a private account but voluntarily hand over information that the user is able to access from the account. In the event that a party does not voluntarily provide the information after a valid discovery request, a court can compel a party to produce relevant user data within the scope of the party’s access. Some ISPs, such as Facebook, will restore information from deleted or deactivated accounts to the extent possible. Even so, this process involves the user handing over the data, not the ISP.

 

Similar to requesting a person’s or company’s email records, discovery requests for social media and other ISP information are often very broad. Sometimes parties request virtually every photo, message and other items of information that the user can access. With the advanced search functions available for digital discovery, this strategy might seem to be the best option. However, examiners should work with counsel to come up with the specific requests that are likely to lead to relevant evidence during civil discovery. Requesting everything and the kitchen sink can backfire. For instance, in Chauvin v. State Farm Mut. Auto. Ins. Co., U.S. Dist. LEXIS 71101 (S.D. Mich. June 21, 2011), one of the parties sought to compel the opposing party to hand over email and Facebook account passwords, which would have effectively given the requesting party access to everything available on those accounts. However, the court accepted the responding party’s argument that the request was overly broad, denied the discovery request, and ordered the requesting party to pay costs. In other words, there might be relevant evidence stored on a user’s ISP account, but requests that are not tailored to the situation can cost the party making them. Examiners can aid in litigation by providing the specific type of evidence that might reasonably be expected on a user’s ISP account or other location.

 

As the means by which people commonly communicate change, fraud examiners must also adapt. The good news is that the wealth of information that can aid investigations is growing, but accessing it within the law is not a simple task. By knowing what is legally required and what to reasonably expect when asking for data from ISPs or their users, government and private investigators can more effectively gather evidence. Additionally, everyone in the investigation process should collect information while respecting the spirit of constitutional search and seizure protections and the basic dignity of privacy.