Skip to content
Policy

The cloud and the future of the Fourth Amendment

The Fourth Amendment to the US Constitution provides that the people shall "be …

David A. Couillard | 55
Story text

In mid-April, a coalition of privacy groups filed a brief in federal district court in Colorado, defending Yahoo against attempts by the federal government to obtain the contents of Yahoo Mail messages without first obtaining a warrant. One month earlier, the Justice Department filed a 17-page brief arguing that Yahoo Mail messages do not fall under current statutory protection because, once opened, those messages are not considered to be in “electronic storage.”

The privacy coalition—which included Google—came to Yahoo’s defense, arguing that users with e-mail stored in the cloud have a reasonable expectation of privacy in the contents of that e-mail, and should thus be protected from warrantless searches by the government. (Hopefully the irony of Google opposing robust searches is not lost on Google’s attorneys.)

Unfortunately, the protections afforded by the warrant requirement have not yet been fully extended to the digital “cloud.” This handy metaphor for the ethereal Internet as a storage and access hub is coming to have other implications: can we really conceal our data inside this cloud, shielding it from government intrusion?

In fact, there is not even any guarantee that e-mails stored locally on a personal home computer will be afforded such protection. But as this novel question has remained unanswered by the sloth-like pace of legal innovation, a dozen more questions have cropped up. Meanwhile, the technological innovators are demanding faster answers.

The fourth amendment and reasonable expectations of privacy

The Fourth Amendment to the US Constitution provides that the people shall “be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures…” The Fourth Amendment also provides a method by which an otherwise unreasonable search might be characterized as “reasonable” and, therefore, constitutionally valid: by aid of a warrant, issued “upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized.”

Requiring law enforcement to properly justify itself before conducting invasive searches offers an essential layer of constitutional privacy protection which, if breached, renders the improperly seized evidence inadmissible in court against the person whose privacy was violated. But a warrant is not always necessary to make a search reasonable. In some situations a search and seizure is reasonable without the need for a warrant, such as when items are in plain view, or when a person consents to being searched.

Over time, the courts have developed a standard for determining when a search requires a warrant and when it is reasonable on its own. This standard, which requires a warrant only if there exists a “reasonable expectation of privacy,” originated from a 1967 Supreme Court case involving the wiretapping of a phone booth. In that case, because the phone booth had a door which could be shut behind the user, he was deemed to have reasonably expected that nobody was listening in. The presence of a physical barrier also acted as a legal one.

The “reasonable expectation of privacy” test actually has two requirements. First, the person must have had a subjectively reasonable expectation that the item was private. Second, that item must also be something that society in general is willing to objectively recognize as reasonably private. In other words, it’s not enough that you think your fenced-in backyard is private if society as a whole would find it unreasonable to think so. Sunbathers beware.

Nuances in this standard have developed in the years since the phone booth case. One such nuance is the “third-party doctrine.” For example, the police do not need a warrant to obtain a list of the phone numbers you have dialed and when those calls were made, because, unlike the content of your calls, the transactional data is part of the business records of a third party—the service provider.

Similarly, receipts and checks exchanged with a bank or retailer are not considered to enjoy Fourth Amendment protection, because society is not prepared to reasonably expect privacy in those documents. This third-party doctrine has narrowed the situations in which a warrant is required to conduct a search.

Of course as the courts have narrowed these protections vis-à-vis the Constitution, Congress has passed legislation fortifying the constitutional protections and filling in the gaps created by new technologies. But there are two major problems with those fortifications. First, statutes can be overturned or repealed, whereas constitutional protections provide more permanent safeguards. Second, most of these laws are decades old and have hardly been updated to account for changing technologies.

Among these laws is the Stored Communications Act (SCA), which was passed in 1986. The SCA is at the heart of the dispute between Yahoo and the Justice Department, and the government’s position is that e-mails in the cloud that have already been opened are no longer in “electronic storage,” and thus fall outside the protection of the statute.

Updating these statutes is one short-term option. But, just as Google and the other groups defending Yahoo have argued, there is a basis for interpreting the “reasonable expectation of privacy” standard to cover these new cloud computing and storage uses, shielding at least parts of the cloud with the protection of the warrant requirement.

The differing evolutions of technology and law

The linchpin in extending Fourth Amendment protection to the cloud rests with the reasonableness of society’s expectations governing privacy in the cloud. But societal expectations change over time.

The linchpin in extending Fourth Amendment protection to the cloud rests with the reasonableness of society’s expectations governing privacy in the cloud. But societal expectations change over time, especially as technology and our uses of that technology change.

With massive increases in bandwidth, wireless access, and mobile device use over the past decade, remote storage (and cloud computing generally) has changed the way in which the Internet is used. Rather than being a purely public medium, the Internet has become a means of private storage and mobile or remote access.

This is in stark contrast to ten or fifteen years ago, when data was often uploaded for the intended purpose of sharing it with a mass audience. Bandwidth and access limitations made it unfeasible for everyday Internet users to rely on the cloud to efficiently store and access their private files, and mobile devices were not yet powerful enough or pervasive enough for consumers to even need such “everywhere access.”

Unfortunately, the law generally does not evolve as quickly as technology. The 1967 phone booth case was the first time telephone conversations were recognized as constitutionally protected from unreasonable searches—nearly one hundred years after the telephone was invented. The Internet and cloud computing have taken a fraction of that time to reach wide market penetration, and show little sign of slowing down. But since Moore’s Law does not apply to legal innovation, the disparities between technology and the law are likely to become even greater.

Take, for example, the case City of Ontario v. Quon, currently pending before the US Supreme Court. Although the case is not precisely within the scope of what we often think of as “cloud computing” (online storage and manipulation of e-mails, photos, documents, and so on), it deals in a similar realm—the storage of text messages within the servers of a service provider. The city of Ontario, California, contracted with Arch Wireless to provide text messaging services for, among others, the city’s police department. Although the police department had no official policy regarding use of the pagers for personal versus work-related messaging, the unofficial policy was that if an officer went over the limit but paid the overcharge fee, their messages would not be audited.

The department later decided it would audit some of these texts and found a significant number of sexually explicit personal messages. Several officers sued, claiming their Fourth Amendment rights were violated because the department, being an agent of the government, should have been required to obtain a warrant first. The district court and the Ninth Circuit Court of Appeals both agreed that the officers had a reasonable expectation of privacy in the content of their texts, and analogized the stored text messages to e-mail, among other things.

The Supreme Court just heard oral arguments in Quon on April 19th, and based on the Justices’ questions and demeanors, they did not seem overly sympathetic to the officers’ privacy concerns—at least not enough to extend Fourth Amendment protections to their stored text messages. In part this may be because the facts in this case were simply not compelling enough; society is likely not prepared to recognize that police officers should have an expectation of privacy in their city-issued (and taxpayer-funded) work pagers.

Though the future of Fourth Amendment protection in the cloud will probably not be foreclosed by this case, it may create a hurdle for privacy groups and entities such as Yahoo and Google who are looking for more favorable Fourth Amendment treatment by the Supreme Court. The Court’s decision in Quon should come out later this summer. Whatever the ultimate decision may be, these groups will undoubtedly be looking for any helpful language in the opinion that can be used in the inevitable next case to be brought concerning this issue.

The new digital divide: a tech-savvy judiciary?

A backpack is a “home away from home” for schoolchildren, the Court argued, and briefcases serve a similar function for adults. Why, then, should the same not apply to the documents that we “carry around with us” and access virtually via the cloud?

But what may be just as telling as the forthcoming Quon decision itself is the way in which the Justices attempted to wrap their heads around the technology during oral arguments. For example, Justice Anthony Kennedy asked what happens if a text is sent at the same time that one is being received. Justice Antonin Scalia and Chief Justice John Roberts expressed surprise that the text was routed through the service provider and did not go directly from person to person.

“Could Quon print these—these spicy conversations out and circulate them among his buddies?” Scalia also asked. And even the lawyer representing Officer Quon was not sure whether deleting a message on a pager would also delete it from the service provider’s records. This might paint a worrisome picture of a judiciary that will be making important technology-related decisions with only a limited understanding of that technology.

But it could also be viewed as a judiciary that is making its best efforts at understanding. And the picture is not all dire. During oral arguments Chief Justice Roberts remarked “I just don’t know how you tell what is reasonable. I suspect it might change with how old people are and how comfortable they are with the technology when you have all these different—different factors.” Meanwhile, several of the Justices remarked that, although a police officer using his work pager might not enjoy a reasonable expectation of privacy, a private party’s texting might be a different matter.

Applying the fourth amendment to the cloud

So how can people protect their private data and still enjoy the functionality of the cloud? As cloud-computing services are being used more and more by individuals and businesses, the financial benefits of outsourcing data storage and services to the cloud are being balanced against data security costs. Encryption methods are advancing to meet these security demands, and everyday consumers now have access to encryption tools that even law enforcement cannot easily crack.

But what if law enforcement does crack the encryption? Or what if the government is able to obtain the data by going through the cloud service provider, who may have a back door built into the system despite assurances that your data is password-protected and private? In those instances, although a patchwork of old statutes might provide limited protection in certain circumstances, the broader constitutional protections of the Fourth Amendment have not been widely accepted as applicable. But should they be?

In the phone booth case discussed earlier, the Supreme Court emphasized that the Fourth Amendment protects people, not places. It is our reasonable expectations that shield us from government intrusion, regardless of where that intrusion is. The Court has found that we have a reasonable expectation of privacy in our bags and briefcases which we use to carry “highly personal items” such as photographs, letters, and diaries around with us. A backpack is a “home away from home” for schoolchildren, the Court argued, and briefcases serve a similar function for adults.

The third-party doctrine has its limits, and should not be used to undermine our reasonable expectation of privacy in portions of the cloud.

Why, then, should the same not apply to the photographs, e-mails, and other personal documents that we “carry around with us” and access virtually via the cloud? Those objects do not lose their status as highly personal simply because they are digitized. The Supreme Court has recognized that intangibles such as fleeting telephone conversations are covered by the Fourth Amendment, and other courts have found digital files to be covered as well.

If the nature of the data isn’t the problem, then perhaps the medium is. E-mail aside, until recently the Internet was considered a primarily public medium, used for mass communication and commerce. But this is no longer the case necessarily. Blogs and YouTube accounts can be made private; services like Mozy, Carbonite, and Amazon’s S3 provide digital backup and storage space; and services provided by Google and Apple allow users to access their contact lists, calendars, e-mails, photos, and other documents from their phones or netbooks. None of these uses are public in nature. In fact, many of them are specifically intended to remain private.

This change in Internet usage seems to indicate that society might be prepared to recognize a reasonable expectation of privacy in the cloud, at least in some circumstances. Even if the Internet remains a public medium in some respects, taking a private object into public doesn’t necessarily destroy a person’s reasonable expectation of privacy in that object. But reasonable efforts to conceal that object must be present.

How do you conceal something digitally, though? The primary methods used now are encryption, password-protection, or concealment by obscurity behind unlisted links. In the physical context, the Court has said that a lock is not necessary to create a reasonable expectation of privacy. This is because expectations of privacy are not based upon how easy or difficult it may be to enter a private space. An unlocked house still needs a warrant to be searched because the home is considered reasonably private; and a briefcase or backpack—our “home away from home”—is opaque and generally doesn’t reveal its contents. And although a phone booth has glass walls, it still “conceals” the content of the conversation, which is audible rather than visible. However, illegal activity viewed through the open window of a home, or contraband viewed through a transparent bag, loses that protection because it is not concealed.

But digital objects cannot be concealed by opacity. Instead, the encryption, password-protection, or obscurity of an unlisted link should be considered as a form of opacity, protecting our corner of the cloud as a “home away from home,” just like a briefcase or backpack. This “virtual container” theory has so far only been advanced by one lower court, but it’s a useful analogy as cloud computing is becoming more complex than a simple e-mail inbox. It is a theory such as this that should be applied to the cloud.

The third-party doctrine

Even if society is prepared to recognize portions of the cloud as reasonably private, and even if courts come to recognize digital concealment as adequate, there is still another hurdle to overcome: the third-party doctrine. When you communicate with another person—whether via telephone, e-mail, or letter—you always assume the risk that the other party to your communication will reveal it to the public or law enforcement. Thus, you have no reasonable expectation of privacy vis-à-vis the other party to your conversation.

But is Yahoo a party to your e-mail communication? Is Google a party to your Picasa photo album or Google Doc spreadsheet? Is Apple a party to your contact list stored on MobileMe? If they are, then the government may be able to obtain that that information without a warrant and without your consent.

There are some aspects to online communication that these service providers likely are parties to. The to/from address on your e-mail is used to route it to the correct recipient, just like the to/from address on a letter or the routing and account numbers on a check. But the content of your e-mail, your photo album, your spreadsheet, or your contact list are not transactional information—or at least should not be considered as such.

As Chief Justice Roberts remarked during the Quon arguments, determining which privacy expectations are reasonable “might change with how old people are and how comfortable they are with the technology.”

Problems arise in this area, however. Google’s advertising algorithms scan your e-mails for keywords used to target advertising. Does that make Google a party to the communication? You submit your password every time you log in to an account, so is your password the same as a routing number? And a cloud service provider may reserve limited rights to access the contents of your account, as laid out in their terms of service. Does that make them a party to the contents?

These are all questions that remain unanswered or, at best, vaguely answered by the courts. But simply because your landlord has a copy of your apartment key and limited rights of access for emergency and maintenance purposes does not mean the police can use your landlord to gain access to your home without a warrant. The third-party doctrine has its limits, and should not be used to undermine our reasonable expectation of privacy in portions of the cloud.

Looking to the future

Although the courts can be slow to adapt to changing technology, the extent and speed at which these technologies are pervading society might force the Court to address these issues more quickly than the hundred years it took to deal with the telephone. In the short term, legislative action might be a good way to fill in the current gaps in protection. Congress can generally move more quickly than the courts on issues such as this.

In the long term, however, the best solution might be to continue petitioning the Supreme Court for constitutional answers to these questions. A robust application of the Fourth Amendment to the cloud might offer stronger, more permanent, and more universal protection for digital data. And with a broad enough framework, an extension of the Fourth Amendment standard into the cloud might be able to adequately address future unanticipated issues that arise as new technologies collide with the government’s attempt to search and seize data.

As Chief Justice Roberts remarked during the Quon arguments, determining which privacy expectations are reasonable “might change with how old people are and how comfortable they are with the technology.” Whatever the Court decides this summer, at least this may be a sign that they are thinking seriously about the issue and recognizing the changing uses and expectations that come with technological innovation. At the same time, technology innovators should keep in mind the legal ramifications of their innovations, and perhaps tailor their marketing of these products and services to fit more comfortably within the existing legal paradigm.

55 Comments