Skip to content
  • Products & Services
  • Security Operations
  • Threat Research
  • AI Research
  • Naked Security
  • Sophos Life
  • Products & Services
  • Security Operations
  • Threat Research
  • AI Research
  • Naked Security
  • Sophos Life
Naked Security Naked Security

NSA metadata collection is illegal, rules US court

Three appeal court judges have ruled that the NSA's bulk collection of metadata went far beyond the original intent of the Patriot Act.
Written by Lee Munson
May 08, 2015
Naked Security bulk data collection edward snowden metadata national security agency NSA phone metadata

NSA. Image courtesy of Carsten Reisinger/ShutterstockA US federal appeals court has ruled that the National Security Agency’s (NSA’s) bulk, warrantless collection of phone records is illegal.

The unanimous decision from the three-judge panel of the Second US Circuit Court of Appeals in New York represents a major victory for opponents of the NSA and its surveillance activities and comes as Congress debates whether to extend or curb the soon-to-sunset legislation that underpins the data collection program.

The appeal court’s ruling undermines many of the legal theories employed by the US government to expand surveillance following the September 11 2001 terror attacks.

While the judges did not rule on whether the NSA program violated privacy rights granted by the US Constitution, they did rule that the wording of the Patriot Act was not sufficient to justify the massive collection of data seen under the Bush and Obama administrations.

In their 97-page ruling the judges wrote:

The statutes to which the government points have never been interpreted to authorize anything approaching the breadth of the sweeping surveillance at issue here. The sheer volume of information sought is staggering.

The ruling will not affect the NSA’s international surveillance efforts but it will go some way in curtailing the agency’s domestic telephone metadata program – which came to light in 2013 when former NSA contractor Edward Snowden leaked documents detailing how the agency was collecting lists of phone numbers called, along with details of the time and duration of each call – in order to aid in the detection of terror suspects.

Though the NSA does not collect the content of the phone conversations, the all-encompassing collection of metadata, the judges noted, was far beyond the original intent of Section 215 of the Patriot Act:

If the government is correct, it could use § 215 to collect and store in bulk any other existing metadata available anywhere in the private sector, including metadata associated with financial records, medical records, and electronic communications (including email and social media information) relating to all Americans.

Such expansive development of government repositories of formerly private records would be an unprecedented contraction of the privacy expectations of all Americans.

The Patriot Act itself was already under threat before this ruling as lawmakers continue to debate Section 215 which is due to expire under a sunset clause on 1 June.

US politicians have already suggested the USA Freedom Act as a possible alternative – it would retain some elements of the Patriot Act while ditching the metadata collection program – hence making this latest decision moot, as noted by the judges:

On April 30, 2015, a modified version of the USA FREEDOM Act, which would limit the bulk metadata program in various ways, was passed by the House Judiciary Committee, see USA FREEDOM Act of 2015, H.R. 2048, 114th Cong. (2015), and a vote in that Chamber is expected later this month.

This latest ruling follows yesterday’s reports that the German government has “drastically reduced” the level of co-operation between its own intelligence agency, the BND, and the NSA.

The union between the BND and the NSA is said to have been in place for at least ten years but is now being re-evaluated as it seems the NSA went far beyond the scope of the 2002 agreement between the two countries on which the co-operation is based.

Image of NSA courtesy of Carsten Reisinger / Shutterstock.com.

Share this:

  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • More
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to print (Opens in new window) Print
  • Click to email a link to a friend (Opens in new window) Email
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • 6
About the Author

Lee Munson

Read Similar Articles

May 24, 2021

What to expect when you’ve been hit with Avaddon ransomware

May 19, 2021

What’s New in Sophos EDR 4.0

May 19, 2021

Sophos XDR: Driven by data

Subscribe to get the latest updates in your inbox.
Which categories are you interested in?
Change Region
  • América Latina
  • Brasil
  • Deutschland
  • English
  • France
  • Iberia
  • Italia
  • Japan
Terms Privacy
  • Privacy Notice
  • Cookies
Legal
  • General
  • Modern Slavery Statement
  • Speak Out
© 1997 - 2025 Sophos Ltd. All rights reserved
Go to mobile version