Sophos News

NSA metadata collection is illegal, rules US court

A US federal appeals court has ruled that the National Security Agency’s (NSA’s) bulk, warrantless collection of phone records is illegal.

The unanimous decision from the three-judge panel of the Second US Circuit Court of Appeals in New York represents a major victory for opponents of the NSA and its surveillance activities and comes as Congress debates whether to extend or curb the soon-to-sunset legislation that underpins the data collection program.

The appeal court’s ruling undermines many of the legal theories employed by the US government to expand surveillance following the September 11 2001 terror attacks.

While the judges did not rule on whether the NSA program violated privacy rights granted by the US Constitution, they did rule that the wording of the Patriot Act was not sufficient to justify the massive collection of data seen under the Bush and Obama administrations.

In their 97-page ruling the judges wrote:

The statutes to which the government points have never been interpreted to authorize anything approaching the breadth of the sweeping surveillance at issue here. The sheer volume of information sought is staggering.

The ruling will not affect the NSA’s international surveillance efforts but it will go some way in curtailing the agency’s domestic telephone metadata program – which came to light in 2013 when former NSA contractor Edward Snowden leaked documents detailing how the agency was collecting lists of phone numbers called, along with details of the time and duration of each call – in order to aid in the detection of terror suspects.

Though the NSA does not collect the content of the phone conversations, the all-encompassing collection of metadata, the judges noted, was far beyond the original intent of Section 215 of the Patriot Act:

If the government is correct, it could use § 215 to collect and store in bulk any other existing metadata available anywhere in the private sector, including metadata associated with financial records, medical records, and electronic communications (including email and social media information) relating to all Americans.

Such expansive development of government repositories of formerly private records would be an unprecedented contraction of the privacy expectations of all Americans.

The Patriot Act itself was already under threat before this ruling as lawmakers continue to debate Section 215 which is due to expire under a sunset clause on 1 June.

US politicians have already suggested the USA Freedom Act as a possible alternative – it would retain some elements of the Patriot Act while ditching the metadata collection program – hence making this latest decision moot, as noted by the judges:

On April 30, 2015, a modified version of the USA FREEDOM Act, which would limit the bulk metadata program in various ways, was passed by the House Judiciary Committee, see USA FREEDOM Act of 2015, H.R. 2048, 114th Cong. (2015), and a vote in that Chamber is expected later this month.

This latest ruling follows yesterday’s reports that the German government has “drastically reduced” the level of co-operation between its own intelligence agency, the BND, and the NSA.

The union between the BND and the NSA is said to have been in place for at least ten years but is now being re-evaluated as it seems the NSA went far beyond the scope of the 2002 agreement between the two countries on which the co-operation is based.

Image of NSA courtesy of Carsten Reisinger / Shutterstock.com.