The Provision That Collects at Scale Without Individual Warrants
Section 702 of the Foreign Intelligence Surveillance Act is the legal authority under which the United States government collects the communications of foreign targets without obtaining a separate court order for each target. The surveillance court approves the program’s rules once a year, and analysts then select individual targets under those approved rules. That single design choice is the reason the program can operate at the scale it does, and it is also the reason the program has been contested in every reauthorization debate since its creation. This article explains the provision as it stood on May 15, 2014, the date carried on this page, and it records every later change with an explicit date, including the 2024 reauthorization and the 2026 lapse of the authority.

The test for this article is a demanding one. After reading it, a reader should be able to explain how the government collects communications at scale without individual warrants and why that practice is lawful under the statute, state precisely who may and may not be targeted, distinguish incidental collection from targeting and understand why that distinction is where the entire debate actually sits, and describe what a query of collected data means and what rules governed it. Precision is the whole point here. General explainers of this program tend to blur the line between whom the government may target and whose communications the government ends up holding, and that blur is where nearly every public misunderstanding of the program begins.
A Note on Dates and How to Read This Article
This article carries the date May 15, 2014, and that date governs how its claims should be read. The main body describes the statute as it stood on that date: the provisions enacted in 2008, the procedures approved under them, and the public knowledge available at the time. Developments after that date appear only in passages that say so explicitly, each with its own date, from the July 2014 oversight board report through the 2018 and 2024 reauthorizations to the June 2026 lapse. The distinction matters because the program changed substantially across those years, and a reader who mixes the 2014 framework with the later rules will misunderstand both.
The convention also serves a substantive point about the subject. Section 702 was never a finished edifice; it was a statute under continuous revision by courts, overseers, and Congress. Presenting it as a single timeless set of rules would misrepresent how it actually worked. The 2014 framework had no statutory querying procedures; the 2018 framework did. The 2014 framework permitted abouts collection subject to the four prohibitions; the 2017 court opinion ended the practice and later statutes barred it. The 2014 framework’s query rules lived inside minimization procedures; the 2024 rewrite stated them as a direct statutory prohibition. Each of these transitions is dated in the text, so the reader can always tell which version of the program a given passage describes. When this article states a rule without a date, the rule belongs to the 2014 frame.
How This Article Uses Sources
An explainer of a classified program must be candid about what its sources can and cannot establish. This article’s account of the statute’s text rests on the public law: the FISA Amendments Act of 2008, the reauthorization statutes, and the codified provisions at 50 U.S.C. 1881a, all of which are public and quotable. Its account of the program’s operation rests on three further source types: declassified opinions of the surveillance court, which supply the compliance findings with their dates; reports of the Privacy and Civil Liberties Oversight Board, each cited with its date; and official summaries and oversight characterizations of the targeting, minimization, and querying procedures, whose full texts remain classified.
The classified remainder imposes a discipline on every claim in this article. Where the procedures’ details are secret, the article describes their framework and says so, rather than inventing specifics. Where the compliance record depends on the government’s own reporting, the article notes that dependence. And where later developments altered the program, the article dates them, so no reader mistakes the 2014 framework for the rules that governed the program’s final years. The verification behind this article checked the statutory citations, the reauthorization statutes and dates, the court opinions and their dates, and the vote counts against primary sources, and the dated later developments carry the results of those checks.
Where Section 702 Sits in the Surveillance Code
The Foreign Intelligence Surveillance Act of 1978 created a special court, the Foreign Intelligence Surveillance Court, and a procedure for the government to obtain court orders for electronic surveillance conducted for foreign intelligence purposes inside the United States. For three decades the model was individualized: the government identified a specific target, presented facts establishing probable cause to a judge of that court, and received an order covering that target. The framework this section sits inside is that individualized model, and understanding it is necessary because Section 702 is best understood as Congress’s deliberate departure from it.
The departure arrived with the FISA Amendments Act of 2008, Public Law 110-261, which added a new title to FISA governing surveillance of persons outside the United States. Section 702 of that Act, codified at 50 U.S.C. 1881a, created a different architecture. Instead of approving individual targets one by one, the court approves annual certifications submitted by the Attorney General and the Director of National Intelligence, together with the targeting and minimization procedures the government will use. Once the court has approved the certification and the procedures, the government selects individual targets under those procedures without returning to the court for each one. Congress reauthorized the provision in 2012 through Public Law 112-238, signed December 30, 2012, which extended the authority without altering this architecture. Later reauthorizations in 2018 and 2024 changed significant details, and each of those changes is noted below with its date.
The distinction between the two architectures matters because it determines where judicial supervision sits. Under traditional FISA, a judge evaluates the facts supporting surveillance of a particular person before collection begins. Under Section 702, a judge evaluates the rules the government will follow when it selects targets, and the selection of any particular target happens inside the executive branch under those rules. Supporters describe this as programmatic authorization suited to fast moving foreign targets. Critics describe it as the removal of the judge from the decision that matters most. Both descriptions refer to the same structural fact, which is that the court reviews the system annually rather than the target individually.
The Vocabulary of Section 702
The program has a specialized vocabulary, and mastering it is a precondition for reading any serious account of the subject. Targeting is the decision to collect against a particular person; it is the act the four prohibitions constrain. Tasking is the operational step that implements a targeting decision: the analyst enters the selector into the collection systems and acquisition begins. A selector is the identifier used for tasking, typically an email address or telephone number, and the statute’s limits attach to the person behind the selector rather than to the selector itself, which is why the location and status assessments focus on the user. Collection is the acquisition of communications pursuant to tasked selectors. These four terms describe the front end of the program, the part that moves from analyst judgment to acquired data.
The back end has its own terms. Minimization is the set of procedures governing what happens to acquired communications, particularly those of United States persons acquired incidentally. A query is a search of collected data using an identifier as the search term. Dissemination is the distribution of intelligence reports derived from collected communications to recipients outside the collecting agency, and masking is the practice of concealing the identities of United States persons in disseminated reports. Unmasking is the authorized revelation of such an identity when the applicable procedures permit it. Certification is the annual submission by the Attorney General and the Director of National Intelligence that, together with the approved procedures, authorizes the program for the coming year. Abouts collection, discontinued in 2017 and later statutorily barred, was the upstream acquisition of communications merely referencing a selector. Incidental collection is the acquisition of a non-target’s communications through lawful targeting of someone else. With these terms fixed, the rest of this article can be read without ambiguity about which stage of the process is under discussion at any point.
The Legislative Road to Section 702
Section 702 did not emerge from abstract theory. It emerged from a specific operational complaint about the original FISA model. By the mid 2000s, intelligence officials argued that the individualized order process, which required a separate application and judicial finding for each target, could not keep pace with foreign intelligence targets who used internet communications. A foreign operative might use a new email account each week, route messages through servers on several continents, and coordinate with associates across a dozen selectors. Each new selector, under the traditional model, meant a new application. Officials described a growing backlog and warned that the process was losing coverage of targets it had already identified. Whether that description was complete was contested at the time, but it supplied the problem statement to which Congress responded.
Congress responded with the FISA Amendments Act of 2008, Public Law 110-261, which added a permanent Title VII to FISA for surveillance directed at persons outside the United States. Section 702 was the centerpiece of that title. The legislative compromise accepted the executive branch’s core claim that foreign targets required a faster mechanism than individualized orders, while writing the targeting limits and the annual judicial review into the statute as the civil liberties price of that speed. The four prohibitions, the certification requirement, and the minimization mandate were all part of the original 2008 enactment, not later additions. The architecture this article describes is therefore the architecture Congress chose at creation, and every later debate has been an argument about whether that architecture’s safeguards proved adequate in practice.
The 2012 reauthorization tested whether the compromise would hold. Public Law 112-238, signed December 30, 2012, extended the authority without altering its structure, after a debate in which supporters cited the program’s operational value and critics cited the scale of incidental collection and the thinness of public information about compliance. The extension preserved the certification model, the targeting standard, and the four prohibitions exactly as enacted. For readers keeping the timeline straight, the 2012 law is the last legislative action on the program that falls inside this article’s 2014 frame. Everything Congress did afterward, in 2018 and 2024, belongs to the dated later developments recorded below, and each of those later laws changed the program in ways the 2012 Congress did not.
The Certification Model: How Programmatic Authorization Works
Each year the Attorney General and the Director of National Intelligence submit certifications to the Foreign Intelligence Surveillance Court attesting that the targeting and minimization procedures in place satisfy the statute’s requirements. The court reviews the certification together with those procedures and either approves them or identifies deficiencies the government must correct. The statute’s judicial review provisions give the court authority to examine whether the procedures are reasonably designed to ensure that acquisitions stay within the targeting limits and that minimization rules protect the identities and communications of United States persons whose information is acquired.
The certification is not a blank check, and the limits on it are worth stating exactly. The certification must attest that a significant purpose of the acquisition is to obtain foreign intelligence information. It must attest that the targeting procedures are reasonably designed to ensure that acquisitions are limited to persons reasonably believed to be located outside the United States and to prevent the intentional acquisition of wholly domestic communications. It must attest that the minimization procedures meet the statutory definition, which requires procedures reasonably designed to minimize the acquisition and retention, and to prohibit the dissemination, of nonpublicly available information concerning unconsenting United States persons, consistent with the need to obtain, produce, and disseminate foreign intelligence information. These attestations are the mechanism by which the statute translates its substantive limits into an annual judicial check.
Once the court approves the certification and the procedures, individual targeting decisions proceed without individualized court orders. An analyst who identifies a selector, such as an email address or telephone number, that is assessed to belong to a foreign target may task that selector for collection after applying the targeting procedures, which include the required checks on the target’s location and status. No judge reviews that individual decision before collection begins. Oversight instead takes the form of after the fact review: the Department of Justice and the Office of the Director of National Intelligence conduct compliance reviews, the inspectors general of the collecting agencies examine the program, and the court receives reports on compliance incidents. Whether after the fact review is an adequate substitute for advance judicial approval of each target is one of the central disagreements about the program, and it cannot be resolved by describing the mechanism more precisely. It is a disagreement about what the Fourth Amendment requires, not about how the paperwork flows.
If no judge approves individual targets, what does the court approve instead?
The court approves the annual certification submitted by the Attorney General and the Director of National Intelligence, together with the targeting and minimization procedures the government will apply. It does not approve individual targets. The government then tasks specific selectors under those approved rules without returning to the court.
A detail of timing matters for readers who encounter later commentary. In the framework as it stood in 2014, the court approved targeting and minimization procedures. The requirement for the government to maintain querying procedures, and for the court to review them, was added by the 2018 reauthorization, and that later development is described below with its date. Describing querying procedure approval as part of the 2014 framework would misstate the law as it stood on this article’s date.
What the Certification Contains
The annual certification is a formal legal document, and its contents are specified by the statute rather than left to executive discretion. The Attorney General and the Director of National Intelligence jointly attest to a series of factual and legal conclusions: that the targeting procedures are reasonably designed to limit acquisitions to persons reasonably believed to be outside the United States and to prevent the intentional acquisition of wholly domestic communications; that the minimization procedures meet the statutory definition; that a significant purpose of the acquisition is to obtain foreign intelligence information; and that the other statutory requirements are satisfied. These attestations are made to the court under the officials’ authority, which gives them a weight that an internal executive memorandum would not carry.
The certification is accompanied by the procedures themselves and by supporting materials explaining how the procedures satisfy the statutory standards. The court’s review engages with these materials substantively rather than ceremonially. The opinions described in the compliance section show the court testing the procedures against the statute’s requirements, identifying gaps between the written procedures and the actual implementation, and directing corrections where the government fell short. The certification is therefore best understood not as a permission slip but as the opening filing in an annual adversarial-ish review, adversarial in the sense that the court probes and the government must justify, even though no opposing party appears. The absence of an opposing party is itself one of the critics’ objections to the model, and it is worth naming plainly: the review is conducted by a judge examining the government’s submissions, without the counterargument that an adversary would supply.
When the Court Finds a Problem: Deficiencies and Corrections
Annual review would mean little if the court could only approve or reject the program wholesale. The statute gives the court a middle path. If the Foreign Intelligence Surveillance Court finds that a certification or its procedures are deficient, it issues an order directing the government to correct the deficiency within a fixed period or to cease the acquisitions conducted under the certification. The correction window forces a concrete response: the government must amend the procedures, supplement the certification, or stop collecting. This mechanism is the reason several of the program’s most consequential changes began as closed court proceedings rather than as legislation.
The correction process also explains the rhythm of the compliance record. When the court’s review identifies a gap between the procedures as written and the collection as implemented, the government typically responds with revised procedures, additional training, or new documentation requirements, and the court then evaluates whether the response cures the problem. That cycle played out across the opinions described in the compliance section below, where initial findings of querying violations were followed by successive rounds of remedial measures and successive opinions assessing them. The statute further provides for appellate review of the court’s Section 702 decisions in the Foreign Intelligence Surveillance Court of Review, a step the government took in the proceedings that preceded the September 2019 declassification. The existence of that appellate layer matters because it means the court’s Section 702 rulings, though issued in a classified setting, are subject to review beyond a single judge.
Who May Be Targeted
The targeting standard has two elements, and both must be satisfied. Under Section 1881a(a), the government may target persons reasonably believed to be located outside the United States, and it may do so for the purpose of acquiring foreign intelligence information. The phrase non-United States persons comes from the section’s title and from the prohibitions discussed in the next section, which bar the intentional targeting of United States persons anywhere in the world. The eligible population is therefore defined by two negatives that work together: the target must not be a United States person, and the target must be reasonably believed to be outside the country.
Reasonable belief is doing substantial work in that sentence. The statute does not require certainty about a target’s location, which would be unworkable for foreign intelligence collection, and it does not permit guesswork either. The targeting procedures approved by the court specify the checks analysts must perform before tasking a selector, including the review of available information bearing on the target’s location and status as a United States person or a non-United States person. In practice this means examining the selector’s attributes, the intelligence reporting that identified it, and any contradictory indicators, then recording the conclusion and its basis. A target who is later discovered to be inside the United States, or to be a United States person, must be detasked, and the procedures address the handling of communications already acquired. The reasonable belief standard is thus both the gateway to collection and the trigger for stopping it when the belief proves wrong. Its application to close cases, where the evidence on location or status points in both directions, is where analyst judgment matters most and where compliance reviewers focus their scrutiny, because a standard built on reasonable belief can only be audited through the records of the beliefs analysts actually formed.
Does the bar on targeting Americans extend beyond United States borders?
No. The statute expressly prohibits intentionally targeting a United States person anywhere in the world, and it separately prohibits intentionally targeting any person known to be in the United States. An analyst who knows the intended target is an American may not task that person under this authority.
The Individualized Counterparts: Targeting Americans Abroad
Section 702 is only one part of the title Congress added in 2008, and the other parts sharpen its meaning by contrast. Where the target is a United States person reasonably believed to be outside the United States, the statute does not permit programmatic collection. It requires the government to obtain an individualized order from the surveillance court, supported by a showing of probable cause that the target is a foreign power or an agent of a foreign power. The same requirement applies to certain other acquisitions targeting Americans abroad. These provisions are the reason the third prohibition is not an empty promise: when the government wants to surveil an American overseas, a different, more demanding procedure exists for that purpose, and Section 702 is fenced off from it.
The contrast illuminates the statute’s design logic. Congress created a two track system: a programmatic track for non-United States persons abroad, with annual judicial review of the rules, and an individualized track for United States persons abroad, with judicial review of each target. The tracks are mutually exclusive by design. An analyst who has identified an American target cannot choose the easier track; the statute assigns the target to the harder one. Critics of the program sometimes argue that the query practice collapses this distinction, because querying incidentally collected American communications by identifier achieves without an individualized order some of what the individualized track would require one for. Supporters respond that the tracks govern acquisition, not analysis of lawfully acquired data, and that the distinction holds. The two track structure is thus both the statute’s answer to the targeting question and the source of the query debate’s intensity.
Foreign Intelligence Information and the Significant Purpose Test
The targeting standard requires that acquisition be for the purpose of obtaining foreign intelligence information, and the certification requires that a significant purpose of the acquisition be the collection of such information. The phrase foreign intelligence information is defined in FISA itself, and its categories set the outer boundary of everything the program may do. The definition covers information about the capabilities, intentions, or activities of foreign governments and their components, foreign organizations, foreign persons, and international terrorist organizations. It covers information about entities engaged in the proliferation of weapons of mass destruction and their means of delivery. And it covers information necessary to the national defense or security of the United States and to the conduct of the foreign affairs of the United States. A targeting decision that cannot be connected to one of these categories fails the statute’s purpose requirement regardless of how valuable the expected collection might be for ordinary law enforcement.
The word significant carries its own history. The certification does not require that foreign intelligence be the primary or sole purpose of the acquisition. It requires that obtaining foreign intelligence information be a significant purpose, which permits acquisitions that also serve law enforcement objectives so long as the foreign intelligence purpose is genuine and substantial. The distinction matters for queries as well as for targeting. An analyst investigating a terrorism case that has both intelligence and criminal dimensions may task selectors and run queries where the foreign intelligence purpose is significant even though a prosecution may eventually result. Critics have argued that the significant purpose standard lets criminal investigations borrow the program’s looser rules, while supporters respond that terrorism and proliferation cases inherently straddle the intelligence and law enforcement lines and that demanding a single exclusive purpose would disable the program against exactly the threats it was built to address. The 2024 rewrite of the query restriction, which bars queries solely designed to find and extract evidence of criminal activity, was Congress’s latest attempt to draw that line, and its date is recorded below.
The Foreign Intelligence Mission in Practice: What the Program Was Built to Collect
The statutory categories of foreign intelligence information translate in practice into several standing mission areas, and describing them concretely shows what the targeting authority was built to do. Counterterrorism has been the most publicly discussed: collecting the communications of members and facilitators of international terrorist organizations to identify plots, map networks, and warn of attacks. The speed rationale for programmatic authorization is sharpest here, because terrorist operatives change selectors frequently and the intelligence value of a new selector is often highest in the first days after it is identified, before the operative realizes it may be known.
Counterproliferation is the second major mission area: tracking the communications of foreign persons and entities involved in the development or transfer of weapons of mass destruction and their delivery systems. Counterintelligence, the detection and disruption of foreign intelligence services operating against United States interests, is the third. Cybersecurity has grown as a fourth, as foreign government and nonstate actors conduct network intrusions and influence operations through the same communications infrastructure the program covers. In each area the program’s contribution is typically described not as the complete intelligence picture but as the initial access: the tip, the selector, or the communication that makes further collection and investigation possible.
These mission areas also explain why the significant purpose standard matters operationally. A counterterrorism investigation will often have both intelligence and law enforcement dimensions from its first day: the same communications that reveal a plot’s planning may later become evidence in a prosecution. The statute’s choice to require a significant foreign intelligence purpose, rather than an exclusive one, reflects the judgment that forcing investigators to choose between intelligence and law enforcement at the moment of tasking would cost the very speed the program was created to provide. The 2024 rewrite’s bar on queries solely designed to find and extract evidence of criminal activity was Congress’s attempt to police the boundary without collapsing the dual character of these investigations. Whether that attempt succeeded is a question for the post lapse assessment, but the tension it addressed was present from the program’s first day.
The Four Prohibitions
The statute states its limits as four express prohibitions, and each one closes a specific path around the targeting standard. They appear in the order Congress wrote them, and the order is worth preserving because each prohibition answers a different anticipated evasion.
The first prohibition bars intentionally targeting any person known at the time of acquisition to be located in the United States. This is the geographic fence. A foreign national visiting the United States, a foreign agent operating inside the country, and a non-United States person whose location is known to be domestic are all off limits to this authority while they are here. Other authorities, including traditional individualized FISA orders, may cover such persons, but Section 702 may not. The knowledge qualifier matters: the bar applies to persons known to be in the United States, which connects directly to the reasonable belief standard for location and to the detasking obligation when location information changes.
The second prohibition is the reverse targeting bar. It bars targeting a person reasonably believed to be located outside the United States where the purpose is to target a particular known person inside the United States. The scenario it addresses is straightforward: the government may not select a foreign target as a pretext for collecting the communications of an American with whom that foreign target communicates. The prohibition looks to purpose, which makes it the most difficult of the four to verify from outside the government, and for that reason it has drawn sustained attention from overseers. Compliance review examines targeting documentation for indications that the stated foreign intelligence purpose is genuine, and the inspectors general have treated reverse targeting as a specific audit focus.
The third prohibition bars intentionally targeting a United States person reasonably believed to be located outside the United States. This is the provision that makes the program’s answer to the most common public question a clear no. An American living abroad, traveling abroad, or communicating from abroad may not be targeted under this authority. The prohibition applies anywhere in the world, without geographic qualification, and it is the textual basis for the statement that appears throughout this article: Americans are not targets under Section 702. The statute defines United States person to include citizens, permanent resident aliens, associations substantially composed of such individuals, and domestic corporations, so the protection extends beyond citizenship alone.
The fourth prohibition bars the intentional acquisition of communications as to which the sender and all intended recipients are known at the time of acquisition to be located in the United States. This is the wholly domestic communications bar. Even when collection is directed at a lawful foreign target, the government may not intentionally acquire a communication it knows to be purely domestic. The prohibition recognizes that foreign targets communicate with people inside the United States, and it draws the line at intentional acquisition of the subset of those communications that never leave the country. Like the first prohibition, it turns on knowledge at the time of acquisition, and like the others it is enforced through the targeting procedures and after the fact compliance review rather than through advance judicial approval of each acquisition.
A fifth limitation on collection methods was added later. The 2018 reauthorization added a prohibition on acquiring communications that merely reference a selector without being to or from the targeted person, the practice known as abouts collection, and that development is described below with its date. In the 2014 framework the four prohibitions above were the complete set of express statutory bars.
The four prohibitions look crisp on paper and blur at the edges in practice, and the edge cases are worth working through because they show where the targeting procedures do their hardest work. Consider the question of who counts as a United States person. A dual national holding American citizenship is a United States person even when living abroad and even when acting against American interests; the prohibition on targeting such a person admits no exception for the target’s conduct. A permanent resident who travels overseas carries the protection with them. The procedures must therefore resolve status questions that can be genuinely uncertain, as when an analyst has a selector and fragmentary biographical information, and the reasonable belief standard governs those close calls.
Location presents harder problems than status. Modern communications obscure geography: virtual private networks route traffic through servers far from the user, travelers cross borders with the same devices and accounts, and a selector’s country code may say little about where its user sits. The targeting procedures address this by requiring analysts to examine the totality of available information bearing on location before tasking, and to revisit the assessment as new information arrives. When information indicates that a target has entered the United States, or that a person previously assessed as foreign is a United States person, the procedures require detasking: collection against the selector stops, and the handling of already acquired communications is governed by the minimization rules. Detasking is one of the compliance record’s recurring subjects, because the gap between learning that a target’s status changed and actually stopping collection is where violations accumulate.
The wholly domestic bar raises its own line drawing questions. The prohibition applies where the sender and all intended recipients are known at the time of acquisition to be in the United States, which means the government must have actual knowledge of domestic location on both ends before the bar engages. A communication from a foreign target to an associate whose location is unknown is not covered, even if the associate turns out to be inside the country. Critics have argued that the knowledge qualifier sets the bar too low to protect domestic communications in practice, since the government will often lack affirmative location knowledge about the far end of a foreign target’s contacts. Supporters respond that a stricter rule would require proving a negative about every communicant before collecting anything, which would end the program. The disagreement is another instance of the pattern that runs through the statute: the text states a clear rule, and the argument moves to whether the rule’s knowledge and belief qualifiers leave it meaningful.
Worked Examples: Applying the Four Prohibitions
The prohibitions are easier to grasp in application than in abstraction, so this section works through four scenarios that show how the rules sort real cases. Each scenario is hypothetical, constructed to isolate one prohibition, and each is resolved under the statutory text as it stood in the 2014 frame.
First, the geographic bar. An analyst identifies a foreign nationalist activist whose public statements and travel records indicate residence in Berlin. The analyst tasks the activist’s email address. Months later, travel records indicate the activist has relocated to Chicago and is living there. The initial tasking was lawful, because the foreignness determination was reasonable at the time it was made. The new information triggers the detasking obligation: collection on the selector must stop, because the target is now known to be in the United States and the first prohibition bars intentionally targeting any person known to be in the country. Communications acquired before the relocation remain lawfully collected; communications acquired after the analyst learned of the relocation would violate the prohibition.
Second, the reverse targeting bar. An analyst is interested in the communications of a United States citizen living in Ohio who is suspected of no crime but whose activities have drawn intelligence interest. The analyst cannot task the citizen directly, so the analyst tasks the citizen’s frequent foreign correspondent, a non-United States person in another country, with the purpose of acquiring the citizen’s side of their correspondence. This is prohibited. The foreign correspondent may be a lawful target in the abstract, but the second prohibition bars targeting a person abroad where the purpose is to acquire the communications of a particular known person in the United States. The violation turns on purpose, which is why the documentation of the analyst’s foreign intelligence justification is the oversight mechanism that matters.
Third, the worldwide bar on targeting Americans. An analyst identifies a United States citizen working as a journalist in the Middle East whose contacts include persons of foreign intelligence interest. The analyst tasks the journalist’s telephone number to learn about those contacts. This is prohibited categorically. The third prohibition bars intentionally targeting a United States person anywhere in the world, and the journalist’s location abroad does not diminish the protection. If the journalist communicates with a lawful foreign target, those communications may be incidentally collected, but the journalist may never be made the target.
Fourth, the wholly domestic bar. Upstream collection acquires a communication in which the tasked selector appears, and review shows that the sender and all intended recipients are known to be located in the United States, with the selector’s appearance being incidental to a domestic conversation. The fourth prohibition bars intentional acquisition of such a communication. The analyst must not retain or use it as foreign intelligence collection, and the targeting procedures must be designed to prevent this category of acquisition. The scenario illustrates why the knowledge qualifier matters: the bar applies where the domestic character is known at the time of acquisition, placing a premium on the procedures that surface that knowledge.
These scenarios share a common moral. The prohibitions are stated as rules about targeting, and they function as rules about targeting, but their practical effectiveness depends on the procedures that implement them: the documentation of foreignness determinations, the detasking discipline, the purpose statements that police reverse targeting, and the handling rules for domestic communications. A reader who can work through these scenarios understands the statute the way an oversight reviewer does, as a set of constraints on thousands of individual decisions rather than as a single abstract guarantee.
Incidental Collection: The Lawful Acquisition Nobody Targets
Incidental collection is the term for communications of United States persons that are acquired even though no United States person was targeted. The mechanism is simple and foreseeable: lawful foreign targets communicate with Americans, and when the government collects the foreign target’s communications, the American’s side of the conversation comes with them. A foreign intelligence target emails an associate in Chicago; the associate’s messages are acquired not because the associate was targeted but because the target was. The statute’s prohibitions were written with full awareness of this consequence. The ban on targeting Americans and the ban on intentionally acquiring wholly domestic communications leave open, by design, the acquisition of international communications between a foreign target and a person inside the United States.
This is lawful collection. That sentence needs emphasis because public discussion of the program frequently treats the presence of Americans’ communications in the collected data as evidence that the targeting rules were violated. It is not. The statute forbids targeting Americans; it does not and could not forbid foreign targets from talking to Americans. Incidental collection is the predictable result of collecting the communications of people who have contacts inside the United States, and any program that collects foreign targets’ communications at scale will hold large volumes of it. The legal question was never whether incidental collection would occur. The legal question, the one the statute’s drafters confronted and the one every reauthorization debate has revisited, is what the government may do with incidentally collected communications once it holds them.
That question is where the entire debate actually sits, and the reason is structural. Everyone who has studied the statute agrees on the two premises: the statute forbids targeting Americans, and Americans’ communications are collected incidentally in large volumes. There is no live dispute about either premise. The dispute concerns the rules for searching, retaining, and disseminating communications the government lawfully acquired without targeting the Americans whose voices appear in them. A reader who understands this has understood the program’s controversy in its precise form. Arguments framed as whether the program targets Americans are arguing about a settled question, because the statute answers it explicitly. Arguments about what analysts may do with incidentally collected data are arguing about the question the statute left genuinely contested.
The minimization procedures are the statute’s answer to that question in the 2014 framework. Those procedures, approved annually by the court, govern the retention and dissemination of incidentally collected communications of United States persons. They require, in general terms, that information identifying United States persons be masked or minimized unless it is necessary to understand the foreign intelligence value of the communication or to assess its importance, and they set time limits on retention and rules for dissemination outside the collecting agency. The procedures are detailed and classified in their specifics, which means public debate about them proceeds at a level of generality that frustrates both supporters and critics. Supporters point to the procedures as the protection that makes incidental collection acceptable. Critics respond that procedures the public cannot read cannot carry the weight supporters place on them.
If targeting Americans is barred, why do their communications get collected?
Incidental collection is the acquisition of a United States person’s communications when that person communicates with a lawful foreign target, without the American being targeted. It is lawful because the statute prohibits targeting Americans, not collecting the communications of foreign targets who happen to talk to them.
Two Ways the Data Arrives: Upstream and Downstream
Section 702 collection reaches the government through two technical methods, and the distinction between them explains several of the program’s most confusing public episodes. The first method, often called downstream collection, involves compelling electronic communications service providers to turn over the communications of tasked selectors. When an analyst tasks an email address under the approved procedures, the provider is directed to furnish the communications to or from that address. The program publicly associated with this method was reported in June 2013 under the name PRISM, and the providers were described in press reporting as furnishing data in response to legal process. The second method, called upstream collection, involves acquiring communications from the internet backbone itself, the high capacity cables and switches over which internet traffic travels, by scanning the traffic for tasked selectors.
The difference that matters legally is what each method can sweep in beyond communications to or from the target. Downstream collection is bounded by the provider’s holdings for the tasked selector. Upstream collection, because it scans traffic in transit, could in the 2014 framework also acquire communications that merely referenced a tasked selector, such as an email between two third parties that mentioned the target’s email address in the body of the message. This was abouts collection: acquisition of communications about a target rather than to or from a target. Abouts collection was the most expansive form of acquisition under the program, and it was also the form most difficult to square with the statute’s prohibitions, because a communication between two unidentified persons that happens to mention a selector offers thin assurance that the acquisition stays within the targeting limits. The history of abouts collection after 2014, including its discontinuation and the statutory response, is set out below with dates.
The separate authority readers confuse with this one is the bulk collection of domestic telephone metadata under a different provision of law, and the confusion between the two programs has distorted public debate about both. Section 702 acquires the contents of communications of foreign targets abroad; the metadata program acquired records of domestic calls in bulk. The two authorities rest on different statutes, were disclosed through different reporting, and were reformed through different legislation. Keeping them distinct is a prerequisite for understanding either one, and the later history of the metadata program’s reform is noted below with its date.
The Targeting Procedures: What the Court Actually Reviews
The targeting procedures are the most important documents in the program that the public cannot read in full, and understanding what they contain is essential to understanding what the court’s annual review actually examines. At their core, the procedures are an instruction manual for analysts: they specify the steps that must be completed before a selector is tasked, the documentation each step must produce, and the circumstances that require detasking. The court reviews these procedures against the statutory standard, which asks whether they are reasonably designed to ensure that acquisitions target only persons reasonably believed to be outside the United States and to prevent the intentional acquisition of wholly domestic communications. The review is thus a test of design: do the prescribed steps, if followed, keep collection within the statute’s limits.
The procedures’ contents reflect the edge cases discussed earlier in this article. They address how analysts are to assess United States person status when the available information is fragmentary, how to weigh conflicting indicators of location, and what to do when a target’s circumstances change after tasking. They specify the foreign intelligence purpose documentation required for each tasking, which is the record that lets compliance reviewers test for reverse targeting. And they set out the handling rules for communications acquired from selectors that must be detasked, distinguishing between data acquired while the tasking was valid and data acquired after the basis for it eroded. Each of these elements has been revised over the years in response to court findings, which means the procedures the court approved in any given year reflected the lessons of the prior year’s compliance review.
The classified character of the procedures creates the central paradox of the program’s oversight. The court’s review is searching and substantive, as the declassified opinions demonstrate, but the public cannot verify that for itself because the procedures under review are secret. Supporters argue that the opinions’ detailed findings prove the review is real. Critics argue that a review the public cannot examine cannot legitimize a program of this scale, and that the compliance violations persisted for years under procedures the court had approved, which suggests the limits of design review as a safeguard. The targeting procedures sit at the center of that disagreement: they are simultaneously the program’s most important protection and the protection the public is least able to evaluate.
How Tasking Works: From Selector to Collection
Tasking is the operational verb at the heart of the program, and understanding it concretely demystifies much of the statute. A selector is a specific communications identifier: an email address, a telephone number, a chat handle. An analyst who has identified a selector assessed to belong to a foreign intelligence target does not send the selector to a judge. Instead the analyst works through the targeting procedures: documenting the foreign intelligence purpose, recording the basis for the reasonable belief that the user is a non-United States person located outside the United States, and checking the proposed tasking against the four prohibitions. Each of these steps creates a record, and those records are what compliance reviewers later examine when they audit whether targeting decisions followed the rules.
Once the checks are complete, the selector is tasked to the collection systems, which then acquire the communications associated with it through the upstream or downstream methods described above. Tasking is not permanent. The procedures require analysts to reexamine the basis for tasking as new information arrives, and to detask selectors when the underlying assessment no longer holds: when the user is found to be inside the United States, when the user is found to be a United States person, or when the foreign intelligence purpose evaporates. The detasking obligation is continuous rather than annual, which means the program’s compliance depends not only on getting the initial decision right but on stopping collection promptly when the facts change. Oversight reviews have paid close attention to delays between the moment the government learned a selector should be detasked and the moment collection actually stopped, because that interval is where unauthorized acquisition occurs even under conscientious procedures.
The documentation requirement deserves emphasis because it is the hinge between the secret operational world and the oversight world. An undocumented targeting decision cannot be reviewed, and a targeting decision documented after the fact cannot be trusted. The procedures therefore require contemporaneous records of the foreign intelligence justification and the location and status assessment for each tasked selector. When the Justice Department’s compliance teams conduct their reviews, they pull samples of these records and test them against the underlying intelligence. When the court’s opinions discuss compliance, they are frequently discussing what these records showed or failed to show. The entire oversight edifice rests on the assumption that analysts write down why they tasked each selector, and the compliance violations that later came to light often involved failures at exactly this level: queries run without recorded justification, taskings continued past the point the records supported.
A Worked Example: From Tip to Tasking
A concrete walkthrough shows how the abstract rules operate on a real case. Suppose an intelligence report identifies a telephone number used by a suspected facilitator for a foreign terrorist organization, operating in a city in the Middle East. An analyst considering that number for tasking must first establish the foreign intelligence purpose: collection against the facilitator is expected to produce information about the capabilities or activities of an international terrorist organization, which falls within the statutory definition. The analyst documents that purpose, creating the record compliance reviewers will later examine.
Next comes the status and location assessment. The analyst reviews available information: the number’s country code, the content of the intelligence report, any subscriber information, and the pattern of the number’s contacts. Nothing in the file suggests the user is a United States person or is located in the United States; the reasonable belief standard is satisfied on the evidence available. The analyst then checks the four prohibitions. The user is not known to be in the United States. The purpose is to acquire the facilitator’s own communications, not to reach a particular known American through him, so the reverse targeting bar is not triggered. The user is assessed to be a non-United States person, and no wholly domestic acquisition is contemplated. The selector is tasked, and collection begins through the appropriate method.
Months later, new reporting indicates the facilitator has traveled to the United States to meet associates. The analyst’s obligation now runs in the other direction. The reasonable belief that supported tasking has been overtaken by information indicating domestic location, and the procedures require detasking: the selector is removed from collection, and any communications acquired after the point at which the government learned of the travel are handled under the minimization rules for improperly acquired data. The example illustrates the program’s continuous character. Targeting is not a one time determination made at tasking and then filed away; it is a standing assessment that must be revisited as the facts change, and the compliance record’s detasking incidents show what happens when the revisit comes late.
The Providers: Compulsion, Compliance, and the Right to Challenge
Provider-based collection depends on the cooperation of electronic communication service providers, and the statute’s treatment of those providers is a distinct component of the design worth understanding on its own terms. The government does not simply take the data; it compels its production through directives, and the directives carry legal consequences for the companies that receive them.
A directive under Section 702 orders the provider to furnish the communications of tasked selectors and to do so in a manner that protects the secrecy of the collection. The statute requires the provider to comply, and it provides that compliance with a directive is a complete defense against civil liability arising from that compliance. The liability protection was essential to the design: without it, providers faced the prospect of lawsuits from their own subscribers for handing over communications, and the collection architecture would have depended on voluntary cooperation that no prudent company would offer. The directives are served and administered through the Federal Bureau of Investigation, which acts as the government’s interface with the providers, receiving the compelled data and forwarding it to the National Security Agency for processing and storage.
The statute does not leave providers without recourse. A provider that objects to a directive may challenge it before the Foreign Intelligence Surveillance Court, and may appeal an adverse ruling to the Foreign Intelligence Surveillance Court of Review. This challenge right was exercised early in the program’s history. In proceedings under the Protect America Act, the predecessor authority, an electronic communication service provider challenged the lawfulness of the directives served on it, arguing that they violated the Fourth Amendment. The Court of Review decided the case as In re Directives Pursuant to Section 105B of the Foreign Intelligence Surveillance Act in 2008, upholding the directives and holding that the foreign intelligence collection at issue satisfied the Fourth Amendment’s reasonableness requirement. The decision remains the only published opinion of the Court of Review addressing the constitutionality of programmatic foreign intelligence collection, and both sides of the later debates invoked it: the government cited it as judicial validation of the programmatic model, while critics noted that it addressed the predecessor statute and predated the documented compliance problems.
The provider’s position in this arrangement has been one of the program’s persistent tensions. Providers are required by law to assist, are prohibited from disclosing the assistance in ways that would compromise collection, and have historically sought to disclose as much as the law permits about the scope of government demands on them. The June 2013 disclosures placed several providers in the position of publicly addressing their cooperation with the program, and the years since have seen ongoing negotiation, through litigation and legislation, over the transparency reports providers may publish about the directives they receive. None of this alters the statute’s allocation of duties: the government tasks the selectors under court approved procedures, and the providers furnish the specified communications. But the arrangement means the program’s operation depends on private actors whose commercial interests and public reputations give them reasons to press for narrower or more transparent implementation than the government might prefer.
Minimization: The Rules for Data Already Held
Minimization procedures answer the question that incidental collection poses: now that the government lawfully holds communications of Americans it did not target, what may it do with them. The statute defines minimization procedures as rules reasonably designed to minimize the acquisition and retention, and to prohibit the dissemination, of nonpublicly available information concerning unconsenting United States persons, consistent with the need to obtain, produce, and disseminate foreign intelligence information. The definition’s final clause is doing the balancing work. Minimization does not require the government to discard everything that touches an American; it requires procedures that protect American identities and communications to the extent consistent with producing the foreign intelligence the program exists to collect.
In practice the procedures operate across the lifecycle of the data. At acquisition, they limit what may be retained when incidentally collected communications are swept in. During retention, they set time limits after which data must be aged off the systems, and they restrict who within the agencies may access unminimized data. At dissemination, they require that reports distributed outside the collecting agency mask the identities of United States persons, substituting generic descriptions for names, unless unmasking is necessary to understand the foreign intelligence value of the information or to assess its importance. Unmasking, the decision to reveal an American’s identity in a disseminated report, is itself governed by procedures specifying who may approve it and on what showing. Each of these stages has been a site of compliance findings, because each involves analyst judgment applied at volume under time pressure.
Two caveats frame everything said here about minimization. First, the procedures’ operational details are classified, so public discussion necessarily operates one level above the actual rule text, relying on official summaries, declassified opinions, and oversight characterizations. Second, the procedures differ across the collecting agencies, reflecting their different missions: the rules that govern the National Security Agency’s handling of the data are not identical to those that govern the Federal Bureau of Investigation’s, and the 2018 court opinion’s findings concerned the Bureau’s practices specifically. Readers should therefore treat general statements about minimization as describing the framework’s shape rather than any single agency’s rulebook. The query rules, which govern the most consequential use of minimized data, receive their own treatment in the next sections, because they outgrew the minimization framework and eventually required procedures of their own.
Retention, Dissemination, and Unmasking in Practice
The minimization framework’s three stages each present distinct tensions, and examining them separately shows why the procedures have been so difficult to get right. Retention is the first. Collected communications cannot be kept indefinitely; the procedures set time limits after which data must be removed from the systems, with longer retention permitted for data that has been determined to contain foreign intelligence information and shorter limits for the rest. The logic is straightforward: the longer incidentally collected American communications sit in government databases, the more opportunities arise for them to be queried, disseminated, or mishandled. Retention limits are therefore privacy protections measured in years, and compliance reviews have examined whether data was aged off on schedule.
Dissemination is the second stage and the one most visible to consumers of intelligence. When analysts write reports based on Section 702 collection, those reports circulate to policymakers, military commands, and law enforcement agencies with a need for the information. The minimization procedures require that reports mask the identities of United States persons whose communications were incidentally collected, describing them with generic phrases rather than names. The purpose is to let the foreign intelligence value of the report reach its readers without exposing the American’s identity to everyone on the distribution list. Dissemination controls also limit which agencies may receive unminimized data at all, reflecting the judgment that the risk to privacy grows with each additional holder of the information.
Unmasking is the exception to masking, and it has generated its own controversies. When a report recipient believes that knowing the masked American’s identity is necessary to understand the foreign intelligence significance of the report, the recipient may request that the identity be revealed, and designated officials may approve the request under the procedures’ standards. Unmasking requests are logged and subject to review, and the standards for approval require a showing tied to the intelligence value rather than curiosity or political interest. Critics have argued that the volume of unmasking requests suggests the protection is thinner than described, while officials have responded that most requests arise in legitimate counterintelligence contexts where the identity is genuinely necessary. The procedures’ classified details make independent assessment difficult, which is itself one of the critics’ central complaints about the entire minimization regime.
The 2013 Disclosures and the Public Debate They Created
In June 2013, the unauthorized disclosure of classified documents brought the program’s existence and its two collection methods into public view for the first time. Press reporting described the downstream program under the name PRISM and described upstream collection from the internet backbone, and the disclosures triggered the most intense public debate about surveillance law in a generation. The debate’s shape is worth recalling because it set the terms for every reauthorization fight that followed. One side argued that the disclosures revealed a program operating lawfully under congressional authorization and judicial supervision, collecting foreign targets’ communications with protections for Americans that the reporting had obscured. The other side argued that the scale of incidental collection and the secrecy of the governing procedures meant the public had never meaningfully consented to the program, regardless of what the statute said.
The government’s response to the disclosures unfolded over the following year through a series of declassifications: opinions of the surveillance court, compliance reports, and official descriptions of the targeting and minimization procedures were released in redacted form. These releases gave the public its first look at the certification model and the four prohibitions as operating realities rather than statutory abstractions. They also revealed the existence of compliance incidents, which both sides read as vindication: supporters saw a system detecting and reporting its own errors, while critics saw errors that had persisted in secret until exposure forced disclosure. This article’s May 2014 date falls near the end of that declassification wave, which is why the article can describe the program’s architecture with confidence while noting that the compliance record’s fullest airing came later, through the opinions declassified after 2017.
The State of Play in Early 2014
This article is dated May 15, 2014, and the picture it presents should be understood as the picture visible on that date, before the later developments the subsequent sections record. The state of play in the spring of 2014 had its own shape: a presidential reform announcement whose implementation was incomplete, a legislative debate with multiple competing bills and no enacted outcome, an oversight board report on Section 702 still in preparation, and a program operating under the original statutory design with the query rules still in their spare 2014 form.
The presidential action came on January 17, 2014, when the President delivered a speech on the government’s signals intelligence activities and issued Presidential Policy Directive 28. The speech acknowledged that the disclosures had raised legitimate concerns, announced the end of the bulk telephony metadata program as it then existed, and directed a transition to a new arrangement. The directive established principles for signals intelligence collection, including that collection must be authorized by statute or executive order, must be reasonable in light of its purposes, and must take into account the privacy interests of all persons regardless of nationality. The directive’s extension of privacy considerations to non-United States persons was a notable policy shift, though its legal force was that of an executive directive rather than a statute, and its implementation across the intelligence community was a work in progress as of the spring.
The legislative landscape in early 2014 featured competing visions. Reform legislation, in the form of the USA FREEDOM Act as then drafted, proposed to end bulk metadata collection, to add transparency requirements, and to introduce an adversarial voice into surveillance court proceedings through appointed advocates. A competing bill, the FISA Improvements Act, proposed to preserve the existing programs while adding more limited transparency and oversight measures. Neither had been enacted as of May 15, 2014. The existence of competing bills with substantial support on each side indicated that Congress had not settled on a direction, and the eventual outcome, the USA FREEDOM Act of 2015 addressing Section 215 while leaving Section 702 for its own reauthorization cycle, was not yet foreseeable in the form it took.
The oversight institutions were mid-cycle. The Privacy and Civil Liberties Oversight Board had issued its report on the Section 215 bulk metadata program in January 2014, finding that the program had not been demonstrated to be effective and recommending its end, but its report on Section 702 was still in preparation and would not issue until July 2, 2014. The surveillance court was conducting its annual review of the Section 702 certifications under the procedures then in force, with no public indication of the compliance findings that the later declassified opinions would reveal. The intelligence committees were receiving the classified compliance reports, but the public debate proceeded without the detailed violation findings that transformed the argument after 2018.
What was known in May 2014, then, was the statutory design, the targeting and minimization procedures as declassified, the aggregate scale of the program in broad terms, and the shape of the public argument as it had developed since the disclosures. What was not known included the compliance findings the court would later publish, the query rule changes the later reauthorizations would make, the outcome of the legislative competition, and the eventual lapse of the authority. This article’s 2014 frame presents the program as it could be understood on its date, and the dated later developments supply what came after. The discipline of the date wall is what keeps the two from contaminating each other.
Congressional Oversight: Reports and the Intelligence Committees
Between reauthorizations, Congress oversees the program through the intelligence committees of the House and Senate, which receive the reports and assessments the statute requires. The executive branch provides semiannual assessments of compliance with the targeting and minimization procedures, and the committees hold briefings, many of them classified, at which members and staff question officials about implementation. This is the oversight the public does not see, and assessments of its adequacy divide along the same lines as assessments of the program itself. Defenders of the arrangement argue that cleared members with access to the classified record provide genuine supervision, pointing to instances in which committee pressure produced changes to procedures. Critics argue that oversight conducted in secret, by committees whose members rarely discuss the program publicly, cannot substitute for adversarial judicial review or informed public debate.
The reauthorization debates are the moments when this closed oversight opens, partially, to public view. The 2012 debate aired the basic arguments for extension without changing the statute. The 2018 debate, conducted with the 2017 abouts discontinuation and the first wave of declassified compliance opinions as background, produced the querying procedures and the other structural changes described below. The 2024 debate, conducted against the far fuller compliance record that included the 2018 court’s findings and the 278,000 figure, produced the closest vote on a warrant requirement the program ever faced and then rewrote the query rules. Each cycle followed the same pattern: disclosure or declassification expanded the public record, the expanded record intensified the query debate, and Congress adjusted the rules governing queries while leaving the targeting architecture intact.
The July 2014 Oversight Board Report
On July 2, 2014, weeks after this article’s date, the Privacy and Civil Liberties Oversight Board released its public report on the Section 702 program, the first comprehensive independent review by a body with access to the classified record. The Board, an independent agency within the executive branch charged with reviewing counterterrorism programs for privacy and civil liberties implications, based its assessment on classified briefings, the targeting and minimization procedures, and compliance reports. Its report assessed the program as valuable for foreign intelligence purposes while recommending reforms to strengthen its safeguards, a split verdict that both sides of the public debate claimed as support.
The report’s significance lies less in any single recommendation than in its demonstration that the program could be examined at all. Before the Board’s review, public discussion had proceeded almost entirely from press reporting and official summaries; after it, there existed an unclassified document, written by cleared reviewers with access to the underlying materials, describing how the certification model worked in practice and where its protections fell short. The Board continued its oversight with further assessments on January 29, 2015 and February 5, 2016, and returned to the subject on September 28, 2023 with a report adopted by a 3 to 2 vote containing 19 recommendations. That 2023 report landed in the middle of the reauthorization debate and supplied much of the factual record over which the House fought the tied vote described below.
Dissent Inside the Oversight System
The oversight system has not spoken with one voice, and its internal disagreements are part of the record. The Privacy and Civil Liberties Oversight Board’s September 28, 2023 report was adopted by a 3 to 2 vote, with the dissenting members taking a more skeptical view of the program’s safeguards than the majority’s 19 recommendations reflected. The split matters because the Board is the oversight body with the broadest access and the most public output; when its members divide, the division signals that the underlying questions admit reasonable disagreement even among cleared reviewers who examined the same classified record. The 2023 report thus did not settle the debate so much as document its terms with unusual precision.
Disagreement has also marked the surveillance court’s own engagement with the program. The court’s opinions show judges pressing the government on successive rounds of remediation, declining to accept initial fixes, and returning to the same compliance problems across multiple certification cycles. That persistence is itself a form of institutional dissent from the proposition that the program’s implementation was sound. At the same time, the court continued to approve the certifications each year, which supporters cite as evidence that the identified problems, however serious, did not render the program as a whole unlawful. The coexistence of pointed findings with continued approvals is the oversight record’s defining feature, and it resists reduction to either vindication or condemnation. Readers who treat the opinions as a single verdict will misread them; they are a multi-year argument between the court and the executive branch, conducted through findings, remediations, and renewed findings.
Queries: Searching Data the Government Already Holds
A query is a search of communications the government has already collected, using an identifier as the search term. An analyst investigating a counterterrorism lead, for example, might search the Section 702 databases for a telephone number or email address connected to the investigation to see whether any collected communications involve that identifier. Queries are how the collected data becomes useful: collection without the ability to search would be a warehouse nobody could enter. The query is also the point at which incidentally collected communications of United States persons are most likely to be surfaced and read, because a query term may be the identifier of an American, and the search will return the American’s incidentally collected communications that match it.
Critics call this practice the backdoor search, and the name captures the objection precisely. The argument runs as follows: the government may not target Americans under Section 702, but it may search the collected data for an American’s identifier and read the American’s communications without ever having obtained a warrant based on probable cause as to that American. The data was lawfully collected, the search is conducted for a foreign intelligence or law enforcement purpose, and no new acquisition from the target occurs, but the practical effect resembles what a targeted collection against the American would have produced. Supporters answer that a query is not a search of the American in the constitutional sense because the data was already lawfully in the government’s possession, and that querying a lawfully held database with an identifier is routine investigative practice across law enforcement. The disagreement is genuine and structural: it turns on whether the Fourth Amendment treats the query as a new search requiring its own justification or as use of information already lawfully acquired.
In the 2014 framework, queries by analysts were governed by the minimization procedures approved annually by the court. Those procedures set rules for when and how analysts could query the data using United States person identifiers, including requirements that queries be reasonably likely to return foreign intelligence information or, in some agency implementations, evidence of a crime. The procedures also addressed the documentation of queries and the handling of results. Because the minimization procedures are classified in their operational detail, the public record in 2014 contained the framework of the rules rather than their full text, and debate about whether the rules were adequate proceeded partly on the basis of official summaries and oversight characterizations.
The query rules changed substantially after 2014, and the evolution is one of the most important parts of the program’s history. The 2018 reauthorization added a new statutory requirement that the Attorney General and the Director of National Intelligence maintain querying procedures governing how analysts search the collected data, and it required the Federal Bureau of Investigation to keep a record of each query term reasonably believed to identify a United States person. The same 2018 law added a restriction, now superseded, that barred the Bureau from using the results of United States person queries in criminal investigations unrelated to national security unless the Bureau first obtained an order from the surveillance court based on probable cause or the query concerned a threat to life or serious bodily harm. That order requirement applied to a narrow class of criminal matters and was the closest the statute ever came to a general warrant requirement for queries. The 2024 reauthorization then rewrote that provision: instead of a court order requirement, the statute as amended bars queries that are solely designed to find and extract evidence of criminal activity, with exceptions for defined circumstances. Each of these changes is dated in the later developments section below, and the rewriting history matters because commentary sometimes describes a court order requirement that the amended text no longer contains in that form.
What does calling a query a backdoor search imply?
A backdoor search is a query of already collected Section 702 data using an identifier belonging to a United States person, such as an American’s email address. Critics use the term to argue that analysts can read an American’s incidentally collected communications without the warrant that targeting that American would have required.
The Query Debate in Depth: Two Readings of the Fourth Amendment
The query debate repays extended attention because it is the rare legal argument in which both sides can claim the support of ordinary intuition. The supporters’ reading starts from a familiar principle: the government may use information it lawfully possesses. Police who lawfully seize a suspect’s address book may look through it without getting a second warrant for each name inside. On this analogy, the Section 702 database is a lawfully assembled holding, the query is an act of looking through it, and requiring a warrant for each United States person identifier would be like requiring a warrant to read a page of a book the government already owns. The reading draws additional support from the principle that the Fourth Amendment regulates searches and seizures, not the subsequent analysis of lawfully seized material, and from the practical observation that investigators across government routinely query databases containing Americans’ information without individualized court orders.
The critics’ reading starts from a different familiar principle: the reasonableness of a search depends on its justification at the time it occurs. On this view, the lawfulness of collecting a foreign target’s communications does not transfer to the distinct act of searching those communications for an American’s identifier years later, for a different purpose, by a different analyst. The analogy critics offer is the general warrant the Fourth Amendment was written to prohibit: a broad authorization that lets officers rummage through private papers looking for evidence of wrongdoing. The query, in this reading, is the rummage, and the fact that the papers were lawfully in the government’s hands does not answer whether rummaging through them for an American’s communications is reasonable without a warrant based on probable cause.
The surveillance court’s October 2018 opinion gave the critics’ reading its most authoritative judicial support, finding that certain of the Bureau’s querying practices violated not only the statute but the Fourth Amendment itself. That finding matters because it rejected the argument that the lawfulness of the initial collection settles the constitutional question for all subsequent uses. At the same time, the opinion did not hold that all United States person queries are unconstitutional, and later opinions evaluated the government’s remedial measures rather than shutting the practice down. The constitutional question therefore remains what it was in the 2014 frame: genuinely contested, with the strongest judicial statement on either side being a finding that the practice as implemented at a particular time crossed the line, not a ruling that the line sits at any fixed point. Readers who want the fullest account of how courts have handled surveillance challenges should consult the companion on court cases and the standing and challenge history, which traces the litigation this article does not attempt to replicate.
Queries Across Agencies: Who Searches the Data
Collection under Section 702 is conducted principally by the National Security Agency, but the collected data does not stay inside that agency. Other intelligence agencies with a foreign intelligence mission may be given access to query the data, and the Federal Bureau of Investigation, with its dual intelligence and law enforcement missions, has been the most consequential and most controversial of those users. The division of labor reflects the program’s design: one agency collects under the targeting procedures, and several agencies exploit what was collected under the minimization and later the querying procedures. Each agency applies its own implementing procedures within the court approved framework, which means a practice found compliant at one agency may be found wanting at another.
The Bureau’s role deserves separate attention because the compliance record’s most serious findings concerned it. The October 2018 court opinion documented Bureau analysts running United States person queries without adequate justification, including queries connected to criminal investigations and vetting matters rather than to foreign intelligence. The 2018 reauthorization responded with Bureau specific requirements, notably the obligation to record each query term reasonably believed to identify a United States person, creating the paper trail that later made the 278,000 figure countable. The pattern illustrates a structural tension in the program’s design: the agency with the broadest domestic law enforcement responsibilities is also the agency whose queries most directly implicate Americans’ privacy, and the rules have repeatedly been tightened around that agency in particular. The 2024 rewrite of the query restriction, barring queries solely designed to find and extract evidence of criminal activity, was aimed at the same tension.
The Targeting and Query Rules Table
| Statutory source | What it forbids or allows | Oversight mechanism | Documented compliance record |
|---|---|---|---|
| 50 U.S.C. 1881a(a), targeting grant | Allows targeting of non-United States persons reasonably believed to be located outside the United States, for the purpose of acquiring foreign intelligence information | Annual certifications by the Attorney General and Director of National Intelligence, reviewed by the Foreign Intelligence Surveillance Court with targeting and minimization procedures | Court has approved annual certifications throughout the program’s operation; aggregate target counts reported in transparency reporting |
| 50 U.S.C. 1881a(b)(1) | Forbids intentionally targeting any person known at the time of acquisition to be located in the United States | Targeting procedures must be reasonably designed to ensure foreignness; detasking required when a target is found to be in the United States; compliance reviews by the Department of Justice and the Office of the Director of National Intelligence | Detasking incidents reported through the compliance process; no systemic violation of this prohibition documented in declassified opinions |
| 50 U.S.C. 1881a(b)(2), reverse targeting bar | Forbids targeting a person abroad where the purpose is to acquire the communications of a particular known person in the United States | Documentation of the analyst’s foreign intelligence purpose; after-the-fact review of tasking patterns against stated purposes | Purpose-based prohibition verified through documentation review; no major declassified finding of reverse targeting violations |
| 50 U.S.C. 1881a(b)(3) | Forbids intentionally targeting a United States person anywhere in the world | Targeting procedures and compliance reviews; categorical bar follows the person rather than the territory | No declassified finding of intentional targeting of a United States person; the bar is the settled element of the program |
| 50 U.S.C. 1881a(b)(4) | Forbids intentionally acquiring communications where sender and all intended recipients are known to be in the United States | Targeting procedures must prevent intentional acquisition of purely domestic communications | Wholly domestic acquisition addressed through procedure design; abouts collection raised adjacent questions resolved by discontinuation |
| Incidental collection, contemplated by the design | Allows acquisition of non-targets’ communications, including those of United States persons, when they communicate with targets; lawful and foreseeable | Minimization procedures governing retention, access, use, and dissemination of United States person information, reviewed annually by the court | Scale estimates contested and partially classified; minimization handling subject to ongoing compliance review |
| Querying of collected data, 2014 frame | Allows analysts to search collected data using identifiers including those of United States persons, under agency procedures and minimization rules | Agency guidelines, minimization procedures, and after-the-fact compliance reviews; no statutory query-specific rules in the original design | October 18, 2018 opinion by Judge Boasberg found Bureau querying and minimization violations of statute and Fourth Amendment; declassified September 2019 |
| Querying procedures, added 2018 by Public Law 115-118 | Requires Attorney General and Director of National Intelligence querying procedures, subject to court review; Bureau must record each United States person query term | Court approval of querying procedures in the annual package; statutory record-keeping creating an auditable trail of United States person queries | December 2019 opinion published September 4, 2020, and November 2020 opinion reviewed continued compliance; approximately 278,000 non-compliant Bureau queries over 2020 to 2021 disclosed in May 2023 |
| Query restrictions, rewritten 2024 by Public Law 118-49 | Prohibits queries solely designed to find and extract evidence of criminal activity, with defined exceptions | Statutory prohibition replacing the 2018 court-order mechanism for the Bureau’s criminal use of query results | Post-enactment compliance record had not been established in declassified materials through the developments dated in this article |
| Abouts collection, discontinued April 28, 2017 | Formerly allowed upstream acquisition of communications merely referencing a tasked selector; barred outright by the 2024 reauthorization | April 26, 2017 opinion by Judge Collyer identified significant compliance problems in implementation | Discontinued by the National Security Agency days after the opinion; 2018 notice regime for resumption repealed and replaced by outright bar in 2024 |
The targeting and query rules collected in this table are standard examinable material in national security law coursework, and students working through them in a legislation study notebook will find that the table’s four columns reproduce the structure of the statute’s own logic: the grant of authority, the express limits, the oversight check on each limit, and the record of how the limits held up. Readers comparing this program’s design with the civic structures that authorize and constrain federal power can work through the same material in a government and civics study guide.
The Compliance Record
In the 2014 framework, compliance rested on several overlapping mechanisms. The court’s annual review of the certification and procedures provided the forward looking check. The Department of Justice and the Office of the Director of National Intelligence conducted periodic compliance reviews examining whether targeting decisions followed the procedures. The inspectors general of the collecting agencies audited aspects of implementation. And the statute required reporting to Congress, including assessments of compliance. The design assumed that violations would be detected after the fact, reported to the court and to the intelligence committees, and corrected through revised procedures or retraining. What the public could verify of this system in 2014 was limited, because the compliance reports and the court’s opinions on them were largely classified, and the declassification of the compliance record came later.
The later record, once declassified, showed substantial violations concentrated in querying rather than in targeting. On October 18, 2018, Judge Boasberg of the surveillance court issued an opinion finding that the Federal Bureau of Investigation’s querying and minimization practices had violated the statute and the Fourth Amendment, documenting instances in which analysts had run United States person queries without an adequate foreign intelligence or law enforcement justification, including queries related to criminal investigations and to vetting. The opinion was declassified in September 2019 after appellate proceedings in the Foreign Intelligence Surveillance Court of Review, which ruled on July 12, 2019. Further opinions followed: a December 2019 opinion published on September 4, 2020, and a November 2020 opinion, each addressing the adequacy of the government’s remedial measures. In a declassification released in May 2023, the government disclosed that the Bureau had conducted approximately 278,000 noncompliant queries in 2020 and 2021, a figure that became the most cited single statistic in the reauthorization debate that followed.
The abouts chapter of the compliance record followed a different arc. On April 26, 2017, Judge Collyer of the surveillance court issued an opinion on the 2016 certifications that identified significant compliance problems with the National Security Agency’s upstream abouts collection. Two days later, on April 28, 2017, the agency announced that it was discontinuing abouts collection. The 2018 reauthorization responded with a statutory regime: it added a prohibition on abouts acquisition and created a notice procedure under which the government would have to notify Congress and obtain court approval before resuming the practice. The 2024 reauthorization repealed that notice procedure and replaced it with an outright statutory bar on resuming abouts collection. The sequence illustrates how the compliance record directly shaped the statute: a court finding about a collection method led to the method’s abandonment, and Congress then wrote the abandonment into law, first as a conditional regime and then as a flat prohibition.
Transparency Reporting and the Public Numbers
For most of the program’s early history, the public knew almost nothing quantitative about Section 702: not how many targets were tasked, not how many Americans’ communications were incidentally collected, not how often analysts queried the data with American identifiers. The 2013 disclosures changed the politics of secrecy without changing the underlying classification rules, and the transparency regime that emerged in their wake is worth describing because it defines what the public record does and does not establish.
The centerpiece of the transparency regime is the statistical transparency report published annually by the Office of the Director of National Intelligence, a practice that began in the aftermath of the disclosures. The report publishes the number of Section 702 targets tasked under the annual certifications, providing the aggregate scale figure, described as running into the tens of thousands of selectors. It also publishes, for later years, the number of queries conducted using United States person identifiers, broken out by agency, which supplied the public with the first systematic measure of the query practices at the heart of the debate. The figures are reported in ranges or approximations where precise numbers would reveal operational detail, a compromise between the public’s interest in oversight and the agencies’ interest in protecting methods.
The transparency reports answered some questions and sharpened others. They established that the program’s target set was large but bounded, that provider-based collection accounted for the dominant share of acquisition, and that United States person queries numbered in the thousands to tens of thousands annually depending on the agency and the year. What the reports did not establish was the figure reform advocates most wanted: an estimate of how many Americans’ communications were incidentally collected. The government declined to produce such an estimate, arguing that counting the Americans in the database would require analysts to examine the communications in ways that would themselves intrude on privacy, and that any estimate would be unreliable because the data does not reliably identify the citizenship of communicants. Critics rejected the argument as self-serving, noting that the government managed to count targets, queries, and reports with precision, and that the refusal left the central empirical question of the debate unanswered.
The transparency regime also extended to the providers, which began publishing the number of directives received, and to the surveillance court, whose declassified opinions supplied the compliance narrative. Taken together, these disclosures created a public record far richer than anything available before 2013, while leaving the most contested empirical question, the scale of incidental collection, unresolved. That asymmetry shaped the debate that followed: both sides argued from the numbers that existed, and both sides accused the other of exploiting the numbers that did not.
The Remediation Arc: From Finding to Fix
The compliance opinions tell a story not only of violations but of the system’s attempts to correct them, and that second story deserves the same attention as the first. After the October 2018 opinion documented the Bureau’s querying and minimization violations, the government did not simply accept the findings and continue unchanged. It implemented remedial measures: revised querying procedures, additional training for analysts, new approval requirements for certain categories of queries, and enhanced documentation rules designed to ensure that the justification for each United States person query was recorded before the query was run. The December 2019 opinion, published September 4, 2020, and the November 2020 opinion each evaluated whether those measures had cured the problems the court had identified.
This iterative pattern, finding followed by remediation followed by judicial assessment of the remediation, is the correction mechanism described earlier operating at full stretch across multiple years. Its defenders present it as evidence that oversight works even when it works slowly: the violations were found, the practices were changed, and the court verified the changes. Its critics present the same timeline as evidence that the mechanism is inadequate: the violations persisted for years before the 2018 opinion, the remediation required multiple rounds of court prodding, and the 278,000 noncompliant queries disclosed in May 2023 covered 2020 and 2021, years after the remediation began. Both readings draw on the same dated record. The remediation arc does not resolve the debate about the program’s oversight; it is one of the things the debate is about.
The abouts sequence offers the contrasting case of a problem resolved by abandonment rather than remediation. After the April 2017 opinion, the government did not attempt to fix abouts collection with better procedures; the National Security Agency discontinued the practice outright within two days. Congress then wrote the discontinuation into the statute, first as a conditional notice regime in 2018 and then as a flat bar in 2024. The difference between the two arcs is instructive. Where the government believed a collection method could be brought into compliance, it remediated and submitted to further review. Where it concluded the method’s compliance problems were structural, it walked away and Congress locked the door. Together the two arcs map the range of outcomes the oversight system can produce.
Reading a Declassified FISC Opinion
The compliance record of the program reaches the public primarily through declassified opinions of the surveillance court, and those opinions have conventions worth understanding. They are written by individual judges of the court, whose names appear on the opinions: Judge Collyer wrote the April 2017 opinion on abouts collection, and Judge Boasberg wrote the October 2018 opinion on querying violations. The opinions address the annual certifications, which is why they are dated to particular years’ submissions and why a single opinion can evaluate conduct stretching back across the certification period. They are released with redactions covering classified operational details, which means the public reads the court’s legal analysis and its factual findings with gaps where the specifics of collection methods and the identities of targets have been removed.
Reading these opinions requires attention to what they decide and what they do not. An opinion finding that particular querying practices violated the statute is a ruling on those practices as implemented, not a ruling that the statute itself is unconstitutional. An opinion approving a certification after requiring corrections is not an endorsement of everything the government did during the prior year; it is a determination that the corrected procedures satisfy the statute going forward. And the opinions’ discussion of compliance incidents reflects what the government’s own reporting disclosed plus what the court’s review uncovered, which means the record is only as complete as the reporting that feeds it. Critics have argued that this dependence on self reporting limits the opinions’ value as oversight, while supporters respond that the opinions’ pointed findings, including Fourth Amendment violations, demonstrate that the court does not simply accept the government’s account.
Where the Real Dispute Sits
The debate is about queries, not targeting: everyone agrees the statute forbids targeting Americans and everyone agrees Americans’ communications are collected incidentally, so the entire live dispute concerns what the government may do with data it lawfully holds, and any argument framed as whether Americans are targeted is arguing about a settled question.
That claim organizes everything else in this article, and it is worth testing against the two simplifications that dominate public discussion. The first simplification holds that the program spies on Americans. It misstates the targeting rules, which forbid exactly that, and it collapses the distinction between targeting a person and holding that person’s incidentally collected communications. The second simplification holds that Americans are unaffected by the program. It ignores incidental collection and querying, through which Americans’ communications are acquired in volume and then searched by identifier. The precise statement gives both halves equal weight: Americans are not targets and are nonetheless affected. Any account of the program that drops either half is incomplete, and most public accounts drop one of them.
The series thesis that runs through this article is that the operative text is the location of the real dispute, and this is the article in the series where the popular framing and the legal reality diverge most sharply. Popular framing asks whether the government is spying on Americans. The legal reality is a statute that answers that question with an explicit no and then generates, through the interaction of its targeting grant with the facts of global communication, a vast holding of incidentally collected American communications whose subsequent use the statute regulates through procedures that took a decade of litigation, oversight findings, and amendments to settle into their later form. The distance between the popular question and the legal question is the measure of how much precision matters here.
What Supporters Cite: The Intelligence Value Case
The case for the program rests on the proposition that collecting the communications of foreign targets at scale produces foreign intelligence that cannot be obtained as quickly, or in some cases at all, through individualized court orders. Executive branch officials across administrations described Section 702 as among the most significant sources of foreign intelligence available to the government, and the Privacy and Civil Liberties Oversight Board’s July 2, 2014 report, issued after this article’s date and noted below as a later development, assessed the program as valuable for foreign intelligence purposes while recommending reforms to its safeguards. The core of the value claim is temporal: foreign targets change selectors, move across borders, and coordinate in real time, and a system that requires a separate court order for each new selector would lose the communications that matter most, which are often the first ones after a target changes direction.
Supporters point to specific categories of contribution. Counterterrorism investigations used Section 702 collection to identify associates of known foreign operatives, to map networks reaching into the United States, and to develop the factual predicates for further investigative steps including traditional FISA applications against persons inside the country. Counterproliferation work drew on the program to track the activities of foreign persons involved in weapons of mass destruction programs. Cybersecurity and counterintelligence investigations used it to follow the communications of foreign government and nonstate actors conducting operations against United States interests. In each category the argument is not that the program replaced other tools but that it supplied the initial access, the tip that made the rest of the investigation possible, at a speed the individualized process could not match.
The query practice that critics call the backdoor search is, in the supporters’ account, one of the program’s most valuable features rather than a defect. When the Federal Bureau of Investigation opens a counterterrorism investigation involving a person inside the United States, supporters argue, the ability to check whether that person’s identifier appears in already collected foreign intelligence holdings can quickly establish or rule out a foreign connection, and requiring a probable cause order before running that check would delay the assessment past the point of usefulness. The supporters’ position treats the lawfully collected database as an investigative resource comparable to other government holdings that agents may search during an investigation, and it treats the query as an act of analysis rather than a new collection. On this view, restricting queries would not merely add a procedural step; it would blind investigators to connections the government already lawfully possesses.
Supporters also invoke the oversight record as evidence that the system’s self correction works. The compliance violations documented in the declassified court opinions were detected by the government’s own oversight mechanisms, reported to the court, and followed by remedial measures that later opinions evaluated. The discontinuation of abouts collection after the court’s 2017 findings is presented as the system functioning as designed: a compliance problem identified, a collection method abandoned, and the abandonment then codified by Congress. For supporters, the arc from violation to remediation to statutory reform demonstrates accountability rather than lawlessness, and they argue that the program’s value should be weighed alongside a compliance record that, while seriously flawed in the querying area, showed the oversight structure detecting and correcting its own failures.
What Critics Cite: The Civil Liberties Case
The civil liberties case against the program begins where the supporters’ case ends: with the incidentally collected communications of Americans and what analysts may do with them. Critics argue that the program’s scale makes incidental collection not a side effect but a central feature, producing a vast repository of Americans’ international communications held by the government without any individualized judicial finding as to those Americans. The constitutional objection holds that acquiring and then searching those communications by United States person identifier constitutes a search of the American under the Fourth Amendment, and that the absence of a warrant based on probable cause renders the practice unreasonable regardless of the lawfulness of the initial collection against the foreign target. On this view, the distinction between targeting and querying is a formalism that obscures the practical reality: the government ends up reading Americans’ emails without a warrant.
Critics ground that objection in the documented compliance record. The October 2018 court opinion’s findings that Bureau analysts ran United States person queries without adequate justification, including queries tied to criminal investigations and vetting rather than foreign intelligence, are cited as proof that the query authority as implemented exceeded its justification. The disclosure of approximately 278,000 noncompliant queries in 2020 and 2021 is cited as proof that the violations were not isolated lapses but a systemic pattern, and critics note that the figure counts only the queries the government’s own later review identified as noncompliant. For critics, the compliance history rebuts the claim that internal procedures adequately protect Americans: the procedures existed throughout the period of violations, were approved by the court, and were violated at scale anyway.
The structural objection goes deeper than any particular violation. Critics argue that programmatic authorization reverses the constitutional default by permitting the executive branch to decide whom to surveil under rules it helped write, with judicial review arriving annually and after the fact rather than before collection begins. The reverse targeting prohibition, which turns on the analyst’s purpose, is singled out as effectively unverifiable from outside the executive branch, since purpose is the easiest element of a targeting decision to assert and the hardest to disprove. The classification of the minimization procedures compounds the problem: critics argue that the public cannot evaluate protections it cannot read, and that congressional oversight, conducted largely in classified settings, cannot substitute for the adversarial testing that open courts provide.
Critics also dispute the claim that the oversight system corrected itself. They note that the most serious querying violations persisted for years before the court’s 2018 opinion, that the Bureau’s remedial measures were evaluated across multiple subsequent opinions rather than accepted at once, and that the statutory reforms arrived only after public disclosure forced the issue. The abouts discontinuation, presented by supporters as self correction, is presented by critics as abandonment under judicial pressure after years of problematic collection. For critics, the arc from violation to remediation demonstrates not accountability but the length of time a flawed practice can operate before the system responds, and they argue that the program’s intelligence value, whatever its extent, must be weighed against years in which Americans’ communications were searched on justifications the court later found unlawful.
What Section 702 Is Not
Clearing away the misconceptions is as important as stating the rules, because the program has accumulated a set of myths that survive every correction. It is not bulk collection of Americans’ communications. The authority targets specific foreign persons through tasked selectors; it does not sweep up domestic communications indiscriminately, and the statute expressly bars the intentional acquisition of purely domestic communications. It is not the telephone metadata program. That program rested on a different provision, collected a different kind of information from a different population, and was ended by the USA FREEDOM Act in 2015 while this authority continued under its own reauthorizations until 2026. Readers who want each of these myths tested against the text should work through the dedicated myths companion, which takes up the claims built on this section one by one.
It is not warrantless surveillance of Americans in the sense the phrase implies. The government may not target Americans under this authority, and the communications of Americans that the program holds arrived there incidentally, through lawful targeting of foreigners. That distinction does not settle the query debate, which is real and serious, but it does settle the targeting question, and commentary that ignores the distinction misleads its audience about what the statute permits. It is not an unregulated query regime either. Queries were governed by court approved minimization procedures in the 2014 framework, then by statutory querying procedures with record keeping requirements from 2018, then by the rewritten restriction of 2024. One may judge those rules inadequate, as the court’s 2018 opinion did for the practices it reviewed, but one may not accurately describe the practice as lawless. The program’s history is better understood as a long argument about the adequacy of rules than as the absence of them.
The 2018 Reauthorization: The First Rewrite
The 2018 reauthorization was the first time Congress substantially rewrote the program rather than merely extending it, and the circumstances explain why. The April 2017 abouts discontinuation had shown a collection method collapsing under judicial scrutiny. The declassification wave had given the public its first sustained look at compliance incidents. And the query debate, sharpened by years of argument since the 2013 disclosures, had produced a bipartisan appetite for statutory query rules to replace the minimization based regime. Public Law 115-118, signed January 19, 2018, was Congress’s answer, and its changes touched nearly every part of the program except the targeting architecture itself.
The law’s querying provisions were its centerpiece. For the first time, the statute required the Attorney General and the Director of National Intelligence to maintain querying procedures governing how analysts search the collected data, moving query governance out of the minimization procedures and into its own statutory home. It required the Bureau to keep a record of each query term reasonably believed to identify a United States person, creating the accountability mechanism the later compliance figures depended on. And it added the restriction, later rewritten in 2024, that barred the Bureau from using United States person query results in criminal matters unrelated to national security without a court order based on probable cause or a qualifying threat to life. That provision was the closest the statute ever came to a warrant requirement for queries, and its replacement six years later shows how unsettled the question remained.
The significance of the 2018 changes lay less in any single restriction than in the concession they represented. Congress had accepted the premise that queries of United States person identifiers were a distinct privacy event deserving distinct statutory rules, rather than a mere incident of lawful collection. The government’s position through the 2014 period had been that querying was analysis, not a separate search, and that the minimization procedures were sufficient protection. The 2018 statute did not adopt the critics’ characterization either, but it legislated on the critics’ terrain, writing query-specific obligations into the text for the first time.
The law also addressed abouts collection directly, adding the statutory prohibition and the notice before resumption regime that required congressional notification and court approval before the practice could return. In doing so it converted a voluntary agency discontinuation into a legal constraint, illustrating the pattern by which the program’s hardest episodes ended up written into the statute. The 2018 reauthorization thus set the template for 2024: leave the targeting rules alone, tighten the query rules, and codify the lessons of the compliance record. The 2024 law followed the template while going further on both queries and abouts, replacing the court order approach with the criminal purpose bar and replacing the conditional abouts regime with a flat prohibition.
None of these changes altered the underlying architecture. The certification model survived both reauthorizations intact. The four prohibitions survived intact, with a fifth added in 2018 barring the abouts form of collection that had already been discontinued. The targeting grant survived intact. What changed, in each round, was the density of the rules around the edges of the program: more documentation, more specific prohibitions on particular uses, more congressional notification. The pattern suggests a legislative judgment that the program’s core was defensible and its margins needed tightening, a judgment that satisfied neither the program’s strongest defenders, who saw unnecessary constraint, nor its strongest critics, who saw insufficient reform.
Why Courts Rarely Reach the Merits
A reader might wonder why the constitutional questions at the heart of the query debate were not settled long ago by the ordinary courts. The answer lies in the threshold barriers that surveillance challenges confront before any judge reaches the merits. To bring a lawsuit in federal court, a plaintiff must show a concrete injury traceable to the challenged conduct, and the secrecy surrounding intelligence collection makes that showing extraordinarily difficult. A person who suspects, but cannot prove, that their communications were incidentally collected and queried will struggle to establish the standing that courts require. The government has also asserted privilege over the details of collection in litigation, further narrowing the path to a merits ruling.
These barriers explain why the surveillance court’s classified opinions, rather than the public federal courts, became the principal forum in which the program’s legality was tested. The Foreign Intelligence Surveillance Court sees the classified record that public plaintiffs cannot, and its judges rule on the statute’s implementation with the full facts before them. The trade-off is the one critics emphasize throughout this article: the forum that can reach the merits is the forum the public cannot watch. The standing and challenge history, including the cases that tried and failed to bring these questions into open court, is traced in the companion on court cases linked earlier in this article. The structural point stands on its own: a program whose constitutional questions are hardest to litigate in public is a program whose public debate will always outrun its case law.
The Tied Vote
On April 12, 2024, the House of Representatives voted on an amendment offered by Representative Andy Biggs of Arizona that would have required the government to obtain a warrant before conducting queries of Section 702 collected data using identifiers of United States persons. The vote was 212 to 212. A tie defeats an amendment, and the warrant requirement was not added to the bill. The reauthorization legislation then passed the House by a vote of 273 to 147. The tied vote is recorded here without characterization of the positions on either side, as the closeness of the result speaks to the depth of the disagreement about queries that this article has described.
The road to that tie ran through the compliance record. When the 2024 reauthorization debate began, the House had before it the fullest public account of the program’s implementation ever assembled: the 2017 and 2018 court opinions with their findings on abouts collection and FBI querying, the 2019 and 2020 follow-on opinions assessing remediation, the May 2023 disclosure of approximately 278,000 noncompliant queries, and the Privacy and Civil Liberties Oversight Board’s September 28, 2023 report with its 19 recommendations, adopted 3 to 2. No earlier reauthorization debate had confronted a record like it. The 2012 extension had been argued largely from official assertions about value and compliance; the 2018 reauthorization had the first wave of declassified opinions; the 2024 debate had a documented pattern of querying violations spanning years.
The warrant amendment was the legislative expression of the critics’ reading of that record. Its premise was that the query rules as implemented had failed to protect Americans’ incidentally collected communications, that internal procedures and after the fact oversight had proven inadequate, and that only a judicial check before the query, a warrant based on probable cause, would suffice. The opposition’s premise was that the query capability was essential to the program’s counterterrorism value, that the compliance problems had been remediated under court supervision, and that a warrant requirement would delay time sensitive investigations past usefulness. The House divided 212 to 212 on those premises. The reauthorization that followed, enacted April 20, 2024 as Public Law 118-49, took the middle path the tied vote left open: it rewrote the query restriction into a prohibition on queries solely designed to find and extract evidence of criminal activity, with defined exceptions, rather than imposing the warrant requirement the amendment had sought.
Later Developments, Explicitly Dated
Everything in this section postdates the article’s May 15, 2014 frame and is dated accordingly. On July 2, 2014, the Privacy and Civil Liberties Oversight Board released its report on the Section 702 program, assessing the program’s value for foreign intelligence while recommending reforms to its safeguards. The Board issued further assessments on January 29, 2015 and February 5, 2016, and on September 28, 2023 it released another report, adopted by a 3 to 2 vote, containing 19 recommendations.
The year 2015 brought the reform of the separate bulk metadata authority. The USA FREEDOM Act, Public Law 114-23, ended the bulk collection of domestic telephone metadata under the provision readers often confuse with Section 702, replacing it with a targeted system. That reform did not alter Section 702 itself, but it is noted here because the two authorities are so frequently conflated.
On April 26, 2017, the surveillance court issued an opinion on the 2016 certifications identifying significant compliance problems with the National Security Agency’s upstream abouts collection, and on April 28, 2017, the agency announced that it was discontinuing that form of collection. On January 19, 2018, the President signed the reauthorization, Public Law 115-118, which added the statutory requirement for querying procedures, required the Bureau to record each query term reasonably believed to identify a United States person, added the since superseded restriction on the Bureau’s use of United States person query results in non national security criminal matters, added the prohibition on abouts acquisition, and created the notice before resumption regime for abouts collection.
On October 18, 2018, the court issued the opinion documenting the Bureau’s querying and minimization violations of the statute and the Fourth Amendment, declassified in September 2019 after the Court of Review’s July 12, 2019 ruling. Further opinions followed in December 2019, published September 4, 2020, and in November 2020. A May 2023 declassification disclosed the approximately 278,000 noncompliant Bureau queries from 2020 and 2021.
On April 12, 2024, the House tied 212 to 212 on the warrant amendment described above, then passed the reauthorization 273 to 147. On April 20, 2024, the Reforming Intelligence and Securing America Act was enacted as Public Law 118-49. It rewrote the query restriction into a prohibition on queries solely designed to find and extract evidence of criminal activity, with defined exceptions; it repealed the notice before resumption regime and replaced it with an outright statutory bar on resuming abouts collection; and it set the authority to expire on April 20, 2026. Short extensions followed: Public Law 119-84 on April 18, 2026, and Public Law 119-87 on April 30, 2026. On June 11, 2026, the House voted 198 to 218 against further extension, and the lapse took effect on June 12, 2026. As dated here in October 2026, the Section 702 authority has lapsed.
Readers wanting the systematic comparison with other surveillance authorities should consult the FISA and Patriot Act comparison.
The Sunset Mechanism: Why the Authority Kept Expiring
Section 702 was never enacted as permanent law. Congress wrote expiration dates into the authority from the beginning, forcing itself to revisit the program at intervals: the 2008 enactment carried a sunset, the 2012 reauthorization extended it, the 2018 reauthorization extended it again, and the 2024 reauthorization set the final expiration for April 20, 2026. The sunset mechanism is a deliberate oversight tool. By making the authority temporary, Congress ensured that the program’s continuation would require an affirmative legislative act, and that each such act would become an occasion for public debate, oversight hearings, and amendments reflecting the lessons of the preceding years. Every major change described in this article, from the 2018 querying procedures to the 2024 rewrite, arrived through a reauthorization that the sunset had forced onto the calendar.
The mechanism worked as designed in 2026, though not in the direction supporters of the program preferred. After the April 20, 2026 expiration was twice extended by short term laws, Public Law 119-84 on April 18, 2026 and Public Law 119-87 on April 30, 2026, the House voted 198 to 218 on June 11, 2026 against further extension, and the lapse took effect June 12, 2026. The sunset thus produced the outcome its drafters contemplated as a possibility: a Congress that declined to continue the authority, ending the program. Whether the lapse proves temporary or permanent is a question for legislation this article does not attempt to predict. The structural point is that the program’s entire history, including its end, was shaped by the decision to make its existence contingent on periodic congressional reapproval rather than self sustaining.
After the Lapse: The Record as of October 2026
The lapse that took effect on June 12, 2026 closed the program’s operational history, and the months since have been a period of assessment rather than collection. As dated here in October 2026, no new acquisitions may be conducted under the authority this article describes, and the debates that structured its reauthorizations have moved to the question of what, if anything, should replace it. That question is outside this article’s scope, which is the statute as it operated, but the record assembled above is the evidence any successor debate will have to confront.
The record’s shape is fixed enough to summarize. The targeting architecture Congress created in 2008 survived every reauthorization essentially intact: the certification model, the reasonable belief standard, and the four prohibitions were never fundamentally restructured, and the documented compliance problems concerned implementation rather than the targeting rules themselves. The query rules, by contrast, were rewritten twice, first in 2018 and again in 2024, each time in response to court findings that the existing rules had been violated. The abouts method was abandoned under judicial pressure and then statutorily barred. The warrant amendment for United States person queries failed by the narrowest possible margin in the House, and the authority itself then lapsed two years later when the House declined to extend it further. Any future legislation will be drafted against this history, and its drafters will have the advantage this article’s 2014 readers did not: a nearly complete public record of how the statute worked, where it failed, and how it was fixed.
Reading the Statute: A Guided Tour of the Provision
Readers who consult the statutory text directly will find it dense but navigable, and a guided tour of its structure helps connect the provisions this article has discussed to their locations in the law. The tour follows the 2014 frame, noting where later reauthorizations added or changed material.
The provision opens with the targeting grant, authorizing the Attorney General and the Director of National Intelligence to target persons reasonably believed to be outside the United States for the purpose of acquiring foreign intelligence information. The section’s title supplies the non-United States person limitation that the prohibition subsection makes explicit. This opening is the authority everything else constrains.
The prohibitions follow immediately. Four paragraphs bar, in sequence, intentional targeting of persons known to be in the United States, reverse targeting aimed at a particular known person in the United States, intentional targeting of United States persons anywhere, and intentional acquisition of purely domestic communications. A fifth paragraph barring abouts collection was added by the 2018 reauthorization, a dated later development, after the practice had already been discontinued. The prohibitions are the shortest path to understanding what the statute forbids, and they repay close reading because each turns on distinct elements of intent, knowledge, and purpose.
The certification provisions come next, setting out what the Attorney General and the Director of National Intelligence must attest to each year and what the court’s review covers. The statute requires the certifications to affirm that the targeting procedures and minimization procedures satisfy the statutory standards, and it provides for judicial review of the certifications through a defined appellate path. The pre-2018 subsection lettering for these provisions changed in the 2018 reauthorization, so readers consulting the current code should expect different letters than a 2014 reader would have found.
The targeting procedures and minimization procedures are not stated in the statute at length; instead, the statute states the standards the procedures must meet and leaves the detailed rules to the classified procedures the court reviews. The targeting procedures must be reasonably designed to ensure that acquisitions target only persons reasonably believed to be outside the United States and to prevent the intentional acquisition of purely domestic communications. The minimization procedures must govern the acquisition, retention, use, and dissemination of United States person information. The 2018 reauthorization added querying procedures to this list, a dated later development this article has described.
The remaining provisions address oversight and implementation. The statute requires the Attorney General and the Director of National Intelligence to assess compliance and report to Congress and the court, mandates semiannual assessments by the agencies, and sets out the notice requirement for criminal proceedings in which the government intends to use information obtained or derived from the collection. These are the provisions that convert the substantive rules into an accountability regime, and they are the provisions the declassified opinions interpret when they evaluate whether the government’s implementation has satisfied the law.
A reader who has walked this structure has the complete map: the grant, the prohibitions, the certifications, the procedures, and the oversight. Every controversy the article has described can be located on that map, which is why the map is worth having before entering the debate.
The program this article has described is neither the warrantless spying on Americans of its harshest critics’ slogan nor the foreign only collection of its warmest defenders’ slogan. It is a statute that forbids targeting Americans, that collects Americans’ communications incidentally as a foreseeable consequence of targeting foreigners who talk to them, that permits analysts to search those communications by identifier under procedures that took a decade of court opinions and amendments to define, and that documented serious violations of those procedures before Congress rewrote them. The authority lapsed on June 12, 2026, after the extensions and the failed vote recorded above. Whatever replaces it, or whether anything does, will be debated against the record this article has set out: the certification model, the four prohibitions, the incidental collection nobody targeted, and the queries where the real dispute always sat.
Frequently Asked Questions
Q: What is section 702 surveillance?
Section 702 surveillance is the collection of communications under Section 702 of the Foreign Intelligence Surveillance Act, codified at 50 U.S.C. 1881a and added by the FISA Amendments Act of 2008, Public Law 110-261. It allows the government to target non-United States persons reasonably believed to be located outside the United States for the purpose of acquiring foreign intelligence information, without obtaining an individualized court order for each target. Instead, the surveillance court annually approves certifications plus targeting and minimization procedures, and analysts task individual selectors under those procedures. The statute expressly forbids targeting Americans or persons known to be in the United States. The authority was reauthorized in 2012, 2018, and 2024, then lapsed on June 12, 2026, after short extensions and a failed House vote on further extension.
Q: Does section 702 require a warrant?
Section 702 does not require an individualized warrant or court order for each target, and that is the structural feature that distinguishes it from traditional FISA surveillance. The statute substitutes programmatic authorization: the Foreign Intelligence Surveillance Court reviews and approves the annual certification together with the targeting and minimization procedures, and the government then selects targets under those procedures without returning to the court. Whether this arrangement satisfies the Fourth Amendment has been contested since the program’s creation. Proposals to require a warrant for queries using United States person identifiers were debated in Congress, and one such amendment failed on a 212 to 212 House tie on April 12, 2024. The authority lapsed on June 12, 2026.
Q: Can section 702 target Americans?
No. The statute expressly prohibits intentionally targeting a United States person anywhere in the world, and separately prohibits targeting any person known to be in the United States. Those are two of the four prohibitions in the statutory text, and no declassified court opinion has found an intentional violation of the targeting bar. But the targeting answer is not the whole answer. Americans’ communications are collected incidentally when foreign targets communicate with them, and analysts may query the collected data using American identifiers without a court order. So the precise statement is that Americans may not be targets and are nonetheless affected through incidental collection and querying, and both halves of that statement must be given equal weight.
Q: What is incidental collection under section 702?
Incidental collection is the acquisition of communications of persons who were not targeted, which happens when a tasked foreign target communicates with them. Because collection is directed at the target’s selector rather than sorted person by person at the moment of acquisition, the American side of a conversation with a foreign target is swept in along with the target’s side. The statute contemplates this rather than prohibiting it: the targeting procedures keep the targeting lawful, and the minimization procedures govern the retention, use, and dissemination of the incidentally collected United States person information. Incidental collection is lawful and foreseeable, and it is the source of nearly every serious concern about the program, because it creates a database of Americans’ communications searchable through queries.
Q: What is a backdoor search under section 702?
A backdoor search is the critics’ term for querying Section 702 databases with a United States person identifier in order to retrieve that American’s incidentally collected communications without a warrant. The front door, intentionally targeting the American, is barred by statute; the query retrieves the same communications through data that was collected for other purposes. Defenders of the program dispute the label, arguing that searching lawfully collected foreign intelligence data is standard analysis rather than a search requiring judicial authorization. The underlying facts are not contested: analysts can use American identifiers as query terms, the searches return Americans’ communications, and no individualized court order precedes the search. The dispute concerns the legal characterization of those facts and the rules that should govern them.
Q: What is upstream collection under section 702?
Upstream collection is the acquisition of communications from the internet backbone, the high capacity cables and switches carrying internet traffic, by scanning that traffic for tasked selectors. It is one of the program’s two collection methods, alongside downstream collection from service providers. In the framework as it stood in 2014, upstream collection could also acquire abouts communications, messages that merely referenced a tasked selector without being to or from the target. After the surveillance court identified significant compliance problems with abouts collection in an April 26, 2017 opinion, the National Security Agency discontinued the practice on April 28, 2017. Congress then addressed it legislatively, and the 2024 reauthorization bars resumption of abouts collection outright.
Q: How often has section 702 been reauthorized?
Section 702 was reauthorized three times after its enactment in 2008. The first reauthorization came in 2012 under Public Law 112-238, signed December 30, 2012, which extended the authority through December 31, 2017, without major structural changes. The second came in 2018 under Public Law 115-118, signed January 19, 2018, which added court-reviewed querying procedures, record-keeping for United States person queries, and restrictions on certain criminal uses of query results. The third came in 2024 under the Reforming Intelligence and Securing America Act, Public Law 118-49, enacted April 20, 2024, which rewrote the query restrictions and set a sunset of April 20, 2026. After two short extensions, the House rejected further extension on June 11, 2026, and the authority lapsed effective June 12, 2026.
Q: Did the House tie vote on section 702 warrants?
Yes. On April 12, 2024, the House of Representatives voted 212 to 212 on an amendment offered by Representative Andy Biggs of Arizona that would have required the government to obtain a court order before querying Section 702 databases with identifiers associated with United States persons. A tie defeats an amendment under House procedures, so the warrant requirement was not adopted. The underlying reauthorization bill, the Reforming Intelligence and Securing America Act, then passed the House 273 to 147 and was enacted April 20, 2024, as Public Law 118-49, without the warrant provision. The tie remains the closest the warrant proposal came to enactment and the clearest measure of how deeply the query question divided the chamber.
Q: What is the certification model under Section 702?
The certification model is the program’s substitute for individualized court orders. Each year the Attorney General and the Director of National Intelligence submit certifications to the Foreign Intelligence Surveillance Court attesting that the targeting and minimization procedures satisfy the statute, and the court reviews and approves the certification with those procedures. Once approved, analysts may task individual selectors under the procedures without seeking a court order for each target. Oversight then operates after the fact through Justice Department and intelligence community compliance reviews, inspector general audits, and reporting to the court and Congress. Supporters describe this as programmatic authorization suited to fast moving targets; critics describe it as removing the judge from the decision that matters most.
Q: What are the four targeting prohibitions in Section 702?
The statute states four express prohibitions. First, the government may not intentionally target any person known at the time of acquisition to be located in the United States. Second, it may not target a person abroad for the purpose of acquiring the communications of a particular known person inside the United States, which is the reverse targeting bar. Third, it may not intentionally target a United States person reasonably believed to be located outside the United States, which applies anywhere in the world. Fourth, it may not intentionally acquire communications as to which the sender and all intended recipients are known at the time of acquisition to be located in the United States. Together these provisions fence the targeting authority geographically, protect Americans everywhere, and bar both pretextual and purely domestic acquisition.
Q: What is reverse targeting under section 702?
Reverse targeting is the practice the statute’s second prohibition forbids: targeting a person reasonably believed to be abroad where the real purpose is to acquire the communications of a particular known person inside the United States. If the government wants the communications of someone in the United States, it may not task that person’s foreign correspondent as a workaround. The prohibition turns on the purpose of the acquisition, which makes it harder to verify from outside than the geographic bars. Oversight depends on documentation of the analyst’s stated foreign intelligence purpose and on after-the-fact review of whether the pattern of tasking is consistent with that purpose. The reverse targeting bar is what keeps the incidental collection doctrine honest, distinguishing foreseeable spillover from pretextual collection.
Q: What is downstream collection under Section 702?
Downstream collection is the acquisition of communications by compelling electronic communications service providers to turn over the communications of tasked selectors. When an analyst tasks an email address under the approved targeting procedures, the provider is directed to furnish communications to or from that address. This is the method publicly associated with the program reported in June 2013 under the name PRISM. It differs from upstream collection, which scans internet backbone traffic, in that it is bounded by the provider’s holdings for the tasked selector rather than by scanning traffic in transit. Downstream collection was not the subject of the abouts controversy, which concerned only the upstream method’s acquisition of communications merely referencing a selector.
Q: What do minimization procedures require under section 702?
Minimization procedures govern what happens to United States person information after it has been lawfully but incidentally acquired. They set retention limits on how long incidentally collected material identifying Americans may be kept, restrict which analysts may access unminimized data, limit the purposes for which the information may be used, and require the masking of American identities in intelligence reports except where the identity is necessary to understand the foreign intelligence. The Foreign Intelligence Surveillance Court reviews the minimization procedures annually alongside the targeting procedures. Because incidental collection is foreseeable and lawful, minimization is where the statute’s privacy protections for Americans actually operate, and disputes over the adequacy of minimization have been central to the compliance findings in the declassified court opinions.
Q: What role does the Foreign Intelligence Surveillance Court play under Section 702?
The court’s role is programmatic rather than individualized. It does not approve targets. Each year it reviews the Attorney General and Director of National Intelligence certification together with the targeting and minimization procedures, and it approves them or requires corrections. It receives compliance reports and has issued opinions evaluating the government’s implementation, including the April 2017 opinion on abouts collection and the October 2018 opinion documenting FBI querying and minimization violations. From 2018 the statute also required querying procedures subject to executive approval with court review of related materials. The court’s Section 702 work is therefore systemic oversight: it judges the rules and the compliance record rather than any individual targeting decision.
Q: What was abouts collection and why did it end?
Abouts collection was a form of upstream acquisition in which a communication was collected because it merely referenced a tasked selector, such as an email address appearing in the body of a message between two other people, rather than being sent to or from the selector. It vastly expanded the incidental collection footprint of upstream collection and strained the connection between the tasked target and the acquired communication. On April 26, 2017, Judge Rosemary Collyer of the Foreign Intelligence Surveillance Court issued an opinion identifying significant compliance problems with its implementation, and on April 28, 2017, the National Security Agency announced it was discontinuing the practice. The 2018 reauthorization created a congressional notice regime for any resumption, and the 2024 reauthorization repealed that regime and barred resumption outright.
Q: How did the 2018 reauthorization change Section 702?
The 2018 reauthorization, Public Law 115-118, signed January 19, 2018, made the most substantial changes to the program since its creation. It added a statutory requirement for querying procedures governing how analysts search collected data, and it required the Federal Bureau of Investigation to record each query term reasonably believed to identify a United States person. It added a restriction, later rewritten, barring the Bureau’s use of United States person query results in non national security criminal matters without a court order based on probable cause or a threat to life. It prohibited abouts acquisition and created a notice procedure for any future resumption. These changes responded directly to the compliance findings and to the query debate that had intensified since the 2013 disclosures.
Q: How did the query rules change after 2018?
Two reauthorizations rewrote the query rules, both dated later developments relative to 2014. The 2018 reauthorization, Public Law 115-118, required the Attorney General and the Director of National Intelligence to establish querying procedures subject to court review, required the Federal Bureau of Investigation to record each query term associated with a known United States person, and barred the Bureau from using United States person query results in non-national-security criminal matters without a court order based on probable cause or a threat to life. The 2024 reauthorization, Public Law 118-49, replaced that court-order mechanism with a direct prohibition on queries solely designed to find and extract evidence of criminal activity, with defined exceptions. Neither reauthorization imposed a general warrant requirement for United States person queries.
Q: Why did section 702 lapse in 2026?
The 2024 reauthorization, the Reforming Intelligence and Securing America Act, Public Law 118-49, set the authority’s sunset at April 20, 2026, a shorter extension than prior reauthorizations, reflecting diminished congressional consensus. Congress then enacted two short extensions, Public Law 119-84 on April 18, 2026, and Public Law 119-87 on April 30, 2026, rather than a further multi-year reauthorization. On June 11, 2026, the House voted on further extension and rejected it by 198 to 218. With no extension enacted, the authority lapsed effective June 12, 2026, ending new collection under the provision. The lapse followed the most contested reauthorization fight in the program’s history, including the 212 to 212 tie vote on the warrant amendment in 2024, and it marked the first time the authority expired without replacement since its enactment in 2008.
Q: How does Section 702 differ from Section 215 bulk metadata collection?
The two authorities are frequently confused but share almost nothing operationally. Section 702 acquires the contents of communications of foreign intelligence targets reasonably believed to be outside the United States, under programmatic court approval of procedures. Section 215, as implemented before 2015, was used for the bulk collection of domestic telephone metadata, records of who called whom and when, covering calls inside the United States. One targeted foreigners abroad for content; the other swept domestic records in bulk. The USA FREEDOM Act, Public Law 114-23, enacted in 2015, ended the bulk metadata program and replaced it with a targeted system. Section 702 continued under its own separate reauthorizations until its 2026 lapse.
Q: What compliance problems did the surveillance court document?
The most consequential findings came in an October 18, 2018, opinion by Judge James Boasberg, which held that Federal Bureau of Investigation querying and minimization practices had violated the statute and the Fourth Amendment, documenting queries made without adequate justification. The opinion was declassified in September 2019 after related appellate proceedings. A December 2019 opinion, published September 4, 2020, and a November 2020 opinion addressed continued compliance questions. In a declassification dated May 2023, the government disclosed approximately 278,000 non-compliant Bureau queries over 2020 to 2021. Separately, an April 26, 2017, opinion by Judge Rosemary Collyer identified significant compliance problems with abouts collection, leading to its discontinuation days later. Critics cited these findings as evidence the rules could not constrain agency behavior; defenders cited the detection and remediation as evidence the oversight system worked.