Last week was about naming things — separating the device from the data from the copy, and insisting that “papers” means content. Naming the object is step one. Step two is deciding the default: when the government encounters your digital property, what is it allowed to do before anyone asks a judge? The answer a statute gives to that question determines almost everything, and the answer our current law gives is the wrong one.
Start, as I keep doing, with the wiretap law, because it got the architecture right. Title III doesn’t open by listing the times the government may wiretap you. It opens, at 18 U.S.C. § 2511, with a flat prohibition: intercepting a communication is forbidden. Full stop. Everything that comes after — who may authorize an intercept, how they apply, what procedures they follow — is written as an exception carved out of that baseline prohibition. Permission is the special case.
That ordering is not a stylistic choice. It decides who must justify what. When the default is “forbidden unless authorized,” the government must point to a specific authority every time it acts, and if it can’t, it loses. When the default runs the other way — “permitted unless forbidden” — the burden flips onto the citizen to find a rule that was broken, and if there’s no rule on point, the government wins by silence.
Now look at how digital property is actually governed today, and you’ll see it runs on the second, backwards default — everywhere except the front door.
At the moment of collection, the Fourth Amendment supplies a real rule: the government generally needs a warrant to seize and search your device. That’s a genuine prohibition-first default, and it mostly works. But collection is only the first of five stages. Once the government has lawfully taken the data, what governs how it analyzes it, how long it keeps the copy, whether it can re-search that copy years later for a new purpose, and what it must do with the copy when the case ends? For those four stages — analysis, retention, use, disposition — there is almost no statute at all, and the effective default is “permitted unless forbidden.” The government keeps the forensic image indefinitely because nothing tells it not to. It re-opens the image for a new investigation because no rule clearly says it can’t. The silence is the permission.
That backwards default is not an abstraction. It is the exact mechanism that produced the retention abuses this blog keeps circling, and on Thursday I’ll show you a case — decided last December — where a federal judge had to reach for extraordinary equitable powers to undo it, precisely because no statute set the default correctly in the first place.
So the model act’s second section does the same thing Title III’s does: it states the prohibition first. The government may not collect, analyze, copy, use, or disclose, or dispose of a person’s digital property except as this Act authorizes. Every one of the five verbs starts at no. The authority to do each of them is then granted, deliberately and with conditions, in the sections that follow. Nothing happens by default and nothing happens by silence.
I want to be precise about what that prohibition is and isn’t, because the strongest objection to it comes from misreading it.
The prohibition does not mean “the government may never touch digital evidence.” It means “not without authority the statute actually grants.” That’s the same thing Title III means, and Title III has not ended electronic surveillance — it has channeled it, forced it through procedures, and given courts something to enforce. A prohibition-first default is not a ban. It’s a requirement that the government be able to say which provision lets it do what it’s doing, at every stage, not just at the moment it first takes the data.
Here is the objection, made as strongly as I can make it. A blanket prohibition on analyzing, copying, and retaining data is wildly overbroad. Modern investigation is nothing but analyzing, copying, and retaining data. Forensic work necessarily copies an entire drive to search any of it; agents necessarily read non-responsive files in the course of finding responsive ones; long or complex cases necessarily retain material for years. Start everything at “forbidden,” the argument runs, and you either criminalize the ordinary mechanics of law enforcement or you hand defendants a suppression argument for every unavoidable technical step — and in any event the list of exceptions will grow so long that it swallows the rule, so why pretend the default is prohibition at all?
I take that seriously, and part of the answer is in last week’s post. The reason to set the default at prohibition and then permit the necessary acts explicitly — rather than to start from permission — is honesty and reach. An explicit permission can be conditioned, logged, and time-limited; a silent default can’t be any of those things. When § 5 permits the technically necessary read of a whole drive, it can also forbid using what that read incidentally exposes. When § 6 permits retention, it can also start a clock running on it. When § 8 addresses disposition, it can require deletion instead of leaving the copy to sit forever. None of that is possible if the baseline is “permitted unless forbidden,” because there is nothing to attach the condition to. The exceptions don’t swallow the rule; the exceptions are where the actual regulation lives. The prohibition’s job is to make sure every one of them has to be written down and justified rather than assumed.
The other half of the objection — that this criminalizes routine work — is a drafting problem, not a reason to abandon the default. The prohibition is the baseline rule of a regulatory statute, not a new criminal offense for every stray byte. It sets what requires authority; the operative sections grant the authority for the things that should be permitted; and the remedy sections decide what actually follows from a violation, which will rarely be “suppress everything” and will often be something more calibrated. A prohibition-first structure is exactly what lets those consequences be proportionate, because it forces the statute to specify them.
Section 2 also has to draw the statute’s scope, and I’ll only sketch it here because each piece gets its own treatment later. It binds the government and those acting on its behalf, not private parties acting on their own — the private-search problem is real and gets its own post. It has to say what triggers the Act and name, at least in outline, the genuine exceptions that don’t fit the ordinary authorization track: consent, true emergencies, and the compelled assistance of providers. Title III has all of these, and a digital lifecycle statute needs them too. The point of § 2 is not to pretend those exceptions don’t exist. It’s to make them exceptions — enumerated, bounded, and carved out of a default that otherwise says no.
That’s the whole move, and it’s a small one to state and a large one in consequence. Name the object (§ 1). Set the default for that object to prohibition (§ 2). Then spend the rest of the statute granting, conditioning, and limiting the permissions. Get the default right and every later section has a job. Get it wrong — leave it where it sits today, permitted-unless-forbidden for everything past the front door — and you get exactly the world we have, where the government keeps your papers because no one ever told it to stop.
Next Tuesday: § 3, the first and most important of those permissions — authorization to collect. And Thursday, the case that shows the price of getting the default wrong.
(Model statutory text for § 2 comes in Pass 2 this fall. This post is the why; the drafting is next.)
Leave a comment