Everything so far has been about getting the data into the government’s hands the right way. Week 1 named it, Week 2 forbade taking it without authority, Week 3 built the authorization, Week 4 governed the procedure for collecting it. Now the data is lawfully in a government forensic lab, sitting on a drive: a complete image of someone’s digital life. What are the rules for looking at it?
There basically aren’t any. And that is the strangest and most consequential gap in the whole field, because looking at it is where I argue the search happens.
Notice that this is the first section of the model act with no predecessor in the wiretap act. Title III has a definitions section, a prohibition, an authorization regime, a collection procedure — the model act’s first four sections all have a § 25-something to borrow from. There is no § 2518-and-a-half for analysis, because a wiretap doesn’t have a separate analysis stage. When agents intercept a call, the interception is the search; the intrusion and the acquisition happen in the same instant, and Title III’s minimization rule governs that instant. Traditionally, there is no later moment when the government sits down with a complete copy of everything and decides what to examine. The wiretap era never needed an analysis section because the wiretap collapsed collection and examination into one act.
The forensic image pulls them apart, and that changes everything. Collection, for digital evidence, has become almost trivial — a technician images a drive in an afternoon, and at that moment nobody has really looked at anything. The looking comes later, and it can continue repeatedly: the government holds the complete copy and examines it at leisure, with tools that can read every file, index every message, reconstruct a timeline, map every contact, surface every photo. That examination is the invasion. That is the moment your life is fully exposed to the state. And it happens in a stage the law does not regulate.
Sit with the consequence, because it’s the thesis of this section. Our entire framework of Fourth Amendment protection is clustered at collection — the warrant, probable cause, particularity. But for digital evidence the real intrusion has migrated downstream to analysis, where we have almost no rules at all. We are guarding the front door long after the valuables have moved to a room with no lock. A regime that protects collection and ignores analysis is protecting the moment that no longer matters most.
The scale of the intrusion is the other half of it, and it’s worth being concrete. A Title III wiretap in 1970 captured a finite set of calls over thirty days, minimized in real time by an agent obligated to stop listening/recording when a call was not evidence of the crime. The scarcity did real work: there were only so many calls, and a human had to attend to each one. A modern forensic image is the opposite in every dimension — it is a person’s entire integrated life, acquired in a single unminimized act, then handed to software that can examine all of it, tirelessly, forever with perfect fidelity. The safeguard that scarcity used to provide is simply gone, and nothing has replaced it, because the replacement would have to live in the analysis stage, and the analysis stage is unwritten.
So § 5 of the model act governs the examination itself. It codifies ‘reasonableness’ into digital search and seizure. Five things it must do.
First, scope-of-search limits. Possessing the whole image is not permission to examine the whole image. The analysis must stay within the scope the warrant authorized — you may look for the evidence you had probable cause to seek, not roam the entire drive because it happens to be in the room. This is the § 4 particularity fight following the data into the lab: particularity that meant something at collection necessarily keeps meaning something at analysis.
Second, search protocols. For comprehensive images, the government should have to articulate, in advance, how it will conduct the examination — what it will search, in what order, with what filters — so that “we looked at everything” isn’t the default method. Courts have already experimented with exactly this; the Ninth Circuit’s search-protocol approach is the well-known attempt, and it’ll get its own post. Section 5 makes the protocol a requirement rather than an occasional judicial improvisation.
Third, plain view. In the physical world, plain view is bounded — an officer lawfully in your living room can seize contraband he happens to see, but he can’t open every drawer without probable cause. In a forensic image, everything is technically in plain view, because to search any of it the tools traverse all of it. Left unmodified, the plain-view doctrine swallows the warrant whole: image a phone for drug evidence, “plainly view” everything else, and the particularized warrant becomes a general search. Some courts have already tried to draw the line. In the Tenth Circuit’s United States v. Loera, agents searching a computer for evidence of hacking came upon child pornography; the court held they could keep searching, but only so long as the search stayed directed at the evidence the warrant named — and that the moment an agent instead steered the search toward the unrelated child pornography, it became a new and unreasonable search that plain view would not excuse. That “directed-at-scope” test is quietly radical. The Supreme Court’s Horton v. California eliminated any requirement that a plain-view discovery be inadvertent; yet the Tenth Circuit’s digital cases effectively smuggle inadvertence back in, because in a forensic image the difference between stumbling onto evidence and steering toward it is very nearly the only thing left standing between a particular warrant and a general one. Section 5 should make that distinction a rule rather than a regional experiment — narrowing plain view for digital analysis, or the whole structure leaks out through it. (What may then be used from a genuinely incidental discovery is a § 7 question — the second-warrant problem — and I’ll take it up there.)
Fourth, and I’m going to flag this one and keep walking, automated examination. The hardest version of every question above is what happens when the examiner isn’t a person but a model — when the government runs AI across the entire image to decide what’s responsive. Is a machine reading your whole drive a “search” at all? If the answer is no, automated analysis could become the mechanism that examines everything while the law pretends nothing was examined. If the answer is yes, the same tools could enforce the limits, surfacing only what’s responsive and keeping the rest from human eyes. That question is sharp enough and consequential enough that it gets its own post later in this section’s run. For now: § 5 has to define automated examination as a regulated act and refuse to let “no human looked” become “no search occurred.”
Fifth, re-search. The government should not be able to return to a lawfully held image and examine it again, for a new purpose, without fresh authorization. Loera shows the problem in miniature: a week after the initial search, an agent reopened the files he knew held child pornography — this time to describe the images in an application for a new warrant — and the court treated that reopening as its own search, directed at evidence the original warrant never authorized. A copy the government already holds is not a standing license to look again whenever a new purpose arises; each fresh examination is a fresh search. (Tellingly, the court found that reopening unreasonable and let the evidence stand anyway — a preview of Thursday, where the line gets drawn and the remedy quietly evaporates.) This is the hinge that connects analysis to retention and use, and it’s the exact practice Thursday’s case is about.
Now the objection, and it’s the load-bearing one. Once the government has lawfully seized and imaged the data, the government will say, examining it is not a separate “search” that needs separate rules — the warrant that authorized taking the drive authorized searching its contents, and layering protocols and scope limits and re-search warrants on top is unworkable micromanagement of investigative judgment. Forensics requires broad examination to find what’s responsive; you cannot know what matters until you’ve looked.
Here is why that’s wrong, and it’s the same flaw I keep pointing at. The claim that “seizing the drive authorized searching all of its contents” is the general warrant reasserting itself in new clothes. The warrant authorized a search for particular evidence of a specified crime. It did not authorize unlimited examination of everything the drive contains, any more than a warrant to search a house for a stolen car authorizes reading the homeowner’s diaries. When the intrusion has moved to analysis, saying “analysis needs no rules because possession was lawful” is saying the search needs no rules at all — it just relocates the lawlessness one step downstream from where we’re all looking. And the workability worry is answered the way § 4 answered it: concede that the government may examine broadly enough to find what’s responsive, then require that the examination stay scoped, follow a protocol, respect a narrowed plain view, and stop at the edge of its authorized purpose. Lawful possession of the image is not a license to do everything the government chooses to do with it. That principle has a name in this project — separate the act from the permission — and analysis is where it matters most, because analysis is where the search now lives.
Next Tuesday, § 6: copying and retention — how the government came to hold that complete image in the first place, and how long it gets to keep it. And Thursday, the case that put every question in this post in front of a federal appeals court a decade ago — and the dodge that left them all unanswered.
(Model statutory text for § 5 comes in Pass 2 this fall. This post is the why; the drafting is next.)
Leave a comment