For six weeks I’ve been building limits on what the government may collect, how it may analyze, and how long it may keep. This week is about the limit that matters when all of those fail — or, more precisely, the limit that keeps working no matter how much the government lawfully ends up holding. It’s the use restriction, and I’ve called § 7 “the idea that ties it all together” since the first post, because it’s the through-line of the whole project and, I think, the single most important provision in the model act.
Here’s the problem it solves. We’ve established that digital collection is comprehensive — the government images the whole drive because it must. We’ve established that analysis traverses everything, because the tools can’t find the responsive files without passing over the rest. And we’ve established that the copy tends to sit, retained and re-searchable. Put those together and you reach an uncomfortable truth: no matter how carefully you write the collection and analysis rules, the government is going to end up holding, and having looked at, a great deal more than the warrant was ever about. The front-end limits leak. Something has to catch what leaks through. That something is a limit on use.
A use restriction says: it does not matter that you lawfully hold this data, or even that you lawfully saw it — you may only use it for the purpose you were authorized to pursue. Stumble onto evidence of a different crime while searching for the one in your warrant, and you don’t get to use it, charge it, or build on it, until you go back to a judge and get fresh authorization. The restriction operates on the output, not the input. And that is exactly why it works where the other limits don’t: you cannot always stop the government from seeing something, but you can absolutely require it to justify using it.
This is not a new idea. It is one of the oldest ideas in the wiretap statute, and § 7 is modeled on it directly. Title III’s § 2517 governs the use and disclosure of what a wiretap captures, and buried in it is § 2517(5), which handles the precise situation I just described. When agents lawfully intercepting communications about one crime overhear evidence of a different crime — one not covered by the wiretap order — § 2517(5) says they may not use that evidence in testimony until a judge, on a later application, confirms the interception was lawful and authorizes the new use. In 1968, Congress looked at the problem of the government stumbling onto evidence of uncharged crimes during a lawful search and answered it with a second trip to the judge. That is the second-warrant requirement, four decades before anyone imaged a hard drive. The model act’s § 7 takes that instinct and makes it the backbone of digital use.
Now let me explain why this ties everything together, because the claim is strong and I want to earn it.
Start with plain view, the doctrine I flagged back in § 5. In the physical world, plain view lets an officer seize contraband he lawfully sees, and it’s bounded by where he’s lawfully allowed to be. In a forensic image, everything is technically “in view,” because the tools traverse all of it — so plain view, unmodified, would let the government use anything it finds, and the particular warrant dissolves into a general one. A use restriction is what replaces the boundary that plain view used to supply. The government may still see what it sees; it simply may not use the out-of-scope discovery without going back to a judge. The limit migrates from what’s visible to what’s usable — which is the only place it can still operate once everything is visible.
Now retention and re-search, from § 6. The whole danger of the retained copy is that the government reaches back into it, later, for a new purpose — Ganias, Richman, the database in Nejad. A use restriction is what makes that reach unlawful without fresh authorization: re-searching retained data for a new crime is a new use, and § 7 requires the government to justify it to a judge first. The retention clock limits how long the copy survives; the use restriction limits what can be done with it while it does. They are two halves of one guard.
And it reaches all the way back to § 1. The thing the Fourth Amendment protects is the content — in whatever form it takes, as I argued last week about copies and transcripts. A use restriction attaches to the content: it governs what may be done with the words, the files, the images, whether they sit in the original, a duplicate, or a transcript. Content is the protected thing; use is the thing done to content. That is why this section is the keystone. Definitions name the content; use restrictions govern its fate.
There’s a fourth use the statute needs to address, and it’s the one the government almost never thinks of as a “use” at all: disclosure to the public. A use restriction that stopped at criminal charging would miss the single largest disclosure pipe the government operates — its own records systems. Because disclosure isn’t only an affirmative act of handing something over. It can be a property of the system the content is placed into. Load a person’s seized data — or a transcript of it, or any derivative — into a records system subject to the Freedom of Information Act, and the government has, by an architectural choice alone, made that content presumptively disclosable to anyone who files a request. Nobody decided to release it. The container decided.
Recall the gap I flagged last week. Title III seals the wiretap recording under a judge’s control — and the FBI’s own policy (DIOG Section 18.7.2.14) goes further still, directing that Title III electronic-surveillance evidence “must not be uploaded into Sentinel,” the Bureau’s central recordkeeping system, with all handling confined to specially trained ELSUR technicians. Sit with that, because it’s the whole argument handed to me by the agency itself: the FBI already has a system-placement rule. It deliberately keeps the wiretap recording out of the general case-file system precisely because of what that system would expose it to. But the rule attaches to the recording — the medium — and not to the content. The transcript of the very same call, carrying the identical words, is routinely uploaded into Sentinel, the exact system the recording is barred from. The FBI walls off the container and waves through the contents. The error this blog keeps naming is written, in so many words, into an agency manual: guard the tape, disclose the transcript.
And automated transcription turns that error from a leak into a flood. When reducing a call to text cost an employee hours, only the pertinent calls ever became transcripts, and only those reached Sentinel — the sheer labor was itself a limit on how much content escaped into the releasable system. Make transcription trivial, as AI now does — one call or ten thousand, if imperfectly — and nothing stands between the entire raw corpus, the innocent and incidental and never-charged alike, and the recordkeeping system the recording was so carefully kept out of. The content escaped into a releasable form, and the system it landed in does the disclosing on its own.
So § 7 forecloses it directly: seized digital property, and content derived from it in any form, may not be placed in a system subject to public-disclosure obligations. It lives in a system walled off from FOIA and its state-law analogs, or the government does not get to keep it in that form at all. In effect it is the FBI’s own ELSUR-out-of-Sentinel rule, corrected — the placement limit moved from the medium to the content, from the cassette to the words recorded on it. The protection follows the content — original, copy, transcript alike — because the content is the only thing that has ever mattered.
So § 7 does four things. It limits use of lawfully-held digital property to the authorized purpose. It requires fresh judicial authorization — the digital § 2517(5) — before the government may use evidence of a different crime discovered incidentally. It requires that same fresh authorization before the government re-searches or re-analyzes retained data for a new purpose. And it forbids placing the content, in any form, into a system that will disclose it to the public. The first three put a judge between the government and a new use; the fourth keeps the content out of the one system that discloses with nobody deciding to at all.
Here’s the strongest objection, and it’s a real one. You cannot unsee evidence of a crime. Once an agent has seen a murder plot, or child-exploitation material, while executing a lawful drug search, telling him he may not “use” it feels artificial and even dangerous — he knows it’s there, and requiring a warrant to act on it could let a serious crime slip away. Plain view exists precisely so that lawfully-discovered evidence isn’t lost to a technicality. And § 2517(5)’s bar is famously low, which cuts the other way too: if the digital version is just as easy to satisfy, is it any real limit at all?
Take the “can’t unsee it” point first, because it contains the answer. The use restriction does not ask anyone to pretend they didn’t see. It asks them to get a judge to sign off before using it — and that judicial checkpoint does something specific and important: it forces the government to show the discovery was genuinely incidental, and not the product of a search that went looking for the new crime under cover of the old warrant. That is the Loera concern in operative form — the difference between stumbling onto evidence and steering toward it. Without a use restriction, nothing stops the government from imaging a phone for drug evidence and “incidentally” combing it for everything else; with one, a judge gets to ask whether the discovery was real. The requirement isn’t there to lose evidence. It’s there to make pretext expensive.
The “criminals escape” fear is answered by making the checkpoint fast, the way § 2517(5) is — you don’t ignore the murder plot, you get quick authorization to act on it, and in a true emergency the Act’s exigency provisions apply. And the “low bar” critique I take as a drafting instruction, not a refutation: § 2517(5) asks too little, so the model act’s version should ask more — not merely that the discovery was lawful, but that it was genuinely incidental, with the burden on the government to show it. A use restriction with teeth is the goal; § 2517(5) is the floor, not the ceiling.
There’s a separate objection aimed at the disclosure piece: FOIA already exempts law-enforcement records — Exemption 7 shields investigative files, Exemption 6 guards personal privacy — so isn’t the danger theoretical? No, and the reasons are structural. A FOIA-subject system runs on a release-unless-exempt default: it puts the burden on the government to correctly invoke an exemption on every request, forever, and an exemption can be waived, misapplied, narrowed by a court, or simply lost to a processing error. The safe state for a person’s most intimate data is not “releasable but usually exempt” — it’s “not in the releasable system at all.” The most relevant shield, Exemption 7(A) for pending proceedings, is temporal: it lapses when the case ends, which is precisely when a never-charged person’s swept-up life should become more protected, not less. And exemptions guard against a wrongful release; they do nothing about the standing exposure of sensitive content sitting in a pipeline built to disclose, one clerk’s redaction away from the public. Content this sensitive should not be one mistake from daylight. The fix isn’t a better exemption. It’s keeping the content out of the pipe.
That’s the section, and it’s the hinge of the whole statute. Collection and analysis and retention rules all try to keep the government from holding too much. Use restrictions accept that it sometimes will, and limit what that overreach can accomplish. If you could enact only one section of this model act, it should be this one — because a use restriction is the rule that still protects you after every other rule has failed.
Next Tuesday, § 8: disposition — the end of the lifecycle, where the content is finally returned, deleted, or kept. And Thursday, the one surveillance statute I am building this model act against rather than from — FISA Section 702 — where the use restriction was moved downstream and the government searches a raw, retained store of Americans’ communications at will. It’s the cautionary example this whole project is designed to prevent.
(Model statutory text for § 7 comes in Pass 2 this fall. This post is the why; the drafting is next.)
Leave a comment