07/21/2026 | Press release | Distributed by Public on 07/21/2026 23:30
By Anton van Seventer, Counsel for Privacy and Data Policy, Software & Information Industry Association (SIIA)
Section 702 of the Foreign Intelligence Surveillance Act has now been lapsed for a month, and the standoff that produced the lapse has had almost nothing to do with surveillance policy. The statute expired after the House rejected a short-term extension, but what has kept it expired is a vacancy at the top of the intelligence community. The Senate Select Committee on Intelligence has now scheduled a confirmation hearing on July 15 for Jay Clayton, the nominee for Director of National Intelligence, and Republican leadership treats that hearing as the procedural key to getting reauthorization back on the floor.
When it gets there, the reform demands will be waiting. The lapse itself changed little in operational terms: the surveillance Section 702 authorizes continues under annual certifications the Foreign Intelligence Surveillance Court approved in March 2026, which runs through roughly March 2027 whether or not the statute is on the books. What is actually being contested is which reforms get attached to the eventual reauthorization - and near the top of that list sits a phrase that is doing an enormous amount of work in this debate: the "data broker loophole." A coalition of more than 130 organizations has urged Congress not to reauthorize Section 702 without closing it, the leading bipartisan reform bills are drafted around it, and entire advocacy campaigns are organized under its banner. Must-pass legislation is precisely when long-stalled reforms become attachable, and the reform coalition knows it.
The term purports to describe a now familiar practice. Federal law enforcement and immigration agencies purchase Americans' location and web browsing records from commercial sources rather than compelling their production through legal process. Because the same data, the argument runs, would require a warrant if the government demanded it, buying it is an end run around the Fourth Amendment. The Fourth Amendment Is Not For Sale Act, which the House passed in 2024, would have barred those purchases outright. That bill stalled in the Senate, but its approach survives in the reform bills now on offer and in the coalition's insistence that a version of it be folded into any Section 702 reauthorization.
It has been an effective slogan. It is also a conclusion dressed up as a description - and it aims policy at the wrong target.
A "loophole" describes an unintended gap in a rule. But the Fourth Amendment has generally never been held to reach the government's acquisition of information that is lawfully available in the commercial market. The Amendment is triggered by a search or a seizure, specifically one by government compulsion. When an agency buys a data set on the open market, on the same terms available to any other purchaser, there is no compelled production, no trespass, and no coercion of the kind the Amendment governs.
The third-party doctrine, articulated in Smith v. Maryland and United States v. Miller, further holds that information a person voluntarily conveys to a third party generally carries no reasonable expectation of privacy. The Supreme Court's 2018 decision in Carpenter v. United States did carve out a narrow exception for compelled historical cell site location records, but the Court was explicit that its holding was narrow, specifically declined to disturb the third-party doctrine, and said nothing about commercial purchase. To call commercial acquisition an "end run" around a warrant requirement, then, is to assume a warrant requirement the law has simply not established.
None of this is to say the underlying concern is frivolous - it is not. A declassified June 2023 report from the Director of National Intelligence's senior advisory group confirmed that the intelligence community acquires substantial volumes of commercially available information, including sensitive location data. Precise location traces over time can reveal the intimate patterns of a person's life - the very concern that animated Carpenter. That is a real problem, one that requires a sophisticated policy solution.
A categorical ban on government acquisition is the wrong instrument, because it regulates the wrong thing. As SIIA argued in its white paper on data practices, the right axis for regulation is use and risk - not the act of acquisition, and not the underlying data. The same commercial information that could be misused for warrantless tracking is also indispensable to functions few would want to lose: identity verification and fraud prevention, AML and sanctions screening, anti-trafficking and counter-narcotics investigations, locating victims and witnesses, child support enforcement, and detecting fraud in public benefits programs. Yet a purchase ban does not distinguish the agency tracking a particular phone from the one verifying an identity or screening for benefits fraud. Instead, it sweeps all of it into a single prohibition keyed to where the data came from instead of what the government does with it. As the white paper put it, there is no free lunch: cutting off law-enforcement access to this information would raise privacy in the abstract, but at the cost of criminals who escape.
The better lever is the one the debate is actually about. Use limits, minimization, transparency, oversight, and audits are the tools suited to the problem, and both Congress and the executive branch have already begun to build them. The Protecting Americans' Data from Foreign Adversaries Act, for example, targeted a specific, dangerous use - making sensitive data available to hostile foreign governments - rather than banning a category of commerce. Similarly, the ODNI's 2024 Policy Framework for Commercially Available Information sets standards for how intelligence agencies access, handle, and safeguard sensitive commercial data.
The contested questions are about handling and use: when sustained tracking of an identified American should require a warrant, what minimization and deletion rules should apply, how long data may be retained, and who audits compliance. Those are governance questions, and Congress can answer them without a blanket acquisition ban that pulls the rug out from under the beneficial uses along with the troubling ones. Congress, to be fair, already knows how to legislate this way - so while critics fault the ODNI framework for not prohibiting sensitive purchases and retention outright, we view its nuance as a feature, not a bug.
There is also a genuine legal dimension the courts have spoken on that the loophole framing ignores. Much of what these companies compile is lawfully obtained, publicly available information, and the creation and dissemination of information is protected speech under Sorrell v. IMS Health and Bartnicki v. Vopper. A regime that treats lawfully acquired information as off-limits because the government might buy it risks reclassifying constitutionally protected information itself as something close to contraband. The more sound legal approach distinguishes among kinds of data and kinds of use: public domain information, which receives the strongest protection; commercially available information, where a genuine debate about particular uses can and should be had; and highly sensitive data, where heightened policy scrutiny is warranted.
The phrase "data broker loophole" has been effective precisely because it compresses an untested constitutional theory, a sweeping policy prescription, and a caricature of an entire industry into three words. The questions underneath it are serious, and they deserve Congress's attention. But none of these questions is answered by a categorical ban on acquisition, nor are they well served by a label that assumes its own conclusion. The answer, as has been the case historically, is to regulate the use, not the marketplace.