TL;DR
- Section 702 lets the NSA collect emails and calls of foreign targets overseas and warrantlessly sweep in every American who communicates with them. The FBI ran 3.4 million such searches on Americans in 2021 alone: no warrant for any of them.
- The 2024 RISAA reauthorization expanded the law dramatically (anyone with physical access to internet infrastructure) data center workers, maintenance crews, commercial landlords: can now be compelled to assist surveillance. Newsrooms got no exemption.
- A parallel system runs with no statutory basis at all: federal agencies buy your location history, browsing data, and movement patterns from commercial data brokers. Their legal theory is that buying data is not a constitutional "search." No court has fully agreed or disagreed.
- On June 5, 2026, the Senate failed 47-52 to advance reauthorization. Section 702 expires June 12. But a secret FISC certification obtained by the Trump administration in March 2026 means surveillance almost certainly continues until March 2027 no matter what Congress does.
- One federal court ruled in January 2025 that backdoor searches require a warrant (Hasbajrami). Congress has not acted. The data broker loophole has never been ruled on by any court. Both systems are fully operational today.
Why This Guide Exists
We have covered the pieces separately: the June 12 deadline, the Wyden-Lee Government Surveillance Reform Act, the data broker purchase system, and the basics of what Section 702 actually says. But covering them separately misses what matters most.
Section 702 and the commercial data broker purchase system are not two separate privacy concerns. They are two channels of the same warrantless surveillance architecture. Section 702 gives agencies the content of your communications (what you said, what you wrote) when one party is a foreign target. Commercial data broker purchases give agencies your physical location history, movement patterns, and device associations. Put them together and you get comprehensive dossiers on any American who communicates internationally. No warrant for either channel. No judicial oversight for either channel.
This guide is the connective tissue. It is long and sourced. Use the headings to navigate.
The Timeline: How We Got Here
Start in 2008. Congress passes the FISA Amendments Act, enacting Section 702. The law authorizes the NSA to collect communications of foreign nationals located outside the U.S. (without individual warrants) when the government believes those foreigners possess foreign intelligence information. The NSA runs two programs: PRISM (collecting from U.S. tech companies including Google, Apple, Microsoft, and Facebook) and Upstream (intercepting data directly from fiber-optic cables). When Americans communicate with designated foreign targets, Americans' communications are swept up too. The government calls this "incidental collection." The EFF notes it is structural, not accidental [1].
2013: Edward Snowden reveals PRISM and Upstream exist. The public learns the scope. Congress does not act to add warrant requirements.
2018: The Supreme Court decides Carpenter v. United States, 585 U.S. 296, holding 5-4 that the Third-Party Doctrine does not apply mechanically to digital location data. Chief Justice Roberts writes that cell-site location information is not "voluntarily" shared in any meaningful sense, enables near-perfect surveillance of past movements, and requires a warrant for seven or more days of records [2]. Agencies immediately begin constructing arguments for why the ruling is narrow. Those arguments become the legal foundation for the data broker loophole.
April 20, 2024 (President Biden signs RISAA into law, reauthorizing Section 702 for exactly two years) expiring April 20, 2026. The reauthorization does not merely extend the law. It expands it. The details matter and are covered in the next section.
January 21, 2025: A federal district court rules in United States v. Hasbajrami that backdoor searches of 702 databases "ordinarily require a warrant" [3]. First time any court has said this directly. The practice continues.
April 20, 2026: Section 702 expires as scheduled. Congress scrambles. A 10-day extension buys time. The House passes a 3-year reauthorization bill on April 29 containing a Federal Reserve CBDC ban rider: immediately declared dead in the Senate. A 45-day clean extension passes April 30, extending the deadline to June 12, 2026. Senator Ron Wyden secures a side commitment to declassify a secret FISC opinion within 15 days [4].
June 5, 2026: The Senate holds a cloture vote on advancing reauthorization. It fails 47-52. Section 702 expires in seven days. No deal is in sight.
What RISAA 2024 Actually Did: The Expansion Nobody Covered Adequately
Every outlet called RISAA a "reauthorization." That word does real work obscuring what happened.
RISAA expanded Section 702 in three distinct ways, none of which were in the original 2008 law.
The Provider Expansion: Landlords, Janitors, and the "Spy Draft"
The original law authorized the government to compel "electronic communications service providers" (telecoms and ISPs) to assist surveillance. RISAA rewrote that definition. The law dropped the word "communication" and added "custodian," producing a new category: any entity with physical "access to equipment that is being or may be used to transmit or store wire or electronic communications."
The practical reach of this language is enormous. Per EPIC's filing with the FISC, it explicitly covers "data centers and buildings owned by commercial landlords, who merely have access to communications equipment in their physical space" [5]. ZwillGen, a technology law firm, warned it could cover "colocation providers, business landlords, shared workspaces, or even hotels where guests connect to the Internet, and the addition of the term 'custodian' could be understood to sweep in any third party involved in providing equipment, storage, or even cleaning services to such entities" [6].
Seth Stern of the Freedom of the Press Foundation called it a "spy draft" [7]. The IT Industry Council warned that "any company, vendor, or any of their employees who touch the physical infrastructure of the internet could now be swept under FISA's scope" [8].
Hotels, restaurants, and dwellings were eventually carved out after protest. Newsrooms were not. There is no explicit exemption protecting media organizations from being compelled to install surveillance infrastructure.
The expansion responded directly to a 2023 FISC Court of Review ruling that had blocked the government from compelling an unnamed company (reportedly a data center) to provide surveillance assistance. RISAA nullified that ruling by expanding the statutory definition past it.
After RISAA passed, the Intelligence Authorization Act for FY 2025 attempted to narrow the ECSP definition. The scope of that narrowing is classified [9].
Two New Surveillance Purposes
RISAA added "counternarcotics" as a permitted basis for Section 702 surveillance: enabling targeting of drug production, distribution, and financing networks. It also authorized use of 702-collected data to vet immigrants and asylum seekers. Neither power existed in the original 2008 law [10].
The Warrant Vote That Failed by One Vote
On April 12, 2024, the House voted on the Biggs amendment: sponsored by Rep. Andy Biggs (R-AZ): which would have required federal agents to obtain a warrant before searching Americans' communications in the 702 database, with carve-outs for imminent threats, consent, and known cyberattacks.
The vote: 212 yes, 212 no. In the House, a tie is a defeat. The amendment failed by a single vote [11].
Vote breakdown: 128 Republicans and 84 Democrats voted yes. 86 Republicans and 126 Democrats voted no. The morning of the vote, Attorney General Merrick Garland and National Security Adviser Jake Sullivan personally called lawmakers urging them to kill the amendment [12].
Rep. Bob Good (R-VA, Freedom Caucus Chair) spoke after: "a sad day when we can't get all Republicans to vote to protect Americans' constitutional liberties." The full RISAA bill then passed 273-147 [13].
Senator Ron Wyden called RISAA "one of the most dramatic and terrifying expansions of government surveillance authority in history" [14]. The EFF, CDT, ACLU, and EPIC all assessed it as leaving Americans worse off than before reauthorization [15].
How Section 702 Actually Works: For Ordinary People
The Incidental Collection Pipeline
Here is the concrete sequence. You email a colleague in Germany. You text a relative in Turkey. You call a contact in Egypt. If the NSA has secretly designated any of those overseas individuals as a Section 702 "target" (and the list of targets is classified; you have no way of knowing) both sides of your communication are collected and stored in a searchable government database. You were never suspected of anything. You were never targeted. No judge ever approved access to your communication. But it is now in the database, searchable by any of thousands of analysts.
PRISM collects from U.S. technology companies: Google, Apple, Microsoft, Facebook. Upstream intercepts directly from fiber-optic cables as data transits the internet. Both channels feed the same databases.
The Backdoor Search
Once your communication is in the database, the FBI, CIA, NSA, and National Counterterrorism Center can query it. An analyst types your name, email address, phone number, or Social Security number. This is called a "backdoor search" or "U.S. person query." The front door was 702 collection: targeting the foreigner. The back door is searching the American communications that were swept in along with the foreigner's.
No warrant. No notice to you. No judicial oversight of that specific search event. The FISC approved the overall 702 certification annually, but it does not review individual queries against Americans.
Minimization: What the Law Requires and What Actually Happens
On paper: five-year default retention limit for U.S. person data, documented justification required for each U.S. person query, supervisory approval, annual FISC certification of all procedures, prohibition on using 702 to deliberately target Americans.
In practice (data that has been "reviewed" can be retained 10-15 years or longer under FBI procedures) inverting the retention limit's purpose. The FBI used a querying tool that allowed agents to access Americans' 702 communications without triggering the approval, documentation, or audit requirements. This operated from an unknown start date until early 2025 [16]. The FISA Court found in March 2026 that the problem persisted and extended beyond the FBI to other intelligence agencies [17]. The FBI's Office of Internal Auditing (created August 2020 specifically to catch these violations) was dismantled by the Trump administration after January 2025 [18].
Who Actually Gets Caught: Documented Cases
These are not hypotheticals. Every case below comes from declassified FISC opinions (May and July 2023), congressional testimony, or official government disclosures.
Rep. Darin LaHood (R-IL). In March 2023, LaHood publicly identified himself at a House Intelligence Committee hearing as the member of Congress queried "multiple times solely by his name" in Section 702 databases without adequate justification. DOJ reviewers deemed the searches "overly broad." LaHood then led the House working group on FISA reform [19].
An unnamed U.S. senator and a state senator. Both were queried "without further limitation": meaning the analyst typed only their names with no additional search terms. The U.S. senator was notified. The state senator was not. Neither has been publicly identified [20].
A state judge. An FBI analyst queried a sitting state judge using their Social Security number, after that judge had filed complaints about alleged civil rights violations by a municipal police chief. The FISC found the search lacked adequate justification and required pre-approval that was never obtained [20].
19,000 political donors. An FBI analyst ran a single batch query on over 19,000 donors to an unnamed congressional campaign, claiming foreign influence concerns. DOJ reviewers found only 8 of the 19,000 identifiers had any plausible foreign ties. The campaign's identity has never been disclosed [21].
133 people arrested during George Floyd protests. All queried in Section 702 databases in late May 2020, without specific connections to terrorist-related activity. The FBI initially defended these searches, then reversed that position [22].
Over 20,000 people connected to January 6. Queries run on individuals affiliated with the January 6, 2021 Capitol attack. DOJ later determined these searches "were not likely to find foreign intelligence information or evidence of a crime." The FBI attributed it to "confusion among the workforce" [22].
Between 2020 and early 2022, FBI personnel conducted more than 278,000 Section 702 searches that did not meet legal standards. The FISA Court characterized this as "persistent and widespread violations" [23].
The other documented categories where 702 was misused: women found on dating apps, rental property tenants, an FBI employee's family members, journalists, political commentators, and U.S. government officials: all queried without the required foreign intelligence nexus [22].
The Scale Problem and the Unknown True Number
FBI query volumes by year:
- 2021: 3,394,053 queries (disclosed by ODNI in April 2022) [24]
- 2022: ~204,090 queries (after opt-in reforms changed the accounting mechanism)
- 2023: 57,094 queries
- 2024 (5,518 queries) but this figure is known to be incomplete
- 2025 (7,413 queries (a 35% rise from 2024)) also incomplete [25]
The 2024 and 2025 figures are incomplete because the undisclosed querying tool was bypassing the counting mechanism. The actual totals for those years are genuinely unknown. No estimate of how many Americans' communications are actually stored in the database has ever been published. The Privacy and Civil Liberties Oversight Board has recommended the government publish such estimates. The government has refused [26].
The Second System: Commercial Data Broker Purchases
This section covers the mechanism and key contracts. Our standalone data broker explainer goes deeper on the full supply chain. The point here is how this system combines with 702: that combination is what neither piece explains on its own.
How It Works and Why It Is (Currently) Legal
Federal agencies purchase location data, browsing history, and communications metadata from commercial data brokers: without obtaining a warrant. The legal argument has three parts ((1) The Fourth Amendment restricts government "compulsion" of data, not market participation) so buying is not the same as demanding; (2) data brokers are private parties, so their collection is not "state action"; (3) when the government purchases already-collected data from a private entity, it is not conducting a constitutional "search." This bypasses both the warrant requirement and the Electronic Communications Privacy Act, which covers telecoms and ISPs but not data brokers [27].
The contracts are real and the dollar figures are documented:
- FBI: Up to $27 million with Babel Street for 5,000 Locate X licenses; $22,000 for a Venntel portal license [28]
- DHS/CBP: Over $2 million with Venntel (2019-2020); approximately $3 million Babel Street renewal (2020) [29]
- Secret Service: Over $600,000 for a 12-month Babel Street contract (2019) [29]
- DEA: $25,000 Venntel license
- CDC: $420,000 for COVID-19 movement tracking
- Defense Intelligence Agency: Acknowledged in a January 2021 internal memo that it purchases "commercially available geolocation metadata aggregated from smartphones" and does not require judicial warrants for such purchases [30]
- Palantir: $30 million ImmigrationOS contract with ICE (April 2025); $145 million+ for the underlying ICM system; a $1 billion DHS-wide AI analytics contract (February 2026) [31]
Babel Street's Locate X product lets an analyst draw a digital geofence around any address, identify every device present during any time window, and then view where each of those devices traveled in prior months. Venntel, its underlying data source, claims access to signals from over 150 million devices via more than 80,000 apps [28].
Carpenter and the Loophole It Created
Carpenter v. United States (2018) was supposed to limit this. It did not. The moment the ruling came down, agencies constructed an argument: Carpenter covers only cell-site location information (CSLI) from carriers, not mobile advertising ID (MAID/AdID)-based data from apps. Carpenter restricts compelled disclosure from carriers, not voluntary commercial sales. Purchasing from a private broker involves no "search." An ICE internal memo explicitly argued AdID-linked data differs from CSLI and is outside Carpenter's scope [27].
Columbia Law Review calls this "laundering data": using the commercial market as a conduit to receive constitutionally protected information without a judge approving it [32]. Yale Law and Policy Review identifies it as an open constitutional question [33]. As of June 5, 2026, no federal court has ruled definitively that purchasing location data from a commercial broker constitutes a Fourth Amendment search. The question is unresolved at every appellate level.
How the Two Systems Combine: The Architecture Nobody Draws Together
Section 702 gives agencies the content of communications. Commercial data broker purchases give agencies physical movement and association data. The combination enables something neither system provides alone.
Walk through the operational sequence. The NSA designates a foreign national as a 702 target. Americans who communicate with that target have both sides of their communications collected and stored. The FBI identifies those Americans through backdoor searches: no warrant. The FBI then turns to commercially purchased location data. Using Babel Street's Locate X, analysts draw geofences around locations the Americans visited. They pull months of prior movement history. They identify every other device that was present at those same locations during overlapping time windows. They map social graphs from physical co-presence rather than digital communications. All of this happens without ever returning to a judge.
The result: comprehensive dossiers that combine what you said with where you went and who you met in person. Two warrant-free channels feeding the same analytical systems.
ImmigrationOS as the Integration Exemplar
The Palantir ImmigrationOS system is the current state of the art for this convergence. The April 2025 $30 million ICE contract and the February 2026 $1 billion DHS-wide contract describe a system that integrates passport data, Social Security records, IRS information, HHS data, FBI, DEA, and ATF databases, license plate reader networks, and Thomson Reuters CLEAR (a commercial data broker product) into a single targeting system with "near real-time visibility" [31].
Section 702 authority on top of this infrastructure gives investigators the contents of communications involving anyone ImmigrationOS flags. Commercial data purchases fill in the physical movement history. Elizabeth Goitein of the Brennan Center described the combined picture as "an unprecedented era of government surveillance that dwarfs anything we saw during the era of COINTELPRO" [34].
In 2021, while the FBI was running 3.4 million warrantless queries against 702 databases, federal agencies were simultaneously purchasing location data on Americans from Venntel, Babel Street, and others. These are not bureaucratic silos. They are operationally connected channels feeding the same analytic systems. The question to ask is not whether agencies use them together. The question is how not to do so, given that both channels are warrant-free and both are legally available.
The January 2025 Court Ruling: What It Means and What It Does Not
United States v. Hasbajrami, No. 11-cr-00623-LDH, U.S. District Court for the Eastern District of New York. Judge LaShann DeArcy Hall. Opinion released January 21, 2025.
The facts: Agron Hasbajrami, an Albanian permanent U.S. resident, was arrested at JFK Airport on September 6, 2011. The FBI had searched 702 databases using terms linked to him and found emails he had exchanged with an overseas contact: emails collected without a warrant. Prosecutors used those emails as evidence. He was convicted and sentenced to 16 years.
What the court held (backdoor searches of 702 databases "ordinarily require a warrant." The court treated each database query as a distinct Fourth Amendment search event) separate from the initial collection. Simply possessing communications lawfully collected under 702 does not permit the government to search them later without judicial authorization. The court rejected the government's "foreign intelligence exception" to the warrant requirement, finding the intrusion on privacy caused by reading sensitive private communications "unreasonable" under the Fourth Amendment [3].
What happened to Hasbajrami: the evidence was not suppressed. The good-faith exception applied: law enforcement reasonably relied on FISC-approved procedures as they existed in 2011. His 16-year sentence stands. A Second Circuit appeal is pending.
What this ruling does not do: it does not affect the data broker purchase loophole in any way. It is a district court ruling: not binding appellate precedent. The Second Circuit appeal will determine whether this becomes the controlling law in that circuit. The FBI compliance office that would implement any resulting reforms was dismantled in 2025. Congress has not passed legislation codifying a warrant requirement. FBI agents were still using unauthorized querying tools as of March 2026.
The gap between the ruling and reality: a federal court has declared the practice unconstitutional. The practice continues.
The FISC Certification Loophole: Why "Going Dark" Is a Myth
Every time Section 702 approaches expiration, the intelligence community warns that allowing it to lapse will cause immediate, catastrophic harm to national security. This claim is misleading in a specific and verifiable way.
How FISC Certifications Actually Work
Section 702 surveillance does not operate directly by statute. It operates through annual certifications that the Attorney General and DNI jointly submit to the Foreign Intelligence Surveillance Court, describing targeting procedures and operational rules. The FISC approves these certifications for up to one year under 50 U.S.C. § 1881a(a). On March 17, 2026, the Trump administration obtained a FISC renewal of those certifications for another year [41].
The Transition Provision
The original FISA Amendments Act includes a transition provision stating that "any order, authorization, or directive issued pursuant to Title VII of FISA shall remain in effect until its stated expiration date." Those March 2026 certifications expire in approximately March 2027: nine months after the June 12 statutory deadline [41].
This means that even if Congress allows Section 702 to lapse on June 12, the NSA and other agencies can continue collecting under the March 2026 FISC-approved certifications until March 2027. A statutory lapse would not immediately halt surveillance. The Cato Institute analyzed this directly and concluded the "going dark" alarm is not a factual claim: it is a pressure tactic designed to force Congress into clean extensions without reforms [42].
What a Lapse Would Actually Cause
What a statutory lapse would cause: serious legal uncertainty for communications providers. Those providers face conflicting interpretations of whether pre-expiration directives remain legally binding after the statute lapses. The government's "valid-when-issued" position (that directives issued before expiration remain enforceable regardless of what happens to the statute) is not settled law. Providers who comply with directives of uncertain validity face potential liability. Providers who refuse face potential contempt. That uncertainty is a real problem, even if it is not the "program goes dark" scenario the intelligence community describes [43].
The Wyden-secured commitment to declassify the March 17 FISC opinion within 15 days of the April 30 extension was specifically intended to put this question on the table. That opinion's contents remain classified. The Senate voted on June 5 without seeing it.
What Reform Would Actually Look Like
The Government Surveillance Reform Act (S.4082, introduced March 2026 by Senators Wyden, Lee, Warren, and Lummis, and Representatives Davidson and Lofgren) is the most comprehensive legislative proposal. Our dedicated GSRA analysis covers it in detail. What matters here is the minimum floor that any meaningful reform requires, and what has and has not moved.
The Four Requirements
First: A warrant requirement for querying Americans' communications in 702 databases. The Biggs amendment (failed 212-212, April 2024), the GSRA, and the SAFE Act (Durbin-Lee, introduced February 2026) all address this at varying levels. None has passed.
Second: Prohibition on federal purchase of Americans' data from commercial data brokers without a warrant. The GSRA and the Fourth Amendment Is Not For Sale Act (passed the House 219-199 in April 2024, died in the Senate without a vote) both address this. Neither is law.
Third: Reversal of the RISAA ECSP expansion that turned landlords and maintenance workers into potential surveillance deputies. No current reauthorization proposal moving through Congress includes this.
Fourth: Mandatory public estimates of how many Americans' communications are in 702 databases. The PCLOB has recommended this. The government has refused. No pending bill would require it.
What Has Passed
The warrant amendment failed by one vote in April 2024. The Fourth Amendment Is Not For Sale Act passed the House but died in the Senate. Montana enacted a state-level data broker loophole closure unanimously in May 2025: the only jurisdiction to do so [44]. The GSRA has not passed. No reauthorization proposal moving through Congress in 2026 includes a warrant requirement or closes the data broker loophole.
The Coalition Math
The civil liberties left and the civil liberties right can block reauthorization. They cannot currently build 60 Senate votes for reform. Democrats will not provide cloture votes while Pulte is acting DNI. Seven Republicans will not vote yes without a warrant requirement. The administration will not accept a warrant requirement. The CBDC rider destroyed the one vehicle with 235 House votes. Ten days remain before the June 12 deadline with no clear path.
What You Can Actually Do: Concrete Steps
Reduce Your Section 702 Exposure
Use end-to-end encrypted messaging (Signal is the best-documented option) for sensitive communications. Upstream collection intercepts data from fiber-optic cables; PRISM collects from tech company servers. End-to-end encryption means content cannot be read even if intercepted or collected. Be aware that metadata (who you communicated with, when, how often) is not protected by E2E encryption and may still be swept in.
A VPN shifts trust to the VPN provider. It does not prevent 702 collection if you are communicating with a person the NSA has designated as a foreign target.
Reduce Your Data Broker Exposure
Limit app location permissions to "while using" or deny them outright. On iOS: Settings > Privacy & Security > Tracking, then disable "Allow Apps to Request to Track." On Android, the path is similar under Privacy settings. This reduces (but does not eliminate) data flowing to the SDK ecosystem that feeds brokers like Venntel and Gravy Analytics.
Venntel claims signals from over 80,000 apps. Comprehensive opt-out is not realistically achievable for individual consumers. This is the policy failure: the problem cannot be solved at the individual level, which is precisely why legislative prohibition matters.
Engage the Political Process Now
The June 12 deadline and the June 5 failed vote of 47-52 mean the next attempt is within days. Calls to Senate offices on the warrant requirement are relevant to a live vote, not an abstract future issue.
The specific ask is clear: a warrant requirement for querying Americans' 702 data, and prohibition on warrantless data broker purchases. The GSRA (S.4082) and the Fourth Amendment Is Not For Sale Act are the specific bills.
Mike Lee's position ("No warrant to protect Americans? No FISA") is available to both parties. Seven Republican senators used it on June 5. It is a politically viable frame that does not require any particular ideology to accept. The obstacle is not public support for reform. It is the administration's resistance and the intelligence community's procedural leverage over deadline-driven reauthorization fights.
The Bottom Line
Two surveillance systems operate in parallel. Section 702 gives agencies the content of your communications when you talk to anyone abroad who is secretly designated a target. Commercial data broker purchases give agencies your physical movements and associations with no warrant and no content required. Together they enable comprehensive dossiers (what you said plus where you went plus who you met) on any American who communicates internationally.
One court has said the first system requires a warrant (Hasbajrami, January 2025). Congress has not acted. No court has ruled on the second. Both systems are fully operational as of June 5, 2026.
The "going dark" framing that the intelligence community deploys at every reauthorization deadline is a manipulation. The March 17, 2026 FISC certification means surveillance continues until March 2027 even if the statute lapses on June 12. The "going dark" alarm has never been accompanied by any public disclosure of what would actually go dark, when, and why the existing FISC certification does not cover it. It is a pressure tactic, not a factual claim.
The warrant amendment failed by one vote in April 2024. Seven Republican senators voted no on June 5, 2026 specifically because there is no warrant requirement. The political coalition for reform exists. It simply cannot yet overcome the administration's resistance and the intelligence community's leverage over deadline-driven fights. The next few days will determine whether that changes: or whether Congress passes another clean extension that kicks the same fight to the next deadline.
References
- EFF ("Decoding 702) What is Section 702?" (2024). structural incidental collection explanation
- Carpenter v. United States, 585 U.S. 296 (2018). Supreme Court ruling on CSLI and the Third-Party Doctrine
- EFF ("Victory) Federal Court Finally Rules Backdoor Searches of 702 Data Unconstitutional" (January 22, 2025). Hasbajrami ruling analysis
- Nextgov/FCW: "House passes 45-day FISA extension after senators secure declassification deal" (April 30, 2026)
- EPIC: FISC amicus filing on RISAA ECSP expansion language (April 2024)
- ZwillGen: "House Intelligence Committee FISA Reform Bill Would Greatly Expand Class of Businesses Required to Assist in FISA 702 Surveillance" (April 2024)
- Reason: "How the FISA reauthorization bill could force maintenance workers and custodians to become government spies" (April 19, 2024)
- IT Industry Council: "Expansion of FISA ECSP Definition Must Be Removed" (April 2024)
- Restore the Fourth: "Scope of FISA Sec. 702 ECSP Provision Narrowed But Remains Classified" (July 2024)
- EFF ("NSA Surveillance and Section 702 of FISA) 2024 in Review" (November 2024)
- Roll Call: "House approves surveillance authority reauthorization bill" (April 12, 2024). 212-212 vote breakdown
- NBC News: "House votes to renew FISA spying tool after earlier Republican revolt" (April 12, 2024). Garland and Sullivan lobbying
- H.R. 7888: Reforming Intelligence and Securing America Act, Congress.gov (signed April 20, 2024)
- CDT: "With the Passage of RISAA, FISA 702 Reform Has Been Delayed But Not Denied" (April 22, 2024)
- EFF: "U.S. Senate and Biden Administration Shamefully Renew and Expand FISA Section 702" (April 2024)
- Brennan Center: "The Truth Behind Section 702 Query Statistics" (2026)
- Brennan Center ("Section 702 of FISA) 2026 Resource Page"
- ACLU: "Court Rules Warrantless Section 702 Searches Violated the Fourth Amendment" (January 22, 2025)
- Washington Post: "Republican Congressman Darin LaHood says his name was wrongly searched by FBI" (March 9, 2023)
- Just Security: "Court Says Warrant Needed for U.S. Person Queries of FISA Section 702 Data" (January 2025). FISC opinions summary
- Brennan Center: "Section 702 of the Foreign Intelligence Surveillance Act" (2024). 19,000 donors case
- Wikipedia: "FBI Section 702 query violations" (sourced from FISC opinions and ODNI reports)
- Cato Institute: "Federal Court Rules FISA Section 702 Back Door Searches Unconstitutional" (January 2025)
- Reason: "The FBI Secretly Searched Americans' Digital Communications 3.4 Million Times Last Year" (May 2, 2022)
- Nextgov/FCW: "FBI queries of Americans' data under FISA 702 rose 35% in 2025" (March 2026)
- Brennan Center: "The Truth Behind Section 702 Query Statistics" (2026). missing data and PCLOB recommendations
- ACLU: "DHS Is Circumventing Constitution by Buying Data It Would Normally Need a Warrant to Access" (2022)
- EFF: "How the Federal Government Buys Our Cell Phone Location Data" (2022). contract figures for Babel Street and Venntel
- ACLU: "New Records Detail DHS Purchase and Use of Vast Quantities of Cell Phone Location Data" (2022)
- Criminal Legal News: "Federal Government Circumventing Fourth Amendment by Buying Data From Data Brokers" (April 2025). DIA January 2021 memo
- ACLU: "All the Ways Palantir is Assisting Trump's Abusive Removal Campaign" (2025-2026)
- Columbia Law Review ("Laundering Data) How the Government's Purchase of Commercial Location Data Violates Carpenter and Evades the Fourth Amendment"
- Yale Law and Policy Review ("End-Running Warrants) Purchasing Data Under the Fourth Amendment and the State Action Problem"
- Brennan Center: "Closing the Data Broker Loophole" (2022). Goitein quote on COINTELPRO comparison
- EFF ("Keep Pushing) We Get 10 More Days to Reform Section 702" (April 17, 2026)
- The Hill: "House conservatives reject Senate's FISA extension plan over CBDC ban" (April 2026)
- The Hill: "Senate Democrats block extension of FISA 702 spy powers to protest Pulte as DNI" (June 5, 2026)
- Punchbowl News: "Dems threaten FISA over Pulte" (June 2026)
- CBS News: "Senate fails to extend FISA surveillance program as deadline nears, with 7 Republicans joining Democrats" (June 5, 2026)
- The Hill: "Six GOP senators join Democrats to block extension of warrantless spy powers" (June 5, 2026)
- Wiley Law: "Congress Again Approaches Deadline for Extending FISA 702 Authorities, Creating Uncertainty for Communications Providers" (2026)
- Cato at Liberty: "The FISA Section 702 Lapse 'Going Dark' Myth" (2026)
- Wiley Law: "Congress Again Approaches Deadline for Extending FISA 702 Authorities" (2026). provider legal uncertainty analysis
- Reason: "New Montana Law Blocks the State from Buying Private Data to Skirt the Fourth Amendment" (May 2025)