Subsentio Guide to CALEA Compliance
The technology is Subsentio's. The legal review is Subsentio's. The law-enforcement liaison is Subsentio's. What stays with the provider is a short list of procedures and people — and this is the guide to them.
Subsentio Guide to CALEA Compliance
CALEA requires telecommunications service providers to provide technical capabilities to law enforcement agencies in support of lawfully authorized electronic surveillance. It covers traditional carriers as well as providers of facilities-based broadband Internet access and two-way interconnected VoIP. As a Subsentio customer, a provider's CALEA obligations are covered in more ways than one: a technology solution, legal expertise to manage court orders, and liaison with law enforcement — the trio of services that lets a provider comply with the law and protect its customers' privacy.
The provider has a role too. When Subsentio processes a court-ordered intercept, the provider needs to be ready — the right procedures, processes and personnel in place to facilitate a prompt and accurate intercept through the Subsentio solution. This guide walks a customer through the procedures, staffing, policies and responsibilities to establish in advance, and the first rule of all: get the court order to Subsentio the moment it arrives.
The parts that matter to a provider.
The first order of business
On receiving a lawful-intercept order: get it to Subsentio immediately — [email protected], with the Service Provider Authorization form.
Procedures and personnel
Who receives an order, who authorizes the provider's side of it, how it is logged, who the 24-hour contact is.
Policies and FCC reporting
The system security and integrity policies 47 CFR Part 1 Subpart Z requires, the senior officer designation, and the records to keep.
Responsibilities that stay with you
What the statute leaves with the carrier even when a Trusted Third Party carries the work — and how to meet it without a legal department.
Does this apply to you?
Subsentio customers first — and any provider deciding what compliance would actually require of its own staff.
Subsentio Guide to CALEA Compliance
Hosted in full by Subsentio. Opens in a new tab.
Other primary documents.
CALEA Act of 1994
What CALEA (1994) requires, section by section — definitions, capability, security, safe harbor, enforcement — with the full text to download.
CALEA Broadband Coverage Order (2005)
The 2005 FCC order that extended CALEA to facilities-based broadband and interconnected VoIP providers — what it decided, why, and what it left open.
CALEA Capability Order (2006)
The 2006 FCC order that set the May 14, 2007 deadline, permitted Trusted Third Parties, required SSI filings and monitoring reports, and settled who pays.
ECPA (1986)
What ECPA did: extended the Wiretap Act to electronic communications and created the Pen Register Act and the Stored Communications Act — the tiers of process.
The Wiretap Act (1968)
The 1968 statute behind every Title III order: a general prohibition on intercepting communications, with a court-supervised exception on probable cause.
FISA (1978)
What FISA authorizes — foreign-intelligence surveillance of foreign powers and their agents under the FISA court — and what a FISA order means for a carrier.