The federal statutes, in order.
Six statutes, passed over forty years, that together decide what a court can authorize, what a provider must produce, and what a network must be able to do. Read in order, they tell one story: the law kept extending; the capability had to keep up.
From the telephone to Section 702.
The federal statutes generally prohibit real-time electronic surveillance as a violation of privacy, and then permit strictly limited exceptions for law enforcement and intelligence investigations. Each statute below either created an exception, extended one to a new technology, or — in CALEA's case — required the network to be able to honor it.
1968 · The Wiretap Act (Title III)
The general rule that communications are private, and the court-supervised exception that lets an agency intercept content on a showing of probable cause. "Title III" orders take their name from it. Read the summary and the full text →
1978 · Foreign Intelligence Surveillance Act (FISA)
Surveillance for foreign-intelligence purposes — foreign powers and their agents — authorized by the FISA court rather than a criminal court. Read the summary and the full text →
1986 · Electronic Communications Privacy Act (ECPA)
Extended the Wiretap Act to electronic communications and added the Pen Register Act and the Stored Communications Act — the tiers of process every records request follows. Read the summary and the full text →
1994 · CALEA
The capability statute: a carrier must be able to execute the orders the other statutes authorize, to an industry standard, without touching anyone else's traffic. Read the summary and the full text →
2001 · USA PATRIOT Act
Amended FISA, the pen-register statute and the Stored Communications Act at once; broadened emergency disclosure and clarified provider protection for good-faith compliance. Read the summary and the full text →
2008 · FISA Amendments Act
Created Section 702 — targeting persons reasonably believed to be outside the United States under directives to providers rather than individual orders. Read the summary and the full text →
Authority, process, capability.
Authority
The Wiretap Act and FISA say who may authorize surveillance and on what showing: a criminal court on probable cause, or the FISA court for foreign intelligence.
Process
ECPA sets the tiers: pen-trap orders for signaling, the Stored Communications Act for records, a warrant for stored content. The PATRIOT Act widened several of them.
Capability
CALEA requires the carrier to be able to execute what the other statutes authorize — to an industry standard, on its own network, without disturbing anyone else's service.
Two other privacy regimes
Section 5 of the FTC Act governs privacy practices through case-by-case enforcement; Section 551 of the Cable Act sets the process for obtaining subscriber data from cable operators.
The statutes, answered.
Which statute authorizes a wiretap?
The Wiretap Act — Title III of the Omnibus Crime Control and Safe Streets Act of 1968, as extended by ECPA in 1986. A criminal court may authorize interception of content on a showing of probable cause. CALEA does not authorize anything; it requires the carrier to be able to execute what Title III authorizes.
What is the difference between a pen register and a wiretap?
A wiretap captures the content of communications. A pen register and trap-and-trace device ("pen-trap") captures only the non-content signaling — the numbers a line calls and the numbers that call it, the routing and addressing of a session — on a certification of relevance rather than probable cause. Federal law permits both.
Where does a subpoena for records fit?
Under the Stored Communications Act, added by ECPA. Stored records are deemed less privacy-sensitive than real-time content, so they can be obtained under lower standards — basic subscriber information on a subpoena, transactional records on a § 2703(d) court order, content on a warrant.
What do the FTC Act and the Cable Act have to do with this?
Section 5 of the FTC Act (15 U.S.C. § 45) is the authority under which the FTC regulates privacy practices through investigations and consent decrees. Section 551 of the Cable Act (47 U.S.C. § 551) establishes the process by which government and non-government entities obtain subscriber data from cable operators — a separate, cable-specific privacy regime a records desk has to know.
What is 47 CFR 1.20000, and what are the FCC's "Part 1" CALEA rules?
The FCC's CALEA regulations live in 47 CFR Part 1, Subpart Z, beginning at § 1.20000 — searched as "FCC 47 CFR 1.20000" or "CFR 47 Part 1", the Commission rules Part 1 that a carrier's SSI filing cites. § 1.20002 defines the terms; § 1.20003 requires the policies and procedures for supervising interceptions and a senior officer reachable 24 hours a day; § 1.20004 requires secure and accurate records of every interception; § 1.20005 requires the policies to be filed with the Commission before commencing service and within 90 days of a change; § 1.20006 restates the assistance-capability duty; § 1.20007 and § 1.20008 cover extensions and enforcement. Since June 2023 the filings go through the CALEA Electronic Filing System.
Where does telecom regulatory compliance for CALEA sit among a carrier's other FCC obligations?
Alongside them, with its own rules. CALEA is one of several telecommunications compliance duties the FCC administers — 911, robocall mitigation, numbering, ownership disclosures — and, since 2023, VoIP providers seeking direct access to numbers certify CALEA compliance in the same filing as those. FCC compliance services for the other obligations — managed compliance telecom providers, regulatory counsel and filing agents — cover those; the CALEA capability, SSI plan and operation are what Subsentio provides.