FISA privacy and oversight

Full Title:
SAFE Act

Summary#

This bill (the SAFE Act) changes parts of the Foreign Intelligence Surveillance Act (FISA). It adds new limits on when intelligence and law enforcement can query or buy data about people in the United States or U.S. persons. It also raises reporting, auditing, and court review requirements and adds new procedures to hold agencies and employees accountable.

  • Limits on queries: FBI must get training, keep written justifications, get extra approvals for sensitive queries (e.g., Members of Congress, judges, batch queries), and log query details. Many queries of U.S. persons or people in the U.S. are barred unless narrowly allowed (warrant/order, consent, exigency, or specific cyber-defense reasons).
  • Audits and reports: DOJ must audit FBI queries every 180 days and give unredacted results to key congressional committees. The Attorney General and DNI must send annual, partly public reports with counts of covered queries, uses of U.S.-person information, and other metrics.
  • Court and oversight changes: The FISA Court must review random samples of targeting decisions. The court’s amicus (outside adviser) role is expanded and given access to more materials and ability to seek further review.
  • Data purchases and provider protections: Intelligence agencies and many law enforcement agencies are limited from buying or acquiring “covered” data about people in the U.S. from data brokers, with listed exceptions. Intermediary and ancillary service providers get limits on voluntary disclosure of contents or subscriber records.
  • Application accuracy and penalties: Government applicants must disclose material information and certify accuracy procedures. New criminal penalties address false statements, material omissions, and unauthorized disclosure of an application.
  • Inspections and compliance: Agency heads must adopt compliance procedures and the DOJ Inspector General must audit FISA compliance every three years.

What it means for you#

  • People in the U.S. and U.S. persons

    • The bill would make it harder for intelligence agencies to acquire or query data about you without a court order, consent, or a narrow emergency exception.
    • If agencies obtain covered data in violation of the rules, that data and evidence derived from it generally cannot be used in court or formal proceedings.
  • Members of Congress

    • The FBI must promptly notify congressional leaders and the Member concerned if the FBI runs a query using that Member’s name or personally identifying information. There is a limited waiver for ongoing investigations.
    • The FBI needs a Member’s consent to run certain queries to supplement defensive briefings, unless the Deputy Director finds exigent circumstances.
  • Intelligence and law enforcement agencies

    • Agencies must adopt new minimization, auditing, and compliance procedures. They face limits on querying and acquiring covered data and must destroy unneeded data in many cases.
    • DOJ must perform frequent audits of FBI queries; the DOJ Inspector General must audit FISA compliance every three years.
  • FBI employees

    • Before running queries, FBI personnel must complete training and, for many sensitive queries, obtain prior attorney approval and create written justifications. Violations trigger escalating personnel consequences.
  • Tech companies, data brokers, and service providers

    • Some service providers (intermediary/ancillary providers) are barred from voluntarily disclosing contents in storage or certain subscriber records.
    • Courts may not compel non-online service data brokers to disclose covered personal data unless the same legal standard would apply to an online service provider.
    • Certain directives to specific types of providers are limited and require notice to the FISA Court and Congress, with a declassification review about the provider types.
  • Courts and public

    • The FISA Court will receive random samples of targeting decisions for review. Amici (outside experts) get broader access to filings and can request review of important legal questions.
    • The DNI and Attorney General must publish more detailed reports, some publicly, on how FISA authorities are used.

Expenses#

No direct public cost estimate or fiscal note is included in the bill text provided.

  • The bill will likely increase administrative and compliance costs for federal agencies (training, audits, new reporting systems, personnel actions).
  • Agencies may need new or updated technical systems to track queries, create required records, and manage data destruction.
  • Private companies that receive new notice or legal standards (providers, intermediaries, data brokers) may face legal and operational costs to comply with new disclosure limits and court notice procedures.
  • No dollar amounts or budget estimates are provided in the supplied material.

Proponents' View#

The bill appears intended to strengthen privacy protections and oversight of foreign-intelligence collection. Possible arguments drawn from the bill text:

  • It would reduce warrantless access to the communications and information of U.S. persons and people located in the United States.
  • It would increase transparency about how Section 702 and other FISA authorities are used, by adding periodic audits, annual public reports, and more detailed DNI reporting.
  • It would improve accountability through FBI training, documentation, personnel consequences for query abuses, and Inspector General audits.
  • It would limit government purchases of personal data from private data brokers and require stronger protections for intermediary service providers.
  • It would require courts to receive more information and allow outside advisers better access to help resolve novel legal and civil liberties issues.

Opponents' View#

The bill text leaves space for several practical concerns and trade-offs:

  • One concern is operational impact: the tighter limits on querying and acquiring covered data, extra approvals, and documentation requirements could slow or complicate time-sensitive intelligence and law-enforcement work, even though some emergency exceptions are included.
  • The bill increases reporting and audit tasks; it is unclear how agencies will meet frequent audit and reporting deadlines without added staff or systems.
  • It may be difficult in practice to segregate or exclude “covered” data from large datasets before acquisition; the bill requires exhaustively removing such data but provides limited guidance on technical feasibility.
  • Some provisions (for example, which providers qualify for special limits, and how courts will review directives about providers) are time-limited or require declassification reviews; until those reviews finish, the practical effect may be unclear.
  • The bill expands disclosure obligations in FISA applications and raises criminal penalties, which could affect how candidly officials present classified or sensitive material to courts; the text does not include detailed guidance on handling classified or foreign-intelligence-sensitive evidence that the government regards as exculpatory but classified.