The idea under most of what we do

Your data isn't yours once you share it.

That's the third-party doctrine — the rule that lets the government read your emails, pull your location, or buy your records from a data broker without ever asking a judge. It shapes the tools we recommend and the campaigns we run.

The rule

What it says

The Fourth Amendment protects your “persons, houses, papers, and effects” from unreasonable searches. As a rule, the government needs a warrant — a judge, probable cause, a specific thing it's looking for — before it can go through your things.

The third-party doctrine is the exception that swallowed a lot of that rule. The idea is simple: the moment you hand information to someone else — a bank, a phone company, an internet provider — you've given up your expectation of privacy in it. You took the risk they'd pass it along. So when the government asks them for it, that isn't treated as a search of you, and the warrant requirement never kicks in.

It comes from two Supreme Court cases in the 1970s. In one, the Court said you have no privacy interest in your bank records, because you handed them to the bank. In the other, it said the same about the phone numbers you dial, because the phone company already has them to connect your calls. Records held by a company, the reasoning went, are the company's business records — not your private papers.

That made a rough kind of sense for a world of paper: a single bank slip, a list of dialed numbers. The trouble is what “handing information to a company” means today.

Why it matters now

Built for a filing cabinet. Applied to your whole life.

Living online means handing almost everything to some third party. Your location pings your carrier every few minutes. Your searches go to Google. Your messages sit on a server. Your face lands in one database, your car's movements in another. A rule written so the government could pull one bank slip without a warrant now reaches a running record of where you go, who you talk to, what you read, and what you buy.

The doctrine didn't stretch to fit the digital age. The digital age grew up inside it.

The problem was never any single record. It's that almost every record of your life is now held by someone else — and the rule says that's exactly when it stops being protected.
In progressA diagram of the rule in one picture: you share data, a company holds it, and the warrant requirement drops away.

The carrier bypass

The same data, without asking the carrier

Carpenter and Chatrie protect the records your carrier holds. Neither touches the routes that go around the carrier entirely — and two of them have been operational for decades.

SS7 is the set of protocols that connects every phone network on earth. It was designed in the 1970s around unconditional trust between telecoms: any node in the network can query any other for a subscriber’s location. That trust model has never been patched. Someone with access to the SS7 network can retrieve the approximate location of any phone worldwide without ever asking the subscriber’s carrier. Diameter, SS7’s 4G successor, has the same class of flaw. In February 2024, Senator Ron Wyden called these vulnerabilities “grave threats” in a letter to the White House and urged mandatory security standards; the FCC opened a formal investigation and asked carriers to document known exploits. EFF submitted comments the same year pressing the commission to act. Access to the SS7 network can be bought from rogue telecoms — no special hardware required.

The physical version of the same bypass is the IMSI catcher — a device that mimics a cell tower, tricks nearby phones into connecting, and logs their location and subscriber identities directly from the air. No carrier record, no court order, no third party in the middle. The ACLU found at least 75 agencies in 27 states using them. A bipartisan bill requiring warrants for their use — introduced by Senators Wyden and Daines alongside Representatives Lieu and McClintock — has been reintroduced repeatedly, most recently in July 2025, but no federal warrant requirement exists today.

The point is narrow but important: the third-party doctrine, and the warrant protection Carpenter and Chatrie carved out of it, only ever reached what a company holds. The infrastructure underneath can be queried directly — and no ruling about carrier records touches what happens before the data gets there.

How the courts have handled it

Four moments tell the story — where the rule came from, and where it has started to crack.

United States v. Miller · U.S. Supreme Court · 1976

Your bank records

The government got a man's bank records without a warrant. The Court held he had no Fourth Amendment interest in them: he'd handed the information to the bank, so they counted as the bank's business records, not his private papers. This is the root of the doctrine.

Read the opinion (Justia) →
Smith v. Maryland · U.S. Supreme Court · 1979

The numbers you dial

Police logged the phone numbers a suspect dialed, no warrant. Same reasoning: you hand those numbers to the phone company to place a call, so you can't expect them to stay private. Miller and Smith together are the doctrine's foundation — and both were decided for a world of paper records.

Read the opinion (Justia) →
Carpenter v. United States · U.S. Supreme Court · 2018

The first real crack

The government pulled months of a suspect's cell-phone location history from his carrier without a warrant. This time the Court said no: that much location data is so revealing that obtaining it counts as a search, and needs a warrant. But the Court called the ruling narrow and left the rest of the doctrine standing — the clearest sign yet that the old rule doesn't automatically fit digital data.

Geofence warrants · Federal & state courts · 2024–2025

The fight that reached the Court

“Reverse” warrants that ask Google for every device near a place and time. The courts are split: in 2024 the Fifth Circuit ruled them unconstitutional, treating location history like the data in Carpenter; the Fourth Circuit reheard its own case before the full court; and state high courts in Georgia and Texas came out differently. With the lower courts split, the question went up to the Supreme Court.

A plain rundown of the geofence fight (congress.gov) →
Chatrie v. United States · U.S. Supreme Court · 2026

The Court's answer — so far

In 2026 the Supreme Court took the Fourth Circuit's geofence case and settled the threshold question: pulling your phone-location history from a company is a search, so the government needs a warrant. It leaned on Carpenter — you don't give up your privacy in where you've been just because an app logged it. But it stopped there. It didn't decide whether any geofence warrant can actually be valid — that went back to the lower court — and it said nothing about the government buying the same data from a broker. One door closed; the broker loophole this whole page keeps circling back to is still wide open. That gap is what the advocacy side is aimed at.

Read the opinion (supremecourt.gov) →

The legislation aimed at the carrier-bypass routes is the Cell-Site Simulator Warrant Act (S.2122 / H.R. 4022), which would establish a probable-cause warrant requirement for IMSI catchers at every level of government. No equivalent statute addresses SS7 and Diameter access. Both gaps sit alongside — and outside — the cases above.

Not a partisan issue, either — Justice Sotomayor has questioned the doctrine from the Court's left, and the libertarian Institute for Justice runs a whole project against it from the right.

Where we come in

Two ways to answer it

This is the whole reason the club has two sides. If the law won't protect data you've handed to a company, you can hand over less — and you can push to change the law itself.

Protect yourself

Give them less to hand over

The doctrine only reaches data a company holds and can read. So a lot of the fix is technical: end-to-end encryption means your provider can't read your messages, so there's nothing to turn over. Services that don't log or store your activity have nothing to hand a subpoena. That's not paranoia — it's building around the exact rule this page describes.

Change the law

Close the loophole

The courts haven't fixed this, so the other lever is legislation. Our priority campaign backs H.R. 8470, the Surveillance Accountability Act — a bill whose sponsors named these exact 1970s cases as its target. It would make the government get a warrant for data held by third parties, the same bar as searching your home, and stop agencies from buying their way around it through data brokers.

Get involved

It’s free, open to everyone at Pitt, and joining takes about a minute.

No dues, no experience needed. Come to a meeting, or leave your name and we’ll tell you when the next one is.