Nate Ranson • SECR-6411 • Midterm Thesis • September 13, 2026
AI Disclosure: Google Gemini was used for proofreading, spell-checking, grammatical suggestions, confirmation of citation formats, and source summarization to confirm their relevance to the project. All text was written by Nate Ranson.

Commercially Available Information: Fourth Amendment Obligations for Intelligence Agencies in the Private Marketplace


The Fourth Amendment protects all individuals in the jurisdiction of the United States from unlawful searches and seizures by the government. In most cases, information collected about individual citizens by government agencies is subject to various legal or statutory obligations or restrictions. Commercially available information (CAI) collected by data brokers, however, has complicated this framework. Private companies and data brokers collect and aggregate granular information and can provide valuable insight about an individual’s movements, activities, or associations (Ayoub and Goitein 2024). The United States Intelligence Community (USIC) can and has purchased this data through commercial marketplaces rather than collecting it directly, raising concerns around the applicability of traditional Fourth Amendment constraints (Office of the Director of National Intelligence 2022).

To the general public, CAI may often be thought of as cell tower pings or purchase histories, but that is an outmoded level of fidelity. When a customer or user opts into the terms and conditions laid out in smartphone apps like TikTok, Tinder, or even Google Maps, what they may be giving up is up-to-the-second metadata about their social and physical networks (Ayoub and Goitein 2024). The data can then be analyzed to identify close friends and/or family members through both physical proximity – through Bluetooth device ID, a shared wifi network, or geolocation data – or via metadata surrounding the frequency and method by which a user contacts another person. In an intelligence investigation, information of this quality is highly valuable (Oerlemans and Langenhuijzen 2024).

The challenge is that information like this that the government wanted to collect on U.S. persons may be subject to significant legal or procedural restrictions. On the open market, however, private companies assume the burden of collection, allowing agencies to purchase directly without necessarily obtaining a warrant first (Sobel 2023). This presents a significant gap in the legal, procedural, and oversight burdens in direct collection versus the speed at which CAI can be purchased. To what degree does the USIC’s reliance on CAI challenge existing legal frameworks governing Fourth Amendment protections and IC-congressional oversight obligations? This paper will argue that while commercially available information has become an increasingly important intelligence capability, supporting national security objectives through capabilities like pattern-of-life analysis, its acquisition by the USIC raises privacy and constitutional concerns that oversight frameworks do not currently address. Greater congressional oversight and updated legislative safeguards, such as the Fourth Amendment Is Not For Sale Act, are necessary to balance intelligence effectiveness with the protection of Americans' civil liberties.

Commercially available information serves legitimate business and governmental purposes. It allows businesses to send better targeted advertising, helps identify emerging business opportunities or demographic trends, and can even help with things like budgetary considerations for local municipalities. CAI has also played a crucial role in open source intelligence collection (Oerlemans and Langenhuijzen 2024). In its most raw form, CAI can provide generalized and anonymized information about growing trends that support national security objectives. For example, analysis of commercially available or publicly accessible social media data can help identify foreign influence operations. Researchers have been able to identify Twitter/X.com account IDs, locations, and recurring hashtags to identify Russian disinformation campaigns (Zannettou et al. 2019). This illustrates how CAI can provide a clear national security capability. Data in the aggregate and abstract is not necessarily a civil liberties problem and is the lifeblood of the USIC’s mission. The problems arise as the data becomes more granular, individualized, and person-specific, potentially revealing patterns of life or data that could otherwise be subject to legal considerations for collection by government agencies.

In a more refined state, CAI can contain exceptionally sensitive information about individuals. From data brokers like FullContact, baseline data – an email address or phone number – can be enriched as pre-aggregated, structured data, giving the buyer a look into the location, contact information, employment, and other data about single individuals. Other data brokers provide “anonymized” data. And while that data may not come with individual names or personal identifiers attached to it, it can be linked to data that does. By compiling data sets from disparate sources, anonymized datasets could provide reidentification possibilities when combined with data containing personally identifying information (PII). The Office of the Director of National Intelligence acknowledges this risk: When purchasing large data sets to track foreign individuals, data of U.S. persons inevitably comes embedded (Office of the Director of National Intelligence 2024).

Deanonymizing datasets by combining anonymous data with PII is possible even with only a small amount of data. In a study from 2008, researchers were able to identify anonymized Netflix subscribers by cross-referencing a similar set of data from IMDb about movie ratings. By linking distinct movie ratings together across datasets, the researchers were able to deanonymize the Netflix data with a high degree of accuracy. This is thanks, in part, to what the researchers describe as the “fat tail,” or that sets of preference or transaction data contain statistically significant, rare attributes (Narayanan and Shmatikov 2008). To build a hypothetical, an intelligence agency could purchase anonymized geolocation data and then cross-reference with cell phone metadata containing PII. Now an intelligence analyst would be able to track the target across the entire dataset. Given a sufficiently large data set, this might be taxing for a single agent, or even a team of agents, but in the age of artificial intelligence and “big data,” the majority of the computational stress could be offloaded to machines to do the deanonymization (Lermen et al. 2026).

The USIC does not typically purchase data directly from applications like Google or Tinder. Instead, data brokers serve as intermediaries between the consumer-facing products and the public and private organizations looking to do data analysis. Data brokers have access to multiple sources of data and can aggregate, anonymize, and provide tailored demographic, location, or other information to purchasers (Ayoub and Goitein 2024). For its part, the USIC’s foreign intelligence collection operates within a policy framework, largely guided by Executive Order 12333, with provisions on how to handle U.S. persons’ information that are incidentally collected (Exec. Order No. 12333 1981). CAI complicates this framework because U.S. persons’ data may already be embedded in these data sets when the IC acquires them. Since its establishment in 2004, the ODNI has played a key role in forming norms and rules around what is or is not considered acceptable bulk intelligence on U.S. persons (Lowenthal 2025). The USIC has attempted to self-govern by establishing rules and documentation standards for collecting CAI. Ultimately, however, the purchase of CAI as a sanctioned practice raises questions about collection “rules” and legal, statutory, or oversight obligations associated with intelligence collection (Office of the Director of National Intelligence 2024).

A watershed moment in CAI was the Supreme Court’s Carpenter v. United States decision in 2018. The case centered around the purchase of cell phone data regarding four suspects in an armed robbery case. Using the Stored Communications Act as a basis, police were able to request the data with a standard lower than probable cause. The Carpenter decision held that the government’s purchase of historical cell-site location information constituted a Fourth Amendment search and generally required a warrant supported by probable cause. The decision did not settle the government’s obligations when purchasing data from intermediaries, leaving an important constitutional question open (Carpenter v. United States 2018).

The USIC and its individual agencies straddle the constitutional line between domestic law enforcement and intelligence service. As such, departments like the FBI or DHS may have different statutory or organization obligations when acquiring CAI. If a police department is bound by Fourth Amendment restrictions for acquiring this data, it would be reasonable to assume that the FBI, a domestic, law enforcement agency, could also be bound by the Carpenter ruling. Intelligence agencies whose scope extends beyond the border of the United States, however, may be bound to different rules or obligations when it comes to CAI that may contain information about U.S. persons as well as international data.

Further, the Defense Intelligence Agency (DIA) contends that since they are not specifically a law enforcement agency, the Carpenter decision does not directly apply to them. In 2021, the DIA provided a written statement to Congress that it “does not construe the Carpenter decision to require a judicial warrant endorsing purchase or use of commercially available data for intelligence purposes.” (Office of the Director of National Intelligence 2022, sec. 3.4) The FBI has also admitted to historically purchasing location data but cited the data as derived from “internet advertising,” further clarifying the bureau was not actively purchasing and would need a court order to purchase such information (Burt 2026). The ODNI, however, has documented the DIA’s understanding in a partially declassified report; the ODNI confirmed the DIA’s stance that the Carpenter ruling was not applicable with regard to intelligence collection when purchasing through third-party brokers (Office of the Director of National Intelligence 2022).

How then should interagency data sharing and integration work? In another hypothetical scenario, the CIA may have substantive information gathered through purchased data. If the target comes into the United States could the CIA share this data with the FBI without a warrant? If outright permitted, this could be interpreted as giving the CIA an asymmetrical intelligence advantage over other domestic-only organizations. The reverse, however, cannot be true; the FBI, if held by the Carpenter decision, CAI containing U.S. persons would be subject to Fourth Amendment protections, therefore putting it in a position to potentially receive external data but adding significant overhead on the return in reciprocity. As outlined by Lowenthal (2025), finite budgetary allocation means that some agencies will get a larger slice of the pie than others. This information imbalance could lead to favoritism or intelligence preferences in terms of how the Legislative or Executive branches are briefed.

The DIA’s narrow interpretation of the Carpenter ruling has caused a reaction in Congress, highlighting the difficulty in oversight when intelligence and law enforcement potentially overlap (Thayer 2023). The legal framework governing electronic privacy is the Electronic Communications Privacy Act (ECPA) of 1986, specifically the Stored Communications Act (SCA) – the same Stored Communications Act at the heart of the Carpenter case. Under the framework laid out by the SCA, electronic communication service (ECS) and remote computing service (RCS) providers – companies like Google, Meta, or Verizon – are prohibited from voluntarily handing over electronic communications data to the government without legal process. The electronic communications world in 1986 was vastly different from today’s ecosystem that includes website cookies, geolocation data, and any number of other permissions granted to cell phone and laptop applications. While the SCA puts restrictions on releasing customer data, it does not prohibit these ECS and RCS providers from selling data to brokers (18 U.S.C. § 2702).

Under the definition laid out by the SCA, these data brokers are merely intermediaries and not classified as ECS or RCS providers. This loophole allows for a data provider governed under the SCA to sell the data to a broker, who is not governed by the SCA, who can turn around and sell it to anyone they choose. This layer of isolation between federal agencies and the ECS and RCS providers makes this transaction statutorily permissive, if not spiritually dubious. Data that is filtered through these brokers is not subject to the warrant requirements established under the ECPA (Ayoub and Goitein 2024; Sobel 2023).

In an attempt to close this loophole, a bipartisan-sponsored bill was introduced in the House of Representatives – H.R. 4639, The Fourth Amendment is Not For Sale Act – that attempted to bar “remote computing service (RCS) providers and electronic communication service (ECS) providers” from providing the federal government with records pertaining to any individual customer or subscriber. It further prohibited the release of these records from intermediary providers and disqualified them for use in trial. The language and framing of the bill is specifically centered around constitutional protections for U.S. persons, and because it was tied to the Foreign Intelligence Surveillance Act’s definition of scope, upheld the USIC exemption for foreign persons. Additionally, it placed narrow exemptions for data collection where U.S. persons’ data could be shared if they explicitly provided consent, the data was publicly available, such as license plates, or it was voluntarily provided, like social media posting history (U.S. Congress [House] 2023).

Although H.R. 4639 narrowly passed the House, the Senate-equivalent, S. 2576, ran into political and lobbying opposition. The lobbying arm of the Fraternal Order of Police publicly denounced the bill, citing it could make investigative work more difficult by requiring a higher legal bar to obtain warrants for the data. The Executive Branch, USIC leadership, and intelligence advocates on both sides of the aisle also raised concerns about the sweeping restrictions it would impose on the USIC’s ability to purchase any data. Because data aggregated in bulk may not have neat nationality boundaries, the bill could severely hamper intelligence agencies with jurisdiction on foreign nationals outside the U.S. boundaries if the data contained any information about U.S.-based persons (Fraternal Order of Police 2024). As a result, the bill died in committee deliberation before reaching a floor vote (U.S. Congress [Senate] 2023).

While legislative efforts like The Fourth Amendment Is Not For Sale Act remain gridlocked, the IC relies heavily on internal technical mitigations as a self-governed backstop between intelligence utility and civil liberty preservation. Chief among these mechanisms are the strict minimization and handling procedures mandated under Executive Order 12333, which require agencies to mask, filter, or destroy incidentally collected information concerning U.S. persons before dissemination (Exec. Order No. 12333 1981). Furthermore, the ODNI’s updated policy framework for commercially available information attempts to establish rigorous internal auditing, documentation, and data-segregation standards to ensure that bulk commercial purchases are not used to circumvent constitutional norms (Office of the Director of National Intelligence 2024). Proponents of this internal administrative approach argue that cryptographic anonymization, automated privacy filters, and data-masking protocols provide a flexible, technologically agile defense that can adapt faster than lagging federal statutes.

However, the IC’s reliance on technical minimization and anonymization as a stand-in for oversight ignores the technological and mathematical landscape of the modern world. The ODNI acknowledges this gap in its own review (Office of the Director of National Intelligence 2022, sec. 1.6). As a factual example, the panel itself cites a New York Times investigation that was able to deanonymize Secret Service cell phone metadata to locate the President (Office of the Director of National Intelligence 2022, sec. 1.6). ODNI specifically found different levels of care for handling anonymized datasets among IC elements. For instance, some agencies may have a singular dataset that lacks a secondary set for deanonymization, while others may have multiple datasets but no expressed intent to deanonymize. The ODNI says this “unacceptably narrow” distinction of intent puts the agencies at unneeded legal or oversight risk (Office of the Director of National Intelligence 2022, sec. 4.3.4). Because AI can reverse-engineer patterns of life from raw commercial metadata, internal technical minimization is fundamentally a policy fiction. Masking a target’s name inside a database offers minimal structural protection if machine-learning architectures can re-identify that individual in seconds, demonstrating why internal executive branch guidelines cannot replace binding statutory boundaries.

Open source data will continue to remain a valuable tool for investigators and intelligence services alike. Lawmakers will face the challenge of legislating an ever-evolving technological landscape to protect U.S. persons’ Fourth Amendment rights without wholesale disregard for CAI as an intelligence source. Historically, legal and oversight frameworks have lagged behind the speed at which technology evolved. The Fourth Amendment’s third-party doctrine, Executive Order 12333’s guardrails for U.S. persons’ privacy, and the ECPA were all drafted before the data economy existed, providing static solutions for evolutionary problems the architects of these legislative and oversight mechanisms couldn’t have anticipated. Carpenter’s application – or not – to IC members like the DIA and FBI shows that even among individual agencies the subject of commercially available information remains unresolved. While The Fourth Amendment Is Not For Sale Act might immediately satisfy Americans who see this as an answer to the weaponization of intelligence, it carries significant national security implications (Berrefjord and Bjørstad 2024). For oversight to matter, Congress must act with an urgency unseen in historical legislative efforts. A commitment to understanding the technological landscape, weighing the intelligence community's operational needs, setting aside partisan differences, and protecting U.S. persons' privacy rights under the Fourth Amendment is paramount to oversight success. Threading the needle between providing the USIC with the tools it needs while simultaneously protecting U.S. persons’ privacy will be an iterative process that will require good faith on both sides of the political aisle.


References
18 U.S.C. § 2702. Voluntary disclosure of customer communications or records.
Ayoub, Emile, and Elizabeth Goitein. 2024. "Closing the Data Broker Loophole." Brennan Center for Justice. https://www.brennancenter.org/our-work/research-reports/closing-data-broker-loophole.
Berrefjord, Vivi Ringnes, and Tor E. Bjørstad. 2024. "Commercially Sourced Intelligence: Friend or Foe?" Intelligence and National Security. https://doi.org/10.1080/02684527.2024.2437955.
Burt, Chris. 2026. "FBI, DIA Pressed on Purchases of Americans’ Phone Location Data." Biometric Update.
Carpenter v. United States. 2018. 138 S. Ct. 2206.
Exec. Order No. 12333. 1981. United States Intelligence Activities.
Fraternal Order of Police (FOP). 2024. H.R. 4639/S. 2576, the “Fourth Amendment Is Not For Sale Act”. Legislative Opposition Letter. https://fop.net/letter/h-r-4639-s-2576-the-fourth-amendment-is-not-for-sale-act/.
Google. 2026. Gemini. Large language model. https://gemini.google.com.
Lermen, Simon, Daniel Paleka, et al. 2026. "Large-scale online deanonymization with LLMs." arXiv preprint arXiv:2602.16800. https://arxiv.org/abs/2602.16800.
Lowenthal, Mark M. 2025. Intelligence: From Secrets to Policy. 10th ed. Washington, DC: CQ Press.
Narayanan, Arvind, and Vitaly Shmatikov. 2008. "Robust De-anonymization of Large Sparse Datasets." Proceedings of the 2008 IEEE Symposium on Security and Privacy: 111–125. https://ieeexplore.ieee.org/document/4531148.
Oerlemans, Jan Jaap, and Sander Langenhuijzen. 2024. "Balancing National Security and Privacy: Examining the Use of Commercially Available Information in OSINT." International Journal of Intelligence and CounterIntelligence. https://doi.org/10.1080/08850607.2024.2387850.
Office of the Director of National Intelligence. 2022. Senior Advisory Group Panel on Commercially Available Information. Declassified June 14, 2023. Washington, DC.
Office of the Director of National Intelligence. 2024. Intelligence Community Policy Framework for Commercially Available Information. ICPM-2024-504-01. Washington, DC: ODNI.
Sobel, Aaron X. 2023. "End-Running Warrants: Purchasing Data Under the Fourth Amendment and the State Action Problem." Yale Law & Policy Review 42 (1): 176–237.
Thayer, Jacob E. 2023. "Tightening the Seam: Improving Purposeful Oversight of Operations at the Nexus of Intelligence and Law Enforcement by Defining Intelligence-Related Activities." American Intelligence Journal 40 (2): 133–144.
U.S. Congress. House. 2023. Fourth Amendment Is Not For Sale Act. HR 4639. 118th Cong., 1st sess.
U.S. Congress. Senate. 2023. S.2576 - Fourth Amendment Is Not For Sale Act, 118th Cong., 1st sess. https://www.congress.gov/bill/118th-congress/senate-bill/2576/amendments.
Zannettou, Savvas, Tristan Caulfield, Emiliano De Cristofaro, Nicolas Kourtellis, Ilias Leontiadis, Michael Sirivianos, Gianluca Stringhini, and Jeremy Blackburn. 2019. "Disinformation on the Web: Impact, Characteristics, and Detection of Tweets, News, and More." Proceedings of the 28th International Conference on World Wide Web.