Password protected website did not create a reasonable expectation of privacy when the information was shared with another

Police received information from one of defendant’s neighbors that defendant and his live-in girlfriend had posted pictures form a cellphone on a Sprint PCS website. “The caller provided the address of D’Andrea’s apartment (90 Veteran’s Way in Gloucester, Massachusetts), the log-in name and password for the website, and the number of a cellular telephone used by defendants.” The police went to the website and downloaded the pictures. A search warrant was obtained for defendant’s premises. First, “[t]he warrant permitted the seizure of ‘cameras’ and ‘computer storage devices.’ The modern cellular telephone fits easily into these categories. It can also be a ‘computer accessory,’ as the warrant also specified.[n.4]” Second, the password protection on a website did not provide a reasonable expectation of privacy, rejecting LaFave’s view. United States v. D’Andrea, 2007 U.S. Dist. LEXIS 52558 (D. Mass. July 20, 2007):

Professor Warren LaFave, a preeminent authority on the Fourth Amendment, argues that a person who avails herself of a website’s password protection should be able to claim a reasonable expectation of privacy in the site’s contents. Professor LaFave makes the point that while a service provider has a need to access information regarding the identity of a site holder and the volume and extent of her usage, it has no legitimate reason to inspect the actual contents of the site, anymore than the postal service has a legitimate interest in reading the contents of first class mail, or a telephone company has a legitimate interest in listening to a customer’s conversations. “Reliance on protections such [as] individual computer accounts, password protection, and perhaps encryption of data should be no less reasonable than reliance upon locks, bolts, and burglar alarms, even though each form of protection is penetrable.” LaFave, 1 Search and Seizure § 2.6 at 721 (4th ed. 2006). Professor LaFave’s argument is persuasively echoed in Warshak v. United States, 2007 WL 1730094 (6th Cir. June 18, 2007).

[T]he reasonable expectation of privacy inquiry in the context of shared communications must necessarily focus on two narrower questions than the general fact that the communication was shared with another. First we must specifically identify the party with whom the communication is shared, as well as the parties from whom disclosure is shielded. Clearly, under Katz [v. United States, 389 U.S. 347 (1967)], the mere fact that a communication is shared with another person does not entirely erode all expectations of privacy, because otherwise eavesdropping would never amount to a search. It is true, however, that by sharing communications with someone else, the speaker or writer assumes the risk that it could be revealed to the government by that person, or obtained through a subpoena directed to that person.

. . .

The second necessary inquiry pertains to the precise information actually conveyed to the party through whom disclosure is sought or obtained. This distinction provides the obvious crux for the different results in Katz and Smith, because although the conduct of the telephone user in Smith “may have been calculated to keep the contents of his conversation private, his conduct was not and could not have been calculated to preserve the privacy of the number he dialed.” [Smith,] 442 U.S. at 43. Like the depositor in Miller, the caller in Smith “assumed the risk” of the phone company disclosing the records that he conveyed to it. Yet this assumption of the risk is limited to the specific information conveyed to the service provider, which in the telephone context excludes the content of the conversation. It is apparent, therefore, that although the government can compel disclosure of a shared communication from the party with whom it was shared, it can only compel disclosure of the specific information to which the subject of it has been granted access.

Id. at *10-11 (emphasis in original).

[The first entry into the website by the private party was not state action.]

At day’s end, this case falls clearly into the “assumption of the risk” exception identified in Warshak and Supreme Court precedent. “It is well-settled that when an individual reveals private information to another, he assumes the risk that his confidant will reveal that information to the authorities, and if that occurs the Fourth Amendment does not prohibit governmental use of that information.” Jacobsen, 466 U.S. at 117. See also United States v. Maxwell, 45 M.J. 406, 419 (C.A.A.F. 1996) (the sender of an email runs the risk that its recipient will publish its contents). Thus, even granting defendants a reasonable expectation of privacy in the graphic website images of Jane Doe, by sharing the website access information with the anonymous caller, defendants took the risk that their right to privacy in the website’s contents could be compromised.

Comment: It is Wayne LaFave; not Warren. Also, this case helps underscore Maxwell as a leading case.

This entry was posted in Uncategorized. Bookmark the permalink.

Comments are closed.