Sunteți pe pagina 1din 21

SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MSN MSN Yahoo AOL MyYearbook


Date Undated 2008 2009 2010 2005 March 2006 June 2006 2007 2006 2008 Undated March 2010 Jan 29, 2010 Undated Undated April 2010 July 2009 April 26, 2010 Undated Undated
Date, length, link Available on Twitter site at: February 2008, five pages 2009, 11 pages May 2010, 5 pages September 2, 2005, 7 pages March 13, 2006, 16 pages June 23, 2006, 16 pages November 1, 2007, 15 pages July 2006, 2 pages March 2008, 22 pages Undated, 17 pages March 2010, 19 total pages, but were only given 12 Jan. 29, 2010, online document, 1 Undated, two pages Undated, eight pages April 2010, four pages July 2009, four pages April 26, 2010, 16 pages Undated, 16 pages Undated, 2 pages
(if available) and http://support.twitter.com/entries/41949- (appear to be missing pages 4-6 and 15-18) page, also available at
other info guidelines-for-law-enforcement http://www.craigslist.org/about/hel
p/subpoenas_and_search_warrants
How does Guide Addresses but does not distinguish: "We Does not say • Subpoena for non- "we will provide records as • Most profile information is "Most profile information is MySpace is both an ECS and RCS "Depending on the type of information sought, ECPA "governs what legal ECPA "sets forth the appropriate legal process required to "ECS for communications including but not Distinguishes between Does not say • signed fax (non-subpoena) "eBay can "The types of process • No legal process required for "Ning can provide you with Non-public information "To request private (non-public) • subpoena for "basic
address Legal require a subpoena, court order, or other content (basic subscriber required by law." (p.2) publicly viewable and available. publicly viewable and (p.4) ECPA may require the use of a different form of documentation is required in order for compel Microsoft's Online Service Records Custodians to limited to email and Messenger" / "RCS for • subpoena for "subscriber information," including provide the following information for necessary to permit "Public Information," such as the following information requires legal process in information from Tagged about a specific account information" will
Process valid legal process to disclose information info), Publicly available information available." (Guide includes • subpoena for "basic user identity, legal process, and the period MySpace retains the Microsoft's Online Service records disclose customer records and contents" purposes including but not limited to storage "name, email addresses, and screen names, users under investigation of illegal Photobucket to produce each profile page, profile images. once we receive a compliance with ECPA profile or user, we requires a subpoena, include "avatar name, e-
Requirements about our users." • ECPA 2703(d) order for includes journal entries (in most instructions for law log-in information, and stored files", information may differ." (p. 4) custodian to disclose customer • subpoena for basic subscriber information, including of photos and files." addresses, detailed billing records or records of activity only: contact name, city, state, category of information under • subpoena for "General subpoena, search warrant search warrant or other legal process. The mail address, customer ID
under Electronic limited content (e.g. cases), images, user comments, enforcement to download this • § 2703(d) court order for "user's • subpoena or § 2703(c)(2) demand for "Basic account information and email "name, address, length of service (start date), screen • subpoena for "basic subscriber information, session times and durations, length of service ZIP, and telephone number, all email the SCA differs only slightly." Information," including user or court order" following list is private content that is not (all unique) as well as the
Communications By default, most Twitter profile information messages over 180 days), and public profile information." info) date of birth, gender, hometown, user identity information," including "date profile content." names, other email acounts, IP address/IP logs/Usage contents of communications on RCS, contents (including start date) and types of service utilized, addrsses and eBay User ID's added to • subpoena for "first name, name, user ID, DOB, age, • subpoena for the publicly accessible" IP address used to register
Privacy Act is public. This includes, according to the • search warrant for (p.2) and occupation, as well as historical created; first and last name provided by user; user • subpoena for basic subscriber logs, billing information content (other than e-mail, such as in electronic storage for over 180 days." telephone or instrument number or other subscriber account with date/time stamps, eBay last name, user/screen name, location (if known), school (if registration email of the • "IP logs (recorded at time of login), Date the account and any
(ECPA)? privacy policy, name and username. It also remaining content (p. 3) • MS requires a subpoena for • Non-public information private message header ID; e-mail address provided by user; ZIP code, information, including "name address, Windows Live Spaces and MSN Groups) and e-mail content • 2703(d) order for "transactional records number or identity, including any temporarily assigned Fraud complaints (if requested)" ZIP code, country, email known), email address, Network Creator and profile created, Dates and times of login device fingerprints on file
may include a short bio, cell phone number, following info: requires subpoena, search information." city, and country provided by user; account length of service (start date), screen more than 180 days old as long as the governmental entity (e.g., Messenger or Chat logs, IP address netowrk address, and the means and source of address, account creation password, date joined, user Members who uploaded (PST), E-mail address provided by user, [. . .] If account
location, address book, a picture, "the -IP logs (recorded at time of warrant, or other legal process • search warrant for private user creation date and time; and the IP address at the names, other email accounts, IP follows the customer notification provisions in ECPA (see infomration associated with any activity other payment for such service (including any credit card or • subpoena for "full eBay contact date/time" name changes, DOB changes, the content, registration IP ZIP code provided by user, Name provided communications are
messages you Tweet and the metadata login), Dates and times of login communications less than 180 days time of sign-up." address/IP logs/Usage logs, billing 18 U.S.C. §§ 2703(b), 2705) than log-in), anything obtainable with a bank account number)." details, including the billing and mailing • subpoena for "Date and IP violations of terms of service, IP addresses, Usernames, by user, Screen Name, Private Messages" requested, IMVU will
provided with Tweets, such as when you (PST), Email address, ZIP code, • Non-public info includes: IP old. • subpoena or § 2703(c)(2) demand for historical information, and e-mail content • 2703(d) order "will compel disclosure of all of the basic subpoena." • 2703(d) court order "is required to compel address, eBay IP addresses: time of for most recent account logs of last 6 months (login credit card information (if • "The following are only retained if the provide the text of web-
Tweeted, but also the lists you create, the name, private messages (pp.2-3) logs (recorded at time of • Subpoena or court order with prior "logs showing the IP address assigned to the user greater than 180 days old as long as subscriber information available under a subpoena pluse • search warrant for "Contents in electronic disclosure of a range of IP connection logs." (p. 12) registration and at time of item listing, access, Registration IP, times only), IP addresses, date any) user has not deleted them from their based messages and a
people you follow, the Tweets you mark as login), Date profile created, notice to the subscriber (or delayed and the date stamp at the time the user accessed the governmental entity follows the the e-mail address book, Messenger contact lists, the rest storage for 180 days or less, anything • search warrant for "subscriber information" complete listing and/or bid history - 2 Banned date/time (if account and time logged in, all profile • search warrant for all page: Confessions, Boxxes, Journals." summary of realt-time
favorites or Retweet and many other bits of Dates and times of login, E- notice under 18 U.S.C. § 2705) for his or her profile." customer notification provisions in of a customer's profile not alread listed above, internet obtainable with a sbupoena or 2703(d) order" obtainable under subpoena, "transactional year max (including bidder information banned), Date/Time of pictures in account (though images and videos of (p. 6) chats (via IMVU's 3D
information." mail address, ZIP code, Stored user files (photos, videos, • Pen register/trap and trace order to "caputre log- ECPA (see 18 U.S.C. § 2705)." (p. 2) usage logs (e.g. WEBTV or MSN Internet Access), and e- (p. 11) information, including: logs of Internet Protocol ("IP") if specifically requested), credit card Upload or Modification of file, accounts deleted by MYB or the suspected child client) that will include the
Name, Private Messages, blogs, classifieds, messages posted in IPs prospectively." • 2703(d) order "will compel mail header information (to/from) excluding subject line." address connections, including dates, times, and time and checking acount information added Upload IP for files uploaded user willnot have any images pornography, date/time accounts participating in
"Non-public information about Twitter users Private blogs (some info may on forums or groups, address book • Search warrant for messages less than 180 days disclosure of all of the Basic • Search warrant "will compel disclosure of all information zones, and any ANI information made available to to an eBay account (if available)" after June 1, 2007" available) stamped IP addresses at chats but not the actual
is not released unless we have received a not be accurate) (p. 6) and calendar contents) old. Subscriber information available under available with a court order issued pursuant to 2703(d) (as AOL, address books, buddys lists, and account history, • court order, search warrant, • search warrant for time member uploaded text of the chat" (page 1)
subpoena, court order, or other valid legal • pen register/trap and trace order • Subpoena or court order (or delayed notice a sbupoena plus the Address Book, listed above), plus all contents (if prior notice is not including contacts with AOL support services and • subpoena for all records relating to a or subpoena where governent "Communications/private content in question, any
process document." • Information provided in for ongoing information about user's under 18 U.S.C. § 2705) for messages over 180 Buddy Lists, the rest of a customer's provided or an order for delayed notice is not obtained), records of action taken online by the subscriber or by PayPal user, including "all PayPal provides prior notice to Information," including private and all messages received
response to subpoena: email IP address each time they log-in to days old. profile not already listed above, and is the only means to compel the disclosure of e-mails, AOL support staff in connection with the service." account information including, SSN, subscriber for "image and messagees, instant messages, from creators and
address, IP Logs, private their account (pp. 4-7) • Subpoena, civil investigative demand, or court internet usage logs (WEBTV), e-mail including subject line, in electronic storage 180 days or • search warrant for "all electronic or wire names, addresses, phone numbers, video content in a user's embedded images in messages. members, subject line and
messages (p.10) • Law enforcement can obtain order for "profile information including photos, header information (to/from) less."(p. 22) communications (including e-mail text, attachments, email addresses, PayPal IP addresses account" (pp. 3-4) (pp. 1-2) date/time stamp of all
publicly available info without videos, blogs, blog comments by other users, the excluding subject line, and e-mail • "as Microsoft receives and processes legal and embedded files) in electronic storage by AOL, or (at each login), financial instruments automated email
MySpace's assistance. (p. 4,5) identities fo the friends and 'About Me' entries." content greater than 180 days old as process for its online services in the Ninth Circuit, held by AOL as a remote computing service, within the added to PayPal account, complete notifications
• § 2703(d) court order for "user's date of birth, long as the governmental entity follow [pursuant to Theofel et al v. Farey-Jones, 341 F.3d 978 meaning of the Stored Communications Act, all PayPal transactional information (pp. 2-3)
gender, hometown, and occupation, as well as the customer notifications provisions (9th Cir. 2003)]Microsoft discloses both opened and photos, files, data, or information in whatever form (including complaints if requested and
historical private message header information, of ECPA (see 18 U.S.C. § 2705)." (p. unopened e-mail in electronic storage for 181 days or less and by whatever means they have been created or available)" (p. 2)
excluding subject."(pp. 5-6) 2) only upon pursuant to a search warrant. stored, all profiles." (pp 7-9)
• search warrant is required for all
email content under 180 days. (p. 2)
How does site Law Enforcement Guide, TOS & Privacy Does not distinguish User ID number, email User ID number, email Guide only distinguishes between Guide only distinguishes basic "user" ID info including user's Basic user ID (subpoena): date profile created, Basic (subpoena): name, address, Basic (subpoena): name, address, length of service, screen Subpoena: basic subscriber information, Subpoena will get "subscriber information:" names, Does not say • No legal service required to access: Basic user (subpoena): name, Public info available without legal Subpoena: email, IP Subpoena required for Subpoena: IP logs, date profile created, Basic account information
define and/or Policy only distinguish between public and between basic subscriber address, time account was address, date/time public and non-public information between public and non-public name, email address, ZIP code, city name, user ID, email address, ZIP code, city, length of service, screen names, IP names, IP address, IP logs, billing info, email greater than contents of communications stored as a email, physical address, billing records, length of Contact information, city, state, ZIP user name, ZIP code, country, process: Profile page, profile address, username, credit basic user information, log- dates of login, email address, ZIP code, (subpoena): avatar name,
distinguish non-public information information and other created, most recent account was created, most (p.2) information (p. 6) & country, account creation county, account creation date, IP address; other address, IP logs, billing info, email 180 days (p. 22) remote computing service provider, contents service, phone number, credit card or bank account code, email addresses, fraud email, account creation date images; General info card information (if in information, and stored name, screen name (p. 6) email address, customer
different types of information (p. 4) logins, registered mobile recent logins, registered date/time, IP address at time of (court order) IP logs, birthday (pp. 5-6) greater than 180 days (p. 2) in electronic storage over 180 days (p. 11) numbers, IP addresses (pp. 7-8) complaints, account listings, and bid (p. 4) (subpoena): user name, ID, available) (pp. 2-3) files (p. 4) ID, IP addresses and
user information number, whether account mobile number (p. 4) signup -- all available via subpoena Full profile (court order): address book, buddy list, email history (p. 2) birthday, age, location password, Unclear what level of legal process is device fingerprint (p. 1)
is publicly viewable (p. 6) (pp. 6-7) Search warrant: private messages less than 180 Full profile (court order): address header info, email content great than 180 days; Email Court order: Transactional records such as IP Search warrant will get "transactional" and IP logs: subpoena, court date joined, changes to profile, Search warrant: Images, Court order required for required for messages (p. 6)
"Expanded Subscriber days old (p. 5) book, buddy list, email header info, (warrant): all messages less than 180 days old (p. 22) logs, messenger or chat logs; search warrant: "communications" info: IP logs, address books, buddy • Subpoena, court order, or warrant to order, search warrant or user IP logs, profile pictures (pp. 1-2) videos, IP address, all full access to profile; Unclear what legal process
"User Neoprint": Contact Content (sometimes user's birthday, gender, hometown, email content great than 180 days; contents in electronic storage less than 180 lists, account history, emails (including attachments), access: billing and mailing address, IP consent (p. 4) messages (p. 3) search warrant required is required for text of web
information, mini-feed, referred to as Neoprint)": occupation, private message header Email (warrant): all messages less days (p. 11) photos or files stored with AOL (p. 9) addresses, credit card, checking Communications (search for private user messages messages and chat logs
status update history, Contact information, mini- information; search warrant: than 180 days old (p. 2) account information, Social Security warrant): private messages, (p. 4) (p. 1)
shares, notes, wall posts, feed, status update messages less than 180 days old -- numbers instant messages, any images
friend listings (including history, shares, notes, wall all available via court order: (p. 6) embedded in messages (p. 2)
their IDs), group listings postings, friend listings
(including group member (include friend IDs), group
IDs), future and past listings (including group
events, video listings (p. member IDs), future and
6) past events, video listings
(p. 4)
What other info Twitter does not host any content other than User photos, group contact "User Photoprint": User "User photos (sometimes unclear Unclear whether photos and Photos, videos, blogs, classifieds Photos, videos, blogs available with subpoena or MSN groups and spaces are Can get this information from all of MSN services, such as Can provide files uploaded on Flickr (p. 9) AOL's Bebo service can only be searched with proper Does not say May be able to get information on Images and video available Does not say Images available with Video, audio, and photo Not clear what level of legal process is Does not say
is available? tweets. This includes any video or images information (p. 4) uploaded photos and referred to as User other content are released (p. can be disclosed with a subpoena court order (p. 6) considered public, and will be Xbox Live, Windows Live, etc. (p. 4) ID. Data retained for past 500 days (p. 19) accounts linked/related to subject (p.1) by subpoena if subscriber search warrant (p. 3) files available via required for this information
that users may share through their photos tagged with user's Photoprint)": User 6) (pages 6-7) disclosed with subpoena (p. 2) given notice; available with subpoena (p. 2)
accounts. name, group contact uploaded photos and court order or warrant
information, private photos tagged with user's otherwise (p. 4)
messages (p. 7) name, group information,
private messages (p. 4)
How does LE Twitter's servers automatically record • Logs are available and • now have a limited • IP logs contain same IP Logs are available for up to Available through subpoena. Can be produced with subpoena (p. Can be produced with court order (p. 5) Can be produced with subpoena (p. 2) Can be produced with subpoena (p. 22) IP logs available with a court order (p. 11) 2703(d) court order required (p. 9) Does not say Can be provided (p. 2) IP logs: subpoena, court Can be produced with subpoena IP addresses can be IP logs available with IP logs are available with subpoena (p. 6) Does not say
Guide address IP information ("Log Data"), which may include include: Script - script capacity of retrieving data as 2008/09 and also ninety days after a user's last Info includes time and date 6) Info includes IP address, date order, search warrant or user (p. 2) produced (p. 3) subpoeana (p. 1, 4)
and other logs? information such as IP address, browser executed, Scriptget - specific logs and are include Session Cookie -- login.(p.3) stamp (p. 10) and time of log-in at time user consent (p. 4)
type, the referring domain, pages visited, additional information technically limited in HTTP cookie set by user accesses profile. Historic IP logs are
and search terms. Other actions, such as passed to the script, providing "everything" session available, and MySpace can capture
interactions with advertisements, may also Userid - Facebook user id within a requested date • Logs are often IP logs prospectively with Pen/Trap
be included in Log Data. of the account active for range. We are unable to incomplete, but if available order.
the request, View time - testify to the completeness will be provided (p. 4)
date of execution in Pacific of the data.
Time, IP - source address • Logs include same data
as 2008
• IP logs contain content
and are treated as such
under ECPA
(p. 7)
How long is data "Twitter retains different types of 90 days (page 3), though 90 days, but an extension 90 days, but an extension • IP Logs are available for up to • "MySpace does not retain • Messages retained as long as not • Messages retained as long as not deleted; sent 90 days from date of request, but can 90 days from date of request, but can preserve for up to "Yahoo! Will preserve information related to a Sample preservation request asks AOL to preserve Does not say eBay keeps most account records Data is retained one year; will Active accounts kept indefinitely, 90 days unless Most data retained 90 "Tagged retains information on its users for "IMVU does not have a
generally information for different time periods. Given IP data may be retained can be made if necessary can be made if necessary. ninety days after a user's last information that is altered on deleted; sent mail retained for 14 mail retained for 14 days; trash mail retained 30 preserve for up to 270 days (p. 2) 270 days (p. 22) subscriber or customer for 90 dyas, which data for 90 days. (p.11) indefinitely and transactional records preserve files requested for IP logs retained for 6 months (p. preservation request has days but will be retained certain periods of time. […] To the extent policy for the regular
retained? How Twitter's real-time nature, some information shorter or longer (p. 6) "By default we will return login. or removed from an active days; trash mail retained 30 days or days or less unless user empties trash, which may be extended for an additional 90 days by for two years. PayPal keeps all records 90 days (p. 4) 3) been made (pp. 1-2) longer if given a information that was scheduled to be purging or removal of
long in reponse may only be stored for a very brief period of depending (p. 5) data no older than 90 days • Private Messages in an active profile. Once a change is less unless user empties trash, permanently deletes message (page 7) a request to extend the preservation." (p. 11) indefinitely (p. 1) preservation request (p. 3) deleted needs to be retained by Tagged account records but
to preservation time." prior to the date we account User's Inbox - Retained made, existing information is which permanently deletes message • "MySpace honors all law enforcement due to an on-going law enforcement communication data may
request? receive the request." (p. until user removes them. overwritten." (p.7) (page 7) preservation requests made during the period the investigation, Tagged will do so in response be missing or incomplete
2) • Sent Mail - Retained for 14 • MySapce has different • Law enforcement can request data is available. MySpace also automatically to a written law enforcement preseration after 6 months." (p. 1)
days. retention times for different preservation for longer (p.7) preserves the data of users who are identified as request."
• Trash Mail - Retained 30 days or types of info but law • Pursuant to preservation request: registerd sex offenders and removed from the • IP logs "are saved for 6 months"
less. Users can empty their trash enforcement can request 90 days but can be extended an MySpace site pursuant to MySpace's Sentinel SAFE • Private messages "are retained until the
at any time. preservation for longer (p. 8) extra 90 (p. 8) Project." (p.6) user removes them. Tagged may be able
• Deleted Accounts - No mail is • Messages retained as long • Pursuant to preservation request: "MySpace will to recover them if the sender's Tagged
available for deleted accounts. as not deleted; sent mail preserve the specific information identified in the User ID or email address is provided."
• User ID, IP Address, Login date retained for 14 days; trash request for up to 180 days and will extend the • Sent Mail "is only retained if the user
stamps are retained for up to 90 mail retained 30 days or less preservation as necessary at your request." (p. 8) saves their outgoing messages."
days after account unless user empties trash, • Trash Mail "(mail that has been read and
• Profile information is available which permanently deletes discarded) is retained 30 days or less."
for up to ten days after account message (p. 7) • Deleted Accounts "mail is available for
deletion.(p. 3) deleted accounts with the same rules as
active accounts."
(pp. 7-8)

Is content that unclear Content available as long • If user has saved If messages are retained • MS cannot recover deleted • Myspace doesn't retain User can delete and modify account User can delete and modify (p. 6) Does not say • "A preservation creates a snapshot of the information in "Yahoo! will be unable to search for and Does not say whether deleted email can be recovered Does not say Does not say Active users can delete files • Describes that "accounts which Does not say • Active users can modify • Users can delete or modify information Does not say
has been as not deleted by user messages, they can be by user, they are available messages unless it is in another altered or removed info. (p.8) • "Upon receipt of a preservation request, or about the account at a particular point in time, but there produce deleted material, including email and from account (p. 4) have been deleted by either MYB and delete account (p. 7)
changed or (page 4) recovered. If deleted by (page 4) user's Sent Mail; However, MySpace may be If user deletes account: however, MySpace will capture all user data is no update of the information throughout the Group posts, unless such requrest is received staff or the user will not have infomration and files (p. 3) • Mail is retained until user deletes the
deleted by user user, they cannot be • "MySpace.com does not retain able to retreive deleted • "User identity and date in the user available at that time, and future actions by the preservation period." (p. 22) within 24 hours of the deletion and is any images available." (p. 3) • Does not say whether messages, though undeleted mail can be
(including recovered (page 7) information that is altered/ messages from another user profile is generally available for up user will not affect the preserved data."(p. 6) • Free MSN and Hotmail accounts are "typically deleted specifically requestsed by prior legal process. • "Accounts which have been there is a different accessed after users delete accounts with
private • If a profile is changed or removed on an active profile. who sent or received email. to 10 days after account deletion. • "User identity information is available for one after 60 days of inactivity. Then if the user does not In most cases where deleted content is deleted by MYB staff or deleted retention schedule for Tagged (p. 7)
messages) still updated, deleted content Once a change is made, existing User ID, IP Address, Login Other stored files, such as photos, year after account deletion. Other stored files, reactivate their account, the free MSN Hotmail and free requested, Yahoo! will seek reimbursement for by the user cannot be seen on email messages
available? is not retained (page 6) information is overwritten." (p.3) date stamps are retained for may be lost at the time of such as photos, may be lost at the time of account Windows Live Hotmail account will become inactive after a any engineer time incurred in connection with the site. Like active accounts, all
up to 90 days after account account deletion." deletion." period of time." (p. 7) the request." (p. 7) information is still available
deletion. Profile information is • "User ID, IP Address and Login • "MySpace retains Friend ID, IP Address and • Microsoft only stores the "e-mails a user has elected to except for profile pictures." (p.
available for up to ten days date stamps are retained for up to Login time and date stamps dating back one year." maintain in the account." (p. 8) 3)
after account deletion. (p. 7) 90 days after account deletion. • "No private messages (inbox or sent mail) are • Does not say regarding private
• no mail is available for deleted available for deleted accounts (except those messages.
accounts (p.8) deleted through our Sentinel SAFE project)." (p. 7) • Regarding instant messages
"No general records are kept on
instant messages. If a member
is reporting a violation of TOS,
the conversation is saved and
provided to MYB. Those IM
conversations are retained."

Can law "Twitter's policy is to notify users of requests Does not say Will normally disable Will normally disable "If restricting the user's access to Will lock accounts but keep • Default upon preservation request • Default upon preservation request is that Does not say Does not say Does not say Does not say Does not say Does not disclose law enforcement Does not say Does not say On discovery of illegal Does not say Once preservation request is received "the "In the legal
enforcement for their information prior to disclosure account unless law account unless law the profile will impede an them viewable upon receiving is that account is still publicly account is still publicly viewable but user will no inquiries to account holders (p. 1) activity, account is account will still be publicly viewable, the documentation please be
monitor user unless we are prohibited from doing so by enforcement clearly enforcement clearly investigation, you can request preservation request. Law viewable but user will no longer be longer be able to log into account (p. 8) disabled and member is user will not be able to log into his/her specific if the account
account without statute or court order." specify that doing so will specify that doing so will that private messages be output enforcement can ask not to able to log into account (p. 8) • upon law enforcement request that user not be informed that law account, information in the Sent Mail/Trash should remain enabled. If
user knowledge? hurt investigation (page 5) hurt investigation (page 2) to flat file for preservation before lock but then user still has • upon law enforcement request notified of investigation, MS "will output to a flat enforcement have been folder is still subject to automatic IMVU becomes aware of
a subpoena is served." (p.4) ability to delete and modify that user not be notified of file the specific information for which preservation contacted (p. 2) deletion." an account with suspicious
(pp. 8, 9) investigation, MS "will output to a is sought that is available at the time the request "If restricting the user's access to the or illegal activity it will
flat file the specific information for is processed." In this situation, user retains access profile will impede and investigation, you likely be disabled. If
which preservation is sought that is to account, and "interim changes . . . may not be may request that private messages be leaving an account
available at the time the request is recorded." (p. 8) output to a flate file for peservation before enabled will assist in an
processed." In this situation, user a subpoena is served.You must specifically investigation, please make
retains access to account, and request in the letter that the user not be sure this is stated when
"interim changes . . . may not be notified of the investigation if you do not submitting the subpoena,
recorded." (p. 8) want the subject account to be locked." search warrant, or other
(p. 8) court-ordered demand."
(p. 2)
Does site have Does not say. Does not say Can provide upon Can provide upon "MySpace may disclose private Does not say MySpace can disclose info when it MySpace can disclose info when it "believes in MSN "will respond to emergency MSN "will respond to emergency requests outside normal "Yahoo! Is permitted, but not required, to "The Stored Communications Act permits an Internet Does not say Has a "First Responder" service that "Photobucket will also Does not say Does not say Can release when it Does not say Does not say
exception for answering 3 questions: answering 3 information to law enforcement "believes in good faith that an good faith that an emergency involving danger of requests outside normal business business hours if the emergency involves 'the immediate voluntarily disclose information, including service provider to disclose the content of electronic or can return calls within 24 hours and exercise its discretion under "believes in good faith that
emergency Describe emergency? questions:Describe without a subpoena in limited, emergency involving danger of death or serious physical injury to any person hours if the emergency involves 'the danger of death or physical injury to an person . . .' as contents of communications and customer wire communications or customer records to law process complaints quickly (pp. 1-2) the SCA to release an emergency involving
disclosure? Provide ID of users emergency? Provide ID of emergency situations in which the death or serious physical injury to requires such disclosure without delay." Must meet immediate danger of death or physical defined in 18 U.S.C. § 2702(b)(8) and (c)(4). Emergencies records [. . .] if Yahoo! believes in good faith enforcement 'if the provider, in good faith, believes information without legal danger of death or serious
involved? Provide location users involved? Provide safety of a MySpace user or any person requires such disclosure "ECPA's threshold requirements." (p.11) injury to an person . . .' as defined in are limited to situations like kidnapping, murder threats, that an emergency involving imminent danger that an emergency involving danger of death or process where an imminent physical injury" (p. 4)
of evidence? (pp. 8, 10) location of evidence? (p. member of the public is at risk without delay." Must meet "ECPA's • MS has special 24/7 emergency phone hotline 18 U.S.C. § 2702(c)(4) and (b)(8). bomb threats, terrorist threats, etc." (p. 3) of death or serious physical injury to any serious physical injury to any person requires threat of death or serious
5) and there is insufficient time for threshold requirements." (p.12) (p.11) Emergencies are limited to situations person requires such disclosure without disclosure withouot delay of communications [or physical injury to a person
the law enforcement agency to • MS has special 24/7 emergency • Form asks 3 questions: nature of emergency? like kidnapping, murder threats, bomb delay." (p. 12) records] relating to the emergency.'" exists that necessitates
obtain a subpoena." (p.3) phone hotline (p.12) Whose death/serious physical injury is threatened? threats, terrorist threats, etc." (p. 1) • Emergency disclosure request has set of "In the event of an emergency, please telephone AOL's disclosure"
• Form asks 3 questions: nature of What information that MS has is needed? (p. 14) seven questions: Nature of emergency? Who Public Safety and Criminal Investigations unit at Asked to provide information
emergency? Whose death/serious is threatened? What is nature of threat? Why [redacted] and provide us with specific facts on the nature of the
physical injury is threatened? What would normal disclosure be insufficient? What concerning the emergency that you believe requires emergency, the name of the
information that MS has is needed? info is needed? Explain how info will avert immediate disclosure of communications or records person who is threatened, the
(page 16) threat? Attach any electronic evidence of relating to the emergency." specific information in
threat? (p. 16) The specific facts should include: description of the Photobucket's possession
emergency, explanation that the danger is imminent, related to the emergency. (p.
what specific records are needed 5)
(p. 13)
Does site charge Does not say. Reserves right to charge Reserves the right to Does not say Does not say Does not say Does not say Does not say Does not say Does not say Federal law "requires law enforcement to Does not say Does not say Does not say Does not say Does not say Does not say Does not say Does not say Does not say
law enforcement reasonable fees (p. 2) charge reasonable fees (p. reimburse providers like Yahoo! for costs
fees? 5) incurred responding to subpoena requests,
court orders, or search warrants."
Lists a fee schedule:
• Basic subscriber records: "approx. $20 for
the first ID, $10 per ID thereafter"
• Basic Group Information (including
information about moderators): "approx $20
for a group with a single moderator"
• Contents of subscriber accounts, including
email: "approx. $30-$40 per user"
• Contents of Groups: "approx. $40-$80 per
group" (p. 12)
• Also, where deleted content is requested,
Yahoo! will seek reimbursement for any
engineer time incurred in connection with the
request." (p. 7)

What are the "Preservation requests must be signed, Request to preserve that Request to preserve from Request to preserve from Does not say Signed fax on law Signed fax on letterhead (page 8) Signed fax or email on letterhead (p. 8) Does not lay out specific requirements Preservation request from law enforcement (p. 22) Sent by fax (p. 11) Signed fax on department letterhead with law "Official requests for release of Signed fax on department letterhead Correspondence must include Faxed requests (p. 1) Requests involving legal Correspondence must Faxed letter on department letterhead (pp. When requesting account
requirements to include a valid return email address, and includes law enforcement law enforcement with ID, law enforcement, with ID, enforcement letterhead with but fax numbers and hotline are listed. enforcement ID (pp. 11-12) records can be submitted by email, for user contact info, subpoena, court contact information where process must be sent via identify officer and 6, 13) data, subpoena or search
begin preserving sent on law enforcement letterhead." officer ID, contact name of agency, and name of agency, and contact info (pp. 8, 13) (p. 1) fax, or mail." order, or search warrant requierd for files will be sent (p. 6) fax and certified mail (p. information sought (pp. 4- warrant are required (p. 2)
records? informtion, name of contact info (p. 5) contact info (p. 3) full records (p. 2) 1) 5)
agency (p. 3)
Does site Not addressed specifically, but Twitter Will disable accounts that Will disable fake police Will "always disable No warning about deleting fake No warning about deleting No warning about deleting fake No warning about deleting fake police accounts No warning about deleting fake police No warning about deleting fake police accounts No warning about deleting fake police No warning about deleting fake police accounts No warning about deleting fake No warning about deleting fake police No warning about deleting No warning about deleting fake No warning about deleting No warning about deleting No warning about deleting fake police No warning about deleting
address fake acknowleges that users may create fake or violate terms of service, accounts (p. 3) accounts that supply false police accounts fake police accounts police accounts accounts accounts police accounts accounts fake police accounts police accounts fake police accounts fake police accounts accounts fake police accounts
accounts created anonymous profiles including fake police or misleading profile
by law However, Twitter's "Rules" prohibit accounts (p. 2) information or
enforcement? impersonation: "You may not impersonate attempt to technically or
others through the Twitter service in a socially circumvent site
manner that does or is intended to mislead, privacy measures." (p. 2)
confuse, or deceive others"

Can user consent Yes - Twitter may "share or disclose your Does not say Will release data upon Does not say Does not say Can get user consent (p. 14) Can get user consent (page 15) Can get user consent (p. 13) Does not say Does not say Can get user consent (p. 13) Will release data upon user consent through form (p. Does not say Does not say Can get user consent (p. 4) Will accept user consent (page Does not say Does not say Can get user consent (p. 14) Does not say
to data release? information with your consent, such as when user consenting through 14) 3)
you use a third party web client to access form (pp. 8, 11)
your Twitter account"
How will site Does not say. Generally through email Generally through email Does not say Does not say Delivered in electronic files Delivered in electronic files (9-11) Delivered via email in Excel spreadsheet (p. 8) Does not say Does not say Unclear how Yahoo! delivers information mail (p. 8) Can respond via fax, email, or mail Provides records electronically, via Delivered via CD (p. 6) Does not say Can send via mail (p. 2) Delivered via email (p. 5) Looks like it is delivered electronically (pp. Does not say
deliver data? (p. 3) (p. 5) (spreadsheet) (p. 10) secure website, or CD via Fed Ex (p. 1) 10-11)
Other info? N/A Facebook may be able to "Special Requests": "We are required to • MS "recommend[s]" that law "MySpace is committed to a "MySpace is committed to a high • Guide potentially contains a quick reference Much of guide is devoted to describing the various online Contains a search warrant directory page, listing fax The guide is a page from Craigslist's • Law enforcement must provide a • The guide lays out how it MYB takes a snap shot of the site Ning's guide is particularly Guide contains a page devoted to • Disclaimer that IMVU
retrieve specific Facebook may be able to disable accounts engaged enforcement agents create an high level of cooperation with level of cooperation with law sheet for law enforcement, including a chart services offered by MSN, such as Windows Live, Xbox Live, numbers for fed and military warrants, state or local website: minimum of name, email address and reports accounts containing every night and is kept on a directed toward the "Understanding IP Addresses" (p. 15) and does not verify customer
information not described retrieve specific in illegal activity, even if account "to understand the full law enforcement to assist in enforcement to assist in showing what legal process MS thinks is required MSN, MSN Groups, Windows Live Spaces (p. 4) agencies, and particular jurisdictions, including http://www.craigslist.org/about/hel User Name (for eBay investigations) to child pornography, using backup file for 7 days. After 7 discovery of child a page with "Websites and Resources" for data (p. 1)
in guide (p. 5) information not described that activity is brought to functionality of the site." (p.1) investigating and identifying investigating and identifying those for different types of information. (p. 16) California, Florida, Minnesota, Washington (state), p/subpoenas_and_search_warrants locate the correct account. (p. 1) NCMEC Reporting. (p. 5) days, the file is deleted. MYB pornography, outlining LE (p. 16) • If request is related to
in guide (p. 9) our attention through a • approximately a 2-week those involved in electronic involved in activity that • First time MySpace's Sentinel SAFE project is New York • The guide contains an FAQ also keeps the file taken on the NCMEC Reporting ID theft, victims can
request for records." (p.5) turnaround for responding to crime and other crime with an undermines this vision." (p.3) detailed. The project removes users identified as (p. 10) • Turnaround time for requests is for law enforcement along last calendar day of the month requirements, as well as request information
"court-requested information" (p. electronic component"(p.4) sex offenders. "The information contained in and The site also has a three paragraph description of typically 10-15 business days (p. 2) with information on how the for two months before deleting outlining ways internationa without a subpoena or
4) related to the profile, including photos, private BEBO searches and the information it can provide to data it sends to LE is it. (p. 4) jurisdictions can use ECPA warrant (page 2)
• User info on site "is not messages, etc. are preserved by MySpace." (p. 6) LE (p. 19) • but Ebay/PayPal make" listing and formatted (pp. 6-7) to get information (p. 3)
necessarily accurate. Users do not MySpace also automatically preserves the data of member information immediately • This guide has what Ning also says that if LE
need to confirm their email users who are identified as registerd sex available to law enforcement via appears to be the same wants child pornography
address, nor provide verified offenders. (p.6) Leadsonline's First Responder Service." reference sheet obtained in mailed to it, it must
information. Users may also fake • Guide includes information telling law (p. 1) either the 2005 or 2007 directly mandate so in the
IP addresses if they use a proxy." enforcement agents where to find MySpace MySpace guide (p. 8) search warrant, as Ning
(p.3) information that may reside on a user's computer, does not want to be
• MS terms of service allows MS such as MySpace Messenger IM client logs, cookie prosecuted for
to "review 'private' content at our data, cached MySpace pages, and stored login transmission of child
discretion." (p. 6) information. (pp. 7-8) pornography (p. 2)

Sample forms or N/A N/A Emergency Disclosure Emergency Disclosure "The time will come when you Sample Supoena (p.12), Sample subpoena and search Sample subpoena and search warrant letter (pp. Yahoo! provides sample preservation request Sample subpoena language and subpoena format Language for preservation sample subpoena (p. 12), sample Guide instructs that "When
sample Form, User Consent to Form need to draft a subpoena in order Preservation Request Letter warrant language (p.12), 11-12), preservation request letter (p. 12), letter (p. 14), sample language for requirements (pp. 7-8), sample search warrant (p. 9), and emergency requests (pp. preservation request letter (p. 13), sample requesting account data,
language? Release Form to request private information" so (p13), Consent Form (p.14) Preservation Request Letter (p.14), consent form (p. 13), emergency disclosure form subpoenas, court orders, and search warrants sample preservation request (pp. 11-12), emergency 4-5) consent form (p. 14) please have the subpoena
MS includes info on how to draft Consent Form (p.15), Emergency (p. 14). (p. 15), emergency disclosure request (p. 16), voluntary disclosure request (p. 13), user consent or search warrant request:
subpoenas and court orders (p.4) Disclosure Form (p16) and sample consent form (p. 17) form (p. 14) 'Account data for the
account(s) matching the
Avatar name, e-mail or IP
addresses [insert known
data here] and for any
account(s) that appears to
be controlled by the same
person." (p. 2)

Electronic Frontier Foundation Page 1 of 1 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Date Undated 2008 2009 2010 2005 March 2006


Date, length, link Available on Twitter site at: February 2008, five pages 2009, 11 pages May 2010, 5 pages September 2, 2005, 7 pages March 13, 2006, 16 pages
(if available) and http://support.twitter.com/entries/41949-
other info guidelines-for-law-enforcement

How does Guide Addresses but does not distinguish: "We Does not say • Subpoena for non- "we will provide records as • Most profile information is "Most profile information is
address Legal require a subpoena, court order, or other content (basic subscriber required by law." (p.2) publicly viewable and available. publicly viewable and
Process valid legal process to disclose information info), Publicly available information available." (Guide includes
Requirements about our users." • ECPA 2703(d) order for includes journal entries (in most instructions for law
under Electronic limited content (e.g. cases), images, user comments, enforcement to download this
Communications By default, most Twitter profile information messages over 180 days), and public profile information." info)
Privacy Act is public. This includes, according to the • search warrant for (p.2)
(ECPA)? privacy policy, name and username. It also remaining content (p. 3) • MS requires a subpoena for • Non-public information
may include a short bio, cell phone number, following info: requires subpoena, search
location, address book, a picture, "the -IP logs (recorded at time of warrant, or other legal process
messages you Tweet and the metadata login), Dates and times of login
provided with Tweets, such as when you (PST), Email address, ZIP code, • Non-public info includes: IP
Tweeted, but also the lists you create, the name, private messages (pp.2-3) logs (recorded at time of
people you follow, the Tweets you mark as login), Date profile created,
favorites or Retweet and many other bits of Dates and times of login, E-
information." mail address, ZIP code,
Name, Private Messages,
"Non-public information about Twitter users Private blogs (some info may
is not released unless we have received a not be accurate) (p. 6)
subpoena, court order, or other valid legal
process document." • Information provided in
response to subpoena: email
address, IP Logs, private
messages (p.10)

How does site Law Enforcement Guide, TOS & Privacy Does not distinguish User ID number, email User ID number, email Guide only distinguishes between Guide only distinguishes
define and/or Policy only distinguish between public and between basic subscriber address, time account was address, date/time account public and non-public information between public and non-public
distinguish non-public information information and other created, most recent was created, most recent (p.2) information (p. 6)
different types of information (p. 4) logins, registered mobile logins, registered mobile
user information number, whether account number (p. 4)
is publicly viewable (p. 6)
"Expanded Subscriber
"User Neoprint": Contact Content (sometimes
information, mini-feed, referred to as Neoprint)":
status update history, Contact information, mini-
shares, notes, wall posts, feed, status update
friend listings (including history, shares, notes, wall
their IDs), group listings postings, friend listings
(including group member (include friend IDs), group
IDs), future and past listings (including group
events, video listings (p. 6) member IDs), future and
past events, video listings
(p. 4)

Electronic Frontier Foundation Page 1 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

What other info Twitter does not host any content other than User photos, group contact "User Photoprint": User "User photos (sometimes unclear Unclear whether photos and
is available? tweets. This includes any video or images information (p. 4) uploaded photos and referred to as User other content are released (p.
that users may share through their photos tagged with user's Photoprint)": User 6)
accounts. name, group contact uploaded photos and
information, private photos tagged with user's
messages (p. 7) name, group information,
private messages (p. 4)
How does LE Twitter's servers automatically record • Logs are available and • now have a limited • IP logs contain same IP Logs are available for up to Available through subpoena.
Guide address IP information ("Log Data"), which may include include: Script - script capacity of retrieving data as 2008/09 and also ninety days after a user's last Info includes time and date
and other logs? information such as IP address, browser executed, Scriptget - specific logs and are include Session Cookie -- login.(p.3) stamp (p. 10)
type, the referring domain, pages visited, additional information technically limited in HTTP cookie set by user
and search terms. Other actions, such as passed to the script, providing "everything" session
interactions with advertisements, may also Userid - Facebook user id within a requested date • Logs are often
be included in Log Data. of the account active for range. We are unable to incomplete, but if available
the request, View time - testify to the completeness will be provided (p. 4)
date of execution in Pacific of the data.
Time, IP - source address • Logs include same data
as 2008
• IP logs contain content
and are treated as such
under ECPA
(p. 7)
How long is data "Twitter retains different types of information 90 days (page 3), though 90 days, but an extension 90 days, but an extension • IP Logs are available for up to • "MySpace does not retain
generally for different time periods. Given Twitter's IP data may be retained can be made if necessary can be made if necessary. ninety days after a user's last information that is altered on
retained? How real-time nature, some information may only shorter or longer (p. 6) "By default we will return login. or removed from an active
long in reponse be stored for a very brief period of time." depending (p. 5) data no older than 90 days • Private Messages in an active profile. Once a change is
to preservation prior to the date we account User's Inbox - Retained made, existing information is
request? receive the request." (p. 2) until user removes them. overwritten." (p.7)
• Sent Mail - Retained for 14 • MySapce has different
days. retention times for different
• Trash Mail - Retained 30 days or types of info but law
less. Users can empty their trash enforcement can request
at any time. preservation for longer (p. 8)
• Deleted Accounts - No mail is • Messages retained as long as
available for deleted accounts. not deleted; sent mail retained
• User ID, IP Address, Login date for 14 days; trash mail
stamps are retained for up to 90 retained 30 days or less unless
days after account user empties trash, which
• Profile information is available permanently deletes message
for up to ten days after account (p. 7)
deletion.(p. 3)

Electronic Frontier Foundation Page 2 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Is content that unclear Content available as long • If user has saved If messages are retained • MS cannot recover deleted • Myspace doesn't retain
has been as not deleted by user messages, they can be by user, they are available messages unless it is in another altered or removed info.
changed or (page 4) recovered. If deleted by (page 4) user's Sent Mail; However, MySpace may be
deleted by user user, they cannot be • "MySpace.com does not retain able to retreive deleted
(including recovered (page 7) information that is altered/ messages from another user
private • If a profile is changed or removed on an active profile. who sent or received email.
messages) still updated, deleted content is Once a change is made, existing User ID, IP Address, Login
available? not retained (page 6) information is overwritten." (p.3) date stamps are retained for
up to 90 days after account
deletion. Profile information is
available for up to ten days
after account deletion. (p. 7)

Can law "Twitter's policy is to notify users of requests Does not say Will normally disable Will normally disable "If restricting the user's access to Will lock accounts but keep
enforcement for their information prior to disclosure account unless law account unless law the profile will impede an them viewable upon receiving
monitor user unless we are prohibited from doing so by enforcement clearly specify enforcement clearly specify investigation, you can request preservation request. Law
account without statute or court order." that doing so will hurt that doing so will hurt that private messages be output enforcement can ask not to
user knowledge? investigation (page 5) investigation (page 2) to flat file for preservation before lock but then user still has
a subpoena is served." (p.4) ability to delete and modify
(pp. 8, 9)

Does site have Does not say. Does not say Can provide upon Can provide upon "MySpace may disclose private Does not say
exception for answering 3 questions: answering 3 information to law enforcement
emergency Describe emergency? questions:Describe without a subpoena in limited,
disclosure? Provide ID of users emergency? Provide ID of emergency situations in which the
involved? Provide location users involved? Provide safety of a MySpace user or
of evidence? (pp. 8, 10) location of evidence? (p. 5) member of the public is at risk
and there is insufficient time for
the law enforcement agency to
obtain a subpoena." (p.3)

Electronic Frontier Foundation Page 3 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Does site charge Does not say. Reserves right to charge Reserves the right to Does not say Does not say Does not say
law enforcement reasonable fees (p. 2) charge reasonable fees (p.
fees? 5)

What are the "Preservation requests must be signed, Request to preserve that Request to preserve from Request to preserve from Does not say Signed fax on law enforcement
requirements to include a valid return email address, and includes law enforcement law enforcement with ID, law enforcement, with ID, letterhead with contact info
begin preserving sent on law enforcement letterhead." officer ID, contact name of agency, and name of agency, and (pp. 8, 13)
records? informtion, name of contact info (p. 5) contact info (p. 3)
agency (p. 3)
Does site Not addressed specifically, but Twitter Will disable accounts that Will disable fake police Will "always disable No warning about deleting fake No warning about deleting fake
address fake acknowleges that users may create fake or violate terms of service, accounts (p. 3) accounts that supply false police accounts police accounts
accounts created anonymous profiles including fake police or misleading profile
by law However, Twitter's "Rules" prohibit accounts (p. 2) information or
enforcement? impersonation: "You may not impersonate attempt to technically or
others through the Twitter service in a socially circumvent site
manner that does or is intended to mislead, privacy measures." (p. 2)
confuse, or deceive others"

Can user consent Yes - Twitter may "share or disclose your Does not say Will release data upon user Does not say Does not say Can get user consent (p. 14)
to data release? information with your consent, such as when consenting through form
you use a third party web client to access (pp. 8, 11)
your Twitter account"
How will site Does not say. Generally through email Generally through email Does not say Does not say Delivered in electronic files
deliver data? (p. 3) (p. 5) (spreadsheet) (p. 10)

Electronic Frontier Foundation Page 4 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Other info? N/A Facebook may be able to "Special Requests": "We are required to disable • MS "recommend[s]" that law "MySpace is committed to a
retrieve specific Facebook may be able to accounts engaged in illegal enforcement agents create an high level of cooperation with
information not described retrieve specific activity, even if that account "to understand the full law enforcement to assist in
in guide (p. 5) information not described activity is brought to our functionality of the site." (p.1) investigating and identifying
in guide (p. 9) attention through a • approximately a 2-week those involved in electronic
request for records." (p.5) turnaround for responding to crime and other crime with an
"court-requested information" (p. electronic component"(p.4)
4)
• User info on site "is not
necessarily accurate. Users do not
need to confirm their email
address, nor provide verified
information. Users may also fake
IP addresses if they use a proxy."
(p.3)
• MS terms of service allows MS
to "review 'private' content at our
discretion." (p. 6)

Sample forms or N/A N/A Emergency Disclosure Emergency Disclosure "The time will come when you Sample Supoena (p.12),
sample Form, User Consent to Form need to draft a subpoena in order Preservation Request Letter
language? Release Form to request private information" so (p13), Consent Form (p.14)
MS includes info on how to draft
subpoenas and court orders (p.4)

Electronic Frontier Foundation Page 5 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MSN MSN
Date June 2006 2007 2006 2008
Date, length, link June 23, 2006, 16 pages November 1, 2007, 15 pages July 2006, 2 pages March 2008, 22 pages
(if available) and
other info

How does Guide MySpace is both an ECS and RCS "Depending on the type of information sought, ECPA "governs what legal ECPA "sets forth the appropriate legal process required to
address Legal (p.4) ECPA may require the use of a different form of documentation is required in order for compel Microsoft's Online Service Records Custodians to
Process • subpoena for "basic user identity, legal process, and the period MySpace retains the Microsoft's Online Service records disclose customer records and contents"
Requirements log-in information, and stored files", information may differ." (p. 4) custodian to disclose customer account • subpoena for basic subscriber information, including
under Electronic • § 2703(d) court order for "user's • subpoena or § 2703(c)(2) demand for "Basic information and email content." "name, address, length of service (start date), screen
Communications date of birth, gender, hometown, user identity information," including "date profile • subpoena for basic subscriber names, other email acounts, IP address/IP logs/Usage logs,
Privacy Act and occupation, as well as historical created; first and last name provided by user; user information, including "name address, billing information content (other than e-mail, such as
(ECPA)? private message header ID; e-mail address provided by user; ZIP code, length of service (start date), screen Windows Live Spaces and MSN Groups) and e-mail content
information." city, and country provided by user; account names, other email accounts, IP more than 180 days old as long as the governmental entity
• search warrant for private user creation date and time; and the IP address at the address/IP logs/Usage logs, billing follows the customer notification provisions in ECPA (see 18
communications less than 180 days time of sign-up." information, and e-mail content U.S.C. §§ 2703(b), 2705)
old. • subpoena or § 2703(c)(2) demand for historical greater than 180 days old as long as • 2703(d) order "will compel disclosure of all of the basic
• Subpoena or court order with prior "logs showing the IP address assigned to the user the governmental entity follows the subscriber information available under a subpoena pluse
notice to the subscriber (or delayed and the date stamp at the time the user accessed customer notification provisions in the e-mail address book, Messenger contact lists, the rest
notice under 18 U.S.C. § 2705) for his or her profile." ECPA (see 18 U.S.C. § 2705)." (p. 2) of a customer's profile not alread listed above, internet
Stored user files (photos, videos, • Pen register/trap and trace order to "caputre log- • 2703(d) order "will compel disclosure usage logs (e.g. WEBTV or MSN Internet Access), and e-
blogs, classifieds, messages posted in IPs prospectively." of all of the Basic Subscriber mail header information (to/from) excluding subject line."
on forums or groups, address book • Search warrant for messages less than 180 days information available under a • Search warrant "will compel disclosure of all information
and calendar contents) old. sbupoena plus the Address Book, available with a court order issued pursuant to 2703(d) (as
• pen register/trap and trace order • Subpoena or court order (or delayed notice under Buddy Lists, the rest of a customer's listed above), plus all contents (if prior notice is not
for ongoing information about user's 18 U.S.C. § 2705) for messages over 180 days old. profile not already listed above, provided or an order for delayed notice is not obtained),
IP address each time they log-in to • Subpoena, civil investigative demand, or court internet usage logs (WEBTV), e-mail and is the only means to compel the disclosure of e-mails,
their account (pp. 4-7) order for "profile information including photos, header information (to/from) excluding including subject line, in electronic storage 180 days or
• Law enforcement can obtain videos, blogs, blog comments by other users, the subject line, and e-mail content less."(p. 22)
publicly available info without identities fo the friends and 'About Me' entries." greater than 180 days old as long as • "as Microsoft receives and processes legal
MySpace's assistance. (p. 4,5) • § 2703(d) court order for "user's date of birth, the governmental entity follow the process for its online services in the Ninth Circuit,
gender, hometown, and occupation, as well as customer notifications provisions of [pursuant to Theofel et al v. Farey-Jones, 341 F.3d 978
historical private message header information, ECPA (see 18 U.S.C. § 2705)." (p. 2) (9th Cir. 2003)]Microsoft discloses both opened and
excluding subject."(pp. 5-6) • search warrant is required for all unopened e-mail in electronic storage for 181 days or less
email content under 180 days. (p. 2) only upon pursuant to a search warrant.

How does site basic "user" ID info including user's Basic user ID (subpoena): date profile created, Basic (subpoena): name, address, Basic (subpoena): name, address, length of service, screen
define and/or name, email address, ZIP code, city name, user ID, email address, ZIP code, city, length of service, screen names, IP names, IP address, IP logs, billing info, email greater than
distinguish & country, account creation county, account creation date, IP address; other address, IP logs, billing info, email 180 days (p. 22)
different types of date/time, IP address at time of (court order) IP logs, birthday (pp. 5-6) greater than 180 days (p. 2)
user information signup -- all available via subpoena Full profile (court order): address book, buddy list, email
(pp. 6-7) Search warrant: private messages less than 180 Full profile (court order): address header info, email content great than 180 days; Email
days old (p. 5) book, buddy list, email header info, (warrant): all messages less than 180 days old (p. 22)
user's birthday, gender, hometown, email content great than 180 days;
occupation, private message header Email (warrant): all messages less
information; search warrant: than 180 days old (p. 2)
messages less than 180 days old --
all available via court order: (p. 6)

Electronic Frontier Foundation Page 6 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MSN MSN
What other info Photos, videos, blogs, classifieds can Photos, videos, blogs available with subpoena or MSN groups and spaces are considered Can get this information from all of MSN services, such as
is available? be disclosed with a subpoena (pages court order (p. 6) public, and will be disclosed with Xbox Live, Windows Live, etc. (p. 4)
6-7) subpoena (p. 2)

How does LE Can be produced with subpoena (p. Can be produced with court order (p. 5) Can be produced with subpoena (p. 2) Can be produced with subpoena (p. 22)
Guide address IP 6) Info includes IP address, date and
and other logs? time of log-in at time user accesses
profile. Historic IP logs are available,
and MySpace can capture IP logs
prospectively with Pen/Trap order.

How long is data • Messages retained as long as not • Messages retained as long as not deleted; sent 90 days from date of request, but can 90 days from date of request, but can preserve for up to
generally deleted; sent mail retained for 14 mail retained for 14 days; trash mail retained 30 preserve for up to 270 days (p. 2) 270 days (p. 22)
retained? How days; trash mail retained 30 days or days or less unless user empties trash, which
long in reponse less unless user empties trash, permanently deletes message (page 7)
to preservation which permanently deletes message • "MySpace honors all law enforcement
request? (page 7) preservation requests made during the period the
• Law enforcement can request data is available. MySpace also automatically
preservation for longer (p.7) preserves the data of users who are identified as
• Pursuant to preservation request: registerd sex offenders and removed from the
90 days but can be extended an MySpace site pursuant to MySpace's Sentinel SAFE
extra 90 (p. 8) Project." (p.6)
• Pursuant to preservation request: "MySpace will
preserve the specific information identified in the
request for up to 180 days and will extend the
preservation as necessary at your request." (p. 8)

Electronic Frontier Foundation Page 7 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MSN MSN
Is content that User can delete and modify account User can delete and modify (p. 6) Does not say • "A preservation creates a snapshot of the information in
has been (p.8) • "Upon receipt of a preservation request, however, or about the account at a particular point in time, but there
changed or If user deletes account: MySpace will capture all user data available at that is no update of the information throughout the preservation
deleted by user • "User identity and date in the user time, and future actions by the user will not affect period." (p. 22)
(including profile is generally available for up the preserved data."(p. 6) • Free MSN and Hotmail accounts are "typically deleted
private to 10 days after account deletion. • "User identity information is available for one after 60 days of inactivity. Then if the user does not
messages) still Other stored files, such as photos, year after account deletion. Other stored files, reactivate their account, the free MSN Hotmail and free
available? may be lost at the time of such as photos, may be lost at the time of account Windows Live Hotmail account will become inactive after a
account deletion." deletion." period of time." (p. 7)
• "User ID, IP Address and Login • "MySpace retains Friend ID, IP Address and Login • Microsoft only stores the "e-mails a user has elected to
date stamps are retained for up to time and date stamps dating back one year." maintain in the account." (p. 8)
90 days after account deletion. • "No private messages (inbox or sent mail) are
• no mail is available for deleted available for deleted accounts (except those
accounts (p.8) deleted through our Sentinel SAFE project)." (p. 7)

Can law • Default upon preservation request • Default upon preservation request is that account Does not say Does not say
enforcement is that account is still publicly is still publicly viewable but user will no longer be
monitor user viewable but user will no longer be able to log into account (p. 8)
account without able to log into account (p. 8) • upon law enforcement request that user not be
user knowledge? • upon law enforcement request that notified of investigation, MS "will output to a flat
user not be notified of investigation, file the specific information for which preservation
MS "will output to a flat file the is sought that is available at the time the request
specific information for which is processed." In this situation, user retains access
preservation is sought that is to account, and "interim changes . . . may not be
available at the time the request is recorded." (p. 8)
processed." In this situation, user
retains access to account, and
"interim changes . . . may not be
recorded." (p. 8)

Does site have MySpace can disclose info when it MySpace can disclose info when it "believes in MSN "will respond to emergency MSN "will respond to emergency requests outside normal
exception for "believes in good faith that an good faith that an emergency involving danger of requests outside normal business business hours if the emergency involves 'the immediate
emergency emergency involving danger of death or serious physical injury to any person hours if the emergency involves 'the danger of death or physical injury to an person . . .' as
disclosure? death or serious physical injury to requires such disclosure without delay." Must meet immediate danger of death or physical defined in 18 U.S.C. § 2702(b)(8) and (c)(4). Emergencies
any person requires such disclosure "ECPA's threshold requirements." (p.11) injury to an person . . .' as defined in are limited to situations like kidnapping, murder threats,
without delay." Must meet "ECPA's • MS has special 24/7 emergency phone hotline 18 U.S.C. § 2702(c)(4) and (b)(8). bomb threats, terrorist threats, etc." (p. 3)
threshold requirements." (p.12) (p.11) Emergencies are limited to situations
• MS has special 24/7 emergency • Form asks 3 questions: nature of emergency? like kidnapping, murder threats, bomb
phone hotline (p.12) Whose death/serious physical injury is threatened? threats, terrorist threats, etc." (p. 1)
• Form asks 3 questions: nature of What information that MS has is needed? (p. 14)
emergency? Whose death/serious
physical injury is threatened? What
information that MS has is needed?
(page 16)

Electronic Frontier Foundation Page 8 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MSN MSN
Does site charge Does not say Does not say Does not say Does not say
law enforcement
fees?

What are the Signed fax on letterhead (page 8) Signed fax or email on letterhead (p. 8) Does not lay out specific requirements Preservation request from law enforcement (p. 22)
requirements to but fax numbers and hotline are listed.
begin preserving (p. 1)
records?

Does site No warning about deleting fake No warning about deleting fake police accounts No warning about deleting fake police No warning about deleting fake police accounts
address fake police accounts accounts
accounts created
by law
enforcement?

Can user consent Can get user consent (page 15) Can get user consent (p. 13) Does not say Does not say
to data release?

How will site Delivered in electronic files (9-11) Delivered via email in Excel spreadsheet (p. 8) Does not say Does not say
deliver data?

Electronic Frontier Foundation Page 9 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MSN MSN
Other info? "MySpace is committed to a high • Guide potentially contains a quick reference Much of guide is devoted to describing the various online
level of cooperation with law sheet for law enforcement, including a chart services offered by MSN, such as Windows Live, Xbox Live,
enforcement to assist in showing what legal process MS thinks is required MSN, MSN Groups, Windows Live Spaces (p. 4)
investigating and identifying those for different types of information. (p. 16)
involved in activity that • First time MySpace's Sentinel SAFE project is
undermines this vision." (p.3) detailed. The project removes users identified as
sex offenders. "The information contained in and
related to the profile, including photos, private
messages, etc. are preserved by MySpace." (p. 6)
MySpace also automatically preserves the data of
users who are identified as registerd sex offenders.
(p.6)
• Guide includes information telling law
enforcement agents where to find MySpace
information that may reside on a user's computer,
such as MySpace Messenger IM client logs, cookie
data, cached MySpace pages, and stored login
information. (pp. 7-8)

Sample forms or Sample subpoena and search Sample subpoena and search warrant letter (pp.
sample warrant language (p.12), 11-12), preservation request letter (p. 12),
language? Preservation Request Letter (p.14), consent form (p. 13), emergency disclosure form
Consent Form (p.15), Emergency (p. 14).
Disclosure Form (p16)

Electronic Frontier Foundation Page 10 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Yahoo AOL
Date Undated March 2010 Jan 29, 2010 Undated
Date, length, link Undated, 17 pages March 2010, 19 total pages, but were only given 12 Jan. 29, 2010, online document, 1 Undated, two pages
(if available) and (appear to be missing pages 4-6 and 15-18) page, also available at
other info http://www.craigslist.org/about/hel
p/subpoenas_and_search_warrants
How does Guide "ECS for communications including but not Distinguishes between Does not say • signed fax (non-subpoena) "eBay can
address Legal limited to email and Messenger" / "RCS for • subpoena for "subscriber information," including provide the following information for
Process purposes including but not limited to storage "name, email addresses, and screen names, users under investigation of illegal
Requirements of photos and files." addresses, detailed billing records or records of session activity only: contact name, city, state,
under Electronic • subpoena for "basic subscriber information, times and durations, length of service (including start ZIP, and telephone number, all email
Communications contents of communications on RCS, contents date) and types of service utilized, telephone or addrsses and eBay User ID's added to
Privacy Act in electronic storage for over 180 days." instrument number or other subscriber number or account with date/time stamps, eBay
(ECPA)? • 2703(d) order for "transactional records identity, including any temporarily assigned netowrk Fraud complaints (if requested)"
(e.g., Messenger or Chat logs, IP address address, and the means and source of payment for
infomration associated with any activity other such service (including any credit card or bank account • subpoena for "full eBay contact
than log-in), anything obtainable with a number)." details, including the billing and mailing
subpoena." • 2703(d) court order "is required to compel disclosure address, eBay IP addresses: time of
• search warrant for "Contents in electronic of a range of IP connection logs." (p. 12) registration and at time of item listing,
storage for 180 days or less, anything • search warrant for "subscriber information" complete listing and/or bid history - 2
obtainable with a sbupoena or 2703(d) order" obtainable under subpoena, "transactional information, year max (including bidder information
(p. 11) including: logs of Internet Protocol ("IP") address if specifically requested), credit card
connections, including dates, times, and time zones, and checking acount information added
and any ANI information made available to AOL, to an eBay account (if available)"
address books, buddys lists, and account history,
including contacts with AOL support services and • subpoena for all records relating to a
records of action taken online by the subscriber or by PayPal user, including "all PayPal
AOL support staff in connection with the service." account information including, SSN,
• search warrant for "all electronic or wire names, addresses, phone numbers,
communications (including e-mail text, attachments, email addresses, PayPal IP addresses
and embedded files) in electronic storage by AOL, or (at each login), financial instruments
held by AOL as a remote computing service, within the added to PayPal account, complete
meaning of the Stored Communications Act, all photos, PayPal transactional information
files, data, or information in whatever form and by (including complaints if requested and
whatever means they have been created or stored, all available)" (p. 2)
profiles." (pp 7-9)

How does site Subpoena: basic subscriber information, Subpoena will get "subscriber information:" names, Does not say • No legal service required to access:
define and/or contents of communications stored as a email, physical address, billing records, length of Contact information, city, state, ZIP
distinguish remote computing service provider, contents service, phone number, credit card or bank account code, email addresses, fraud
different types of in electronic storage over 180 days (p. 11) numbers, IP addresses (pp. 7-8) complaints, account listings, and bid
user information history (p. 2)
Court order: Transactional records such as IP Search warrant will get "transactional" and
logs, messenger or chat logs; search warrant: "communications" info: IP logs, address books, buddy • Subpoena, court order, or warrant to
contents in electronic storage less than 180 lists, account history, emails (including attachments), access: billing and mailing address, IP
days (p. 11) photos or files stored with AOL (p. 9) addresses, credit card, checking
account information, Social Security
numbers

Electronic Frontier Foundation Page 11 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Yahoo AOL
What other info Can provide files uploaded on Flickr (p. 9) AOL's Bebo service can only be searched with proper Does not say May be able to get information on
is available? ID. Data retained for past 500 days (p. 19) accounts linked/related to subject (p.1)

How does LE IP logs available with a court order (p. 11) 2703(d) court order required (p. 9) Does not say Can be provided (p. 2)
Guide address IP
and other logs?

How long is data "Yahoo! Will preserve information related to a Sample preservation request asks AOL to preserve Does not say eBay keeps most account records
generally subscriber or customer for 90 dyas, which may data for 90 days. (p.11) indefinitely and transactional records
retained? How be extended for an additional 90 days by a for two years. PayPal keeps all records
long in reponse request to extend the preservation." (p. 11) indefinitely (p. 1)
to preservation
request?

Electronic Frontier Foundation Page 12 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Yahoo AOL
Is content that "Yahoo! will be unable to search for and Does not say whether deleted email can be recovered Does not say Does not say
has been produce deleted material, including email and
changed or Group posts, unless such requrest is received
deleted by user within 24 hours of the deletion and is
(including specifically requestsed by prior legal process.
private In most cases where deleted content is
messages) still requested, Yahoo! will seek reimbursement for
available? any engineer time incurred in connection with
the request." (p. 7)

Can law Does not say Does not say Does not say Does not disclose law enforcement
enforcement inquiries to account holders (p. 1)
monitor user
account without
user knowledge?

Does site have "Yahoo! Is permitted, but not required, to "The Stored Communications Act permits an Internet Does not say Has a "First Responder" service that
exception for voluntarily disclose information, including service provider to disclose the content of electronic or can return calls within 24 hours and
emergency contents of communications and customer wire communications or customer records to law process complaints quickly (pp. 1-2)
disclosure? records [. . .] if Yahoo! believes in good faith enforcement 'if the provider, in good faith, believes
that an emergency involving imminent danger that an emergency involving danger of death or
of death or serious physical injury to any serious physical injury to any person requires
person requires such disclosure without disclosure withouot delay of communications [or
delay." (p. 12) records] relating to the emergency.'"
• Emergency disclosure request has set of "In the event of an emergency, please telephone AOL's
seven questions: Nature of emergency? Who Public Safety and Criminal Investigations unit at
is threatened? What is nature of threat? Why [redacted] and provide us with specific facts
would normal disclosure be insufficient? What concerning the emergency that you believe requires
info is needed? Explain how info will avert immediate disclosure of communications or records
threat? Attach any electronic evidence of relating to the emergency."
threat? (p. 16) The specific facts should include: description of the
emergency, explanation that the danger is imminent,
what specific records are needed
(p. 13)

Electronic Frontier Foundation Page 13 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Yahoo AOL
Does site charge Federal law "requires law enforcement to Does not say Does not say Does not say
law enforcement reimburse providers like Yahoo! for costs
fees? incurred responding to subpoena requests,
court orders, or search warrants."
Lists a fee schedule:
• Basic subscriber records: "approx. $20 for
the first ID, $10 per ID thereafter"
• Basic Group Information (including
information about moderators): "approx $20
for a group with a single moderator"
• Contents of subscriber accounts, including
email: "approx. $30-$40 per user"
• Contents of Groups: "approx. $40-$80 per
group" (p. 12)
• Also, where deleted content is requested,
Yahoo! will seek reimbursement for any
engineer time incurred in connection with the
request." (p. 7)

What are the Sent by fax (p. 11) Signed fax on department letterhead with law "Official requests for release of Signed fax on department letterhead
requirements to enforcement ID (pp. 11-12) records can be submitted by email, for user contact info, subpoena, court
begin preserving fax, or mail." order, or search warrant requierd for
records? full records (p. 2)

Does site No warning about deleting fake police No warning about deleting fake police accounts No warning about deleting fake No warning about deleting fake police
address fake accounts police accounts accounts
accounts created
by law
enforcement?

Can user consent Can get user consent (p. 13) Will release data upon user consent through form (p. Does not say Does not say
to data release? 14)

How will site Unclear how Yahoo! delivers information mail (p. 8) Can respond via fax, email, or mail Provides records electronically, via
deliver data? secure website, or CD via Fed Ex (p. 1)

Electronic Frontier Foundation Page 14 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

Yahoo AOL
Other info? Contains a search warrant directory page, listing fax The guide is a page from Craigslist's • Law enforcement must provide a
numbers for fed and military warrants, state or local website: minimum of name, email address and
agencies, and particular jurisdictions, including http://www.craigslist.org/about/hel User Name (for eBay investigations) to
California, Florida, Minnesota, Washington (state), New p/subpoenas_and_search_warrants locate the correct account. (p. 1)
York
(p. 10) • Turnaround time for requests is
The site also has a three paragraph description of typically 10-15 business days (p. 2)
BEBO searches and the information it can provide to
LE (p. 19) • but Ebay/PayPal make" listing and
member information immediately
available to law enforcement via
Leadsonline's First Responder Service."
(p. 1)

Sample forms or Yahoo! provides sample preservation request Sample subpoena language and subpoena format
sample letter (p. 14), sample language for subpoenas, requirements (pp. 7-8), sample search warrant (p. 9),
language? court orders, and search warrants (p. 15), sample preservation request (pp. 11-12), emergency
emergency disclosure request (p. 16), and voluntary disclosure request (p. 13), user consent
sample consent form (p. 17) form (p. 14)

Electronic Frontier Foundation Page 15 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MyYearbook
Date Undated April 2010 July 2009 April 26, 2010 Undated Undated
Date, length, link Undated, eight pages April 2010, four pages July 2009, four pages April 26, 2010, 16 pages Undated, 16 pages Undated, 2 pages
(if available) and
other info

How does Guide "The types of process • No legal process required for "Ning can provide you with Non-public information "To request private (non-public) • subpoena for "basic
address Legal necessary to permit "Public Information," such as the following information requires legal process in information from Tagged about a specific account information" will
Process Photobucket to produce each profile page, profile images. once we receive a compliance with ECPA profile or user, we requires a subpoena, include "avatar name, e-
Requirements category of information under • subpoena for "General subpoena, search warrant search warrant or other legal process. The mail address, customer ID
under Electronic the SCA differs only slightly." Information," including user or court order" following list is private content that is not (all unique) as well as the
Communications • subpoena for "first name, name, user ID, DOB, age, • subpoena for the publicly accessible" IP address used to register
Privacy Act last name, user/screen name, location (if known), school (if registration email of the • "IP logs (recorded at time of login), Date the account and any device
(ECPA)? ZIP code, country, email known), email address, Network Creator and profile created, Dates and times of login fingerprints on file [. . .] If
address, account creation password, date joined, user Members who uploaded (PST), E-mail address provided by user, account communications
date/time" name changes, DOB changes, the content, registration IP ZIP code provided by user, Name provided are requested, IMVU will
• subpoena for "Date and IP violations of terms of service, IP addresses, Usernames, by user, Screen Name, Private Messages" provide the text of web-
for most recent account logs of last 6 months (login times credit card information (if • "The following are only retained if the based messages and a
access, Registration IP, only), IP addresses, date and any) user has not deleted them from their page: summary of realt-time
Banned date/time (if account time logged in, all profile pictures • search warrant for all Confessions, Boxxes, Journals." chats (via IMVU's 3D
banned), Date/Time of Upload in account (though accounts images and videos of (p. 6) client) that will include the
or Modification of file, Upload deleted by MYB or the user suspected child accounts participating in
IP for files uploaded after willnot have any images pornography, date/time chats but not the actual
June 1, 2007" available) stamped IP addresses at text of the chat" (page 1)
• court order, search warrant, • search warrant for time member uploaded
or subpoena where governent "Communications/private content in question, any
provides prior notice to Information," including private and all messages received
subscriber for "image and messagees, instant messages, from creators and
video content in a user's embedded images in messages. members, subject line and
account" (pp. 3-4) (pp. 1-2) date/time stamp of all
automated email
notifications
(pp. 2-3)

How does site Basic user (subpoena): name, Public info available without legal Subpoena: email, IP Subpoena required for Subpoena: IP logs, date profile created, Basic account information
define and/or user name, ZIP code, country, process: Profile page, profile address, username, credit basic user information, log- dates of login, email address, ZIP code, (subpoena): avatar name,
distinguish email, account creation date images; General info card information (if in information, and stored name, screen name (p. 6) email address, customer
different types of (p. 4) (subpoena): user name, ID, available) (pp. 2-3) files (p. 4) ID, IP addresses and
user information birthday, age, location password, Unclear what level of legal process is device fingerprint (p. 1)
IP logs: subpoena, court date joined, changes to profile, Search warrant: Images, Court order required for required for messages (p. 6)
order, search warrant or user IP logs, profile pictures (pp. 1-2) videos, IP address, all full access to profile; Unclear what legal process
consent (p. 4) messages (p. 3) search warrant required for is required for text of web
Communications (search private user messages (p. messages and chat logs (p.
warrant): private messages, 4) 1)
instant messages, any images
embedded in messages (p. 2)

Electronic Frontier Foundation Page 16 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MyYearbook
What other info Images and video available by Does not say Images available with Video, audio, and photo Not clear what level of legal process is Does not say
is available? subpoena if subscriber given search warrant (p. 3) files available via subpoena required for this information
notice; available with court (p. 2)
order or warrant otherwise (p.
4)

How does LE IP logs: subpoena, court Can be produced with subpoena IP addresses can be IP logs available with IP logs are available with subpoena (p. 6) Does not say
Guide address IP order, search warrant or user (p. 2) produced (p. 3) subpoeana (p. 1, 4)
and other logs? consent (p. 4)

How long is data Data is retained one year; will Active accounts kept indefinitely, 90 days unless Most data retained 90 days "Tagged retains information on its users for "IMVU does not have a
generally preserve files requested for IP logs retained for 6 months (p. preservation request has but will be retained longer certain periods of time. […] To the extent policy for the regular
retained? How 90 days (p. 4) 3) been made (pp. 1-2) if given a preservation information that was scheduled to be purging or removal of
long in reponse request (p. 3) deleted needs to be retained by Tagged account records but
to preservation due to an on-going law enforcement communication data may
request? investigation, Tagged will do so in response be missing or incomplete
to a written law enforcement preseration after 6 months." (p. 1)
request."
• IP logs "are saved for 6 months"
• Private messages "are retained until the
user removes them. Tagged may be able to
recover them if the sender's Tagged User
ID or email address is provided."
• Sent Mail "is only retained if the user
saves their outgoing messages."
• Trash Mail "(mail that has been read and
discarded) is retained 30 days or less."
• Deleted Accounts "mail is available for
deleted accounts with the same rules as
active accounts."
(pp. 7-8)

Electronic Frontier Foundation Page 17 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MyYearbook
Is content that Active users can delete files • Describes that "accounts which Does not say • Active users can modify • Users can delete or modify information Does not say
has been from account (p. 4) have been deleted by either MYB and delete account (p. 7)
changed or staff or the user will not have infomration and files (p. 3) • Mail is retained until user deletes the
deleted by user any images available." (p. 3) • Does not say whether messages, though undeleted mail can be
(including • "Accounts which have been there is a different accessed after users delete accounts with
private deleted by MYB staff or deleted retention schedule for Tagged (p. 7)
messages) still by the user cannot be seen on email messages
available? the site. Like active accounts, all
information is still available
except for profile pictures." (p. 3)
• Does not say regarding private
messages.
• Regarding instant messages
"No general records are kept on
instant messages. If a member is
reporting a violation of TOS, the
conversation is saved and
provided to MYB. Those IM
conversations are retained."

Can law Does not say Does not say On discovery of illegal Does not say Once preservation request is received "the "In the legal
enforcement activity, account is disabled account will still be publicly viewable, the documentation please be
monitor user and member is informed user will not be able to log into his/her specific if the account
account without that law enforcement have account, information in the Sent Mail/Trash should remain enabled. If
user knowledge? been contacted (p. 2) folder is still subject to automatic deletion." IMVU becomes aware of an
"If restricting the user's access to the account with suspicious or
profile will impede and investigation, you illegal activity it will likely
may request that private messages be be disabled. If leaving an
output to a flate file for peservation before account enabled will assist
a subpoena is served.You must specifically in an investigation, please
request in the letter that the user not be make sure this is stated
notified of the investigation if you do not when submitting the
want the subject account to be locked." subpoena, search warrant,
(p. 8) or other court-ordered
demand." (p. 2)

Does site have "Photobucket will also Does not say Does not say Can release when it Does not say Does not say
exception for exercise its discretion under "believes in good faith that
emergency the SCA to release an emergency involving
disclosure? information without legal danger of death or serious
process where an imminent physical injury" (p. 4)
threat of death or serious
physical injury to a person
exists that necessitates
disclosure"
Asked to provide information
on the nature of the
emergency, the name of the
person who is threatened, the
specific information in
Photobucket's possession
related to the emergency. (p.
5)

Electronic Frontier Foundation Page 18 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MyYearbook
Does site charge Does not say Does not say Does not say Does not say Does not say Does not say
law enforcement
fees?

What are the Correspondence must include Faxed requests (p. 1) Requests involving legal Correspondence must Faxed letter on department letterhead (pp. When requesting account
requirements to contact information where process must be sent via identify officer and 6, 13) data, subpoena or search
begin preserving files will be sent (p. 6) fax and certified mail (p. information sought (pp. 4- warrant are required (p. 2)
records? 1) 5)

Does site No warning about deleting No warning about deleting fake No warning about deleting No warning about deleting No warning about deleting fake police No warning about deleting
address fake fake police accounts police accounts fake police accounts fake police accounts accounts fake police accounts
accounts created
by law
enforcement?

Can user consent Can get user consent (p. 4) Will accept user consent (page 3) Does not say Does not say Can get user consent (p. 14) Does not say
to data release?

How will site Delivered via CD (p. 6) Does not say Can send via mail (p. 2) Delivered via email (p. 5) Looks like it is delivered electronically (pp. Does not say
deliver data? 10-11)

Electronic Frontier Foundation Page 19 of 20 www.eff.org


SOCIAL MEDIA—A Guide to the Law Enforcement Guides

MyYearbook
Other info? • The guide lays out how it MYB takes a snap shot of the site Ning's guide is particularly Guide contains a page devoted to • Disclaimer that IMVU
reports accounts containing every night and is kept on a directed toward the "Understanding IP Addresses" (p. 15) and does not verify customer
child pornography, using backup file for 7 days. After 7 discovery of child a page with "Websites and Resources" for data (p. 1)
NCMEC Reporting. (p. 5) days, the file is deleted. MYB also pornography, outlining LE (p. 16) • If request is related to ID
• The guide contains an FAQ keeps the file taken on the last NCMEC Reporting theft, victims can request
for law enforcement along calendar day of the month for requirements, as well as information without a
with information on how the two months before deleting it. outlining ways internationa subpoena or warrant (page
data it sends to LE is (p. 4) jurisdictions can use ECPA 2)
formatted (pp. 6-7) to get information (p. 3)
• This guide has what appears Ning also says that if LE
to be the same reference wants child pornography
sheet obtained in either the mailed to it, it must
2005 or 2007 MySpace guide directly mandate so in the
(p. 8) search warrant, as Ning
does not want to be
prosecuted for
transmission of child
pornography (p. 2)

Sample forms or Language for preservation sample subpoena (p. 12), sample Guide instructs that "When
sample and emergency requests (pp. preservation request letter (p. 13), sample requesting account data,
language? 4-5) consent form (p. 14) please have the subpoena
or search warrant request:
'Account data for the
account(s) matching the
Avatar name, e-mail or IP
addresses [insert known
data here] and for any
account(s) that appears to
be controlled by the same
person." (p. 2)

Electronic Frontier Foundation Page 20 of 20 www.eff.org

S-ar putea să vă placă și