Over the past year, the Department of Homeland Security’s use of administrative subpoenas to obtain information about individuals and groups critical of its immigration enforcement efforts has alarmed many lawmakers and members of the public. As worrisome as this practice is, it represents only a small part of a much bigger problem. Numerous federal agencies possess statutory authority to obtain a wide range of highly sensitive information without advance judicial approval or probable cause of illegal activity. While the Supreme Court has stepped in recently to protect one particularly revealing type of information, Fourth Amendment doctrine continues to lag behind the realities of modern technology, leaving Americans’ private data vulnerable to agencies’ expansive administrative subpoena powers.
DHS Use of Administrative Subpoenas
In February, the Washington Post reported the troubling story of a Philadelphia man, identified as Jon, who received notice from Google that the government had subpoenaed his information. The notice arrived just hours after Jon sent an email to a federal prosecutor urging that the government grant asylum to an immigrant he had read about in the news. Jon would later learn that the subpoena, issued by the Department of Homeland Security (DHS), demanded a range of information going back two months, including the day, time, and duration of all of his online sessions; every associated IP address (a numerical code that identifies the network and often the location a person is connecting from) and physical address; a list of each service used; and any alternate usernames and email addresses. With the help of lawyers from the American Civil Liberties Union, Jon challenged the subpoena in court, arguing that it violated the First Amendment and exceeded the scope of DHS’s statutory subpoena authority. Before the court could issue its ruling, DHS withdrew the subpoena.
Jon’s experience is far from an isolated incident. Over the past year, DHS has issued scores of administrative subpoenas to obtain information about online users perceived to oppose its immigration enforcement efforts. Members of Congress and free speech advocates have rightly decried these subpoenas as constitutionally and legally dubious. But when plaintiffs, like Jon, have challenged the subpoenas in court, DHS has withdrawn them, preventing judges from ruling on the merits to halt the practice.
While these subpoenas raise serious First Amendment concerns, DHS’s use — and misuse — of administrative subpoenas is not new. DHS has broad statutory authority to require “the production of books, papers, and documents . . . concerning any matter which is material and relevant to the enforcement of [the Immigration and Nationality Act].” Pursuant to this authority, ICE has issued subpoenas for a wide range of sensitive information, including geolocation data, stored media and communications, and communications metadata. In 2017, the DHS Office of the Inspector General found that Customs and Border Protection personnel “regularly” issued customs summonses — a type of administrative subpoena authorized for investigations of illegal imports or unpaid customs duties — in violation of agency policy.
What Are Administrative Subpoenas?
In contrast to warrants, which authorize the government to conduct a direct search of someone’s person, property, papers, and effects (e.g., by searching their home or placing a wiretap), subpoenas instruct the recipient to search for and turn over the requested items or information and can be contested by the recipient in court. They are frequently served on third parties, often companies, that hold records about the person or entity being investigated — records that have historically been given diminished privacy protections. For these reasons, the law has traditionally treated subpoenas quite differently from other types of searches.
There are two primary differences. First, agencies may issue subpoenas and obtain judicial enforcement if the information sought is “relevant” to an authorized agency investigation or inquiry — a much lower standard than the probable cause required for a warrant. Second, unlike judicial warrants, which are issued by a neutral magistrate, administrative subpoenas are issued by government agency officials without prior judicial authorization.
This divergent approach to subpoenas and warrants evolved decades ago, at a time when the universe of private information held by third parties was limited. Since then, both the sensitivity and the volume of information stored by third parties have grown dramatically. Indeed, in the digital age, third parties hold much of the sensitive information we increasingly generate in our daily activities on and offline. Google has our browsing history; AT&T has our phone records; Amazon has our purchase history; WHOOP has our health data; and so on. These third-party companies have much less incentive to challenge a subpoena for users’ information than users would themselves.
Often, an individual may be completely unaware that the government has subpoenaed their information. Companies are under no legal obligation to notify customers when they receive a subpoena. (While some do as a matter of company policy, others do not.) And in some cases, companies are actually prohibited from doing so — a prohibition that may last indefinitely.
For example, under the Stored Communications Act (SCA), the government can seek an order prohibiting a communications service provider from notifying customers of a subpoena for their records. Experts generally agree that obtaining these nondisclosure orders has largely become a “box-checking exercise.” But even if the customer receives notice of the subpoena and they or the service provider challenges it in court, Fourth Amendment doctrine — as discussed later in this piece — affords surprisingly little protection.
Expansive Subpoena Authority
A 2002 Justice Department report to Congress identified over 300 statutes granting dozens of federal administrative agencies broad authority to obtain records using administrative subpoenas. Much like the DHS subpoena provisions, these statutes are often written in sweeping terms, permitting agencies to require the production of “any relevant records.”
The Health Insurance Portability and Accountability Act, for example, grants the Department of Justice (DOJ) power to subpoena “any records or other things relevant to [an] investigation” of a federal healthcare offense, including the medical records of individuals receiving treatment. The Trump administration recently invoked this authority to subpoena patient records from healthcare providers that offer gender-affirming care. While numerous courts have quashed those subpoenas — primarily because they were issued for an improper purpose — the government has successfully relied on this statute in other contexts to obtain patients’ medical records without demonstrating probable cause.
Administrative subpoenas are used to obtain information, such as communications content, that would receive the highest Fourth Amendment protection if acquired through a direct government search. For instance, the Securities and Exchange Commission (SEC) has broad authority to subpoena “any records” relevant to its investigations of insider trading, market manipulation, and other securities law violations. Pursuant to this authority, the SEC regularly seeks to compel the production of emails and other electronic communications from individuals, including private text messages on personal cell phones. Moreover, as noted above, U.S. Immigration and Customs Enforcement (ICE) has used its subpoena power to seek geolocation information, even after the Supreme Court ruled that obtaining seven days’ worth of historical cell-site location records requires a warrant.
Agencies have also used administrative subpoenas to obtain sensitive information in bulk. The Drug Enforcement Administration (DEA), for instance, relied on its power to subpoena “any records . . . which the Attorney General finds relevant or material” to a drug investigation as the basis for operating bulk collection programs for telephone metadata and money-counting machine purchase records. Of course, the vast majority of the records obtained through these programs had no relevance to any DEA investigation, causing the DOJ Office of the Inspector General (OIG) to doubt the programs’ legality and fault the DEA for “fail[ing] to conduct a comprehensive legal analysis before initiating” them. Despite the OIG’s conclusions, the DEA in 2019 refused to disclaim the authority to use administrative subpoenas for bulk collection. As of 2023, the DEA continues to rely on its administrative subpoena authority to obtain call detail records that the government pays AT&T to maintain in bulk.
While there is no complete accounting of the number of administrative subpoenas issued by federal agencies each year, a database of DHS subpoenas reviewed by WIRED showed that ICE agents issued more than 170,000 customs summonses between 2016 and mid-August 2022 — an average of more than 25,000 subpoenas issued each year by just one DHS component, using just one of its administrative subpoena authorities. Google alone received over 50,000 subpoenas from U.S. federal, state, and local government entities in 2025. (This reported statistic also includes subpoenas issued by grand juries and Congress, which are outside the scope of this piece.)
Subpoenas and the Fourth Amendment
The legal doctrine governing administrative subpoenas largely developed during the New Deal, when administrative agencies’ power to investigate and regulate industry greatly expanded. In a trilogy of cases from 1946 to 1964, the Supreme Court considered the validity of subpoenas for corporate records. At that time, Fourth Amendment protections were primarily focused on property intrusions, and the Fifth Amendment offered individuals much more robust privacy protections against demands for incriminating documents. Corporations, however, could not claim Fifth Amendment privileges and did not enjoy the same Fourth Amendment privacy rights as individuals.
In the foundational 1946 case, Oklahoma Press Publishing Co. v. Walling, an administrative agency subpoenaed a publisher’s business records to determine whether the company was violating federal minimum wage requirements. The Supreme Court rejected the publisher’s Fourth Amendment challenge, distinguishing subpoenas from “actual searches,” in which a government official physically intrudes onto a person’s property to search or seize records. The Court described the subpoena instead as a less intrusive “constructive search,” in which the government directs the recipient to perform a search herself and produce requested records, and the recipient has an opportunity to contest the subpoena before any intrusion occurs.
This distinction between “actual” and “constructive” searches gave rise to a body of case law in which, instead of requiring a warrant based on probable cause, courts have permitted subpoenas for documents under a less demanding standard. Specifically, the government may obtain documents with a subpoena if the documents are relevant to an investigation authorized by law and if the request is neither overbroad nor unduly burdensome.
In 1967, however, the Court moved away from the property-focused rationale underlying this distinction. In Katz v. United States, the Supreme Court made clear that trespass on private property is not required for a government “search” under the Fourth Amendment; rather, a search takes place whenever the government intrudes on a reasonable expectation of privacy. Thus, in Katz, a government wiretap of a conversation that took place in a public phone booth was a “search” for Fourth Amendment purposes because the caller had a reasonable expectation that his communication would remain private, even though the wiretapped communications equipment was not his private property.
In the decades after the ruling in Katz redefined the scope of Fourth Amendment privacy rights, the Supreme Court no longer focused on the distinction between actual and constructive searches when deciding subpoena cases. Instead, it considered whether individuals had a reasonable expectation of privacy in the records sought. Until 2018, however, the Supreme Court and lower courts largely continued to uphold the issuance of subpoenas for sensitive information, for two reasons.
First, although the Supreme Court stopped focusing on the distinction between actual and constructive searches, it did not directly repudiate or override the case law that established the distinction. Lower courts have thus largely continued to apply the less demanding subpoena standards of Oklahoma Press, without considering how its property-based privacy principles square with the reasonable expectation of privacy test under Katz.
Second, in assessing whether the subject of a search had a reasonable expectation of privacy, the Supreme Court has employed the “third-party doctrine.” First articulated in 1976, the doctrine holds that people lack a reasonable expectation of privacy in information they voluntarily convey to third parties, such as canceled checks and deposit slips that a person voluntarily shares with their bank. For decades, this doctrine precluded any application of the Fourth Amendment to the compelled production of even highly sensitive information companies hold about their customers.
In 2018, the Supreme Court began to confront the constructive-search doctrine head-on and to narrow the reach of the third-party doctrine. In Carpenter v. United States, the Court held that a warrant is required to compel companies to turn over customers’ historical cell site location information on the ground that individuals have a reasonable expectation of privacy in their location over time. The Supreme Court explained that this type of information can reveal the most intimate details of a person’s life — not only their movements, but also their “familial, political, professional, religious, and sexual associations.” It also reasoned that there is nothing truly “voluntary” about disclosing one’s location information to a cell phone service provider, as the alternative is to completely forgo cell phone use — and, by corollary, life in modern society.
In his dissent, Justice Alito argued that the Court’s decision ignored the pre-Katz distinction between actual and constructive searches and would upend subpoena authorities. But the majority rejected that concern, refusing to categorically subject subpoenas to lenient scrutiny without regard to a suspect’s expectation of privacy in the records. Whether a subpoena would be sufficient, in the Court’s analysis, must turn on the nature of the information sought and the degree to which any disclosure to a third party was “voluntary” in a meaningful sense.
Eight years later, the Court reaffirmed that principle and further narrowed the third-party doctrine in Chatrie v. United States, holding that the government needs a warrant to compel the production of cell phone location records even for a short period of time. The Court again rejected Justice Alito’s argument that compelled document-production orders are never Fourth Amendment searches. And it explained that the records generated by using apps and services on a cell phone — records necessarily shared with third-party companies — remain the user’s “own” and deserve Fourth Amendment protection, whether they are “emails, documents, photographs, or calendars,” as well as location data or other private materials.
Subpoena Authorities Should Be Reformed
Over the last decade, the Supreme Court has grappled with the tensions between decades-old Fourth Amendment jurisprudence and the realities of the digital age, moving toward an updated doctrine more suitable to the modern world. Central to that development has been the Court’s acknowledgment that it must not “uncritically extend existing precedents” and that the “progress of science” must not erode Fourth Amendment privacy protections.
But the Supreme Court cannot be the sole guardian of our privacy, if only because its Fourth Amendment rulings tend to be few and far between. Congress must reform this country’s outdated and sweeping administrative subpoena authorities to ensure that, at a minimum, law enforcement and intelligence agencies investigating an individual cannot issue administrative subpoenas to acquire that person’s sensitive information. That is especially urgent now, as emerging AI tools offer government agencies the ability to piece together seemingly innocuous information at a previously unimaginable scale to expose a person’s habits, beliefs, associations, or health conditions.
Congress can start by codifying certain protections that flow directly from the Court’s recent decisions. Most obviously, Congress should require a warrant for the government to obtain geolocation information. While Carpenter and Chatrie addressed specific types of geolocation information (location data generated from using cell phones), the Supreme Court made clear in Chatrie that the government needs a warrant to access even a small amount of cell phone location data — including GPS and IP address information and data captured by nearby Wi-Fi networks, Bluetooth beacons, and cell sites — because it can reveal one-off private matters such as attendance at a gun show, political rally, or abortion clinic. Any type of location information presents that risk. Congress should thus ensure that location information receives warrant protection regardless of how it is captured or the type of third-party service provider that stores it.
In addition, Congress should extend warrant protection to the content of personal communications, such as private text messages or emails. Although the Court has not directly addressed stored communications held by communications service providers, its decisions in Carpenter and Chatrie reaffirmed that the government must get a warrant to obtain the modern-day equivalents of a person’s papers or effects, even when those records are held by a third party. Private communications fall squarely within that characterization.
Another category of information that merits heightened protection is telephone records. A good start would be passing the bipartisan Subpoena Abuse Prevention Act. The bill would prohibit federal agencies from using subpoenas to compel the disclosure of phone call metadata — including the telephone numbers on each end of a call, the time it was placed, and the call duration — from electronic communication service providers. It would also place limits on the use of subpoenas to obtain subscriber information, such as a customer’s name, address, and account identifier. Specifically, it would prevent agencies from obtaining subscriber information in bulk, and it would bar agencies from seeking subscriber information to investigate First Amendment-protected activities — thus protecting Americans against the chilling practice recently employed by DHS.
But Congress should expand on the bill’s protections by prohibiting the use of administrative subpoenas to obtain other types of personal communications metadata, including data about emails and text messages. Experts have explained that accumulated communications metadata can expose personal associations and patterns of behavior.
Internet search and browsing records are also highly sensitive and currently lack adequate statutory protection. The Senate overwhelmingly supported a bipartisan amendment in 2020 that would have restricted warrantless access to such records, acknowledging that they can reveal a person’s most private thoughts and preferences.
Members of Congress have also recognized the sensitivity of health information, including reproductive and sexual health data collected and maintained by cellphone applications and wearable devices. Limiting warrantless access to medical records and other private health information is particularly important given the increased risk of reproductive and sexual health data being weaponized to target those seeking or providing abortions or gender-affirming care.
Certain types of financial information may also deserve stronger privacy protections. Records of every online purchase we make are increasingly held by third parties and analyzed by advertisers to determine our habits and preferences, the causes we support, and even our reproductive health. That financial information, far more than the bank records afforded diminished privacy protections by the Supreme Court in 1976, can reveal sensitive details about a person’s activities and beliefs — particularly when combined with other data and subjected to AI-driven data analysis tools.
***
DHS’s use of administrative subpoenas to identify online critics has laid bare the need for reform. Congress must rein in the nation’s sweeping administrative subpoena authorities and limit the government’s access to certain categories of private information without a judicial warrant based on probable cause, subject to well-recognized exceptions such as exigent circumstances. The Supreme Court is slowly updating Fourth Amendment law to reflect the realities of our modern world. To protect Americans’ privacy in the interim, it is critical that Congress do its part.






