How does the Cybersecurity Act of 2015 change the Internet surveillance laws?
[Commentary] The Omnibus Appropriations Act that President Barack Obama recently signed into law has a provision called the Cybersecurity Act of 2015. The Cyber Act, as I’ll call it, includes sections about Internet monitoring that modify the Internet surveillance laws. This post details those changes, focusing on how the act broadens powers of network operators to conduct surveillance for cybersecurity purposes.
The upshot: The Cyber Act expands those powers in significant ways, although how far isn’t entirely clear. In short, it seems to me that the new Cyber Act substantially broadens the powers of network operators to monitor and disclose beyond the existing provider exception and trespasser exception. The new language focuses mostly on the purpose of the monitoring and disclosure, with relatively little in place about the scope of monitoring or disclosure (although there is a requirement of scrubbing personal data if known). And it seems to allow monitoring for cybersecurity purposes generally, including outsourcing of that role to others, instead of limiting the exception to monitoring to protect the provider’s own network. With that said, there is a lot that is unclear, especially with regard to what counts as a “cybersecurity purpose.”
[Orin Kerr is the Fred C. Stevenson Research Professor at The George Washington University Law School]
How does the Cybersecurity Act of 2015 change the Internet surveillance laws?