
Please note that SCOTUS Outside Opinions constitute the views of outside contributors and do not necessarily reflect the opinions of SCOTUSblog or its staff.
This term, in Chatrie v. United States, the Supreme Court recognized one’s digital location as firmly protected by the Constitution from police searches without a warrant. Beyond its particular context, Chatrie also opens the door to a major expansion of digital privacy under the Fourth Amendment. But the nature and extent of this privacy is far from certain.
Where digital location data stood
Before this summer, certain kinds of digital location data were already protected. In 2018’s Carpenter v. United States, the court held that police needed to get a warrant before reviewing at least seven days’ worth of a certain kind of digital location data – cell-site location information. Cell phone providers collect CSLI when cell phones connect to cell towers, and it can provide an estimate of a user’s location somewhere within one-eighth to four square miles. This kind of information can be useful to police in, for instance, placing suspects at the locations of crimes.
In Carpenter, the court held that people have a reasonable expectation of privacy (and therefore Fourth Amendment protections) in at least seven days’ worth of this data because, for one, such location data is particularly revealing of the privacies of life, as it tracks a person’s movements both extensively and into private areas. Such information was also revealing, according to the court, since the volume of CSLI far outstripped past police capacity to track individuals, and given that police could retrospectively delve into any cell phone carriers’ past, regardless of whether the police had earlier identified them as a suspect worth devoting resources to tracking. Additionally, the court found that phone users’ generation of CSLI was involuntary: carrying a cell phone is inescapable in modern life and one’s phone automatically generates this data, not through any active choice on the user’s part. (One commenter has termed these facets the Carpenter test factors).
Chatrie: Carpenter redux
The court’s holding in Carpenter was fairly hedged, however. Was digital location data of this kind spanning less than seven days protected? What about data generated from some kind of interaction with a user, rather than data generated automatically by one’s phone?
Enter Chatrie v. United States. The case dealt with exactly those questions, and the court answered them with a resounding affirmation of location data’s protections. Specifically, Chatrie involved police constructing a “geofence” – a virtual perimeter of sorts – and requesting data from companies about all cell phones located within that perimeter, from which the police ultimately can identify suspects. The particular kind of data requested in the Chatrie geofence involved information collected by a Google service called “location history.” This service records the location of a user’s cell phone more frequently and more precisely than CSLI.
This feature also allows for data to be collected on the scale of hours, rather than days, and involves data generated through a process with arguably more interaction from the user than in Carpenter: users opt-in, with varied degrees of awareness, for their location to be tracked.
Despite these differences, the court concluded that this type of data should be treated similarly to that in Carpenter, emphasizing that its precision was actually more revealing than CSLI, even with only a very short window of collection. The court also focused on the data’s retrospective nature: any officer could reconstruct the movements of any individual in both public and private spaces at the click of a button. The court thus concluded that one had a reasonable expectation of privacy in their digital location history.
Power to the people?
Perhaps the court’s most surprising move, however, was to characterize this kind of digital location data as belonging to the user. The majority described this data as a record the user “views as his own” because users use this data as “a personal journal” of what restaurants they visited, what they saw on vacation, when they were at a friend’s house, and much more. In contrast, cell phone users generally “have no awareness of CSLI records.” In the majority’s eyes, this distinction made the case for protecting location history data even stronger than the data reviewed in Carpenter.
So why is such a characterization surprising? Because of a background rule known as the third-party doctrine. This doctrine holds that a person loses a reasonable expectation of privacy in records they share with a third party, such as phone numbers or bank records.
In Carpenter, the Supreme Court carved CSLI out from that doctrine, finding that such information was not voluntarily shared by cell phone users with the cell phone companies.
In Chatrie, however, the government argued that users do voluntarily share this information, because they arguably opt-in to Google location history. Nevertheless, the court dismissed this distinction: “A cell-phone user is not to be viewed as [voluntarily] sharing private information with third parties . . . just by doing the ordinary things cell-phone users do,” with location-tracking apps among those normal things.
This wholesale exemption of a broad swath of records from the third-party doctrine raises significant implications for other technologies. For example, Chatrie’s logic offers a clear basis for requiring warrants before accessing AI chat logs. Although these records are turned over to a third party, they are certainly as or more intimate as a list of past-visited locations.
But this decision also leaves a great deal of gray: is one’s fitness data as revelatory as one’s location? Does the third-party exemption only count for cell-phone-generated data, meaning if I generate the same information on a stationary computer I lose my expectation of privacy? The court offers little guidance on figuring out which records are “ours” enough to count as retaining a reasonable expectation of privacy.
Automatic license plate readers may prove to be the most interesting area of Carpenter-Chatrie litigation. ALPR cameras, like Flock, collect a record of a car’s location, store it, and allow it to be accessed retrospectively. Arguably, this information is revelatory: it can reveal information about when and where you’ve gone. And although collection is contemporaneous, searching ALPR databases is retrospective. Given Chatrie’s reliance on these two factors, there’s a strong argument to be made that such database queries now require a warrant. But prosecutors may (and likely will) counter: ALPRs only capture public locations, which the Chatrie court went out of its way to distinguish. How far Chatrie’s logic will stretch (whether on how “private” one’s data is or the voluntariness of surrendering this), and which factors emerge as the most important, thus very much remain to be decided.
To make matters even more complicated, in Chatrie itself the court punted a huge question back to the U.S. Court of Appeals for the 4th Circuit. It instructed that court to consider whether the actual legal process used in that case – a three-step dance between Google and the police in which Google reveals increasingly more information in response to increasingly developed police suspicion – is constitutionally sound. The process, designed by Google, goes as follows: First, after receiving the geofence coordinates and timeframe from the police, Google provides anonymized location data for cell phones present at the designated place and time. Second, the police narrow down the list and request additional information – typically for the same data over a longer period of time – about the remaining entries. Google responds. Finally, the police request the identities of an even smaller subset of that list, using other investigative tactics to narrow their request. (Because Google now stores location history locally on a user’s phone, it can no longer respond to such requests with respect to this kind of data. But this general process continues to be used across companies and law enforcement agencies for other kinds of information.)
As I wrote in my Chatrie preview, a lot rides on whether this kind of process is constitutionally reasonable. This kind of search – called a reverse search – is likely only possible through some set of procedures like Google’s. Critics argue that the process lacks one of the foundational requirements of constitutional searches, particularity, which means that the police must present sufficient information about who and what they seek. Justice Ketanji Brown Jackson, for instance, spent her concurrence laying out this argument. Ruling the process unconstitutional on this basis might effectively outlaw reverse searches. So although Chatrie confirmed that the police need a warrant to access this information, it is not yet settled what kind of warrant is necessary here, as is whether this kind of search can continue at all.
We may be back in the Supreme Court with this question – and a whole host of others – in the relatively near future.