Section 702 of the Foreign Intelligence Surveillance Act, added by the FISA Amendments Act 2008, authorizes warrantless surveillance of non-US persons reasonably believed to be located outside the US. Operationally implemented through the PRISM and UPSTREAM programs disclosed in the 2013 Snowden documents. Reauthorized in 2017 (Section 702 Reauthorization Act) and again in 2024 (with significant debate over backdoor-search reform that ultimately produced modest changes). The largest US foreign-intelligence surveillance authority by data volume.
What it means in practice
The structural framework of Section 702: the FISA Court approves annual certifications of programmatic targeting (categories of foreign intelligence purposes), and within those certifications individual selectors (email addresses, phone numbers, identifiers) can be tasked without individual judicial review. The data is collected from US-incorporated providers (Google, Microsoft, Apple, Meta, Yahoo when active, plus several others identified in the disclosures) under the PRISM authority, and from upstream cable taps under the UPSTREAM authority. The “incidental collection” of US-person communications when the US person is in contact with a Section 702 target is the structural concern: US-person content collected under Section 702 can be queried by FBI in domestic investigations through the controversial “backdoor search” practice, which 2024 reauthorization debate addressed only modestly.
Who it affects, and how
Direct targets: non-US persons outside the US, with the operational reality that the targeting includes journalists’ sources, NGO contacts, family members of US persons abroad, foreign legal representation of US persons, and the broader category of any non-US-person communication transiting the major US-incorporated platforms. Incidental collection: US persons whose communications include any contact with Section 702 targets, which through the digital-communication graph is a significant fraction of US-person internet activity. Backdoor searches: FBI queries of the Section 702 corpus for US-person identifiers in domestic investigations, used in the post-2017 period in tens of thousands of queries annually with documented compliance failures (the 2023 PCLOB report and earlier FBI Inspector General reports). The Predaxia operational frame: Section 702 makes US-incorporated provider data structurally reachable for foreign-intelligence purposes regardless of warrant protections; the architecture defense (end-to-end encryption that the provider cannot decrypt) is the only structurally complete protection.
What you can change today
If your communications include foreign contacts (journalist sources abroad, family members in other countries, legal representation overseas, NGO partners in other jurisdictions), three operational implications. First, prefer end-to-end encrypted channels where the US-incorporated provider cannot read content: Signal for messaging, ProtonMail end-to-end for email-to-Proton (the email-to-Gmail leg remains on the Google side and reachable to Section 702), age or rage for file encryption. Second, prefer non-US-incorporated providers for sensitive cross-border use: Proton (Switzerland), Tutanota (Germany), Mullvad (Sweden) reduce the US-provider Section 702 exposure though do not eliminate the broader Five Eyes share. Third, awareness that Section 702 reauthorization remains contested politically; the framework is moving and the operational implications track the legislative outcomes.
