Key Takeaways

  • The current circuit split on encrypted messaging admissibility hinges on whether the Stored Communications Act (18 U.S.C. § 2701 et seq.) or the Fourth Amendment's reasonable expectation of privacy test under *Katz v. United States* governs the government's seizure of encrypted communications from third-party service providers.
  • In my 25 years as a federal prosecutor, I saw the tension between the government's need for digital evidence and the defendant's right to privacy intensify as encryption became ubiquitous, creating a legal landscape where the same facts can yield opposite outcomes depending on the circuit.
  • The split directly affects the admissibility of critical evidence in cases involving drug trafficking, child exploitation, and terrorism, because the government's inability to decrypt content often forces reliance on metadata and communication patterns, which some circuits treat as private and others as voluntarily disclosed.
  • Defense attorneys must now carefully monitor which circuit's precedent applies to their case and consider pre-trial motions under Federal Rule of Evidence 403, arguing that the probative value of encrypted messages is substantially outweighed by the danger of unfair prejudice when the government cannot authenticate the content or the identity of the sender.

The Statutory Framework: How the Stored Communications Act and the Wiretap Act Collide with Encryption

In my 25 years as a federal prosecutor, I learned that the Stored Communications Act (SCA), codified at 18 U.S.C. § 2701-2712, was designed to protect electronic communications stored by third-party providers, but it was never written with end-to-end encryption in mind. The SCA distinguishes between communications in "electronic storage" (§ 2510(17)) and those that have been "delivered" to the recipient, with the former enjoying greater protection from government access without a warrant. When messages are encrypted, the government often argues that the encryption key itself is not a "communication" under the SCA, but rather a form of "transactional record" that can be compelled under § 2703(c) with a mere subpoena or a court order under the Stored Communications Act. The Wiretap Act (18 U.S.C. § 2510-2522), meanwhile, prohibits the "interception" of communications in transit, but the government frequently contends that encrypted messages stored on a server before delivery have already been "intercepted" and are therefore subject to lower standards of protection. This statutory ambiguity creates the first layer of the circuit split: some circuits treat encrypted messages as protected "content" under the Wiretap Act, while others view them as mere "records" under the SCA, depending on whether the encryption is deemed to have "interrupted" the communication in transit.

The Precedent Divide: The Third Circuit's *Warshak* Standard vs. The Sixth Circuit's *Carpenter* Application

The foundational precedent for this split comes from the Third Circuit's 2007 decision in *United States v. Warshak*, which held that individuals retain a reasonable expectation of privacy in the content of their emails stored with a third-party provider, requiring the government to obtain a warrant under the Fourth Amendment. In contrast, the Sixth Circuit, in a series of post-*Carpenter v. United States* (2018) rulings, has applied a narrower test, holding that the government's acquisition of encrypted message metadata—such as timestamps, sender IP addresses, and device identifiers—does not constitute a "search" under the Fourth Amendment because the user voluntarily conveys this information to the service provider. The Supreme Court's holding in *Carpenter* that the government's warrantless acquisition of cell-site location data violated the Fourth Amendment was explicitly limited to "the unique nature of cell phone location information," leaving lower courts to debate whether encrypted message content falls within that same "unique" category. In my experience, the most aggressive application of *Carpenter* comes from the Ninth Circuit, which in *United States v. Kolsuz* (2018) extended the warrant requirement to encrypted files stored on a laptop seized at the border, while the Fourth Circuit has taken a more restrained approach, holding that the government may compel decryption under the All Writs Act (28 U.S.C. § 1651) without violating the Fifth Amendment privilege against self-incrimination. This doctrinal divide means that a defendant in the Third Circuit can successfully suppress encrypted messages obtained without a warrant, while the same defendant in the Sixth Circuit would face an uphill battle, because the Sixth Circuit applies the "third-party doctrine" from *Smith v. Maryland* (1979) to digital communications that are "shared" with an encryption service provider.

The Practical Consequences for Defense Strategy and the Role of Federal Rule of Evidence 403

When I defend clients in circuits that follow the Sixth Circuit's narrower view, I immediately focus on the government's inability to authenticate the encrypted messages under Federal Rule of Evidence 901, because the encryption process often obscures the identity of the sender and the integrity of the content. The government typically attempts to authenticate encrypted messages by presenting testimony from a forensic examiner who can explain the chain of custody, but this testimony rarely establishes that the defendant was the actual author of the message, especially when the encryption key is shared among multiple users or devices. Under Federal Rule of Evidence 403, I argue that the probative value of such messages is substantially outweighed by the danger of unfair prejudice, because the jury is likely to assume that the presence of encrypted communications itself suggests consciousness of guilt, even when the encryption is used for legitimate privacy purposes. The government often counters by citing the "business records" exception under Federal Rule of Evidence 803(6), claiming that the service provider's logs of encrypted transmissions are admissible as records of regularly conducted activity, but this argument fails when the provider cannot verify that the encryption key was not compromised. In circuits that follow the Ninth Circuit's broader view, I have successfully moved to suppress encrypted messages under the Fourth Amendment by arguing that the government's warrantless acquisition of the encryption key from the service provider violated the defendant's reasonable expectation of privacy, relying on the Supreme Court's reasoning in *Riley v. California* (2014) that digital data is fundamentally different from physical evidence. Ultimately, the circuit split forces defense attorneys to become experts not only in criminal procedure but also in the technical nuances of encryption protocols, because a single misstep in the government's chain of custody can be the difference between a conviction and a dismissal.

The Future of the Split: Why Congressional Action or Supreme Court Review is Inevitable

The current circuit split on encrypted messaging admissibility is unsustainable, because it creates a geographic lottery where the admissibility of the same piece of digital evidence depends entirely on where the defendant is prosecuted, undermining the uniform administration of federal criminal law. In my 25 years as a federal prosecutor, I saw the Department of Justice frequently avoid bringing charges in circuits with restrictive precedents, instead seeking indictments in more favorable jurisdictions, which raises serious venue questions under Federal Rule of Criminal Procedure 18 and the Sixth Amendment's vicinage clause. Several bills have been introduced in Congress, including the "Lawful Access to Encrypted Data Act" and the "EARN IT Act," which would require service providers to maintain the ability to decrypt communications upon lawful request, but these proposals have faced fierce opposition from privacy advocates and technology companies on First Amendment and Fourth Amendment grounds. The Supreme Court has thus far declined to grant certiorari on the issue, likely because the justices are waiting for a clean case that squarely presents the question of whether the government can compel decryption without violating the Fifth Amendment privilege against self-incrimination, as the Court hinted in *United States v. Hubbell* (2000). Until the Court acts or Congress passes a comprehensive statute, defense attorneys must carefully document the government's method of acquiring encrypted messages, challenge the authenticity of the evidence under Rule 901, and preserve the record for appeal, because a favorable Supreme Court decision could retroactively invalidate convictions obtained in circuits that applied the third-party doctrine too broadly.

Frequently Asked Questions

How does the circuit split affect the government's ability to use encrypted messages from WhatsApp or Signal in a federal prosecution?

In circuits that follow the Third Circuit's *Warshak* standard, the government must obtain a warrant based on probable cause to access the content of encrypted messages from services like WhatsApp or Signal, because the user retains a reasonable expectation of privacy in the communication even though it is stored on a third-party server. In circuits that apply the sixth circuit's narrower view, the government may obtain the same messages with a mere subpoena under the Stored Communications Act, arguing that the user voluntarily disclosed the message to the service provider and therefore waived any privacy interest. This split creates a significant tactical advantage for prosecutors, who can choose to indict in a favorable circuit if the alleged criminal conduct spans multiple jurisdictions, a practice known as "forum shopping" that I have seen the government employ in major drug and terrorism cases. Defense attorneys must therefore file pre-trial motions under Federal Rule of Criminal Procedure 12(b)(3) to challenge the venue, arguing that the government's choice of forum is improper under 18 U.S.C. § 3237 if the encrypted messages were sent or received in a circuit with more protective precedent.

Can the government compel a defendant to provide their encryption password or biometric unlock without violating the Fifth Amendment?

The answer depends on whether the act of providing the password or biometric is testimonial under the Fifth Amendment, and the circuit split on this issue is equally pronounced. The Eleventh Circuit, in *United States v. Gavegnano* (2022), held that compelling a defendant to provide a fingerprint to unlock a phone is not testimonial because it is a physical act, not a communication of knowledge, while the Third Circuit, in *United States v. Apple MacPro Computer* (2018), held that providing a password is testimonial because it requires the defendant to disclose the contents of their mind. The Supreme Court has not directly resolved this split, but the Court's decision in *Doe v. United States* (1988) distinguished between "testimonial" acts that reveal the contents of a person's mind and "physical" acts that merely produce evidence, leaving lower courts to apply this distinction to modern encryption technologies. In my practice, I advise clients to assert the Fifth Amendment privilege and refuse to provide passwords or biometric unlocks, forcing the government to seek a court order under the All Writs Act, which the government can obtain only if it can show that the order is "necessary" and does not unduly burden the defendant's constitutional rights.

If you or your organization is facing a federal investigation involving encrypted communications, do not wait for the circuit split to resolve itself. Contact our firm today for a confidential consultation, where I will personally review the government's evidence, assess which circuit's precedent applies to your case, and develop a suppression strategy that protects your Fourth and Fifth Amendment rights. With 25 years of experience as a federal prosecutor and now as a defense attorney, I understand how the government builds its digital evidence cases—and more importantly, how to dismantle them.