11.1 RFPA, BSA, ECPA, and CALEA
Key Takeaways
- The Right to Financial Privacy Act of 1978 (12 U.S.C. §§ 3401–3422) limits federal — not state or private — access to customer bank records and generally requires customer notice plus 10 days from service or 14 days from mailing to challenge
- The Bank Secrecy Act of 1970 is an anti-money-laundering reporting statute (currency transaction reports over $10,000, suspicious activity reports, customer due diligence), not a customer privacy-rights statute; 12 U.S.C. § 3413(d) excepts BSA reports from the Right to Financial Privacy Act
- Electronic Communications Privacy Act of 1986 Title I (Wiretap Act) is a prospective-intercept “super-warrant” statute; Title II is the Stored Communications Act; Title III is the Pen Register Act
- Carpenter v. United States (2018) requires a warrant for historical cell-site location information; Congress has not rewritten the Stored Communications Act’s 180-day email rule, which courts and Department of Justice practice treat as constitutionally suspect for content
- The Communications Assistance for Law Enforcement Act of 1994 requires carriers to isolate and deliver intercepts once lawful process exists; it is a capability statute, not an authorization to intercept
11.1 RFPA, BSA, ECPA, and CALEA
Domain III of the CIPP/US Body of Knowledge 2.6.1 is Government and Court Access and accounts for 3–5 of the exam’s 90 questions. Competency III.A is law-enforcement access. This section is the criminal-process ladder: the Right to Financial Privacy Act of 1978 (RFPA), 12 U.S.C. §§ 3401–3422; the Bank Secrecy Act of 1970 (BSA); the Electronic Communications Privacy Act of 1986 (ECPA); and the Communications Assistance for Law Enforcement Act of 1994 (CALEA). Keep the jobs separate. RFPA is a customer-rights statute aimed at the federal government. The BSA is an anti-money-laundering reporting statute aimed at the institution. ECPA is the communications-process statute. CALEA is the capability statute that tells carriers they must be able to isolate and deliver what lawful process already requires.
Right to Financial Privacy Act — federal banks, notice, and challenge
The RFPA is Congress’s response to United States v. Miller, 425 U.S. 435 (1976). Miller held that a bank customer has no Fourth Amendment interest in records the bank itself created and kept. Congress did not overrule Miller. It created a statutory procedure that a federal “Government authority” must follow before it obtains a customer’s financial records from a financial institution.
12 U.S.C. § 3402 is the gate. Absent a listed exception, the government may obtain those records only by customer authorization, administrative subpoena or summons, search warrant, judicial subpoena, or formal written request. For subpoenas, summonses, and formal written requests, the agency must generally serve or mail the customer a copy on or before the date it serves the institution, explain why the records are sought, and tell the customer how to object. Under 12 U.S.C. § 3410 the customer then has 10 days from personal service or 14 days from mailing to move to quash or to enjoin. A court may delay notice under § 3409 when notice would result in endangerment of life or physical safety, flight, destruction of evidence, intimidation of witnesses, or serious jeopardy to an investigation.
The RFPA’s scope is narrower than candidates expect:
| Limit | What the statute actually does |
|---|---|
| Federal only | “Government authority” means an agency or department of the United States. State and local process, and private civil discovery, are outside the RFPA. State law may still apply. |
| Customer records | It protects records of an identified customer. Aggregate or non-identifying information is not the same right. |
| Notice is not absolute | Delayed-notice orders, grand-jury process, and the § 3413 exceptions cut the ordinary challenge window. |
| Certification | The institution generally needs a certificate of RFPA compliance before it releases records, and it may rely on that certificate. |
Section 3413 is the exception list the exam uses to spring traps. Supervisory and regulatory examinations, records sought under the Federal Rules of Civil or Criminal Procedure or comparable rules, grand-jury subpoenas (with a court able to gag the bank), emergency access, and — critically — disclosures required by the BSA are carved out. 12 U.S.C. § 3413(d) is why a suspicious activity report (SAR) is not an RFPA “customer challenge” event. § 3403(c) also immunizes the institution and its employees for reporting suspected crimes. Do not treat an RFPA notice letter as something the bank must send when it files a SAR.
Bank Secrecy Act — reporting to the government, not a privacy right
The Currency and Foreign Transactions Reporting Act of 1970, its amendments, and related titles are collectively the BSA. FinCEN’s official description is the exam’s north star: Treasury may require records and reports that help detect and prevent money laundering. The BSA is sometimes called an anti-money-laundering (AML) law, or BSA/AML. It is not a statute that gives the customer a right to stop the bank from talking to the government.
Three BSA tools appear on Domain III items:
- Currency transaction reports (CTRs). Implementing rules require a report of cash transactions exceeding $10,000 in a daily aggregate amount (31 C.F.R. § 1010.311; statutory hook 31 U.S.C. § 5313). The current instrument is FinCEN Form 112. Structuring transactions to evade the CTR is itself a crime under 31 U.S.C. § 5324.
- Suspicious activity reports (SARs). 31 U.S.C. § 5318(g) authorizes Treasury to require reports of suspicious transactions. The institution generally may not notify the person involved — the “tipping off” ban in § 5318(g)(2). A SAR safe harbor protects good-faith filings. The RFPA’s BSA exception is how those reports leave the bank without a customer-challenge letter.
- Customer due diligence (CDD). FinCEN’s 2016 CDD Rule (31 C.F.R. Parts 1010, 1020, 1023, 1024, and 1026) requires covered institutions to identify and verify customers, identify beneficial owners of legal-entity customers (generally 25 percent equity owners plus one control person), understand the nature and purpose of the relationship, and conduct ongoing monitoring so the institution can file SARs and keep customer information current.
Exam trap. A question that says “the customer may enjoin the bank from filing the CTR / SAR under the RFPA” is wrong. The BSA requires the report. The RFPA excepts it. GLBA’s privacy notice and the RFPA’s challenge right live in different statutes and do not cancel BSA filing duties.
Electronic Communications Privacy Act — three titles, three standards
ECPA, Pub. L. 99-508, is three titles. Naming is a trap of its own. ECPA Title I amended the Wiretap Act, which people still call “Title III” because that is the 1968 Omnibus Crime Control title that first banned wiretaps. ECPA Title II is the Stored Communications Act (SCA), 18 U.S.C. §§ 2701–2713. ECPA Title III is the Pen Register Act, 18 U.S.C. §§ 3121–3127. On the exam, “Title III” in an ECPA question usually means pen/trap; “Title III” in a 1968-wiretap question means the Wiretap Act. Read the fact pattern for prospective content intercept versus dialed-number / routing capture.
Wiretap Act (ECPA Title I). This is the prospective-intercept statute. Intercepting the contents of a wire, oral, or electronic communication in transmission requires a so-called super-warrant under 18 U.S.C. § 2518. A judge must find probable cause that a listed offense is being committed and that particular communications concerning that offense will be obtained; that normal investigative procedures have been tried and failed, reasonably appear unlikely to succeed, or are too dangerous (necessity); and that the facilities are used by the target or in connection with the offense. The order lasts no longer than necessary and in any event 30 days, must require minimization of non-pertinent intercepts, and may be extended only on a fresh showing. Provider-assistance and one-party-consent exceptions exist; they do not turn a stored-email pull into a Title I intercept.
Stored Communications Act (ECPA Title II). The SCA governs communications and records at rest with a provider of electronic communication service (ECS) or remote computing service (RCS) to the public. 18 U.S.C. § 2702 generally bars the provider from voluntarily divulging contents. § 2703 is how a governmental entity compels disclosure:
| Process | Statutory standard | Classic yield |
|---|---|---|
| Administrative, grand-jury, or trial subpoena | Relevance | Basic subscriber information under § 2703(c)(2): name, address, length of service, telephone or instrument number, means and source of payment |
| § 2703(d) court order | Specific and articulable facts showing reasonable grounds that the records are relevant and material to an ongoing criminal investigation | Non-content records; by the text of the statute, also contents held more than 180 days if the government gives customer notice |
| Warrant | Probable cause, Federal Rules of Criminal Procedure | Contents in electronic storage 180 days or less (the only process § 2703(a) allows for that category); also available for older contents and for records |
The 180-day doctrine is still in the United States Code. Congress has not comprehensively rewritten § 2703(a)–(b) to delete it. Teach two later developments without pretending the statute was replaced. First, United States v. Warshak, 631 F.3d 266 (6th Cir. 2010), held that a subscriber has a reasonable expectation of privacy in email content stored with an internet service provider, so a warrant is required; the 180-day subpoena path is constitutionally insufficient for that content. Department of Justice practice generally seeks warrants for email content regardless of age. Second, Carpenter v. United States, 138 S. Ct. 2206 (2018), held that acquiring historical cell-site location information (CSLI) is a Fourth Amendment search. The government had used a § 2703(d) order — not a warrant — to obtain 127 days of Carpenter’s CSLI. The Court refused to extend Miller and Smith v. Maryland (the third-party doctrine cases) to that comprehensive location trail and required a warrant supported by probable cause. Carpenter did not rewrite the SCA. It held that the statute’s 2703(d) path is not enough for historical CSLI. Lower courts and the Department of Justice treat the 180-day email-content rule as constitutionally suspect for the same reason: the Code still says one thing; the Fourth Amendment now requires more.
Pen Register Act (ECPA Title III). A pen register captures outgoing dialing, routing, addressing, or signaling information. A trap-and-trace device captures incoming signaling information. Neither captures contents. The court order issues on a government attorney’s certification that the information likely to be obtained is relevant to an ongoing criminal investigation — a far lower bar than § 2518 or a search warrant. Smith v. Maryland, 442 U.S. 735 (1979), is the third-party-doctrine backdrop; Carpenter limited that doctrine for CSLI but did not invalidate the Pen Register Act.
CALEA and the company playbook
CALEA, 47 U.S.C. §§ 1001–1010, is a capability statute. 47 U.S.C. § 1002 requires a telecommunications carrier to ensure that its equipment can expeditiously isolate a subscriber’s communications, to the exclusion of others, and deliver intercepted communications and call-identifying information to the government pursuant to a court order or other lawful authorization, in a format the government can receive off the carrier’s premises. The Federal Communications Commission (FCC) implements CALEA and has extended the duty to broadband internet access and interconnected voice over Internet Protocol (VoIP) (upheld in United States Telecom Ass’n v. FCC). CALEA does not itself authorize a wiretap. If the process is unlawful, CALEA does not make the intercept lawful. If the process is lawful and the carrier cannot isolate and deliver, CALEA is the compliance failure.
Company playbook — the legal-process ladder. When legal or privacy counsel opens an envelope from law enforcement, classify the paper before anyone hits “export.”
- Subpoena / administrative summons — relevance. Typical yield: RFPA-covered bank records (with customer notice unless an exception applies) or SCA basic subscriber information. Not contents of live communications. Not historical CSLI after Carpenter.
- Court order — 2703(d) “specific and articulable facts,” or a pen/trap order on a relevance certification. Typical yield: non-content records, session logs, to/from headers. Not a live content intercept. Not, after Carpenter, days of CSLI.
- Warrant — probable cause. Typical yield: stored contents, devices, and historical CSLI. Still not a continuing wiretap.
- Super-warrant (§ 2518) — probable cause plus necessity, listed offenses, minimization, and a 30-day cap. The only ordinary criminal process for prospective content intercept. CALEA then tells the carrier to isolate and deliver.
Scenario. An FBI agent serves a cloud provider with a one-page “order” demanding the last 200 days of a user’s email bodies and 90 days of CSLI, citing “ECPA” and “CALEA.” Counsel should reject the mash-up. Email content requires a warrant under current Fourth Amendment doctrine (Warshak and Department of Justice practice), even though § 2703’s 180-day text still exists. Historical CSLI requires a warrant after Carpenter. CALEA is irrelevant until a lawful intercept order exists. If the same agent later arrives with a § 2518 order aimed at future incoming mail, the provider’s CALEA (or assistance) duty is to isolate that stream — not to dump the stored archive.
Exam traps
- RFPA is federal-government process against a financial institution, not a state search warrant and not a private divorce subpoena.
- The BSA’s CTR/SAR/CDD duties are why the bank must talk to FinCEN; they are not RFPA customer rights.
- ECPA Title I is the Wiretap Act (super-warrant). ECPA Title III is pen/trap. The 1968 Wiretap Act is also nicknamed Title III. Match the process to the data.
- The 180-day SCA rule is still in the Code. Do not say Congress repealed it. Do say courts treat warrantless email-content demands as constitutionally suspect, and Carpenter requires a warrant for historical CSLI.
- CALEA never supplies the missing probable cause.
A federal criminal investigator wants three years of a suspect’s checking-account statements from a national bank and serves the bank with a judicial subpoena. The investigator has not obtained a delayed-notice order. What does the Right to Financial Privacy Act generally require?
Which statement correctly distinguishes the Bank Secrecy Act from the Right to Financial Privacy Act?
Prosecutors obtain 90 days of a suspect’s historical cell-site location information from a wireless carrier using only a Stored Communications Act § 2703(d) order. They also demand, by the same order, the contents of emails stored 200 days. Which statement matches current law?