Skip to main content
Hero background

FISA Section 702

FISA 702 Overview

FISA Section 702 is a part of the Foreign Intelligence Surveillance Act. It authorizes U.S. intelligence agencies to collect foreign intelligence from non-U.S. persons located outside the United States. Collection is selector-based. Agencies target specific identifiers, such as email addresses, not broad categories of communications. The program runs under annual certifications reviewed by the Foreign Intelligence Surveillance Court (FISC). The FISC does not issue individual warrants for each collection. It evaluates the procedures agencies use for targeting, minimization, and querying.

FISA 702 Operational Framework

FISA 702 works by requiring a determination that the acquisition will produce foreign intelligence tied to certified topics like counterterrorism and cybersecurity threats. The law does not hinge on probable cause of a crime. 

Targeting procedures direct collection at non-U.S. persons located overseas. These procedures include safeguards to avoid the intentional acquisition of U.S. person communications. The Office of the Director of National Intelligence (ODNI) manages oversight and reporting. The Department of Justice (DOJ) ensures legal compliance. Agencies like the National Security Agency (NSA) and Federal Bureau of Investigation (FBI) serve as primary users of 702 data. U.S. service providers are required to assist in these efforts. 

FISA 702 Strategic Importance

Threats move quickly across borders and networks. FISA Section 702 enables time-sensitive collection that can surface intelligence on foreign adversaries before risks materialize at home. For leaders responsible for public safety, national resilience, and essential services, the value is practical: actionable insight that informs decisions. 

At the same time, modern internet routing means communications may traverse U.S. infrastructure even when participants are overseas. This reality introduces the possibility of incidental U.S.-person collection. Required under FISA 702, strong minimization, auditing, and query controls keep that risk bounded. When these controls are clear, consistently enforced, and independently reviewed, they support both operational agility and civil liberties of protection. 

FISA 702 Key Elements

FISA 702 is built on five interlocking elements that together enable lawful, targeted intelligence collection while limiting overreach:

  1. Selector-based targeting ties collection to specific identifiers, reducing overreach and focusing activity on known foreign intelligence value. 

  2. Programmatic court oversight requires annual certifications and FISC-approved targeting, minimization, and querying procedures for all Section 702 operations. 

  3. Minimization and querying controls establish rules for masking, retention, dissemination, and documented analyst queries, with additional procedural steps required for U.S.-person identifiers. 

  4. Multi-branch accountability distributes responsibility across the executive branch for implementation and compliance reviews, Congress for oversight, and the judiciary through FISC and the Court of Review. 

  5. Transparency mechanisms include ODNI public reporting, declassified opinions, and provider transparency reports that supply aggregate metrics and trends. 

FISA 702 Use Cases

Counterterrorism and counterproliferation:  Selector-focused collection reveals foreign planning indicators and logistical ties that inform interdictions and sanctions. 

Cybersecurity threat intelligence:  FISA Section 702 collection can surface command-and-control infrastructure or foreign adversary toolsets targeting U.S. networks, improving defensive posture and coordinated response. 

Transnational criminal activity:  Communications among foreign actors involved in ransomware operations, fraud, or illicit finance can be identified and shared under defined legal processes. 

Critical infrastructure protection:  Indicators of planned disruption against energy, transportation, healthcare, or water systems can be surfaced to support rapid mitigation. 

Across all four areas, the intelligence value holds only when agencies apply these authorities with strong minimization and oversight. That discipline is what makes the program defensible.

FISA 702 Implementation and Compliance Practices

Enterprises that may receive lawful orders — including those potentially associated with Section 702 — need documented intake, validation, and response processes supported by counsel, privacy leads, and security operations. The objective is to fulfill lawful obligations, protect users, and preserve a defensible audit trail.

Operational Best Practices 

Authority and scope validation: Before acting on any order, confirm jurisdiction, legal basis, and specificity. The order itself should identify specific selectors or accounts.

Least privilege and dual control: Limit access to what each role actually requires. Sensitive actions need two-person approval before they proceed.

Immutable logging: Maintain tamper-evident audit logs that record who accessed what, when, and why. That record is your compliance evidence when it counts.

Data minimization: Retain only what operations and security require. Less retained data means less exposure when production requests arrive.

Engineering Controls 

Data inventories and classification:  Map data flows and sensitivity tiers to scope production precisely and expedite assessments. 

Retention schedules:  Enforce time-bound retention aligned to legal, regulatory, and operational needs. 

Tokenization and pseudonymization:  De-risk sensitive fields while preserving operational utility. 

Security baselines:  Align to NIST frameworks for identity, access, monitoring, and incident response. Employ role-based access, just-in-time privileges, and continuous monitoring. 

Lawful Access Readiness 

Treat anomalies in legal request workflows as potential security events. Run regular tabletop exercises that cover intake of national security orders, escalation to counsel, communications within legal allowances, and post-action reviews. Documented playbooks reduce uncertainty and support timely, defensible decisions under pressure. 

Protecting Users While Enabling Compliance 

Secure platform design can limit exposure while meeting obligations under FISA 702 and other authorities. Where feasible, use end-to-end encryption for user content, with lawful production limited to provider-controlled layers consistent with policy and user commitments. Enforce strong key management with hardware-backed protections, split-knowledge, and split-control so no single administrator can access sensitive material unilaterally. These measures help organizations respond to 702 requests within the law and maintain user trust. 

FISA 702 Technical and Policy Context 

Modern architecture creates real friction for targeting and collection under Section 702. Encryption is standard across most communications. Traffic routes through content delivery networks. Workloads run across global cloud infrastructure. Lawful acquisition typically focuses on data in provider-controlled layers, such as metadata or content at rest, leaving end-to-end encryption intact. Cross-border data flows add jurisdictional complexity. As a result, precise selectors, rigorous location assessments, and close adherence to FISC-approved procedures all carry more weight.

The legal framework is still being refined. Current debates focus on tighter U.S.-person query rules, enhanced auditing, improved notice in criminal proceedings, and expanded transparency. The aim is to preserve operational value while reducing the risk of unwarranted access and keeping independent oversight of Section 702 meaningful.

FISA 702 Transparency and Accountability

Although intelligence activities are classified, meaningful transparency exists. ODNI publishes annual reports with aggregate metrics on targets, U.S.-person queries, and compliance incidents. Declassified FISC opinions illuminate judicial reasoning. Service providers publish transparency reports within permitted bands. These artifacts, combined with inspector general evaluations and civil society analysis, inform public debate and support legitimacy. 

Organizations can go further. Clear governance for lawful requests, public-facing law enforcement guidelines, independent audits where appropriate, and plain-language explanations of policies build confidence. Well-defined appeal channels and consistent reporting demonstrate that compliance is disciplined, measured, and subject to oversight. 

FISA 702 Balanced and Defensible Approach

FISA 702 is designed to provide timely foreign intelligence while respecting constitutional boundaries. Its effectiveness depends on selector precision, layered oversight, and technical safeguards that prevent misuse. For leaders in government and critical infrastructure, those requirements translate into specific organizational commitments: adopt privacy-by-design principles so that data minimization and access controls are embedded from the start; engineer for least privilege and auditability so that every access event is bounded and recorded; and maintain transparent governance that holds up under independent review from courts, inspectors general, and oversight bodies. Organizations that build these controls into their systems as operating standards fulfill their lawful obligations more consistently, protect user rights, and give the public a concrete basis for trust in how sensitive authorities are applied.

Criminal warrants require a probable cause of a crime. FISA 702 does not. Authorization turns on a determination that collection will produce foreign intelligence tied to certified national security topics: counterterrorism, counterproliferation, and cybersecurity threats. Targeting procedures must direct collection at non-U.S. persons located overseas and include specific safeguards to prevent intentional acquisition of U.S.-person communications.

Key entities include the Office of the Director of National Intelligence (ODNI) for oversight and reporting, the Department of Justice (DOJ) for legal compliance, and agencies such as the National Security Agency (NSA) and Federal Bureau of Investigation (FBI) as primary users of 702 data, alongside U.S. service providers required to assist. Oversight involves FISC-approved procedures, inspectors general, internal audits, and congressional review. 

BlackBerry for Secure Communications

For Environments Where Failure Isn’t an Option

BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.

Explore BlackBerry Secure Communications solutions

FAQ

Frequently asked questions about FISA Section 702 answered

Q: What is FISA Section 702? 

A: FISA Section 702 is a provision of the Foreign Intelligence Surveillance Act authorizing U.S. intelligence agencies to collect communications from non-U.S. persons located outside the United States for foreign intelligence purposes. Collection is tied to specific selectors such as email addresses and operates under annual certifications reviewed and approved by the Foreign Intelligence Surveillance Court (FISC).

Q: Does FISA Section 702 allow the government to collect U.S. person communications?

A: FISA Section 702 targets non-U.S. persons located overseas, not U.S. persons. Minimization procedures and documented query controls required by law govern any incidental contact with U.S. person communications, and additional procedural steps apply before analysts can query those records.

Q: How does FISA Section 702 differ from a traditional criminal search warrant?

A: Unlike a criminal warrant, FISA Section 702 does not require probable cause of a crime. It requires a determination that collection will produce foreign intelligence tied to certified national security topics such as counterterrorism, counterproliferation, or cybersecurity threats.

Q: Who oversees FISA Section 702 and how is it reauthorized?

A: FISA Section 702 authority operates under annual certifications reviewed by the Foreign Intelligence Surveillance Court, with additional oversight from the Office of the Director of National Intelligence, the Department of Justice, inspectors general, and Congress. The FISC evaluates targeting, minimization, and querying procedures rather than issuing individual warrants for each collection.