Made4it

Court Order Requiring Internet Service Providers to Provide Information

Requests from various authorities for customer information are becoming increasingly common.

As natural as this may seem to some, it is common for others to end up feeling excessively nervous, often letting themselves be pressured by authorities, and ultimately acting impulsively in ways that lead to irreversible consequences.

Given this, the first piece of advice we give our clients in situations like this is: STAY CALM!

As a second recommendation, we suggest that your company be supported by some form of LEGAL COUNSEL specializing in internet and telecommunications matters.

It is worth reiterating that legal counsel should be provided by a professional or firm with proven experience in these matters. Without in any way disparaging other professionals, we emphasize that the issues in this area are legally very dynamic and technically specific; as a result, we have observed that some cases handled by legal counsel lacking the necessary expertise end up yielding undesirable results.

It is worth noting that most provider associations have agreements with professionals and companies that meet the necessary qualifications to address issues such as this.

And now, in the third section—the main focus of this document—we will address the questions, scenarios, and issues we most frequently encounter with our clients, and we will share some of the analyses and guidance we provide to our clients on these topics.

It is worth noting that “legal advisory services in the field of the Internet and telecommunications” are not currently included in Made4it’s portfolio of services (as of June 2021).

In this document, in our examples, we will intentionally refrain from referring to specific legislation by number or identification, as it is not the purpose of this document to replace or supersede the guidance provided by a legal advisory service specializing in these matters.

The question we get asked most often on this topic:

“From a legal standpoint, who has the authority to request information about a provider’s customers from the Internet service provider?”

Answer -> IT DEPENDS!

What kind of information are we talking about?

If we’re talking about linking an IP address to a user or between a user and an IP address, the only person authorized to request this is a judge! And a judge can only do so through a court order, which must specify the exact dates and times for this identification; furthermore, if the access originated from an IPv4 address, the source port used for the access must also be specified.

This means that:

  • A police officer (whether state, federal, or even a member of the Capitol Police) does not have the legal authority to request a user’s identification based on an IP address.
  • A congressman, mayor, or city council member also has no legal authority to request a user’s identification based on an IP address. As incredible as it may seem, there are frequent reports of ISP owners being pressured by these types of authorities.
  • Even if he is a judge, he cannot request a user’s identification based on an IP address without a court orderwhether by phone, email, WhatsApp, or even in person—without issuing any official document.

If we’re talking about registration data, any law enforcement official (police chief, investigator, police officer) may request REGISTRATION INFORMATION from the database of companies providing mass-scale services, provided that they provide an unambiguous identification of the desired data.

So let’s take it one step at a time:

  • What does “companies providing services on a massive scale” mean?
    • These are companies that have information on many people, many addresses, and similar data in their databases.
    • Examples of such companies include water and sewerage companies, electric utilities, telephone companies, Internet service providers, colleges, and universities.
  • What does “unambiguous identification of the desired data” mean?
    • The police authority may request registration information for 1 (one) address or 1 (one) user.
    • Law enforcement authorities MAY NOT request something like: “Give me a complete list of your customers, including their addresses and phone numbers.”
    • In cases of ambiguity or homonyms, it is up to the police authority to resolve the ambiguity. This can be done by specifying details such as the house number or the serial number of equipment installed in the house to be identified, or by providing document numbers and parents’ names, in order to rule out the possibility of people with the same name and specifically identify the desired individual.
  • What would be appropriate examples under the logic of the legislation that ensures the disclosure of this registration data?
    • Imagine that you are a police investigator and are looking for a person named “Teófilo Antônio de Oliveira Antunes de Souza e Sá” (fictitious name). You have learned somehow that this individual has been residing for some time in the city of “Lugarlândia” (fictional city). In that city, Internet service is primarily provided by the company “CoisaNet” (fictional company). The investigator can go to that company and request the registration information SPECIFICALLY FOR THAT PERSON, and thus find out where that person resides.
    • Imagine you’re a police officer gathering information about a crime that occurred at a residence where, as of that moment, the owner of the property is unknown. And at this property, there’s an active “CoisaNet” Internet connection. The police officer can go to the company and request the registration information for the person responsible for the Internet connection at “Rua Azul, 123” (fictitious address).
    • It is important to note that the legislation governing access to registration data does not specify that such a request for registration data must be made using any specific type of document. There is also disagreement regarding whether an official letter from the relevant law enforcement agency is required. Our recommendation is that you NEVER DISCLOSE DATA WITHOUT SOME FORM OF DOCUMENTARY RECORD OF SUCH DISCLOSURE. This does not mean that you should create obstacles to the progress of police activities; in the worst-case scenario, you can ask the authority to handwrite a request on a blank sheet of paper specifying the data being requested. And when handing over this data, provide two copies and obtain a signed acknowledgment of receipt with the date and location. All of this takes less than 10 minutes to arrange.
  • What are the most common cases of improper use of the legislation governing the disclosure of registration data?
    • It is very common for police officers, investigators, or law enforcement officials to send official letters to internet service providers requesting, “Please provide us with the name and address of the user with the IP address ‘A.B.C.D’.” No! Law enforcement does NOT HAVE THE AUTHORITY to request a user’s identification based on an IP address.
    • Another common instance of the inappropriate use of this legislation involves requests for registration data that are formulated in very general terms, without specifying exactly which person or location is being referred to. Examples include requests such as “Please provide the registration information—including address, phone number, and full name—for all of your company’s customers named ‘José Carlos’” (fictitious name), or “We request the registration information—including address, phone number, and full name—for all of your company’s customers in the ‘Alvorada Neighborhood’” (fictitious neighborhood).

Still on the subject of the information that may be requested by the authorities—even in the case of requests made by a judge through a court order—there are limits to what can be requested.

This is a very delicate issue to explain to people who aren’t tech-savvy. But it’s not uncommon—even from judges who are supposed to be supported by competent technical advisors—for us to receive requests such as:

  • “We request that you provide us with a list of all websites accessed by the customer of your provider, ‘Teófilo Antônio de Oliveira Antunes de Souza e Sá’” (fictitious name).

An Internet service provider that complies with all laws related to connection logs, data privacy, data protection, and data security should not be able to obtain this data.

And here’s a very important reminder!

  • In a general operational context, if you are able to obtain a list of the content accessed by one of your customers—without that customer being in any special debug or troubleshooting mode—we can say with nearly 100% certainty that your provider is(inadvertently) some kind of illegal act in obtaining this data.

Given this, it is correct to say that under normal circumstances, even if requested by a judge, an Internet service provider should not be able to do so.

What steps should an Internet Service Provider take when it receives a request for customer data?

Short answer:

  1. Stay calm and don’t act rashly.
  2. Be polite, friendly, and helpful to anyone who identifies themselves as an authority figure. But remain cautious.
  3. Verify the identity of the person claiming to be an official, including by checking that information on the websites of the agencies they claim to represent.
  4. Notify your provider’s legal counsel that you have received this claim, and consult with them about whether or not to respond, and how to respond.
  5. If the request for information was made by a competent authority, and the requested information may be disclosed, the following steps must be taken:
    1. Submit the requested information in writing
    2. Obtain confirmation of receipt of the information, including the recipient’s identification, location, and date.
  6. If the request for information was not made by a competent authority, or if the requested information cannot be provided, the following steps must be taken:
    1. Check the relevant data and ensure that it is properly stored and protected against potential loss due to accidental overwriting
    2. Send a written response to the requesting authority explaining why the information cannot be provided, noting that the data has already been protected under the statute of limitations.
    3. If further details are needed from the user, request them from the requesting authority.
    4. If this is a matter outside the authority’s jurisdiction, suggest that the requesting authority take the necessary steps to ensure that the request is
    5. Obtain a delivery confirmation for the response that includes the recipient’s name, location, and date.

This content is based on situations we encounter in our daily lives; these are tips and steps we recommend our clients follow. Please note that we do not provide legal advice; if you are facing this situation, we recommend that you consult a legal professional.

Author: Douglas Fischer (Made4it Networking Specialist)

Made4it arises to meet the needs of the market, which has been demanding more and more personalized solutions.