Government Surveillance Reform Act of 2026
- Read twice and referred to the Committee on the Judiciary.
- Introduced in Senate
The provisions, in plain language.
Bars federal officers and employees from looking at Americans' communications and other sensitive information returned by a search of foreign-intelligence data, unless a court order or warrant already covers that person; narrow exceptions allow access only for a genuine imminent threat of death or serious injury, with the person's consent, or for defensive cybersecurity, each of which must be reported to Congress within 14 days.
Makes any of an American's information accessed in violation of the new query rules unusable: it cannot be used as evidence or shared in any court, grand jury, agency, or other government proceeding, and cannot later be used or disclosed against the person without consent except to prevent death or serious bodily harm.
Requires that any search of foreign-intelligence data be reasonably likely to find foreign-intelligence information and made for a significant foreign-intelligence purpose, and requires the government to create and keep an electronic record of each search and access (the search terms, date, the officer's identity, and the facts justifying it), including attributing automated searches to the responsible officer; agencies must report on compliance to Congress within 90 days.
Prohibits federal officers from intentionally targeting any person in order to acquire the information of a particular known American, unless there is an imminent life-or-death emergency or the person consents, with emergency targeting reported to Congress within 14 days.
Bars the intelligence community from buying or otherwise acquiring datasets of Americans' personal data (data linkable to a person or to a household device, including from data brokers) unless a court has authorized it, the person consented, or a narrow exception applies; the data is treated as covered even when anonymized but re-linkable, while truly public records are excluded.
Requires the Attorney General to adopt procedures that minimize acquiring and keeping Americans' commercially obtained data, force agencies to exclude or delete data not covered by an exception before operational use, and promptly destroy data acquired in violation of the ban.
Makes Americans' commercially acquired data obtained in violation of the purchase ban unusable in any government proceeding, and requires the Director of National Intelligence to report annually to Congress and the Privacy and Civil Liberties Oversight Board on bulk data acquisitions, with the unclassified portion published publicly.
Extends FISA Section 702 protections that previously applied only to 'United States persons' to a broader category of 'covered persons,' and broadens the definition of a 'query' to cover automated searches and searches of subsets of already-retrieved data.
Raises the legal standard for targeting a known American under Section 702, requiring that obtaining that person's information be 'the primary' purpose of the acquisition rather than merely 'a significant' purpose.
Extends the rule barring use of Section 702-derived information about an American without court approval so that it now applies in civil and administrative proceedings, not just criminal ones.
Narrows which companies the government can compel to assist with Section 702 surveillance by removing 'custodians' and similar entities from the definition of electronic communication service provider, and voids existing directives to entities that no longer qualify.
Prohibits the government from intentionally acquiring, for foreign-intelligence purposes, any communication where the sender and all recipients are known to be inside the United States, except under existing FISA court authority or a reported imminent life-or-death emergency.
Requires Americans' information collected for foreign-intelligence purposes outside FISA authorities to be destroyed within five years of collection unless the Attorney General determines in writing it must be kept for pending litigation or an authorized proceeding, and directs agencies to adopt retention procedures.
Strengthens the independent advisers (amici curiae) before the FISA Court by requiring cybersecurity and cryptography expertise and at least one legal and one technical expert, making their role to raise Americans' privacy and civil-liberties interests mandatory rather than optional, and giving them more time and access to review surveillance applications.
Requires that FISA surveillance applications fairly reflect all relevant information and directs the Attorney General to issue accuracy procedures for those applications within 180 days.
Requires the Department of Justice and intelligence-community Inspectors General to audit FISA court-order applications and Section 702 directives for accuracy and compliance, report findings to Congress, the courts, the oversight board, and the amici, and publish unclassified versions.
Strengthens the Privacy and Civil Liberties Oversight Board by adding it to those who receive certain whistleblower disclosures, setting its pay relative to intelligence-community positions, and requiring it to report publicly on how often First Amendment-protected activity and protected classes such as race, ethnicity, and religion appear in FISA applications.
Requires the government to get a probable-cause warrant to obtain a person's location information, web-browsing records, and internet search-query records from a service provider, instead of the lower legal standard previously allowed.
Requires a warrant to obtain the contents of stored emails and other electronic communications regardless of their age, eliminating the prior rule that let the government obtain communications older than 180 days without a warrant.
Raises the standard for pen-register and trap-and-trace surveillance (which captures dialing, routing, and addressing data) by making a court order discretionary ('may' instead of 'shall') and requiring the government to provide specific, articulable facts showing reasonable grounds the information is relevant and material.
Requires the government to obtain a tracking order or warrant to use a tracking device, renaming the relevant provision and setting jurisdiction rules for where the order applies.
Bars federal agencies from obtaining or using data that a state or local agency acquired in a way that would have violated federal law had the federal government done it, makes any such laundered data unusable in federal proceedings, and preserves an aggrieved person's ability to use the data against the violation.
Requires the Attorney General to issue and publish minimization procedures for voluntary disclosures of communications and records by providers to federal agencies, including removing or masking personal information and not retaining the information after the investigation ends.
Expands public transparency by requiring pen-register and wiretap reports to be published online, requiring annual public reporting on voluntary provider disclosures to federal agencies, and requiring the Director of National Intelligence to publish a good-faith estimate of how many Americans' communications are collected under Section 702.
Extends the expiration date of Section 702 surveillance authority to April 20, 2030, and repeals the Title V business-records (Section 215-type) authority 180 days after enactment.
Adds a privacy exception to the Driver Privacy Act so that certain vehicle data is protected unless an exception applies.
Who it helps · who it burdens.
Who it helps
- Americans whose communications or data are swept into surveillanceGain new protections: the government generally needs a court order or warrant before searching or accessing their foreign-intelligence-collected information, location, web-browsing, search-query, and email records, and unlawfully obtained information cannot be used against them.
- FISA Court advisers (amici curiae) and the Privacy and Civil Liberties Oversight BoardGain expanded authority, expertise requirements, mandatory roles, pay parity, and new reporting and review responsibilities over surveillance applications.
Who it burdens
- Federal intelligence and law-enforcement agenciesTake on new duties and limits: they must obtain warrants or court orders before many queries and acquisitions, keep detailed records of every search, report compliance to Congress, destroy improperly held or aging data, and submit to Inspector General audits.
- Data brokers and commercial sellers of personal dataLose the intelligence community as a customer for datasets of Americans' personal data, because agencies may not acquire such 'covered data' absent a court order, consent, or a narrow exception.
- Communication service providersMust respond only to warrants for stored content, location, web-browsing, and search-query records, follow new disclosure-minimization procedures, and submit certain ongoing certifications to Congress; some entities are removed from the class that can be compelled to assist.