18 U.S.C. 2258A: What Providers Are Legally Required to Report.
In addition to establishing providers’ duties in the event of child exploitation, Section 2258A also defines which providers are affected under the federal child exploitation statutes. Specifically, Section 2258E defines a “provider” as an entity that qualifies as either an “electronic communication service provider” or a “remote computing service”. Those terms, in turn, are identical to the definitions of “electronic communication service” and “remote computing service” in the Electronic Communications Privacy Act (18 U.S.C. 2258A(d)). The Electronic Communications Privacy Act (stored communications statute) defines these terms, among others, as:
- “Any internet service provider (ISP) or other provider that provides an electronic communication service or a remote computing service. This includes a wide range of entities such as companies providing wireless internet access, including:
- Satellite, cellular, and other wireless communication services
- Web-based email services
- Other internet-based communications services
- Cloud computing services
- “Any other person, business, entity, or entity that makes available to the public, either commercially or without charge, electronic communication services or remote computing services or both. This includes entities such as, among others, those providing content hosting, content distribution, and data processing services.”
The plain language of Section 2258A applies to both commercial providers and those offering their services free of charge. Therefore, nonprofit entities, such as charitable or educational online platforms, do not qualify for an exception based on their nonprofit status.
While the majority of public providers will qualify as “covered providers” under the statute, there may still be entities outside the scope of Section 2258A that face potential reporting duties. Entities in certain jurisdictions should investigate their potential reporting duties under state law.
Who is legally covered by 18 U.S.C. 2258A?
The federal provider-reporting duty is codified at 18 U.S.C. § 2258A. While this statute does not impose any legal requirements on the vast majority of ordinary internet users, it does establish legal requirements for “covered providers.” The scope of covered providers is defined in Section 2258E, which includes:
- Electronic communication service providers; and,
- Remote computing service providers.
Section 2258E adopts the definitions of “electronic communication service” and “remote computing service” found in 18 U.S.C. § 2510(15) and 18 U.S.C. § 2711(2), respectively, which are also used in the stored communications statute. The Stored Communications Act (SCA) also adopts these definitions. The SCA defines the terms as:
- “Electronic communication service” (18 U.S.C. § 2510(15)): “‘electronic communication service’ means any service which provides to users thereof the ability to send or receive wire or electronic communications.”
- “Remote computing service” (18 U.S.C. § 2711(2)): “‘remote computing service’ means the provision to the public of computer storage or processing services by means of an electronic communications system.”
Does Operating a Private Communications System Make an Employer a “Covered Provider”?
As established above, “covered providers” are providers of electronic communication services or remote computing services, although the statutory definition of “remote computing service” requires provision to the public. Operating a private employee-only communications system does not, in and of itself, make an employer a “covered provider” under Section 2258A. An employer providing a remote computing service must make that service “available to the public” in order to fall within the scope of Section 2258A; the electronic-communication-service definition contains no comparable public-availability language.
What actual knowledge triggers a CyberTipline report
What triggers the mandatory duty to report to NCMEC (and preserve data for law enforcement)?
Covered providers must reportapparent (and not necessarily actual) criminal violations of specified federal statutes. The relevant provisions of Section 2258A address apparent violations of the following child-related federal provisions:
- 18 U.S.C. 1591(a)
- 18 U.S.C. 2251, 2251A, 2252, 2252A, and 2252B
- 18 U.S.C. 2260
- 18 U.S.C. 2422(b)
- 18 U.S.C. 2423(a)
- While there are many apparent (and actual) offenses under these covered provisions, the vast majority are within the definition of “child exploitation” for purposes of federal criminal law (and cyber-reporting under Section 2258A).
- While the majority of apparent violations under Section 1591(a) do not fall within the scope of Section 2258A, providers must report apparent violations of the federal trafficking statute under Section 2258A if “the violation involves a minor”.
- The four categories of apparent criminal violations covered by Section 2258A are:
- Sex trafficking (involving a child) under Section 1591(a);
- “The illegal solicitation, production, distribution, promotion, or advertisement of any other form of child sexual exploitation (i.e. Other than sex trafficking)”, or, more broadly, production, distribution, promotion, or advertisement of child sexual exploitation material (i.e. CSAM) under Sections 2251, 2251A, 2252, 2252A, and 2252B;
- Production abroad of sexually explicit depictions of a minor for importation into the United States under Section 2260;
- Solicitations by the Internet for unlawful sexual activity with children under Section 2422(b).
- “Apparent” criminal violations are a lower threshold than confirmed criminal violations. While a provider must have “actual knowledge” that it possesses evidence of an “apparent” offense in order to trigger its mandatory reporting obligations under Section 2258A, the provider does not need to have evidence of an “actual” violation of federal criminal law (i.e. Beyond a reasonable doubt) to satisfy its statutory reporting obligation.
- At the same time, merely having “generalized suspicion” or “knowledge of certain circumstances and conditions that are more likely than not indicative of unlawful conduct” generally will not suffice to satisfy Section 2258A’s actual-knowledge trigger.
- While most providers’ reporting systems are fully automated and operate in real-time, a cybertipline report is either voluntary or required under Section 2258A depending on the provider’s level of knowledge of the underlying apparent violation. The following table summarizes the conditions under which cybertipline reports are either voluntary or mandatory under Section 2258A:
- When a child safety-related algorithm flags a child-exploitation-related violation, an employee or user of the platform, or an employee of an affiliated third-party company, reports a child-exploitation-related violation, or other internal or external compliance personnel reports a child-exploitation-related violation, the nature of the apparent violation will determine the level of urgency (i.e. Whether reporting is mandated) and the content of the provider’s reporting obligation.
- Conversely, when a child-exploitation-related violation is suspected but not confirmed, or, more generally, the extent to which a covered provider has “actual knowledge” of an “apparent” offense, this is the central question as to whether providers can only make a cybertipline report on a voluntary basis or if reporting is mandatory under Section 2258A.
- Once a covered provider’s statutory obligation under Section 2258A is triggered (i.e. upon actual knowledge of an apparent offense), the covered provider must promptly report to NCMEC and preserve the materials covered by the statute.
What must providers include and preserve in a CyberTip?
While the Electronic Communications Privacy Act, Section 2258A, and federal law broadly require that “covered providers” report evidence of apparent child exploitation to the National Center for Missing & Exploited Children (NCMEC), there are specific requirements as to the manner, timing, content, and scope of these mandatory reports. Specifically: - Mandatory reports go to the NCMEC’s “CyberTipline,” rather than directly to local, state, or federal law enforcement.
- In addition to providing information related to the suspected criminal activity, covered providers may also, at their sole discretion, provide information relating to the identity of the individual involved. This may include (among other things):
- The name and address (or other contact information, such as an e-mail address) of the subscriber(s) involved;
- The subscriber’s account number(s) and any billing address(es) associated with the account(s);
- The subscriber’s IP address(es), and any other identifiers of the computer or device used to access the covered provider’s service; and,
- Any other identifiers of the subscriber(s) that are “reasonably available.”
- In addition to submitting the mandatory CyberTipline report, covered providers are also required to preserve the contents that were submitted with the report. This includes images or video depicting child exploitation, as well as any other content related to the suspected criminal activity. While this data-preservation obligation was extended to one year pursuant to the REPORT Act, Section 2258A also clarifies that it does not limit a covered provider’s preservation obligations under 18 U.S.C. § 2703(f). In fact, upon receipt of a valid § 2703(f) evidence preservation request, a covered provider’s obligations may extend to preserving evidence in addition to (and/or in addition to the one-year period following) the data preserved pursuant to a Section 2258A report.
- A Section 2258A report must also provide the covered provider’s:
- Mailing address;
- Telephone number;
- Facsimile number;
- Electronic mail address; and,
- Individual point of contact.
- A Section 2258A report may, at the provider’s sole discretion and to the extent within its custody or control, include information about the known facts and circumstances surrounding the apparent offense. This may include:
- The date the apparent offense came to the provider’s attention;
- The date(s) and time(s) (including time zone) of the underlying transmissions, posts, emails, and/or other activity;
- A description of the alleged child exploitation offense, including the specific images, videos, or other content that led to the suspected offense; and,
- Any other information related to the apparent offense that is “reasonably available” to the covered provider.
- If a covered provider has relevant images or video within its custody or control, it may, at its sole discretion, include any visual depiction of apparent child pornography or other content relating to the incident with the report. Todd Spodek is the managing partner of Spodek Law Group, a second generation criminal defense firm that has been practicing since 1976.
Does 2258A require providers to monitor or scan users for (apparent) violations of federal law?
To meet the actual-knowledge requirement under Section 2258A, covered providers need only have actual knowledge of facts or circumstances that indicate an apparent violation of a covered federal child exploitation statute. This knowledge can derive from sources such as automated detection tools, employee or moderator review, user complaints, or referrals from other companies or federal authorities.
We can assist providers of any size with implementing monitoring, search, and scan-related requirements, as well as screening and investigation compliance strategies.
Does 18 U.S.C. 2258A require providers to search, screen, or scan?
While covered providers have an obligation to report apparent violations to NCMEC, they do not have an affirmative duty to proactively search, screen, or scan for covered offenses. Covered providers’ reporting obligations trigger upon actual knowledge of facts or circumstances indicative of a violation, not a general obligation to affirmatively search for violations.
But, the extent to which a provider has an obligation to affirmatively monitor content, and the extent to which it may actually monitor and review content, are subject to a wide range of considerations. We work with providers to determine their monitoring obligations and implement appropriate compliance procedures.
Does Section 2258A mandate the use of hash-matching technology?
At this time, federal law does not require covered providers to deploy hash-matching technology to identify potential child exploitation material (i.e. Child sexual abuse material, or “CSAM”). While some providers voluntarily use hash-matching and other digital fingerprinting technologies to recognize and report known CSAM, this practice is not currently mandated by Section 2258A.
We can assist providers with assessing the suitability of hash-matching technology, and we can work with providers to implement appropriate compliance procedures if warranted.
Does content disclosure fall within the scope of Section 2258A?
Generally, content disclosure to NCMEC, and other entities that may play an intervening role in enforcement, is governed by the Electronic Communications Privacy Act’s (i.e. The Stored Communications Act, or “SCA”)
What happens after NCMEC receives a CyberTip?
NCMEC serves as a national clearinghouse for information related to child sexual exploitation, which includes fielding CyberTipline reports from providers (as well as individual citizens). After receiving a CyberTip, NCMEC reviews the tip and makes it available to one or more specified federal, state, local, or foreign law-enforcement agencies involved in the relevant investigation. A CyberTipline report, by itself, is not a criminal charge or conviction; rather, it is simply the provision of evidence that, as described above, falls within the provider’s mandatory reporting obligations under Section 2258A.
Does a CyberTip authorize law enforcement to search my home?
Receiving a CyberTip will not necessarily authorize law enforcement to execute a home search or examine a device. While a CyberTipline report may be the first step in a federal or state child exploitation investigation, initiating the investigation by targeting the home or devices connected to the internet is generally not immediate. If law enforcement obtains information from the provider and other sources that support its investigation, it can seek a warrant to search and seize any devices that it can establish link an apparent violation of the law to a residence.
How can I protect myself if I am worried about an investigation?
If you are worried that an investigation related to a CyberTipline report is pending (or that it might even be underway already), you should immediately consult with an experienced federal criminal defense attorney. We can intervene promptly.
What are the next steps after law enforcement receives a CyberTip?
After obtaining an apparent violation from the National Center for Missing and Exploited Children (NCMEC), investigating authorities may:
- Initiate a cyber investigation by requesting the pertinent subscriber and account records from the reporting provider. These requests will often take the form of grand jury subpoenas;
- Seek a warrant to seize and forensically examine any computers, smartphones, or other electronic devices that the investigator believes are connected to the illegal activity.
- Seek a warrant for the physical search and arrest of the suspected offense participant(s).
What penalties and protections apply under Section 2258A?
Section 2258A contains provisions for civil and criminal penalties. Recently enacted under the REPORT Act, penalties for covered providers’ knowing failure to report apparent offenses under Section 2258A have increased. An initial knowing failure-to-report violation will now cost $850,000, while subsequent knowing failure-to-report violations will cost $1 million. Both fines are subject to periodic inflation adjustments.
Section 2258A’s failure-to-report provision does not currently authorize imprisonment, but it does provide for statutory liability protection for covered providers under Section 2258B.
What are the conditions for statutory liability protection under Section 2258B?
Under Section 2258B, covered providers, along with their employees and agents, can potentially obtain statutory liability protection in connection with:
- CyberTipline reporting, and
- Data preservation under Section 2258A.
To qualify for protection under Section 2258B, reporting and data preservation must be accompanied by:
- No intentional misconduct.
- No reckless conduct (including conduct that was performed with willful ignorance or gross negligence).
- No statutory or common law negligence.
- A good faith effort to maintain patient, client, and employee confidentiality.
Additionally, if a covered provider’s data preservation or reporting is not voluntary (i.e. It is mandated under Section 2258A), it must comply with all other applicable statutory procedures. While Section 2258B offers limited protection, providers must still comply with the Stored Communications Act and other federal privacy protections.
What is Section 2258, and who does it apply to?
Section 2258 addresses the failure of individuals who “regularly work” in federal-operated facilities and institutions to report evidence of federal sexual crimes. This includes, but is not limited to, individuals working in:
- Hospitals, clinics, and other medical facilities.
- Federal lands (including National Parks).
- Schools, institutions of higher education, and other child-care related facilities.
While Section 2258 does not cover CyberTipline reporting, the failure to report federal sexual offenses is a criminal offense under Section 2258 that authorizes up to one year’s imprisonment. Additionally, criminal fines of $250,000 apply for first criminal offenses and $500,000 apply for subsequent criminal offenses. Civil penalties apply for “knowing and willful” failures to report, as well, in the amount of $25,000 for first civil offenses and $50,000 for subsequent civil offenses.
Get Advice on Your Situation
If you want someone to look at the specifics of your case, Spodek Law Group handles federal criminal defense nationwide from New York and Los Angeles. The firm has been practicing since 1976 and its motto is simple: we owe loyalty to only you. Call 212-300-5196.
Reading is good. Calling is better.
Answered within 24 hours, guaranteed. Some stories are better told out loud -
212 300 5196