Law Enforcement Data Requests and Subpoenas: A Security Team's Response Guide

Retool's new app builder is where AI-generated code ships safely
Building apps with AI is easy. Getting them to production safely is another story.
Law enforcement data requests are a routine operational reality for any technology company with users at scale. In 2024, Google received over 200,000 requests from government agencies worldwide; even small SaaS companies with a few thousand users receive occasional subpoenas related to criminal investigations involving their users. Handling these correctly — neither over-producing data beyond legal compulsion nor under-producing in a way that creates contempt risk — requires a documented process developed with legal counsel before the first request arrives.
Security and operations teams are often in the operational chain for these requests: preserving specific user data, producing account logs, and coordinating technical extraction of requested information. This guide covers what each instrument type requires, how to protect your organization through the production process, and the organizational infrastructure that makes a repeatable process possible.
The four US legal instruments: what each authorizes
Each legal instrument type authorizes a specific category of data and carries its own judicial review threshold, response timeline, and notification restrictions. Treating a search warrant like a subpoena — or vice versa — creates liability in both directions: over-production exposes user privacy, under-production creates contempt risk. The four primary instruments are administrative subpoenas, grand jury subpoenas, 18 USC 2703(d) court orders, and search warrants. A fifth instrument, the National Security Letter, shares the scope of an administrative subpoena but adds a mandatory non-disclosure order. Legal counsel should review every instrument before any data is preserved or produced.
Administrative subpoena: subscriber information and metadata
Administrative subpoenas are issued by federal agencies without judicial review. They are authorized to obtain basic subscriber information under 18 U.S.C. 2703(c)(2): name, address, records of session times and durations, length of service and type of service used, telephone or instrument number or other subscriber number, and means of payment. They cannot compel production of content (message content, stored files) without higher legal authority. Response action: verify the agency issuing, confirm your legal obligation under the applicable statute, produce only the listed subscriber information. Turnaround: 10-14 business days is typical, though some specify shorter windows.
Search warrant: required for stored content
A search warrant is the highest-standard instrument and the only one that can compel production of stored content of electronic communications (email content, private messages, stored files). Warrants require probable cause, signed by a federal magistrate judge, and must specify the scope of data to be seized. Warrants typically come with sealing orders preventing you from notifying the target. Response action: produce only the data specified in the warrant, no broader. If the warrant specifies 'all emails sent or received by user X between January and March 2026,' produce only that — not the user's complete email history. Keep a copy of what was produced and document the chain of custody.
National Security Letter: no judicial review, mandatory non-disclosure
NSLs are administrative subpoenas issued directly by FBI field offices in national security investigations, requiring no judicial approval. They can compel basic subscriber information and metadata (same scope as administrative subpoenas) but not content. NSLs carry mandatory non-disclosure orders — you cannot tell anyone, including the target, that you received an NSL. Receipt action: notify your legal counsel immediately and only your legal counsel. Remove your warrant canary if one exists. Comply with the production requirement. NSL non-disclosure orders have been challenged successfully in court in some cases — legal counsel can evaluate whether to challenge.
The production workflow: from receipt to delivery
A repeatable production workflow protects your organization by creating an auditable record of every request received, every validation step taken, and every record produced. The workflow has two gates before any data leaves the organization: a legal validity check and a scope confirmation. Both are designed to prevent the two most common production errors — complying with a fraudulent or invalid instrument, and producing data beyond what the instrument legally compels. The steps below cover the validation check, the scoped extraction process, and the documentation practices that protect you in any subsequent regulatory or litigation review.
Validate before acting on any legal process
Before taking any action: verify the document is a legitimate legal instrument (check the court seal, issuing attorney's bar number, case number format, and that the issuing court has jurisdiction over your company). Phishing attempts that mimic legal process documents are common — always call the issuing agency directly using a phone number from official government websites, not the number on the document. Refer all legal process to legal counsel before any data is produced or preserved. Never comply immediately under pressure from a law enforcement officer calling directly — legitimate law enforcement follows the formal legal process channel.
Scope the production precisely
Produce only what is legally compelled, nothing more. Build a data extraction process that accepts specific parameters (user ID, date range, data type) and produces exactly that scope. Before producing: have legal counsel review what you are producing against what the instrument requires. Common over-production mistakes: producing all user data when only subscriber information was subpoenaed, producing associated accounts when only the named account was listed, and including data from before the specified date range. Document the exact files or records produced, the format, the date of production, and to whom they were delivered.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
The bottom line
Law enforcement data requests require legal counsel involvement at every step, a documented workflow that has been reviewed before the first request arrives, and precise production that gives law enforcement exactly what they are legally entitled to — no more. Build the infrastructure now: a legal process log, a data production tool, a designated legal process coordinator, and a published transparency report practice. When a request arrives, the sequence is: validate the instrument, involve legal counsel, check for non-disclosure requirements, preserve the data, produce only the specified scope, and document everything. Over-disclosure creates user privacy liability; under-disclosure creates contempt risk; premature user notification can obstruct an investigation. The documented process protects you from all three.
Frequently asked questions
What types of legal instruments can compel us to produce user data?
In the US: Administrative subpoenas (issued by agencies like the FBI, DEA without judicial review, typically for subscriber information and metadata, not content). Grand jury subpoenas (compelling production for a criminal investigation, require a prosecutor but no judicial approval). 18 U.S.C. 2703(d) court orders (require specific articulable facts that information is relevant and material, provide access to non-content records and communications older than 180 days). Search warrants (require probable cause, issued by a judge, required for accessing content of stored electronic communications). National Security Letters (administrative subpoenas issued by FBI for national security investigations, carry mandatory non-disclosure orders). International requests vary by country and mutual legal assistance treaty.
Do we have to comply with every subpoena we receive?
No. You should validate every legal process document before complying. Check: the document is from the correct jurisdiction and authority for the data requested (a California state subpoena cannot compel data held in Ireland without an MLAT); the document is facially valid (proper court header, signature, case number, serving attorney bar number); the request is narrowly scoped (a subpoena demanding 'all data for all users' is overbroad); you are actually the correct party (the subpoena is addressed to your legal entity, not a similarly named company). Refer all legal process to your legal counsel before any action. Never ignore a legal process, but legal counsel should evaluate validity before production.
Can we notify a user that law enforcement requested their data?
It depends on the instrument. Administrative subpoenas and grand jury subpoenas generally do not have automatic non-disclosure, but law enforcement can seek a gag order. Court orders under 2703(d) include default non-disclosure provisions. Search warrants come with a sealing order prohibiting disclosure. National Security Letters include mandatory non-disclosure orders. When a non-disclosure order or gag is in effect, you cannot notify the user, and doing so can constitute criminal contempt of court. When no non-disclosure order is in effect, you have discretion to notify — many companies do as a matter of policy, but review the instrument and local law before notifying. Always involve legal counsel before making any notification decision.
What data do we preserve vs. produce in response to a legal process?
Preservation (the 2703(f) letter): when law enforcement sends a preservation request (before a full legal process), you preserve the specified data and prevent its deletion for 90 days (renewable). You do not produce the data — you only hold it. Production: respond only to the scope specified in the instrument. A subpoena for subscriber information (name, address, billing history) does not authorize producing message content. A 2703(d) court order for metadata does not authorize producing stored content. Never volunteer data beyond what is legally compelled. Document exactly what data was produced, the date, and to whom, for your records.
What is a warrant canary and how should we manage it?
A warrant canary is a statement published in a transparency report or on a company website stating that no classified government data demand has been received (for example, 'As of Q2 2026, we have received no NSLs'). When an NSL with a non-disclosure order is served, the company cannot announce it received an NSL, but it can remove the canary statement — which signals to the public that something has changed without directly violating the non-disclosure order. To manage a canary: update it on a regular published schedule (quarterly), have legal counsel review every update, and remove it immediately upon receiving an NSL with non-disclosure. Note that canaries are not legally bulletproof in all jurisdictions — consult legal counsel on their effectiveness in your specific context.
How do we handle law enforcement data requests from foreign governments?
Foreign government data requests require different analysis than US law enforcement. Direct foreign requests (a foreign police agency emailing your legal team) are generally not legally compellable under US law — you can comply voluntarily if legally permitted to do so by both US and foreign law, but you are not compelled. Formal international requests (MLATs — Mutual Legal Assistance Treaties) route through the US Department of Justice and result in valid US legal process. GDPR and other foreign privacy laws may prohibit producing EU user data in response to US government requests without an appropriate legal basis. The CLOUD Act provides a framework for US-UK and US-EU data sharing agreements that may affect compliance obligations. Treat all foreign requests as requiring legal counsel review before any action.
What should our law enforcement response process look like organizationally?
Build a documented workflow before you receive your first request. Designate a legal process coordinator (typically legal counsel or the security/privacy team) who receives all requests. Create a secure, access-controlled log of all requests received, actions taken, data produced, and non-disclosure orders in effect. Build a data production tool that can export exactly the data specified in the legal process (not more) in a standard format. Establish a target response time (many instruments have 10-14 day response windows). Publish an annual transparency report covering aggregate request counts by instrument type. Review your logging practices: you can only produce data you actually retain, so align retention policies with what you are likely to need to produce.
Sources & references
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
Win a $2,495 Black Hat pass.
Full-access to Black Hat USA 2026 in Las Vegas. Subscribe free to enter.
