Investigations
Is who a person contacted treated the same as what they said?
No. Two instruments define the line in their own text — the Convention defines subscriber information as data "other than traffic or content data", and United States law excludes contents from the pen-register and subscriber-record definitions — and the three categories carry different conditions.
In short
Legal systems do not treat a communication as one undifferentiated thing. They separate what was said from the record that a communication happened, and separate both from the account details of the person who holds the service. Three categories, three sets of conditions.
AnalysisTwo of the instruments read here draw the line in their own definitions rather than leaving it to be inferred, which is unusual and makes the categories checkable rather than argued.
Why it exists
AnalysisThe categories exist because the intrusions are different sizes and the investigative uses are different too. Establishing that a particular account belongs to a particular person is often the first step in an investigation and reveals little on its own. Establishing who contacted whom, when, and for how long reveals a great deal about associations without revealing a word of what was said. Obtaining what was said reveals the most.
How it works
The Convention on Cybercrime defines the third category by excluding the other two. Article 18(3) provides that "subscriber information" means information held by a service provider relating to subscribers of its services other than traffic or content data, by which can be established the type of service used and the period of service; the subscriber’s identity, postal or geographic address, telephone and other access number and billing and payment information available on the basis of the service agreement; and any other information on the site of installation of communication equipment available on the same basis.
United States law states the same boundary twice, in definitions rather than in argument. Section 3127(3) of Title 18 defines a pen register as a device or process recording or decoding "dialing, routing, addressing, or signaling information" transmitted by an instrument or facility, "provided, however, that such information shall not include the contents of any communication". Section 2703(c)(1) permits a governmental entity to require disclosure of "a record or other information pertaining to a subscriber to or customer of such service (not including the contents of communications)".
The consequence in that statute is a ladder of instruments. Section 2703(c)(2) lists six items a provider shall disclose on an administrative, grand jury or trial subpoena — name; address; local and long distance telephone connection records, or records of session times and durations; length of service including start date and types of service utilised; telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and means and source of payment. Other records under § 2703(c) require a warrant, a § 2703(d) court order, or the subscriber’s consent. Contents in electronic storage for 180 days or less require a warrant.
- Germany — three provisions, three thresholds
- Subscriber-type information under § 100j may be requested where necessary to investigate the facts or determine an accused’s whereabouts. Traffic data under § 100g requires specific facts grounding suspicion of an offence of significant weight also in the individual case, or of an offence committed by means of telecommunications, and requires the collection to stand in an appropriate relationship to the significance of the matter. Content monitoring under § 100a requires a serious offence from a closed catalogue, seriousness in the individual case, and subsidiarity.
- And one exception that reverses the order
- Where a § 100j request reaches data by which access to terminal devices or their storage is protected, the ordinary low threshold does not apply: the information may be requested only where the statutory conditions for using those data are met, and for the digital-services limb only for the prosecution of an especially serious offence within the § 100b(2) categories. Material that is formally subscriber data is pulled up to the level of the code’s most intrusive power.
- Location data is a traffic-data question, and Germany splits it by time
- § 100g(1) provides that the collection of stored — retrograd — location data is permitted only on the stricter conditions of § 100g(2), and that otherwise location data may be collected only for future traffic data or in real time, and only in the case of an offence of significant weight. Historical and prospective location data are not the same request in this system.
Common misconceptions
Widely held beliefs that do not match how the system actually operates.
Common belief: Metadata is just data about data, so obtaining it raises no real question.
In practice: The systems read here condition it. Germany requires specific facts grounding suspicion of an offence of significant weight also in the individual case, and requires proportionality to the significance of the matter. The Convention gives real-time traffic data its own article and its own safeguards.
Common belief: Who a person contacted and what they said are legally the same material.
In practice: Article 18(3) of the Convention defines subscriber information as data "other than traffic or content data". Section 3127(3) of Title 18 defines a pen register as recording dialling, routing, addressing or signalling information "provided, however, that such information shall not include the contents of any communication".
Common belief: Subscriber information is a category of communication content.
In practice: Both instruments that define it exclude content expressly. Section 2703(c)(1) covers "a record or other information pertaining to a subscriber ... (not including the contents of communications)".
Common belief: Basic account details always require a court to authorise their disclosure.
In practice: Section 2703(c)(2) lists six items a provider shall disclose on an administrative, grand jury or trial subpoena. Germany’s § 100j states no judicial order for the ordinary subscriber-data request.
Both systems then impose higher requirements for other categories in the same statute.
Common belief: Because subscriber data is the least protected category, everything in it is.
In practice: Germany’s § 100j reverses the order for one class of material: where the request reaches data protecting access to terminal devices or their storage, the ordinary threshold does not apply and the especially-serious-offence conditions do.
Common belief: The categories mean the same thing in every legal system.
In practice: They are defined separately in each instrument, and this page describes them separately for that reason. The German definitions sit in telecommunications and digital-services statutes that were not read for this wave, and no alignment with the Convention’s categories is assumed.
How this varies between jurisdictions
A required section on every guide. Arrangements differ between countries, and we say how.
Three categories, and three different ways of making the line operative.
- By definition, excluding the other two — Council of Europe, Convention Art. 18(3): subscriber information is data "other than traffic or content data".
- By statutory definition of the instrument — United States, 18 U.S.C. § 3127(3): a pen register records dialling, routing, addressing or signalling information and "shall not include the contents of any communication".
- By the instrument required — United States, § 2703: subpoena for six enumerated items, § 2703(d) court order on specific and articulable facts, warrant for contents held 180 days or less.
- By separate provisions with separate thresholds — Germany, StPO § 100j, § 100g and § 100a.
- With an exception that inverts the graduation for access-credential data — Germany, § 100j.
- With location data split into stored and prospective, on different conditions — Germany, § 100g(1).
Rights and accountability
AnalysisWhat makes these categories matter for accountability is that they are the unit an authorisation is written in. An order that names a category defines what may be collected, and an order that collects a different category has exceeded itself in a way that can be identified afterwards without any argument about degree.
It is worth noting who the statutory subjects are, because the terms are precise and none of them is a citizenship term. United States law speaks of a "subscriber or customer" and of a "governmental entity"; the Convention of "subscribers of its services" and of a "service provider offering its services in the territory of the Party"; German law of "der Beschuldigte" and of those who commercially provide telecommunications services. The category of person a provision protects is drawn from the service relationship, not from nationality.
What we could not establish
- The German definitions of Bestandsdaten and Verkehrsdaten sit in the telecommunications and digital-services statutes that §§ 100g and 100j cross-refer to. Those statutes were not read, and no claim here rests on the precise German definitions.
- Whether any system’s categories align with any other’s was not researched and is not assumed. The German and Convention categories are described separately for that reason.
- Nothing here describes how any category of data is generated, held, transmitted or obtained.
Where to go next
Related: interception and stored data, preserving data and producing it, and what privacy protects in law. These categories are defined for each instrument separately, and the international ones do not all match: see data categories across instruments.
Related topics
- Is listening to a conversation the same legal act as obtaining messages already stored?
No system read here treats them as one power. The Convention gives each its own article; Germany conditions them differently in the same code; and Japan’s Code excludes interception altogether, routing it to a separate Act.
- Who decides that an investigator may take a digital investigative step?
Not always a judge, and not always the same judge. One German power needs a single court, another a three-judge panel with a higher court taking over after six months; United States law allocates three different instruments to three categories; and the Convention requires "judicial or other independent supervision".
- If data has been "preserved", has anyone read it?
No. Preservation freezes material so that it still exists later; production hands it over. The Convention caps preservation at ninety days precisely because its purpose is to enable authorities to seek disclosure afterwards, by a separate power.
- What exactly does a legal system protect when it protects privacy?
Not one interest but several, bundled differently in each text. Switzerland puts private life, the home, mail and telecommunications in one article; South Africa defines privacy by the searches it forbids; Brazil separates intimacy from the house and both from communications.
Sources
Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0001839) · International organisation · 2001-11-23 · link verified 2026-09-05
WAVE 22 ADDITION. ACCESS NOTE: rm.coe.int and coe.int returned HTTP 403 to automated requests in this session, so the Convention was read from the official Dutch government treaty database, which publishes the authentic English text alongside the Dutch translation. The English text quoted below is the authentic one; English and French are the authentic languages. Supports Art. 14(1)–(2), that the procedural powers are established “for the purpose of specific criminal investigations or proceedings” and are applied to the offences established under Arts. 2–11, to other criminal offences committed by means of a computer system, and to “the collection of evidence in electronic form of a criminal offence”. Supports Art. 14(3)(a), that a Party restricting the Art. 20 power to specified offences must not restrict it more narrowly than the range to which it applies Art. 21. Supports Art. 15(1), that the powers are subject to conditions and safeguards under domestic law providing adequate protection of human rights, including rights under the 1950 European Convention and the 1966 Covenant, “and which shall incorporate the principle of proportionality”. Supports Art. 15(2), that such conditions and safeguards shall, as appropriate, “include judicial or other independent supervision, grounds justifying application, and limitation of the scope and the duration of such power or procedure”. Supports Art. 16(1)–(3): expedited preservation of specified stored computer data “including traffic data”, in particular where it is particularly vulnerable to loss or modification; where effected by order to a person, an obligation to preserve and maintain integrity “for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure”, renewable; and an obligation on the custodian to keep the undertaking of the procedure confidential. Supports Art. 17, expedited preservation and PARTIAL disclosure of traffic data sufficient to identify the service providers and the path through which the communication was transmitted. Supports Art. 18(1)(a)–(b), the production order: a person in the territory to submit specified stored computer data in that person’s possession or control, and a service provider offering services in the territory to submit subscriber information. Supports Art. 18(3), which defines “subscriber information” as information held by a service provider relating to subscribers of its services “OTHER THAN TRAFFIC OR CONTENT DATA” and by which the type of service, the subscriber’s identity, postal or geographic address, telephone and other access number, billing and payment information, and information on the site of installation of communication equipment can be established. Supports Art. 19(1)–(4): the power to search or similarly access a computer system or a computer-data storage medium; the power under 19(2) to EXTEND the search expeditiously to another system in the territory where the data sought is “lawfully accessible from or available to the initial system”; the power under 19(3) to seize or similarly secure, comprising the separate powers to “seize or similarly secure a computer system or part of it or a computer-data storage medium”, to “make and retain a copy of those computer data”, to “maintain the integrity of the relevant stored computer data”, and to “render inaccessible or remove those computer data in the accessed computer system”; and the power under 19(4) to order any person with knowledge about the functioning of the system to provide, as is reasonable, the necessary information. Supports Art. 20, real-time collection of TRAFFIC data, and Art. 21, interception of CONTENT data, the latter available only “in relation to a range of serious offences to be determined by domestic law”; both articles oblige a service provider to keep the execution confidential. Cited for the structural propositions that preservation is a distinct act from production, that traffic data and content data are distinct powers, that subscriber information is defined by exclusion from both, and that seizing, copying and accessing are separately enumerated. LIMITATIONS, and they are load-bearing: this is a TREATY. It obliges Parties to establish powers in domestic law; it is NOT evidence of what any particular Party has enacted, and no country claim on this platform rests on it. It describes no technique. STATUS: in force; the Convention has two additional protocols, of which the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was located but NOT read for this wave. WAVE 23 ADDITION. That Protocol has now been read and is held separately as `coe-cybercrime-second-protocol`. Chapter III of the Convention, on international co-operation, was read from the same authentic English text, and it is a different subject from the domestic powers above. Supports Art. 23, that Parties co-operate “in accordance with the provisions of this chapter, and through the application of relevant international instruments on international co-operation in criminal matters, arrangements agreed on the basis of uniform or reciprocal legislation, and domestic laws”. Supports Art. 25(1)-(4), and in particular Art. 25(2), that “Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35” -- the Convention’s own statement that its co-operation articles are not self-executing -- and Art. 25(4), that except as specifically provided “mutual assistance shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation”. Supports Art. 27(1), that the Article applies only “where there is no mutual assistance treaty or arrangement on the basis of uniform or reciprocal legislation in force between the requesting and requested Parties”, and Art. 27(2)(a)-(d), that each Party designates a central authority “responsible for sending and answering requests for mutual assistance, the execution of such requests or their transmission to the authorities competent for their execution”, that central authorities communicate directly with each other, and that the Secretary General keeps a register of them. Supports Art. 29(1)-(4): a Party may request another to preserve data “located within the territory of that other Party and in respect of which the requesting Party intends to submit a request for mutual assistance”; the request must state that intention (29(2)(f)); “For the purposes of responding to a request, dual criminality shall not be required as a condition to providing such preservation” (29(3)); and a Party that requires dual criminality for disclosure may reserve the right to refuse preservation where it has reasons to believe the condition cannot be fulfilled at the time of disclosure (29(4)). Supports Art. 30(1)-(2), expedited disclosure of a sufficient amount of preserved traffic data to identify a service provider in another State and the path through which the communication was transmitted, withholdable only for a political offence or where execution is likely to prejudice sovereignty, security, ordre public or other essential interests. Supports Art. 31(1)-(3), mutual assistance to search, seize and disclose stored data “including data that has been preserved pursuant to Article 29”, responded to on an expedited basis where data is particularly vulnerable to loss. Supports Art. 32 IN FULL, and its narrowness is the point: “A Party may, without the authorisation of another Party: a) access publicly available (open source) stored computer data, regardless of where the data is located geographically; or b) access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data to the Party through that computer system.” There is no third limb and no unilateral remote-access provision. Supports Art. 33(1)-(2), mutual assistance in the real-time collection of traffic data, governed by the conditions and procedures of domestic law and available at least for offences for which such collection would be available in a similar domestic case; and Art. 34, mutual assistance regarding the interception of content data “to the extent permitted under their applicable treaties and domestic laws”. Supports Art. 35(1)-(2), that each Party designates a point of contact available twenty-four hours a day, seven days a week, to ensure immediate assistance -- facilitating or, if permitted by its domestic law and practice, directly carrying out technical advice, preservation under Arts. 29 and 30, and the collection of evidence, provision of legal information and locating of suspects -- and that where the point of contact is not part of the Party’s authority responsible for international mutual assistance, it must ensure co-ordination with that authority. LIMITATION ON CHAPTER III, restated because it is easy to lose: these are obligations on Parties to legislate and to co-operate. They are NOT evidence of what any Party has enacted. The Party list, signature dates and ratification counts were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403 to three separate URL forms.
Legal Information Institute, Cornell Law School (reproducing the United States Code) · Legislation · link verified 2026-09-05
WAVE 22 ADDITION. ACCESS NOTE, stated because it affects the tier of this record: the official hosts were attempted first and were unreachable in this session — uscode.house.gov timed out without response and govinfo.gov returned HTTP 502 — so the text was read from the Legal Information Institute, which reproduces the United States Code verbatim rather than summarising it. It is cited for statutory wording only, and every proposition below is a quotation or a close paraphrase of one. Supports § 2703(a): a governmental entity may require disclosure of the CONTENTS of a wire or electronic communication in electronic storage for one hundred and eighty days or less “only pursuant to a warrant”; contents held more than one hundred and eighty days may be required by the means available under subsection (b). Supports § 2703(b)(1): contents held by a remote computing service may be required WITHOUT required notice to the subscriber or customer on a warrant, or WITH prior notice where the entity uses an administrative, grand jury or trial subpoena or obtains a § 2703(d) court order, with delayed notice available under § 2705. Supports § 2703(c)(1), that a governmental entity may require disclosure of “a record or other information pertaining to a subscriber to or customer of such service (NOT INCLUDING THE CONTENTS OF COMMUNICATIONS)” only by warrant, § 2703(d) order, subscriber consent, a narrow written request confined to telemarketing-fraud investigations, or under paragraph (2). Supports § 2703(c)(2), which lists the six items a provider shall disclose on an administrative, grand jury or trial subpoena: name; address; local and long distance telephone connection records, or records of session times and durations; length of service including start date and types of service utilised; telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and means and source of payment. Supports § 2703(c)(3), that a governmental entity receiving records under subsection (c) “is not required to provide notice to a subscriber or customer”. Supports § 2703(d), that a court order shall issue “only if the governmental entity offers specific and articulable facts showing that there are reasonable grounds to believe” the material sought is “relevant and material to an ongoing criminal investigation”, and that a court may quash or modify on a provider’s prompt motion where the records are unusually voluminous or compliance would cause an undue burden. Cited for the proposition that one statute can allocate three different authorising instruments to three different categories of digital material. LIMITATIONS: this record supports the wording of § 2703 and nothing else. It establishes no United States constitutional doctrine, no case law, and nothing about the Wiretap Act, which was not read. STATUS: current codified text as reproduced at the verification date. WAVE 23 ADDITION. Section 2703(h) was read from the same source under the same access note. Supports § 2703(h)(1)(A), defining a “qualifying foreign government” as one “with which the United States has an executive agreement that has entered into force under section 2523” and whose laws provide electronic communication service providers and remote computing service providers “substantive and procedural opportunities similar to those provided under paragraphs (2) and (5)”. Supports § 2703(h)(2)(A), that a provider -- “including a foreign electronic communication service or remote computing service” -- being required to disclose the contents of a communication may file a motion to modify or quash the legal process where it reasonably believes (i) that the customer or subscriber “is not a United States person and does not reside in the United States” and (ii) that the required disclosure “would create a material risk that the provider would violate the laws of a qualifying foreign government”, such a motion to be filed not later than 14 days after service. Cited for the proposition that the same body of legislation which removes the data’s location as an answer also provides a route for a provider to raise a conflict of legal obligations. LIMITATION: which governments qualify turns on executive agreements under § 2523, and that coverage was NOT RESEARCHED. No list of qualifying foreign governments is stated anywhere on this platform.
18 U.S.C. § 3127 — Definitions for chapter (pen registers and trap and trace devices)
Legal Information Institute, Cornell Law School (reproducing the United States Code) · Legislation · link verified 2026-09-05
WAVE 22 ADDITION. The same access note applies as for us-18usc-2703-stored-communications: the official hosts were attempted and unreachable in this session, and the text was read from the Legal Information Institute’s verbatim reproduction of the United States Code. Supports § 3127(3), the statutory definition: the term “pen register” means “a device or process which records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, provided, however, that such information shall not include the contents of any communication”, and excludes devices or processes used by a provider or customer for billing or for cost accounting in the ordinary course of business. Cited for one proposition only: that United States law states the content / non-content boundary as a matter of statutory definition rather than leaving it to be inferred. LIMITATIONS: this record supports the DEFINITION. It establishes nothing about the standard for obtaining such an order, nothing about how any such device or process operates, and nothing about any other country. STATUS: current codified text as reproduced at the verification date.
Strafprozessordnung (StPO) § 100g — Erhebung von Verkehrsdaten (German original text)
Bundesministerium der Justiz / Bundesamt für Justiz (Gesetze im Internet) · Legislation · link verified 2026-09-05
WAVE 22 ADDITION. The authoritative German text, read directly. Supports § 100g(1): where specific facts ground the suspicion that someone has committed (1) an offence of significant weight also in the individual case, in particular one designated in § 100a(2), or (2) an offence committed by means of telecommunications, Verkehrsdaten may be collected so far as necessary to investigate the facts and provided the collection stands in an appropriate relationship to the significance of the matter; in case (2) the measure is permissible only where investigating the facts by other means would be futile. Supports the LOCATION-DATA distinction, which is stated inside this subsection: “Die Erhebung gespeicherter (retrograder) Standortdaten ist nach diesem Absatz nur unter den Voraussetzungen des Absatzes 2 zulässig. Im Übrigen ist die Erhebung von Standortdaten nur für künftig anfallende Verkehrsdaten oder in Echtzeit und nur im Fall des Satzes 1 Nummer 1 zulässig, soweit sie für die Erforschung des Sachverhalts oder die Ermittlung des Aufenthaltsortes des Beschuldigten erforderlich ist.” — stored (retrograde) location data only on the stricter subsection (2) conditions; otherwise location data only prospectively or in real time. Supports that § 100g(2) applies a narrower, especially-serious-offence condition. Cited for the proposition that traffic data is a distinct category from content with its own threshold, and that at least one system splits location data by whether it is historical or prospective. LIMITATIONS: the definitions of Verkehrsdaten are in the instruments this section cross-refers to and were not read; nothing here describes how any such data is generated, held or obtained in practice. STATUS: current consolidated text at the verification date.
Strafprozessordnung (StPO) § 100j — Bestandsdatenauskunft (German original text)
Bundesministerium der Justiz / Bundesamt für Justiz (Gesetze im Internet) · Legislation · link verified 2026-09-05
WAVE 22 ADDITION. The authoritative German text, read directly. Supports § 100j(1) sentence 1: so far as necessary to investigate the facts or to determine the whereabouts of an accused, information may be requested about Bestandsdaten from those who commercially provide or participate in providing telecommunications services, and about the corresponding category from those who commercially hold ready or mediate access to digital services. Supports the GRADUATION inside the same subsection: where the request concerns data by which access to terminal devices, or to storage facilities used in or physically separate from them, is PROTECTED, the information may be requested only where the statutory conditions for using those data are met, and — for the digital-services limb — only for the prosecution of an especially serious offence within the meaning of the listed § 100b(2) categories. Cited for the proposition that subscriber-type information sits at the least-protected end of the ladder for ordinary purposes while access-credential data is pulled up to the level of the most intrusive power in the same code. LIMITATIONS: the definitions of Bestandsdaten sit in the telecommunications and digital-services statutes this section cross-refers to and were not read; this record establishes no claim about what any provider holds, and describes nothing about how access protections work. STATUS: current consolidated text at the verification date.
Strafprozessordnung (StPO) § 100a — Telekommunikationsüberwachung (German original text)
Bundesministerium der Justiz / Bundesamt für Justiz (Gesetze im Internet) · Legislation · link verified 2026-09-05
WAVE 22 ADDITION. The authoritative German text, read directly. Supports § 100a(1) sentence 1: telecommunications may be monitored and recorded even without the knowledge of those concerned where (1) specific facts ground the suspicion that someone has committed, attempted where the attempt is punishable, or prepared through an offence a SCHWERE STRAFTAT designated in subsection (2); (2) the offence weighs seriously ALSO IN THE INDIVIDUAL CASE; and (3) investigating the facts or determining the accused’s whereabouts by other means would be substantially more difficult or futile. Supports § 100a(1) sentence 2, that the monitoring may also be effected by intervening with technical means in information-technology systems used by the person concerned where this is necessary to enable monitoring and recording in particular in unencrypted form. Supports § 100a(1) sentence 3, that content and circumstances of communication STORED on the person’s information-technology system may be monitored and recorded where they could also have been monitored and recorded during the ongoing transmission process in the public telecommunications network in encrypted form — i.e. the category boundary is drawn by reference to what the interception power would have reached in transit. Supports that § 100a(2) contains a closed catalogue of qualifying offences. LIMITATIONS: this record establishes the CONDITIONS of the power, not who orders it (§ 100e) and not what follows it (§ 101). It describes no interception method, no technical means, and nothing about how any communication is protected or examined. STATUS: current consolidated text at the verification date.