facebook 2010 law enforcement guidelines

Upload: bowssen

Post on 09-Apr-2018

219 views

Category:

Documents


0 download

TRANSCRIPT

  • 8/8/2019 Facebook 2010 Law Enforcement Guidelines

    1/5

    FACEBOOK CONFIDENTIAL AND PROPRIETARY

    Facebook, Inc. 2010. All Rights Reserved.

    FacebookLawEnforcementGuidelines

    Thisdocumentdescribesprocedureslawenforcementauthoritiesshouldfollowtorequestdata

    fromFacebook.

    This document isCONFIDENTIAL and intended for law enforcementuse only.Please donot

    redistributeitwithouttheexpresswrittenpermissionofFacebook.

    Facebook services continuously change and thecompanymaymodify these policieswithout

    notice.ThisversionwasreleasedinMay,[email protected]

    torequestthelatestversionoftheseguidelines.

  • 8/8/2019 Facebook 2010 Law Enforcement Guidelines

    2/5

    FACEBOOK CONFIDENTIAL AND PROPRIETARY

    Facebook, Inc. 2010. All Rights Reserved.

    Address

    Allrequestsforrecordsmustbesentoneofthreeways:

    Byfaxto(650)644-3229 [email protected]

    Bymailto: Facebook,Inc.

    Attn:SecurityDepartment/CustodianofRecords

    1601CaliforniaAvenue

    PaloAlto,CA94304

    TypeofRequest

    Allrequestsforrecordsshouldclearlyidentifythetypeofrequestinthesubjectline.Onlythe

    followingtypesofrequestswillbeaccepted:

    PreservationRequests.ForrequeststhatidentifyanaccountbyUserID,Usernameor

    emailaddress,wewillpreservethen-existingaccountrecordsfor90days,pending

    serviceofformallegalprocess.

    FormalLegalRequests.Forrequestspursuanttoformalcompulsorylegalprocessissued

    underU.S.law,wewillproviderecordsasrequiredbylaw.Responsetimesvary

    dependingoncasecomplexityandrecordsrequested.

    EmergencyRequests.EmergencyrequestsmustbemadeusingtheattachedEmergency

    RequestForm,andwillonlyreceivearesponseifwebelieveingoodfaiththatserious

    bodilyharmordeathofapersonmayoccurifwedonotrespondquickly.

    ImportantConsiderationsYoushouldreviewtheFacebookStatementofRightsandResponsibilitiestounderstandmore

    aboutrulesofconductonFacebook.Inparticularyoushouldbeawareofthefollowing,asthey

    mayimpactyourinvestigation:

    Wewillalwaysdisableaccountsthatsupplyfalseormisleadingprofileinformationor

    attempttotechnicallyorsociallycircumventsiteprivacymeasures.

    Wearerequiredtodisableaccountsengagedinillegalactivity,evenifthatactivityis

    broughttoourattentionthrougharequestforrecords.

    Ifdisablingorrestrictinguseraccesstotheusersprofilewilljeopardizeyourinvestigation,youshould clearly specify DONOT DISABLE UNTIL XX/XX/XXXX on your request. Please note

    however,ifthematterhasalreadybeenreportedindependentlytoouroperationsteam,they

    maytakeindependentaction.

    Bydefaultwewillreturndatanoolderthan90dayspriortothedatewereceivetherequest.

    Youmustspecifyadaterangeorspecificdateifyouneedinformationoutsidethatrange.

  • 8/8/2019 Facebook 2010 Law Enforcement Guidelines

    3/5

    FACEBOOK CONFIDENTIAL AND PROPRIETARY

    Facebook, Inc. 2010. All Rights Reserved.

    RequestRequirements

    Formalrequestsforrecordsmustaddresseachofthefollowing3areas:

    AuthorizedLawEnforcementAgentinformation:

    Thefollowingcontactinformationisrequiredforeveryrequest:

    RequestingAgencyName

    RequestingAgentNameandBadge/Identificationnumber

    RequestingAgentwork-authorizede-mailaddress

    RequestingAgentphonenumberincludinganyextension

    RequestingAgentMailingAddress

    Requestedresponseduedate(Pleaseallowatleast26weeksforprocessing)

    FacebookUserInformation:

    Weonlyrespondtorequeststhatidentifyanaccountbyemailaddress,userIDorusername.

    FacebookIDsareintrinsicinsiteURLs.IfyouhaveasubjectsprofilepageURL,youcanfindthe

    IDbylookingforthestring idintheURLandpassingalongthenumberimmediatelyfollowing.

    Forinstance,theuserIDforthefollowingprofileis29445421:

    http://www.facebook.com/profile.php?id=29445421

    Group IDs follow a similar pattern, but the string to look for is gid. The group ID of the

    followingURLis2204894392:

    http://www.facebook.com/group.php?gid=2204894392

    InsteadofaFacebookIDintheURL,youmayseeaFacebookusername.Forexample:

    http://www.facebook.com/john.smith.

    Inorderforustoacceptausernameasavalidaccountidentifier,youmustalsosupplythedate

    whenyouviewedtheURLinquestion.

    InvestigationDetails:

    We review each request for records individually and prioritize requests based upon case

    circumstancesandotherfactorsnotalwaysobviousfromtheformalprocess.Pleaseprovide

    anyadditionaldetailsaboutthecasethatyoucan,so thatwecanmakesurethatyourcaseis

    prioritizedappropriatelyandtherecordsyoureceivearemostrelevanttoyourcase.

  • 8/8/2019 Facebook 2010 Law Enforcement Guidelines

    4/5

    FACEBOOK CONFIDENTIAL AND PROPRIETARY

    Facebook, Inc. 2010. All Rights Reserved.

    TypesofData

    Dependingonthetypeofformallegalprocessprovided,wewillbeabletorespondwithoneor

    moreofthefollowingtypesofdata:

    Basic Subscriber Information (sometimes referred to as Neoselect)will be delivered in XML

    formatandmayinclude:

    UserIdentificationNumber

    E-mailaddress

    DateandTimeStampofaccountcreationdatedisplayedin CoordinatedUniversalTime

    MostRecentLogins(generallycapturesthelast2-3daysoflogspriortoprocessingthe

    request)inCoordinatedUniversalTime

    RegisteredMobileNumber

    Expanded Subscriber Content (sometimes referred to as Neoprint) will be delivered in PDF

    formatandmayinclude:

    ProfileContactInformation

    Mini-Feed

    StatusUpdateHistory

    Shares

    Notes

    WallPostings

    FriendListing,withFriendsFacebookIDs

    GroupsListing,withFacebookGroupIDs

    FutureandPastEvents

    VideoListing,withfilename

    User Photos (sometimes referredto asUserPhotoprint) isdelivered inPDF format andmay

    include photos uploaded by the user and photos uploaded by other users that have therequestedusertaggedinthem.

    GroupInformationwillincludetheBSIofthegroupcreator/administratorinXMLformatandthe

    currentstatusofthegroupinaPDFformat.

    PrivateMessagesifretainedwillbeinPDFformat.

    IP Logsareverylimitedandfrequentlyincomplete,butwhenavailableareprovidedinatab

    delimitedtextfileandinclude:

    [ColumnOne]ViewtimeDateofexecution,inPACIFICTIMEZONE(UTC-8/-7).

    [ColumnTwo]UseridTheFacebookuserIDoftheaccountactivefortherequest

    [ColumnThree]IPSourceIPaddress

    [Column Four] Script Script executed. For instance, a profile view of the url

    http://www.facebook.com/profile.php?id=29445421 would populate script with

    profile.phpandScriptgetAdditionalinformationpassedtothescript. intheabove

    example,scriptgetwouldcontainid=29445421

    [ColumnFive]SessionCookie HTTPcookiesetbyusersession.

  • 8/8/2019 Facebook 2010 Law Enforcement Guidelines

    5/5

    FACEBOOK CONFIDENTIAL AND PROPRIETARY

    Facebook, Inc. 2010. All Rights Reserved.

    EMERGENCY DISCLOSURE REQUEST FORM

    RequestingAgencyName

    RequestingAgentName

    RequestingAgentBadge#RequestingAgentwork-authorizede-mail

    RequestingAgentphonenumberincludinganyextension

    Detailed descriptionof thenatureof theemergency (i.e. potential bodily harm, crime being

    committed):

    IdentifyingInformationforuseraccount(FacebookUserID,Username,Email&DOB):

    Detailedexplanationofinformationneededtoresolveemergency:

    I,_________________________,attestthattheabove-mentionedfactsaretrueandaccurateto

    thebestofmyknowledge.

    _____________________________ ______________________________

    SignatureandBadge# Date