COMPLIANCE GUIDE FOR LAW ENFORCEMENT Yah! Inc. Cmpliance Team Phne: 408-349-3687 Fax: 408-349-7941
TABLE OF CONTENTS Page I. YAHOO! LEGAL CONTACT INFORMATION...6 II. GENERAL INFORMATION...6 III. YAHOO! PROPERTIES AND SERVICES...6 General Infrmatin abut Yah! and Yah! IDs... 7 Yah! Mail... 7 Yah! Chat/Messenger... 8 Flickr... 8 Yah! Grups... 9 Yah! GeCities, Dmains, Web-Hsting, and Stres... 10 Yah! Answers... 10 Yah! Prfiles... 10 Yah! Partnerships... 10 IV. PRESERVATIONS...11 V. SERVICE OF PROCESS...11 VI. NCMEC REPORTING PROCEDURES...12 VII. COST REIMBURSEMENT POLICY...12 VIII. EMERGENCY DISCLOSURES...12 IX. CONSENT...13 APPENDIX A... 14 Sample Preservatin Request Letter... 14 APPENDIX B... 15 Sample Language fr Subpenas, Curt Orders, and Search Warrants... 15 Sample Subpena Wrding fr Identificatin f a Yah! User... 15 Sample Subpena Wrding fr Infrmatin Abut a Yah! Grup and its Mderatrs... 15 Sample Search Warrant Wrding fr Infrmatin Related t a Yah ID... 15 Sample Search Warrant Wrding fr Infrmatin abut a Grup and its cntents... 15-2-
APPENDIX C... 16 Yah! Emergency Disclsure Request... 16 APPENDIX D... 17 Sample Cnsent t Search Frm... 17-3-
COMPLIANCE GUIDE AT A GLANCE Hw d I cntact Yah! Legal? Questins: Cmpliance Team Yah! Inc. 701 First Avenue Sunnyvale, Califrnia 94089 408-349-3687 (tel.) Subpenas/Other Service f Prcess: Fax requests fr dcuments t Custdian f Recrds at 408-349-7941. Subpenas fr in-persn testimny must be persnally served. After-hurs emergencies: Yah! Security at 408-349-5400 General Tips: Include a Yah! ID r Yah! email address in yur request. Befre making a request, check t see if the infrmatin sught is publicly available. See http://help.yah.cm t find publicly available infrmatin. Make requests as specific and narrwly tailred as pssible. What Infrmatin Can Yah! Prvide? Subscriber Infrmatin Subscriber infrmatin supplied by the user at the time f registratin, including name, lcatin, date accunt created, and services used. IP addresses assciated with lg-ins t a user accunt are available fr up t ne year. Registratin IP address data available fr IDs registered since 1999. Yah! Mail (including email assciated with specific prperties such as Persnals, Small Business, Dmains, and Flickr) Any email available in the user s mail accunt, including IP address f cmputer used t send email. Yah! is nt able t search fr r prduce deleted emails. Nte that Yah! nw hsts tw new email dmains: ymail.cm and rcketmail.cm. Yah! Chat/Messenger Friends List fr Yah! Messenger. Time, date, and IP address lgs fr Chat and Messenger use within the prir 45-60 days. Archives f Messenger cmmunicatins may be available n the user s cmputer if the user has chsen t archive cmmunicatins. Archives f Web Messenger cmmunicatins may be stred n Yah! servers if at least ne party t the cmmunicatin chse t archive cmmunicatins. Yah! Grups Member list, email addresses f members, and date when members jined the Grup. Infrmatin abut Grup mderatrs. Cntents f the Files, Phts, and Messages sectins. Grup activity lg describing when members subscribe and unsubscribe, pst r delete files, and similar events. Nte: Message Archive des nt cntain attachments t messages. Yah! GeCities, Dmains, Web-hsting, and Stres Active files user has upladed t the website and date f file uplad. Fr stres, may have stre transactinal data. -4-
Yah! Flickr Cntents in Flickr accunt and cmments n ther users phts. IP address and timestamp f cntent upladed t accunt. Flickr Grups t which a user belngs and Grup cntent. Yah! Prfiles Cntents f a user s prfile. Time, date, and IP address lgs f cntent added. Des Yah! partner with ther cmpanies? Yah! has a c-branded service with AT&T. Fr custmers with email addresses that have an SBC r AT&T suffix, AT&T has the primary custmer relatinship. In such cases, it is mst apprpriate t direct legal prcess first t AT&T. Yah! als has partnerships with Verizn, Rgers (Canada), and BT (UK). Will Yah! preserve infrmatin? Yah! will preserve subscriber/custmer infrmatin fr 90 days. Yah! will preserve infrmatin fr an additinal 90-day perid upn receipt f a request t extend the preservatin. If Yah! des nt receive frmal legal prcess fr the preserved infrmatin befre the end f the preservatin perid, the preserved infrmatin may be deleted when the preservatin perid expires. DATA AVAILABILITY AT A GLANCE Recrd Type Accessible fr? Purged After? Subscriber Infrmatin As lng as accunt is active 18 mnths f inactivity r 90 days if subscriber self-deletes accunt Accunt Lg-in IP addresses Up t ne year N/A Email (free r premium) As lng as user chses t keep it 4 r mre mnths f inactivity depending n hw lng user s accunt was pen Flickr Accunt Cntents, including Flickr Email As lng a accunt is active (Email stred as lng as user chses t keep it) Upn deactivatin f accunt Grups Activity Lgs Life f the Grup Minimum f 30 days after terminatin f Grup Grups Cntent Life f the Grup (nly current versin f Grup stred; nt past versins) Chat/Instant Messenger Lgs 45-60 days N/A Web Messenger Cntents (Yah! des nt stre cntents f cmmunicatins sent via the dwnladable Messenger client) GeCities, Dmains, Web-hsting Activity Lgs and Cntent As lng as user chses t keep it As lng as website r dmain is active Minimum f 30 days after terminatin f Grup N/A Minimum f 30 days after terminatin f website r dmain Prfiles As lng as the Prfile is active Minimum f 90 days after deactivatin -5-
I. YAHOO! LEGAL CONTACT INFORMATION Cmpliance Team Yah! Inc. 701 First Avenue Sunnyvale, Califrnia 94089 Phne: 408-349-3687 Fax: 408-349-7941 Please address all subpenas and ther legal prcess t the Custdian f Recrds at the abve address. If yu need t speak t smene at Yah!, the phne number listed abve will allw yu t leave a message in the vicemail fr the Cmpliance Team. Yah! will use its best effrts t return all calls during the same business day, r within 24 hurs, depending n call vlume. II. GENERAL INFORMATION This cmpliance guide is designed t assist law enfrcement in understanding Yah! s plicies and practices with regard t retentin and disclsure f electrnic infrmatin and t prvide answers t frequently asked questins related t subpenas and ther legal prcess. The plicies and prcedures in this guide are subject t change withut ntice, and this dcument is nt meant t be distributed t individuals r rganizatins that are nt law enfrcement entities, including Yah! custmers, cnsumers, r civil litigants. Nthing in this guide is intended t create any enfrceable rights against Yah!. Yah! will make reasnable effrts t advise law enfrcement f significant changes in plicies r prcedures thrugh updates t this guide. Law enfrcement shuld be aware that Yah! prvides its users with a variety f different prducts and services, many f which are free and sme f which require separate lg-ins r subscriptins and generate separate electrnic recrds. In Yah! s experience, the majrity f law enfrcement requests seek general infrmatin abut a Yah! user r infrmatin specific t a particular Yah! service. Accrdingly, in crafting a subpena, curt rder, r search warrant fr such infrmatin, law enfrcement shuld be as specific as pssible. Narrwly tailred requests yield significantly faster results, create fewer pprtunities fr misinterpretatin, and generate lwer reimbursable csts under the Electrnic Cmmunicatins Privacy Act, 18 U.S.C. 2701, et seq. ( ECPA ) and ther federal statutes. Law enfrcement als shuld be aware that a great deal f the infrmatin that is subpenaed frm Yah! each year is publicly available infrmatin that can be viewed withut any assistance frm Yah!. Fr example, many Yah! Grups can be fund thrugh a search at grups.yah.cm. Similarly, websites hsted n Yah! s servers can be accessed by members f the public. Yah! recmmends that yu visit Yah! s help pages befre yu seek t btain infrmatin frm Yah!. Help pages als prvide valuable infrmatin n hw services wrk, their features and ptins, and what infrmatin may be available publicly r thrugh legal prcess. A menu t all f Yah! s help pages can be fund at http://help.yah.cm. III. YAHOO! PROPERTIES AND SERVICES Yah! Inc. is a glbal Internet business and cnsumer services cmpany that ffers a cmprehensive branded netwrk f prperties and services, many f which are free, t mre than 500 millin unique users wrldwide. Currently, Yah! has abut 230 millin registered users. Due t the differences amng the many prperties and services ffered by Yah!, the amunt f infrmatin, if any, maintained by Yah! abut its custmers and subscribers varies. Mrever, as a public prvider f electrnic cmmunicatins services and remte cmputing services, the disclsure f infrmatin maintained by Yah! is gverned in large part by the ECPA, amng ther federal and state statutes. A detailed applicatin f these laws t -6-
all f the types f infrmatin held r maintained by Yah! is beynd the scpe f this guide. This guide prvides basic guidance as t the infrmatin mst frequently requested by law enfrcement frm Yah! regarding its key cnsumer prperties, including Yah! s nrmal retentin perids, and the legal prcess that will allw fr prductin f the requested infrmatin. General Infrmatin abut Yah! and Yah! IDs Signing up fr a Yah! ID is free. T btain a Yah! ID, Yah! requests certain infrmatin during the registratin prcess. This infrmatin is nt verified by Yah! but is used t help cnfirm the user s identity fr passwrd changes and ther custmer service requests. 1 Fr each Yah! ID, Yah! may have the fllwing infrmatin: name, hme address, business address, phne, time zne, birthday, gender, ccupatin, alternate email address, registratin IP address, date accunt was created, and current accunt status. Nt all f the fields f infrmatin requested at registratin are required. Please always prvide a Yah! ID when requesting subscriber infrmatin. Requests based n prper names r IP addresses, fr example, render inaccurate results and ften n results. Fr a specified Yah! ID, Yah! can determine which services the subscriber uses, whether the subscriber has cnfigured the My Yah service, whether the subscriber has a public prfile, 2 and whether the subscriber has paid fr any Yah! premium services. If the user has subscribed t a premium service, Yah! will have a credit card number n file fr that subscriber. Yah! will be unable t search fr and prduce deleted material, including email and Grup psts, unless such request is received within 24 hurs f the deletin and is specifically requested by prper legal prcess. In mst cases where deleted cntent is requested, Yah! will seek reimbursement fr any engineer time incurred in cnnectin with the request. Yah! IDs remain active s lng as the subscriber has lgged int the accunt in the prir eighteen (18) mnths. After 18 mnths f inactivity, the ID may be deactivated and the accunt data deleted. If a subscriber self-deletes an accunt, then after 90 days the ID may be deactivated and the accunt data deleted. T the extent available, basic subscriber infrmatin prvided in respnse t criminal r administrative subpenas will include infrmatin the user prvided t Yah! during the registratin prcess, except fr infrmatin nt specifically enumerated in 18 U.S.C. 2703(c)(2), such as date f birth, gender, and ccupatin. Other subscriber recrds, including full registratin data and transactinal recrds (e.g., email headers, Grups activity lgs, messenger lgs, chat lgs), may be btained thrugh a curt rder issued under 18 U.S.C. 2703(d). Yah! maintains lgs f IP addresses assciated with accunt lg-in in an accessible frmat fr up t ne year. In additin, since 1999, Yah! has cllected the IP address used t register a Yah! ID. Such infrmatin is retained as part f ur basic subscriber infrmatin and is available t the extent the user s accunt is stred in ur system, as described abve. Yah! Mail Yah! has bth free and premium mail services. Yah! s free services are web-based nly, while premium members can get POP and SMTP access t Yah! s mail servers using any email client. Yah! nw ffers unlimited strage fr its free mail services. Users wh purchase Yah! s premium mail services get email with n graphical ads, the ability t have ffline access (with POP) and mail frwarding, and Spamguard Plus. Current infrmatin abut premium mail services is available at http://mailplus.mail.yah.cm. Yah! nw hsts tw new email dmains: rcketmail.cm and ymail.cm. The Yah! ID fr a ymail r rcketmail user is the full email accunt name (e.g., accunthlder@ymail.cm, whereas the Yah! ID fr a @yah email address is merely the name befre the @ sign (e.g., accunthlder where the email address is accunthlder@yah.cm ). This means that Yah! may have three subscribers with these three similar IDs: 1 2 Yah! des nt maintain passwrds in an accessible frmat. A user s Yah! prfile may available t the public depending n a user s prfile privacy setting. Please visit prfiles.yah.cm. -7-
jhnde@yah.cm, jhnde@ymail.cm, and jhnde@rcketmail.cm, where the three Yah! IDs are, respectively, jhnde, jhnde@ymail.cm, and jhnde@rcketmail.cm. Every message sent by a Yah! mail user cntains the riginating IP address in the header. That is, Yah! recrds the IP address f the cmputer that was used t send the email, and Yah! inserts that IP address in the header f the message. Accrdingly, if law enfrcement is seeking t determine the IP address frm which a Yah! email was sent, Yah! will have n additinal infrmatin ther than what is visible in the message itself. The relevant line frm the header will generally lk like this: Received: frm [65.207.97.120] by web41705.mail.yah.cm via HTTP; Fri, 05 Sep 2003 07:30:05 PDT In this example, the IP address in brackets crrespnds t the cmputer frm which the message was sent. Fr mre infrmatin n email headers and IP addresses, please see: http://help.yah.cm/help/us/mail/spam/spam-05.html. Yah! retains a user s incming mail as lng as the user chses t stre such messages in their mail flders and the user s email accunt remains active. Yah! retains a user s sent mail nly if the user sets their email accunt ptins t save sent mail and has nt subsequently deleted specific messages. Once the trash flder has been emptied, which usually ccurs autmatically within 24 hurs f when the user has placed messages in the trash flder, Yah! will be unable t search fr and prduce deleted emails. Yah! may set an email accunt t inactive status and delete all accunt cntents after at least fur (4) mnths f inactivity. Yah! Chat/Messenger Yah! Chat and Messenger are tw distinct Yah! prducts, althugh users may nly access Chat rms via Yah! Messenger. Yah! als ffers users tw frms f Messenger a dwnladable client r a versin that is accessible n the web. Web-based Messenger may be accessed at messenger.yah.cm r it may be accessed by users f Yah! s new mail interface. Fr Yah! Chat and all frms f Messenger, Yah! has lg infrmatin regarding the use f the services. Yah! maintains a Friends List fr users f Yah! Messenger and can determine frm its lgs the time and date that a user lgged int Messenger r Chat (in the prir 45-60 days) and the IP address used. Yah! als can retrieve frm its Chat and Messenger lgs the names f the chat rms that the user accessed and the Yah! IDs f the ther peple with whm a user cmmunicated thrugh Messenger during the prir 45-60 days. In rder t search these lgs, a Yah! ID and a specific time frame, preferably n mre than three days, must be prvided. Yah! des nt stred cntent fr the dwnladable Messenger client. Yah! Messenger client users can archive Messenger cmmunicatins, hwever, by string the archives lcally n their PC r n whatever media they designate. If a user has archived Messenger cmmunicatins, the archives can be viewed lcally thrugh the Messenger client resident n the user s cmputer. Fr web-based Messenger, Yah! may be able t access the cntent f cmmunicatins if at least ne party t the cmmunicatin elected t archive the cnversatin n Yah! s servers. Again, this is fr web-based Messenger nly. Yah! des nt archive the cntent f cmmunicatins fr the dwnladable Messenger client. Yah! des nt stre the cntent fr Yah! Chat. Yah! Chat made several prduct changes in 2005. In July 2005, Yah! suspended users ability t create their wn chat rms. In Octber 2005, Yah! restricted access t the Chat prduct t nly thse users wh are registered as being 18 years f age r lder. The teen categry and any assciated chat rms were remved. Finally, when users lg in t Chat, Yah! nw displays users IP addresses t them and gives them ntice that their IP addresses are being recrded. Flickr Flickr is Yah! s free nline pht management and sharing applicatin. Free users are able t uplad 100MB wrth f phts each calendar mnth. Users may upgrade t FlickrPr a premium service that allws users t -8-
pay fr unlimited pht uplads (up t 20MB per pht). Pr users als are able t uplad vides (90 secnds maximum length per vide). All Flickr accunts are identified uniquely in the URL fr the accunt. The URL either will reflect a user s NSID (a unique alphanumeric cde assigned t a user) r a user-created persnalized URL (e.g., http://flickr.cm/phts/username). In additin, each Flickr user has a unique email accunt that is separate frm their Yah! Mail. Flickr als ffers users the ability t create and jin Flickr Grups and t cmment n their wn and thers phts. Flickr users may keep their phts private, share them with friends and/r family, r make their phts public. Users als may classify phts as safe (suitable fr a glbal, public audience); mderate (sme pht cntent may be cnsidered as ffensive by sme peple); r restricted (pht cntent is unsuitable fr minrs and may be cnsidered ffensive by sme peple). If prvided with a Yah! ID, Flickr URL, r Flickr NSID, Yah! has the ability t prduce subscriber infrmatin fr the accunt-hlder. As lng as the Flickr accunt is active, Yah! has the ability t prduce cntent in the accunt with assciated uplad IP addresses and date and time as well as the email and Grups infrmatin fr the accunt. Yah! n lnger ffers the Yah! Phts service. Yah! Grups Yah! Grups is a free service that allws Yah! users t cmmunicate with ther peple with similar interests. Each Yah! Grup has at least ne wner r mderatr wh sets the tpic and rules fr the Grup, including whether membership is pen t the public, restricted s that mderatrs must apprve all requests fr membership, r clsed s that nly invited members can jin. The Grup wner r mderatr als determines whether r nt the Grup is listed in the Grups directry. A Grup wner may name additinal mderatrs. Each member f a Grup can select a delivery ptin whether they want t receive every email message sent t the Grup, a digest f messages, r n email. Users are nt required t have a Yah! ID t participate in Grups and may chse t subscribe using email addresses. Hwever, Grup members with Yah! IDs als may (r in the alternative) read messages thrugh the Grup website instead f electing t receive email. Each Yah! Grup has several sectins fr user-generated cntent available n the Grup website. These sectins include Messages, Files, Phts, Links, Plls, Calendar, and Database. In additin t the materials frm these sectins, a member list, including a list f all current members f the Grup, their partial email addresses (the name befre the @ symbl), and when they jined the Grup, als is available t members f the Grup fr restricted Grups, r may be available t the general public fr public Grups. Fr Grups that are publicly accessible t ther Yah! users, all f the Grups cntent, including the Yah! ID and email address f the mderatr(s) may be available thrugh the Grup s website. Yah! maintains n additinal files, phts, r messages that cannt be btained thrugh the Grup s website. In additin, the Yah! ID r email address f members wh psted files r phts is als apparent frm a public Grup s website. Fr Grups that are nt publicly accessible, Yah! can prduce the Grup s cntents as they wuld be seen by ne f the Grup s private members. Yah! maintains infrmatin abut Grup mderatrs, as well as an activity lg fr each Grup. The Grup activity lg is a transactinal lg that indicates when members have subscribed r unsubscribed frm the Grup, psted r deleted files r plls, r ther similar events. Nt all Grup activities are lgged, hwever. Fr example, the reading f messages r dwnlading f files r phts is nt lgged. Althugh the Grup Message archive maintains messages sent t Grup members, the message archive des nt cntain any attachments t the messages. Yah! des nt maintain thse attachments in any frm. Fr current Grups, Yah! retains infrmatin relating t the mderatr, members, and the active cntents f the Files, Phts, and Messages sectins. If a Grup has been deactivated r deleted, infrmatin abut the Grup may be preserved fr apprximately 30 days, after which the infrmatin may be deleted. -9-
Yah! GeCities, Dmains, Web-Hsting, and Stres Yah! perates GeCities, a web-hsting service that prvides bth free and premium hsting ptins. All Yah! IDs cme with a www.gecities.cm/yur-yah!-id web address that users may chse whether r nt t use. Premium GeCities members can register (r transfer) their wn dmain name and hst their website with GeCities. Fr GeCities websites, Yah! will have basic Yah! registratin infrmatin abut the user wh psted the page. Yah! als will have the active files that the user has upladed t the website, including the date n which the file was upladed. Yah! als perates premium small business web-hsting services and free and premium dmain services. Users may register unique dmain names and hst their websites n Yah!. Web-hsting and Dmains service packages als prvide users with dmain-based email accunts. The strage capacity fr the websites and the number f email addresses per dmain are determined by the package fr which a user registers. Fr web-hsting and dmains, Yah! will have basic Yah! registratin infrmatin abut the user wh psted the page. Yah! als will have the active files that the user has upladed t the website, including the date n which the files were upladed, and the dmain-based email that is available t the user. Deleted email is nt available. Yah! ffers a merchant hsting slutin as well. If a user pays fr and uses this add-n package t Yah! s web-hsting service in rder t perate an nline stre, Yah! will have transactinal infrmatin fr the nline merchant s custmers, including items purchased and custmer billing and shipping infrmatin. Yah! Answers Answers is a site that allws users t pst questins and slicit answers. The user wh asks the questin can vte which answer is the best ne t the questin asked. Each questin and answer has a unique URL with a QID cde. Answers is a text-nly site. The nly images that appear are thse assciated with a user s nickname. Fr Answers, Yah! has available the subscriber infrmatin assciated with a psted questin r answer, including the IP address and date and time f psting. Law enfrcement seeking infrmatin abut a specific psting shuld, where pssible, prvide Yah! with the unique URL f that psting when requesting infrmatin. Yah! Prfiles Yah! Prfiles is a central cntrl panel fr nline activity, making it easy fr peple t manage their identity, activities, interest, and cnnectins and giving users the pprtunity t share this infrmatin n the web. Each Yah! Prfile includes a basic user card that includes a user s pht (r avatar), nickname, name, age, sex, and lcatin. The Prfile als gives users the ability t pst basic infrmatin abut their schl, wrk, interests, relatinship status, etc. Users will be able t see the ther users they are cnnected t as friends, and there is a sectin n the prfile where a user can see updates frm his r her cnnectins. Each prfile als includes a guestbk where visitrs t a prfile page can add cmments. Users have the ability t make their prfiles searchable by nickname, by first and last name, and by email address. Alternatively, users can hide their prfiles frm appearing in public search results. Users als have the ability t make their entire prfile hidden frm the wrld, r t nly share their prfile with their friends r cnnectins, r t make their prfile publicly available. The URL f a prfile cntains unique identifying infrmatin fr a user s prfile, s law enfrcement shuld prvide that URL t Yah! when requesting infrmatin abut a user s prfile. Yah! stres the cntent f the current versin f a user s prfiles. Yah! als lgs the IP addresses and dates and times f new cntent added t a prfile (e.g., guestbk cmment, newly upladed phts). Yah! Partnerships Yah! has a c-branded service with AT&T (frmerly SBC). Fr AT&T Yah! DSL and Dial-up custmers, AT&T prvides users with Internet access, and Yah! prvides cntent and cmmunicatins services available thrugh the Yah! netwrk. Many users wh have an AT&T/SBC r AT&T/SBC-affiliated cmpany email address may be -10-
AT&T Yah! custmers (fr example, users with email addresses ending with @sbcglbal.net may be AT&T Yah! custmers). AT&T has a billing relatinship with all AT&T Yah! custmers. Legal prcess shuld be directed t AT&T first. In circumstances where Yah! may have additinal infrmatin regarding a user s accunt, AT&T may direct law enfrcement t Yah! fr mre infrmatin. In these instances, Yah! may have infrmatin regarding the use f Yah! services, as well as email accunt cntents. Yah! has partner relatinships with ther cmpanies, including Verizn Online, British Telecm, and Rgers. Depending n the specific arrangements f each partnership, Yah! s partner may have the primary custmer relatinship, and it may be mre apprpriate t direct legal prcess first t the partner rather than Yah!. Depending n the particular partnership, Yah! may r may nt have infrmatin abut the user. IV. PRESERVATIONS Pursuant t 18 U.S.C. 2703(f), Yah! will preserve infrmatin related t a subscriber r custmer fr 90 days, which may be extended fr an additinal 90 days by a request t extend the preservatin. Fr best handling, we request that preservatin requests be sent by fax t 408-349-7941. Please be as specific as pssible in describing the infrmatin yu wuld like Yah! t preserve and nly request preservatin fr thse materials that yu intend t btain legal prcess t receive. Please reference the initial preservatin request (by date and case name r number) when sending legal prcess t btain the preserved infrmatin. Als, please indicate whether the preserved infrmatin will satisfy the request r whether the request seeks the preserved infrmatin as well as ther infrmatin that may have been added t the accunt between the preservatin date and the date f the request that may be available. 3 If Yah! des nt receive a request fr extensin r frmal legal prcess by the end f the 90 day preservatin perid, the preserved infrmatin may be deleted. V. SERVICE OF PROCESS Yah! generally will accept service f curt rders, search warrants, and criminal grand jury r administrative subpenas fr the prductin f dcuments by fax frm gvernment entities. Yah! will nt accept service by fax f any subpena purprting t call fr the in-persn testimny f Yah! witnesses. Yah! will prvide a certificatin f authenticity alng with the prductin f recrds. In general, law enfrcement can expect Yah! s respnses t legal prcess t cnfrm with the Electrnic Cmmunicatins Privacy Act as described belw. Yah! is bth an Electrnic Cmmunicatins Service Prvider (ECS) and a Remte Cmputing Service Prvider (RCS). Yah! is an ECS fr cmmunicatins including but nt limited t email and Messenger, and Yah! is an RCS fr purpses including but nt limited t strage f phts and files. Subpena 2703(d) Order Search Warrant Basic subscriber infrmatin Cntents f cmmunicatins n RCS* Cntents in electrnic strage fr ver 180 days* Transactinal recrds (e.g., Messenger r Chat lgs, IP address infrmatin assciated with any activity ther than lgin) Anything btainable with a subpena* Cntents in electrnic strage fr 180 days r less Anything btainable with subpena r 2703(d) rder * Yah! will ask law enfrcement t certify that the prir r delayed ntice prvisins have been satisfied if cntents are sught with legal prcess ther than a Search Warrant. 3 Please nte that requests t cllect infrmatin regarding a user s accunt n a frward-ging basis require the apprpriate surveillance rders (such as a Title III Order). -11-
VI. NCMEC REPORTING PROCEDURES Yah! has wrked with law enfrcement and the Natinal Center fr Missing and Explited Children (NCMEC) t develp practices fr reprting instances f apparent child prngraphy (CP) as required by 18 U.S.C. 2258A. Yah! may learn abut pssible CP n its netwrk frm a variety f surces, including abuse reprts frm users, tips frm NCMEC and law enfrcement, and internal practive effrts using a cmbinatin f technlgical and human resurces. Upn becming aware f CP, Yah! Custmer Care disables public access t material and escalates the material t Yah! s legal department, which will review the material and determine whether it is required t be reprted t NCMEC. Users reprted t NCMEC fr child prngraphy-related incidents are terminated frm Yah! s service at the time f reprting. In keeping with recent changes in Federal law, the infrmatin Yah! reprts t NCMEC includes, when available: A user s Yah! ID and/r unique NSID fr Flickr and/r website dmain fr hsted sites; The user s registratin IP address and registratin date and time and/r the IP address and date and time f uplad f a pht image r ther cntent; The images themselves; and Infrmatin abut whether the subject accunt is already under investigatin by law enfrcement. VII. COST REIMBURSEMENT POLICY Federal law (See 18 U.S.C. 2706) requires law enfrcement t reimburse prviders like Yah! fr csts incurred respnding t subpena requests, curt rders, r search warrants. Yah! generally requests reimbursement when respnding t legal prcess, except that Yah! maintains an exceptin t this plicy fr cases invlving the abductin r explitatin f children. Yah! may waive reimbursement in specific cases r recgnize additinal exceptins t this plicy in the future. Yah! will seek reimbursement based n the actual time expended by Yah! s cmpliance staff in cmplying with the request. The average csts related t cmpliance matters are listed belw fr yur cnvenience. These estimates are neither a ceiling nr a flr but represent the average csts f typical searches. Time spent may vary cnsiderably based n the wrding f the request and the infrmatin available abut the user. These time estimates are als based n narrwly tailred requests that d nt require extensive searches in multiple databases. These estimates are nt price qutes, budgets, r guarantees and shuld nt be used fr budgeting purpses. Yah! reserves the right t adjust its estimates and reimbursement charges as necessary. Basic subscriber recrds: apprx. $20 fr the first ID, $10 per ID thereafter Basic Grup Infrmatin (including infrmatin abut mderatrs): apprx. $20 fr a grup with a single mderatr Cntents f subscriber accunts, including email: apprx. $30-$40 per user Cntents f Grups: apprx. $40 - $80 per grup VIII. EMERGENCY DISCLOSURES Under 18 U.S.C. 2702(b)(7) and 2702(c)(4) Yah! is permitted, but nt required, t vluntarily disclse infrmatin, including cntents f cmmunicatins and custmer recrds, t a federal, state, r lcal gvernmental entity if Yah! believes in gd faith that an emergency invlving imminent danger f death r serius physical injury t any persn requires such disclsure withut delay. In rder t assist Yah! in exercising its discretin, Yah! requests that, where pssible, Yah! s Emergency Disclsure Request Frm be cmpleted, r the -12-
infrmatin requested by this frm be cnveyed t Yah! by sme ther means. (See Appendix C) Withut such infrmatin, it will be difficult, if nt impssible, fr Yah! t determine the nature f the emergency and the need fr an immediate respnse. The Emergency Disclsure Request must be submitted by a law enfrcement fficer. If yu need t get in tuch with Yah! after hurs fr an emergency request, the mst reliable way is t cntact Yah! Security at 408-349-5400, wh will in turn page a member f Yah! s cmpliance team. Alternatively, yu may cntact the San Jse FBI Office, wh will cntact Yah! persnnel. Please nte that cntacting Yah! cmpliance via the San Jse FBI Office may nt necessarily be as efficient fr an emergency respnse. IX. CONSENT In rder fr Yah! t turn ver any infrmatin t law enfrcement based n a user s cnsent t search, the user s signed cnsent must be accmpanied by a subpena, and Yah! must be able t successfully verify the accunt f the user whse infrmatin is being sught. Alng with the user s signed cnsent and a detailed descriptin f the infrmatin the user is requesting frm Yah!, the user must prvide the infrmatin requested in the Sample Cnsent t Search Frm t Yah! in writing. (See Appendix D) If the user is unable t verify wnership f the accunt by prviding registratin infrmatin that matches what is in Yah! s recrds, Yah! will be unable t prduce recrds pursuant t the user cnsent. -13-
APPENDIX A Sample Preservatin Request Letter Cmpliance Team Yah! Inc. 701 First Avenue Sunnyvale, Califrnia 94089 Fax: 408-349-7941 Dear Custdian f Recrds: This letter serves as a frmal request fr the preservatin f recrds and ther evidence pursuant t 18 U.S.C. 2703(f) pending further legal prcess. Fr the Yah! subscriber ID [INSERT ID, email address, Grup name, Flickr NSID, Flickr URL, r Prfile URL], yu are hereby requested t preserve, fr a perid f 90 days, the recrds described belw currently in yur pssessin. This request applies nly retrspectively. It des nt in any way bligate Yah! t capture and preserve new infrmatin that arises after the date f this request. This preservatin request specifically applies t all recrds and ther evidence relating t the subscriber(s), custmer(s), accunt hlder(s), r ther entity(ies) assciated with the subscriber(s) identified abve, including, withut limitatin, [include as may be relevant]: Subscriber names, user names, screen names, r ther identities; Mailing addresses, residential addresses, business addresses, email addresses, telephne numbers, and ther cntact infrmatin; Billing recrds; Infrmatin abut length f service and the types f services the subscriber(s) r custmer(s) used; Any ther identifying infrmatin, whether such recrds are in electrnic r ther frm; Cnnectin lgs and recrds f user activity fr the subscriber(s) identified abve, including lg-in histry and recrds identifying sent and received cmmunicatins; All cmmunicatins stred in the accunt(s) f the subscriber(s) identified abve; and All files that are cntrlled by user accunts assciated with the subscriber(s) identified abve. At this time we are expecting t btain frmal legal prcess within 90 days. We acknwledge that if we d nt serve legal prcess upn yu in the next 90 days and d nt request a 90-day extensin, the preserved infrmatin may n lnger be available. -14-
APPENDIX B Sample Language fr Subpenas, Curt Orders, and Search Warrants Sample Subpena Wrding fr Identificatin f a Yah! User Any and all recrds regarding the identificatin f a user with the Yah! ID r Yah! email accunt, t include name and address; Yah! email address; alternate email address; IP address and date and time f registratin; accunt status; and lg-in IP addresses assciated with sessin times and dates. Nte: If Credit card numbers are sught, please identify any Yah! premium service used by the subscriber, if knwn, and insert: credit card numbers used by the Yah! user t pay fr Yah! premium services [r the name f the specific Yah! premium service used]. Sample Subpena Wrding fr Infrmatin Abut a Yah! Grup and its Mderatrs Fr the Yah! Grup knwn as, email addresses fr all mderatrs and members f the Grup, the date the Grup was created, the Grup/List ID, and Grup descriptin. Any and all recrds regarding the identificatin f the wners and/r mderatrs f the Yah! Grup listed abve, t include name and address; Yah! email address; alternate email address; IP address and date and time f registratin; accunt status; and lg-in IP addresses assciated with sessin times and dates. Sample Search Warrant Wrding fr Infrmatin Related t a Yah ID Any and all infrmatin fr Yah! ID r Yah! email accunt, t include name and address; Yah! email address; alternate email address; IP address and date and time f registratin; accunt status; and lg-in IP addresses assciated with sessin times and dates. (If infrmatin related t email cntent is sught, add) Fr the subscriber identified in Paragraph A abve, the cntents f any and all emails stred in the subscriber s Yah! accunt. [NOTE: Email cntent stred in dmain-based email accunts hsted n Yah! r Flickr email must be requested explicitly.] (If infrmatin is sught related t stred Yah! Briefcase files r Flickr phts, add) Any and all cntents f electrnic files that the subscriber has stred in the subscriber s Briefcase and/r Flickr accunt. (If Friends List infrmatin is sught, add) Any and all Yah! IDs listed n the subscriber s Friends list. (If infrmatin related t payments is sught, add) Any and all methds f payment prvided by the subscriber t Yah! fr any premium services. Sample Search Warrant Wrding fr Infrmatin abut a Grup and its cntents A. The identity f the mderatrs and members f the Yah! Grup knwn as, including the date the Grup was created, the Grup ID, the dates that members jined the grup, and the delivery ptins fr the current members. B. The current cntents f the Files, Phts, Links, and Plls sectin f the Yah! Grup knwn as and the archived message psts, and all recrds relating t the activities f the Grup members, as reflected in the Grup Activity Lg. -15-
APPENDIX C Yah! Emergency Disclsure Request Please respnd t the questins n this frm t assist Yah! in determining whether t exercise its discretin t disclse infrmatin t yu pursuant t 18 U.S.C. 2702(b)(8) and 2702(c)(4). Please fax this cmpleted frm t us at 408-349-7941. Fr an after-hurs emergency, please send it by email t page-legalpc@yah-inc.cm. During business hurs, please call 408-349-3687 with any questins abut this frm. If Yah! des nt receive sufficient infrmatin in writing r verbally, Yah! may nt be able t make an emergency disclsure under federal law. Please make sure yu specify the Yah! ID fr which the infrmatin is being requested. 1. What is the nature f the emergency invlving death r serius physical injury? 2. Whse death r serius physical injury is threatened? 3. What is the imminent nature f the threat? Please prvide infrmatin that suggests that there is a specific deadline befre which it is necessary t receive the requested infrmatin and/r that suggests that there is a specific deadline n which the act indicated in respnse t Questin 1 will ccur (e.g., tnight, tmrrw at nn)). 4. Please explain why the nrmal disclsure prcess (including any statutry emergency prcedures) wuld be insufficient r untimely in light f the deadline set frth in Questin 3. 5. What specific infrmatin in Yah! s pssessin related t the emergency are yu seeking t receive n an emergency basis? SPECIFY THE YAHOO! ID FOR WHICH THE INFORMATION IS BEING REQUESTED. (Nte: Please d nt respnd by asking fr everything Yah! has in its pssessin as such respnse will likely result in delaying r denying this request.) 6. Please explain/describe hw the infrmatin yu request will assist in averting the threatened death r serius physical injury. 7. If email sent frm a Yah! accunt is the basis fr the belief that there is a risk f imminent harm, please attach a cpy f the email message(s) t this frm. I declare under penalty f perjury that the freging is true and crrect. Signature f Law Enfrcement Officer Date Printed Name f Law Enfrcement Officer, Title, and Agency -16-
APPENDIX D Sample Cnsent t Search Frm (This request must be accmpanied by a subpena and a cver letter r fax bearing the fficial seal f the requesting agency) I, the accunt hlder f the Yah! accunt with Yah! ID understand that my accunt is being sught in cnnectin with an fficial law enfrcement investigatin. As part f that investigatin, I hereby grant my cnsent t authrize the fllwing agency:, t receive, review, cpy, and therwise btain access t all infrmatin f any kind held by Yah! relating t my accunts and any and all accunts that I have linked t the fllwing Yah! ID, including but nt limited t infrmatin abut my identity, my nline activities, and the cntents f all electrnic files r cmmunicatins maintained by Yah! related t me r my ID. Pursuant t the cnsent I hereby request that the fllwing specific infrmatin be prvided: In cnnectin with this authrity t release infrmatin, I d hereby agree t hld harmless and d frever hld harmless Yah! fr the disclsure f such infrmatin and d frever waive n my behalf, and n behalf f my heirs and assigns, any and all claims resulting frm Yah! s disclsure f any infrmatin related t my accunt pursuant t this authrizatin. The fllwing infrmatin shuld be used by Yah! t verify my identity: Lgin name/yah! ID Yah! email address Alternate email address Birthday (as indicated n this accunt) Answer t secret questin (Cntact Yah! Cmpliance fr secret questin) City, state, and zip Gender Yah! user s signature Date -17-