New bill would force ISPs to retain user data for two years
A pair of Republican legislators have introduced legislation that would require ISPs to retain user data for two years as a means of helping law enforcement fight child porn; is this latest effort narrow enough to finally pass?
Context & Ripple Effects
This 2009 bill is an early move in a long-running tug-of-war over whether ISPs become de facto archives for law enforcement. A year later the FBI pushed for records of Web sites visited, and by 2015 the idea had gone mainstream abroad: Australia mandated two-year telco data retention with warrantless access, followed by a UK surveillance bill requiring ISPs to log browsing history for a year. The recurring framing is child protection — the same justification behind California's bipartisan children's online data bill and the Senate's repeated passes of COPPA 2.0, which has repeatedly stalled in the House.
First-order effects
- If passed, ISPs and their subscribers immediately bear the cost: network operators must build and run two-year storage of user activity data, while every customer's traffic records become retrievable without needing a preservation request upfront.
- Law enforcement gains a standing corpus of subscriber and usage data for investigations, shifting evidence-gathering from case-by-case requests to routine lookup.
Second-order effects
- ISPs would face new compliance costs that favor scale, accelerating consolidation among smaller regional providers and pushing retained-data infrastructure into the hands of a few large carriers.
- The child-safety rationale invites copycat provisions: expect parallel pushes at the state level and in other countries, as happened when Australia and the UK enacted their own retention mandates.
Third-order effects
- Mandatory retention normalizes the ISP as a surveillance intermediary, structurally separating what users do from who can later see it — and making future access expansions (warrantless or otherwise) a policy question rather than a technical one.
- Over time, retention mandates collide with privacy legislation moving the other direction, like children's data protections; the likely equilibrium is a bifurcated regime where data must be kept but tightly scoped in use — an outcome still genuinely uncertain in the US.
The trend: Governments are steadily converting ISPs from passive conduits into mandatory evidence custodians, with child safety as the durable justification for expanding data retention mandates.