03/04/09
As it stands, in accordance with the Electronic Communications Privacy Act of 1986, U.S. based ISPs are required, upon the request of law enforcement, to retain the data associated with specific IP addresses for at least 90 days. If the new bill is passed, ISPs will be required to retain the user information for two years. The new bills reads: ''A provider of an electronic communication service or remote computing service shall retain for a period of at least two years all records or other information pertaining to the identity of a user of a temporarily assigned network address the service assigns to that user.''
The purpose of the two separate bills, collectively called The Internet Safety Act, is to help prevent child pornography found and accessed on the Internet. The Internet Safety Act calls for stiffer penalties for those individuals who are accessing online child pornography and that all Internet and e-mail service providers will be required to maintain records and information regarding individuals who access the pornography via a network addresses. Although the new bills were created to aid in the prevention of child pornography, any law enforcement agency can access and use this information for enforcement purposes. The RIAA and MPAA could also utilize this information in their quest to reduce online piracy.
If the bills are passed, in addition to ISPs, certain institutions and organizations including schools, diners, internet cafes, and delis will be required to retain detailed logs of the data associated with the IP addresses randomly assigned to individual users. The information gathered will include logins, the websites visited, online search queries, HTTP PUT and GET commands, encoded data input on user’s forms, and almost any other information that is voluntarily entered into a URL.
Similar bills have been unsuccessfully introduced in the U.S., however presently, the European Union already has a law that is directly aimed at ISPs.