A subpoena arrives for one of your users: what a U.S. classifieds operator actually has to hand over

The call that is not a subpoena
An email arrives from a police department asking about one advertiser's account: name, IP address, the messages tied to a listing. Nothing in the message says what law requires an answer, only that the sender is a detective and the case is real. Most operators do one of two things at that point, and both are mistakes. They hand over whatever the dashboard shows because refusing feels like it will make the business look complicit, or they refuse everything because handing anything over feels like a risk with no upside. Neither response depends on what the law actually requires, and that gap is where an otherwise well-run directory gets into trouble.
A badge, a phone call and an email from a government address are not, by themselves, legal process. Nothing in U.S. law obligates a provider to disclose a user's data because an officer asked, and treating every request as automatically valid is exactly the instinct that leads to disclosing more than any court has actually authorized. What compels disclosure is a specific instrument: a subpoena, a court order issued under one particular section of federal law, or a warrant. Each one reaches a different, precisely defined slice of what a directory holds, and none of them is interchangeable with the others.
The one situation where handing data over without any of those instruments is lawful is narrow, and worth knowing exactly, because operators either forget it exists or stretch it to cover cases it was never written for. Under 18 U.S.C. § 2702(b), a provider may voluntarily disclose records, and even the content of communications, to a government entity if it believes in good faith that an emergency involving danger of death or serious physical injury requires disclosure without delay. That is a genuine emergency exception: a listing that reads as an imminent threat to someone's safety, not an investigation that could just as easily wait a week for paperwork.
Outside that one case, the right first move is the same regardless of who is asking: get the request in writing, confirm it names the actual legal instrument behind it, and route it to one person inside the business, ideally the same person or counsel who already handles the platform's other compliance obligations, rather than whoever happened to open the email. Everything that follows depends on knowing which instrument is in hand before deciding what it actually entitles the requester to.
What a subpoena alone can reach, and what it cannot
A subpoena is the weakest instrument in this hierarchy, and it is also the one operators most often over-comply with. Under 18 U.S.C. § 2703(c)(2), a subpoena can compel disclosure of what the statute calls basic subscriber information: name, address, session and connection records or their duration, length and type of service, any subscriber or device identifier including a temporarily assigned network address, and the means or source of payment for the service, including a credit card or bank account number. That is the entire list. It does not include the content of a message, a listing description, or a photo, no matter how the request is worded.
This matters because a subpoena is comparatively easy to obtain: it does not require a judge to weigh evidence the way a warrant does, and it is the instrument that shows up most often in the ordinary course of an investigation, not just the serious ones. A directory that treats a subpoena as authorization to hand over message logs or verification documents is giving away more than the law asked for, and every extra document handed over is one more thing the business has to account for later if a user, a regulator, or a court ever asks why it left the building.
Content, meaning the substance of what a user actually wrote or sent rather than the fact that an account exists, sits behind a much higher bar. Under § 2703(a), content held in storage 180 days or less can only be compelled with a warrant, obtained under the same probable-cause standard used in any other criminal case. The statute's text treats content stored longer than that differently, in theory allowing a subpoena or a lesser court order once notice is given, but that gap on paper does not reflect how the request will actually arrive.
Following a federal appeals court ruling in 2010 and a policy change that came after it, U.S. federal prosecutors adopted a nationwide practice of obtaining a warrant for content regardless of how long it has been stored, treating the 180-day distinction in the statute as effectively retired even though the text itself was never rewritten. In practice, if a request for anything resembling message content arrives without a warrant attached, that is the signal to ask what instrument is actually behind it before producing anything, not to assume the sender already checked.
Between a subpoena and a warrant sits one more instrument, a court order under § 2703(d), which a judge can issue on a lower showing than probable cause: specific and articulable facts showing reasonable grounds to believe the records sought are relevant and material to an ongoing investigation. It still requires going before a judge, which separates it from a subpoena issued without judicial review, but it does not reach content that only a warrant can compel. Knowing which of the three is on the desk, subpoena, order, or warrant, decides what a directory owes a response and what it doesn't.
The preservation letter that arrives first
Before any subpoena or warrant, most investigations touching a directory start with something quieter: a preservation request under 18 U.S.C. § 2703(f). No court is involved. A governmental entity asks the provider to preserve specific records, and the provider has to freeze what it holds so the data isn't overwritten, deleted, or rotated out by the platform's own retention schedule while the government decides whether to seek a subpoena, an order, or a warrant for it.
The request itself does not compel disclosure of anything: preservation and production are two separate steps, and a directory that reads a preservation letter as a demand to hand data over immediately is doing more than the law asked, in the same direction as over-complying with a bare subpoena. What the request does compel is retention: the statute sets the hold at 90 days, extendable once for another 90 days if the government renews the request before the first period runs out.
This is the moment where a directory's own data practices either make the request simple or turn it into a scramble. Deciding in advance how long identity verification records, payment records, and account logs are kept is what determines whether a 90-day hold is trivial, because the data was going to sit there anyway, or impossible, because the platform's normal deletion schedule already erased it before the letter arrived. A preservation request cannot resurrect data that a retention policy has already destroyed, and a provider that cannot honor a hold because of its own deletion habits has created a problem for itself independent of anything the government did.
The practical answer is to have a documented process ready before the first letter arrives: one inbox or contact that preservation requests go to, one person who checks that the request is genuinely from a government entity, and a way to flag the named account so normal deletion routines skip it for the hold period. None of this requires a lawyer to execute once it is designed, but designing it without ever having handled a real request is far easier than improvising it under a deadline.
The duty that has nothing to do with a request
Everything so far concerns what happens when the government asks. One obligation runs the other way: a duty to report, triggered by what the platform itself finds, with no request involved at all. Under 18 U.S.C. § 2258A, a provider that obtains actual knowledge of apparent child sexual abuse material on its platform must report it to the CyberTipline run by the National Center for Missing & Exploited Children as soon as reasonably possible.
The statute is specific about what triggers the duty and what does not: it requires a report once a provider has actual knowledge, not a general obligation to search, scan, or monitor listings looking for it. A directory does not have to run its own detection program to comply with this law, but if a moderator, a support ticket, or a flag from a payment or verification vendor surfaces something that looks like it, the clock on "as soon as reasonably possible" starts immediately, not once the team gets around to reviewing it.
The consequence for getting this wrong changed materially in 2024. The REPORT Act raised the required preservation period for a report and the material behind it from the previous 90 days to a full year, and raised the civil penalties for a knowing and willful failure to report to up to 600,000 dollars for a first violation and 850,000 dollars for a subsequent one, for a provider with under 100 million monthly users, which covers essentially every classifieds directory. Older compliance notes that still cite a 90-day hold or the pre-2024 penalty figures are describing a law that no longer exists in that form.
This duty sits next to, but is legally distinct from, the platform liability question that determines whether an operator can be held criminally responsible for facilitating trafficking through its listings. A directory can be careful about the first and still fail the second if it does not have a working, tested path from the person who spots something to the person who actually files the report, and that path is worth testing before it is needed rather than discovering it does not work in the middle of an actual case.
What to do, in order
Put one person or role in charge of every law enforcement contact, the same way a directory would designate one person to own a chargeback queue or a data-deletion schedule. Whoever receives the first phone call should have a direct way to hand it to that person rather than answering on the spot.
Require the instrument in writing before producing anything beyond confirming an account exists, and read it for what it actually is: a subpoena, a preservation request, a § 2703(d) order, or a warrant, each authorizing a different, non-overlapping slice of data. If a request for message content or verification documents arrives without a warrant attached, that is the cue to ask what is behind it, not to assume the sender already has the right paperwork.
Log every request that comes in, whether or not it results in anything being produced: the date, the requesting agency, the instrument attached, what was preserved or handed over, and who signed off. This is the same discipline that turns a payment dispute or a data-access complaint from a vague memory into a record the business can actually stand behind later.
Fix the CyberTipline reporting path before it is ever needed: know who inside the business actually has the authority and the login to file a report, and confirm the retention period the team is working from is the current one, a full year, not an outdated 90 days copied from an older policy document.
Get a lawyer's number settled before the day a subpoena arrives, not after. Nothing in this piece replaces legal advice on an actual request, and the value of everything above is that it tells that lawyer, and the operator, which of these instruments is in front of them before either one has to guess.

