CALEA

Privacy & Surveillance

CALEA Explained: Wiretapping Law & Digital Privacy

The Communications Assistance for Law Enforcement Act (CALEA) requires telecom carriers to build wiretap capability into their networks. Here’s what the law does, how it expanded to the internet, the privacy debate around it, and why a 2024 hack put it back in the headlines.

Reviewed & updated · 8 min read

CALEA at a Glance

1994
Signed into law
In force January 1, 1995
2005
Extended to the web
Broadband & VoIP, via FCC order
Court order
Still required
CALEA governs capability, not authority
Encryption
Not mandated open
Congress hasn’t required messaging backdoors

What Is CALEA?

The Communications Assistance for Law Enforcement Act (CALEA) was enacted on October 25, 1994. Its goal was to preserve law enforcement’s ability to conduct court-authorized electronic surveillance as the phone network shifted from analog to digital. CALEA requires telecommunications carriers to design their networks so that, when presented with a valid court order, they can isolate and hand over a target’s communications.

Importantly, CALEA is about capability, not authority. It does not grant new power to listen in — a wiretap still requires a court order based on probable cause. What CALEA does is require carriers to keep their systems “tappable” so that lawful orders can actually be executed.

From Phone Lines to Broadband

CALEA originally applied to traditional telephone carriers. In 2004–2005, the Federal Communications Commission (FCC) extended it to cover facilities-based broadband internet access and interconnected Voice over IP (VoIP) services — an expansion the courts upheld in 2006. That brought a large slice of internet infrastructure under CALEA’s interception requirements.

What CALEA has not done is reach every corner of the internet. Repeated proposals — often called “CALEA II” or framed around the FBI’s “Going Dark” concern — would require messaging apps and other online services to build in interception or decryption capabilities. Congress has not enacted those mandates, and the question of “lawful access” to end-to-end encrypted communications remains unresolved.

The Privacy Debate: Two Sides

The case for expansion

Law enforcement argues that criminals and threats increasingly use digital channels — encrypted messaging, VoIP, social platforms — that fall outside CALEA. Without updated capability, agencies say court-ordered surveillance “goes dark,” even with a valid warrant in hand. Their goal, they say, is to preserve the status quo, not extend it.

The case against

Privacy advocates counter that surveillance has, in many ways, gotten easier in the digital age — location data, metadata, and device access already exist. They warn that mandated backdoors raise Fourth Amendment concerns, impose heavy compliance costs that consumers ultimately pay, chill innovation, and — most critically — create security holes that criminals and foreign adversaries can exploit.

Why It Matters Now

2024: Hackers Exploited the Wiretap Backdoor

In late 2024, U.S. officials confirmed that a Chinese state-linked hacking group known as “Salt Typhoon” had compromised the CALEA-mandated lawful-interception systems at several major U.S. telecom carriers. The breach turned a tool built for court-ordered surveillance into an entry point for foreign espionage — a real-world example of the long-standing warning that building interception capability into networks also builds a target for attackers.

Authoritative Resources

Primary sources and analysis on CALEA, from government and respected policy organizations.

Regulator

FCC — CALEA

The Federal Communications Commission’s official CALEA rules and compliance hub.

Visit →
Enforcement

FBI NDCAC — About CALEA

The FBI’s National Domestic Communications Assistance Center on CALEA implementation.

Visit →
The Law

Congress.gov — H.R.4922 (1994)

The original text and legislative history of CALEA as passed by Congress.

Visit →
Analysis

CRS — Digital Surveillance & CALEA

Nonpartisan Congressional Research Service report on CALEA and its debates.

Visit →
Privacy Advocacy

EFF — CALEA

The Electronic Frontier Foundation’s overview and FAQ on CALEA and its expansion.

Visit →
Privacy Advocacy

EPIC & CDT

Background and policy analysis from the Electronic Privacy Information Center and the Center for Democracy & Technology.

Visit CDT →

Frequently Asked Questions

Plain-language answers about CALEA and digital wiretapping.

CALEA — the Communications Assistance for Law Enforcement Act of 1994 — is a U.S. law requiring telecommunications carriers to design their networks so they can deliver a target’s communications to law enforcement when presented with a valid court order.

Traditional telephone carriers, and — since the FCC’s 2005 order — facilities-based broadband internet access providers and interconnected VoIP services. It does not cover every online service or app.

No. CALEA does not require a carrier to decrypt communications it doesn’t hold the keys to, and Congress has not extended it to mandate backdoors in internet messaging or end-to-end encryption. That remains the unresolved “lawful access” or “Going Dark” debate.

No. CALEA governs technical capability, not legal authority. Intercepting communications still requires a court order or warrant under existing wiretap law — CALEA simply ensures carriers are able to comply with one.

It’s a central concern of critics: any interception capability is also a potential attack surface. In late 2024, the “Salt Typhoon” hacking group reportedly exploited CALEA-mandated wiretap systems at major U.S. carriers, illustrating that the backdoors built for law enforcement can be abused by adversaries.

More From Our Security Library

JMAC Supply follows the technology and policy shaping physical and digital security. Explore related guides, including the history of CCTV and our full resource library.

Live Chat