PRISM: Section 702 FAA Surveillance Program (Revealed June 6, 2013)
Introduction
On June 6, 2013, two news organizations published simultaneously: the Washington Post, with reporting by Barton Gellman, and The Guardian, with reporting by Glenn Greenwald. Both published slides from a classified NSA PowerPoint presentation titled "PRISM/US-984XN Overview." The slides had been provided by Edward Snowden, a contractor for Booz Allen Hamilton working at an NSA facility in Hawaii, who had deliberately collected the documents and transmitted them to journalists.
The slides described a program called PRISM — formally designated US-984XN — under which the NSA collected communications content directly from the servers of nine major US internet companies: Microsoft, Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube, and Apple. The program operated under Section 702 of the Foreign Intelligence Surveillance Act, as amended by the FISA Amendments Act (FAA) of 2008.
How PRISM Worked
Section 702 of FISA authorizes the collection of communications of non-US persons located outside the United States for foreign intelligence purposes. Under PRISM, the NSA served legal orders on US-based internet companies compelling them to provide communications content — emails, chat logs, files, photos, stored data — for targeted foreign intelligence subjects.
The companies could not publicly disclose these orders due to gag provisions. They provided data in response to individual court orders from the FISA Court, which operates in secret. The companies' subsequent denials of "direct access" to their servers by the NSA were technically accurate in a narrow sense — the NSA was not sitting inside their data centers with unrestricted access — but they obscured the legal compulsion to provide data on demand.
The Boundless Informant Tool
Among the documents Snowden provided was information about Boundless Informant, an NSA metadata analytics tool that tracked the volume and type of intelligence collected. Boundless Informant data showed that the NSA collected billions of records monthly under various programs. The tool's existence contradicted NSA Director Keith Alexander's 2012 Senate testimony in which he stated the NSA did not collect data on millions of Americans — Boundless Informant showed the scale of collection.
Congressional Response and PCLOB Review
Following the Snowden disclosures, NSA Director Keith Alexander testified before Congress, defending the programs as legally authorized and operationally necessary. President Obama acknowledged the programs and commissioned the President's Review Group on Intelligence and Communications Technologies, which issued a report in December 2013.
The Privacy and Civil Liberties Oversight Board (PCLOB) issued a detailed report on the Section 702 program in July 2014. The PCLOB found the program legally authorized under the FAA but raised significant concerns about the collection of US persons' communications incidentally captured during foreign intelligence collection — so-called "incidental collection" that could include vast amounts of wholly domestic communication.
Company Denials and Acknowledgments
All nine companies named in the PRISM slides issued initial denials of varying specificity. Google stated it did not provide the government with "direct access" to its servers. Facebook stated it did not provide "direct" or "backdoor" access. The denials were carefully worded to be technically accurate while avoiding confirmation of the legal compulsion structure.
In subsequent years, all major companies began publishing "transparency reports" disclosing the number and type of government requests they received annually. These reports confirmed ongoing legal compliance with FISA court orders.
Scope and Scale
The PCLOB's 2014 report confirmed that Section 702 collection touched a significant portion of all internet communications. "Incidental collection" of US persons' communications — captured because they communicated with targeted non-US persons — was acknowledged as a feature of the program's architecture, not an anomaly.
Verdict
Confirmed. The PRISM program is confirmed by the NSA slides, congressional testimony, the PCLOB 2014 report, and the subsequent company transparency reporting framework. The program operated under legal authority (Section 702 FAA) but the scale of incidental US-person collection and the secrecy of the FISA court orders raised documented constitutional concerns. This is confirmed surveillance, not conspiracy theory.
Mechanism: Downstream Collection From Nine Providers Under Section 702
Section 702 of FISA, added by the FISA Amendments Act (FAA) of 2008, does not authorize one collection method but two, run under a single statutory umbrella. PRISM is the "downstream" half: an NSA analyst tasks a "selector" — an email address, a username, a phone identifier — reasonably believed to belong to a non-US person located outside the United States, and a provider is compelled to hand over communications to and from that specific selector. No judge reviews each selector. Instead, the Foreign Intelligence Surveillance Court (FISC) approves a yearly certification and a package of targeting and minimization procedures that govern how selectors may be chosen and how any incidentally collected US-person data must be handled. "Upstream" collection, by contrast, taps the internet backbone itself — historically through companies like AT&T — and for years scanned transiting traffic not just for communications to or from a target but for any communication that mentioned a tasked selector, so-called "about" collection. PRISM's provider-side handoff and upstream's backbone tap are legally and technically distinct programs that both fall under Section 702, which is why fact-checks of "PRISM" and of "NSA mass surveillance" more broadly often talk past each other. The leaked slide deck itself listed the nine named providers with the specific dates each began supplying data: Microsoft (September 2007), Yahoo (March 2008), Google (January 2009), Facebook (June 2009), PalTalk (December 2009), YouTube (September 2010), Skype (February 2011), AOL (March 2011), and Apple (October 2012) — a staggered rollout over five years, not a single simultaneous switch-on.
Key Evidence: The Slides and the Providers' Own Escalation
Only a handful of the roughly 41 slides in the "PRISM/US-984XN Overview" deck were ever published, and Gellman and Greenwald both withheld operational details at the government's request. What was published was enough to be independently checked: internal NSA branding, the FAA 702 legal citation, and the provider join-date table above, which no outside party could have fabricated and which no named company disputed on the facts, only on the characterization of "direct access." The companies' response went beyond the carefully worded denials described above. On June 18, 2013, Google filed a motion with the FISC itself, asking for a declaratory judgment that it had a First Amendment right to publish the aggregate number of FISA orders it received; Microsoft, Yahoo, Facebook, and LinkedIn filed parallel motions within days. Rather than litigate the question, the government notified the court on January 27, 2014 that it would permit the companies to publish banded aggregate figures, and the Director of National Intelligence declassified the underlying data. That a group of the largest technology companies in the world chose to sue their own government's secret court over the right to describe the scope of the program, and that the government settled rather than defend the gag order, is itself evidence that the underlying legal compulsion was real, not a mistaken inference from the slides.
Official Findings: PCLOB and the Declassified FISC Opinions
The clearest confirmation that the government had, in the past, misrepresented the scope of Section 702 collection to its own overseers came from the FISC itself. On October 3, 2011, then-presiding FISC Judge John D. Bates issued an 81-page opinion finding that NSA's upstream collection, as it was then being conducted, was unconstitutional under the Fourth Amendment in part because it was sweeping in an estimated 56,000 wholly domestic communications a year. Bates noted this was the third time since 2008 the government had disclosed to the court that it was collecting more than it had represented. That opinion, along with a related November 2011 ruling, remained classified until the Office of the Director of National Intelligence declassified it in August 2013, two months after the Snowden disclosures forced the issue into public view. The Privacy and Civil Liberties Oversight Board's July 2014 report — and its 2023 follow-up report reassessing the program nearly a decade later — drew on this same body of FISC opinions and NSA compliance filings, and both found the program operating within a real, court-supervised legal structure while continuing to flag unresolved problems, particularly around FBI queries of Section 702 data using US-person identifiers.
The Strongest Counter-Argument — and Where It Holds
The most serious objection to characterizing PRISM as "mass surveillance" is that Section 702 collection is targeted, not bulk: a company cannot be ordered to hand over "everyone's data," only communications tied to a specific tasked selector believed to belong to a non-US person abroad, under a legal framework a federal court reviews annually. This distinction is real and it is documented, not a talking point invented after the fact — PCLOB's reports and the FISC's own declassified opinions describe exactly this selector-based architecture, and it is meaningfully different from the NSA's separate, since-ended bulk telephone metadata program under Section 215. Where the counter-argument runs out of room is incidental collection: because a target's communications with anyone, including Americans, are collected in full, and because upstream's former "about" collection swept in communications merely referencing a selector, PCLOB itself acknowledged that a substantial share of the communications in NSA's Section 702 holdings involve at least one party who is a US person. The 2011 Bates opinion shows this was not a hypothetical risk but a documented, recurring compliance failure for years. So the "targeted, not bulk" defense correctly describes the legal mechanism and correctly rebuts claims of an unrestricted backdoor; it does not show that incidental US-person collection is rare or that oversight caught every problem before disclosure forced the issue.
Aftermath: From the USA FREEDOM Act to the 2024 Reauthorization
The disclosures produced a decade of legislative revisions rather than repeal. The USA FREEDOM Act, signed June 2, 2015, ended the NSA's bulk telephone metadata program and, for the first time, gave the FISC a mechanism to hear an independent legal voice — an amicus "special advocate" — on significant novel questions, a reform later applied to Section 702 opinions as well. In 2017 the NSA announced it would stop upstream "about" collection and purge the previously gathered data, directly responding to the compliance history the Bates opinion had exposed. Congress reauthorized the underlying Section 702 authority in January 2018 through 2023, and again on April 20, 2024 through the Reforming Intelligence and Securing America Act (RISAA), which extends the authority to April 2026, statutorily bars any resumption of "about" collection, and adds new supervisory-approval and reporting requirements after further reported FBI query failures. PRISM's downstream mechanism, now publicly acknowledged rather than secret, remains active today — reauthorized, not dismantled, each time Congress has revisited it.
Evidence Filters12
NSA PowerPoint slides published simultaneously by WaPo and Guardian
SupportingStrongOn June 6 2013, the Washington Post and The Guardian simultaneously published NSA internal slides from a classified presentation titled "PRISM/US-984XN Overview." The slides identified nine companies and described the collection program in operational detail.
PCLOB 2014 report confirmed Section 702 program scope
SupportingStrongThe Privacy and Civil Liberties Oversight Board's July 2014 report on the Section 702 program confirmed PRISM's legal basis and operational parameters, including the scale of US-person "incidental collection." The PCLOB is an independent federal oversight body.
NSA Director Keith Alexander testified to Congress about the program
SupportingStrongFollowing the Snowden disclosures, NSA Director Alexander testified before Senate and House committees. His testimony confirmed the programs' existence and legal authorization while defending their operational necessity.
Boundless Informant metadata tool contradicted Alexander's prior testimony
SupportingStrongSnowden also disclosed Boundless Informant, an NSA analytics tool showing billions of records collected monthly. The tool's existence and data contradicted Alexander's 2012 Senate testimony that the NSA did not collect data on millions of Americans.
Companies denied "direct access" — technically accurate but misleading
NeutralAll nine named companies issued denials of "direct access" to servers. The denials were technically accurate in the narrow sense that NSA did not have unrestricted server access but obscured the legal compulsion to provide data on demand under FISA court orders.
Rebuttal
The "direct access" denial is accurate as far as it goes. Companies complied with legal compulsion through FISA court orders, not through open-door server access. The program still resulted in large-scale content collection from these platforms — the distinction is architectural, not substantive for affected users.
Section 702 legal authority — program was legally authorized
DebunkingUnlike the Room 641A program, PRISM operated under explicit Section 702 FISA authorization. The PCLOB found the program legally authorized. The constitutional concerns relate to incidental US-person collection, not to the absence of legal authority.
Rebuttal
Legal authorization under Section 702 does not resolve all constitutional concerns. The PCLOB and civil liberties groups identified significant Fourth Amendment questions about the scale of incidental US-person collection. Congress reauthorized Section 702 in subsequent legislation.
Edward Snowden provided documents from NSA contractor position
SupportingStrongSnowden worked as a contractor for Booz Allen Hamilton at an NSA facility in Hawaii. His access to PRISM documents came from his legitimate work role. He transmitted the documents to journalists Greenwald and Gellman before traveling to Hong Kong.
Company transparency reports confirmed ongoing FISA compliance post-disclosure
SupportingStrongFollowing the disclosures, all major named companies began publishing annual transparency reports disclosing FISA request volumes. These reports confirmed ongoing legal compliance with FISA court orders, corroborating the program's continuing operation.
PRISM targeting requires an individualized, FISC-approved selector — not open-ended access to a provider's servers
DebunkingUnder Section 702, an NSA analyst must task a specific selector (e.g., an email address) reasonably believed to belong to a non-US person located abroad; the FISC approves yearly certifications and targeting/minimization procedures, not each search. Companies could not be compelled to hand over their full user base at once.
Rebuttal
This describes the legal targeting mechanism accurately, but it does not address the volume of incidental collection: because a target's full communications are collected, and because upstream 'about' collection (a separate Section 702 channel) once swept in messages merely referencing a selector, PCLOB found a substantial share of NSA's Section 702 holdings include at least one US-person party. Targeted process and large-scale incidental sweep are not mutually exclusive.
NSA ended upstream 'about' collection in 2017 and RISAA (2024) statutorily bars its resumption
DebunkingFollowing years of documented compliance problems, the NSA voluntarily halted 'about' collection under upstream surveillance in 2017 and purged previously collected data. The 2024 Reforming Intelligence and Securing America Act (RISAA) made the prohibition statutory, with no exceptions for resuming it administratively.
Rebuttal
The change applies to upstream collection specifically, not to PRISM's downstream provider-based collection, which continues under Section 702 largely as originally structured. It shows the oversight system can force corrections after the fact, not that incidental collection concerns were resolved for PRISM itself.
Show 2 more evidence points
Tech Companies Provided Court-Ordered Access, Not Voluntary 'Direct Access' Backdoors
DebunkingApple, Google, Microsoft, Facebook, and other PRISM-listed companies consistently and specifically denied providing NSA with 'direct access' to their servers. Post-Snowden reporting and subsequent legal proceedings established that companies received Section 702 orders through FISC and provided responsive data through secure government portals — a court-ordered process, not a backdoor arrangement. This distinction matters: framing PRISM as a secret voluntary corporate conspiracy to share user data without legal process misstates the documented mechanism, which involved compelled disclosure under classified judicial authority.
Section 702 Has Foreign Intelligence Surveillance Court Oversight With Documented Compliance Reviews
NeutralThe FISC reviews Section 702 certifications annually and has issued opinions — some of which were declassified post-Snowden — finding compliance violations and requiring remediation. The court's 2011 opinion finding certain upstream collection techniques violated the Fourth Amendment (later modified) demonstrates that judicial oversight identified and constrained NSA overreach. While critics argue FISC oversight is insufficiently adversarial, the existence of compliance findings and mandated remediation is inconsistent with a characterisation of Section 702 as a completely unchecked or wholly secret programme operating outside any legal accountability.
Evidence Cited by Believers6
NSA PowerPoint slides published simultaneously by WaPo and Guardian
SupportingStrongOn June 6 2013, the Washington Post and The Guardian simultaneously published NSA internal slides from a classified presentation titled "PRISM/US-984XN Overview." The slides identified nine companies and described the collection program in operational detail.
PCLOB 2014 report confirmed Section 702 program scope
SupportingStrongThe Privacy and Civil Liberties Oversight Board's July 2014 report on the Section 702 program confirmed PRISM's legal basis and operational parameters, including the scale of US-person "incidental collection." The PCLOB is an independent federal oversight body.
NSA Director Keith Alexander testified to Congress about the program
SupportingStrongFollowing the Snowden disclosures, NSA Director Alexander testified before Senate and House committees. His testimony confirmed the programs' existence and legal authorization while defending their operational necessity.
Boundless Informant metadata tool contradicted Alexander's prior testimony
SupportingStrongSnowden also disclosed Boundless Informant, an NSA analytics tool showing billions of records collected monthly. The tool's existence and data contradicted Alexander's 2012 Senate testimony that the NSA did not collect data on millions of Americans.
Edward Snowden provided documents from NSA contractor position
SupportingStrongSnowden worked as a contractor for Booz Allen Hamilton at an NSA facility in Hawaii. His access to PRISM documents came from his legitimate work role. He transmitted the documents to journalists Greenwald and Gellman before traveling to Hong Kong.
Company transparency reports confirmed ongoing FISA compliance post-disclosure
SupportingStrongFollowing the disclosures, all major named companies began publishing annual transparency reports disclosing FISA request volumes. These reports confirmed ongoing legal compliance with FISA court orders, corroborating the program's continuing operation.
Counter-Evidence4
Section 702 legal authority — program was legally authorized
DebunkingUnlike the Room 641A program, PRISM operated under explicit Section 702 FISA authorization. The PCLOB found the program legally authorized. The constitutional concerns relate to incidental US-person collection, not to the absence of legal authority.
Rebuttal
Legal authorization under Section 702 does not resolve all constitutional concerns. The PCLOB and civil liberties groups identified significant Fourth Amendment questions about the scale of incidental US-person collection. Congress reauthorized Section 702 in subsequent legislation.
PRISM targeting requires an individualized, FISC-approved selector — not open-ended access to a provider's servers
DebunkingUnder Section 702, an NSA analyst must task a specific selector (e.g., an email address) reasonably believed to belong to a non-US person located abroad; the FISC approves yearly certifications and targeting/minimization procedures, not each search. Companies could not be compelled to hand over their full user base at once.
Rebuttal
This describes the legal targeting mechanism accurately, but it does not address the volume of incidental collection: because a target's full communications are collected, and because upstream 'about' collection (a separate Section 702 channel) once swept in messages merely referencing a selector, PCLOB found a substantial share of NSA's Section 702 holdings include at least one US-person party. Targeted process and large-scale incidental sweep are not mutually exclusive.
NSA ended upstream 'about' collection in 2017 and RISAA (2024) statutorily bars its resumption
DebunkingFollowing years of documented compliance problems, the NSA voluntarily halted 'about' collection under upstream surveillance in 2017 and purged previously collected data. The 2024 Reforming Intelligence and Securing America Act (RISAA) made the prohibition statutory, with no exceptions for resuming it administratively.
Rebuttal
The change applies to upstream collection specifically, not to PRISM's downstream provider-based collection, which continues under Section 702 largely as originally structured. It shows the oversight system can force corrections after the fact, not that incidental collection concerns were resolved for PRISM itself.
Tech Companies Provided Court-Ordered Access, Not Voluntary 'Direct Access' Backdoors
DebunkingApple, Google, Microsoft, Facebook, and other PRISM-listed companies consistently and specifically denied providing NSA with 'direct access' to their servers. Post-Snowden reporting and subsequent legal proceedings established that companies received Section 702 orders through FISC and provided responsive data through secure government portals — a court-ordered process, not a backdoor arrangement. This distinction matters: framing PRISM as a secret voluntary corporate conspiracy to share user data without legal process misstates the documented mechanism, which involved compelled disclosure under classified judicial authority.
Neutral / Ambiguous2
Companies denied "direct access" — technically accurate but misleading
NeutralAll nine named companies issued denials of "direct access" to servers. The denials were technically accurate in the narrow sense that NSA did not have unrestricted server access but obscured the legal compulsion to provide data on demand under FISA court orders.
Rebuttal
The "direct access" denial is accurate as far as it goes. Companies complied with legal compulsion through FISA court orders, not through open-door server access. The program still resulted in large-scale content collection from these platforms — the distinction is architectural, not substantive for affected users.
Section 702 Has Foreign Intelligence Surveillance Court Oversight With Documented Compliance Reviews
NeutralThe FISC reviews Section 702 certifications annually and has issued opinions — some of which were declassified post-Snowden — finding compliance violations and requiring remediation. The court's 2011 opinion finding certain upstream collection techniques violated the Fourth Amendment (later modified) demonstrates that judicial oversight identified and constrained NSA overreach. While critics argue FISC oversight is insufficiently adversarial, the existence of compliance findings and mandated remediation is inconsistent with a characterisation of Section 702 as a completely unchecked or wholly secret programme operating outside any legal accountability.
Timeline
FISA Amendments Act Section 702 enacted — PRISM legal basis established
The FAA 2008 creates Section 702, authorizing foreign intelligence collection from US-based internet companies under FISA court orders. PRISM begins operating under this authority shortly after enactment, targeting non-US persons outside the US communicating via US internet services.
Snowden leaks PRISM slides — WaPo and Guardian publish simultaneously
Edward Snowden transmits NSA PowerPoint slides to Barton Gellman (Washington Post) and Glenn Greenwald (The Guardian). Both publish simultaneously on June 6 2013, revealing PRISM's nine company targets, collection architecture, and legal basis.
Source →NSA Director Alexander defends programs in Senate testimony
NSA Director Keith Alexander testifies before the Senate Intelligence Committee, defending PRISM as legally authorized and operationally essential. He describes the program as having disrupted multiple terrorist plots, a claim subsequently contested by independent review groups.
Clapper apologizes for 'clearly erroneous' Senate testimony
DNI James Clapper sent a letter to the Senate Intelligence Committee acknowledging his March 2013 answer to Sen. Ron Wyden — that the NSA did not collect data on millions of Americans — was 'clearly erroneous,' after Snowden's leaks revealed bulk collection programs.
Source →
Verdict
The PRISM program is confirmed by NSA PowerPoint slides leaked by Edward Snowden, published simultaneously by the Washington Post and The Guardian on June 6 2013. The PCLOB 2014 report confirmed the program's legal basis and scope. NSA Director Keith Alexander testified to Congress. Nine companies named — all acknowledged compliance with FISA court orders. Section 702 collection of US-person communications as 'incidental' collection is documented.
Frequently Asked Questions
Did companies like Google and Facebook knowingly participate in PRISM?
Yes, through legal compulsion. All nine named companies received FISA court orders compelling them to provide data. They could not disclose the orders due to gag provisions. Their denials of "direct access" were technically accurate in a narrow architectural sense but did not capture the reality of legal compulsion to provide content on demand. Company transparency reports published after the disclosures confirm ongoing FISA compliance.
Was PRISM legal?
The PCLOB found PRISM legally authorized under Section 702 of the FISA Amendments Act. Constitutional concerns center on the scale of "incidental collection" of US persons' communications captured because they communicated with targeted non-US persons. Courts have upheld Section 702 against Fourth Amendment challenges, though the issue has not been fully resolved by the Supreme Court.
What is the difference between PRISM and upstream collection?
PRISM collected content from US internet companies under legal orders — targeted collection from identified platforms. "Upstream" collection, also disclosed by Snowden, involved tapping the internet backbone cables directly, similar to Room 641A. Both operated under Section 702 but through different technical mechanisms. PRISM required company compliance; upstream collection tapped the physical infrastructure.
What happened to Edward Snowden?
Sources
Show 10 more sources
Further Reading
- documentaryCitizenfour (documentary) — Laura Poitras (2014)
- bookNo Place to Hide: Edward Snowden, the NSA, and the U.S. Surveillance State — Glenn Greenwald (2014)
- documentaryCitizenfour — Laura Poitras (director) (2014)
- bookPermanent Record — Edward Snowden (2019)
- bookDark Mirror: Edward Snowden and the American Surveillance State — Barton Gellman (2020)