United States v. Graham
The Fourth Circuit's major pre-Carpenter en banc decision holding that government acquisition of historical cell-site location information from Sprint/Nextel under Stored Communications Act § 2703(d) orders did not violate the Fourth Amendment— a ruling later displaced for Carpenter-covered CSLI by the Supreme Court's modern location-privacy doctrine.
Executive Summary
Aaron Graham and Eric Jordan were prosecuted for participating in a series of armed robberies in the Baltimore area. During the investigation, federal agents obtained historical cell-site location information from Sprint/Nextel using court orders under 18 U.S.C. § 2703(d), rather than search warrants supported by probable cause. The records spanned 221 days for each defendant and included nearly 30,000 location data points per person. A divided Fourth Circuit panel initially held that obtaining the records without a warrant violated the Fourth Amendment, though it affirmed the convictions under the good-faith exception. The Fourth Circuit granted rehearing en banc, vacated the panel opinion, and reversed the constitutional holding. The en banc majority treated the CSLI as non-content provider business records voluntarily exposed to Sprint/Nextel in the ordinary course of cellular service. Applying Smith v. Maryland and United States v. Miller, it held that the government could obtain the records under § 2703(d) without conducting a Fourth Amendment search. Judge Wynn dissented from that constitutional conclusion, emphasizing that users do not meaningfully volunteer CSLI and that 221 days of location data revealed a substantial record of movements. Two years later, Carpenter v. United States adopted the central premise rejected by Graham's en banc majority: sufficiently revealing historical CSLI remains protected despite being held by a cellular provider.
United States v. Graham is one of the most important pre-Carpenter location cases because the facts made the privacy issue unusually stark. The government obtained seven months of records covering tens of thousands of call and text events for each defendant.
The en banc majority nevertheless viewed quantity as irrelevant once the third-party doctrine applied. If the defendants had exposed each data point to Sprint/Nextel, the majority reasoned, collecting many such points did not transform the records into protected information.
Judge Wynn's dissent took the opposite view. He argued that cell users do not affirmatively convey location information in the way a caller dials a telephone number, and that even less precise location points can become deeply revealing when accumulated over many months. That reasoning closely anticipated Carpenter.
Key Holdings at a Glance
Facts and Investigation
Graham and Jordan were convicted of offenses arising from a series of armed robberies. The government used historical CSLI to place their phones in the vicinity of robbery locations at relevant times.
Sprint/Nextel generated the records as part of its ordinary network operations. The data identified the cell tower used when defendants made or received calls or sent or received text messages.
The records also identified sectors associated with the cell sites, permitting location estimates more refined than the tower location alone.
The government did not install a tracking device or intercept radio signals directly. Instead, it compelled Sprint/Nextel to disclose records already maintained by the carrier.
What the Historical CSLI Revealed
The records identified the cell tower and sector associated with phone activity. The record indicated that sites in the case could cover circular areas with radii up to approximately two miles, with sectors representing roughly one-third slices of those coverage areas.
The majority emphasized that the records were less precise than GPS and did not necessarily place a phone at a specific house or room.
The dissent emphasized something different: precision is only one dimension of privacy. Even neighborhood-level information can become revealing when government possesses thousands of data points accumulated over seven months.
The Stored Communications Act and § 2703(d)
The Stored Communications Act allowed government to seek specified non-content provider records through a § 2703(d) order upon a showing of specific and articulable facts giving reasonable grounds to believe the records were relevant and material to an ongoing criminal investigation.
That standard was below probable cause.
Graham and Jordan did not principally argue that the government had failed to satisfy the statutory standard. Their claim was constitutional: § 2703(d) could not authorize the government to obtain this volume of historical location information if the Fourth Amendment required a warrant.
The 2015 Panel Decision
A divided Fourth Circuit panel initially held that the government's acquisition of the historical CSLI without a warrant violated the Fourth Amendment.
The panel majority reasoned that long-term cell-site information revealed sensitive location information and that a person did not surrender all privacy merely because the carrier generated and stored the records.
The panel nevertheless affirmed the convictions because officers had acted in good-faith reliance on the Stored Communications Act and then-existing law.
When the Fourth Circuit granted rehearing en banc, the panel opinion was vacated.
The En Banc Majority
Judge Motz's majority opinion framed the challenged government action narrowly: government obtained historical records from Sprint/Nextel rather than directly tracking the defendants.
That framing allowed the court to distinguish GPS and sensor cases such as Jones, Karo, and Kyllo. Those cases involved direct governmental acquisition of information through tracking or sense-enhancing technology. Graham, the majority said, involved compelled production of a third party's preexisting business records.
The court then applied Smith and Miller.
Each time defendants used their phones for calls or texts, Sprint/Nextel's equipment generated records of the cell sites used. Because the carrier needed those records to route communications and operate its network, the majority viewed the information as exposed to the provider in the ordinary course of business.
The Third-Party Doctrine
The majority treated the third-party doctrine as categorical once voluntary disclosure occurred.
Under Smith, a person who voluntarily conveys information to a telephone company assumes the risk that the company may disclose it to government. Under Miller, records exposed to a bank in the course of financial transactions are similarly outside the customer's Fourth Amendment protection.
Graham extended that logic to historical CSLI.
| Case | Record | Pre-Carpenter Theory |
|---|---|---|
| Smith v. Maryland | Dialed telephone numbers | Voluntarily exposed to carrier |
| United States v. Miller | Bank transaction records | Third-party business records |
| United States v. Graham | Historical CSLI | Carrier business records outside Fourth Amendment |
| Carpenter v. United States | Historical CSLI | Third-party possession does not eliminate privacy |
Content Versus Non-Content Information
The majority emphasized that historical CSLI was non-content routing information rather than the contents of phone calls or text messages.
It analogized cell-site data to routing information needed to complete a communication. The provider used cell towers to transmit calls and messages; the tower record reflected that routing function.
The distinction was important to the majority, but later cases demonstrate that "non-content" is not itself a constitutional conclusion. Historical location information can be extraordinarily revealing even though it is not the content of a communication.
Judge Wilkinson's Concurrence
Judge Wilkinson joined the majority and wrote separately to emphasize institutional concerns.
He argued that Congress had created a detailed statutory framework in the Stored Communications Act to regulate government access to provider-held information and that courts should be cautious about displacing legislative judgments without clear constitutional direction.
His concurrence recognized that technological change creates substantial privacy concerns, but viewed Congress as an important participant in setting rules for access to digital records.
Judge Wynn's Dissent
Judge Wynn, joined by Judges Floyd and Thacker, agreed that the convictions should be affirmed under the good-faith exception but rejected the majority's constitutional holding.
CSLI Is Not Meaningfully Voluntary
A cell-phone user does not manually choose which tower serves a call. The network makes that decision automatically. In the dissent's view, turning on and using a phone does not amount to meaningful voluntary disclosure of a detailed location history.
Quantity Changes the Privacy Impact
The dissent emphasized the massive record at issue: 221 days and tens of thousands of location points per defendant.
Location Data Reveals Patterns
Even if each individual cell-site record was less precise than GPS, accumulated records could reveal recurring locations, movements, routines, associations, and other highly personal facts.
Jones Was a Warning
Judge Wynn drew on the concurring opinions in United States v. Jones, where five Justices expressed concern about the privacy consequences of prolonged location monitoring.
Quantity, Aggregation, and the Mosaic Problem
Graham presented a direct conflict over whether constitutionally unprotected data can become protected when government aggregates enough of it.
The majority rejected that approach within third-party doctrine. Once information had been voluntarily exposed to Sprint/Nextel, the majority saw no principled basis for making the first day unprotected but the 221st day protected.
The dissent viewed aggregation as essential. A single location observation may reveal little. Tens of thousands of observations can reconstruct a life.
Carpenter later embraced that broader understanding of digital location privacy. The Supreme Court emphasized the depth, breadth, and retrospective power of historical CSLI rather than viewing each record in isolation.
Carpenter v. United States Superseded Graham's Core Rule
In 2018, the Supreme Court held that government acquisition of historical CSLI in Carpenter was a Fourth Amendment search.
The Court rejected the premise that Smith and Miller automatically controlled merely because wireless carriers possessed the records.
Several factors mattered:
- historical CSLI creates a retrospective chronicle of physical movement;
- cell phones are carried almost continuously;
- location records are automatically generated as part of ordinary phone use;
- the records can reach backward in time; and
- provider possession does not eliminate the user's privacy interest in that digital history.
| Question | Graham (2016) | Carpenter (2018) |
|---|---|---|
| Does carrier possession defeat privacy? | Yes, under traditional third-party doctrine | No, not categorically for historical CSLI |
| Is CSLI voluntarily conveyed? | Yes, through ordinary phone use | Not meaningfully in the Smith sense |
| Does quantity matter? | Not once third-party doctrine applies | Yes; longitudinal depth is constitutionally significant |
| Legal process | § 2703(d) order sufficient | Warrant generally required for covered historical CSLI |
Graham, Carpenter, and Chatrie
The Supreme Court's 2026 decision in Chatrie v. United States further develops the modern law of provider-held location data.
Chatrie addressed a geofence warrant seeking Google Location History data associated with devices located within a specified geographic area during a specified period.
The Court vacated the Fourth Circuit's judgment and remanded after concluding that the execution of the geofence warrant violated the Fourth Amendment. The decision reinforces the principle that provider possession does not permit courts to ignore the sensitivity, scope, and search mechanics of digital location records.
Carpenter: historical CSLI can remain constitutionally protected despite third-party possession.
Chatrie: modern location-data collection must also satisfy Fourth Amendment limits on the manner and scope of digital location searching.
What Graham Means Today
Graham remains valuable for understanding the history of third-party doctrine and pre-Carpenter location law. It is not a sound basis for warrantless acquisition of ordinary historical CSLI falling within Carpenter.
Carpenter itself described its holding as narrow. Several categories still require technology- and jurisdiction-specific analysis, including:
- very short-duration historical CSLI;
- real-time CSLI;
- tower dumps;
- cell-site simulators;
- emergency provider disclosures;
- consent-based location access;
- other application-generated location records; and
- location evidence obtained from non-carrier technologies.
Graham, AI, and Location Analytics
Graham is particularly useful for understanding how modern analytics can change the meaning of raw location records.
Pattern-of-Life Analysis
AI can identify likely home, work, routines, recurring travel, and anomalies from historical location data.
Association Analysis
Systems can identify devices that repeatedly appear near one another, creating inferred social or organizational relationships.
Route Reconstruction
Software can interpolate likely movement paths between discrete cell-site events, but those routes are analytical inferences—not direct carrier measurements.
Cross-Dataset Fusion
CSLI may be combined with ALPR, Google Location History, financial transactions, camera detections, and communications metadata.
Precision Inflation
Maps and dashboards can visually imply greater precision than the underlying cell-site records justify. Analysts should clearly distinguish observed tower associations from inferred locations.
Technology in 2026
The technological assumptions in Graham are increasingly dated even though the case remains doctrinally instructive.
Denser Networks
Modern network architecture can produce different kinds and degrees of location precision than legacy macro-cell systems. Investigators should not rely on generic statements about cell-tower accuracy.
Location Data Is Multi-Source
A single investigation may include carrier CSLI, geofence information, app telemetry, Wi-Fi associations, Bluetooth encounters, vehicle records, ALPR, and advertising-location data.
Aggregation Is Nearly Frictionless
The practical obstacle to analyzing tens of thousands of records has largely disappeared. Software can organize months of movement data almost instantly—the very aggregation concern emphasized by Graham's dissent and Carpenter.
Reverse Location Searching Is a Separate Problem
Traditional CSLI investigations begin with an identified account and seek that person's records. Geofence warrants begin with a place and time and seek to identify unknown devices. Chatrie makes clear that those architectures raise additional Fourth Amendment concerns.
AI Can Produce New Facts
Modern platforms do not merely display records. They infer patterns, identities, associations, and likely routes. Those conclusions should be treated as analytical products requiring validation rather than raw facts from the carrier.
Practical Guidance for Law Enforcement Agencies
1. Use Warrants for Carpenter-Covered Historical CSLI
Do not rely on Graham's en banc no-search holding for ordinary retrospective CSLI within Carpenter's rule.
2. Identify the Exact Location Technology
State whether the request concerns historical CSLI, real-time CSLI, app location, geofence records, tower dumps, GPS, or another source.
3. Define the Time Period
Longer periods can materially increase privacy impact and should be tied to probable cause.
4. Explain Technical Precision
Affidavits and testimony should avoid implying GPS precision where the records show only tower and sector association.
5. Preserve Provider Documentation
Keep field definitions, tower lists, sector maps, timestamps, certifications, and production documentation.
6. Separate Raw Records From Inference
A carrier record showing a tower/sector connection is not the same thing as a software- generated route or point estimate.
7. Treat Emergency Access Separately
Emergency disclosure and exigent circumstances require independent documentation and analysis.
8. Govern Cross-Dataset Fusion
Document the authority and purpose for combining CSLI with ALPR, geofence, financial, or camera records.
9. Audit AI Analysis
Maintain logs showing what data was ingested, what algorithms were used, and what conclusions were generated.
10. Check State Law
State constitutions and electronic-privacy statutes may provide greater protection than federal doctrine.
Historical CSLI Investigative Checklist
| Question | Why It Matters |
|---|---|
| What exact records are sought? | Location technologies differ in constitutional treatment. |
| What period is requested? | Duration affects privacy and nexus. |
| What carrier holds the records? | Data fields and architecture vary by provider. |
| What does each field actually mean? | Necessary for accurate location interpretation. |
| Does Carpenter apply? | Covered historical CSLI generally requires a warrant. |
| Is the request a reverse-location search? | Chatrie raises additional architecture and particularity concerns. |
| What level of precision is supported? | Avoid overstating tower-based location evidence. |
| Will AI infer routes or patterns? | Distinguish raw facts from derived conclusions. |
| Will data be combined with other surveillance? | Aggregation can substantially increase informational depth. |
| Is an emergency exception asserted? | Document the factual basis separately. |
| Does state law provide greater protection? | Federal law may be only the floor. |
Litigation Checklist for Agency Counsel and Prosecutors
- Identify the precise provider records obtained.
- Establish the dates and duration of collection.
- Identify the legal process used.
- Do not cite Graham's vacated 2015 panel as controlling precedent.
- Do not rely on Graham's 2016 no-search holding where Carpenter governs.
- Develop technical evidence regarding tower, sector, and record precision.
- Separate raw location data from analyst or AI inference.
- Analyze emergency, consent, or other exceptions independently.
- Address Chatrie if the search architecture is reverse-location or geofence based.
- Preserve provider returns, affidavits, warrants, orders, maps, and analytical files.
- Check state constitutional authority.
- Analyze good faith separately if historical pre-Carpenter acquisition is litigated.
Frequently Asked Questions
What did the Fourth Circuit hold in United States v. Graham?
Sitting en banc in 2016, the Fourth Circuit held that obtaining historical CSLI from Sprint/Nextel under § 2703(d) orders did not violate the Fourth Amendment because the records fell within Smith and Miller's third-party doctrine.
How much location data did the government obtain?
The record involved 221 days for each defendant. Judge Wynn's dissent identified 29,659 location data points for Graham and 28,410 for Jordan.
Was there an earlier panel ruling?
Yes. A divided panel held that warrantless acquisition violated the Fourth Amendment but applied the good-faith exception. That panel opinion was vacated when the court granted rehearing en banc.
Is Graham still the current rule for historical CSLI?
No, not where Carpenter applies. Carpenter held that government acquisition of sufficiently revealing historical CSLI is a Fourth Amendment search generally requiring a warrant.
Why did the Graham majority reject the privacy claim?
It viewed CSLI as non-content business records generated by Sprint/Nextel and exposed to the carrier through ordinary use of cellular service.
What did Judge Wynn argue?
He argued that CSLI is not meaningfully volunteered and that seven months of location records reveal sensitive patterns of movement. That reasoning anticipated Carpenter.
Does precision determine whether location data is protected?
No single precision rule controls. Carpenter emphasizes the revealing nature of longitudinal digital location data, while technology and jurisdiction matter for categories outside its express holding.
How does Chatrie relate to Graham?
Chatrie addresses a different location-search architecture—geofence warrants—but reinforces the modern rule that provider possession does not end the Fourth Amendment inquiry.
Why is Graham worth keeping in the Case Law Center?
It shows the exact doctrinal conflict that existed immediately before Carpenter and provides an unusually strong discussion of aggregation, provider records, quantity, and the third-party doctrine.
Primary Authorities
Official Fourth Circuit en banc opinion.
Read the official Graham opinion
Official Supreme Court opinion governing historical CSLI within its holding.
Read the official Carpenter opinion
Supreme Court decision addressing execution of a geofence warrant and modern digital location searching.
View Supreme Court October Term 2025 opinions
Final Assessment
Graham is the strongest possible pre-Carpenter illustration of the limits of a mechanical third-party doctrine.
The en banc majority had a coherent doctrinal argument: Sprint/Nextel generated the records, defendants exposed routing information to the carrier, and Smith and Miller told lower courts that voluntarily disclosed third-party records were not protected. From that premise, quantity did not matter.
But Graham's dissent identified what traditional doctrine missed. A modern phone can generate tens of thousands of location observations without a user consciously disclosing each one. When government acquires those records in bulk, it can reconstruct movement on a scale that bears little resemblance to the limited telephone and bank records in the old cases.
Carpenter resolved that conflict in favor of the technology-sensitive approach. Chatrie now pushes the inquiry further by examining not only whether location information is private, but also how reverse-location searches identify people through large provider datasets.