Legal & Policy

How to Read a Transparency Report

July 31, 2026 9 min read Haven Team

Twice a year, most large providers publish a document full of tables counting government demands for user data. Coverage of these reports usually extracts one number, notes whether it went up or down, and moves on. That number aggregates several legal instruments that differ enormously in what they can reach and how much scrutiny they receive, which makes the total the least informative figure on the page.


Reading one properly takes about ten minutes and tells you something real about a service you rely on. Here is what the columns mean.

Three tiers of process, three depths of access

In the United States, most demands to a provider are structured by the Stored Communications Act, part of the Electronic Communications Privacy Act. It sorts what the government can obtain into tiers, and the tier determines how hard the demand is to get.

Instrument What it reaches Who approves it
Subpoena Basic subscriber information: name, account details, session times, addresses used at signup and login, means of payment Issued by a prosecutor or agency; no judge required
Court order (2703(d)) Non-content records: who you communicated with and when, device and network records A judge, on a standard lower than probable cause
Search warrant Content: message bodies, attachments, stored files A judge, on probable cause

A report that breaks its numbers out this way is telling you something. A report that publishes one combined "legal requests" figure is telling you considerably less, because a thousand subpoenas for signup addresses and a thousand content warrants describe completely different relationships between a service and the state.

This is also where end-to-end encryption becomes visible in the numbers. A provider that cannot read message contents can still be served a content warrant. It will comply, and hand over ciphertext. Look for whether the report distinguishes "requests where data was produced" from "requests where the produced data was encrypted and unreadable," because several providers do make that distinction and it is the most concrete evidence a report can offer about an architectural claim.

Non-content is doing more work than the word suggests

The middle tier is easy to skim past. It sounds procedural. It is not.

Non-content records are the metadata layer: who spoke to whom, at what times, from which addresses, on which devices, for how long. A complete set of those records over a year describes a person's associations, routines, movements and relationships with a precision that message contents often do not reach.

The Supreme Court acknowledged as much in Carpenter v. United States in 2018, holding that acquiring historical cell-site location records requires a warrant despite those records being held by a third party and counting as non-content by the older classification. That decision was narrow on its face and left most of the third-party doctrine intact, but it established that some categories of non-content data are sensitive enough to need real judicial protection.

Reading tip

Compare the count of requests against the count of accounts specified. One order can name hundreds of accounts. A report that publishes only requests, and never accounts, cannot be used to estimate how many users were affected, and the gap between the two figures is often an order of magnitude.

Why some cells are ranges instead of numbers

National security demands appear in a separate section and they will not be exact. National Security Letters and orders from the Foreign Intelligence Surveillance Court come with statutory limits on what a recipient may say about them. The USA FREEDOM Act of 2015 settled a compromise: providers may report these in bands rather than exact counts, and reporting on some categories is delayed by months.

Two consequences follow, and both are commonly misread.

First, a band beginning at zero cannot be read as confirmation that anything happened. "0 to some upper bound" is the smallest disclosure the law permits, and a provider that received nothing at all reports the same band as a provider that received a handful. Second, the delay means the national security section describes an older period than the criminal section on the same page. Comparing them as though they cover the same months produces nonsense.

This banding is precisely the constraint that warrant canaries were invented to work around, with all the fragility that idea carries. It is also why National Security Letters and Section 702 collection deserve to be understood on their own terms rather than through the report's summary line.

The row with no judge in it

Buried below the main tables, most reports carry a line for emergency disclosure requests. Under 18 U.S.C. § 2702(b)(8), a provider may voluntarily hand over user data, including content, if it believes in good faith that an emergency involving danger of death or serious physical injury requires it.

No court order exists. No judge reviews it. The decision to disclose is made by the provider's own team, usually under time pressure, on the strength of an assertion from someone claiming to be law enforcement.

That last clause is not hypothetical. In 2022, reporting by Bloomberg and by Krebs on Security documented criminals compromising law enforcement email accounts and using them to send forged emergency requests to major platforms, which responded with user data. The mechanism is designed to be fast, and speed and verification pull against each other.

When you read a report, find this number, and find out whether the provider publishes anything about how it authenticates the requester. The number itself matters less than whether the company has thought publicly about the failure mode.

What a transparency report structurally cannot tell you

Four things are missing from every report, no matter how well produced.

Which is the practical takeaway. A transparency report measures how often a provider was asked and how often it complied. It cannot measure the thing that actually determines your exposure, which is how much there was to ask for. A retention policy and a data minimisation practice do more to bound the worst case than a compliance rate ever will, and unlike request counts they are verifiable against the product itself rather than against a self-published table.

Read the report. Then go read the retention policy, which is usually shorter and almost always more revealing.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →