midpage
Sign in to see your projects.
149 F. Supp. 3d 39
D.D.C.
2015
Read the full case

Background

  • TRAC (Long and Burnham) submitted seven FOIA requests (2010–2013) to ICE and CBP seeking EID and IIDS database documentation: table/field listings, code/lookup tables, database schema, DBMS/version, and copies/info about periodic "snapshots" (extracts) of EID data.
  • ICE searched its System Lifecycle Management (SLM) repository, produced 97 pages (some redacted), and withheld other records invoking FOIA Exemptions 3, 7(A), and 7(E); CBP did not search for some requests.
  • ICE declined to produce full snapshot copies, asserting they do not retain readily reproducible extract files, lack the technology to produce/redact full snapshots, and production would be unduly burdensome and costly.
  • Plaintiffs challenged the adequacy of searches and the applicability of asserted exemptions, and submitted expert declarations disputing ICE’s technical claims about reproducibility, redaction burden, and cyber-risk.
  • District court granted in part and denied in part cross-motions for summary judgment: upheld adequacy of ICE’s search of SLM for metadata/schema and upheld nonproduction of full snapshots as unduly burdensome; but rejected defendants’ 7(E)/7(A) showing that disclosure would reasonably risk circumvention (SQL injection) and denied Exemption 3 claim under the Federal Information Security/Modernization Act.
  • Court allowed ICE 30 days to supplement the record with additional evidence about (1) cyber-risk from disclosure of metadata/schema (to support Exemption 7 claims) and (2) the search undertaken for Request III (records identifying snapshots/extracts).

Issues

Issue Plaintiff's Argument Defendant's Argument Held
Whether EID/IIDS metadata and schema are exempt under FOIA Exemption 7(E) (risk of circumvention) Metadata/schema are administrative, not law-enforcement techniques; disclosure won’t reasonably risk circumvention Metadata/schema are law‑enforcement guidelines/techniques; disclosure would facilitate SQL injection or other cyber-attacks enabling database compromise Denied summary judgment for defendants on 7(E) (and 7(A)); court found agency’s showing on cyber-risk (SQL injection) insufficient on current record and allowed agency to supplement evidence
Whether Exemption 3 (statutory withholding under FISMA/Modernization Act) authorizes non-disclosure Plaintiffs: Modernization Act does not exempt these records from FOIA Defendants: security statute precludes disclosure Denied: Modernization Act does not specifically cite FOIA Exemption 3 and does not displace FOIA obligations; Exemption 3 not available here
Whether ICE/CBP must produce full EID "snapshots" (extracts) requested (readily reproducible/redactable) Plaintiffs: snapshots are readily reproducible and redactable with standard DBMS tools; ICE previously produced redacted extracts Defendants: no tangible extract files exist; producing/redacting full snapshots would impose undue burden/cost and require new contracts/technology Granted for defendants: court accepted agency affidavits that production/redaction is unduly burdensome and accorded them substantial weight; no discovery allowed to probe further
Adequacy of agency searches (particularly for Request III and for metadata/schema) Plaintiffs: searches were inadequate — ICE didn’t search the live EID/IIDS databases or CBP systems and didn’t show search for snapshot-identification records (Request III) Defendants: searched SLM repository (authoritative source for technical docs) and need not search every system; CBP requests largely moot given snapshot ruling Mixed: search of SLM for metadata/schema held adequate; agency must supplement and describe search efforts for Request III (court denied summary judgment on adequacy for Request III)

Key Cases Cited

  • Anderson v. Liberty Lobby, 477 U.S. 242 (summary judgment standard)
  • NLRB v. Robbins Tire & Rubber Co., 437 U.S. 214 (FOIA purpose: informed citizenry)
  • SafeCard Servs., Inc. v. SEC, 926 F.2d 1197 (agency affidavits in FOIA summary judgment)
  • Oglesby v. U.S. Dep't of the Army, 920 F.2d 57 (search must be reasonably calculated; agency affidavit requirement)
  • Blackwell v. FBI, 646 F.3d 37 (law-enforcement database methods and organization may be protected under Exemption 7(E))
  • Mayer Brown LLP v. IRS, 562 F.3d 1190 (standard for risk-of-circumvention under 7(E))
  • Pub. Emps. for Envtl. Responsibility v. U.S. Section, Int'l Boundary & Water Comm'n, 740 F.3d 195 (low bar for establishing risk under 7(E))
  • Weisberg v. DOJ, 745 F.2d 1476 (reasonableness standard for search)
Read the full case

Case Details

Case Name: Long v. Immigration and Customs Enforcement
Court Name: District Court, District of Columbia
Date Published: Dec 14, 2015
Citations: 149 F. Supp. 3d 39; 2015 U.S. Dist. LEXIS 166612; 2015 WL 8751005; Civil Action No. 2014-0109
Docket Number: Civil Action No. 2014-0109
Court Abbreviation: D.D.C.
Log In