23 F. Supp. 3d 234
S.D.N.Y.2014Background
- Zhu was indicted on multiple counts including honest services fraud, bribery conspiracies, and falsification of records stemming from NIH-funded NYU research.
- Zhu, an MRI expert at NYU, used a laptop funded by NIH; NYU owned grant assets and equipment, including the laptop.
- Zhu encrypted the laptop and used passwords; he did not share passwords and kept it at home, not leaving it unlocked in the office.
- NYU later permitted FBI access to the laptop via a consent-to-search signed by NYU General Counsel; FBI decrypted and searched the device without a warrant.
- Zhu had signed documents before employment acknowledging NYU's right to inspect NYU-owned computers and personal work computers for policy compliance; staff handbook policies warned of no privacy in NYU computers, but Zhu was faculty, not staff.
- The court denied Zhu’s suppression motion, holding NYU’s consent was valid and the Fourth Amendment was not violated.
Issues
| Issue | Plaintiff's Argument | Defendant's Argument | Held |
|---|---|---|---|
| Did Zhu have a reasonable expectation of privacy in the laptop’s contents? | Zhu had encrypted, password-protected data and exclusive control, negating a reasonable expectation of privacy. | Zhu’s encryption and home use still supported privacy; NYU policies did not eliminate privacy for a private employer search. | Yes, Zhu had a reasonable expectation of privacy. |
| Was NYU's third-party consent valid to authorize the FBI search? | NYU could not consent because Zhu controlled access via passwords and encryption; consent requires access to the area searched. | NYU had legal access to the laptop via Zhu’s authorization to inspect for policy compliance and NYU ownership of the device. | Yes, NYU’s consent was valid. |
| Did NYU have effective authority over Zhu’s laptop to give third-party consent? | NYU lacked common authority because Zhu controlled the device with passwords and encryption. | NYU owned the laptop, had a substantial interest, and Zhu authorized inspection, giving NYU permission to access. | Yes, NYU had both access and authority under Davis/Matlock standards. |
Key Cases Cited
- O’Connor v. Ortega, 480 U.S. 709 (1987) (employee privacy in the workplace; distinction between government employer vs. police search)
- Mancusi v. DeForte, 392 U.S. 364 (1968) (private office privacy vs. government search; reasonable expectation of privacy)
- Matlock, 415 U.S. 164 (1974) (common authority for third-party consent; joint access and control)
- Davis, 967 F.2d 84 (1992) (two-part test for third-party consent: access and authority/substantial interest/permission)
- Buettner-Janusch, 646 F.2d 759 (2d Cir. 1981) (consent burden and validity of third-party consent evidence)
- Ziegler, 474 F.3d 1184 (9th Cir. 2007) (privacy expectations in password-protected work computers)
- Leventhal v. Knapek, 266 F.3d 64 (2001) (privacy in office computer where not notified of no expectation of privacy)
- Angevine, 281 F.3d 1130 (10th Cir. 2002) (employer computer-monitoring policy and privacy expectations)
- Simons, 206 F.3d 392 (4th Cir. 2000) (CIA searches and privacy expectations for government employees)
- Ehrlich v. Town of Glastonbury, 348 F.3d 68 (2d Cir. 2003) (access must be considered beyond mere physical possession)
