Social media and remote computing service providers requirement to report to the attorney general
SF5120 would create a new reporting regime for social media platforms and remote computing service providers when they have actual knowledge, or in some cases a reasonable belief, that certain drug-related crimes are occurring on their services. The bill focuses on fentanyl, methamphetamine, counterfeit substances, and unauthorized prescription pain medications or stimulants. Providers would be required to submit reports to the attorney general within 60 days when they have actual knowledge of such crimes, and they could also submit reports based on reasonable belief.
The required report would include account and identifying information such as names, addresses, email addresses, account IDs, IP addresses, screen names, and other identifying details. Providers could also include related content, metadata, timestamps, location information, and communications tied to the suspected crime. The bill expressly says it does not require providers to monitor users, scan content, or decrypt encrypted communications, and it does not require them to use or abandon end-to-end encryption. It also exempts broadband internet access service and text messaging services from the reporting duty.
The bill would add new sections to Minnesota Statutes chapter 325M, creating duties for providers, new responsibilities for the attorney general, preservation requirements, and civil penalties. It would require the attorney general to review reports, decide whether to investigate further, share reports with law enforcement when appropriate, minimize and delete data when no longer needed, and publish annual reporting statistics. It would also create a 90-day preservation framework for reported content and related data, with limits on extensions and notice rules to users. Providers that fail to report or submit deficient reports could face substantial civil penalties, while good-faith reporters would receive immunity from liability unless they knowingly submit false information.
The bill text and available context do not include committee testimony or recorded votes, so there is no documented legislative debate to gauge support or opposition. Based on the structure of the bill, its stated purpose is enforcement-oriented and aimed at combating online drug trafficking, suggesting a public-safety rationale. At the same time, the bill includes privacy and encryption protections, which indicates an effort to address likely concerns from technology and civil-liberties stakeholders.
The main points of contention are likely to be the scope of provider obligations, the privacy implications of mandatory reporting, and whether the bill could pressure platforms to increase monitoring of user activity. The bill tries to limit that concern by prohibiting affirmative monitoring, content scanning, and decryption requirements, but it still requires providers to report when they have actual knowledge and allows reports based on reasonable belief. Another likely issue is the breadth of the information that can be reported and preserved, including account identifiers, IP addresses, and communications, as well as the significant civil penalties for noncompliance. Technology companies, privacy advocates, and encryption supporters would likely focus on those concerns, while law enforcement and proponents of drug enforcement would likely support the reporting and preservation tools.