The United States is poised on the verge of implementing new regulations for digital assets, spurred by bipartisan momentum to modernize our financial landscape. Amid discussions of innovation and global competitiveness, one critical concern has been alarmingly overlooked: financial privacy. As we craft the digital framework of the 21st century, it’s essential to consider not merely what is feasible, but what is ethically acceptable. This involves addressing the expanding surveillance powers ingrained in our financial system, enabling the tracking of almost every transaction without the necessity of a warrant.
Many Americans might associate financial surveillance with oppressive regimes, yet the reality in the U.S. is starkly similar. Thanks to the Bank Secrecy Act (BSA), enacted during the Nixon administration, and the digitization of finance over the last fifty years, our financial privacy faces an unprecedented threat. Most citizens are unaware that they live under an expansive surveillance regime that potentially undermines their constitutional rights. Every transaction—from a small Venmo payment for morning coffee to hefty hospital bills—adds to a digital trail that watches over us, even when we haven’t committed any wrongdoing.
As a former federal prosecutor, I maintain a strong commitment to equipping law enforcement with the necessary tools to ensure public safety. However, the current paradigm does not enhance safety. Instead, it fosters a false sense of security while systematically eroding the constitutional freedoms of countless Americans.
When Congress enacted the BSA in 1970, the financial environment was vastly different. Cash transactions dominated, and organized crime was the primary focus. The law imposed a framework whereby banks must retain specific customer records and release them to law enforcement upon request. Unlike a warranted search, which necessitates a judge’s approval based on probable cause, this power operates without checks or balances. Prosecutors can simply demand years of banking records via a subpoena, bypassing judicial oversight entirely. Consequently, the burden of this invasive practice rests wholly on the banking institutions.
In the landmark case United States v. Miller (1976), the Supreme Court upheld the BSA, asserting that citizens have no “legitimate expectation of privacy” regarding information shared with third parties like banks. This ruling laid the groundwork for the third-party doctrine, which permits law enforcement access to financial records without a warrant. Over the years, the BSA has undergone several amendments—most notably in 2001 as part of the Patriot Act—compounding the record-keeping obligations imposed on an ever-growing array of financial institutions. Today, these rules nearly enclose the lives of everyday Americans.
Back in the 1970s, when the BSA was born, banking and non-cash payments were largely conducted through physical methods such as writing checks, visiting bank branches, and utilizing passbooks. Cash transactions exceeding $10,000 required reporting—an amount that has remained unchanged and unadjusted for inflation for decades. In contrast, today’s consumers engage in various banking transactions daily, with only approximately 16% conducted with cash. This significant shift has rendered the original provisions of the BSA increasingly outmoded.
The advancement of technology has further amplified the scope of financial data collection. Coupled with extensive personal information collected from technological platforms—ranging from location history to communication metadata—the intrusive nature of financial surveillance converges with nearly every facet of an individual’s identity, movements, and behaviors.
Curiously, the BSA doesn’t seem to accomplish its primary objective of deterring crime effectively. In the fiscal year 2024, financial institutions submitted approximately 4.7 million Suspicious Activity Reports (SARs) alongside over 20 million currency transaction reports. Rather than hindering significant criminal activity, the system inundates law enforcement with a deluge of low-quality information, clouding their ability to identify credible threats. Mass surveillance often diminishes effectiveness by overwhelming agents with irrelevant data. While it fails to deter hackers, the BSA ensures a repository of permanent information on every individual.
Moreover, the incentives underpinning the BSA are misaligned. Financial institutions must report any vaguely suspicious activity to shield themselves from potential liability. The repercussions for failing to submit a SAR can be severe, even resulting in indictment. Conversely, these institutions bear no consequences for submitting excessive reports. As a result, the overwhelming accumulation of data becomes a natural outcome of the current regulatory framework. The practices instituted under the BSA necessitate clearer boundaries, enabling executive branch officials to responsibly delegate surveillance responsibilities to private entities.
Inspired by: Source

