Take-Aways (AI)
  • US sur­veil­lan­ce law (Sec­tion 702) allo­ws mass access to cloud data wit­hout a tra­di­tio­nal search warrant.
  • CLOUD Act and SCA force pro­vi­ders to hand over even extra­ter­ri­to­ri­al data; legal pro­tec­tion for for­eig­ners remains limited.
  • RISAA 2024 mas­si­ve­ly expands the defi­ni­ti­on of obli­ga­ted ser­vice pro­vi­ders, cove­ring many non-tra­di­tio­nal providers.
  • The decisi­ve fac­tor is con­trol over data, not ser­ver loca­ti­on; tech­ni­cal com­part­ment­a­lizati­on offers hard­ly any relia­ble pro­tec­tion against the obli­ga­ti­on to dis­c­lo­se data.

Are aut­ho­ri­ties, com­pa­nies and hol­ders of pro­fes­sio­nal secrets allo­wed to use cloud ser­vices from US pro­vi­ders, indi­rect­ly US-con­trol­led pro­vi­ders and other pro­vi­ders with a for­eign con­nec­tion? This que­sti­on has been on the agen­da for years, not only in Switz­er­land, but also in other count­ries – ulti­m­ate­ly sin­ce Edward Snow­den. For public bodies, the focus is on com­pli­ance with fun­da­men­tal rights and offi­ci­al sec­re­cy, while for pri­va­te indi­vi­du­als it is on pri­va­te data pro­tec­tion law and the que­sti­on of the con­di­ti­ons under which out­sour­cing to a cloud pro­vi­der is com­pa­ti­ble with pro­fes­sio­nal sec­re­cy. A chro­no­lo­gy of the cor­re­spon­ding dis­cus­sion we have published on daten­recht.

As is well known, the dis­cus­sion revol­ves pri­ma­ri­ly around the que­sti­on of which risks of access by aut­ho­ri­ties abroad may be accept­ed, whe­ther „accep­tance“ of the risk of such access is pro­hi­bi­ted at all or whe­ther such access must rather be accept­ed becau­se other risks for data sub­jects can be redu­ced through the use of cor­re­spon­ding cloud solu­ti­ons. This dis­cus­sion is one of Swiss fede­ral and can­to­nal law. Howe­ver, the law of the for­eign count­ries con­cer­ned, and the USA in par­ti­cu­lar, plays a signi­fi­cant role as a risk factor.

In this con­text, the Decem­ber 2025 Expert opi­ni­on made public through a free­dom of infor­ma­ti­on request inte­re­st­ing to read and an occa­si­on for a cor­re­spon­ding pre­sen­ta­ti­on. A per­son from the Uni­ver­si­ty of Colo­gne was com­mis­sio­ned by the Ger­man Fede­ral Mini­stry of the Inte­ri­or (BMI) to wri­te a legal opi­ni­on on the US legal situa­ti­on in March 2025. The report is curr­ent­ly only available in a redac­ted version.

Expert opi­ni­on assignment

The BMI asked three questions:

  1. What is the cur­rent legal situa­ti­on in the USA? Do US intel­li­gence ser­vices have a right of direct access to cloud infor­ma­ti­on and a right of dis­clo­sure vis-à-vis cloud providers?
  2. Are for­eign pro­vi­ders also sub­ject to US jurisdiction?
  3. Does such a right of access also exist if a US com­pa­ny estab­lishes a Ger­man sub­si­dia­ry under Ger­man law and ope­ra­tes the cloud on Ger­man territory?

The report ana­ly­zes the rele­vant US sur­veil­lan­ce law, essen­ti­al­ly with the fol­lo­wing fin­dings, some of which we have sup­ple­men­ted with addi­tio­nal infor­ma­ti­on or fur­ther references:

FISA

Sec­tion 702

Sec­tion 702 FISA (Tit­le VII) is the cen­tral regu­la­ti­on for the sur­veil­lan­ce of „non-US per­sons“ out­side the USA. It aut­ho­ri­zes US intel­li­gence agen­ci­es to coll­ect com­mu­ni­ca­ti­ons data from Elec­tro­nic Com­mu­ni­ca­ti­on Ser­vice Pro­vi­ders (ECSPs). The For­eign Intel­li­gence Sur­veil­lan­ce Court (FISC) only appro­ves the moni­to­ring para­me­ters annu­al­ly, not indi­vi­du­al tar­get persons.

Sec­tion 702 applies fac­tual­ly to All cloud ser­vice pro­vi­ders and data cen­ters Appli­ca­ti­on. The pro­ce­du­re is lar­ge­ly car­ri­ed out wit­hout com­pre­hen­si­ble judi­cial review; in prin­ci­ple, no judi­cial search war­rant is requi­red for the order.

Sec­tion 501/502

Sec­tion 501/502 FISA (Tit­le V), also Sec­tion 215 of the USA PATRIOT Act, aut­ho­ri­zed the FBI to app­ly to the FISC for orders to sur­ren­der „tan­gi­ble things“ (inclu­ding busi­ness records and docu­ments). This pro­vi­si­on was the basis for the NSA mass coll­ec­tion of tele­pho­ne meta­da­ta. The USA FREEDOM Act 2015 rest­ric­ted this „bulk coll­ec­tion“ and at the same time exten­ded the term of the pro­vi­si­on until March 2020.

Howe­ver, Sec­tion 501/502 expi­red in March 2020 and has sin­ce been not rene­wed. Accor­din­gly, the opi­ni­on sta­tes that Sec­tion 502 FISA is no lon­ger applicable.

Tit­le IV FISA

Tit­le IV FISA (Sec­tions 401 – 406) regu­la­tes the use of Pen Regi­sters and Trap-and-trace devices for intel­li­gence pur­po­ses. A Pen Regi­ster cap­tures „dia­l­ing, rou­ting, addres­sing, or signal­ing infor­ma­ti­on“ of out­go­ing com­mu­ni­ca­ti­on, a Trap-and-Trace Device the cor­re­spon­ding data of inco­ming com­mu­ni­ca­ti­on (18 U.S.C. § 3127). Both instru­ments expli­ci­t­ly do not record com­mu­ni­ca­ti­on con­tent, but only metadata.

The USA FREEDOM Act 2015 also pro­hi­bi­ted the bulk coll­ec­tion and has sin­ce deman­ded a spe­ci­fic sel­ec­tion term, i.e. a con­cre­te point of refe­rence such as a spe­ci­fic per­son, account or device. The hurd­le for a FISC order under Tit­le IV is lower than for sur­veil­lan­ce under Tit­le I (elec­tro­nic sur­veil­lan­ce with con­tent): It is suf­fi­ci­ent to cer­ti­fy that the infor­ma­ti­on is likely to be rele­vant for an ongo­ing inve­sti­ga­ti­on to pro­tect against inter­na­tio­nal ter­ro­rism or clan­de­sti­ne intel­li­gence activities.

Stored Com­mu­ni­ca­ti­ons Act & CLOUD Act

The Stored Com­mu­ni­ca­ti­ons Act (SCA) obli­ges pro­vi­ders of elec­tro­nic com­mu­ni­ca­ti­ons ser­vices and remo­te com­pu­ting ser­vices to dis­c­lo­se com­mu­ni­ca­ti­ons con­tent, docu­ments stored in clouds and meta­da­ta. With the amend­ment to the CLOUD Act of 2018 that this obli­ga­ti­on also applies to data stored out­side the USA (back­ground was the case United Sta­tes v. Micro­soft Corp., in which Micro­soft refu­sed to hand over emails stored in Ireland).

Legal pro­tec­tion

Legal pro­tec­tion against SCA orders is limi­t­ed under the CLOUD Act. Cover­ed ser­vice pro­vi­ders can chall­enge an order („moti­on to quash or modi­fy“, 18 U.S.C. § 2703(h)), if

  • the data sub­ject is not a US per­son and does not live in the USA,
  • the sur­ren­der of the right of a qua­li­fy­ing for­eign govern­ment would hurt, and
  • the court comes to the con­clu­si­on after a comi­ty ana­ly­sis (i.e. weig­hing up the con­flic­ting inte­rests) that the order should be lifted.

As qua­li­fy­ing for­eign govern­ment only one sta­te that has a trea­ty with the USA applies. Exe­cu­ti­ve Agree­ment to 18 U.S.C. § 2523 has con­clu­ded. Such exe­cu­ti­ve agree­ments initi­al­ly allow sim­pli­fi­ed mutu­al data access bet­ween law enforce­ment aut­ho­ri­ties and remo­ve the other­wi­se appli­ca­ble data pro­tec­tion regu­la­ti­ons. Blocking Sta­tu­tes (i.e. data sha­ring bans). To date, such agree­ments only exist with the United King­dom (in force sin­ce Octo­ber 2022) and Austra­lia (in force sin­ce Janu­ary 2024). Nego­tia­ti­ons are ongo­ing with the EU and Cana­da (BSA Tech­Post).

For Swiss com­pa­nies, this means that No spe­cial legal pro­tec­tion against orders under the SCA. A ser­vice pro­vi­der can also rai­se a comi­ty defen­se wit­hout an exe­cu­ti­ve agree­ment. com­mon law-basis (CLOUD Act § 103(c)), but whe­ther legal pro­tec­tion is gran­ted is at the broad dis­creti­on of the com­pe­tent US court. Switz­er­land would, howe­ver, also have to accept that US aut­ho­ri­ties could ser­ve resti­tu­ti­on orders direct­ly on Swiss CSPs, out­side the scope of mutu­al legal assi­stance. The Swiss Ban­kers Asso­cia­ti­on in par­ti­cu­lar is oppo­sed to such an agree­ment. skep­ti­cal about.

EO 12333

The Exe­cu­ti­ve Order 12333 then aut­ho­ri­zes US intel­li­gence agen­ci­es to coll­ect intel­li­gence-rele­vant infor­ma­ti­on abroad. The coope­ra­ti­on of the ser­ver ope­ra­tors is not requi­red in prin­ci­ple; secu­ri­ty gaps in the IT infras­truc­tu­re are exploi­ted. The con­di­ti­ons for such access are not publicly known.

EO 14086 and Data Pri­va­cy Framework

The report says not­hing about Exe­cu­ti­ve Order 14086 – pro­ba­b­ly becau­se it is hea­vi­ly redac­ted and/or becau­se it focu­ses pri­ma­ri­ly on super­vi­so­ry powers and not on pro­tec­tion mecha­nisms. Howe­ver, EO 14086 is rele­vant for the over­all picture.

In Octo­ber 2022, Pre­si­dent Biden announ­ced the Exe­cu­ti­ve Order 14086 („Enhan­cing Safe­guards for United Sta­tes Signals Intel­li­gence Acti­vi­ties“; see here). Tog­e­ther with a regu­la­ti­on issued by the Att­or­ney Gene­ral, it forms the basis for the Ade­qua­cy decis­i­on of the EU Com­mis­si­on of July 2023, the EU-US Data Pri­va­cy Frame­work. EO 14086 pro­vi­des for Rest­ric­tions on intel­li­gence sur­veil­lan­ce of Non-US Persons:

  • Signals intel­li­gence may only be used to pur­sue defi­ned legi­ti­ma­te objec­ti­ves (e.g. coun­ter-ter­ro­rism, coun­ter-espio­na­ge, pro­tec­tion of natio­nal security).
  • Moni­to­ring must be neces­sa­ry and proportionate.
  • A new redress mecha­nism has been crea­ted: Data sub­jects from „qua­li­fy­ing sta­tes“ can file com­plaints with the Civil Liber­ties Pro­tec­tion Offi­cer (CLPO), who­se decis­i­ons can be review­ed by a new­ly crea­ted Data Pro­tec­tion Review Court.

In August 2024, the Fede­ral Coun­cil invi­ted the USA to the List of count­ries with an ade­qua­te level of data pro­tec­tion set, to the ext­ent that reci­pi­en­ts are cer­ti­fi­ed under the Data Pri­va­cy Frame­work. Howe­ver, the regi­stra­ti­on only applies to data reci­pi­en­ts that are sub­ject to the Frame­work, i.e. US com­pa­nies that have cer­ti­fi­ed them­sel­ves to the US Depart­ment of Commerce.

Whe­ther EO 14086 offers effec­ti­ve pro­tec­tion in prac­ti­ce is dis­pu­ted. noyb published a Com­plaint against the Irish data pro­tec­tion aut­ho­ri­ty becau­se it is not taking any mea­su­res against Meta despi­te its known sur­veil­lan­ce prac­ti­ces. The orga­nizati­on argues that the frame­work, like its pre­de­ces­sors Safe Har­bor and Pri­va­cy Shield, is legal­ly untenable.

Reforming Intel­li­gence and Secu­ring Ame­ri­ca Act (RISAA) 2024

The report also addres­ses the Reforming Intel­li­gence and Secu­ring Ame­ri­ca Act (RISAA) which came into force on April 20, 2024 and exten­ded Sec­tion 702 FISA until April 20, 2026 (see our pre­vious post). In 2022, a cloud data cen­ter objec­ted to a dis­clo­sure order befo­re the FISC on the grounds that it was not an „elec­tro­nic com­mu­ni­ca­ti­on ser­vice pro­vi­der“. The FISC ruled in favor of the com­pa­ny and blocked the order. The FISC decis­i­on from 2022 and the con­fir­ming FISCR decis­i­on from 2023 are hea­vi­ly blacked out. RISAA was the legis­la­ti­ve response.

Abo­ve all, Sec­tion 25 Defi­ni­ti­on of „Elec­tro­nic Com­mu­ni­ca­ti­on Ser­vice Pro­vi­der“ con­sider­a­b­ly expan­ded. This defi­ni­ti­on in 50 U.S.C. § 1881(b)(4) deter­mi­nes which com­pa­nies can be obli­ged to coope­ra­te in Sec­tion 702 monitoring.

The old ver­si­on read as follows:

(A) a tele­com­mu­ni­ca­ti­ons carrier […];

(B) a pro­vi­der of elec­tro­nic com­mu­ni­ca­ti­on service […];

(C) a pro­vi­der of a remo­te com­pu­ting service […];

(D) any other com­mu­ni­ca­ti­on ser­vice pro­vi­der who has access to wire or elec­tro­nic com­mu­ni­ca­ti­ons eit­her as such com­mu­ni­ca­ti­ons are trans­mit­ted or as such com­mu­ni­ca­ti­ons are stored; or

(E) an offi­cer, employee, or agent of an enti­ty descri­bed in sub­pa­ra­graph (A), (B), (C), or (D).

Sec­tion 25 RISAA added a new let­ter (E), the pre­vious (E) beca­me (F) with an addi­ti­on. The new cate­go­ry reads:

(E) any other ser­vice pro­vi­der who has access to equip­ment that is being or may be used to trans­mit or store wire or elec­tro­nic com­mu­ni­ca­ti­ons, but not inclu­ding any enti­ty that ser­ves pri­ma­ri­ly as: (i) a public accom­mo­da­ti­on faci­li­ty; (ii) a dwel­ling; (iii) a com­mu­ni­ty faci­li­ty; or (iv) a food ser­vice establishment.

The old cate­go­ry (D) requi­red as one Com­mu­ni­ca­ti­on Ser­vice pro­vi­der with access. The new cate­go­ry covers each Ser­vice pro­vi­der with access to devices that are or can be used for com­mu­ni­ca­ti­on. The expert opinion:

Nowa­days, every ser­vice pro­vi­der who uses smart­phones, com­pu­ters and Wi-Fi rou­ters in their com­pa­ny has “access” to such devices. Ser­vice pro­vi­ders the­r­e­fo­re no lon­ger need to be tele­com­mu­ni­ca­ti­ons pro­vi­ders. Rather, an unma­na­geable num­ber of ser­vice pro­vi­ders are cover­ed, laun­dro­mats, hair­dress­ers, fit­ness cen­ters, den­tal prac­ti­ces, DIY stores and com­mer­cial land­lords of office space.

Civil rights orga­nizati­ons such as the Brennan Cen­ter for Justi­ce, the Elec­tro­nic Fron­tier Foun­da­ti­on and the Cen­ter for Demo­cra­cy and Tech­no­lo­gy have cri­ti­ci­zed RISAA accor­din­gly as „Patri­ot Act 2.0“. Sena­tor Ron Wyden (D‑OR) cal­led it

one of the most dra­ma­tic and ter­ri­fy­ing expan­si­ons of govern­ment sur­veil­lan­ce aut­ho­ri­ty in history

Sena­tor Mark War­ner (D‑VA), the chair­man of the Sena­te Intel­li­gence Com­mit­tee, ack­now­led­ged that the pro­vi­si­on was „poor­ly draf­ted“, and pro­mi­sed a cor­rec­tion through the Intel­li­gence Aut­ho­rizati­on Act. Alt­hough the cor­rec­tion announ­ced for June 2024 was Par­ti­al­ly imple­men­ted, but the exact scope of the rest­ric­tion is clas­si­fi­ed, the exten­ded defi­ni­ti­on remains in force in principle.

Data Bro­ker Loophole“

A second aspect is only men­tio­ned in pas­sing in the report, but com­ple­tes the pic­tu­re: US aut­ho­ri­ties can cir­cum­vent con­sti­tu­tio­nal rest­ric­tions by sim­ply buy­ing cer­tain data.

Com­mer­ci­al­ly Available Infor­ma­ti­on (CAI) is defi­ned by the US intel­li­gence com­mu­ni­ty as infor­ma­ti­on that is com­mer­ci­al­ly available to the public through purcha­se or sub­scrip­ti­on. CAI is con­side­red a sub­set of Publicly Available Infor­ma­ti­on (PAI) and inclu­des, in par­ti­cu­lar, data gene­ra­ted by smart­phones, net­work­ed devices and adver­ti­sing-based busi­ness models on the inter­net. This data is aggre­ga­ted and sold by data bro­kers such as Acxi­om, Lexis­Ne­xis or Oracle.

The declas­si­fi­ed com­pa­ny men­tio­ned in the expert opi­ni­on in June 2023 Report of the Office of the Direc­tor of Natio­nal Intel­li­gence (ODNI) of Janu­ary 2022 docu­ments this prac­ti­ce. Becau­se CAI is trea­ted as PAI, fewer rest­ric­tions app­ly than for other intel­li­gence coll­ec­tion methods. Howe­ver, accor­ding to the report, CAI is fun­da­men­tal­ly dif­fe­rent from tra­di­tio­nal PAI such as news­pa­pers. Today’s CAI is far more sen­si­ti­ve, affects vir­tual­ly ever­yo­ne, is hard to avo­id and easy to dean­ony­mi­ze. Sim­ply sta­ting that CAI is publicly available is not enough:

[T]o say that CAI is „publicly available“ or can be purcha­sed by „anyo­ne“ obscu­res the quan­ti­ty and sen­si­ti­vi­ty of infor­ma­ti­on available for purcha­se today. […] To say that lar­ge-sca­le per­sist­ent­ly updated data on mil­li­ons of Ame­ri­cans obtai­ned through sophi­sti­ca­ted opaque cor­po­ra­te sur­veil­lan­ce is equi­va­lent to a news­pa­per that the govern­ment could always go out and buy is like say­ing that a ride on hor­se­back is mate­ri­al­ly indi­stin­gu­is­ha­ble from a flight to the moon.

The report lists a num­ber of con­trac­tu­al rela­ti­on­ships for the pro­cu­re­ment of CAI:

  • FBICon­tract with Zero­Fox for social media alerting„
  • Defen­se Intel­li­gence Agen­cy (DIA)Con­tracts for social media reports on per­sons app­ly­ing for secu­ri­ty cle­ar­an­ces and with Lexis­Ne­xis for „com­pre­hen­si­ve on-line search results rela­ted to com­mer­cial due diligence“
  • U.S. NavyCon­tract with Saya­ri Ana­ly­tics for access to a data­ba­se with „tens of thou­sands of pre­vious­ly-uniden­ti­fi­ed spe­ci­fic nodes, faci­li­ties and key peo­p­le rela­ted to US sanc­tion­ed actors“
  • Tre­a­su­ry Depart­ment: Access to Banker’s Almanac
  • Depart­ment of Defen­se: Access to Jane’s online
  • Coast GuardCon­tract with Babel Street for „Open Source Data Coll­ec­tion, Trans­la­ti­on, Ana­ly­sis Application“

DIA also buys loca­ti­on data from smart­phones on the open mar­ket. In a Let­ter to Con­gress dated Janu­ary 15, 2021 the DIA dis­c­lo­sed this:

DIA curr­ent­ly pro­vi­des fun­ding to ano­ther agen­cy that purcha­ses com­mer­ci­al­ly available geo­lo­ca­ti­on meta­da­ta aggre­ga­ted from smart­phones. […] Per­mis­si­on to query the U.S. device loca­ti­on data has been gran­ted five times in the past two-and-a-half years for aut­ho­ri­zed purposes.

The report then warns that anony­mi­zed data easi­ly re-iden­ti­fi­ed can be used:

Alt­hough CAI may be „anony­mi­zed,“ it is often pos­si­ble (using other CAI) to dean­ony­mi­ze and iden­ti­fy indi­vi­du­als, inclu­ding U.S. persons.

As an exam­p­le, the report refers to a Rese­arch by the New York Times from 2019, which work­ed with 50 bil­li­on loca­ti­on data of 12 mil­li­on Americans:

It was a ran­dom sam­ple from 2016 and 2017, but it took only minu­tes – with assi­stance from publicly available infor­ma­ti­on – for us to dean­ony­mi­ze loca­ti­on data. […] The Times was able to track the move­ments of Pre­si­dent Trump via a mem­ber of his Secret Ser­vice detail.

The U.S. Supre­me Court had ruled in 2018 in Car­pen­ter v. United Sta­tes howe­ver, ruled that secu­ri­ty agen­ci­es gene­ral­ly need a court order to obtain loca­ti­on data from tele­com­mu­ni­ca­ti­ons pro­vi­ders. Accor­ding to the ODNI report, howe­ver, the intel­li­gence ser­vices do not have a uni­form posi­ti­on on the appli­ca­bi­li­ty of Car­pen­ter on purcha­sed data. The DIA, for exam­p­le, con­siders Car­pen­ter- as not appli­ca­ble to purcha­sed data. The expert opi­ni­on refers to this practice:

While the U.S. Supre­me Court in Car­pen­ter found that the secu­ri­ty aut­ho­ri­ties may only com­pel com­pa­nies to hand over the reque­sted data on the basis of a court order, this court decis­i­on is par­ti­al­ly inef­fec­ti­ve in prac­ti­ce. As long as the com­pa­nies hand over the data „vol­un­t­a­ri­ly“, accor­ding to the secu­ri­ty aut­ho­ri­ties’ inter­pre­ta­ti­on, the­re is no need for a court order. Howe­ver, the secu­ri­ty aut­ho­ri­ties buy the com­pa­nies’ vol­un­t­a­ri­ness with hard cash, as a report pre­pared by the US govern­ment in 2022 found.

The Fourth Amend­ment Is Not For Sale Act, which was inten­ded to pre­vent this prac­ti­ce, pas­sed the Hou­se of Repre­sen­ta­ti­ves in April 2024 by 219 votes to 199, but fai­led in the Sena­te as an amend­ment to RISAA. Data purcha­sing the­r­e­fo­re remains per­mit­ted at fede­ral level. Only the sta­te of Mon­ta­na has pro­hi­bi­ted law enforce­ment agen­ci­es from purcha­sing data in May 2025 (in force sin­ce Octo­ber 1, 2025) that could other­wi­se only be obtai­ned with a search warrant.

In respon­se to cri­ti­cism, on May 8, 2024, the ODNI published a IC Poli­cy Frame­work for Com­mer­ci­al­ly Available Infor­ma­ti­on which is inten­ded to imple­ment the report’s recom­men­da­ti­ons and estab­lish uni­form stan­dards for intel­li­gence agen­ci­es. Howe­ver, reports from Janu­ary 2025 show that DHS has reac­qui­red access to sur­veil­lan­ce systems that can moni­tor cell pho­nes in neigh­bor­hoods and track move­ments over time. The ACLU released ICE docu­ments show­ing how the agen­cy is attemp­ting to cons­truct a legal justi­fi­ca­ti­on for purcha­sing loca­ti­on data wit­hout a warrant.

Con­trol and not ser­ver loca­ti­on is decisive

The report also con­clu­des that the Sto­rage loca­ti­on of data lar­ge­ly irrele­vant from a legal per­spec­ti­ve is. The decisi­ve fac­tor is con­trol over the data:

The pro­vi­si­ons of the SCA undoub­ted­ly also app­ly extra­ter­ri­to­ri­al­ly. This cor­re­sponds to the clear inten­ti­on of the CLOUD Act legis­la­tor. In addi­ti­on, it is sett­led case law of US fede­ral courts that docu­ments must be released even if they are loca­ted out­side the USA but the obli­gor has con­trol over the­se docu­ments. The term “con­trol” is inter­pre­ted broad­ly, mea­ning that any exe­cu­ti­ve who can arran­ge for the infor­ma­ti­on to be sent has con­trol in this sense.

If a US com­pa­ny has a Ger­man sub­si­dia­ry, US courts will be able to order the parent com­pa­ny to hand over data to the US aut­ho­ri­ties. Euro­pean com­pa­nies can also com­ply with the US juris­dic­tion to the ext­ent that they main­tain busi­ness cont­acts with the USA. The expert opi­ni­on refers to Pli­xer Int’l, Inc. v. Scru­ti­ni­zer GmbH, accor­ding to which a Ger­man IT com­pa­ny was sub­ject to US juris­dic­tion sole­ly becau­se its Eng­lish-lan­guage web­site was also acce­s­si­ble to US cus­to­mers and the com­pa­ny had ser­ved around 150 US cus­to­mers with a tur­no­ver of appro­xi­m­ate­ly USD 200,000 for seve­ral years:

The ope­ra­ti­on of a web­site that is at least also aimed at US cus­to­mers or does not expli­ci­t­ly exclude them from acce­s­sing the web­site may also be suf­fi­ci­ent for the assump­ti­on of spe­ci­fic per­so­nal juris­dic­tion. For a cloud pro­vi­der, sim­ply offe­ring its ser­vices to US cus­to­mers may be suf­fi­ci­ent if the pro­ce­e­dings con­cern pre­cis­e­ly this activity.

Tech­ni­cal pro­tec­ti­ve measures?

The expert opi­ni­on con­ti­nues to exami­ne, whe­ther cloud pro­vi­ders can take tech­ni­cal mea­su­res to avo­id the obli­ga­ti­on to sur­ren­der data, for exam­p­le by exclu­ding them­sel­ves from data access, but has con­sidera­ble doubts about this:

It seems que­stionable whe­ther an obli­ga­ti­on to dis­c­lo­se can be avo­ided by cloud pro­vi­ders tech­ni­cal­ly exclu­ding them­sel­ves from the cloud. […] Under US pro­ce­du­ral law, howe­ver, par­ties are obli­ged to store infor­ma­ti­on rele­vant to the pro­ce­e­dings even befo­re the start of a legal dis­pu­te. […] If a cloud pro­vi­der exclu­des its­elf from access to the cloud ser­ver by means of tech­ni­cal mea­su­res, it can no lon­ger ful­fill the­se obli­ga­ti­ons and some­ti­mes risks sub­stan­ti­al fines, cri­mi­nal pro­se­cu­ti­on, or both.