- US surveillance law (Section 702) allows mass access to cloud data without a traditional search warrant.
- CLOUD Act and SCA force providers to hand over even extraterritorial data; legal protection for foreigners remains limited.
- RISAA 2024 massively expands the definition of obligated service providers, covering many non-traditional providers.
- The decisive factor is control over data, not server location; technical compartmentalization offers hardly any reliable protection against the obligation to disclose data.
Are authorities, companies and holders of professional secrets allowed to use cloud services from US providers, indirectly US-controlled providers and other providers with a foreign connection? This question has been on the agenda for years, not only in Switzerland, but also in other countries – ultimately since Edward Snowden. For public bodies, the focus is on compliance with fundamental rights and official secrecy, while for private individuals it is on private data protection law and the question of the conditions under which outsourcing to a cloud provider is compatible with professional secrecy. A chronology of the corresponding discussion we have published on datenrecht.
As is well known, the discussion revolves primarily around the question of which risks of access by authorities abroad may be accepted, whether „acceptance“ of the risk of such access is prohibited at all or whether such access must rather be accepted because other risks for data subjects can be reduced through the use of corresponding cloud solutions. This discussion is one of Swiss federal and cantonal law. However, the law of the foreign countries concerned, and the USA in particular, plays a significant role as a risk factor.
In this context, the December 2025 Expert opinion made public through a freedom of information request interesting to read and an occasion for a corresponding presentation. A person from the University of Cologne was commissioned by the German Federal Ministry of the Interior (BMI) to write a legal opinion on the US legal situation in March 2025. The report is currently only available in a redacted version.
Expert opinion assignment
The BMI asked three questions:
- What is the current legal situation in the USA? Do US intelligence services have a right of direct access to cloud information and a right of disclosure vis-à-vis cloud providers?
- Are foreign providers also subject to US jurisdiction?
- Does such a right of access also exist if a US company establishes a German subsidiary under German law and operates the cloud on German territory?
The report analyzes the relevant US surveillance law, essentially with the following findings, some of which we have supplemented with additional information or further references:
FISA
Section 702
Section 702 FISA (Title VII) is the central regulation for the surveillance of „non-US persons“ outside the USA. It authorizes US intelligence agencies to collect communications data from Electronic Communication Service Providers (ECSPs). The Foreign Intelligence Surveillance Court (FISC) only approves the monitoring parameters annually, not individual target persons.
Section 702 applies factually to All cloud service providers and data centers Application. The procedure is largely carried out without comprehensible judicial review; in principle, no judicial search warrant is required for the order.
Section 501/502
Section 501/502 FISA (Title V), also Section 215 of the USA PATRIOT Act, authorized the FBI to apply to the FISC for orders to surrender „tangible things“ (including business records and documents). This provision was the basis for the NSA mass collection of telephone metadata. The USA FREEDOM Act 2015 restricted this „bulk collection“ and at the same time extended the term of the provision until March 2020.
However, Section 501/502 expired in March 2020 and has since been not renewed. Accordingly, the opinion states that Section 502 FISA is no longer applicable.
Title IV FISA
Title IV FISA (Sections 401 – 406) regulates the use of Pen Registers and Trap-and-trace devices for intelligence purposes. A Pen Register captures „dialing, routing, addressing, or signaling information“ of outgoing communication, a Trap-and-Trace Device the corresponding data of incoming communication (18 U.S.C. § 3127). Both instruments explicitly do not record communication content, but only metadata.
The USA FREEDOM Act 2015 also prohibited the bulk collection and has since demanded a specific selection term, i.e. a concrete point of reference such as a specific person, account or device. The hurdle for a FISC order under Title IV is lower than for surveillance under Title I (electronic surveillance with content): It is sufficient to certify that the information is likely to be relevant for an ongoing investigation to protect against international terrorism or clandestine intelligence activities.
Stored Communications Act & CLOUD Act
The Stored Communications Act (SCA) obliges providers of electronic communications services and remote computing services to disclose communications content, documents stored in clouds and metadata. With the amendment to the CLOUD Act of 2018 that this obligation also applies to data stored outside the USA (background was the case United States v. Microsoft Corp., in which Microsoft refused to hand over emails stored in Ireland).
Legal protection
Legal protection against SCA orders is limited under the CLOUD Act. Covered service providers can challenge an order („motion to quash or modify“, 18 U.S.C. § 2703(h)), if
- the data subject is not a US person and does not live in the USA,
- the surrender of the right of a qualifying foreign government would hurt, and
- the court comes to the conclusion after a comity analysis (i.e. weighing up the conflicting interests) that the order should be lifted.
As qualifying foreign government only one state that has a treaty with the USA applies. Executive Agreement to 18 U.S.C. § 2523 has concluded. Such executive agreements initially allow simplified mutual data access between law enforcement authorities and remove the otherwise applicable data protection regulations. Blocking Statutes (i.e. data sharing bans). To date, such agreements only exist with the United Kingdom (in force since October 2022) and Australia (in force since January 2024). Negotiations are ongoing with the EU and Canada (BSA TechPost).
For Swiss companies, this means that No special legal protection against orders under the SCA. A service provider can also raise a comity defense without an executive agreement. common law-basis (CLOUD Act § 103(c)), but whether legal protection is granted is at the broad discretion of the competent US court. Switzerland would, however, also have to accept that US authorities could serve restitution orders directly on Swiss CSPs, outside the scope of mutual legal assistance. The Swiss Bankers Association in particular is opposed to such an agreement. skeptical about.
EO 12333
The Executive Order 12333 then authorizes US intelligence agencies to collect intelligence-relevant information abroad. The cooperation of the server operators is not required in principle; security gaps in the IT infrastructure are exploited. The conditions for such access are not publicly known.
EO 14086 and Data Privacy Framework
The report says nothing about Executive Order 14086 – probably because it is heavily redacted and/or because it focuses primarily on supervisory powers and not on protection mechanisms. However, EO 14086 is relevant for the overall picture.
In October 2022, President Biden announced the Executive Order 14086 („Enhancing Safeguards for United States Signals Intelligence Activities“; see here). Together with a regulation issued by the Attorney General, it forms the basis for the Adequacy decision of the EU Commission of July 2023, the EU-US Data Privacy Framework. EO 14086 provides for Restrictions on intelligence surveillance of Non-US Persons:
- Signals intelligence may only be used to pursue defined legitimate objectives (e.g. counter-terrorism, counter-espionage, protection of national security).
- Monitoring must be necessary and proportionate.
- A new redress mechanism has been created: Data subjects from „qualifying states“ can file complaints with the Civil Liberties Protection Officer (CLPO), whose decisions can be reviewed by a newly created Data Protection Review Court.
In August 2024, the Federal Council invited the USA to the List of countries with an adequate level of data protection set, to the extent that recipients are certified under the Data Privacy Framework. However, the registration only applies to data recipients that are subject to the Framework, i.e. US companies that have certified themselves to the US Department of Commerce.
Whether EO 14086 offers effective protection in practice is disputed. noyb published a Complaint against the Irish data protection authority because it is not taking any measures against Meta despite its known surveillance practices. The organization argues that the framework, like its predecessors Safe Harbor and Privacy Shield, is legally untenable.
Reforming Intelligence and Securing America Act (RISAA) 2024
The report also addresses the Reforming Intelligence and Securing America Act (RISAA) which came into force on April 20, 2024 and extended Section 702 FISA until April 20, 2026 (see our previous post). In 2022, a cloud data center objected to a disclosure order before the FISC on the grounds that it was not an „electronic communication service provider“. The FISC ruled in favor of the company and blocked the order. The FISC decision from 2022 and the confirming FISCR decision from 2023 are heavily blacked out. RISAA was the legislative response.
Above all, Section 25 Definition of „Electronic Communication Service Provider“ considerably expanded. This definition in 50 U.S.C. § 1881(b)(4) determines which companies can be obliged to cooperate in Section 702 monitoring.
The old version read as follows:
(A) a telecommunications carrier […];
(B) a provider of electronic communication service […];
(C) a provider of a remote computing service […];
(D) any other communication service provider who has access to wire or electronic communications either as such communications are transmitted or as such communications are stored; or
(E) an officer, employee, or agent of an entity described in subparagraph (A), (B), (C), or (D).
Section 25 RISAA added a new letter (E), the previous (E) became (F) with an addition. The new category reads:
(E) any other service provider who has access to equipment that is being or may be used to transmit or store wire or electronic communications, but not including any entity that serves primarily as: (i) a public accommodation facility; (ii) a dwelling; (iii) a community facility; or (iv) a food service establishment.
The old category (D) required as one Communication Service provider with access. The new category covers each Service provider with access to devices that are or can be used for communication. The expert opinion:
„Nowadays, every service provider who uses smartphones, computers and Wi-Fi routers in their company has “access” to such devices. Service providers therefore no longer need to be telecommunications providers. Rather, an unmanageable number of service providers are covered, laundromats, hairdressers, fitness centers, dental practices, DIY stores and commercial landlords of office space.
Civil rights organizations such as the Brennan Center for Justice, the Electronic Frontier Foundation and the Center for Democracy and Technology have criticized RISAA accordingly as „Patriot Act 2.0“. Senator Ron Wyden (D‑OR) called it
one of the most dramatic and terrifying expansions of government surveillance authority in history
Senator Mark Warner (D‑VA), the chairman of the Senate Intelligence Committee, acknowledged that the provision was „poorly drafted“, and promised a correction through the Intelligence Authorization Act. Although the correction announced for June 2024 was Partially implemented, but the exact scope of the restriction is classified, the extended definition remains in force in principle.
„Data Broker Loophole“
A second aspect is only mentioned in passing in the report, but completes the picture: US authorities can circumvent constitutional restrictions by simply buying certain data.
Commercially Available Information (CAI) is defined by the US intelligence community as information that is commercially available to the public through purchase or subscription. CAI is considered a subset of Publicly Available Information (PAI) and includes, in particular, data generated by smartphones, networked devices and advertising-based business models on the internet. This data is aggregated and sold by data brokers such as Acxiom, LexisNexis or Oracle.
The declassified company mentioned in the expert opinion in June 2023 Report of the Office of the Director of National Intelligence (ODNI) of January 2022 documents this practice. Because CAI is treated as PAI, fewer restrictions apply than for other intelligence collection methods. However, according to the report, CAI is fundamentally different from traditional PAI such as newspapers. Today’s CAI is far more sensitive, affects virtually everyone, is hard to avoid and easy to deanonymize. Simply stating that CAI is publicly available is not enough:
[T]o say that CAI is „publicly available“ or can be purchased by „anyone“ obscures the quantity and sensitivity of information available for purchase today. […] To say that large-scale persistently updated data on millions of Americans obtained through sophisticated opaque corporate surveillance is equivalent to a newspaper that the government could always go out and buy is like saying that a ride on horseback is materially indistinguishable from a flight to the moon.
The report lists a number of contractual relationships for the procurement of CAI:
- FBIContract with ZeroFox for social media alerting„
- Defense Intelligence Agency (DIA)Contracts for social media reports on persons applying for security clearances and with LexisNexis for „comprehensive on-line search results related to commercial due diligence“
- U.S. NavyContract with Sayari Analytics for access to a database with „tens of thousands of previously-unidentified specific nodes, facilities and key people related to US sanctioned actors“
- Treasury Department: Access to Banker’s Almanac
- Department of Defense: Access to Jane’s online
- Coast GuardContract with Babel Street for „Open Source Data Collection, Translation, Analysis Application“
DIA also buys location data from smartphones on the open market. In a Letter to Congress dated January 15, 2021 the DIA disclosed this:
DIA currently provides funding to another agency that purchases commercially available geolocation metadata aggregated from smartphones. […] Permission to query the U.S. device location data has been granted five times in the past two-and-a-half years for authorized purposes.
The report then warns that anonymized data easily re-identified can be used:
Although CAI may be „anonymized,“ it is often possible (using other CAI) to deanonymize and identify individuals, including U.S. persons.
As an example, the report refers to a Research by the New York Times from 2019, which worked with 50 billion location data of 12 million Americans:
It was a random sample from 2016 and 2017, but it took only minutes – with assistance from publicly available information – for us to deanonymize location data. […] The Times was able to track the movements of President Trump via a member of his Secret Service detail.
The U.S. Supreme Court had ruled in 2018 in Carpenter v. United States however, ruled that security agencies generally need a court order to obtain location data from telecommunications providers. According to the ODNI report, however, the intelligence services do not have a uniform position on the applicability of Carpenter on purchased data. The DIA, for example, considers Carpenter- as not applicable to purchased data. The expert opinion refers to this practice:
While the U.S. Supreme Court in Carpenter found that the security authorities may only compel companies to hand over the requested data on the basis of a court order, this court decision is partially ineffective in practice. As long as the companies hand over the data „voluntarily“, according to the security authorities’ interpretation, there is no need for a court order. However, the security authorities buy the companies’ voluntariness with hard cash, as a report prepared by the US government in 2022 found.
The Fourth Amendment Is Not For Sale Act, which was intended to prevent this practice, passed the House of Representatives in April 2024 by 219 votes to 199, but failed in the Senate as an amendment to RISAA. Data purchasing therefore remains permitted at federal level. Only the state of Montana has prohibited law enforcement agencies from purchasing data in May 2025 (in force since October 1, 2025) that could otherwise only be obtained with a search warrant.
In response to criticism, on May 8, 2024, the ODNI published a IC Policy Framework for Commercially Available Information which is intended to implement the report’s recommendations and establish uniform standards for intelligence agencies. However, reports from January 2025 show that DHS has reacquired access to surveillance systems that can monitor cell phones in neighborhoods and track movements over time. The ACLU released ICE documents showing how the agency is attempting to construct a legal justification for purchasing location data without a warrant.
Control and not server location is decisive
The report also concludes that the Storage location of data largely irrelevant from a legal perspective is. The decisive factor is control over the data:
The provisions of the SCA undoubtedly also apply extraterritorially. This corresponds to the clear intention of the CLOUD Act legislator. In addition, it is settled case law of US federal courts that documents must be released even if they are located outside the USA but the obligor has control over these documents. The term “control” is interpreted broadly, meaning that any executive who can arrange for the information to be sent has control in this sense.
If a US company has a German subsidiary, US courts will be able to order the parent company to hand over data to the US authorities. European companies can also comply with the US jurisdiction to the extent that they maintain business contacts with the USA. The expert opinion refers to Plixer Int’l, Inc. v. Scrutinizer GmbH, according to which a German IT company was subject to US jurisdiction solely because its English-language website was also accessible to US customers and the company had served around 150 US customers with a turnover of approximately USD 200,000 for several years:
The operation of a website that is at least also aimed at US customers or does not explicitly exclude them from accessing the website may also be sufficient for the assumption of specific personal jurisdiction. For a cloud provider, simply offering its services to US customers may be sufficient if the proceedings concern precisely this activity.
Technical protective measures?
The expert opinion continues to examine, whether cloud providers can take technical measures to avoid the obligation to surrender data, for example by excluding themselves from data access, but has considerable doubts about this:
It seems questionable whether an obligation to disclose can be avoided by cloud providers technically excluding themselves from the cloud. […] Under US procedural law, however, parties are obliged to store information relevant to the proceedings even before the start of a legal dispute. […] If a cloud provider excludes itself from access to the cloud server by means of technical measures, it can no longer fulfill these obligations and sometimes risks substantial fines, criminal prosecution, or both.