Short Reads

E-mails stored outside the US cannot be claimed by the US Government

E-mails stored outside the US cannot be claimed by the US Government

E-mails stored outside the US cannot be claimed by the US Government

13.10.2016

On 14 July 2016 the United States Court of Appeals for the Second Circuit (the Court of Appeals) rendered a judgment in the “Warrant case” (or the “Microsoft Ireland case”).

The three judge panel ruled that Microsoft is not obliged to hand over personal data (e-mails) at the request of US intelligence agencies if this information is stored outside US territory. The Court of Appeals thereby overturned an earlier ruling from the District Court.

In 2013 a US intelligence agency requested access to all e-mails and private information of a suspect in a narcotics case. The e-mails were stored in a Microsoft data center in Dublin, Ireland. Microsoft agreed to provide access to all information stored on US servers but refused to hand over the data stored in Dublin. Microsoft’s defense in doing so was that a US judge has no authority to issue warrants to seize information stored outside US territory.

In May 2014 a federal magistrate judge ordered Microsoft to hand over the e-mails to the US government. Microsoft appealed to the District Court for the Southern District of New York against this decision. This District Court ruled in favor of the US government, hence Microsoft’s appeal before the Court of Appeals.

In short, the Court of Appeals concludes that the US government does not have legal grounds to seek possession of data stored on servers outside the US territory: “Congress did not intend the SCA’s (Stored Communications Act) warrant provisions to apply extraterritorially. The focus of those provisions is protection of a user’s privacy interests. Accordingly, the SCA does not authorize a US court to issue and enforce an SCA warrant against a United States-based service provider for the contents of a customer’s electronic communications stored on servers located outside the US. The SCA warrant in this case may not lawfully be used to compel Microsoft to produce to the government the contents of a customer’s e-mail account stored exclusively in Ireland. Because Microsoft has otherwise complied with the Warrant, it has no remaining lawful obligation to produce materials to the government.”

This decision can be considered revolutionary because it puts an end to EU-located cloud providers’ common practice of handing over data requested by US intelligence agencies under a warrant. It is expected that the US government will appeal against this decision of the Court of Appeals.

In view of news reports regarding recent revelations made by Edward Snowden, the question remains whether this decision of the Court of Appeals effectively limits US intelligence agencies’ gaining possession of personal data from the EU. Snowden’s revelations say that EU intelligence agencies provide data of European citizens and companies without having to fulfill many formalities to US intelligence agencies. The Washington Post reported in February that the US and the UK are negotiating to give their intelligence agencies the authority to give interception orders and warrants to companies based in both countries.

This article was co-written by summer intern Sebastiaan de Koning.

Team

Related news

06.06.2019 BE law
TMT Roundtable: Getting a handle on software quality

Roundtable - Erik Valgaeren, TMT Partner at Stibbe Brussels, and his team organize a roundtable on software quality in our Brussels office on June 6th, 2019. Software quality is a recurring theme in many matters handled by our TMT team. Whether our assistance relates to preparing tender documents, contracting effectively, assessing proper performance or allocating ownership and accountability in challenging IT projects, questions concerning software quality always arise.

Read more

24.05.2019 EU law
One year of GDPR - The regulatory warm-up

Short Reads - The first year of the General Data Protection Regulation ("GDPR") is over. Although early noises predicted an entirely new data protection regime, the European legal framework did not change substantially, the major changes being an expansion of the territorial scope to non-EU countries and stronger powers of enforcement. In spite of fears and rumours of immediate enforcement and huge fines, most regulators focused on helping companies achieve compliance, or they enforced without directly imposing fines.

Read more

21.05.2019 EU law
Part one - GDPR and Public Law - Applicability of GDPR to public bodies

Articles - Since the GDPR became applicable almost one year ago, multiple questions have arisen about its interaction with other fields of law. In this three-part blog series of “GDPR and Public Law”, we discuss three relevant issues of the interaction of GDPR with public law and government. In this blog we discuss the applicability of GDPR to public bodies.

Read more

Our website uses functional cookies for the functioning of the website and analytic cookies that enable us to generate aggregated visitor data. We also use other cookies, such as third party tracking cookies - please indicate whether you agree to the use of these other cookies:

Privacy – en cookieverklaring