Short Reads

E-mails stored outside the US cannot be claimed by the US Government

E-mails stored outside the US cannot be claimed by the US Government

E-mails stored outside the US cannot be claimed by the US Government

13.10.2016

On 14 July 2016 the United States Court of Appeals for the Second Circuit (the Court of Appeals) rendered a judgment in the “Warrant case” (or the “Microsoft Ireland case”).

The three judge panel ruled that Microsoft is not obliged to hand over personal data (e-mails) at the request of US intelligence agencies if this information is stored outside US territory. The Court of Appeals thereby overturned an earlier ruling from the District Court.

In 2013 a US intelligence agency requested access to all e-mails and private information of a suspect in a narcotics case. The e-mails were stored in a Microsoft data center in Dublin, Ireland. Microsoft agreed to provide access to all information stored on US servers but refused to hand over the data stored in Dublin. Microsoft’s defense in doing so was that a US judge has no authority to issue warrants to seize information stored outside US territory.

In May 2014 a federal magistrate judge ordered Microsoft to hand over the e-mails to the US government. Microsoft appealed to the District Court for the Southern District of New York against this decision. This District Court ruled in favor of the US government, hence Microsoft’s appeal before the Court of Appeals.

In short, the Court of Appeals concludes that the US government does not have legal grounds to seek possession of data stored on servers outside the US territory: “Congress did not intend the SCA’s (Stored Communications Act) warrant provisions to apply extraterritorially. The focus of those provisions is protection of a user’s privacy interests. Accordingly, the SCA does not authorize a US court to issue and enforce an SCA warrant against a United States-based service provider for the contents of a customer’s electronic communications stored on servers located outside the US. The SCA warrant in this case may not lawfully be used to compel Microsoft to produce to the government the contents of a customer’s e-mail account stored exclusively in Ireland. Because Microsoft has otherwise complied with the Warrant, it has no remaining lawful obligation to produce materials to the government.”

This decision can be considered revolutionary because it puts an end to EU-located cloud providers’ common practice of handing over data requested by US intelligence agencies under a warrant. It is expected that the US government will appeal against this decision of the Court of Appeals.

In view of news reports regarding recent revelations made by Edward Snowden, the question remains whether this decision of the Court of Appeals effectively limits US intelligence agencies’ gaining possession of personal data from the EU. Snowden’s revelations say that EU intelligence agencies provide data of European citizens and companies without having to fulfill many formalities to US intelligence agencies. The Washington Post reported in February that the US and the UK are negotiating to give their intelligence agencies the authority to give interception orders and warrants to companies based in both countries.

This article was co-written by summer intern Sebastiaan de Koning.

Team

Related news

18.02.2019 EU law
Erik Valgaeren moderates a panel on Data Governance and Compliance during IBA's Silicon Beach Conference

Speaking slot - The discussion topic will cover various legal aspects relating to data lifecycle management, both for personal and non personal data. These aspects will include rights in and obligations regarding data, such retention obligations and portability rights. Practical suggestions on holistic data management and the role of the chief data officer will be debated.

Read more

22.02.2019 BE law
Sarah De Wulf on challenges of SAP contracts and indirect use during a Beltug seminar.

Speaking slot - Sarah De Wulf, junior TMT associate, discusses SAP licensing agreements during a Beltug seminar on 20 February 2019. Many of the Beltug members are customers of SAP and face daily questions and challenges regarding SAP's software licensing policies.  These questions include (among others): how the licence models will evolve (especially in terms of the growth of cloud services) and how to cope with indirect access.

Read more

18.02.2019 NL law
Brexit and data protection: preparing for a 'no-deal'

Short Reads - As it stands, the UK will exit the European Union at midnight on 29 March 2019. Therefore, businesses within the UK, or with trade relations with the UK, would be best advised to assume that a no-deal Brexit is inevitable. The exchange of personal data  within the EU is governed by the General Data Protection Regulation (GDPR). In a no-deal Brexit, the GDPR will cease to be applicable in the UK upon its EU exit.

Read more

Our website uses cookies: third party analytics cookies to best adapt our website to your needs & cookies to enable social media functionalities. For more information on the use of cookies, please check our Privacy and Cookie Policy. Please note that you can change your cookie opt-ins at any time via your browser settings.

Privacy – en cookieverklaring