US-UK Agreement under the CLOUD Act to Take Effect this Summer

In March 2018, the US Congress passed an amendment to the Stored Communications Act (SCA)[1] and Wiretap Act[2] in an attempt to facilitate access to electronic data stored outside the US in criminal investigations. Known as the Clarifying Lawful Overseas Use of Data (CLOUD) Act,[3] this legislation endeavours to more quickly resolve conflicting legal obligations of companies faced with a request to release customer data, which access might ordinarily be prohibited by law. The CLOUD Act was the result of the legal challenge to a 2013 warrant issued by the FBI requesting the Ireland-stored email correspondence of a Microsoft customer implicated in a drug trafficking investigation. A lawsuit ensued and made its way to the Supreme Court on appeal,[4] but before the case was resolved, the US passed the CLOUD Act to address this sort of issue.

The CLOUD Act sets forth requirements relating to US access to data stored outside the US as well as a detailed proposed path for other nations’ access to electronic communications data stored within the US.[5] Under the Act, (1) US government and law enforcement officials may direct an overseas company to produce customer communications data pertaining to a US person; and (2) non-US law enforcement officials may gain access to data stored in the US, but only in conjunction with investigations involving “serious crime, including terrorism”[6] and only when an “executive agreement”[7] is in place between the US and the relevant non-US governments prior to a release of access to the requested data.

This Act applies to providers of remote computing services and electronic communication services (ECS). Significantly, once a CLOUD Act executive agreement is in place, data requests for transfers that implicate the conditions of national laws such as the EU’s General Data Protection Regulation (GDPR)[8] and the UK’s Data Protection Act 2018 will need careful consideration.[1] It is not yet known if EU authorities will find terms of executive agreements sufficient to meet a data protection exception under Article 49 GDPR.

Currently, no executive agreements are in place under the CLOUD Act, although the US and the UK negotiated and signed such an agreement[9] that is set to go into effect this summer, absent objection by US Congress.[10] Until the US-UK executive agreement takes effect, all requests from a US authority to the EU, including the UK during the Brexit transition period, are subject to the traditional Mutual Legal Assistance Treaty (MLAT) process unless a bilateral executive agreement is pursued.[11]

The US-UK Agreement is set to enter into force beginning on July 8, so a request prior to its effective date from the US government to the UK regarding a US person – or to US from the UK government regarding a UK person – will be managed pursuant to that executive agreement. This agreement is in compliance with the CLOUD Act framework and is anticipated to serve as a model for future agreements,[12] so it will be important for businesses to monitor its application. Of course, for all requests under CLOUD Act executive agreements as with any cross-border data request, it will continue to be crucial to refer requests to legal counsel for a full analysis.

Although the agreement is quite comprehensive, some of the key considerations for counsel will be to determine that:

  • A warrant or subpoena that relates to a serious crime[13] is issued in compliance with the domestic law and is reasonably justified, as well as limited to a fixed, limited duration not longer than is reasonably necessary[14]
  • A provider’s representatives are prepared only to produce the requested data directly to the Issuing Party’s Designated Authority[15]
  • Processing and access to data are compatible with the nations’ respective laws addressing privacy, data protection and civil liberties[16]
  • Safeguards are in place to minimize targeting of persons who are not subject to the request, particularly nationals of the non-requesting nation[17]

ECS providers may raise specific objections when they believe an order might not conform with the executive agreement, and government authorities may confer to resolve the outstanding issues.[18] It is worth noting regarding future requests that the CLOUD Act permits providers to bring a motion to quash a request based on the risk of violating law to which they are beholden.[19] The specific terms of the objection process may be addressed within the individual agreements, as is the case with the US-UK agreement. As referenced above, it will be important to reconcile CLOUD Act orders with requirements of the GDPR and the use of objections will be a key to the protection of individual interests.

Executive agreements under the CLOUD Act are designed to address US requests for foreign-held data regarding US persons and foreign requests for US-held data regarding its own persons. Non-US requests for data regarding US persons are not covered by the CLOUD Act and will continue to require the MLAT process.[20]

Based on the complicated and agreement-specific nature of the CLOUD Act, it will continue to be crucial to refer government data requests to legal counsel to determine the validity of the request. It will be particularly important to challenge orders that appear to run afoul of data privacy requirements, at least until authorities have determined the extent of compatibility with CLOUD Act mandates. From a broader perspective, having been as-yet untested, the future of cross-border data access compliance is far from clear. Company policies addressing customer data requests from all sources needs to continue to evolve to account for the dynamic nature of cross-border data requests as the laws of all nations grapple with the rapid increase in the global volume of data.

