Gebäude der Microsoft

Six Principles on the CLOUD Act from Microsoft -

In September 2018, Microsoft published six recommendations on its website for dealing with secret requests from US intelligence and law enforcement agencies for customer data from cloud providers. Today, these secret requests are made without a judicial search warrant or even a formal investigation by the respective intelligence agency. It goes without saying that the cloud provider is not allowed to disclose the secret data requests to the person affected by the request. If they do, they face draconian penalties from the Department of Justice (DoJ).

 

Microsoft's 6 principles on the CLOUD Act

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) was approved and ratified by the US Congress on March 26, 2018, after the Department of Justice (DoJ) lost patience with Microsoft in Ireland. At the time, the DoJ wanted Microsoft to hand over data of a US citizen on Microsoft's cloud servers in Ireland to the DoJ. Microsoft refused to do so, citing the local data protection laws of Ireland and the EU. The DoJ then sued Microsoft in the USA and wanted to force Microsoft to hand over the data with the help of the court. The proceedings dragged on because the judges could not easily derive the DoJ's demand from the law. So the DoJ simply addressed Congress with the bill for the CLOUD Act mentioned above. At the time, the EFF (Electronic Frontier Foundation) supported Microsoft's push against the Clarifying Lawful Overseas Use of Data Act (CLOUD Act) and called on other corporate giants such as Amazon and Google to follow suit. However, the efforts of Microsoft and the EFF were unsuccessful. Microsoft ultimately had to comply with the new law and hand over the data. 

The law states that US cloud providers such as Microsoft Azure, Amazon Web Services, Gmail or Hotmail must hand over data to the US authorities on request - even if this violates local data protection laws. Providers such as Dilligent, Brainloop or E-Shares are not affected by this. The obligation to hand over data applies regardless of where the provider's servers are located and does not require a search warrant or court proceedings. The so-called CLOUD Act thus overrides national data protection laws for US providers and forces them to break them under threat of penalties.

In practice, it is almost impossible to separate the data of a US citizen from that of an EU citizen. For example, the content of an email cannot be clearly distinguished between a US and an EU citizen. As a result, the CLOUD Act means that data of EU citizens is regularly passed on to US law enforcement authorities without their knowledge.
 

In light of this problem, Microsoft is now trying to do damage limitation for its cloud products in the EU. Brad Smith, a Microsoft representative, has proposed six principles that could be implemented as amendments to the CLOUD Act in order to protect the privacy rights of all Microsoft cloud users.

Although these principles appear to be concrete measures at first glance, they are merely a wish list. They reflect measures that are currently not guaranteed and which illustrate the extent of potential data misuse under European standards such as the GDPR.

 
The required measures
 
Microsoft is calling for six measures to strengthen the data protection of its users and limit abuse under the CLOUD Act:
  1. Right to be informed: Users should be informed if their data is accessed by law enforcement authorities, except in exceptional cases such as an ongoing investigation or a threat to public security. Cloud providers should also be allowed to inform their users.

  2. Judicial review and limited access to data: Access to sensitive user data should only be permitted after examination by an independent court and should be kept to a minimum that only affects the specific case.

  3. Transparent review procedures: Cloud providers should receive sufficient information to thoroughly review requests for user data. In addition, clear legal remedies must be available to challenge unlawful or inappropriate requests.

  4. International agreements: In order to avoid legal conflicts, international agreements should be reached with third countries that provide for conflict resolution mechanisms.

  5. Control over data: Companies should have the right to control their data and receive direct requests for data release.

  6. Transparency for the public: The public must be informed about how and when US law enforcement agencies seek access to digital data and what protective measures are in place.

Although Microsoft presents these demands as measures to protect customer interests, it is clear that the CLOUD Act in its current form has created a legal vacuum. Microsoft itself has only limited options to protect its customers' data from access by US authorities. The demands illustrate how profoundly the CLOUD Act undermines data protection in accordance with European standards such as the GDPR.

 

Conclusion

The CLOUD Act does not provide any legal basis for whether and how users must be informed about access to their data, let alone whether this access is lawful at all. There are also no independent authorities or third-party bodies that could review or restrict access to data.

In his thesis paper, Brad Smith clearly shows that with the CLOUD Act, the US government has given the surveillance authorities a powerful and at the same time supranationally unlawful tool for unhindered access to data. Despite the six principles proposed by Microsoft, the current legal situation raises questions as to how different national legal systems will deal with these regulations. There has been no public discussion on this so far.

Microsoft has called on other major cloud providers such as Google and Facebook to join the theses and exert joint pressure on the US government. However, this call has so far gone unanswered. It seems that these companies have given up on the prospect of change and have instead chosen the strategy of concealing the issue from customers in order to avoid critical questions. Although Microsoft deserves credit for raising the issue, the sobering reality remains: Data stored with US cloud providers cannot be protected from access by the 17 US intelligence agencies in the long term.

Under the guise of law enforcement, far more data is presumably accessed and stored than is actually necessary or legally justified. The fundamentally different understanding of data protection in the USA is also underlined by the Patriot Act. This law also allows US authorities to access all data of US citizens and companies without the need for a court order.

While such practices are now accepted in the US, the same approach is widely rejected in Europe. The GDPR obliges European companies to guarantee the data protection of their customers, which makes the use of US cloud services virtually impossible for many data categories.

We at Loomion are keeping a close eye on developments surrounding the CLOUD Act and will continue to report. With the imminent introduction of the European «eVidence» law in response to the CLOUD Act, it will be exciting to see how this draft will actually strengthen data protection within the framework of the GDPR.

Christopher Knabe Loomion AG
Christopher Knabe

CEO Loomion AG
+41 61 500 16 25
knabe@loomion.com

icon_datalynxgroup_colored-1png
Supplementary services of the Datalynx Group