Document type: Checklist Practice area: Technology — Data and Privacy Jurisdiction: United States (federal) and international Last reviewed: 5 September 2026
Part 1 — Threshold: do the rules apply to us?
Determine this once, in writing, before the first demand.
- Which of our services are electronic communication services?
- Which are remote computing services? (Definitions at 18 U.S.C. § 2711 and in the Wiretap Act.)
- Which are offered to the public?
- Which are neither, such that the Stored Communications Act does not apply?
- Determination recorded, with reasoning, by counsel.
- Revisit when the product changes — a new messaging or storage feature can move a service across the line.
- Separately identify our own business records (contracts, invoices, account-opening documents), which the Act does not shield and which we should not over-refuse.
Part 2 — Intake
- Single published service address — email and physical — listed on the website and in the terms of service.
- Front line trained across support, sales, and reception: forward it, do not respond to it.
- Every demand logged on receipt: date, method, issuing authority, country, process type, account identifiers, deadline, nondisclosure order present?
- Internal service level set (e.g. acknowledged in 1 business day, validated in 2, routed in 3).
- Case management system in place — not a spreadsheet, once volume is real.
Part 3 — Validation (roughly a third of demands fail something here)
- Facially valid: signed, dated, complete, attachments present, identifiable issuing authority.
- Issuing authority has jurisdiction over us.
- Right process for the data sought under 18 U.S.C. § 2703:
- Basic subscriber information — subpoena sufficient.
- Other non-content records — court order on specific and articulable facts.
- Contents — warrant on probable cause. A subpoena for content is defective; object.
- Account correctly identified and verified to exist.
- Scope defined: date range, data categories, account limits.
- Nondisclosure order present? Read what it actually prohibits and for how long.
- Return date realistic; extension sought if not.
- Is this a preservation request rather than a production demand? Different obligation.
- Validation form completed and filed.
Part 4 — Route by type
- US criminal process — warrant, § 2703(d) order, subpoena, pen register, wiretap. Response team; escalate content, novel process, high-profile accounts.
- Foreign government demand — always escalate to counsel.
- Civil subpoena — template objection; content cannot be produced.
- Section 1782 application — escalate; content bar still applies.
- Emergency request — 24-hour handling, verification, documented assessment.
- National security process — designated recipient only; never the general queue.
- Decision tree exists on one page where the team can see it.
Part 5 — Scope negotiation (do this every time)
- Demand read against the actual account — how much is genuinely within the described conduct and period?
- Issuing authority called, not written to first.
- Specific narrowing proposed: date range, categories, accounts.
- Alternatives offered: non-content instead of content, targeted export instead of full image, staged production.
- Agreed narrowing confirmed in writing and filed.
- Escalate only if negotiation fails.
Part 6 — Foreign government demands
- Identify who was served and whether that entity has possession, custody, or control of the data.
- Apply the § 2702 bar — it is not limited to United States authorities; exposure runs under § 2707.
- Is there a CLOUD Act executive agreement with that country? (Check the current list.) If so, a qualifying order may be honored directly.
- Will the account holder consent? Consent under § 2702 dissolves the problem.
- Does the emergency exception apply? Document contemporaneously.
- Otherwise refer to mutual legal assistance, in the local language, through local counsel.
- Local counsel engaged immediately wherever the company has an entity or personnel exposed.
- Contemporaneous memorandum of the conflict, the analysis, and the path chosen.
- Longer term: corporate and technical separation so the local entity genuinely lacks control — built before the demand arrives.
Part 7 — Civil subpoenas and section 1782
Civil subpoena:
- Section 2702 bars production of content to a private litigant; no civil discovery exception.
- Template objection sent same day: the Act prohibits it; seek it from the party under Rule 34 and Rule 26; we will produce on the account holder's lawful consent; we will preserve pending resolution.
- Non-content records analyzed separately — practice varies as against private parties.
- Our own business records distinguished and produced where properly demanded.
- Preservation obligations assessed independently of production.
Section 1782 (28 U.S.C. § 1782):
- Is the tribunal qualifying? After ZF Automotive US, Inc. v. Luxshare, Ltd., 596 U.S. 619 (2022), it must be a governmental or intergovernmental adjudicative body. Private commercial arbitration does not qualify.
- Respondent resides or is found in the district; material for use in the proceeding; applicant is an interested person.
- Discretionary factors addressed: participation in the foreign proceeding, receptivity of the tribunal, circumvention of foreign restrictions, burden.
- Content still barred — a § 1782 order is not § 2703 process. Separate business records from content in the response.
Part 8 — Emergency requests
- 24-hour coverage with a named on-call responder.
- Standard form required: agency, named officer with agency contact details, nature of the emergency, the specific danger, why disclosure cannot wait, specific data sought.
- Requester independently verified — call back on a number from the agency's own public directory, never from the request. This defeats the great majority of fraudulent requests.
- Good-faith assessment recorded in writing by a named person before disclosure.
- Disclosure narrowed to what the emergency requires.
- Counsel review of every emergency disclosure within a week.
- Customer notified afterwards where lawful and appropriate.
- Responders trained to refuse requests that do not describe danger of death or serious physical injury, however urgent the tone.
Part 9 — Nondisclosure orders and customer notice
- Order read precisely: what is prohibited, to whom, for how long (18 U.S.C. § 2705(b)).
- Do not over-comply — an order barring notice to the subscriber does not bar internal communication, counsel, or aggregate transparency reporting.
- Expiry calendared; customer notified when the order lapses.
- Indefinite orders flagged for a possible challenge.
- Terms of service contain the necessary clause: notify except where prohibited by law or counterproductive to an emergency.
- Notification template ready and consistent.
Part 10 — Preservation
- Section 2703(f) preservation: 90 days, extendable once on renewed request.
- Preserve narrowly — an account request does not freeze a tenant environment.
- Expiry and any extension calendared; released on expiry unless renewed or superseded.
- Preservation tracked separately from production.
- Understood: preservation is not production, does not authorize notice, and does not itself require silence.
- Deletion-request conflict workflow exists — privacy team and legal process team can see each other's queues.
Part 11 — Production
- Only what the demand covers, as narrowed.
- Second reviewer checks the export against the demand's scope before it goes. Over-production is irreversible.
- Third-party data identified; filtered where permitted, flagged where not.
- Secure channel used; receipt confirmed.
- Cover letter states what was produced, the narrowed scope, what was withheld and why, and preserves objections.
- Production copy retained.
- Completion logged: date, scope, method, recipient, approver.
Part 12 — Deciding to challenge
- Wrong process for the data — object; usually resolves without litigation.
- Unbounded scope after negotiation failed.
- Comity motion where a foreign legal conflict is real — the CLOUD Act mechanism at § 2703(h) where the customer is a non-United States person and a qualifying foreign government's law is implicated; otherwise common-law comity informed by Société Nationale Industrielle Aérospatiale v. United States District Court, 482 U.S. 522 (1987).
- Indefinite nondisclosure order.
- Sensitivity mismatch — Carpenter v. United States, 585 U.S. 296 (2018) requires a warrant for historical cell-site location information and its reasoning is pressed for comparable categories.
- Cost, delay, and relationship weighed honestly.
- Objection framed as process, not investigation, and always states the path forward.
Part 13 — Real-time collection
- Position decided in advance: are we technically capable, and to what extent?
- Wiretap orders under 18 U.S.C. § 2518 recognized as a distinct and far more demanding track.
- Pen register / trap-and-trace orders under 18 U.S.C. § 3123 recognized as a lower-threshold, higher-volume category.
- Named, trained implementation team; need-to-know perimeter defined before engineering involvement.
- Cross-border policy written for real-time collection touching foreign users, infrastructure, or personnel.
- Technical assistance response template ready: what we can do, format, timeline, cost, notice.
Part 14 — National security process
- Designated recipient with an alternate, cleared where required.
- Intake staff trained to recognize and escalate without reading further.
- Separate, separately secured file — not the general case management system.
- Experienced outside counsel engaged from the first minute.
- FISA authorities and national security letters understood as distinct tracks with distinct nondisclosure regimes.
- Transparency reporting only within permitted bands — reviewed before every publication.
- Privacy team and legal process team connected, because this is the substance of every transfer impact assessment the company writes.
Part 15 — Contract terms the program depends on
- Notification clause — prompt notice of legal process, except where prohibited by law or counterproductive to an emergency.
- Narrow-production commitment.
- Opportunity to object before production, subject to the demand's deadline.
- Cost allocation for responding, and for litigating at the customer's request.
- Data location and control disclosure — without implying residency is a legal shield; under the CLOUD Act, possession, custody, and control governs.
- Transparency reporting reservation.
Part 16 — Program build-out and annual review
- Function staffed as a specialist role, not a rotation.
- Templates in place: acknowledgment, validation form, objection letters by type, scope negotiation email, production cover letter, customer notification, emergency request form.
- Transparency report published: by type and country, accounts affected, complied in full / in part / rejected, narrowed. Report the rejection rate.
- Annual review of volumes, error rates, turnaround, the decision tree against current law, the terms of service clause, and the executive agreement country list.
- Position stated clearly from the top: require the right process for the data, produce what is properly demanded, notify the customer when lawful.
Part 17 — Diagnosing a function that grew without a plan
- Where do demands actually arrive today? Audit the last twelve months across all inboxes.
- How many were never logged?
- Any content produced on less than a warrant?
- Any content produced to a foreign authority without consent, an executive agreement, or an emergency basis?
- Any nondisclosure order whose expiry passed with no customer notice?
- Any preservation held past its window with no legal basis?
- Any emergency disclosure with no documented assessment?
- Any national security matter handled in the general queue?
- Is the terms of service notification clause actually in the current form?
- Fix in order: intake first, validation second, emergency verification third, everything else after.
Related documents
- Cross-Border Government Demands for Data: The Stored Communications Act, the CLOUD Act, and MLATs
- Responding to a Cross-Border Data Demand: A Practical Guide
- Government Data Demand Toolkit: Legal Process Review, Objections, and Notification
- International Data Transfers After Schrems II: Standard Contractual Clauses and Transfer Impact Assessments
- Privacy Compliance Program Checklist: A Practical Checklist
- Cloud and SaaS Agreements: Service Levels, Data Rights, Security, and Exit
This checklist is general information, not legal advice, and does not create an attorney-client relationship.
