Document type: Article Practice area: Technology — Data and Privacy Jurisdiction: United States (federal) and international Last reviewed: 5 September 2026
The problem, stated plainly
A company holds data. A government wants it. The company is in one country, the data is in another, the customer is in a third, and the government is in a fourth. Every one of those jurisdictions has an opinion about whether the company may hand it over, and at least two of them have made the wrong answer a criminal offense.
This is not an exotic scenario. It is Tuesday for any cloud provider, communications platform, payment processor, or SaaS company with international customers. And the law that governs it is a genuinely difficult mixture of a 1986 statute written for bulletin board systems, a 2018 amendment that answered one question and opened others, a treaty regime that predates the internet, and a set of foreign rules designed specifically to obstruct the American ones.
The good news is that the structure is learnable, the categories are few, and most of the work is done by a decision tree that a company can build once and follow every time.
Kestrel Data Systems
Kestrel Data Systems is a Virginia-headquartered SaaS company with 2,300 employees, data centers in Ashburn, Frankfurt, and São Paulo, and customers in forty-one countries. Ingrid Ferrante-Osei is the general counsel. Marcus Delacroix-Weiss runs the law enforcement response function, which for the first four years of the company's life was Ferrante-Osei's inbox.
In one quarter, Kestrel received:
- A federal search warrant from the Eastern District of Virginia for the contents of a business customer's account, where the customer is a German company and the data sits in Frankfurt.
- A production order from a Brazilian prosecutor addressed to Kestrel's Brazilian subsidiary, seeking records of an account belonging to a United States person.
- A civil subpoena in a commercial dispute in the Northern District of Illinois, seeking a party's stored communications directly from Kestrel.
- An application under 28 U.S.C. § 1782 by a litigant in a Singapore proceeding, seeking documents and testimony from Kestrel for use abroad.
Four demands, four completely different analyses. We will take them in order after establishing the framework.
The Stored Communications Act: the tiered structure
The governing statute for United States legal process directed at a provider is the Stored Communications Act, 18 U.S.C. §§ 2701–2712 — Title II of the Electronic Communications Privacy Act of 1986.
The Act does two things at once, and confusion about which one is operating causes most of the errors in this area.
First, it prohibits disclosure. Section 2702 provides that a provider of electronic communication service to the public may not knowingly divulge the contents of a communication in electronic storage, and that a provider of remote computing service may not divulge contents carried or maintained for a subscriber. Providers are also barred from divulging non-content records about subscribers to a governmental entity. These are prohibitions with teeth: § 2707 creates a civil cause of action with statutory damages against a provider that discloses in violation of the Act.
Section 2702 then supplies exceptions — disclosure to the addressee or intended recipient, with lawful consent, as necessarily incident to the service, to a law enforcement agency where the contents were inadvertently obtained and appear to pertain to a crime, and — the exception that matters most operationally — in an emergency involving danger of death or serious physical injury to any person, where the provider in good faith believes such an emergency requires disclosure without delay.
Second, it authorizes compelled disclosure, on a tiered basis. Section 2703 sets out what process a governmental entity must use for what data:
- Basic subscriber information — name, address, records of session times and durations, length of service and types of service used, telephone or instrument number or other subscriber identity, and means and source of payment — may be obtained with an administrative subpoena, grand jury subpoena, or trial subpoena.
- Other non-content records pertaining to a subscriber — the broader transactional record — require a court order under § 2703(d), issued on specific and articulable facts showing reasonable grounds to believe the records are relevant and material to an ongoing criminal investigation.
- Contents of communications require a warrant issued under the Federal Rules of Criminal Procedure or an equivalent state warrant, on probable cause.
The Act as written contained a more complicated content scheme distinguishing communications in storage for more or less than 180 days, and permitting subpoena or § 2703(d) order with notice for older communications. That distinction has been overtaken in practice: providers as a class now require a warrant for content, the Department of Justice's stated policy is to obtain a warrant for content, and the constitutional footing for the older approach is doubtful. Advise clients on the warrant-for-content rule and treat any demand for content by subpoena as an objection to be made.
Notice and nondisclosure. Section 2705 governs both. Subsection (a) permits the government to delay notice to the subscriber in defined circumstances. Subsection (b) authorizes a court to order the provider not to notify any other person of the existence of the process, on a finding of adverse result — endangering life, flight from prosecution, destruction of evidence, witness intimidation, or otherwise seriously jeopardizing an investigation. Nondisclosure orders are the single most operationally consequential feature of this practice, because they collide directly with contractual commitments providers make to customers about notice, and because their duration is frequently indefinite in a way that has drawn sustained criticism and some judicial pushback.
Where the data sits: the CLOUD Act answer
For years the hardest question in this area was territorial: can United States process compel a provider to produce data stored on a server outside the United States?
Microsoft litigated that question to the Supreme Court over data held in Ireland, and while the appeal was pending Congress mooted it by enacting the Clarifying Lawful Overseas Use of Data Act in 2018. The CLOUD Act added 18 U.S.C. § 2713, which provides that a provider shall comply with the Act's obligations to preserve, backup, or disclose the contents of a communication and any record pertaining to a subscriber within the provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.
That is the rule, and it is clear. Location of the server is not a defense. What matters is possession, custody, or control — a concept borrowed from discovery practice and carrying its familiar difficulties in a corporate group with foreign subsidiaries.
The comity safety valve. The CLOUD Act paired that rule with a mechanism, added at § 2703(h), permitting a provider to file a motion to quash or modify legal process where the provider reasonably believes that the customer or subscriber is not a United States person and does not reside in the United States, and that the required disclosure would create a material risk that the provider would violate the laws of a qualifying foreign government. The court then conducts a comity analysis weighing the interests of the United States and the foreign government, the customer's connection to each, the provider's ties, the importance of the information to the investigation, and the availability of alternative means.
The practical limitation is in the phrase "qualifying foreign government," which means a government that has entered an executive agreement with the United States under the CLOUD Act's other principal provision. Where no such agreement exists, the statutory comity motion is unavailable, and a provider facing a genuine legal conflict is left to common-law comity arguments and to the practical negotiation with the prosecutor that resolves most of these situations in reality.
Executive agreements. The CLOUD Act's second half, at 18 U.S.C. § 2523, authorizes the Attorney General, with the Secretary of State's concurrence and certification to Congress, to enter bilateral executive agreements with foreign governments meeting substantive and procedural rights requirements. The effect is to lift the § 2702 disclosure bar for orders issued by that government, so that a qualifying foreign government may serve orders directly on United States providers for data relating to its own investigations, without going through mutual legal assistance. These agreements are the intended long-run solution to the whole problem, and their number is growing but limited. Check the current list; it changes.
MLATs: the slow default
Where no executive agreement exists, the formal route for a foreign government seeking data from a United States provider is a mutual legal assistance treaty request. The requesting state's central authority transmits a request to the United States Department of Justice's Office of International Affairs, which if it accepts the request obtains United States legal process — a § 2703(d) order or a warrant — and serves it on the provider. The data comes back through the same channel.
The system works and it is slow. Timelines measured in many months are ordinary, and for a fast-moving investigation the delay is often dispositive. That is precisely why foreign authorities try direct routes: serving a local subsidiary, using local production orders with extraterritorial reach, or applying pressure through local regulatory levers.
For providers, the important thing is to recognize an MLAT-derived demand for what it is. When United States process arrives that seems oddly disconnected from any United States investigation, it may well be an MLAT request. That does not change the provider's obligation — the process is valid United States process — but it changes the context, and in particular it means the underlying foreign investigation may be subject to constraints the United States order does not reflect.
Demand one: the Virginia warrant for German data
Kestrel's first demand was a § 2703(a) warrant from the Eastern District of Virginia for the contents of a German business customer's account, stored in Frankfurt.
The analysis. Under § 2713, the location of the data in Frankfurt is not a defense; Kestrel has possession, custody, and control. The warrant is facially valid, issued by a court of competent jurisdiction, on probable cause. The default answer is that Kestrel must comply.
The complication is that the customer is a German company whose data is subject to European data protection law, and Article 48 of the GDPR provides that a judgment or decision of a third-country authority requiring a controller or processor to transfer or disclose personal data is recognized or enforceable only if based on an international agreement such as a mutual legal assistance treaty. Read strictly, Article 48 says the American warrant is not by itself a lawful basis for the disclosure. European regulators have taken that position with some force.
What Kestrel actually did, and what most providers do, has three parts.
First, scope reduction. Delacroix-Weiss's team reviewed the warrant against the account and identified that a substantial portion of what it covered was outside the described offense conduct and outside the date range in the supporting affidavit. Counsel engaged the Assistant United States Attorney and negotiated a narrowed production. This is the single most effective step in the entire practice and it is available in the great majority of cases — prosecutors generally want the relevant material, not the maximum material, and a provider that engages substantively gets a hearing.
Second, the comity assessment. Kestrel evaluated whether a § 2703(h) motion was available. It was not, on these facts, because the analysis turns on the customer not being a United States person and on the existence of a qualifying foreign government agreement. Counsel documented the analysis anyway, because the documentation is what demonstrates good faith to a European regulator later.
Third, notice. The warrant came with a § 2705(b) nondisclosure order, so Kestrel could not tell the customer. The company's terms of service commit it to notify customers of legal process "except where prohibited by law," which is the clause every provider needs and many do not have. Kestrel calendared the nondisclosure order's expiration and notified the customer when it lapsed.
The honest summary for a client in this position: the conflict between United States compulsion and European restriction is real, it is not resolved, and it is managed rather than solved. Comply with valid United States process, narrow it aggressively, document the analysis, and give the customer notice as soon as you lawfully can.
Demand two: the Brazilian order served on the subsidiary
Kestrel's second demand was a production order from a Brazilian prosecutor, served on Kestrel Brasil Ltda., seeking records of an account belonging to a United States person and stored in Ashburn.
This is the mirror image of the first problem, and it is the fact pattern that has produced the sharpest confrontations in this area — foreign authorities using pressure on a local subsidiary, including fines and in some documented instances the detention of local executives, to compel production of data held by the United States parent.
The legal difficulty. Section 2702 prohibits Kestrel from divulging the contents of communications, and prohibits divulging non-content subscriber records to a governmental entity. The prohibition is not limited to United States governmental entities in the way clients often assume. A provider that hands over content to a foreign prosecutor without a recognized basis is exposed under § 2707, and the exception structure of § 2702 does not contain a general "foreign law required it" carve-out.
The available paths.
An executive agreement, if one exists with that country under 18 U.S.C. § 2523, lifts the § 2702 bar for qualifying orders. This is the clean answer and it is available for a growing but still limited set of countries.
An MLAT request, which converts the foreign demand into United States process. Slow, and often the right recommendation to make to the foreign authority.
Consent. Section 2702 permits disclosure with the lawful consent of the originator, addressee, or intended recipient, or of the subscriber in the case of remote computing service. Where the account holder will consent, the problem dissolves.
The emergency exception, where there is a good-faith belief that an emergency involving danger of death or serious physical injury requires disclosure without delay. This is real and is used, and it is also the exception most likely to be stretched. Document the basis contemporaneously.
Non-content, non-governmental-entity distinctions, which occasionally matter but rarely resolve the case.
The structural answer, which is not legal. Companies in this position invest in corporate structure and data architecture: keeping the local subsidiary genuinely without possession, custody, or control of the parent's data; ensuring local personnel have no technical ability to produce it; and documenting that separation in advance. Whether that is respected by a foreign authority under pressure is a different question, but it is the only durable protection, and it must be built before the demand arrives.
What Kestrel did. It responded to the Brazilian prosecutor explaining, in Portuguese, with local counsel, that the data was held by the United States entity, that United States law prohibited the local entity from producing it, and identifying the mutual legal assistance route. It also notified the account holder, because no United States nondisclosure order applied and the terms of service required it. The matter proceeded through MLAT and took eleven months.
Demand three: the civil subpoena
Kestrel's third demand was a subpoena under Federal Rule of Civil Procedure 45 in a commercial case, served by a private litigant, seeking a party's stored communications from Kestrel.
The answer is short and it surprises litigators every time: the Stored Communications Act generally bars it. Section 2702 prohibits a provider from divulging the contents of communications, and the exceptions do not include "a civil subpoena." Courts have consistently held that a civil litigant cannot use Rule 45 to obtain content from a provider, because the Act contains no exception for civil discovery. The prohibition on disclosing non-content records to a governmental entity does not by its terms reach private litigants, and practice on non-content records is accordingly more varied — but content is off the table.
What the litigant should do instead, and what a provider's objection letter should say, is that the data must be sought from the party through ordinary discovery. A party in possession of its own communications can be compelled to produce them under Rule 34 and Rule 26, and if the party's account is with a provider, the party can obtain and produce its own data or consent to the provider's disclosure. Consent under § 2702 is the mechanism, and it is routine.
For the provider, this is a template response, not a bespoke analysis. Kestrel's objection letter cites the Act, explains the consent path, and offers to preserve pending resolution. It goes out the same day, and it has never been successfully challenged.
Two caveats. First, preservation is a different question from production: a provider that receives notice of litigation may have preservation obligations even where it cannot produce. Second, the Act's bar protects the provider, not the party — a party who tries to use the Act to shield its own communications from discovery in its own case will not be heard sympathetically.
Demand four: the section 1782 application
Kestrel's fourth demand arose from an application under 28 U.S.C. § 1782, which authorizes a district court to order a person residing or found in the district to produce documents or give testimony for use in a proceeding in a foreign or international tribunal, on the application of an interested person.
Section 1782 is a genuinely powerful tool. It permits a foreign litigant to obtain American-style discovery, from a person in the United States, for use abroad, without any requirement that the material be discoverable under foreign law and without a foreign court's request.
What changed. In ZF Automotive US, Inc. v. Luxshare, Ltd., 596 U.S. 619 (2022), the Supreme Court held that "foreign or international tribunal" in § 1782 means a governmental or intergovernmental adjudicative body — a body imbued with governmental authority by one or more nations. Private commercial arbitration panels do not qualify. The decision resolved a long-running circuit split and materially narrowed the statute's reach, closing off what had become a common route for parties in international commercial arbitration to obtain United States discovery.
The framework that remains. A § 1782 application requires that the person from whom discovery is sought reside or be found in the district, that the discovery be for use in a proceeding before a qualifying tribunal, and that the applicant be an interested person. Even where those statutory requirements are met, the district court retains discretion, guided by factors that include whether the person is a participant in the foreign proceeding, the nature of the foreign tribunal and its receptivity to United States judicial assistance, whether the request conceals an attempt to circumvent foreign proof-gathering restrictions, and whether the request is unduly intrusive or burdensome.
For a provider, § 1782 does not defeat the Stored Communications Act. A § 1782 order is a court order, but it is not one of the mechanisms § 2703 authorizes for compelled content disclosure, and § 2702's prohibition applies. The provider's response is the same as to a civil subpoena: content cannot be produced without consent or qualifying process. Non-content material and the provider's own business records are a different matter and may well be producible.
Kestrel's response distinguished the two categories, produced its own business records regarding the account relationship, and declined content on § 2702 grounds while identifying the consent path.
Civil discovery abroad, and the comity question
Section 1782 runs one direction. The other direction — a United States litigant seeking evidence located abroad — raises its own conflict.
Société Nationale Industrielle Aérospatiale v. United States District Court, 482 U.S. 522 (1987) is the governing decision. The Court held that the Hague Evidence Convention provides optional procedures, not exclusive ones, and does not deprive a district court of jurisdiction to order a party subject to its jurisdiction to produce evidence located abroad. Whether to use Convention procedures instead is committed to the court's discretion, guided by a comity analysis: the importance of the documents to the litigation, the specificity of the request, whether the information originated in the United States, the availability of alternative means, and the extent to which noncompliance would undermine important interests of the United States or of the state where the information is located.
Blocking statutes are the foreign response. France's is the best known, and several other states have enacted similar measures prohibiting the production of certain categories of information to foreign authorities or in foreign proceedings. Courts applying Aérospatiale have been notably unimpressed by blocking statutes that are not enforced domestically, and a party invoking one is generally expected to show a real risk of prosecution rather than the theoretical existence of a prohibition. That said, the risk is not always theoretical, and the analysis has become more sympathetic where the foreign restriction is a data protection rule of general application rather than a statute aimed at foreign discovery.
Practical advice for a party caught between. Raise the conflict early and specifically. Offer alternatives — Hague Convention procedures, production in the foreign jurisdiction, anonymization, a protective order that satisfies the foreign concern. Document good-faith efforts to obtain foreign authorization. A party that engages the conflict looks different to a court than one that asserts a blocking statute and stops.
National security process, which follows different rules
A distinct set of demands operates outside the framework above.
National security letters are administrative demands issued by the FBI, without prior judicial approval, for certain categories of non-content records — subscriber and transactional information from communications providers, financial records, and consumer credit information. They come with nondisclosure requirements subject to a reciprocal notice and judicial review procedure added by statute. Providers may challenge them, and a number have.
FISA process. 50 U.S.C. § 1881a authorizes the targeting of non-United States persons reasonably believed to be located outside the United States to acquire foreign intelligence information, with directives to providers to assist. Orders for business records and other FISA authorities have their own procedures before the Foreign Intelligence Surveillance Court.
What a provider needs to know operationally. These demands go to a specifically cleared team, not to the general legal process queue. Nondisclosure is more restrictive and longer-lasting than under § 2705. Transparency reporting about them is limited to bands and ranges specified by statute and agreement, and reporting outside those constraints is itself unlawful. And their existence is the reason foreign regulators are skeptical of transfers to United States providers, which links this practice area directly to the transfer-mechanism analysis that privacy teams run separately.
The Fourth Amendment overlay
Underneath the statutory scheme sits a constitutional question that has been moving.
Carpenter v. United States, 585 U.S. 296 (2018) held that the government's acquisition of historical cell-site location information from a wireless carrier is a Fourth Amendment search, and generally requires a warrant supported by probable cause. The Court declined to extend the third-party doctrine — under which information voluntarily conveyed to a third party carries no reasonable expectation of privacy — to the comprehensive, retrospective, and effectively involuntary record of a person's movements that cell-site data represents.
Carpenter was expressly narrow, and the Court disclaimed any view on other business records or on real-time surveillance techniques. But its reasoning has been pressed in litigation over every comparable category of digital record, and the direction of travel matters to providers because it shapes what process courts will demand and what challenges are worth supporting.
For a provider's practice, the operational takeaway is conservative and simple: require a warrant for content, require a warrant for location data, scrutinize § 2703(d) orders that seek categories of information approaching Carpenter's concerns, and be willing to litigate where the process does not match the sensitivity of the data.
Building the response program
A company that receives more than a handful of these demands needs a function, not a lawyer with an inbox.
A single intake point, published, with a defined address for service. Demands arriving at sales offices, support queues, or individual employees are how deadlines get missed.
A trained first-line team that validates every demand: is it facially valid; is it issued by a court or authority with jurisdiction; is it the right type of process for the data sought; is the account identified correctly; is the scope defined; is there a nondisclosure order and what does it actually prohibit.
A decision tree that routes by demand type — United States criminal process, foreign government demand, civil subpoena, § 1782 application, national security process, emergency request — and specifies who handles each.
An escalation path to counsel with defined triggers: content demands, foreign conflicts, novel process, anything touching a high-profile account, and every national security matter.
Emergency request handling, twenty-four hours a day, with a documented good-faith assessment. Emergencies are real; the exception is also the most abused route into a provider's data, and the record of the assessment is what protects the company.
Scope negotiation as a standard step, not an exception. Most demands are broader than the investigation requires, and most issuing authorities will narrow them when asked by someone who has read the affidavit.
Notice to the customer as the default, subject to legal prohibition — with the terms of service written to permit exactly that, and with a calendar entry to notify when a nondisclosure order expires.
Preservation on request, tracked separately from production. Preservation letters are cheap for the government to send and easy for a provider to lose track of.
Logging and transparency reporting, because the numbers will be asked for by customers, regulators, and eventually a journalist.
An annual review of the whole function against volumes, error rates, and the current legal landscape — which in this area changes materially every couple of years.
The enterprise customer's side of the table
Most of this article is written from the provider's chair. The customer whose data is being sought has its own set of moves, and they are frequently neglected because the customer does not learn about the demand until late — or at all.
Negotiate the notice clause before you sign. A cloud contract should commit the provider to notify the customer of legal process seeking the customer's data, promptly, unless legally prohibited; to provide the process itself; to give the customer a reasonable opportunity to seek protective relief before production; and to produce the narrowest set responsive to the demand. Providers resist parts of this, particularly a hard waiting period, and a negotiated version is achievable.
Know where your data lives and who controls it. The question that matters under the CLOUD Act is possession, custody, and control, not geography. A customer that has architected for data residency without understanding the control question has bought comfort rather than protection.
Understand that you, not the provider, are usually the better target. Because § 2702 blocks civil discovery of content from providers, a civil litigant seeking your communications will subpoena you. The provider's inability to produce is not a shield for the customer; it just relocates the fight. Plan your own discovery posture accordingly.
Ask for the transparency report and the process. During vendor diligence, ask how many demands the provider received, how many it rejected or narrowed, whether it has litigated a nondisclosure order, and what its escalation path is. A provider that has thought about this answers crisply. One that has not gives you the answer you need.
Build the internal escalation. When a provider notifies you of a demand touching your data, you have days — sometimes fewer — to decide whether to intervene, move to quash, or negotiate scope with the issuing authority. Decide in advance who makes that call.
Consider encryption and key management honestly. A provider that does not hold the keys cannot produce readable content, and that is a real architectural answer to a real risk. It is also an answer with operational costs, and it does not affect metadata, which is frequently what is actually sought. Do not oversell it internally as a solution to a problem it only partially addresses.
Wiretaps, pen registers, and real-time collection
Everything above concerns stored data. Real-time collection runs on a separate and more demanding track, and providers receive these demands too.
Content interception — a wiretap — is governed by the Wiretap Act, and 18 U.S.C. § 2518 sets out the procedure: an application by a specified official, a judicial finding of probable cause, a showing that normal investigative procedures have been tried and failed or are unlikely to succeed or are too dangerous, minimization requirements, a limited duration with extensions, and sealing and inventory obligations. This is the most demanding process in the criminal law, deliberately so, and providers assisting with interception are compensated and subject to specific technical assistance obligations.
Non-content real-time collection — dialing, routing, addressing, and signaling information — is governed by the pen register and trap-and-trace provisions. Section 3123 requires a court order on a certification by the applicant that the information likely to be obtained is relevant to an ongoing criminal investigation. The standard is materially lower than probable cause, and the orders are correspondingly common.
Why this matters for a provider's intake process. Real-time demands have short fuses, technical implementation requirements, and their own nondisclosure rules. They cannot be routed through the same queue as a subscriber-information subpoena. A provider that is technically capable of interception needs a cleared, trained team and a documented implementation procedure; a provider that is not needs to be able to say so, precisely, in a response.
And the cross-border version is worse. Real-time collection touching foreign users, foreign infrastructure, or foreign personnel raises every conflict discussed above with none of the time available to work through it. Decide the policy in advance.
Preservation, which is separate from production
Section 2703(f) permits a governmental entity to require a provider to preserve records and other evidence pending the issuance of legal process, for an initial period of 90 days, extendable for an additional 90 days on renewed request.
Preservation requests are cheap to send and easy to mishandle, and three practices matter.
Preserve narrowly and precisely. A preservation request identifying an account should not result in the preservation of an entire tenant's environment. Over-preservation creates cost, creates a repository that will be sought in later litigation, and can conflict with deletion commitments made to customers and with data minimization obligations under privacy law.
Track the expiry. A preservation obligation that no one has released does not last forever, and a preserved dataset held indefinitely without legal basis is a liability. Calendar the 90-day period and the extension, and release on expiry unless renewed or superseded by process.
Understand what preservation is not. It is not production, it is not notice to the customer that anything has happened, and it does not itself carry a nondisclosure obligation unless one is separately imposed. Providers frequently conflate these and either notify when they should not or stay silent when they need not.
And note the interaction with deletion requests. A customer exercising a deletion right under privacy law, for an account subject to a preservation request, creates a genuine conflict. The answer is usually to suspend deletion of the preserved material, document the legal basis, and complete the deletion when the preservation obligation ends — but the workflow has to exist before the request arrives, because the privacy team and the legal process team are usually different people looking at different systems.
What to tell the client
Five things, in this order.
One: location does not decide it. Under the CLOUD Act, a United States provider must produce data within its possession, custody, or control regardless of where it sits. Data localization can serve other purposes; it is not a shield against United States process.
Two: the conflict is real and it is managed, not solved. European law says an American warrant is not a lawful basis for disclosure; American law says produce. Providers live in that gap by narrowing scope, documenting analysis, and giving notice when they can.
Three: the type of process matters more than anything else. Subscriber information, transactional records, and content sit on three different tiers under § 2703, and getting the tier wrong is the most common defect in the demands you will receive.
Four: civil litigants cannot get content from you. Section 2702 says so, there is no civil discovery exception, and the answer is a template letter pointing to consent and to the party.
Five: build the function before you need it. Every serious failure in this area — the missed nondisclosure order, the over-broad production, the disclosure to a foreign authority without a basis, the emergency request nobody documented — traces to a company that was handling demands ad hoc when the volume outgrew the improvisation.
Related documents
- Responding to a Cross-Border Data Demand: A Practical Guide
- Cross-Border Data Demand Response Checklist: A Practical Checklist
- Government Data Demand Toolkit: Legal Process Review, Objections, and Notification
- International Data Transfers After Schrems II: Standard Contractual Clauses and Transfer Impact Assessments
- Privacy and Data Protection Toolkit: Building and Running a Privacy Program
- Cross-Border IP Litigation and Service Toolkit: A Roadmap and Resource Library for International Disputes
This article is general information, not legal advice, and does not create an attorney-client relationship.
