Document type: Guide Practice area: Technology — Data and Privacy Jurisdiction: United States (federal) and international Last reviewed: 5 September 2026
Who this is for
The person inside a company who has just been handed a government demand for customer data and does not have a process — or the person who has a process and is discovering that it does not survive the second country.
Our example is Solstice Ledger, a payments infrastructure company with 800 employees, customers in twenty-six countries, and processing in Virginia, Dublin, and Singapore. Yevgenia Marchetti-Obi is the deputy general counsel. Last year Solstice received nine demands, all handled by her. This year it is on pace for two hundred and thirty, and three of the first thirty came from authorities in countries where Solstice has no entity, no lawyer, and no idea what the process means.
The steps below are the ones she used to build the function.
Step 1 — Create a single intake point
Publish a service address. A dedicated email address and a physical address for service, listed on the website and in the terms of service. Demands that arrive at a sales representative, a support queue, or a named executive are how deadlines get missed.
Route everything to one place. Every demand — subpoena, warrant, court order, foreign production order, preservation letter, emergency request — lands in the same queue regardless of how it arrived. Train the front line: anyone who receives a document that looks like legal process forwards it immediately and does not respond.
Log it on receipt. Date received, method, issuing authority, country, type of process, account identifiers, response deadline, and whether a nondisclosure order accompanies it. This log becomes the transparency report and the audit trail.
Set an internal service level. Solstice's is: acknowledged within one business day, validated within two, routed within three.
Step 2 — Validate before you do anything else
Roughly a third of demands have a defect that matters. Run the same validation pass every time.
- Is it facially valid? Signed, dated, issued by an identifiable authority, and complete. Attachments present.
- Does the issuing authority have jurisdiction over us? A state court subpoena from a state where the company has no presence is a different problem from a federal warrant.
- Is it the right type of process for the data sought? This is the highest-value check. Under 18 U.S.C. § 2703, basic subscriber information may be obtained by subpoena; other non-content records require a court order on specific and articulable facts; contents require a warrant. A subpoena seeking content is defective and the objection is straightforward.
- Is the account correctly identified? Wrong identifiers are common. Verify the account exists and belongs to whom the demand assumes.
- Is the scope defined? Date ranges, data categories, and account limits. An undefined scope is a scope objection.
- Is there a nondisclosure order? If so, read what it actually prohibits and for how long. Do not assume it bars notice to the customer forever; many do not.
- Is there a return date, and is it realistic? Extensions are usually available for the asking.
- Is this a preservation request rather than a production demand? Different obligation entirely.
Document the validation. A short standard form completed on every demand. It is the record that shows the company applied a process rather than reacting.
Step 3 — Route by demand type
Build the decision tree once. Solstice's has six branches.
Branch 1 — United States criminal process. Warrant, § 2703(d) order, grand jury or trial subpoena, pen register order, wiretap order. Handled by the response team; escalated to counsel for content demands, novel process, or high-profile accounts.
Branch 2 — Foreign government demand. Any order issued by a non-United States authority, however served. Always escalated to counsel. The § 2702 disclosure prohibition applies and the exceptions are narrow.
Branch 3 — Civil subpoena or civil discovery. Private litigant. Template objection under the Stored Communications Act; content cannot be produced.
Branch 4 — Section 1782 application. Foreign litigant seeking discovery through a United States court under 28 U.S.C. § 1782. Escalate to counsel; the Act's bar on content disclosure still applies.
Branch 5 — Emergency request. Voluntary disclosure sought under the emergency exception. Twenty-four-hour handling, documented good-faith assessment, senior sign-off.
Branch 6 — National security process. National security letters and FISA process. Routed to a specifically designated and, where required, cleared individual. Never discussed outside that channel.
Write the tree on one page and put it where the team can see it. The purpose is that a person receiving a demand at 4:45 on a Friday knows within ninety seconds which branch it is.
Step 4 — Negotiate scope, every time
This is the step that resolves more demands than everything else in this guide combined, and it is the step companies skip.
Read the demand against the account. How much of what is demanded actually relates to the described conduct and time period? In most cases, considerably less than all of it.
Call the issuing authority. Not to refuse — to narrow. Prosecutors and investigators generally want relevant material, not maximum material, and a provider that engages substantively and proposes a targeted production is usually met halfway. Offer specifics: a narrower date range, defined data categories, the accounts actually implicated.
Propose alternatives. Non-content records instead of content where they would answer the investigative question. A targeted export instead of a full account image. A staged production.
Get the narrowing in writing. An email confirming the agreed scope, attached to the file.
Escalate only when negotiation fails. Litigation is expensive, slow, and occasionally necessary. Most demands do not require it.
Solstice's experience after six months of doing this systematically: 41% of demands were narrowed by agreement, average production volume fell by more than half, and not one narrowing negotiation resulted in a motion to compel.
Step 5 — Handle the nondisclosure order
Nondisclosure orders under 18 U.S.C. § 2705(b) collide directly with what a company has told its customers, and this is where reputational damage happens.
Read the order precisely. What does it prohibit — notifying the subscriber, notifying anyone, acknowledging the existence of the process? For how long? Indefinite orders exist and are contestable.
Do not over-comply. An order barring notice to the subscriber does not bar the company from reporting the demand in aggregate transparency numbers, or from telling its own counsel, or from telling the individuals inside the company who need to know. Over-compliance is a real and common failure that costs the company its own ability to manage the matter.
Calendar the expiry. The single most useful operational practice here. When the order lapses, notify the customer. Companies that do this consistently earn credibility that companies making general privacy promises do not.
Consider challenging an indefinite order. Courts have become more receptive to arguments that a nondisclosure order must be tailored in duration and supported by particularized findings. Whether to litigate is a business decision, but a company should know the argument exists.
Make sure the terms of service permit the position you are taking. The clause you need commits the company to notify customers of legal process except where prohibited by law or where notice would be counterproductive to an emergency. Without it, you are either breaching the contract or breaching the order.
Step 6 — Handle a foreign government demand
Escalate every one of these. The analysis has a fixed shape.
Identify who was served and what they control. A demand served on a foreign subsidiary for data held by the United States parent is the hard case. Establish, in writing, whether the served entity has possession, custody, or control of the data. If it does not — and if that separation is genuine and was built deliberately — say so precisely.
Apply the § 2702 bar. Section 2702 prohibits disclosure of the contents of communications, and prohibits disclosure of non-content subscriber records to a governmental entity. The prohibition is not limited to United States authorities. A provider that produces content to a foreign prosecutor without a recognized basis is exposed under § 2707, which creates a civil action with statutory damages.
Then work through the available paths, in order:
- Is there a CLOUD Act executive agreement with that country? If so, a qualifying order may be served directly and the § 2702 bar is lifted for it. Check the current list; it grows.
- Will the account holder consent? Section 2702 permits disclosure with lawful consent. In business-to-business contexts consent is often obtainable and dissolves the problem entirely.
- Does the emergency exception apply? Good-faith belief of an emergency involving danger of death or serious physical injury. Document the assessment contemporaneously.
- Is the material non-content and the requester arguably not a governmental entity for the relevant prohibition? Rarely dispositive, but worth analyzing.
- Otherwise, refer to mutual legal assistance. Respond in the local language, through local counsel, explaining the United States legal prohibition and identifying the MLAT route.
Engage local counsel immediately in any country where the company has an entity or personnel exposed. Enforcement pressure in these matters has, in documented instances, extended to fines against the local entity and to action against local executives. That risk drives the response more than the doctrine does.
Document the conflict. A contemporaneous memorandum explaining the legal bind, the analysis performed, and the path chosen is what protects the company later — with a foreign regulator, with a court, and with its own customers.
Step 7 — Handle the civil subpoena
This is a template, not a project.
The Stored Communications Act generally bars production of content to a civil litigant. Section 2702 prohibits disclosure and contains no civil discovery exception. Courts have consistently so held.
The objection letter says three things: the Act prohibits the disclosure sought; the material must be obtained from the party, whose own communications are discoverable under Rule 34 and Rule 26; and the provider will preserve pending resolution and will produce on the account holder's lawful consent.
Send it the same day. Speed here is free and it prevents the follow-on motion practice that a slow response invites.
Two caveats to hold onto. Non-content records are not protected by the same prohibition as against private parties, and practice varies — analyze rather than assume. And preservation is a separate obligation from production; a provider on notice of litigation may need to preserve even where it cannot produce.
If the subpoena is directed at the company's own business records — the contract, the billing history, the account relationship — that is ordinary third-party discovery, and the Act does not shield it. Distinguish the two categories explicitly in the response.
Step 8 — Handle the section 1782 application
Section 1782 permits a district court to order a person residing or found in the district to produce documents or testify for use in a proceeding before a foreign or international tribunal.
Three things to establish.
Is the tribunal qualifying? After ZF Automotive US, Inc. v. Luxshare, Ltd., 596 U.S. 619 (2022), "foreign or international tribunal" means a governmental or intergovernmental adjudicative body. Private commercial arbitration does not qualify. This threshold defeats a meaningful share of applications that would have succeeded before 2022.
Do the statutory requirements otherwise hold? The respondent resides or is found in the district; the material is for use in the foreign proceeding; the applicant is an interested person.
What does discretion suggest? Courts weigh whether the respondent is a participant in the foreign proceeding (non-participants are more appropriate targets), the nature of the tribunal and its receptivity to United States assistance, whether the application circumvents foreign proof-gathering restrictions, and whether the request is unduly intrusive or burdensome.
And remember the overlay: a § 1782 order is not one of the mechanisms § 2703 authorizes for compelled content disclosure, so the § 2702 prohibition still applies to customer content. Separate the categories in the response: business records about the account relationship may well be producible; content is not, absent consent.
Step 9 — Handle the emergency request
The emergency exception in § 2702 permits voluntary disclosure where the provider in good faith believes an emergency involving danger of death or serious physical injury to any person requires disclosure without delay.
These are real. Missing children, suicide threats, active threats of violence, kidnapping. A provider that cannot respond quickly to a genuine emergency has a serious problem.
They are also the most abused route into a provider's data, including through fraudulent requests sent from compromised or spoofed law enforcement accounts — a well-documented attack pattern.
So the process has to be both fast and disciplined:
- Twenty-four-hour coverage with a named on-call responder.
- A standard emergency request form requiring the requesting agency, a named officer with agency contact details, the nature of the emergency, the specific danger, why disclosure is needed without delay, and the specific data sought.
- Independent verification of the requester — call back on a number obtained from the agency's own public directory, not from the request. This single step defeats the great majority of fraudulent requests.
- A good-faith assessment recorded in writing, by a named person, before disclosure.
- Narrow disclosure — what the emergency requires, not what was asked for.
- Post-hoc review of every emergency disclosure by counsel within a week.
- Notice to the customer afterwards, where lawful and appropriate.
Train the on-call responders on refusal too. A request that does not describe an emergency involving danger of death or serious physical injury is not an emergency request, however urgent the requester says it is.
Step 10 — Track preservation separately
Section 2703(f) lets a governmental entity require preservation for 90 days, extendable once on renewed request.
Preserve narrowly. A request identifying an account should not freeze an entire tenant environment. Over-preservation creates cost, creates a discoverable repository, and conflicts with deletion commitments and data minimization obligations.
Track the expiry. Calendar the 90 days and any extension. Release on expiry unless renewed or superseded by process. A preserved dataset held indefinitely with no legal basis is a liability, not a precaution.
Do not confuse preservation with anything else. It is not production. It does not by itself carry a nondisclosure obligation. It does not authorize notice or require silence.
Build the deletion-request workflow now. A customer exercising a privacy deletion right on an account subject to preservation creates a genuine conflict. Suspend deletion of the preserved material, document the basis, complete the deletion when the obligation ends — and make sure the privacy team and the legal process team can see each other's queues, because they usually cannot.
Step 11 — Produce carefully
Produce only what the demand covers, as narrowed.
Have someone review the production before it goes. Over-production is the most common substantive error, and it is irreversible. A second set of eyes on the export, against the demand's scope, catches it.
Watch for third-party data. A production about one account frequently sweeps in communications with people who are not the subject. Where the demand permits, filter; where it does not, flag the issue to the issuing authority.
Use a secure channel and confirm receipt.
Include a cover letter stating what was produced, the scope as narrowed, what was withheld and on what basis, and any preservation of objections.
Keep the production copy. You will be asked what you produced, and reconstructing it later from logs is unpleasant.
Log the completion — date, scope, method, recipient, and the person who approved it.
Step 12 — Decide when to fight
Most demands are complied with. Some should not be.
Challenge when the process does not match the data. A subpoena for content is defective under § 2703. This objection is cheap and usually resolves without litigation.
Challenge scope that is genuinely unbounded after negotiation has failed.
Consider a comity motion where a foreign legal conflict is real. The CLOUD Act added a mechanism at § 2703(h) permitting a motion to quash or modify where the customer is not a United States person and does not reside here and disclosure would create a material risk of violating the laws of a qualifying foreign government. Where the mechanism is unavailable, common-law comity arguments remain — informed by the multi-factor analysis of Société Nationale Industrielle Aérospatiale v. United States District Court, 482 U.S. 522 (1987), which weighs the importance of the material, the specificity of the request, where the information originated, alternative means, and the competing sovereign interests.
Consider challenging an indefinite nondisclosure order.
Consider challenging process that reaches data of a sensitivity the process does not match. Carpenter v. United States, 585 U.S. 296 (2018) held that acquiring historical cell-site location information is a Fourth Amendment search requiring a warrant, declining to extend the third-party doctrine to a comprehensive record of a person's movements. The decision was expressly narrow, but its logic is pressed regularly, and a provider deciding whether to require a warrant for a category of sensitive data has a principled place to stand.
Weigh it honestly. Litigation costs money, delays the matter, and occasionally damages a relationship with an authority you will deal with again. Fight where the principle matters, the customer is materially affected, or the precedent would be bad.
Step 13 — Report transparently
Publish a transparency report. Demands received by type and country, accounts affected, how many were complied with in full, in part, or rejected, and how many were narrowed.
Know the constraints. National security process may generally be reported only in bands and ranges specified by statute and agreement. Reporting outside those constraints is itself unlawful. Get this reviewed.
Report what you rejected. The most credible number in any transparency report is the rejection rate, because it shows the company applies scrutiny rather than a rubber stamp.
Use the report internally too. Volume trends, error rates, and turnaround times are how the function gets resourced.
Step 12A — National security process: a separate world
This branch of the decision tree operates under different rules, and the most important instruction is that it does not touch the ordinary queue.
National security letters are administrative demands issued without prior judicial approval for defined categories of non-content records. They arrive with nondisclosure requirements, and a statutory reciprocal notice procedure gives the recipient a route to judicial review of the nondisclosure. Recipients have challenged them; some challenges have succeeded in narrowing or lifting nondisclosure.
FISA process. 50 U.S.C. § 1881a authorizes targeting non-United States persons reasonably believed to be located outside the United States to acquire foreign intelligence information, with directives to providers to assist. Other FISA authorities have their own procedures before the Foreign Intelligence Surveillance Court.
Operating rules for a provider:
A designated recipient. One named individual, with an alternate, holding any required clearance. Nobody else.
No routing through the general queue. A national security demand that lands in the ordinary intake is a handling problem the moment it is opened by the wrong person. Train intake staff to recognize the envelope and escalate without reading further.
A separate file, separately secured. Not in the case management system with everything else.
Counsel involvement from the first minute, with a firm that has done this work.
Transparency reporting only within the permitted bands. Reporting outside the statutory and agreed ranges is itself unlawful. Have the report reviewed before publication, every time.
Know that this is why your European customers ask. The existence of these authorities is the substance of the concern that drives transfer-mechanism analysis on the privacy side of the house. The two functions should talk. A company whose privacy team is writing transfer impact assessments while its legal process team is handling the underlying demands, with no communication between them, is describing itself inaccurately to regulators without meaning to.
Step 8A — Working with the authority you are objecting to
Every objection in this guide is made to someone the company will deal with again. How the objection is made matters nearly as much as whether it is right.
Object to the process, not to the investigation. "This subpoena seeks content, and 18 U.S.C. § 2703 requires a warrant for content — we will produce on a warrant" is a sentence that gets a warrant. "We decline to produce" is a sentence that gets a motion.
Say what you will do. Every objection letter should end with the path forward: the process that would be sufficient, the narrowing that would be acceptable, the consent that would resolve it, or the preservation the company will maintain in the meantime.
Call before you write. A five-minute conversation with the issuing agent or prosecutor resolves defects that a letter turns into a dispute. Wrong account identifiers, missing date ranges, and content-by-subpoena problems are usually clerical, and the issuer would rather fix them than litigate them.
Do not editorialize. Objection letters that comment on the merits of the investigation, the wisdom of the statute, or the company's values are read by people who are simply trying to do their jobs, and they harden positions.
Be reachable. A named person, a direct number, and a response within a business day. Providers that are hard to reach get broader demands, because the issuer cannot negotiate scope with a form.
Keep the escalation option quiet until you use it. Threatening to move to quash in the first letter converts a negotiation into a posture. Make the substantive point first; the option remains available.
And be consistent. A company that requires a warrant for content in one matter and produces on a subpoena in another has no position at all — and will be told so, accurately, the next time it objects.
Step 9A — Where Solstice Ledger ended up
Nine months after Marchetti-Obi started building the function, Solstice Ledger's numbers looked like this.
Volume: 214 demands received, against 9 the prior year. The increase was not new attention; it was that demands had previously been arriving at sales representatives and support queues and being answered, ignored, or lost. The single published service address surfaced a workload that had always existed.
Validation: 68 demands — nearly a third — had a defect that mattered. Nineteen sought content by subpoena. Twenty-two misidentified the account. Fourteen had no defined date range. Thirteen came from authorities with no apparent jurisdiction over Solstice. All were addressed by letter, and none produced a motion to compel.
Scope: 41% of valid demands were narrowed by agreement after a phone call. Median production volume fell by more than half.
Foreign demands: eleven, from six countries. Two were resolved by account-holder consent. One proceeded under an executive agreement. Six were referred to mutual legal assistance. Two remain open and are being managed with local counsel in a country where the local entity is under real pressure — the honest outcome, and the reason the corporate separation work matters more than the doctrine.
Emergencies: twenty-three requests. Nineteen were verified and answered, in a median of forty-one minutes. Four were fraudulent — spoofed agency email domains, urgent language, no verifiable callback. All four were caught by the call-back-on-a-public-number rule, which cost nothing to implement and is the single highest-return control in the entire program.
Nondisclosure orders: thirty-one. Twenty-two have lapsed, and the customers were notified on lapse — which produced, unexpectedly, three customer expansions and one written commendation from a chief information security officer who had never seen a provider do it.
Cost: one full-time specialist, one part-time paralegal, a case management tool, and outside counsel on defined triggers. Less than the company had been spending on ad hoc escalations.
Marchetti-Obi's summary to the board was two sentences: "We are not producing less data than we were. We are producing the right data, to the right authorities, on the right process, and we can prove it."
Step 10A — The company that does not think it is a provider
A large share of the companies that receive these demands do not consider themselves communications providers at all, and are surprised to discover the Stored Communications Act applies to them.
Who is covered. The Act's obligations attach to a provider of electronic communication service to the public and to a provider of remote computing service — definitions supplied by 18 U.S.C. § 2711 and the Wiretap Act. In practice that reaches far beyond email and messaging: hosting and storage providers, collaboration platforms, file sharing services, backup services, many SaaS applications that store customer content, and platforms with messaging features bolted onto something else. Whether the service is offered "to the public" matters, and an enterprise-only service may fall outside parts of the framework — but the analysis has to actually be done.
Why it matters both ways. A company that wrongly believes the Act does not apply may disclose content in violation of § 2702 and face liability under § 2707. A company that wrongly believes the Act does apply may refuse to produce material it could lawfully produce, and invite a motion to compel it will lose.
So make the determination, once, in writing. Which of the company's services are electronic communication services, which are remote computing services, which are neither, and whether each is offered to the public. Have counsel do it, record the reasoning, and revisit it when the product changes — because the product will change, and a new feature can move a service across the line without anyone noticing.
Then note the categories that fall outside the Act entirely. A demand for the company's own business records — the contract, invoices, account-opening documents, the identity of the customer's administrator — is ordinary third-party process, and the Act does not shield it. Companies routinely over-refuse here, on the theory that anything about a customer is protected. It is not, and refusing ordinary business records damages credibility with the authority for the demands where the objection is real.
Step 11A — When you are the customer, not the provider
Companies that buy cloud services are on the receiving end of this process too, and the moves are different.
Negotiate the notification clause before signing, not after a demand arrives. The clause is set out in Step 13B; ask for it by name.
Know where your data lives and, more importantly, who controls it. Under the CLOUD Act, possession, custody, and control governs — not geography. Residency commitments are useful for other reasons and are not a shield.
Assume you are the better target. Because § 2702 blocks civil discovery of content from providers, a private litigant seeking your communications will subpoena you directly. Your provider's inability to produce relocates the fight; it does not end it.
Diligence the provider's process. Ask how many demands it received last year, how many it narrowed or rejected, whether it has ever litigated a nondisclosure order, what its emergency verification procedure is, and who decides. A provider that has built the function answers in a paragraph.
Build your own escalation. When a provider notifies you of a demand touching your data, you may have days to decide whether to intervene, move to quash, or negotiate directly with the issuing authority. Name the decision-maker in advance.
Be honest internally about encryption. Keys you hold, the provider cannot produce. That is a real architectural control. It does not protect metadata, which is frequently what is actually sought, and it carries operational costs. Do not let it be described internally as a complete answer.
Step 13A — Real-time collection, if you can do it at all
Stored data is one problem. Real-time collection is another, and a company that has not decided its position in advance will decide it badly under a deadline.
Wiretap orders. Content interception requires an order under 18 U.S.C. § 2518, which demands an application by a specified official, judicial findings of probable cause, a showing that normal investigative procedures have failed or would fail or are too dangerous, minimization, limited duration, and sealing. It is the most demanding process in criminal law. Providers subject to technical assistance obligations are compensated for assistance.
Pen register and trap-and-trace orders. Real-time non-content — dialing, routing, addressing, and signaling information — requires an order under 18 U.S.C. § 3123 on a certification that the information is relevant to an ongoing criminal investigation. Much lower standard, much more common.
Decide three things in advance.
Are we technically capable? Many companies are not, and the correct response is a precise statement of what the company can and cannot do — not a vague refusal, which invites a motion, and not an over-promise, which creates an obligation you cannot meet.
Who implements it? A named, trained, small team. Real-time collection touches production systems and requires engineering involvement, which means people outside legal will know about a matter that may be under a nondisclosure order. Plan the need-to-know perimeter before, not during.
What is the cross-border position? Real-time collection touching foreign users, foreign infrastructure, or foreign personnel raises every conflict in this guide with none of the time to work through it. Write the policy.
And build the technical assistance response template — what the company can produce, in what format, on what timeline, at what cost, with what notice requirements. Having it ready converts a crisis into an administrative task.
Step 13B — Where the customer contract has to do the work
Several of the positions in this guide only work if the contracts support them. Get these into the standard terms.
The notification clause. Commit to notifying customers of legal process seeking their data, promptly, except where prohibited by law or where notice would be counterproductive to an emergency involving danger of death or serious physical injury. Without the exception, you will breach the contract or breach an order. Without the commitment, enterprise customers will not sign.
The narrow-production commitment. State that the company will produce the narrowest set of data responsive to the demand and will seek to narrow overbroad demands. This is what the scope negotiation step already does; saying so contractually converts good practice into a selling point.
The opportunity-to-object provision. Where notice is permitted, give the customer a reasonable period to seek protective relief before production, subject to the demand's deadline. Enterprise customers ask for a fixed number of days; a reasonableness standard tied to the return date is the usual landing spot.
The cost provision. Who bears the cost of responding to demands directed at a customer's data, particularly where the customer asks the company to litigate.
The data location and control disclosure. Say where data is processed. Do not imply that location determines legal exposure; under the CLOUD Act, possession, custody, and control is the operative concept, and a customer who believes residency is a shield has been misled.
The transparency reporting reservation. Reserve the right to include the demand in aggregate transparency reporting, so a nondisclosure order about a specific matter does not become an argument that the aggregate number breaches the contract.
Step 14 — Build the function to survive volume
Staff it. At meaningful volume this is a specialist role, not a rotation. The people who do it well develop judgment that is difficult to transfer.
Tool it. A case management system with the log, deadlines, nondisclosure expiry dates, preservation expiry dates, and production records. A spreadsheet works until it does not, and the failure mode is a missed date.
Template it. Acknowledgment, validation form, objection letters by type, scope negotiation email, production cover letter, customer notification, emergency request form. Templates make the process fast and consistent, which is what makes it defensible.
Train the front line across support, sales, and reception: forward it, do not respond to it.
Review annually — volumes, error rates, the decision tree against current law, the terms of service notification clause, and the list of countries with executive agreements.
And set the tone from the top. The function's job is neither to obstruct legitimate investigations nor to hand over whatever is asked. It is to require the right process for the data, produce what is properly demanded, and tell the customer when it lawfully can. A company that states that position clearly, and follows it, is in a defensible place with every audience that matters.
Related documents
- Cross-Border Government Demands for Data: The Stored Communications Act, the CLOUD Act, and MLATs
- Cross-Border Data Demand Response Checklist: A Practical Checklist
- Government Data Demand Toolkit: Legal Process Review, Objections, and Notification
- International Data Transfers After Schrems II: Standard Contractual Clauses and Transfer Impact Assessments
- Privacy and Data Protection Toolkit: Building and Running a Privacy Program
- Developing a Privacy Compliance Program
This guide is general information, not legal advice, and does not create an attorney-client relationship.
