US bill to toughen cloud data protection

Powered by SC Magazine

But the FBI will keep authority to obtain data under terrorism and intelligence clauses.

A bill introduced in the US Senate would require authorities to obtain a court-issued search warrant before retrieving a person's email and other content stored in cloud services.

The proposed legislation would update a 25-year-old digital privacy law called the Electronic Communications Privacy Act (ECPA) which set standards for government wiretapping of telephone and electronic communications.

US Senator Patrick Leahy, who authored both the 1986 law and the amendment bill, said the legislation was "outpaced by rapid changes in technology”.

The newly introduced ECPA Amendments Act would require authorities to obtain a search warrant based on probable cause before obtaining customer information from electronics communications, cloud computing or other technology service providers.

Under current law, law enforcement does not need to acquire a search warrant to obtain email communications that have been stored for longer than 180 days.

The proposed legislation would eliminate this rule and require a search warrant regardless of the age of an email.

It would also implement new protections for geolocation information that is collected, used or stored by smartphones or other mobile technologies.

If enacted, the bill would mandate a warrant to access or use an individual's smartphone or other electronic communications device to obtain geolocation information.

A coalition of privacy groups and technology companies, called Digital Due Process, has been pushing since last year for the reform of ECPA.

The group includes AOL, the American Civil Liberties Union, Google and Microsoft and argues that the ECPA is a “patchwork of confusing standards” that no longer adequately protects the vast amount of personal data generated by the latest digital communication devices and services.

“The reforms take an important step toward updating antiquated protections for consumers utilising modern-day cloud and mobile services," said Kelly William Cobb, executive director of consumer choice group Americans for Tax Reform's DigitalLiberty.Net.

Leahy's measure, however, does not do away with the FBI's authority, under the national security letters, to obtain digital information about a person, without a court order, if authorities consider it relevant to a terrorism or national intelligence case.

This article originally appeared at

Copyright © SC Magazine, US edition

US bill to toughen cloud data protection
Top Stories
ANZ looks to life beyond the transaction
If digital disruptors think an online payments startup could rock the big four, they’ve missed the point of why people use banks, says Patrick Maes.
What InfoSec can learn from the insurance industry
[Blog post] Another way data breach laws could help manage risk.
A ten-point plan for disrupting security
[Blog post] How can you defend the perimeter when it’s in the cloud?
Sign up to receive iTnews email bulletins
Latest Comments
What is delaying adoption of public cloud in your organisation?

   |   View results
Lock-in concerns
Application integration concerns
Security and compliance concerns
Unreliable network infrastructure
Data sovereignty concerns
Lack of stakeholder support
Protecting on-premise IT jobs
Difficulty transitioning CapEx budget into OpEx