FISA 702
In shortUS intelligence agencies may access Europeans' data held by American providers, and those affected are not told.
At a glance
- Provision
- Section 702 of the Foreign Intelligence Surveillance Act, codified at 50 U.S.C. § 1881a
- Who it concerns
- Non-US persons outside the United States — in practice, every European customer
- Who is compelled
- US providers of electronic communication services, including cloud and collaboration services
- Procedure
- Annual certification of whole target categories by a court sitting in private; no judicial review of the individual case
- Notification
- Not provided for; providers are routinely barred from discussing specific directives
- Why it appears here
- The CJEU relied on this power in striking down both Safe Harbor and the Privacy Shield
Section 702 of the Foreign Intelligence Surveillance Act allows US intelligence agencies to target the communications of people outside the United States who are not US citizens. Collection happens not on their own wires but through the assistance of American service providers.
That makes this provision the actual reason why transferring personal data to US providers has been legally difficult for years — and why two adequacy decisions have fallen.
How the procedure works
The US Attorney General and the Director of National Intelligence submit annual certifications describing categories of intelligence targets. A court sitting in private reviews those certifications together with the targeting and minimisation procedures.
What that court does not review is the individual person. Selecting specific targets within the approved categories is done by the agencies themselves. Precisely this point — review of the category rather than the case, without any involvement of the person concerned — sits at the centre of the European criticism.
Why this matters for European companies
In Schrems II the Court of Justice did not find that European data had flowed out en masse. It found that the power exists and that the people affected have no redress equivalent to the European one.
For your own assessment that means: the standard is the law in the recipient country, not your estimate of how interesting your data is. A mid-sized manufacturer with design data has to answer the same question as a corporation.
What follows in practice
The provider question comes before the location question. A provider outside US jurisdiction takes the power off the table. Everything else is damage limitation.
Encryption works only with your own key control. The European Data Protection Board names it explicitly as a supplementary measure — but only on the condition that the provider in the recipient country cannot make the data readable. See Key control.
The assessment belongs on paper. Not because a document protects you, but because the supervisory authority will ask for it, and because the assessment hands you the ranking of your own dependencies.
What often gets confused
FISA 702 and the US CLOUD Act are two different routes. The CLOUD Act is law enforcement and addresses the company; it has a procedure a provider can challenge in court. FISA 702 is foreign intelligence and runs through certified categories; here the people affected have no comparable route.
Looking only at the CLOUD Act understates the position. Looking only at FISA 702 overlooks that ordinary criminal proceedings can lead to disclosure too.
Common questions
- How does FISA 702 differ from the CLOUD Act?
- The CLOUD Act is a law-enforcement instrument: an authority demands data from a company in a specific case. FISA 702 is an intelligence instrument: a court certifies categories of targets and providers assist. The second route is the broader and the less transparent one.
- Does a European data centre help?
- No, if the provider is subject to US jurisdiction. The obligation binds the company, not the location. What works is a provider outside that jurisdiction, or encryption whose keys the provider does not hold.
- Is this not theoretical? We are not an intelligence target.
- For most companies that is true. Legally, though, what counts is the power rather than the probability: the CJEU relied on the abstract possibility of access without equivalent redress, not on proven individual cases. For your duty to assess under Schrems II, that is the standard.
- Does the Data Privacy Framework change this?
- It does not change the power; it adds proportionality requirements and a redress mechanism for individuals. Whether that suffices is currently before European courts — exactly as it was for both predecessor arrangements.
Sources
See also
Related terms
- US CLOUD ActUS providers must hand over data even when it sits in Frankfurt.
- Schrems IISince 2020 you must assess yourself whether data is safe in the recipient country — the provider cannot do it for you.
- Adequacy decisionAn adequacy decision permits transfers to a third country without extra safeguards — until it is struck down.