Skip to content
SOVEREIGNTYBALANE
Back to the wiki
Law · 2 min read · Updated 16 August 2026

FISA 702

In shortUS intelligence agencies may access Europeans' data held by American providers, and those affected are not told.

At a glance

Provision
Section 702 of the Foreign Intelligence Surveillance Act, codified at 50 U.S.C. § 1881a
Who it concerns
Non-US persons outside the United States — in practice, every European customer
Who is compelled
US providers of electronic communication services, including cloud and collaboration services
Procedure
Annual certification of whole target categories by a court sitting in private; no judicial review of the individual case
Notification
Not provided for; providers are routinely barred from discussing specific directives
Why it appears here
The CJEU relied on this power in striking down both Safe Harbor and the Privacy Shield

Section 702 of the Foreign Intelligence Surveillance Act allows US intelligence agencies to target the communications of people outside the United States who are not US citizens. Collection happens not on their own wires but through the assistance of American service providers.

That makes this provision the actual reason why transferring personal data to US providers has been legally difficult for years — and why two adequacy decisions have fallen.

CLOUD Act FISA 702 Purpose: law enforcement Addressee: the company Trigger: a specific case Redress: US court, partly challengeable Subjects are told: sometimes Purpose: foreign intelligence Addressee: the service provider Trigger: certification of whole categories Redress: non-public proceedings Subjects are told: no
Two separate routes to the same data. Assessing a provider requires looking at both.

How the procedure works

The US Attorney General and the Director of National Intelligence submit annual certifications describing categories of intelligence targets. A court sitting in private reviews those certifications together with the targeting and minimisation procedures.

What that court does not review is the individual person. Selecting specific targets within the approved categories is done by the agencies themselves. Precisely this point — review of the category rather than the case, without any involvement of the person concerned — sits at the centre of the European criticism.

Why this matters for European companies

In Schrems II the Court of Justice did not find that European data had flowed out en masse. It found that the power exists and that the people affected have no redress equivalent to the European one.

For your own assessment that means: the standard is the law in the recipient country, not your estimate of how interesting your data is. A mid-sized manufacturer with design data has to answer the same question as a corporation.

What follows in practice

The provider question comes before the location question. A provider outside US jurisdiction takes the power off the table. Everything else is damage limitation.

Encryption works only with your own key control. The European Data Protection Board names it explicitly as a supplementary measure — but only on the condition that the provider in the recipient country cannot make the data readable. See Key control.

The assessment belongs on paper. Not because a document protects you, but because the supervisory authority will ask for it, and because the assessment hands you the ranking of your own dependencies.

What often gets confused

FISA 702 and the US CLOUD Act are two different routes. The CLOUD Act is law enforcement and addresses the company; it has a procedure a provider can challenge in court. FISA 702 is foreign intelligence and runs through certified categories; here the people affected have no comparable route.

Looking only at the CLOUD Act understates the position. Looking only at FISA 702 overlooks that ordinary criminal proceedings can lead to disclosure too.

Common questions

How does FISA 702 differ from the CLOUD Act?
The CLOUD Act is a law-enforcement instrument: an authority demands data from a company in a specific case. FISA 702 is an intelligence instrument: a court certifies categories of targets and providers assist. The second route is the broader and the less transparent one.
Does a European data centre help?
No, if the provider is subject to US jurisdiction. The obligation binds the company, not the location. What works is a provider outside that jurisdiction, or encryption whose keys the provider does not hold.
Is this not theoretical? We are not an intelligence target.
For most companies that is true. Legally, though, what counts is the power rather than the probability: the CJEU relied on the abstract possibility of access without equivalent redress, not on proven individual cases. For your duty to assess under Schrems II, that is the standard.
Does the Data Privacy Framework change this?
It does not change the power; it adds proportionality requirements and a redress mechanism for individuals. Whether that suffices is currently before European courts — exactly as it was for both predecessor arrangements.

Sources

See also

Related terms