Executive Summaries Feb 21, 2019

De-fogging the Cloud Act

Recently, and perhaps in response to plans by the Quebec government to transfer much of the personal data it holds to a cloud infrastructure most probably hosted by an American server, there has been renewed interest and concern about the effects of the U.S. Clarifying Lawful Overseas Use of Data Act otherwise know as the Cloud Act on data protection. 

Danielle Miller Olofsson has authored this article.

While concerns about the extraterritorial reach of any legislation are justified, some of the alarmism and misconceptions regarding the Cloud Act are not. They may in fact be diverting attention from an equally important risk: cybersecurity. 

What Is the Cloud Act?

The Cloud Act is a law that was passed March 23 2018 largely in response the case of Microsoft Corp. v. United States in which Microsoft challenged the extraterritoriality of United States law enforcement seeking access to electronic data stored on Microsoft servers in Ireland. Although Microsoft lost at trial, it won on appeal. Congress then passed the Cloud Act rendering any appeal to the Supreme Court moot.

Welcomed by companies such as Microsoft and Apple, the Cloud Act essentially enables the American government to ask a communications or remote computing service provider to preserve, back-up or disclose the contents of a wire or electronic communication. It also allows the government to access any record or other information pertaining to a customer or subscriber in the provider’s possession, custody or control regardless of whether the provider is located in the United States or abroad. In essence, the law enables the U.S. government to initiate a process to access data hosted on an American server even if this server is located in another country. 

The Cloud Act, however, also enables the service provider to bring a motion to quash or modify the disclosure process if: 

  • the customer or subscriber is not an American citizen and does not reside in the United States; and
  • the disclosure would create a material risk that the provider would violate the laws of the foreign jurisdiction.

A court would then have to apply a three part test in which it determines: 

  • first, whether the disclosure causes the provider to violate the laws of a foreign jurisdiction;
  • second, whether the interests of justice dictate that the disclosure process should be modified or quashed and; 
  • third, whether the customer or subscriber is a citizen and residents of the United States.

In light of the above, given that most information that Quebec companies store in the cloud – even clouds hosted by American servers – pertain to citizens and residents of countries other than the United States, and given that Quebec privacy legislation, notably the Act Respecting the Protection of Personal Information in the Private Sector (arts. 17-23) and the Act Respecting Access to Documents Held by Public Bodies and the Protection of Personal Information would most certainly prevent such a transfer, it is difficult to see how an American server would not bring a motion to quash a disclosure process. Indeed, the Cloud Act finally gives large American servers a means to stand up to government disclosure demands thus assuaging the costly fears of organisations that refuse to use these servers because of their inability to protect information from the extraterritorial reach of the US government It is also difficult, but perhaps not impossible, to conceive that a court would deny a motion to modify or quash a demand provided the right circumstances were present. 

Although there has been much justified concern about the extraterritorial nature of legislation passed by the United States in the wake of the terrorist attacks of September 11 2001, many indications suggests that the United States is retreating from its previous position according to which it could seek information anywhere by any means. The Cloud Act, arguably, is an example of this new approach. Another example is the USA Freedom Act that replaced the Patriot Act in 2015 and that has considerably reduced the scope of America’s extraterritorial reach.

So while extraterritoriality may have been a convincing argument for non-American servers seeking to attract business by playing on justified fears, these fears are not as justified as they once were. Moreover, when it comes to data protection, although national sovereignty is a valid concern, a second equally pressing concern is cyber security and the fact that large, mostly American, servers have the resources required to offer the most adequate protection against criminals seeking to access and misuse our data. 

BCF's Web team

BCF's Web team offers our clients relevant legal services and advice about their presence on the Internet. This constantly evolving environment requires the expertise of a multidisciplinary team like BCF.

Stay on the lookout!

Subscribe to our communications and benefit from our market knowledge to identify new business opportunities, learn about innovative best practices and receive the latest developments. Discover our exclusive thought leadership and events.

Subscribe

You would also like

Data-Privacy

Bill 82: One Step Closer to a National Digital Identity (and Modifications to Other Provisions!)

Entrepreneurship forum

Entrepreneurship Forum: Vision 2025

Athlete

Protecting Privacy in Sports – Don’t Wait to be Caught Flat-Footed!

data-protection

Obligation to Report Information Security Incidents: The Autorité des Marchés Financiers Catches the Wave and Publishes a New Regulation

Right to Data Portability: Is your Organization Ready?

Tech Forum 360

Tech 360 Forum: Growth and Inflection Points

Prospera: Québec’s Economic Barometer

Canada's Best Managed Companies: BCF Recognized for 17th Consecutive Year

paul et misha

BCF Strengthens its Expertise in Artificial Intelligence

new-partners-2024

BCF Has Appointed Three New Partners

Who’s Who Legal : 5 BCF Professionals Stand Out

BCF extends its Partnership with the Canadian Association of Black Lawyers to a Third Year

Demystifying Privacy Impact Assessments (PIAs)

The Data Processing Agreement: An Essential Resource to Implement

camera-on-a-wall

The Incident Response Plan: the Cornerstone of Effective Crisis Management

forum-privacy-en

Strategic Forum on Enterprise Data Protection

Chambers Canada Ranking: Five of our Lawyers Recognized

Photo of Julie Doré

Julie Doré Takes Over Management of The BCF Business Law Firm

Prospera – Quebec Economic Barometer

Julien Tricart, Member of the Meritas Sports Law Group

Pride Month: Let’s Create an Inclusive Future

Canada’s Best Managed Companies: BCF Recognized for 16th Consecutive Year

New Privacy Requirements: Is Your Business Compliant?

Every Woman Counts

Strategic Forum on the Role Played by Businesses in the Fight Against Climate Change

BCF Partners with the Canadian Association of Black Lawyers to Promote Diversity in Québec Law Faculties

BCF's More Inclusive Approach: Improved Parental Leave

Shaun E. Finn Appointed to the Superior Court of Québec

How to Ensure a Business Succession?

Business black folders on table

Adoption of Bill 78 on Transparency Business: Are You Ready?

Strategic Forum on Market Consolidation and Business Succession

BCF Partners with the Clinique Juridique de Saint-Michel to Promote Access to Legal Studies for Young People from Diverse Communities

What Are the Best Practices for Managing Privacy Incidents?

Shaun E. Finn, Co-Author of In the Public Eye: Privacy, Personal Information, and High Stakes Litigation in the Canadian Public Sector

Should Using Personal Information Obtained Without Consent Be Grounds for Class Action Authorization?

Five of our Lawyers Stand out in the 2023 Edition of the Chambers Canada Ranking

Cybersecurity and Privacy in Canada: What You Need to Know About Bill C-27

Is the Loss of Personal Information Sufficient to Justify the Success of a Class Action on the Merits?

Bill C-26: The Federal Government Takes a Closer Look at Cybersecurity and Privacy

Jocelyn Poirier, BCF’s Chief Privacy Officer

43 BCF Professionals Stand Out with 78 Nominations in the 2023 Editions of Best Lawyers in Canada and Ones to Watch

Seven New Lawyers Join BCF

Adoption of Bill 96: Be Ready

Pride Month: The Value of Diversity

BCF, the 3rd Largest Law Firm in Québec

Canada’s Best Managed Companies: BCF Recognized for 15th Consecutive Year

BCF Recognized by the Globe and Mail as one of Canada’s top Law Firms

Chambers Canada 2022: BCF Earned Band 1 Ranking in Québec for Corporate and Commercial Law

Seven New Lawyers Join BCF

Privacy and Data Protection Class Actions: Trends, Challenges and Best Practices

A First in Canada: Privacy Class Action Dismissed on the Merits

escalier

BCF Welcomes Seven New Lawyers

Collaboration in the Time of COVID-19: Legal Considerations for Successful AI and Healthcare Partnerships

Shaun E. Finn and Danielle Miller Olofsson Publish a Unique Practical Handbook on Privacy and Data-Protection Class Actions

What Are the Implications of the End of EU-U.S. Privacy Shield Framework for Your Business?

Investigation on Tim Hortons’ Application

Québec’s Bill 64 to Amend Data Protection Legislation: A Bill with Teeth?

Does the Use of Thermal Imaging Cameras in Stores Comply with Privacy Laws?

COVID-19: Solutions to Address this Situation

COVID-19: Finally a Toolbox for Developers of Geolocalisation Applications

Tracking the COVID-19 Pandemic with Cellphones

COVID-19: Don’t Forget Data Protection When Designing a Response Strategy

BCF once again ranks as one of Montreal's Top Employers

BCF Names 16 New Partners for Its 25th Anniversary

Joint Controllership or the Risks of using Website Plugins

Are You a Leader or a Follower?Results of the Innovation Survey

Chambers Canada 2020: BCF Recognised in Corporate and Commercial Law

Strategic Forum on Innovation

Different Legislative Approaches to 5G

Innovating to Survive: Are You a Leader or a Follower?

Is Your Company Implementing a New Technology System? Remember to Protect Your Data

5G Technology Is Coming: Legal Questions Abound

Legal Issues Surrounding the Industrial Revolution 4.0

Where Does Québec Stand in Terms of Privacy Class Actions?

fenetres

Google and CNIL: a Case of Inappropriately Obtained Consent

Best Practices for Québec Companies Receiving European Data

Anonymization? Think Again

The Deep Web and Dark Web Demystified for Businesses

The GDPR is Coming: How to Get Ready

Protection of Personal Data: New Measures Put in Place by the European Union

Is Your Organisation Collecting Too Much Data and Is It Well Protected?