Cloud Computing in Higher Education and Research Institutions and the USA Patriot Act

42 Pages Posted: 28 Nov 2012 Last revised: 13 Mar 2014

Joris van Hoboken

NYU Law School - Information Law Institute; New York University (NYU) - Information Law Institut

Axel Arnbak

University of Amsterdam - Institute for Information Law (IViR); Harvard University - Berkman Klein Center for Internet & Society

N.A.N.M. van Eijk

Institute for Information Law (IViR)

Date Written: November 27, 2012

Abstract

Institutions have started to move their data and ICT operations into the cloud. It is becoming clear that this is leading to a decrease of overview and control over government access to data for law enforcement and national security purposes. This report looks at the possibilities for the U.S. government to obtain access to information in the cloud from Dutch institutions on the basis of U.S. law and on the basis of Dutch law and international co-operation. It concludes that the U.S. legal state of affairs implies that the transition towards the cloud has important negative consequences for the possibility to manage information confidentiality, information security and the privacy of European end users in relation to foreign governments.

The Patriot Act from 2001 has started to play a symbolic role in the public debate. It is one important element in a larger, complex and dynamic legal framework for access to data for law enforcement and national security purposes. In particular, the FISA Amendments Act provision for access to data of non-U.S. persons outside the U.S. enacted in 2008 deserves attention. The report describes this and other legal powers for the U.S. government to obtain data of non-U.S. persons located outside of the U.S. from cloud providers that fall under its jurisdiction. Such jurisdiction applies widely, namely to cloud services that conduct systematic business in the United States and is not dependent on the location where the data are stored, as is often assumed. For non-U.S. persons located outside of the U.S., constitutional protection is not applicable and the statutory safeguards are minimal.

In the Netherlands and across the EU, government agencies have legal powers to obtain access to cloud data as well. These provisions can also be be used to assist the U.S. government, when it does not have jurisdiction for instance, but they must stay within the constitutional safeguards set by national constitutions, the European Convention on Human Rights and the EU Charter.

UPDATE (11.06.13): Recent leaks around the PRISM surveillance program of the National Security Agency seem to support that these legal possibilities are used in practice on a large scale. Therefore, the authors have decided to publish a draft of their update paper on SSRN under the title 'Obscured by Clouds or How to Address Governmental Access to Cloud Data from Abroad'. The analysis is updated and it includes regulatory and policy solutions to the current legal reality.

Keywords: cloud computing, privacy, information security, lawful access, Patriot Act, FISAA, ECPA

Suggested Citation

van Hoboken, Joris and Arnbak, Axel and van Eijk, N.A.N.M., Cloud Computing in Higher Education and Research Institutions and the USA Patriot Act (November 27, 2012). Available at SSRN: https://ssrn.com/abstract=2181534 or http://dx.doi.org/10.2139/ssrn.2181534

Joris V. J. Van Hoboken

NYU Law School - Information Law Institute ( email )

139 MacDougal Street
WILF Hall, Room 418
New York, NY 10011
United States

New York University (NYU) - Information Law Institut ( email )

40 Washington Square South
New York, NY 10012-1099
United States

Axel Arnbak (Contact Author)

University of Amsterdam - Institute for Information Law (IViR) ( email )

Kloveniersburgwal 48
Amsterdam, 1012 CX
Netherlands

HOME PAGE: http://www.ivir.nl/staff/arnbak.html

Harvard University - Berkman Klein Center for Internet & Society ( email )

23 Everett Street
Cambridge, MA 012138
United States

N.A.N.M. Van Eijk

Institute for Information Law (IViR) ( email )

Postbus 1030
Amsterdam, 1000 BA
Netherlands

HOME PAGE: http://www.ivir.nl/medewerkerpagina/eijk

Paper statistics

Downloads
3,878
Rank
1,720
Abstract Views
23,206