🇬🇧 đŸ‡łđŸ‡± đŸ‡«đŸ‡· â„č

BeLibre

Digital Autonomy

BeLibre

Analysis Government Requests for Customer Data

Both Google and Microsoft are trying really hard to not only be compliant about what information they had to disclose, but also try to explain that they are doing the best they can to minimize the importance of what they disclosed.

A big distinction is being made between “Content Disclosure” and “Non-content Disclosure” (metadata). There are way less content disclosures, but the catch is that the most important data is in the Metadata: Who communicated with whom, at what time? Did an e-mail have an attachment? What was the location of the smartphone at the time that encrypted chat was sent, and where was the recipient? How often do they communicate? For how long? What was the used device? Did they xbox-players have a paid account? Did the person type the password, or did it get pasted? Metadata often gets described simply as “the envelope” of a letter. Unfortunately it contains way more information.

So every 6 months, Google and Microsoft share their government request reports.

# Context

# Every country can subpoena…

Every country can subpoena Google or Microsoft within the legal grounds of the country. When looking into the data for the first half of 2025, this is what we see:

  • Microsoft: 28.593 requests, for a total of 101.115 accounts (59 countries)
  • Google: 313.424 requests 724.861 accounts (107 countries)

When looking at the historical figures for both reports, we see the same trend with both: not only is the number steadily rising, the number of accounts per request is also rising. Especially the 2025 spike in the Belgian accounts is surprising. At this point, we could not find an explanation for this, but it might be worth researching.

Consumer Requests Trends Worldwide Consumer Requests Trends in Belgium

# … but the US has its own laws.

Companies like Goolge and Microsoft are bound by law and makes this explicit in its principles. Because they are also bound by US law with regards to its own company, this sometimes causes a dilemma. Here, FISA 702 and Executive Order 12333 are the most important ones. We have ball park numbers for FISA, but don’t even have information on EO 12333.

# Google and Microsoft

Google and Microsoft share their aggregated numbers on FISA requests for H1 2025:

2025 Jan-Jun Number of Content Requests Number of Content Request accounts Number of Non-content Requests Number of Non-content Request accounts
Google 0 – 499 177.500 – 177.999 0 – 499 75.500 – 75.999
Microsoft 0 – 499 33.500 – 33.999 0 – 499 0 – 499

It is clear that while the number of requests may be quite limited, there is a significant number of accounts that are affected. Microsoft does point out that users sometimes have more than one account, thus the number of affected users may be somewhat lower. Furthermore, Google shows us a trend: non-content FISA accounts went from ~27,500 (H1 2021) to ~75,500 (H1 2025): nearly tripled in four years. Content accounts went from ~89,000 to ~177,500 so they roughly doubled.

Both Google and Microsoft report somewhere between under 500 FISA content-requests and under 500 non-content requests. This puts the total number somewhere between 0 and 1000 requests.. but the number of connected accounts to these less than a thousand requests, gives us a slightly more accurate number, since the numbers must be given in slices of 500 range: somewhere over 210.000 affected accounts.

# Consumer versus corporate: consumer is underprotected

Analysis shows us how Google (Android, Google Drive, Gmail, Youtube) is much more actively used at consumer level and Microsoft has a much more corporate customer base. The number of affected accounts (both country subpoenas and FISA requests) is clearly much higher in the Google ecosystem than in the Microsoft ecosystem. But even in the Microsoft environment, the Requests for Enterprise Customer Data chart shows how there were 28.000 consumer requests and only 168 enterprise requests (0.6%).

It is clear that it is much easier to acquire data for single consumers than for enterprises. It might be worth researching in what ways consumers can gain insight in or protection against these information requests.

# Impact of AI and LLMs on requests

An emerging consequence of this growing number of requests, is that big chunks of data get collected. Two potential novel approaches that aren’t clearly covered by current legislation:

  1. Both Microsoft and Google have an embedded LLM in their ecosystem. Is it possible for law enforcement or intelligence services to interact with these LLMs?
  2. If these datasets are harvested, in what ways are these processed? While the intended use is clear, will these sets also be ingested by large AI models that then are used to train surveillance tools? If this is the case, it will clearly discriminate consumers (and underrepresent enterprises) as they make out the bulk (99.4%) of the dataset.

# Conclusion

When looking into the deep dive that follows, the conclusion seems to be that while there are certain guard rails protecting consumers and enterprises, they are crippled and subject to abuse.

For any Belgian public sector body evaluating US cloud providers, these three instruments collectively mean that data sovereignty cannot be guaranteed contractually, regardless of data residency commitments. The assessment needs to be made in how far exploitation of stored (meta)data provided through these services, can impact the freedom and integrity of Belgian and EU citizens individually or as a society.

EO 12333 FISA 702 CLOUD Act
Purpose Intelligence Intelligence Law enforcement
Scope Dragnet bulk Programmatic clusters Targeted
Company cooperation needed No Yes Yes
Court oversight None FISC (secret) Regular courts
Gag order N/A Permanent Temporary (1/3 of cases)
Non-US person protection Almost none None Weak, unresolved (GDPR Art. 48)
Transparency reporting None 6-month delayed ranges Included in Law Enforcement Request report

# Deep dive: Relevant US extraterritorial laws

To have a better understanding of the US laws impacting our privacy and sovereignty, we are performing an extensive analysis of FISA 702, and also briefly explain what Executive Order 12333 and CLOUD Act are. It appears that especially FISA 702 is underrepresented in public awareness.

# FISA 702

FISA 702 approval flow (from brochure)

Main source: the official FISA 702 Documentation.

# Step 1: Certifications

The Attorney General (AG) and Director of National Intelligence (DNI) submit “certifications” lasting up to one year to the Foreign Intelligence Surveillance Court (FISC) specifying categories of foreign intelligence the Intelligence Community (IC) can use Section 702 to collect. There are four certifications, covering:

  • foreign governments and related entities
  • counterterrorism
  • combatting proliferation
  • counternarcotics

The Attorney General until recently was Pam Bondi - and is now Todd Blanche, this person is nominated by the president - hence an aligned person. The Director of National Intelligence is Tulsi Gabbard. She too is known to be strongly aligned with the president.

Foreign governments are clearly in scope, including “related entities” (which is not clearly defined. Government contractors too?)

# Step 2: Procedures

With the Certifications the AG and DNI also submit:

  • Targeting Procedures: ensure that Section 702 is used only to acquire foreign intelligence information from foreign persons located outside the U.S.
  • Minimization Procedures: rules designed to safeguard any U.S. person information incidentally acquired through Section 702.
  • Querying Procedures: govern how agencies query unminimized information acquired via Section 702.

It is clear that these procedures do nothing to protect Belgian/EU citizens.

# Step 3: FISC Review

The FISC reviews the Certifications and Procedures to ensure they comply with both FISA and the Fourth Amendment, taking into account the compliance history of collection under Section 702.

The FISC is required to appoint amici curiae (friends of the court) to provide further input into the court’s deliberations. The FISC judges themselves appoint amici curiae. There is no external oversight or confirmation process. The American Civil Liberties Union (ACLU) have requested at multiple occasions to allow true independent experts but this has never been granted. Amici curiae are thus appointed only in exceptional cases, and rarely form any opposition.

The court’s judges are appointed solely by the chief justice of the United States without confirmation or oversight by the U.S. Congress. The chief justice is appointed by the President.

  • Indirect Influence: The President cannot directly appoint FISC judges, but the Chief Justice (appointed by the President) plays a key role. A President who appoints a Chief Justice with a particular judicial philosophy could shape the court’s long-term composition.
  • Executive Pressure: While the court is independent in theory, the executive branch (e.g., the Attorney General, FBI, NSA) submits requests and may pressure for broader surveillance powers. The court’s secretive nature makes it difficult to know if such pressure has influenced rulings.
  • No Direct Oversight: The President does not have direct oversight of the FISC’s operations, but the executive branch can influence the court by shaping the legal and political environment in which it operates.

The Section 702 expansion allowing the NSA to search for Americans’ communications without a warrant was first approved by the FISC in 2017, but the major expansion and reauthorization in 2024—which further broadened the government’s surveillance powers—was signed into law by President Joe Biden in April 2024. The 2017 decision was made during the Trump administration, while the 2024 expansion happened under Biden.

Conclusion: FISA will not protect non-US citizens (e.g. EU) and Fourth Amendment (unreasonable searches and seizures) does not protect non-US citizens.

The above three steps constitute the annual certification cycle that establishes the legal framework. The following steps describe what occurs if a company contests a specific collection directive under that framework — which in practice rarely happens.

# Step 4: Order

The FISC issues a written opinion explaining its reasoning. When the FISC issues an order, the companies can appeal it to the FISC Court of Appeals. Only once a decision on that appeal is made can the U.S. government compel the companies to support Section 702 collection.

In practice this rarely ever happens, because it is a big risk to take.

  • Secrecy and Lack of Transparency: The FISC and FISCR operate in secrecy, with most opinions and reasoning redacted. Companies cannot publicly challenge the orders or even discuss them without risking legal consequences.
  • No True Adversarial Process: The system is designed to favor the government. Companies have no meaningful way to present counterarguments or challenge the necessity of the surveillance. Even with amici curiae (friends of the court), these are usually government-friendly experts, not advocates for privacy or civil liberties.
  • Legal and Financial Risks: Challenging a Section 702 order is risky for companies. They risk losing access to government contracts, facing legal penalties for non-compliance, or being subject to criminal charges for revealing classified information. Most companies comply without challenge to avoid these risks.
  • Government Leverage: The government has historically been able to compel compliance even after challenges. For example, after Yahoo challenged a predecessor surveillance statute in 2008, the government won a court battle to force Yahoo back into compliance.
  • 2024 Expansion: The Reforming Intelligence and Securing America Act (RISAA) passed in 2024 further expanded the government’s ability to compel technical assistance from a broader range of companies, including data centers and other entities not traditionally considered ECSPs. This makes it even harder for companies to avoid complying with orders.

# Step 5: Directives

Only upon FISC approval of the Certifications, including the Targeting, Minimization, and Query Procedures, can the AG and DNI compel U.S. electronic communication service providers to assist with collection against authorized Section 702 targets.

At this point, a US based company (even with locations outside the US) can be legally compelled to comply.

# Step 6: Collections

The government uses information gathered under Section 702 to protect the U.S. and its allies from hostile foreign adversaries, including terrorists, proliferators, spies, cyber hackers, and international drug traffickers.

Hostile foreign adversaries is a vague term. It is documented how certain population groups or situations get described as hostile to the US.

# FISA Conclusion

  • Safeguards against political bias and abuse are not robustly present
  • Objecting against FISA claim is hard to combat or refuse (practically impossible)
  • Current law prohibits recipients of FISA orders from ever disclosing the existence of a FISA order
  • Only vague (ball park) statistics 6 months after the facts, yet still showing a steady growth year after year of the number of FISA requests

This has severe impact on non-US sovereignty.

# CLOUD ACT versus GDPR Art. 48

Before the CLOUD Act, there was a legal grey zone: US law enforcement could subpoena a US company for data, but if that data was physically stored outside the US, companies would argue they couldn’t comply without violating local law. Microsoft actually litigated this all the way to the Supreme Court (US v. Microsoft, 2018) — and Congress rendered the case moot by passing the CLOUD Act while it was pending. The CLOUD Act resolved the ambiguity in the government’s favor: a US company must produce data it controls, regardless of where it is physically stored. The legal hook is “possession, custody, or control”. While FISA gag orders are permanent, the CLOUD Act also has means to impose temporary gag orders (and does so in roughly 1 out of 3 cases)

The second part of the CLOUD Act is what gets less attention but is arguably more significant for Europe. It allows the US to negotiate executive agreements with other governments (bypassing treaty ratification entirely) that let foreign law enforcement send data requests directly to US companies, skipping the slow Mutual Legal Assistance Treaty (MLAT) process. The UK (since 2020) and Australia already have such an agreement and negotiations ongoing with Canada and the EU. What this means in practice: if a US-EU CLOUD Act agreement is signed, Belgian federal police could theoretically send a direct request to Microsoft or Google for data on a Belgian suspect. But so could the US send requests that affect European data subjects, under terms negotiated between executives without parliamentary ratification on either side.

While FISA 702 does programmatic collection, and EO 12333 bulk infrastructure-level collection, the CLOUD Act operates on a per case basis with a specific legal demand.

  • GDPR Article 48 says: transfers based on foreign court orders are only lawful if grounded in an international agreement recognized under EU law.
  • CLOUD Act says: produce the data regardless of where it’s stored. These two legal instruments point in opposite directions and no court has definitively resolved the conflict. Microsoft and Google are technically in an impossible position: comply with the CLOUD Act and potentially violate GDPR, or refuse and face US legal consequences. In practice companies comply with the CLOUD Act and manage the GDPR exposure quietly. The European Data Protection Board has flagged this conflict repeatedly but enforcement actions against companies for CLOUD Act compliance have not materialized at scale.

Microsoft points to Microsoft Ireland Operations Limited (MIOL) as the legal entity serving EU customers, implying EU jurisdiction governs. However, the CLOUD Act’s ‘possession, custody, or control’ test bypasses this: US courts ask whether the US parent can access the data, not who signed the customer contract. At best, MIOL creates procedural hurdle.

# Executive Order 12333

This is a nasty one. The PCLOB (Privacy and Civil Liberties Oversight Board) concluded in 2014 that EO 12333 surveillance is the largest component of NSA collection by volume, and that non-US persons have almost no meaningful protections under it. The European Court of Justice referenced this in Schrems II (2020) as one of the reasons the Privacy Shield framework was invalidated. EO 12333 is a Presidential directive: it can be rewritten, expanded, or reinterpreted by executive order alone, with no Congressional vote required. The current administration has actively dismantled the PCLOB: board members were removed in early 2025, leaving it without a quorum. The oversight body that produced the 2014 assessment no longer functions as intended, which means the “largest component of NSA collection” now has even less scrutiny than when that assessment was written. Any stated “limitations” in EO 12333’s current text are only as durable as the current or next executive’s preferences.

Yet, despite this sour context, this is how Microsoft frames it:

Executive Order (EO) 12333 is a Presidential directive that organizes U.S. intelligence activities and regulates the foreign intelligence collection of certain components of the U.S. Intelligence Community. Importantly, EO 12333 does not include any authorization to compel private companies, such as Microsoft, to disclose customer data, and Microsoft would not comply with a request from the U.S. government under EO 12333 for Microsoft to voluntarily provide personal data.

EO 12333 doesn’t need to compel Microsoft to do anything, because it authorizes collection that happens upstream of Microsoft (at the network level, before data ever reaches or leaves Microsoft’s servers). Concretely documented examples:

  • MUSCULAR (2013, Snowden): NSA and GCHQ tapped the fiber links between Google’s and Yahoo’s data centers. Traffic that was unencrypted internally between their own infrastructure. No court order. No company notification.
  • UPSTREAM collection: NSA taps backbone internet infrastructure under EO 12333 authority, intercepting traffic in transit. Microsoft and Google may have no knowledge this is happening to their users’ data.