What is the UK US Data Access Agreement?
10th August 2022
What is the UK US Data Access Agreement?
The UK US Data Access Agreement was first heralded with much fanfare back in 2018. At the time, the Agreement was declared to be a ‘landmark’ Agreement and a world-first. It is finally due to come into force on 3 October 2022. So, what is the UK US Data Access Agreement, why do we need it and who is it going to affect?
What is the UK US Data Access Agreement?
It is an Agreement between the two territories, which is designed to make the sharing of data, for the purpose of criminal investigations, easier.
Specifically, it is aimed at Communication Service Providers (CSPs) – such as Facebook and Telecoms companies for example. The Agreement means that law enforcement agencies from either the UK or the US, with proper court authority, can demand electronic data from the CSPs, in order to investigate serious crime.
Why do we need the UK US Data Access Agreement?
Law enforcement can request this information now via something called Overseas Production Orders (OPOs), but it is frequently an incredibly lengthy process – we are talking many months and very often years to come to fruition – which of course hinders investigations and risks repeat offence and leaves people vulnerable to attack in the meantime.
When you consider the ‘serious’ crimes in question, it is clear that speed could often be of the essence: The Agreement is designed exclusively for the purpose of: “preventing, detecting, investigating and prosecuting serious crimes such as terrorism and child sexual abuse and exploitation”(source www.Gov.uk: Factsheet).
Perhaps one of the biggest differences between the OPOs and the new Agreement is that the process is controlled by the courts of the REQUESTING country.
Who is it going to affect?
It is expected that many more requests will be made by UK law enforcement agencies to US Communication Services Providers – because so many of the big cloud communication companies are based in the US.
For example, Meta who owns Facebook announced yesterday, 11 august 2022 that they are testing end-to-end encryption as the default in the messenger app – it is already the default in WhatsApp which they also own. Messages on these platforms require information requests to be made to US authorities.
The legislative burden on the US is lessened by the Data Access Agreement compared to the onerous OPO system – ie it will make it easier for them to comply.
The big win is that the whole process will be speeded up – making just a few days from request to receipt of data a possibility – this is a step that will help enforcement agencies get much more speedy access to the evidence they need to bring perpetrators of serious crime to justice.
“This agreement is the latest demonstration of the strength of the bond between the United States and the United Kingdom, and our commitment to robust co-operation in the future”
Data Protection practitioners need to bear in mind that if you are in the UK and you are requested to produce data by the US law enforcement – under the UK GDPR, and additionally the Schrems II decision, you must ensure any international transfers take place with the relevant risk assessments and safeguard practices.
We have recently seen many EU data protection authorities make the transfer of data to companies like Google in the US unlawful; if US law enforcement can gain easier access to UK datasets via this new mechanism, we may find our adequacy decision with the EU cancelled, and data transfers to the UK in general also brought into question.
If you have any questions or queries as to whether this might affect you and if so, what you should do about it, please do take advantage of your complimentary 30-minute consultation with one of our data protection specialists. Book yours here.