Approved vendor storage for law enforcement

Full Title:
Safe Cloud Storage Act

Summary#

The bill adds a new law to let certain cloud storage companies work for law enforcement by storing child sexual abuse material (called “child pornography” in federal law) and by limiting lawsuits or criminal charges against those companies for doing that work. It also sets security rules for vendors, requires evidence to stay in the United States, and requires vendors to notify the Department of Justice (or a state attorney general) in some circumstances.

  • Main change: Creates a new category of “approved vendor” for law enforcement evidence storage and gives those vendors broad protection from civil claims and criminal charges for carrying out their contract duties, with listed exceptions for misconduct.
  • Security and custody rules: Approved vendors must follow specific cybersecurity steps (NIST framework, encryption, audits), limit access, and keep the stored material in the U.S.
  • Notification and custody: Vendors must tell the Department of Justice within 30 days of a contract and must notify DOJ or state attorneys general if an agency stops paying or breaches the contract; vendors must preserve evidence until lawful transfer.
  • Evidence retention: Agencies using cloud storage must keep evidence according to FBI CJIS security policy and usual retention or statute-of-limitations periods.
  • Unclear points: The bill does not clearly define “child obscenity,” and the standards that allow lawsuits (negligence vs. malice/recklessness) are written in a way that could be confusing.

What it means for you#

  • Cloud storage companies and tech contractors

    • If you are an approved vendor contracted by U.S. law enforcement, you would have legal protection against most civil suits and criminal charges for performing your contract duties — except in certain misconduct cases.
    • You must meet technical rules: follow the NIST Cybersecurity Framework, use end-to-end encryption (or equivalent), limit employee access, run yearly independent cybersecurity audits, and fix audit problems promptly.
    • You must keep the data and analytics inside the United States and file a notice with the Department of Justice within 30 days of starting a contract.
    • If a law enforcement agency breaches or cancels the contract (or fails to pay), you must notify DOJ or the state attorney general and keep preserving the evidence until it is lawfully transferred.
  • Law enforcement and prosecutors

    • Agencies can hire approved vendors to store and analyze child sexual abuse material and require the vendor to provide access and forensic services on request.
    • Agencies must follow FBI CJIS security policy and keep evidence for required retention periods or at least until applicable statutes of limitation or sentence/post-conviction review periods end.
  • Department of Justice and state attorneys general

    • DOJ receives mandatory notification letters when vendors start contracts and when contracts are breached or terminated.
    • DOJ or state AGs may become the next lawful custodian of evidence if a contract is terminated.
  • Victims, families, and civil plaintiffs

    • The bill could affect the ability to bring some legal actions against vendors. Lawsuits and criminal charges remain possible in certain cases described in the bill, but the precise scope is not fully clear from the text.

Expenses#

No publicly available information.

  • The bill requires annual independent cybersecurity audits and corrective actions. Those create compliance costs for vendors (audit fees, technical work, staffing limits).
  • Requiring data to remain in the United States may raise costs for vendors that use international cloud infrastructure or global data centers.
  • Vendors must preserve evidence after a contract breach or termination until transfer. That could create storage and legal costs for vendors.
  • Agencies may face administrative costs for complying with FBI CJIS security policies and for managing transfers when contracts end.
  • The bill itself does not include a federal spending estimate in the supplied material.

Proponents' View#

  • The bill appears intended to modernize how law enforcement stores and analyzes child sexual abuse material by enabling private cloud vendors to provide storage and forensic support.
  • Supporters may argue limiting liability will make vendors more willing to enter contracts with law enforcement and thus improve investigators’ technical capacity.
  • The bill sets clear security expectations (NIST framework, encryption, audits), which could be seen as protecting evidence integrity and reducing leaks.
  • Requiring data to stay in the U.S. and mandating notifications and preservation of evidence seeks to preserve chain of custody and make transfer to other agencies orderly.

Opponents' View#

  • One concern is that broad liability protection could reduce vendors’ incentives to prevent misuse or to handle material with extra caution, especially where the limits on liability are not clearly defined.
  • The bill’s language about when claims are allowed is unclear. It lists both “negligent conduct” and standards like “actual malice” and “reckless disregard,” which could create confusion about when lawsuits or criminal charges are allowed.
  • The bill refers to “child obscenity” but does not define that term, which may create legal uncertainty.
  • Requiring U.S.-only storage and annual independent audits could raise significant compliance costs for vendors, especially smaller firms, and might limit the pool of available vendors.
  • The bill does not explain what the Department of Justice must do after receiving notifications, or how oversight of approved vendors will be enforced.