Cloud storage companies and tech contractors
- If you are an approved vendor contracted by U.S. law enforcement, you would have legal protection against most civil suits and criminal charges for performing your contract duties — except in certain misconduct cases.
- You must meet technical rules: follow the NIST Cybersecurity Framework, use end-to-end encryption (or equivalent), limit employee access, run yearly independent cybersecurity audits, and fix audit problems promptly.
- You must keep the data and analytics inside the United States and file a notice with the Department of Justice within 30 days of starting a contract.
- If a law enforcement agency breaches or cancels the contract (or fails to pay), you must notify DOJ or the state attorney general and keep preserving the evidence until it is lawfully transferred.
Law enforcement and prosecutors
- Agencies can hire approved vendors to store and analyze child sexual abuse material and require the vendor to provide access and forensic services on request.
- Agencies must follow FBI CJIS security policy and keep evidence for required retention periods or at least until applicable statutes of limitation or sentence/post-conviction review periods end.
Department of Justice and state attorneys general
- DOJ receives mandatory notification letters when vendors start contracts and when contracts are breached or terminated.
- DOJ or state AGs may become the next lawful custodian of evidence if a contract is terminated.
Victims, families, and civil plaintiffs
- The bill could affect the ability to bring some legal actions against vendors. Lawsuits and criminal charges remain possible in certain cases described in the bill, but the precise scope is not fully clear from the text.