Home › Cybercrime Law › Module 10 · Direct access
Module 10 · Direct access and mutual trust: new models for transnational digital investigations
What this module covers and why it matters. This module covers a shift in how states reach evidence held abroad. The old route is mutual legal assistance, meaning one state formally asks another for help and waits. The new route is direct access, meaning a state serves its own order straight on a service provider in another country and the provider complies. This shift is built on mutual trust between close allies rather than on case-by-case approval by the state where the data sits. The module sits at the end of the subject's arc from offences to jurisdiction to investigations to cooperation. It follows Module 9 on extradition and mutual legal assistance and it explains the arrangements that are now displacing that older cooperation. Because the assessment is a 3000-word research essay the Debate section is the part to mine hardest. The centrepiece is a comparison table of the four direct-access mechanisms.
How to use this guide. The framed boxes give you a scaffold you can carry into an answer. The comparison table is the spine of the module and every later section refers back to it. The Debate section sets out the live controversies as two-sided contests and each closes with critical-analysis questions to test your own view. Read the guide once to learn the map and then return to the table and the Debate to revise from.
Instruments at a glance
Four instruments recur in this module. Meet them once here and then use the table below to compare them.
| Instrument | Key provisions | What it does |
|---|---|---|
| United States CLOUD Act 2018 | 18 USC s 2713 (extraterritorial reach of provider obligations); 18 USC s 2523 (executive agreements); s 2703(h) (comity ground to quash) | Requires US providers to disclose data in their control wherever stored. Lets the US enter reciprocal executive agreements with qualifying foreign governments for direct cross-border access |
| Australia-US CLOUD Act Agreement | Agreement on Access to Electronic Data for the Purpose of Countering Serious Crime, signed 15 December 2021, in force 30 January 2024 | The reciprocal executive agreement between Australia and the United States. Lets each country's agencies order data direct from the other's providers for serious crime |
| Telecommunications Legislation Amendment (International Production Orders) Act 2021 (Cth) (the IPO Act) | Inserts Schedule 1 into the TIA Act 1979, creating the international production order framework, the issuing authority and the Australian Designated Authority | Australia's domestic implementing law. It was the change Australia had to make to become a qualifying partner under the CLOUD Act |
| EU e-Evidence Regulation (EU) 2023/1543 | European Production Order and European Preservation Order; notification of the enforcing state for traffic and content data; grounds for refusal | Lets an authority in one Member State serve a production or preservation order direct on a provider offering services in the Union, regardless of where the data sits |
| Second Additional Protocol to the Budapest Convention (CETS 224, 2022) | Art 6 domain-name registration data; art 7 direct disclosure of subscriber information; art 8 orders given effect by the receiving Party; art 14 data-protection safeguards | Adds direct and expedited cooperation tools to the Budapest framework. Its headline direct-access power in art 7 reaches subscriber information only |
Attack plan
Use this fixed order when a problem asks how an agency can reach evidence held by a provider in another country.
Attack plan. Work a cross-border access problem in this order. First, locate the evidence and the provider. Ask which country holds the data and which country the provider answers to, because the available route depends on both. Second, ask whether a direct-access arrangement is in force between the two states. If a CLOUD Act agreement, the IPO framework, the e-Evidence Regulation or the Second Additional Protocol applies, a direct order may be possible. Third, match the data sought to the mechanism. Subscriber information, traffic data and content data are treated differently, and the Second Additional Protocol's direct route reaches subscriber data only. Fourth, check the issuing conditions. Confirm the seriousness threshold, the targeting limits and the authority that must issue or review the order. Fifth, identify the safeguards and the review. Ask who oversees the order, whether the data subject is notified and where any challenge must be brought. Sixth, fall back to mutual legal assistance if no direct route fits, and note the rights implications of each choice for the data subject.
From mutual legal assistance to direct access
What this section covers and why it matters. Before you can compare the four mechanisms you need the problem they answer. This section explains why mutual legal assistance no longer copes with cloud evidence and what direct access does instead. The reason matters because the whole module is a response to a single practical failure.
Start with the failure. Walden sets out the position an investigator faces when the evidence sits with a foreign cloud provider. There are in substance four courses of action. The investigator can start formal mutual legal assistance through a treaty, can seek informal cooperation from the foreign agency, can ask the foreign provider directly for voluntary help, or can reach the material directly (Walden, in Millard ch 11). Mutual legal assistance is the orthodox route and it is the slow one. Walden describes these procedures as notoriously complex, slow and bureaucratic, which is a poor fit for data that can be moved or deleted in seconds (Walden, in Millard ch 11).
Cloud computing sharpens the problem. Data is stored at a location the user often cannot identify, controlled by a company headquartered in a third country, and relates to a person who may be somewhere else again. Hörnle draws out the three connecting factors a state might use to found investigatory jurisdiction over such data. They are the place where the person controlling the data sits, the place where the data is stored, and the place where the data subject is located. Each is unsatisfactory on its own (Hörnle ch 6).
The Microsoft Ireland litigation exposed the gap. US law enforcement sought emails that Microsoft controlled from the United States but stored in a data centre in Dublin. The Second Circuit held that a warrant under the Stored Communications Act did not reach data stored abroad because the statute did not envisage extraterritorial application. That decision told the US government it would have to use cumbersome mutual assistance every time data was held offshore, and it drove the legislative response (Hörnle ch 6).
Worked example. An Australian agency investigating an online fraud needs the content of a suspect's email account. The provider is headquartered in the United States and the data may sit on a server anywhere in the provider's network. Under mutual legal assistance Australia would ask the United States to obtain and transfer the material, which can take many months. Under the Australia-US CLOUD Act Agreement the agency can instead serve an international production order that reaches the provider directly. The evidence is the same. The route and the speed are not.
Consolidation. Direct access exists because mutual legal assistance is too slow for cloud evidence. Each of the four mechanisms in this module is a way of letting a state's order reach a foreign provider without waiting for the other state to act. What each gives up in exchange is the subject of the rest of the module.
What mutual trust means
What this section covers and why it matters. Direct access only works if the state where the provider sits is willing to let a foreign order take effect on its territory. The concept that justifies this willingness is mutual trust. This section defines it and shows why it is contested, because the whole architecture of direct access rests on it.
Mutual recognition is the older idea and mutual trust is its foundation. Within the European Union mutual recognition means a judicial decision made in one Member State is recognised and given effect in another, almost automatically and with almost no questions asked (Hörnle ch 6, citing Mitsilegas). The ideological underpinning is mutual trust, meaning each state trusts the others to respect the rule of law and fundamental rights, not only for their own citizens but for everyone (Hörnle ch 6). International cooperation in criminal matters always needs some degree of trust in the other state's legal system. Direct access needs a great deal of it, because the state where the data sits gives up its usual chance to screen the request.
The critical question is whether that trust can be assessed once and in advance or must be checked case by case. Hörnle frames this as the central problem. A system that presumes trust categorically and a priori is efficient but risky, because a country's legal situation can change and a general finding of compliance is no comfort to an individual whose rights have in fact been infringed (Hörnle ch 6). Her verdict on the CLOUD Act model is pointed. She argues that an international version of presumed mutual trust is dangerous, because compliance with fundamental rights needs to be checked on a case-by-case basis and not only a priori (Hörnle ch 6).
Consolidation. Mutual trust is the belief that a partner state's legal system protects rights well enough that its orders can be honoured with little scrutiny. It is what lets direct access work and it is the thing critics say is granted too cheaply. Hold this tension because every mechanism in the comparison table sits somewhere on it.
The four mechanisms
What this section covers and why it matters. This section states each mechanism as an operative rule so you can pin the authority in an answer. The four differ in the data they reach, the safeguards they carry, the review they allow and who they mainly serve. The comparison table that follows lays those four axes side by side and is the centrepiece of the module.
The four direct-access mechanisms compared
This table is the centrepiece. Read the four mechanisms down the same four axes and use it as the frame for any essay on cross-border access.
| Axis | CLOUD Act agreements | IPO Act 2021 (Australia) | EU e-Evidence Regulation | Second Additional Protocol |
|---|---|---|---|---|
| Scope of data reached | Metadata and content data, and interception under some agreements, for serious crime | Stored communications, telecommunications data and interception product, for offences punishable by at least three years | Subscriber, access, transactional and content data held by a provider offering services in the Union | Direct art 7 route reaches subscriber information only. Traffic data comes through art 8 orders given effect by the receiving Party |
| Safeguards | Order must be targeted, based on articulable facts and lawful under the issuing state's law. Targeting limits protect the other state's persons | Seriousness threshold, targeting limits, and Designated Authority review for agreement compliance. Rests on the issuing state's law | Notification of the enforcing state for traffic and content data with suspensive effect. Defined grounds of refusal | Art 7 requires the order to state the offence and legal grounds. Art 14 data-protection safeguards apply. Reservation and supervision options |
| Review or oversight | Judicial review or oversight in the issuing state. No case-by-case review in the state where the data sits | Issuing authority plus post-issue Designated Authority review. Challenge lies in the issuing state | Judicial or independent authority issues the order. Enforcing state may raise refusal grounds. Data-subject review in the issuing state | Optional judicial or independent supervision by declaration. Enforcement of art 8 orders runs through the receiving Party |
| Who primarily benefits | Contested. The mechanism is reciprocal but critics say US data power makes it one-sided in favour of the United States | Australian agencies gain fast access to US-held data. Australia had to legislate the IPO framework to qualify | EU Member States gain reach over providers in the Union and stronger negotiating power with the United States | The requesting Party gains fast subscriber data. The narrow scope limits the benefit and preserves more of the receiving state's control |
Consolidation. The four mechanisms all replace waiting with a direct order, but they differ sharply on scope and on how much the receiving state gives up. The CLOUD Act agreements reach the widest data and cede the most sovereignty. The Second Additional Protocol's direct route reaches the least data and cedes the least. The IPO Act is Australia's key into the CLOUD Act system, and the e-Evidence Regulation is the intra-EU counterpart built on mutual recognition.
Common confusions
These are the errors that cost marks. Each states the mistake and then the correction.
Debate
This is the centre of gravity for the research essay. Each strand is a two-sided contest with the leading voices named and each closes with critical-analysis questions to test a position rather than settle it.
What does a state give up when it enters a mutual-trust agreement? Direct access is presented as reciprocal and efficient, and Daskal describes the executive-agreement model as a novel and workable way of building cross-border cooperation through a series of bilateral deals with minimum procedural safeguards (Hörnle ch 6, citing Daskal). Against that, Hörnle argues the model rests on a mutual cessation of sovereignty. The state where the provider sits gives up its usual power to screen a foreign request on its own territory, and it does so on a general and a priori finding of trust rather than a check in each case (Hörnle ch 6). Her sharpest point is that a country's legal situation can change after the agreement is signed, so trust warranted at signing may not be warranted later, and a general finding of compliance is no comfort to the individual whose rights are in fact infringed (Hörnle ch 6). The strand turns on whether efficiency is worth the loss of case-by-case control over what happens to data on one's own soil.
- Is a one-off finding that a partner state respects rights an adequate substitute for reviewing each order where the data is held?
- If a partner state's rights record deteriorates after an agreement is signed, what in the mechanism corrects for it?
Is the Second Additional Protocol's subscriber-data limitation a strength or a weakness? The Protocol's headline direct-access power in art 7 reaches subscriber information only, and traffic data must come through art 8 orders that the receiving Party gives effect to. One reading treats the limit as a principled safeguard. Subscriber data is less intrusive than traffic or content data, so confining unilateral direct access to it preserves more of the receiving state's control and protects the data subject. The other reading treats the limit as a failure of ambition. Davies and Kennedy-Mayo argue the Protocol is unlikely to achieve its stated objectives, because its utility is constrained by legal fragmentation and by potential conflicts with domestic data-protection law, so the very caution that produced the narrow scope also blunts the tool (Davies and Kennedy-Mayo 2026). The limitation reveals a choice about the rights of data subjects. It says that direct foreign access is tolerable for identifying data but not yet for the content of a person's communications, which places subscriber data on the wrong side of the privacy line for some and the right side for others.
- Does confining direct access to subscriber data protect the data subject or simply relocate the same intrusion to a slower channel?
- If subscriber data can identify a person and link them to an account, is treating it as low-sensitivity defensible?
Who is the primary beneficiary of a CLOUD Act agreement, the United States or the qualifying foreign government? On its face the agreement is mutual, and each side may serve orders on the other's providers. Hörnle argues the reciprocity is largely formal. Because so much of the world's data is held or controlled by US-headquartered companies, the flow that matters is foreign agencies reaching US-held data, so the US wields superior data power and the agreements are likely to be one-sided in its favour (Hörnle ch 6). She reads the CLOUD Act as using that power to win concessions on sovereignty from partner states who negotiate from a weaker position (Hörnle ch 6). The asymmetry is written into the terms. Under the US-UK Agreement the foreign government may obtain data only for serious crime while no equivalent limit binds the US, and the data-minimisation duties fall on the foreign partner and not on the US (Hörnle ch 6). The counter-argument is that the foreign government is the real winner in practice, because it gains fast access to data it previously could reach only through slow mutual assistance, and providers gain the legal certainty they wanted (Hörnle ch 6, noting Google's support). The strand asks whether formal reciprocity can be trusted when bargaining power is so unequal.
- If reciprocity is formal but the data flows mostly one way, which state is the mechanism really built for?
- Do the asymmetric targeting and minimisation terms in the US-UK Agreement show the balance the US can extract, or just one negotiation?
Whose rights does direct access protect, the provider's or the data subject's? Hörnle draws a distinction that runs through every mechanism. Providers need legal certainty about when they must comply with a foreign order, and the CLOUD Act supplies it. Data subjects need enforceable privacy standards and accessible review, and the CLOUD Act does not supply those, because it relies on the safeguards of the issuing state and offers no case-by-case review in the state where the data sits (Hörnle ch 6). The same criticism reaches the e-Evidence Regulation. Hörnle notes that a data subject must bring any challenge in the issuing Member State, which may mean costly cross-border litigation, and that the Regulation is more concerned with the interests of the states involved than with the fundamental rights of the data subject (Hörnle ch 6). The defence is that harmonised minimum safeguards plus notification of the enforcing state, as the e-Evidence Regulation now provides for traffic and content data, are a real advance on the near-invisible position under mutual legal assistance. The strand turns on whether a system built for provider certainty can be retrofitted with rights that the data subject can actually use.
- Should the data subject be able to challenge a cross-border order where they live rather than in the issuing state?
- Is notification of the enforcing state a meaningful safeguard for the individual, or only for the two governments?
Discussion prompts
- Explain what "mutual trust" means in transnational digital investigations and assess whether it can safely be found once and in advance rather than checked in each case.
- Set out the factors a state should weigh before entering a direct-access agreement and argue which factor should carry the most weight.
- Evaluate the claim that the United States is the primary beneficiary of a CLOUD Act agreement, drawing on the reciprocity terms and Hörnle's data-power argument.
- Explain what change the Australia-US CLOUD Act Agreement required Australia to make and why, and assess whether the IPO Act framework gives data subjects adequate protection.
- Consider whether the Second Additional Protocol's direct-access power should be limited to subscriber data, and explain what that limitation indicates about the fundamental rights of data subjects.
- Compare the four direct-access mechanisms on the scope of data reached and on the review available to the data subject, and say which model best balances effectiveness against rights.
Check your understanding
Auto-marked drills. Answer, then read the authority in the feedback.