HomeCybercrime Law › Module 10 · Direct access

Module 10 · Direct access and mutual trust: new models for transnational digital investigations

What this module covers and why it matters. This module covers a shift in how states reach evidence held abroad. The old route is mutual legal assistance, meaning one state formally asks another for help and waits. The new route is direct access, meaning a state serves its own order straight on a service provider in another country and the provider complies. This shift is built on mutual trust between close allies rather than on case-by-case approval by the state where the data sits. The module sits at the end of the subject's arc from offences to jurisdiction to investigations to cooperation. It follows Module 9 on extradition and mutual legal assistance and it explains the arrangements that are now displacing that older cooperation. Because the assessment is a 3000-word research essay the Debate section is the part to mine hardest. The centrepiece is a comparison table of the four direct-access mechanisms.

How to use this guide. The framed boxes give you a scaffold you can carry into an answer. The comparison table is the spine of the module and every later section refers back to it. The Debate section sets out the live controversies as two-sided contests and each closes with critical-analysis questions to test your own view. Read the guide once to learn the map and then return to the table and the Debate to revise from.

Instruments at a glance

Four instruments recur in this module. Meet them once here and then use the table below to compare them.

Instrument Key provisions What it does
United States CLOUD Act 2018 18 USC s 2713 (extraterritorial reach of provider obligations); 18 USC s 2523 (executive agreements); s 2703(h) (comity ground to quash) Requires US providers to disclose data in their control wherever stored. Lets the US enter reciprocal executive agreements with qualifying foreign governments for direct cross-border access
Australia-US CLOUD Act Agreement Agreement on Access to Electronic Data for the Purpose of Countering Serious Crime, signed 15 December 2021, in force 30 January 2024 The reciprocal executive agreement between Australia and the United States. Lets each country's agencies order data direct from the other's providers for serious crime
Telecommunications Legislation Amendment (International Production Orders) Act 2021 (Cth) (the IPO Act) Inserts Schedule 1 into the TIA Act 1979, creating the international production order framework, the issuing authority and the Australian Designated Authority Australia's domestic implementing law. It was the change Australia had to make to become a qualifying partner under the CLOUD Act
EU e-Evidence Regulation (EU) 2023/1543 European Production Order and European Preservation Order; notification of the enforcing state for traffic and content data; grounds for refusal Lets an authority in one Member State serve a production or preservation order direct on a provider offering services in the Union, regardless of where the data sits
Second Additional Protocol to the Budapest Convention (CETS 224, 2022) Art 6 domain-name registration data; art 7 direct disclosure of subscriber information; art 8 orders given effect by the receiving Party; art 14 data-protection safeguards Adds direct and expedited cooperation tools to the Budapest framework. Its headline direct-access power in art 7 reaches subscriber information only

Attack plan

Use this fixed order when a problem asks how an agency can reach evidence held by a provider in another country.

Attack plan. Work a cross-border access problem in this order. First, locate the evidence and the provider. Ask which country holds the data and which country the provider answers to, because the available route depends on both. Second, ask whether a direct-access arrangement is in force between the two states. If a CLOUD Act agreement, the IPO framework, the e-Evidence Regulation or the Second Additional Protocol applies, a direct order may be possible. Third, match the data sought to the mechanism. Subscriber information, traffic data and content data are treated differently, and the Second Additional Protocol's direct route reaches subscriber data only. Fourth, check the issuing conditions. Confirm the seriousness threshold, the targeting limits and the authority that must issue or review the order. Fifth, identify the safeguards and the review. Ask who oversees the order, whether the data subject is notified and where any challenge must be brought. Sixth, fall back to mutual legal assistance if no direct route fits, and note the rights implications of each choice for the data subject.

What this section covers and why it matters. Before you can compare the four mechanisms you need the problem they answer. This section explains why mutual legal assistance no longer copes with cloud evidence and what direct access does instead. The reason matters because the whole module is a response to a single practical failure.

Start with the failure. Walden sets out the position an investigator faces when the evidence sits with a foreign cloud provider. There are in substance four courses of action. The investigator can start formal mutual legal assistance through a treaty, can seek informal cooperation from the foreign agency, can ask the foreign provider directly for voluntary help, or can reach the material directly (Walden, in Millard ch 11). Mutual legal assistance is the orthodox route and it is the slow one. Walden describes these procedures as notoriously complex, slow and bureaucratic, which is a poor fit for data that can be moved or deleted in seconds (Walden, in Millard ch 11).

Cloud computing sharpens the problem. Data is stored at a location the user often cannot identify, controlled by a company headquartered in a third country, and relates to a person who may be somewhere else again. Hörnle draws out the three connecting factors a state might use to found investigatory jurisdiction over such data. They are the place where the person controlling the data sits, the place where the data is stored, and the place where the data subject is located. Each is unsatisfactory on its own (Hörnle ch 6).

The Microsoft Ireland litigation exposed the gap. US law enforcement sought emails that Microsoft controlled from the United States but stored in a data centre in Dublin. The Second Circuit held that a warrant under the Stored Communications Act did not reach data stored abroad because the statute did not envisage extraterritorial application. That decision told the US government it would have to use cumbersome mutual assistance every time data was held offshore, and it drove the legislative response (Hörnle ch 6).

Worked example. An Australian agency investigating an online fraud needs the content of a suspect's email account. The provider is headquartered in the United States and the data may sit on a server anywhere in the provider's network. Under mutual legal assistance Australia would ask the United States to obtain and transfer the material, which can take many months. Under the Australia-US CLOUD Act Agreement the agency can instead serve an international production order that reaches the provider directly. The evidence is the same. The route and the speed are not.

Consolidation. Direct access exists because mutual legal assistance is too slow for cloud evidence. Each of the four mechanisms in this module is a way of letting a state's order reach a foreign provider without waiting for the other state to act. What each gives up in exchange is the subject of the rest of the module.

What mutual trust means

What this section covers and why it matters. Direct access only works if the state where the provider sits is willing to let a foreign order take effect on its territory. The concept that justifies this willingness is mutual trust. This section defines it and shows why it is contested, because the whole architecture of direct access rests on it.

Mutual recognition is the older idea and mutual trust is its foundation. Within the European Union mutual recognition means a judicial decision made in one Member State is recognised and given effect in another, almost automatically and with almost no questions asked (Hörnle ch 6, citing Mitsilegas). The ideological underpinning is mutual trust, meaning each state trusts the others to respect the rule of law and fundamental rights, not only for their own citizens but for everyone (Hörnle ch 6). International cooperation in criminal matters always needs some degree of trust in the other state's legal system. Direct access needs a great deal of it, because the state where the data sits gives up its usual chance to screen the request.

The critical question is whether that trust can be assessed once and in advance or must be checked case by case. Hörnle frames this as the central problem. A system that presumes trust categorically and a priori is efficient but risky, because a country's legal situation can change and a general finding of compliance is no comfort to an individual whose rights have in fact been infringed (Hörnle ch 6). Her verdict on the CLOUD Act model is pointed. She argues that an international version of presumed mutual trust is dangerous, because compliance with fundamental rights needs to be checked on a case-by-case basis and not only a priori (Hörnle ch 6).

Consolidation. Mutual trust is the belief that a partner state's legal system protects rights well enough that its orders can be honoured with little scrutiny. It is what lets direct access work and it is the thing critics say is granted too cheaply. Hold this tension because every mechanism in the comparison table sits somewhere on it.

The four mechanisms

What this section covers and why it matters. This section states each mechanism as an operative rule so you can pin the authority in an answer. The four differ in the data they reach, the safeguards they carry, the review they allow and who they mainly serve. The comparison table that follows lays those four axes side by side and is the centrepiece of the module.

RULE. A provider of electronic communication or remote computing service must preserve, back up or disclose the content of a communication and any related record in its possession, custody or control, regardless of whether that material is located inside or outside the United States (US CLOUD Act, 18 USC s 2713).
RULE. The United States may enter an executive agreement giving a qualifying foreign government reciprocal direct access to data held by providers in the other state. The Attorney-General must certify, with the concurrence of the Secretary of State, that the foreign government affords robust privacy and civil-liberties protections (US CLOUD Act, 18 USC s 2523).
RULE. A disclosure order under a CLOUD Act agreement may be challenged on comity grounds only where the order would require the provider to break the law of the qualifying foreign government, the customer is not a United States person and does not reside in the United States, and quashing serves the interests of justice (US CLOUD Act, 18 USC s 2703(h)).
RULE. The Australia-US Agreement lets each country's agencies serve orders direct on providers in the other country for the investigation of serious crime, meaning conduct punishable by at least three years imprisonment. Australia may not target United States persons and the United States may not target persons located in Australia (Australia-US CLOUD Act Agreement, in force 30 January 2024).
RULE. The IPO Act inserts Schedule 1 into the TIA Act 1979 to create international production orders. An order is made by an issuing authority and is then reviewed by the Australian Designated Authority for compliance with the designated international agreement before it is given to the foreign provider (IPO Act 2021, TIA Act Sch 1).
RULE. An issuing authority may issue an international production order only where satisfied on reasonable grounds that a person is using or is likely to use the service and that the information would likely assist the investigation of an offence punishable by at least three years imprisonment (IPO Act 2021, TIA Act Sch 1).
RULE. An authority in one Member State may serve a European Production Order or European Preservation Order on a provider offering services in the Union, regardless of where the data is stored. For traffic data and content data the enforcing state must be notified and the notification suspends the duty to disclose (EU e-Evidence Regulation (EU) 2023/1543).
RULE. The enforcing authority may object to a European Production Order on defined grounds, including that the conduct is not an offence in the enforcing state, the protection of immunities and privileges, press freedom, a manifest breach of a fundamental right, and the rule against double jeopardy (EU e-Evidence Regulation (EU) 2023/1543).
RULE. A Party may issue an order directly to a service provider in the territory of another Party for the disclosure of subscriber information in the provider's possession or control. The order must state the offence, the applicable penalties and the domestic legal grounds for the request (Second Additional Protocol, CETS 224, art 7).
RULE. A Party may declare that an art 7 order must be issued by, or under the supervision of, a prosecutor or other judicial authority, or be otherwise subject to independent supervision. A Party may also reserve the right not to apply art 7 at all (Second Additional Protocol, CETS 224, art 7).
RULE. Where the Parties are not bound by a comprehensive data-protection agreement between them, the transfer of personal data under the Protocol is subject to the data-protection safeguards in art 14 (Second Additional Protocol, CETS 224, art 14).

The four direct-access mechanisms compared

This table is the centrepiece. Read the four mechanisms down the same four axes and use it as the frame for any essay on cross-border access.

Axis CLOUD Act agreements IPO Act 2021 (Australia) EU e-Evidence Regulation Second Additional Protocol
Scope of data reached Metadata and content data, and interception under some agreements, for serious crime Stored communications, telecommunications data and interception product, for offences punishable by at least three years Subscriber, access, transactional and content data held by a provider offering services in the Union Direct art 7 route reaches subscriber information only. Traffic data comes through art 8 orders given effect by the receiving Party
Safeguards Order must be targeted, based on articulable facts and lawful under the issuing state's law. Targeting limits protect the other state's persons Seriousness threshold, targeting limits, and Designated Authority review for agreement compliance. Rests on the issuing state's law Notification of the enforcing state for traffic and content data with suspensive effect. Defined grounds of refusal Art 7 requires the order to state the offence and legal grounds. Art 14 data-protection safeguards apply. Reservation and supervision options
Review or oversight Judicial review or oversight in the issuing state. No case-by-case review in the state where the data sits Issuing authority plus post-issue Designated Authority review. Challenge lies in the issuing state Judicial or independent authority issues the order. Enforcing state may raise refusal grounds. Data-subject review in the issuing state Optional judicial or independent supervision by declaration. Enforcement of art 8 orders runs through the receiving Party
Who primarily benefits Contested. The mechanism is reciprocal but critics say US data power makes it one-sided in favour of the United States Australian agencies gain fast access to US-held data. Australia had to legislate the IPO framework to qualify EU Member States gain reach over providers in the Union and stronger negotiating power with the United States The requesting Party gains fast subscriber data. The narrow scope limits the benefit and preserves more of the receiving state's control

Consolidation. The four mechanisms all replace waiting with a direct order, but they differ sharply on scope and on how much the receiving state gives up. The CLOUD Act agreements reach the widest data and cede the most sovereignty. The Second Additional Protocol's direct route reaches the least data and cedes the least. The IPO Act is Australia's key into the CLOUD Act system, and the e-Evidence Regulation is the intra-EU counterpart built on mutual recognition.

Common confusions

These are the errors that cost marks. Each states the mistake and then the correction.

Confusion. The CLOUD Act itself gives foreign governments access to US data. It does not. The Act requires US providers to disclose data wherever stored and creates the power to enter executive agreements. A foreign government gains direct access only once a reciprocal agreement is certified and in force (US CLOUD Act, 18 USC ss 2713, 2523).
Confusion. The Australia-US Agreement and the IPO Act are the same instrument. They are not. The Agreement is the bilateral executive agreement between the two governments. The IPO Act is Australia's domestic law inserting Schedule 1 into the TIA Act, and it was the legislative change Australia had to make to qualify for the Agreement (IPO Act 2021; Australia-US CLOUD Act Agreement).
Confusion. The Second Additional Protocol lets a state directly order any data from a foreign provider. It does not. The direct disclosure power in art 7 reaches subscriber information only. Traffic data is reached through art 8, which relies on the receiving Party to give the order effect (Second Additional Protocol, CETS 224, arts 7 and 8).
Confusion. The e-Evidence Regulation is still only a Commission proposal. It is not. It was adopted as Regulation (EU) 2023/1543 in July 2023 and applies from 18 August 2026. Older sources describing a draft predate its adoption (EU e-Evidence Regulation (EU) 2023/1543).
Confusion. Direct access removes the need for judicial oversight. It does not. Each mechanism keeps some oversight, but it usually sits in the issuing state rather than the state where the data is held, which is precisely the feature critics attack (Hörnle ch 6).

Debate

This is the centre of gravity for the research essay. Each strand is a two-sided contest with the leading voices named and each closes with critical-analysis questions to test a position rather than settle it.

What does a state give up when it enters a mutual-trust agreement? Direct access is presented as reciprocal and efficient, and Daskal describes the executive-agreement model as a novel and workable way of building cross-border cooperation through a series of bilateral deals with minimum procedural safeguards (Hörnle ch 6, citing Daskal). Against that, Hörnle argues the model rests on a mutual cessation of sovereignty. The state where the provider sits gives up its usual power to screen a foreign request on its own territory, and it does so on a general and a priori finding of trust rather than a check in each case (Hörnle ch 6). Her sharpest point is that a country's legal situation can change after the agreement is signed, so trust warranted at signing may not be warranted later, and a general finding of compliance is no comfort to the individual whose rights are in fact infringed (Hörnle ch 6). The strand turns on whether efficiency is worth the loss of case-by-case control over what happens to data on one's own soil.

Is the Second Additional Protocol's subscriber-data limitation a strength or a weakness? The Protocol's headline direct-access power in art 7 reaches subscriber information only, and traffic data must come through art 8 orders that the receiving Party gives effect to. One reading treats the limit as a principled safeguard. Subscriber data is less intrusive than traffic or content data, so confining unilateral direct access to it preserves more of the receiving state's control and protects the data subject. The other reading treats the limit as a failure of ambition. Davies and Kennedy-Mayo argue the Protocol is unlikely to achieve its stated objectives, because its utility is constrained by legal fragmentation and by potential conflicts with domestic data-protection law, so the very caution that produced the narrow scope also blunts the tool (Davies and Kennedy-Mayo 2026). The limitation reveals a choice about the rights of data subjects. It says that direct foreign access is tolerable for identifying data but not yet for the content of a person's communications, which places subscriber data on the wrong side of the privacy line for some and the right side for others.

Who is the primary beneficiary of a CLOUD Act agreement, the United States or the qualifying foreign government? On its face the agreement is mutual, and each side may serve orders on the other's providers. Hörnle argues the reciprocity is largely formal. Because so much of the world's data is held or controlled by US-headquartered companies, the flow that matters is foreign agencies reaching US-held data, so the US wields superior data power and the agreements are likely to be one-sided in its favour (Hörnle ch 6). She reads the CLOUD Act as using that power to win concessions on sovereignty from partner states who negotiate from a weaker position (Hörnle ch 6). The asymmetry is written into the terms. Under the US-UK Agreement the foreign government may obtain data only for serious crime while no equivalent limit binds the US, and the data-minimisation duties fall on the foreign partner and not on the US (Hörnle ch 6). The counter-argument is that the foreign government is the real winner in practice, because it gains fast access to data it previously could reach only through slow mutual assistance, and providers gain the legal certainty they wanted (Hörnle ch 6, noting Google's support). The strand asks whether formal reciprocity can be trusted when bargaining power is so unequal.

Whose rights does direct access protect, the provider's or the data subject's? Hörnle draws a distinction that runs through every mechanism. Providers need legal certainty about when they must comply with a foreign order, and the CLOUD Act supplies it. Data subjects need enforceable privacy standards and accessible review, and the CLOUD Act does not supply those, because it relies on the safeguards of the issuing state and offers no case-by-case review in the state where the data sits (Hörnle ch 6). The same criticism reaches the e-Evidence Regulation. Hörnle notes that a data subject must bring any challenge in the issuing Member State, which may mean costly cross-border litigation, and that the Regulation is more concerned with the interests of the states involved than with the fundamental rights of the data subject (Hörnle ch 6). The defence is that harmonised minimum safeguards plus notification of the enforcing state, as the e-Evidence Regulation now provides for traffic and content data, are a real advance on the near-invisible position under mutual legal assistance. The strand turns on whether a system built for provider certainty can be retrofitted with rights that the data subject can actually use.

Discussion prompts

  1. Explain what "mutual trust" means in transnational digital investigations and assess whether it can safely be found once and in advance rather than checked in each case.
  2. Set out the factors a state should weigh before entering a direct-access agreement and argue which factor should carry the most weight.
  3. Evaluate the claim that the United States is the primary beneficiary of a CLOUD Act agreement, drawing on the reciprocity terms and Hörnle's data-power argument.
  4. Explain what change the Australia-US CLOUD Act Agreement required Australia to make and why, and assess whether the IPO Act framework gives data subjects adequate protection.
  5. Consider whether the Second Additional Protocol's direct-access power should be limited to subscriber data, and explain what that limitation indicates about the fundamental rights of data subjects.
  6. Compare the four direct-access mechanisms on the scope of data reached and on the review available to the data subject, and say which model best balances effectiveness against rights.

Check your understanding

Auto-marked drills. Answer, then read the authority in the feedback.