Investigations
Is a cross-border request made to a country or to a company?
Both exist and they are different instruments. Mutual assistance and the European Investigation Order run state to state; a European Production Order is addressed to a provider’s establishment in another Member State; and the Second Additional Protocol contains one of each.
In short
A cross-border request has an addressee, and the addressee is the thing that changes most between mechanisms. Some go to a government, which then decides under its own law whether to act. Some go to a company, or to a person a company has been obliged to appoint. The difference determines who evaluates the request, whose law governs the evaluation, and whether a second State ever sees it.
Why it exists
AnalysisThe state-to-state route is the older one and answers the sovereignty problem directly: nothing happens on another State’s territory without that State deciding it should. Its cost is that a second legal system has to be engaged for every request, however routine the material.
AnalysisThe provider-addressed route answers a different problem. Where a service is offered across many countries, the material sought is held by one company that could simply be asked — and requiring an inter-governmental process for an account name is disproportionate to what is being sought. The response has been to build narrow routes to the provider, and to keep the wider ones running through States.
How it works
The Convention on Cybercrime is entirely state-to-state. Article 25(1) obliges Parties to afford one another mutual assistance; Articles 29 and 31 are requests from one Party to another; Article 27(2) routes them through designated central authorities. Nothing in Chapter III is addressed to a company.
The European Investigation Order is also state-to-state, and its own definition says so. Article 1(1) of Directive 2014/41/EU defines it as "a judicial decision … issued or validated by a judicial authority of a Member State … to have one or several specific investigative measure(s) carried out in another Member State", executed under Article 1(2) on the principle of mutual recognition. The measure is carried out by the executing State.
A European Production Order is not. Article 3(1) of Regulation (EU) 2023/1543 defines it as a decision "addressed to a designated establishment or to a legal representative of a service provider offering services in the Union, where that designated establishment or legal representative is located in another Member State bound by this Regulation". The addressee is the provider’s point of contact.
- The Second Additional Protocol contains one of each
- Article 7(1) empowers authorities "to issue an order to be submitted directly to a service provider in the territory of another Party" — provider-addressed. Article 8(1) empowers them to issue an order "to be submitted as part of a request to another Party" compelling a provider in the requested Party’s territory to produce — state-addressed, with the provider reached through the requested Party.
- And a third form addressed to neither
- Article 6(1) provides for a request — not an order — to an entity providing domain name registration services in another Party’s territory, for information identifying or contacting a registrant, which under Article 6(2) that entity may disclose "subject to reasonable conditions provided by domestic law".
- A fourth runs between designated contacts
- Article 9(1)(a) lets the Convention’s 24/7 point of contact transmit and receive requests seeking immediate assistance in obtaining expedited disclosure from a provider in another Party’s territory "without a request for mutual assistance".
- When the two obligations collide
- Article 17 of the EU Regulation lets an addressee that considers compliance would conflict with a third country’s law raise a reasoned objection, which may not rest merely on the absence of similar provisions there. Section 2703(h)(2)(A) of Title 18 lets a provider — including a foreign provider — move to modify or quash where it reasonably believes the customer is not a United States person and does not reside there, and that disclosure would create a material risk of violating the laws of a qualifying foreign government.
Common misconceptions
Widely held beliefs that do not match how the system actually operates.
Common belief: Cross-border evidence requests go from one government to another.
In practice: Some do and some do not. A European Production Order is addressed to a provider’s designated establishment or legal representative in another Member State, and Article 7 of the Second Additional Protocol provides for an order submitted directly to a service provider in another Party.
Common belief: An order addressed to a company is a way around the other state.
In practice: Article 8(1) of the EU Regulation requires the enforcing authority to be notified where the order seeks traffic data other than identification data, or content data, and Article 8(4) suspends the addressee’s obligations meanwhile except in emergencies.
Common belief: A European Investigation Order and a European Production Order are the same instrument.
In practice: An EIO has measures carried out in another Member State by that State, on mutual recognition. A European Production Order is addressed to a provider’s establishment or legal representative. The Regulation’s recital 8 states why both exist.
Common belief: Direct routes to providers reach whatever a state-to-state request would.
In practice: They reach less. Article 7 of the Protocol reaches specified, stored subscriber information; traffic data requires the Article 8 route through the requested Party; content data is in neither and remains with Convention mutual assistance.
Common belief: A provider faced with conflicting legal obligations simply chooses one.
In practice: Both instruments read here provide a route. EU Regulation Article 17 provides for a reasoned objection to the issuing and enforcing authorities; 18 U.S.C. § 2703(h)(2)(A) provides for a motion to modify or quash on stated beliefs.
Which foreign governments qualify for the United States mechanism turns on executive agreements that were not researched here.
Common belief: Because some routes go straight to companies, states are no longer involved.
In practice: Every provider-addressed mechanism read here exists inside a treaty or a regulation that States made, obliges States to legislate, and keeps a role for the other State in the more intrusive cases.
How this varies between jurisdictions
A required section on every guide. Arrangements differ between countries, and we say how.
Who the request is addressed to, mechanism by mechanism.
- State to state, through central authorities — Convention on Cybercrime, Arts. 25, 27, 29, 31.
- State to state, by judicial decision on mutual recognition, measures carried out by the executing State — Directive 2014/41/EU, Art. 1(1)–(2).
- Authority to the provider’s designated establishment or legal representative in another Member State — Regulation (EU) 2023/1543, Art. 3(1)–(2), with the enforcing authority notified for traffic and content data under Art. 8(1).
- Authority directly to a service provider in another Party — Second Additional Protocol, Art. 7(1).
- Authority to another Party, which compels the provider in its own territory — Second Additional Protocol, Art. 8(1).
- Authority to a domain name registration entity, by request rather than order — Second Additional Protocol, Art. 6(1)–(2).
- Point of contact to point of contact, in an emergency, without a mutual assistance request — Second Additional Protocol, Art. 9(1)(a).
Rights and accountability
AnalysisThe addressee determines who is in a position to object. A state-to-state request is evaluated by a government that may refuse it on its own grounds. A provider-addressed order is evaluated first by a company, which is why both instruments that use that route give the company a defined way to raise a conflict rather than leaving it to choose which law to break.
What we could not establish
- Five instruments were read. No national implementing legislation was read for any country, and nothing here establishes which mechanisms are available between any particular pair of States.
- Which foreign governments qualify under 18 U.S.C. § 2703(h) depends on executive agreements under § 2523, and that coverage was not researched.
- No provider is named anywhere in this wave, and nothing here compares how any provider or any jurisdiction responds. That is a deliberate limit on the research.
Where to go next
Related: direct cooperation with foreign providers, European production and preservation orders, and jurisdiction over foreign-held data.
Related topics
- Investigators are in one country and the data is in another. Whose law decides whether they may have it?
There is no single answer, because the instruments do not use the same connecting factor. One keys on where the data is stored, one on where the provider’s addressee is established, and one makes the data’s location expressly irrelevant.
- Can an authority in one country order a service provider in another country directly?
Under the Second Additional Protocol, for one category of data. Its direct route reaches specified, stored subscriber information only; traffic data requires going through the other Party, and content data is in neither.
- What does the European Union framework for electronic evidence create, and does it operate yet?
Two orders addressed to a provider’s establishment in another Member State, under a Regulation applying from 18 August 2026. Who may issue one depends on the data category — and a prosecutor may order content preserved but not produced.
- How does one state ask another for evidence?
Through a channel each Party designates and a body of law that mostly is not the treaty being invoked. The Convention’s own procedure applies only where no assistance treaty is in force between the two Parties, and its cooperation articles require each Party to legislate first.
Sources
Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0001839) · International organisation · 2001-11-23 · link verified 2026-09-05
WAVE 22 ADDITION. ACCESS NOTE: rm.coe.int and coe.int returned HTTP 403 to automated requests in this session, so the Convention was read from the official Dutch government treaty database, which publishes the authentic English text alongside the Dutch translation. The English text quoted below is the authentic one; English and French are the authentic languages. Supports Art. 14(1)–(2), that the procedural powers are established “for the purpose of specific criminal investigations or proceedings” and are applied to the offences established under Arts. 2–11, to other criminal offences committed by means of a computer system, and to “the collection of evidence in electronic form of a criminal offence”. Supports Art. 14(3)(a), that a Party restricting the Art. 20 power to specified offences must not restrict it more narrowly than the range to which it applies Art. 21. Supports Art. 15(1), that the powers are subject to conditions and safeguards under domestic law providing adequate protection of human rights, including rights under the 1950 European Convention and the 1966 Covenant, “and which shall incorporate the principle of proportionality”. Supports Art. 15(2), that such conditions and safeguards shall, as appropriate, “include judicial or other independent supervision, grounds justifying application, and limitation of the scope and the duration of such power or procedure”. Supports Art. 16(1)–(3): expedited preservation of specified stored computer data “including traffic data”, in particular where it is particularly vulnerable to loss or modification; where effected by order to a person, an obligation to preserve and maintain integrity “for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure”, renewable; and an obligation on the custodian to keep the undertaking of the procedure confidential. Supports Art. 17, expedited preservation and PARTIAL disclosure of traffic data sufficient to identify the service providers and the path through which the communication was transmitted. Supports Art. 18(1)(a)–(b), the production order: a person in the territory to submit specified stored computer data in that person’s possession or control, and a service provider offering services in the territory to submit subscriber information. Supports Art. 18(3), which defines “subscriber information” as information held by a service provider relating to subscribers of its services “OTHER THAN TRAFFIC OR CONTENT DATA” and by which the type of service, the subscriber’s identity, postal or geographic address, telephone and other access number, billing and payment information, and information on the site of installation of communication equipment can be established. Supports Art. 19(1)–(4): the power to search or similarly access a computer system or a computer-data storage medium; the power under 19(2) to EXTEND the search expeditiously to another system in the territory where the data sought is “lawfully accessible from or available to the initial system”; the power under 19(3) to seize or similarly secure, comprising the separate powers to “seize or similarly secure a computer system or part of it or a computer-data storage medium”, to “make and retain a copy of those computer data”, to “maintain the integrity of the relevant stored computer data”, and to “render inaccessible or remove those computer data in the accessed computer system”; and the power under 19(4) to order any person with knowledge about the functioning of the system to provide, as is reasonable, the necessary information. Supports Art. 20, real-time collection of TRAFFIC data, and Art. 21, interception of CONTENT data, the latter available only “in relation to a range of serious offences to be determined by domestic law”; both articles oblige a service provider to keep the execution confidential. Cited for the structural propositions that preservation is a distinct act from production, that traffic data and content data are distinct powers, that subscriber information is defined by exclusion from both, and that seizing, copying and accessing are separately enumerated. LIMITATIONS, and they are load-bearing: this is a TREATY. It obliges Parties to establish powers in domestic law; it is NOT evidence of what any particular Party has enacted, and no country claim on this platform rests on it. It describes no technique. STATUS: in force; the Convention has two additional protocols, of which the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was located but NOT read for this wave. WAVE 23 ADDITION. That Protocol has now been read and is held separately as `coe-cybercrime-second-protocol`. Chapter III of the Convention, on international co-operation, was read from the same authentic English text, and it is a different subject from the domestic powers above. Supports Art. 23, that Parties co-operate “in accordance with the provisions of this chapter, and through the application of relevant international instruments on international co-operation in criminal matters, arrangements agreed on the basis of uniform or reciprocal legislation, and domestic laws”. Supports Art. 25(1)-(4), and in particular Art. 25(2), that “Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35” -- the Convention’s own statement that its co-operation articles are not self-executing -- and Art. 25(4), that except as specifically provided “mutual assistance shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation”. Supports Art. 27(1), that the Article applies only “where there is no mutual assistance treaty or arrangement on the basis of uniform or reciprocal legislation in force between the requesting and requested Parties”, and Art. 27(2)(a)-(d), that each Party designates a central authority “responsible for sending and answering requests for mutual assistance, the execution of such requests or their transmission to the authorities competent for their execution”, that central authorities communicate directly with each other, and that the Secretary General keeps a register of them. Supports Art. 29(1)-(4): a Party may request another to preserve data “located within the territory of that other Party and in respect of which the requesting Party intends to submit a request for mutual assistance”; the request must state that intention (29(2)(f)); “For the purposes of responding to a request, dual criminality shall not be required as a condition to providing such preservation” (29(3)); and a Party that requires dual criminality for disclosure may reserve the right to refuse preservation where it has reasons to believe the condition cannot be fulfilled at the time of disclosure (29(4)). Supports Art. 30(1)-(2), expedited disclosure of a sufficient amount of preserved traffic data to identify a service provider in another State and the path through which the communication was transmitted, withholdable only for a political offence or where execution is likely to prejudice sovereignty, security, ordre public or other essential interests. Supports Art. 31(1)-(3), mutual assistance to search, seize and disclose stored data “including data that has been preserved pursuant to Article 29”, responded to on an expedited basis where data is particularly vulnerable to loss. Supports Art. 32 IN FULL, and its narrowness is the point: “A Party may, without the authorisation of another Party: a) access publicly available (open source) stored computer data, regardless of where the data is located geographically; or b) access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data to the Party through that computer system.” There is no third limb and no unilateral remote-access provision. Supports Art. 33(1)-(2), mutual assistance in the real-time collection of traffic data, governed by the conditions and procedures of domestic law and available at least for offences for which such collection would be available in a similar domestic case; and Art. 34, mutual assistance regarding the interception of content data “to the extent permitted under their applicable treaties and domestic laws”. Supports Art. 35(1)-(2), that each Party designates a point of contact available twenty-four hours a day, seven days a week, to ensure immediate assistance -- facilitating or, if permitted by its domestic law and practice, directly carrying out technical advice, preservation under Arts. 29 and 30, and the collection of evidence, provision of legal information and locating of suspects -- and that where the point of contact is not part of the Party’s authority responsible for international mutual assistance, it must ensure co-ordination with that authority. LIMITATION ON CHAPTER III, restated because it is easy to lose: these are obligations on Parties to legislate and to co-operate. They are NOT evidence of what any Party has enacted. The Party list, signature dates and ratification counts were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403 to three separate URL forms.
Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0006966) · International organisation · 2022-05-12 · link verified 2026-09-05
WAVE 23 ADDITION. ACCESS NOTE: coe.int and rm.coe.int returned HTTP 403 to automated requests on three separate URL forms, so the Protocol was read from the official Dutch government treaty database, which publishes the authentic English text. English and French are the authentic languages. TEMPORAL STATUS, and it is the most load-bearing fact on this record: the database records exactly ONE lifecycle row for this instrument -- “Nieuwe-regeling · Trb. 2022, 66 · 12-05-2022 · Totstandkoming” -- and its “Inwerkingtreding / Voorlopige toepassing” (entry into force / provisional application) column is EMPTY, on a page stating “Informatie geldend op 05-09-2026”. Every article of the Protocol additionally carries the marker “[Tekst zonder datum inwerkingtreding]” -- text without entry-into-force date. Supports the four distinct co-operation channels the Protocol creates, and their DIFFERENT REACH, which is the point. Supports Art. 6(1)-(2): a Party empowers its competent authorities, for specific criminal investigations or proceedings, to issue a REQUEST to an entity providing domain name registration services in another Party’s territory for information to identify or contact the registrant of a domain name, and permits an entity in its own territory to disclose such information “subject to reasonable conditions provided by domestic law”. Supports Art. 7(1): a Party empowers its competent authorities “to issue an order to be submitted directly to a service provider in the territory of another Party, in order to obtain the disclosure of specified, stored subscriber information in that service provider’s possession or control, where the subscriber information is needed for the issuing Party’s specific criminal investigations or proceedings” -- SUBSCRIBER INFORMATION ONLY. Supports Art. 7(2)(a) and, importantly, Art. 7(2)(b): a Party may, at signature or when depositing its instrument, DECLARE that “The order under Article 7, paragraph 1, must be issued by, or under the supervision of, a prosecutor or other judicial authority, or otherwise be issued under independent supervision” -- a declaration, not a default. Supports Art. 7(3)-(4), the order’s required contents and supplemental information. Supports Art. 8(1): an order “to be submitted as part of a request to another Party” compelling a service provider in the REQUESTED Party’s territory to produce specified and stored (a) subscriber information AND (b) traffic data. Supports Art. 9(1)(a): in an emergency, the Art. 35 Convention 24/7 point of contact may transmit and receive requests seeking immediate assistance in obtaining expedited disclosure of specified stored computer data from a provider in another Party’s territory “without a request for mutual assistance”; and Art. 9(1)(b), that a Party may declare it will not execute such requests seeking only subscriber information. LIMITATIONS: this is a TREATY and it obliges Parties to legislate; it is NOT evidence of what any Party has enacted, and no country claim rests on it. Articles 5, 10, 11, 12, 13 and 14 were NOT read. The number of ratifications and the list of Parties were NOT RESEARCHED, because the Council of Europe Treaty Office was unreachable; secondary summaries stating a count were found and are deliberately NOT used. It describes no technique.
Publications Office of the European Union (EUR-Lex) · International organisation · 2023-07-12 · link verified 2026-09-05
WAVE 23 ADDITION. The Regulation read directly on EUR-Lex. TEMPORAL STATUS, verified from the instrument itself: Art. 34(1) provides that it enters into force on the twentieth day following publication in the Official Journal, and Art. 34(2) provides in terms “It shall apply from 18 August 2026.” Against the research date of 5 September 2026 the Regulation is therefore APPLICABLE, and had been for eighteen days. The SAME paragraph carries a separate and later trigger: “the obligation for competent authorities and service providers to use the decentralised IT system established in Article 19 for written communication under this Regulation shall apply from one year after the adoption of the implementing acts referred to in Article 25” -- whether those implementing acts have been adopted was NOT RESEARCHED, so that trigger date is NOT ESTABLISHED. Supports Art. 3(1), that a “European Production Order” is a decision ordering the production of electronic evidence, issued or validated by a judicial authority of a Member State, and “addressed to a designated establishment or to a legal representative of a service provider offering services in the Union, where that designated establishment or legal representative is located in another Member State bound by this Regulation”. Supports Art. 3(2), that a “European Preservation Order” orders preservation “for the purposes of a subsequent request for production”. Supports the four data definitions in Art. 3(9)-(12): subscriber data; “data requested for the sole purpose of identifying the user” as a DISTINCT category; traffic data; and content data, defined as any data in digital format “other than subscriber data or traffic data”. Supports Art. 4(1)-(3), the authorisation ladder: a production order for subscriber data or identification data may be issued by a judge, court, investigating judge OR PUBLIC PROSECUTOR, or by another competent investigating authority whose order is then validated by one of those; a production order for traffic data (other than identification data) or content data may be issued only by a judge, court or investigating judge -- NOT a public prosecutor -- or validated by one of those; and a PRESERVATION order for data of ANY category may be issued by a judge, court, investigating judge or public prosecutor. Supports Art. 8(1)-(4): where a production order seeks traffic data (other than identification data) or content data, the issuing authority shall notify the enforcing authority by transmitting the EPOC to it at the same time as to the addressee; that duty does not apply where the issuing authority has reasonable grounds to believe both that the offence was, is being or is likely to be committed in the issuing State and that the person whose data are requested resides there; and the notification “shall have a suspensive effect on the obligations of the addressee” except in emergency cases. Supports Art. 13(1)-(3): the issuing authority shall without undue delay inform the person whose data are being requested, may delay, restrict or omit that under the conditions of Art. 13(3) of Directive (EU) 2016/680 while recording reasons, and when informing shall include information about available remedies. Supports Art. 17(1)-(2), the reasoned-objection procedure where an addressee considers compliance would conflict with the law of a third country, and that the objection may not rest merely on the absence of similar provisions in that law. Supports Art. 18(1)-(2), that any person whose data were requested has the right to effective remedies, exercised “before a court in the issuing State” and including a challenge to legality, necessity and proportionality. Supports recital 8, which states why the instrument exists alongside the European Investigation Order: Directive 2014/41/EU and the Convention on Mutual Assistance in Criminal Matters provide for requesting evidence from another Member State, but “the procedures and timelines” they provide “might not be appropriate for electronic evidence, which is more volatile and could more easily and quickly be deleted”. LIMITATIONS: this is EU law binding the Member States bound by it. It is NOT evidence of the law of any non-EU country and NOT evidence that any particular Member State has any particular arrangement in place. Whether any Member State has designated addressees under Directive (EU) 2023/1544 was NOT RESEARCHED. Articles 5, 6, 7, 9, 10, 11, 12, 14, 15, 16 and 19-33 were not read in full.
Directive 2014/41/EU regarding the European Investigation Order in criminal matters, Article 1
Publications Office of the European Union (EUR-Lex) · International organisation · 2014-04-03 · link verified 2026-09-05
WAVE 23 ADDITION. Read directly on EUR-Lex, and cited for one purpose only: to state what a European Investigation Order IS in its own words, so that the contrast with a European Production Order rests on both instruments rather than on one instrument’s description of the other. Supports Art. 1(1): “A European Investigation Order (EIO) is a judicial decision which has been issued or validated by a judicial authority of a Member State (‘the issuing State’) to have one or several specific investigative measure(s) carried out in another Member State (‘the executing State’) to obtain evidence in accordance with this Directive”, and that an EIO may also be issued for obtaining evidence already in the possession of the executing State’s competent authorities. Supports Art. 1(2), that Member States execute an EIO “on the basis of the principle of mutual recognition”. Supports Art. 1(3), that the issuing of an EIO may be requested by a suspected or accused person, or by a lawyer on his behalf, within the framework of applicable defence rights. Supports Art. 1(4), that the Directive does not modify the obligation to respect fundamental rights and legal principles enshrined in Art. 6 TEU. LIMITATIONS: only Article 1 was read. Nothing about grounds for refusal, formalities, time limits, specific investigative measures or the Directive’s temporal status is established by this record, and no claim about any Member State’s implementation rests on it.
Legal Information Institute, Cornell Law School (reproducing the United States Code) · Legislation · link verified 2026-09-05
WAVE 22 ADDITION. ACCESS NOTE, stated because it affects the tier of this record: the official hosts were attempted first and were unreachable in this session — uscode.house.gov timed out without response and govinfo.gov returned HTTP 502 — so the text was read from the Legal Information Institute, which reproduces the United States Code verbatim rather than summarising it. It is cited for statutory wording only, and every proposition below is a quotation or a close paraphrase of one. Supports § 2703(a): a governmental entity may require disclosure of the CONTENTS of a wire or electronic communication in electronic storage for one hundred and eighty days or less “only pursuant to a warrant”; contents held more than one hundred and eighty days may be required by the means available under subsection (b). Supports § 2703(b)(1): contents held by a remote computing service may be required WITHOUT required notice to the subscriber or customer on a warrant, or WITH prior notice where the entity uses an administrative, grand jury or trial subpoena or obtains a § 2703(d) court order, with delayed notice available under § 2705. Supports § 2703(c)(1), that a governmental entity may require disclosure of “a record or other information pertaining to a subscriber to or customer of such service (NOT INCLUDING THE CONTENTS OF COMMUNICATIONS)” only by warrant, § 2703(d) order, subscriber consent, a narrow written request confined to telemarketing-fraud investigations, or under paragraph (2). Supports § 2703(c)(2), which lists the six items a provider shall disclose on an administrative, grand jury or trial subpoena: name; address; local and long distance telephone connection records, or records of session times and durations; length of service including start date and types of service utilised; telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and means and source of payment. Supports § 2703(c)(3), that a governmental entity receiving records under subsection (c) “is not required to provide notice to a subscriber or customer”. Supports § 2703(d), that a court order shall issue “only if the governmental entity offers specific and articulable facts showing that there are reasonable grounds to believe” the material sought is “relevant and material to an ongoing criminal investigation”, and that a court may quash or modify on a provider’s prompt motion where the records are unusually voluminous or compliance would cause an undue burden. Cited for the proposition that one statute can allocate three different authorising instruments to three different categories of digital material. LIMITATIONS: this record supports the wording of § 2703 and nothing else. It establishes no United States constitutional doctrine, no case law, and nothing about the Wiretap Act, which was not read. STATUS: current codified text as reproduced at the verification date. WAVE 23 ADDITION. Section 2703(h) was read from the same source under the same access note. Supports § 2703(h)(1)(A), defining a “qualifying foreign government” as one “with which the United States has an executive agreement that has entered into force under section 2523” and whose laws provide electronic communication service providers and remote computing service providers “substantive and procedural opportunities similar to those provided under paragraphs (2) and (5)”. Supports § 2703(h)(2)(A), that a provider -- “including a foreign electronic communication service or remote computing service” -- being required to disclose the contents of a communication may file a motion to modify or quash the legal process where it reasonably believes (i) that the customer or subscriber “is not a United States person and does not reside in the United States” and (ii) that the required disclosure “would create a material risk that the provider would violate the laws of a qualifying foreign government”, such a motion to be filed not later than 14 days after service. Cited for the proposition that the same body of legislation which removes the data’s location as an answer also provides a route for a provider to raise a conflict of legal obligations. LIMITATION: which governments qualify turns on executive agreements under § 2523, and that coverage was NOT RESEARCHED. No list of qualifying foreign governments is stated anywhere on this platform.