Skip to main content

Investigations

Investigators are in one country and the data is in another. Whose law decides whether they may have it?

There is no single answer, because the instruments do not use the same connecting factor. One keys on where the data is stored, one on where the provider’s addressee is established, and one makes the data’s location expressly irrelevant.

Fact-checkedSafety review clearedLast updated Last reviewed

In short

A domestic investigative power is a power a State gives its own authorities. It does not travel. When the thing an investigator wants sits in another country, or is held by a company established in one, the question stops being what the investigator may do and becomes which legal system connects them to it — and the instruments that answer that question do not agree on the connection.

Why it exists

AnalysisThe problem is a mismatch of speeds. Data moves between countries in the time it takes to press a key, and legal authority moves between countries at the speed of a treaty. A system that ignored the gap would either leave ordinary offences uninvestigable whenever a service happened to be foreign, or would let each State reach into every other whenever it judged that convenient.

How it works

The Convention on Cybercrime connects on the territory where the data is stored. Article 29(1) lets a Party ask another to preserve data "located within the territory of that other Party", and Article 31(1) lets it ask another to search, seize and disclose data "stored by means of a computer system located within the territory of the requested Party". The request goes where the data is.

Regulation (EU) 2023/1543 connects on where the addressee is established. Article 3(1) defines a European Production Order as a decision addressed "to a designated establishment or to a legal representative of a service provider offering services in the Union, where that designated establishment or legal representative is located in another Member State bound by this Regulation". The order goes to the provider’s point of contact, not to the place the data sits.

United States law connects on control, and says the data’s location is irrelevant. Section 2713 of Title 18 provides that a provider of electronic communication service or remote computing service "shall comply with the obligations of this chapter to preserve, backup, or disclose" the contents of a communication and any record pertaining to a customer or subscriber "within such provider’s possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States".

What a Party may do without asking anyone — and it is very little
Article 32 of the Convention is exhaustive on its face. A Party may, without the authorisation of another Party, "access publicly available (open source) stored computer data, regardless of where the data is located geographically", or "access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data". Two situations. There is no third limb, and no unilateral remote-access provision.
Where a conflict is expected, the instruments provide for it
Article 17 of Regulation (EU) 2023/1543 lets an addressee that considers compliance would conflict with the law of a third country raise a reasoned objection to the issuing and enforcing authorities — while providing that the objection may not rest merely on the absence of similar provisions in that third country’s law. Section 2703(h)(2)(A) of Title 18 lets a provider, including a foreign one, move to modify or quash where it reasonably believes the customer is not a United States person and does not reside there, and that disclosure would create a material risk of violating the laws of a qualifying foreign government.
And the requested State’s law governs what it will do
Article 25(4) of the Convention provides that except as specifically provided, mutual assistance "shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation".

Common misconceptions

Widely held beliefs that do not match how the system actually operates.

  • Common belief: A court order applies wherever the data happens to be.

    In practice: The Convention routes a request to the Party in whose territory the data is stored, and Article 25(4) subjects the response to the requested Party’s own law including its refusal grounds. A domestic order is not a global instrument.

  • Common belief: Data is governed by the law of the country where the server sits.

    In practice: Only one of the three instruments read here connects that way. The EU Regulation connects on where the provider’s designated establishment or legal representative is located, and 18 U.S.C. § 2713 makes the data’s location expressly irrelevant to the provider’s obligation.

  • Common belief: The internet has no borders, so jurisdiction does not apply to it.

    In practice: Every instrument read here is a jurisdictional instrument. They differ on what connects an authority to the data, not on whether a connection is required.

  • Common belief: The CLOUD Act lets the United States obtain data anywhere.

    In practice: Section 2713 governs providers already subject to the obligations of chapter 121 of Title 18 and removes the data’s location as an answer. It creates no power over foreign territory and establishes nothing about any other country’s law.

    Which foreign governments qualify under § 2703(h) depends on executive agreements made under § 2523, and that coverage was not researched for this wave.

  • Common belief: If data can be reached from a computer at home, it may be reached.

    In practice: Article 32 of the Convention permits access without another Party’s authorisation in two situations only: publicly available data, and data accessed with the lawful and voluntary consent of the person who has lawful authority to disclose it.

  • Common belief: Because these mechanisms are limited, foreign-held evidence is out of reach.

    In practice: Every instrument here exists to make it reachable on terms. The Convention obliges Parties to co-operate "to the widest extent possible", and the EU Regulation creates orders addressed directly to a provider’s establishment in another Member State.

How this varies between jurisdictions

A required section on every guide. Arrangements differ between countries, and we say how.

What each instrument treats as the connection.

  • The territory where the data is stored — Convention on Cybercrime, Arts. 29(1) and 31(1).
  • Where the provider’s designated establishment or legal representative is located — Regulation (EU) 2023/1543, Art. 3(1)–(2).
  • The provider’s possession, custody or control, with the data’s location expressly irrelevant — 18 U.S.C. § 2713.
  • No authorisation from another Party needed at all, in two situations only: publicly available data, and lawful and voluntary consent — Convention Art. 32.
  • And in every case, the requested Party’s own law and refusal grounds govern its response — Convention Art. 25(4).

Rights and accountability

AnalysisWhy the connecting factor matters beyond doctrine is that it decides which State’s safeguards attach. If the connection is the territory of storage, the requested State’s law and its refusal grounds apply. If the connection is the addressee’s establishment, a different State’s authorities may never see the order at all unless the instrument requires notification. If the connection is control, the safeguard has to come from somewhere else entirely.

What we could not establish

  • Three international and supranational instruments and two United States sections were read. No national implementing legislation was read for any country, and nothing here is asserted about how any State gives effect to these instruments.
  • No case law was read in any system. Where a connecting factor has been construed by a court, that construction is not described here.
  • Nothing on this page describes where data may be held, how any measure is executed, or anything a reader could use to place data beyond a mechanism’s reach. That is a deliberate limit on the research.

Where to go next

Related: mutual legal assistance, asking a state and ordering a provider, and legal authority and technical capability.

  • How does one state ask another for evidence?

    Through a channel each Party designates and a body of law that mostly is not the treaty being invoked. The Convention’s own procedure applies only where no assistance treaty is in force between the two Parties, and its cooperation articles require each Party to legislate first.

  • Is a cross-border request made to a country or to a company?

    Both exist and they are different instruments. Mutual assistance and the European Investigation Order run state to state; a European Production Order is addressed to a provider’s establishment in another Member State; and the Second Additional Protocol contains one of each.

  • If investigators are technically able to obtain something, does that mean they may?

    No, and two systems say so in terms. Japan’s Code permits compulsory measures only where the Code itself provides for them; Spain forbids authorising a technological measure to discover offences or to dispel suspicion that has no objective basis.

  • What exactly does a legal system protect when it protects privacy?

    Not one interest but several, bundled differently in each text. Switzerland puts private life, the home, mail and telecommunications in one article; South Africa defines privacy by the searches it forbids; Brazil separates intimacy from the house and both from communications.

Sources

  1. Convention on Cybercrime (Council of Europe, ETS No. 185, Budapest, 23 November 2001), Articles 14–21 and Chapter III (Articles 23–35)

    Council of Europe; consulted in the official treaty database of the Government of the Netherlands (wetten.overheid.nl, BWBV0001839) · International organisation · 2001-11-23 · link verified 2026-09-05

    WAVE 22 ADDITION. ACCESS NOTE: rm.coe.int and coe.int returned HTTP 403 to automated requests in this session, so the Convention was read from the official Dutch government treaty database, which publishes the authentic English text alongside the Dutch translation. The English text quoted below is the authentic one; English and French are the authentic languages. Supports Art. 14(1)–(2), that the procedural powers are established “for the purpose of specific criminal investigations or proceedings” and are applied to the offences established under Arts. 2–11, to other criminal offences committed by means of a computer system, and to “the collection of evidence in electronic form of a criminal offence”. Supports Art. 14(3)(a), that a Party restricting the Art. 20 power to specified offences must not restrict it more narrowly than the range to which it applies Art. 21. Supports Art. 15(1), that the powers are subject to conditions and safeguards under domestic law providing adequate protection of human rights, including rights under the 1950 European Convention and the 1966 Covenant, “and which shall incorporate the principle of proportionality”. Supports Art. 15(2), that such conditions and safeguards shall, as appropriate, “include judicial or other independent supervision, grounds justifying application, and limitation of the scope and the duration of such power or procedure”. Supports Art. 16(1)–(3): expedited preservation of specified stored computer data “including traffic data”, in particular where it is particularly vulnerable to loss or modification; where effected by order to a person, an obligation to preserve and maintain integrity “for a period of time as long as necessary, up to a maximum of ninety days, to enable the competent authorities to seek its disclosure”, renewable; and an obligation on the custodian to keep the undertaking of the procedure confidential. Supports Art. 17, expedited preservation and PARTIAL disclosure of traffic data sufficient to identify the service providers and the path through which the communication was transmitted. Supports Art. 18(1)(a)–(b), the production order: a person in the territory to submit specified stored computer data in that person’s possession or control, and a service provider offering services in the territory to submit subscriber information. Supports Art. 18(3), which defines “subscriber information” as information held by a service provider relating to subscribers of its services “OTHER THAN TRAFFIC OR CONTENT DATA” and by which the type of service, the subscriber’s identity, postal or geographic address, telephone and other access number, billing and payment information, and information on the site of installation of communication equipment can be established. Supports Art. 19(1)–(4): the power to search or similarly access a computer system or a computer-data storage medium; the power under 19(2) to EXTEND the search expeditiously to another system in the territory where the data sought is “lawfully accessible from or available to the initial system”; the power under 19(3) to seize or similarly secure, comprising the separate powers to “seize or similarly secure a computer system or part of it or a computer-data storage medium”, to “make and retain a copy of those computer data”, to “maintain the integrity of the relevant stored computer data”, and to “render inaccessible or remove those computer data in the accessed computer system”; and the power under 19(4) to order any person with knowledge about the functioning of the system to provide, as is reasonable, the necessary information. Supports Art. 20, real-time collection of TRAFFIC data, and Art. 21, interception of CONTENT data, the latter available only “in relation to a range of serious offences to be determined by domestic law”; both articles oblige a service provider to keep the execution confidential. Cited for the structural propositions that preservation is a distinct act from production, that traffic data and content data are distinct powers, that subscriber information is defined by exclusion from both, and that seizing, copying and accessing are separately enumerated. LIMITATIONS, and they are load-bearing: this is a TREATY. It obliges Parties to establish powers in domestic law; it is NOT evidence of what any particular Party has enacted, and no country claim on this platform rests on it. It describes no technique. STATUS: in force; the Convention has two additional protocols, of which the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence was located but NOT read for this wave. WAVE 23 ADDITION. That Protocol has now been read and is held separately as `coe-cybercrime-second-protocol`. Chapter III of the Convention, on international co-operation, was read from the same authentic English text, and it is a different subject from the domestic powers above. Supports Art. 23, that Parties co-operate “in accordance with the provisions of this chapter, and through the application of relevant international instruments on international co-operation in criminal matters, arrangements agreed on the basis of uniform or reciprocal legislation, and domestic laws”. Supports Art. 25(1)-(4), and in particular Art. 25(2), that “Each Party shall also adopt such legislative and other measures as may be necessary to carry out the obligations set forth in Articles 27 through 35” -- the Convention’s own statement that its co-operation articles are not self-executing -- and Art. 25(4), that except as specifically provided “mutual assistance shall be subject to the conditions provided for by the law of the requested Party or by applicable mutual assistance treaties, including the grounds on which the requested Party may refuse co-operation”. Supports Art. 27(1), that the Article applies only “where there is no mutual assistance treaty or arrangement on the basis of uniform or reciprocal legislation in force between the requesting and requested Parties”, and Art. 27(2)(a)-(d), that each Party designates a central authority “responsible for sending and answering requests for mutual assistance, the execution of such requests or their transmission to the authorities competent for their execution”, that central authorities communicate directly with each other, and that the Secretary General keeps a register of them. Supports Art. 29(1)-(4): a Party may request another to preserve data “located within the territory of that other Party and in respect of which the requesting Party intends to submit a request for mutual assistance”; the request must state that intention (29(2)(f)); “For the purposes of responding to a request, dual criminality shall not be required as a condition to providing such preservation” (29(3)); and a Party that requires dual criminality for disclosure may reserve the right to refuse preservation where it has reasons to believe the condition cannot be fulfilled at the time of disclosure (29(4)). Supports Art. 30(1)-(2), expedited disclosure of a sufficient amount of preserved traffic data to identify a service provider in another State and the path through which the communication was transmitted, withholdable only for a political offence or where execution is likely to prejudice sovereignty, security, ordre public or other essential interests. Supports Art. 31(1)-(3), mutual assistance to search, seize and disclose stored data “including data that has been preserved pursuant to Article 29”, responded to on an expedited basis where data is particularly vulnerable to loss. Supports Art. 32 IN FULL, and its narrowness is the point: “A Party may, without the authorisation of another Party: a) access publicly available (open source) stored computer data, regardless of where the data is located geographically; or b) access or receive, through a computer system in its territory, stored computer data located in another Party, if the Party obtains the lawful and voluntary consent of the person who has the lawful authority to disclose the data to the Party through that computer system.” There is no third limb and no unilateral remote-access provision. Supports Art. 33(1)-(2), mutual assistance in the real-time collection of traffic data, governed by the conditions and procedures of domestic law and available at least for offences for which such collection would be available in a similar domestic case; and Art. 34, mutual assistance regarding the interception of content data “to the extent permitted under their applicable treaties and domestic laws”. Supports Art. 35(1)-(2), that each Party designates a point of contact available twenty-four hours a day, seven days a week, to ensure immediate assistance -- facilitating or, if permitted by its domestic law and practice, directly carrying out technical advice, preservation under Arts. 29 and 30, and the collection of evidence, provision of legal information and locating of suspects -- and that where the point of contact is not part of the Party’s authority responsible for international mutual assistance, it must ensure co-ordination with that authority. LIMITATION ON CHAPTER III, restated because it is easy to lose: these are obligations on Parties to legislate and to co-operate. They are NOT evidence of what any Party has enacted. The Party list, signature dates and ratification counts were NOT RESEARCHED, because the Council of Europe Treaty Office returned HTTP 403 to three separate URL forms.

  2. Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings, Articles 3, 4, 8, 13, 17, 18 and 34

    Publications Office of the European Union (EUR-Lex) · International organisation · 2023-07-12 · link verified 2026-09-05

    WAVE 23 ADDITION. The Regulation read directly on EUR-Lex. TEMPORAL STATUS, verified from the instrument itself: Art. 34(1) provides that it enters into force on the twentieth day following publication in the Official Journal, and Art. 34(2) provides in terms “It shall apply from 18 August 2026.” Against the research date of 5 September 2026 the Regulation is therefore APPLICABLE, and had been for eighteen days. The SAME paragraph carries a separate and later trigger: “the obligation for competent authorities and service providers to use the decentralised IT system established in Article 19 for written communication under this Regulation shall apply from one year after the adoption of the implementing acts referred to in Article 25” -- whether those implementing acts have been adopted was NOT RESEARCHED, so that trigger date is NOT ESTABLISHED. Supports Art. 3(1), that a “European Production Order” is a decision ordering the production of electronic evidence, issued or validated by a judicial authority of a Member State, and “addressed to a designated establishment or to a legal representative of a service provider offering services in the Union, where that designated establishment or legal representative is located in another Member State bound by this Regulation”. Supports Art. 3(2), that a “European Preservation Order” orders preservation “for the purposes of a subsequent request for production”. Supports the four data definitions in Art. 3(9)-(12): subscriber data; “data requested for the sole purpose of identifying the user” as a DISTINCT category; traffic data; and content data, defined as any data in digital format “other than subscriber data or traffic data”. Supports Art. 4(1)-(3), the authorisation ladder: a production order for subscriber data or identification data may be issued by a judge, court, investigating judge OR PUBLIC PROSECUTOR, or by another competent investigating authority whose order is then validated by one of those; a production order for traffic data (other than identification data) or content data may be issued only by a judge, court or investigating judge -- NOT a public prosecutor -- or validated by one of those; and a PRESERVATION order for data of ANY category may be issued by a judge, court, investigating judge or public prosecutor. Supports Art. 8(1)-(4): where a production order seeks traffic data (other than identification data) or content data, the issuing authority shall notify the enforcing authority by transmitting the EPOC to it at the same time as to the addressee; that duty does not apply where the issuing authority has reasonable grounds to believe both that the offence was, is being or is likely to be committed in the issuing State and that the person whose data are requested resides there; and the notification “shall have a suspensive effect on the obligations of the addressee” except in emergency cases. Supports Art. 13(1)-(3): the issuing authority shall without undue delay inform the person whose data are being requested, may delay, restrict or omit that under the conditions of Art. 13(3) of Directive (EU) 2016/680 while recording reasons, and when informing shall include information about available remedies. Supports Art. 17(1)-(2), the reasoned-objection procedure where an addressee considers compliance would conflict with the law of a third country, and that the objection may not rest merely on the absence of similar provisions in that law. Supports Art. 18(1)-(2), that any person whose data were requested has the right to effective remedies, exercised “before a court in the issuing State” and including a challenge to legality, necessity and proportionality. Supports recital 8, which states why the instrument exists alongside the European Investigation Order: Directive 2014/41/EU and the Convention on Mutual Assistance in Criminal Matters provide for requesting evidence from another Member State, but “the procedures and timelines” they provide “might not be appropriate for electronic evidence, which is more volatile and could more easily and quickly be deleted”. LIMITATIONS: this is EU law binding the Member States bound by it. It is NOT evidence of the law of any non-EU country and NOT evidence that any particular Member State has any particular arrangement in place. Whether any Member State has designated addressees under Directive (EU) 2023/1544 was NOT RESEARCHED. Articles 5, 6, 7, 9, 10, 11, 12, 14, 15, 16 and 19-33 were not read in full.

  3. 18 U.S.C. § 2713 - Required preservation and disclosure of communications and records (added by the CLOUD Act, Pub. L. 115-141, div. V, § 103(a)(1))

    Legal Information Institute, Cornell Law School (reproducing the United States Code) · Legislation · 2018-03-23 · link verified 2026-09-05

    WAVE 23 ADDITION. ACCESS NOTE, carried forward from Wave 22 and re-tested this wave: the official hosts were attempted first and were unreachable -- uscode.house.gov timed out with no response and govinfo.gov returned HTTP 502 -- so the text was read from the Legal Information Institute, which reproduces the United States Code verbatim rather than summarising it. It is cited for statutory wording only. Supports § 2713 in full: “A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider’s possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.” Supports the parenthetical provenance printed with it: added by Pub. L. 115-141, div. V, § 103(a)(1), Mar. 23, 2018, 132 Stat. 1214. Cited for one proposition: that a legal system may attach the obligation to the PROVIDER’S POSSESSION, CUSTODY OR CONTROL and expressly make the data’s location irrelevant to it. LIMITATIONS, and they matter because this provision is widely overstated: the section governs a provider already subject to the obligations of chapter 121. It does NOT confer authority to access data anywhere, it creates no power over foreign territory, and it establishes nothing about any other country’s law. Executive-agreement coverage under § 2523 was NOT RESEARCHED and no list of qualifying foreign governments is stated anywhere in this wave.

  4. 18 U.S.C. § 2703 — Required disclosure of customer communications or records (Stored Communications Act)

    Legal Information Institute, Cornell Law School (reproducing the United States Code) · Legislation · link verified 2026-09-05

    WAVE 22 ADDITION. ACCESS NOTE, stated because it affects the tier of this record: the official hosts were attempted first and were unreachable in this session — uscode.house.gov timed out without response and govinfo.gov returned HTTP 502 — so the text was read from the Legal Information Institute, which reproduces the United States Code verbatim rather than summarising it. It is cited for statutory wording only, and every proposition below is a quotation or a close paraphrase of one. Supports § 2703(a): a governmental entity may require disclosure of the CONTENTS of a wire or electronic communication in electronic storage for one hundred and eighty days or less “only pursuant to a warrant”; contents held more than one hundred and eighty days may be required by the means available under subsection (b). Supports § 2703(b)(1): contents held by a remote computing service may be required WITHOUT required notice to the subscriber or customer on a warrant, or WITH prior notice where the entity uses an administrative, grand jury or trial subpoena or obtains a § 2703(d) court order, with delayed notice available under § 2705. Supports § 2703(c)(1), that a governmental entity may require disclosure of “a record or other information pertaining to a subscriber to or customer of such service (NOT INCLUDING THE CONTENTS OF COMMUNICATIONS)” only by warrant, § 2703(d) order, subscriber consent, a narrow written request confined to telemarketing-fraud investigations, or under paragraph (2). Supports § 2703(c)(2), which lists the six items a provider shall disclose on an administrative, grand jury or trial subpoena: name; address; local and long distance telephone connection records, or records of session times and durations; length of service including start date and types of service utilised; telephone or instrument number or other subscriber number or identity, including any temporarily assigned network address; and means and source of payment. Supports § 2703(c)(3), that a governmental entity receiving records under subsection (c) “is not required to provide notice to a subscriber or customer”. Supports § 2703(d), that a court order shall issue “only if the governmental entity offers specific and articulable facts showing that there are reasonable grounds to believe” the material sought is “relevant and material to an ongoing criminal investigation”, and that a court may quash or modify on a provider’s prompt motion where the records are unusually voluminous or compliance would cause an undue burden. Cited for the proposition that one statute can allocate three different authorising instruments to three different categories of digital material. LIMITATIONS: this record supports the wording of § 2703 and nothing else. It establishes no United States constitutional doctrine, no case law, and nothing about the Wiretap Act, which was not read. STATUS: current codified text as reproduced at the verification date. WAVE 23 ADDITION. Section 2703(h) was read from the same source under the same access note. Supports § 2703(h)(1)(A), defining a “qualifying foreign government” as one “with which the United States has an executive agreement that has entered into force under section 2523” and whose laws provide electronic communication service providers and remote computing service providers “substantive and procedural opportunities similar to those provided under paragraphs (2) and (5)”. Supports § 2703(h)(2)(A), that a provider -- “including a foreign electronic communication service or remote computing service” -- being required to disclose the contents of a communication may file a motion to modify or quash the legal process where it reasonably believes (i) that the customer or subscriber “is not a United States person and does not reside in the United States” and (ii) that the required disclosure “would create a material risk that the provider would violate the laws of a qualifying foreign government”, such a motion to be filed not later than 14 days after service. Cited for the proposition that the same body of legislation which removes the data’s location as an answer also provides a route for a provider to raise a conflict of legal obligations. LIMITATION: which governments qualify turns on executive agreements under § 2523, and that coverage was NOT RESEARCHED. No list of qualifying foreign governments is stated anywhere on this platform.