deep-dive

What Police and Courts Can Get From Your Cloud Storage

Google received over 200,000 government data requests in a year and complied in 80% of cases. Here's what that means for your stored files.

Most people who choose a cloud storage service think about storage limits, pricing, and maybe the privacy policy. Few think about what happens when law enforcement comes asking.

It’s a scenario most people will never encounter directly. But understanding the legal mechanisms that govern access to your cloud-stored photos, documents, and files fundamentally changes what “private” means in the context of cloud storage.

The short version: if your files are in a major cloud service, law enforcement in many jurisdictions can obtain them — legally, with varying levels of judicial oversight.


The Numbers First

Google publishes a transparency report detailing government data requests across all its products, including Google Photos, Google Drive, and Gmail. In a recent year, Google received over 200,000 requests globally and produced data in roughly 80% of cases.

Apple publishes similar reports. Microsoft, Meta, and Amazon do as well.

These are not exceptional or unusual events. They are the routine operation of legal systems that were written before cloud storage existed and have been incrementally updated to address it.


In the United States, the primary law governing government access to electronically stored data is the Stored Communications Act (SCA), enacted in 1986 — before the public internet existed in its modern form. The SCA has been amended multiple times, but its age means courts have spent years interpreting how it applies to cloud storage scenarios that the original legislature could not have anticipated.

The type of legal process determines what data can be compelled:

Subpoenas

A subpoena can be issued by prosecutors without judicial approval. It typically reaches only “non-content” data:

  • Your name, address, and billing information
  • Account creation date
  • Login records — IP addresses, timestamps, device identifiers
  • What services you’ve subscribed to

Importantly, a subpoena generally cannot compel the content of what you’ve stored — your photos, documents, or messages. But the metadata it can reach is itself significant. Login records from your Google account can show where you’ve been, what devices you used, and when you last accessed your files.

Court Orders Under 18 U.S.C. § 2703(d)

A “d order” requires prosecutors to show specific and articulable facts establishing that the records requested are relevant to an ongoing investigation. This is a higher bar than a subpoena but still does not require probable cause.

Court orders can reach transaction and connection records beyond what a subpoena can access, but still generally stop short of compelling content.

Search Warrants

A search warrant requires a showing of probable cause and must be approved by a judge. A valid search warrant can compel production of:

  • The actual content of your cloud storage — photos, documents, videos
  • Your emails and messages
  • Files you’ve shared with others

If law enforcement obtains a search warrant targeting your Google account, Google is legally required to hand over the contents of your Google Photos library, your Drive files, and any other stored content.


The CLOUD Act: Cross-Border Access

The situation becomes more complicated when data is stored in a different country from where the request originates.

The CLOUD Act (Clarifying Lawful Overseas Use of Data Act), passed in 2018, requires US-based technology companies to comply with valid legal process for data regardless of where that data is physically stored. If your files are on servers in Ireland, Google must still produce them in response to a valid US court order.

The CLOUD Act also creates a framework for bilateral agreements between the US and partner countries, allowing each country to make requests directly to the other’s technology companies.

The practical implication: data jurisdiction — the country where your data is stored — provides less protection than many users assume, at least for US-based cloud services. The company’s legal domicile matters more than the server location.


What Encryption Protects — And What It Doesn’t

Here’s the critical distinction that most cloud storage marketing obscures:

Encryption protects data from unauthorised access. It does not protect data from the company that holds the encryption keys — and therefore does not protect it from legal requests served on that company.

Most cloud storage services — Google, Apple (without Advanced Data Protection), Microsoft, Dropbox, and many others — use server-side encryption. They hold the encryption keys. This means they can decrypt your files when required to do so by law.

When Google receives a valid search warrant for your Google Photos library, its encryption does not prevent compliance. The encryption protects against a data breach from outside. It does not protect against Google itself.

The exception: end-to-end encryption

Services that implement true end-to-end encryption (E2EE) hold no encryption keys. The company cannot access your files even if it wanted to. A legal request produces nothing useful because the company cannot decrypt the data it holds.

This is why E2EE is the meaningful differentiator in the privacy context — not just marketing language, but a technical architecture that changes what’s possible under legal compulsion.

Apple’s Advanced Data Protection for iCloud brings E2EE to iCloud backups, iCloud Drive, and iCloud Photos when enabled. It’s opt-in and not enabled by default. With it enabled, Apple cannot comply with a content request for your iCloud Photos library — it genuinely doesn’t have the key.


What Major Services Can Be Compelled to Produce

ServiceEncryption modelContent accessible via warrant?
Google PhotosServer-side (Google holds keys)Yes
iCloud Photos (default)Server-sideYes
iCloud Photos (ADP enabled)End-to-endNo (Apple holds no key)
OneDriveServer-sideYes
DropboxServer-sideYes
Amazon PhotosServer-sideYes
ProtonDriveEnd-to-endNo

This table reflects the architecture of each service, not the likelihood of any request. For most people, the practical probability of a targeted warrant for their cloud storage is very low. The question is about the theoretical exposure and the value of the data.


What About daftei?

daftei uses AES-256 encryption at rest and TLS 1.3 in transit. This is server-side encryption — daftei holds the keys. Like most cloud storage services, daftei would be required to comply with a valid legal order under applicable law.

The honest disclosure: daftei is not end-to-end encrypted, and users who require E2EE protection from legal process should use a service that explicitly provides it. Where daftei differs from major platforms is in its privacy stance toward commercial data use: it does not sell your data, does not show ads, does not train third-party AI on your content, and has a strict account deletion policy — permanent erasure after a 30-day grace window.

These are important properties that most major cloud services cannot claim. They are distinct from E2EE, and users deserve clarity about both dimensions.


Government Requests for Content: Who Receives Them?

It’s worth grounding this in reality.

Law enforcement requests for cloud storage content are typically part of criminal investigations where the account holder is a suspect or where the account holds records relevant to an investigation involving someone else. They are not routine sweeps of people’s personal photo libraries.

The people most practically affected are:

  • Those under active criminal investigation
  • Journalists, activists, or dissidents in jurisdictions with aggressive surveillance
  • People whose accounts are caught in broad “geofence warrants” or “keyword warrants” — legal mechanisms that target accounts by location or by the fact that users searched specific terms

Geofence warrants in particular are worth understanding. They ask cloud providers for data about all accounts that were geographically present in a specific area during a specific time window — effectively conducting a location-based dragnet that can sweep in thousands of uninvolved people. Google has faced repeated geofence warrant requests and has produced identifying data on thousands of people in response.


What You Can Do

If legal access to your cloud storage is a meaningful concern:

Enable Advanced Data Protection on iCloud. This is the highest-impact action available to Apple users. It moves iCloud Photos, iCloud Drive, and backups to true E2EE, which Apple cannot decrypt.

Use an E2EE storage service for the most sensitive files. ProtonDrive and similar services are designed around this property. If you have documents you’d want protected even from a valid legal process, these are the right tool.

Understand that encryption type matters more than encryption existence. “Encrypted” is almost universal among cloud services. E2EE is significantly less common. The distinction determines what’s accessible under compulsion.

Don’t conflate commercial privacy with legal privacy. A service that doesn’t sell your data (commercial privacy) is not necessarily one that can’t produce your data in response to a warrant (legal privacy). Both matter but they’re different properties.

Read transparency reports. Google, Apple, Microsoft, and others publish annual reports on government data requests. These reports show how many requests were received, how many were complied with, and in what categories. Reading them is the clearest picture of how frequently this actually happens.


The Big Picture

Cloud storage has made it easier than ever to keep copies of everything. It has also made it easier than ever for legal processes to access everything — because “the cloud” is not a private vault, it’s a company’s server, and companies operate within legal systems.

This doesn’t mean cloud storage is dangerous for ordinary use. It means that the word “private” in the context of cloud storage has a specific and limited meaning, and understanding those limits helps you make better decisions about what to store where and with what level of protection.

Your personal photos and files are almost certainly safe from legal requests. But “almost certainly” is not the same as “by design.” If the design matters to you, the architecture of the service you choose matters too.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts