Tl;dr: For most data, the cloud vendor is basically forced to violate either the cloud act or the gpdr. The gpdr has a bunch of fuzzy carve outs for requests involving people in danger or the “public interest”. My guess is that those will be expanded over time to force the data to be handed over, regardless.
If the data isn’t “personal information” (financial records aren’t, for example), GPDR doesn’t apply and the warrant must be served.
I think this means that, because they could hypothetically receive a warrant they have to serve, the Ireland/EU intermediary (or the US company that provides them with the software/hardware) will have to backdoor the encryption.
I am not a lawyer, and I haven’t even read any of these bills. I’m just piecing together summaries. I don’t think anyone really knows how the three bills will interact in practice.
Tl;dr: For most data, the cloud vendor is basically forced to violate either the cloud act or the gpdr. The gpdr has a bunch of fuzzy carve outs for requests involving people in danger or the “public interest”. My guess is that those will be expanded over time to force the data to be handed over, regardless.
If the data isn’t “personal information” (financial records aren’t, for example), GPDR doesn’t apply and the warrant must be served.
I think this means that, because they could hypothetically receive a warrant they have to serve, the Ireland/EU intermediary (or the US company that provides them with the software/hardware) will have to backdoor the encryption.
I am not a lawyer, and I haven’t even read any of these bills. I’m just piecing together summaries. I don’t think anyone really knows how the three bills will interact in practice.