In a recent opinion, the Second Circuit ruled against the United States government and in favor of protecting data stored overseas. In Microsoft v. United States, the Second Circuit held that the Stored Communications Act (SCA) does not authorize courts to issue warrants against internet service providers (ISPs) for the seizure of customer email content stored exclusively on foreign servers. The case began in December 2013 when the government obtained a warrant to gain access to a Microsoft customer’s account on a server in Dublin, Ireland. Microsoft argued that the United States lacked the authority to obtain the data due to its location in an overseas server. The United States countered, arguing that the SCA warrant required Microsoft to turn over the data because, although the data was stored in an overseas server, Microsoft had access to it in the United States. Ultimately, the Second Circuit decided in favor of Microsoft. The Court held that the data was located in Ireland and the SCA was not meant to be applied extraterritorially.
On January 24, 2017, the Second Circuit denied rehearing the case. Although the decision was reached in a tie (4-4 vote), the rehearing request was denied due to a rule requiring a majority vote for granting of petitions. The decision garnered four dissents, with each dissenter essentially arguing that the issue rested on the location of the disclosure of the information, which would take place in the United States, and not the location of the information itself.
Microsoft v. United States raises important data privacy questions that will likely reappear in future cases. Asking courts to apply dated technology statutes and answer the complicated question of where virtual data is physically located leaves no straightforward answer. The United States government might get another shot to revisit this question in the near future, but it will have to be through the Supreme Court.