Cross-border data requestsA demand has to become an order where the disk is, or it stays a letter.

Three guides on this site use the phrase “mutual legal assistance” and not one of them stops to say what it is. This one does: the five routes a request can take across a border, how many desks each one passes, which two reach a company without a treaty at all — and the two that never involve a court.

13 хв читання · Востаннє перевірено 15 вересня 2026 · Це не рекламна сторінка

The phrase this market uses and never explains

Read enough of this industry and you meet the same claim in two opposite directions. One says a server abroad is simply out of reach. The other says none of it matters because they will get the data anyway. Both are guesses, and the thing they are guessing about has a name, a procedure, a queue and a paper trail.

An investigator in one country who wants records held by a company in another has a small number of routes open — five, on a generous count. Only one of them is the treaty everybody names and nobody describes. Two are faster than the treaty and rest on a test that has nothing to do with where the hardware is. And the fastest routes of all are not law at all, which is the part of this that actually ends websites.

The five routes across a border

They differ in who is served, who is able to refuse, and whether a judge ever reads the file. Roughly fastest first, which is close to the reverse of how much weight each one carries.

ШляхWho it is served onWhat stops it
An informal request by emailThe provider, directly, with no local process behind it at allВідмова провайдера, яка не коштує йому нічого, крім рішучості
A production order posted abroadThe provider, directly, on the issuing country’s paperJurisdiction: an order binds an entity its court can actually reach
A direct order under a regional instrumentA provider that has agreed, by operating there, to be reachableWhether the provider is inside that instrument’s scope at all
Mutual legal assistanceThe provider, on an order from a court in its own countryDual criminality, two central authorities, and a local judge
A letter rogatoryThe same, with no treaty underneath the requestEverything that stops an MLAT, plus diplomatic discretion

Three of the five end with somebody local serving local paper, and that is the sentence worth carrying away from the table. The other two ask a company to act on a document that has no force where the company is standing. Whether “offshore” means anything at all is, almost entirely, the question of what a provider does with those two.

An MLAT is a treaty between two states promising each other help in criminal matters: evidence, testimony, records, the service of documents. There are hundreds of them, nearly all bilateral; the United States alone is party to more than sixty. They exist because a prosecutor has no power abroad and a court order is a domestic instrument. The treaty does not hand the requesting state reach. It hands it a queue.

The queue runs through designated offices called central authorities, and a request is passed from one to the next rather than sent point to point. In the United States that office is the Office of International Affairs in the Department of Justice; elsewhere it is usually the ministry of justice. The chain has the same shape almost everywhere:

  1. An investigator drafts the request and gives it to their own central authority, in the form the treaty specifies, naming the offence and the records wanted.
  2. That authority checks the request falls within the treaty and transmits it to the central authority of the requested state. Requests are sent back at this step for being vague, and a great many are.
  3. The receiving authority tests it against its own country’s law and hands it to a local prosecutor or investigating magistrate.
  4. That prosecutor applies to a local court for a domestic order, exactly as they would in a domestic case, on domestic grounds.
  5. The court grants or refuses. If it grants, a domestic order is served on the company — in its own country, in its own language, under its own law.
  6. Whatever is produced travels back up the same chain in reverse, each step with a queue of its own.

A letter rogatory is the same journey with nothing underneath it: a request from a court in one country to a court in another, sent through diplomatic channels and granted as a matter of comity rather than obligation. It is what is used where no treaty exists, and it is slower than the mechanism people already complain is slow.

The four filters a request has to survive

These are not formalities. They are where the attrition happens, and three of the four are applied by people with no stake in the investigation.

  1. Dual criminality. Most treaties allow assistance to be refused where the conduct described is not an offence in the requested state as well. A country whose law does not recognise the offence has nothing to instruct its own courts about.
  2. Specificity. The request has to name what is wanted with enough precision for a local judge to sign an order for it. “Everything associated with this website” is not a thing a court in a rule-of-law state issues an order for.
  3. The requested state’s own law. The order that finally lands is a domestic order, so it has to satisfy domestic requirements — proportionality, data protection, and in the European Union Article 48 of the GDPR, which makes a third-country demand recognisable only where an international agreement backs it.
  4. The record has to exist. No treaty compels a company to produce a thing it does not hold, and no court orders it to reconstruct one.

The fourth filter is the only one a customer has any influence over, and it is therefore the only one worth spending money on. Everything else in that list is somebody else’s procedure. What is in the records is a decision taken by a provider years before the request arrives, and by you when you choose what your own application writes down — which is the subject of what your own site records about readers.

Why it takes as long as it does

Every hop in that chain is a desk with a backlog, and the delays compound rather than overlap. The figure usually quoted for a completed mutual legal assistance request is close to ten months, and it does not come from this industry: the United States’ own review group on intelligence and communications technologies reported it in 2013, and the European Commission cited a comparable figure when it was making the case for the instrument described two sections below. Nothing since has made it dramatically faster.

Ten months is neither a technicality nor a reason to relax, and treating it as either is a mistake. It is a structural fact about a process with six queues in it, and it is why the preservation request exists: a short instrument, sent on day one, asking that records which exist today stop being deleted while the slow machinery runs. Preservation is the part people miss when they think about timescales. A demand that produces nothing for a year may still have frozen something on the first afternoon — if there was something there to freeze.

The CLOUD Act is about the company, not the country

In 2013 the United States served a warrant on Microsoft for email stored in Dublin. Microsoft argued that a domestic warrant did not reach Ireland. The case ran as far as the Supreme Court, and in March 2018 Congress made it moot by passing the CLOUD Act.

What the Act did takes one sentence, and it is the sentence this market should have read. It amended the Stored Communications Act — 18 U.S.C. §2703 — to require a provider subject to United States jurisdiction to produce data in its possession, custody or control, regardless of whether that data is stored inside the United States or not.

Now read it for what it does not say. It says nothing whatever about where the server is. The location of the disk stopped being the question; the only question the Act asks is whether the company holding it can be reached by a United States court. A US corporation with a Frankfurt datacentre is inside. A company with no US presence is outside, and the disk sitting in Virginia would not change that — for that, the United States is back in the queue described above.

The Act opened a second route as well: executive agreements between the United States and a qualifying foreign government, under which each side’s authorities may serve orders directly on providers in the other. The United Kingdom signed the first in 2019 and it took effect in 2022; Australia followed. These reach providers within the grasp of the signatory governments and nobody else, which is the same test as before wearing a different hat.

What changed in Europe in August 2026

The European Union has built its own version of the direct route, and it began applying on 18 August 2026 — recently enough that most pages in this market have not caught up with it. Regulation (EU) 2023/1543 creates the European Production Order and the European Preservation Order: an authority in one member state can issue an order and serve it directly on a service provider offering services in the Union, without passing through the second state’s authorities the way mutual assistance does.

Its companion, Directive (EU) 2023/1544, is the part that makes it work. Providers offering services in the Union must designate an establishment or a legal representative in a member state to receive these orders. That designation is the hook, and it is the CLOUD Act test written the European way round: the instrument reaches whoever has agreed, by operating there, to be reachable.

ІнструментWhat it reachesHow many states have to agree
Mutual legal assistanceAny company at all, through a court in its own countryTwo, and a judge in the second one
CLOUD Act, 18 U.S.C. §2703A provider subject to US jurisdiction, wherever the data sitsOne
Regulation (EU) 2023/1543A provider offering services in the Union, from 18 August 2026One
Budapest Convention, Article 32(b)Data already public, or held by someone who consents to disclose itNone — no request is made

The last row is the one quoted wrongly most often. The Budapest Convention on Cybercrime — Council of Europe treaty ETS 185, opened in 2001 and now ratified well beyond Europe — provides for expedited preservation in Article 29, for mutual assistance with stored data in Article 31, and in Article 35 requires every party to keep a point of contact reachable twenty-four hours a day. Article 32(b), the one people cite as a general power of remote access, permits it only where the data is publicly available or where the person lawfully entitled to disclose it consents. It is a narrow door, and it is not a back one.

The two routes that never see a judge

Here is the uncomfortable half of the answer. Every route above is slow, formal and countable — the report at the end of this page counts them. The routes that actually end most websites are none of those things, and a reader who has followed the treaty machinery this far is usually worrying about the wrong thing.

  • The upstream. A provider rents transit from carriers and floor space from a facility. A complaint sent to those instead of to the provider reaches a party with no relationship to you and nothing to lose by acting on it. What answers it is a provider that owns the relationship and has refused before.
  • The registrar. A domain is a licence from a registry in its own jurisdiction, and a registry can suspend a name without touching the server at all. The machine keeps serving; nothing resolves. It is a different attack surface with its own guide.
  • The payment rail. A card processor can freeze an account on a complaint, at will, with no process worth the name and no appeal. It is most of the reason settlement here is on-chain only.
  • The abuse desk. A complaint is read by a person at a different desk, on a different clock, against a policy rather than a statute. Who reads a complaint about you describes that from the inside.

None of those is a cross-border data request, which is precisely why they belong in a guide about cross-border data requests. The threat people buy offshore hosting to solve is frequently not the threat that reaches them.

Reading a host’s structure against all of this

Everything above reduces to a handful of checkable facts about a company, and every one of them can be established before you spend anything.

  1. Which entity is on the invoice, and where is it registered. Not the region, not the flag on the map: the company you are forming a contract with.
  2. One entity, or one for each region. A single company operating eight countries is one defendant with eight addresses, and an order against it reaches all of them.
  3. Is anything in the group reachable from the jurisdiction you are thinking about. A parent, a subsidiary, an office, a bank account. This is the CLOUD Act test and it applies far more widely than the Act does.
  4. What does the provider say it does with a foreign order. In writing, with a timescale, published before it needed one.
  5. What does it publish afterwards. A count of what arrived, what met the bar, and what was actually produced. The third number is the one nobody fakes convincingly because it is the one that would be embarrassing.
  6. What exists to be produced at all. The last question, and in the end the only one that decides anything.

The structure on this estate is eight regions and eight companies, each on its own country’s register, which is the reason an order obtained against one is not enforceable against another without starting the whole process again in the second country. It is an expensive way to arrange a business and it is arranged that way for this reason alone; the terms say so in clause 1 and the entity list is on the about page.

What it looks like in the numbers

This estate publishes what arrives, by quarter, and has since it opened. Of 164 law-enforcement requests received to date, 54 met the legal bar — an order from a court with jurisdiction over the entity served — and 31 produced anything at all.

The figure worth reading is the gap. One hundred and ten requests, two thirds of everything that arrived, never got past the question this entire guide is about: was this served by a court that can reach the company it was served on. That is not a refusal rate and it is not defiance. It is the shape of the problem, in a sample of one company.

The second figure is at the other end. Of the thirty-one that produced something, what was produced is inventory — an email address held against an account, an on-chain ledger entry — and never the contents of a disk. Not because a line was heroically held, but because a record that was never created cannot be handed to anybody. The full report is at the transparency page, and the process it counts is written out at the law-enforcement policy.

Питання, які справді ставлять

How long does an MLAT request take?

The figure most often cited is around ten months, and it comes from governments rather than from hosting companies: the United States’ 2013 review group on intelligence and communications technologies reported it, and the European Commission used a comparable number when arguing for a faster instrument. The reason is structural rather than institutional laziness — the request passes through six desks in two countries, four of which are entitled to send it back, and the delays add up instead of overlapping.

Can United States police get data from a server in Europe?

Through a European court, yes, on the same terms as European police: a mutual legal assistance request that becomes a domestic order in the country where the company is. Directly, only where the company is subject to United States jurisdiction — which the CLOUD Act made the whole question in 2018, replacing the older argument about where the disk was. A provider with no United States presence receives a US warrant as correspondence, because that is what it is where the provider stands.

Does the CLOUD Act apply to my offshore host?

It applies if that host is subject to United States jurisdiction, and the location of its servers has no bearing on the answer. Check the legal entity on the invoice, then check its parent and its group: a US corporation with hardware abroad is inside the Act, and a non-US company with hardware in the United States is not — for that hardware the United States would use a domestic warrant on the facility instead. None of the eight entities on this estate is incorporated in the United States or owned by a company that is.

What is a letter rogatory?

A formal request from a court in one country to a court in another, sent through diplomatic channels, asking for assistance that no treaty obliges the second country to give. It is the older mechanism and the one still used where no mutual legal assistance treaty exists between the two states. It is granted as a matter of comity, which means it can be declined without explanation, and it is slower than an MLAT rather than faster.

Can a foreign police force seize my server directly?

No. A seizure is a physical act inside a facility, and it requires a warrant from a court with authority over the ground that facility stands on. A foreign force wanting that has to persuade the local authorities to obtain it and execute it, which is the mutual assistance route with an extra step on the end. No equipment at any facility this estate occupies has ever been seized, imaged or physically accessed by any authority, and that assertion is one of the lines in the signed warrant canary.

Does the Budapest Convention let police access data in another country?

Only in two narrow cases, and the article is routinely quoted as though it said something wider. Article 32 permits access without the other state’s authorisation where the data is publicly available, or where the person lawfully entitled to disclose it gives consent. Everything else runs through Articles 29 and 31, which are preservation and mutual assistance — the ordinary machinery, with a twenty-four-hour point of contact bolted on by Article 35.

What is a European Production Order?

An order issued by an authority in one EU member state and served directly on a service provider offering services in the Union, created by Regulation (EU) 2023/1543 and applying since 18 August 2026. It removes the second state’s authorities from the path that mutual assistance runs along. Its reach is defined by the provider offering services in the Union, not by where the data is kept, and its companion directive requires such providers to designate somebody in a member state to receive one.

Does hosting in several countries actually make a difference?

Only if the countries are also several companies, which is the distinction almost every provider in this market leaves deliberately blurry. Eight flags operated by one legal entity is one defendant, and a single order against that entity reaches every rack it owns. Eight flags that are eight companies on eight registers means a ruling against one of them stops at the border and the applicant starts again. The map is decoration; the company register is the fact.

Кожна ціна цієї інфраструктури повністю опублікована в одному місці. Переглянути весь каталог