Legal Threats

Laws, Jurisdiction & Compliance

Legal Challenges to Privacy

Data Retention Laws

Mandatory logging by ISPs and providers

Compliance

Lawful Intercept

Legal wiretapping and surveillance

Government

Compelled Decryption

Laws requiring password disclosure

Controversial

Gag Orders

Secret court orders prohibiting disclosure

Secrecy

Jurisdiction Considerations

Five EyesUS, UK, Canada, Australia, New Zealand - share intelligence
Nine/Fourteen EyesExtended intelligence sharing alliances
MLAT TreatiesMutual Legal Assistance enables cross-border requests
Company LocationWhere a company is based affects legal obligations

Concerning Laws

Notable Legislation
USA - PATRIOT Act, FISA Section 702, CLOUD Act
UK  - Investigatory Powers Act ("Snoopers Charter")
EU  - Chat Control proposals, eIDAS concerns
AU  - Assistance and Access Act (encryption backdoors)
CN  - Cybersecurity Law, Data Security Law

Protection Strategies

  • Choose services in privacy-friendly jurisdictions
  • Use providers with no-log policies (and audits)
  • End-to-end encryption means provider can't comply
  • Understand local laws before traveling
  • Consider plausible deniability tools
  • Know your rights regarding device searches