Law & Policy

MLATs: How One Country Asks Another for Your Data

July 31, 2026 9 min read Haven Team

A prosecutor in Berlin is investigating a case and needs the contents of an account held by a company in California. German law gives them the authority to demand evidence. It does not give them any authority over a California company. The formal answer to that problem is a mutual legal assistance treaty, and almost everything else built in this area over the past decade exists because the formal answer is slow.


The formal channel, step by step

Mutual Legal Assistance Treaties are bilateral agreements to help each other gather evidence in criminal matters. They predate the internet by decades and were built for bank records, witness statements and physical searches. A request for stored electronic communications travels roughly like this:

  1. The German investigator prepares a request and sends it to Germany's central authority for treaty matters.
  2. That authority reviews and forwards it to its counterpart in the United States, which is the Justice Department's Office of International Affairs.
  3. US lawyers assess whether the request satisfies United States legal standards, not German ones. For message contents, that means probable cause and a search warrant.
  4. A federal prosecutor applies to a US court for the warrant.
  5. The warrant is served on the provider, which produces the data.
  6. The material travels back up the same chain to Berlin.

Each step is a queue. The translation has to be right, the legal theory has to be re-expressed in the receiving country's terms, and the central authority handling the volume is a small office. Response times measured in many months, sometimes years, are a long-standing and well-documented complaint. The President's Review Group on Intelligence and Communications Technologies flagged the delays and recommended reform back in its 2013 report, and the process has been under continuous criticism since.

The structural friction

An MLAT request is judged by the standards of the country receiving it. A German investigation that met every German requirement can still fail in the United States because probable cause is a different test. The treaty is not a translation layer between legal systems; it is a requirement to satisfy both.

What grew in the gap

When a formal channel is too slow for the pace of the work, practice routes around it. Four routes now carry most of the traffic.

Direct voluntary requests

Many US providers will respond to a foreign law enforcement request for basic subscriber information without any treaty process, on a voluntary basis, if their own policies permit it. Content is different and generally still requires US legal process. This means the tier of data a foreign investigator can reach informally is exactly the tier that is easiest to obtain and hardest to notice, which is the metadata layer.

Emergency requests

The emergency disclosure provisions that let a provider hand over data without a court order in a life-threatening situation do not require a treaty either. A foreign agency can invoke them directly. This is the same mechanism, with the same weak requester-authentication problem, described in how to read a transparency report.

Data localisation

The simplest way to avoid needing a treaty is to require the data to be inside your own borders in the first place. That is a substantial part of the motivation behind localisation laws, which are frequently framed as privacy measures and function, in this respect, as the opposite: they bring data within reach of domestic legal process.

Executive agreements under the CLOUD Act

This is the largest change. The CLOUD Act, passed in 2018, did two separate things. It confirmed that a US warrant reaches data in the possession or control of a US provider regardless of which country the servers sit in, which resolved the long-running Microsoft Ireland litigation by making it moot. And it created a framework for executive agreements allowing a qualifying foreign government to serve orders directly on US providers, skipping the treaty chain entirely.

The United Kingdom was first, with a data access agreement in force since 2022, and an agreement with Australia followed. Under such an agreement, a British order goes to the provider, not through Washington. The eligibility conditions are meant to be the safeguard: a partner government must meet standards on rule of law and civil liberties, and must not target US persons.

The European Union built its own version internally. The e-Evidence Regulation creates European Production Orders that an authority in one member state can serve on a service provider established in another, with a compliance clock measured in days for urgent cases rather than months. It becomes applicable during 2026. Separately, the Second Additional Protocol to the Budapest Convention, opened in 2022, provides for direct cooperation with providers in other parties for subscriber information.

Same data, four very different journeys

Channel Typical speed Judicial review where? Reaches content?
MLAT Months to years Both countries Yes
CLOUD Act agreement Days to weeks Requesting country only Yes
Direct voluntary request Days None Generally no
Emergency request Hours None Yes

Read down the last three columns together. The channels that resolve fastest are the ones with the least independent review, and the fastest of all can reach message contents. That ordering is not an oversight. It reflects a genuine trade-off between the speed investigators need in a kidnapping and the scrutiny everyone else needs the rest of the time, and it is why the authentication of emergency requests matters far more than its obscure placement in most reports suggests.

What this does to jurisdiction claims

Privacy services frequently market their country of incorporation. Switzerland, Iceland, Panama and Germany all get invoked as though the flag settles the question.

It settles less than it used to, for a specific reason. The newer channels attach to the provider rather than to the data's location. The CLOUD Act reaches data controlled by a US company wherever it is stored. An EU production order reaches a provider offering services in the Union. A local court reaches a local entity. Moving bytes to a friendlier country does not move the company that can be ordered to fetch them, and moving the company creates a new set of obligations rather than an absence of them.

There is also a plain historical example. In 2021 a Swiss provider with a strong privacy reputation logged a user's IP address after a Swiss court order originating in a foreign request, and said so publicly afterward. Swiss law applied, exactly as written. The company's jurisdiction was never the protection its users had understood it to be, a point we went through in more detail when looking at the limits of that model.

What actually survives every channel above is the same thing in each case: data the provider does not hold, and data the provider holds but cannot read. A warrant compels production, not comprehension. If a service holds only ciphertext it cannot decrypt, then whether the order arrived by treaty, by executive agreement or by emergency request changes the speed of the response and nothing about its contents. That is the difference between a legal promise and an architectural one, and it is the reason the encryption question and the jurisdiction question deserve to be asked separately.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →