The Legal Nature of the UK-US CLOUD Agreement


The 2019 international agreement between the United Kingdom and the United States[1] on access to electronic evidence has attracted wide attention as a new tool of international assistance in criminal matters.[2]  Historically, countries have conducted such cooperation pursuant to mutual legal assistance treaties (MLATs). The UK-US CLOUD Agreement, however, is the first international instrument putting in place a new mechanism providing that law enforcement authorities can request e-evidence directly from a cloud service provider, without going through MLAT procedures.

The US Congress enacted the 2018 CLOUD Act[3] to address two significant questions relating to the relatively new phenomenon of evidence in electronic form.  First, the Act decrees that a US law enforcement authority may rely upon a warrant issued by a federal court to obtain, from a cloud service provider present in the United States, the content of electronic communications physically located outside the United States.  Second, the CLOUD Act pre-authorizes the US executive to conclude executive agreements with foreign states enabling their law enforcement authorities to obtain US-located e-evidence directly from cloud service providers. These agreements are to be reciprocal in nature, also allowing US law enforcement likewise to make direct requests to providers for e-evidence located in the territory of the other state.

In part I of this post, we examine the legal nature of the UK-US CLOUD Agreement: is this “executive agreement” a binding legal treaty under international law, subject to the 1969 Vienna Convention on the Law of Treaties (VCLT)? This topic, so far unexplored, is important because the agreement purports to create binding rights and obligations not only for the two States but also for private actors, including cloud service providers and individuals. It matters as well for the series of similar negotiations that the United States intends to pursue with other States and entities, including those already underway with the European Union and Australia.

Part II considers questions of the meaning and legal effect of a CLOUD Act agreement under US law.  In part III, we examine how the two parts of the CLOUD Act relate to each other.  May the United States resort to its unilateral warrant authority to obtain e-evidence located in the United Kingdom, instead of utilizing the channels prescribed in the UK-US CLOUD Agreement itself?  If so, are others pursuing negotiations with the United States obliged to accept this approach taken by the UK-US CLOUD Agreement while remaining within the framework of the agreements envisioned by the second part of the CLOUD Act? Is the United States free to vary it?


I.      Does a CLOUD Act Agreement Satisfy the Requirements of the Vienna Convention on the Law of Treaties?

“What is a treaty? Simply put, it is an international agreement,” according to the Oxford Guide to Treaties.[4]  Another standard source describes a treaty as “the creation of written agreements whereby the States participating bind themselves legally to act in a particular way or to set up the particular relations between themselves.”[5]

Article 2(1)(a) of the Vienna Convention on the Law of Treaties (VCLT) provides a more precise definition: “treaty means an international agreement concluded between States in written form and governed by international law, whether embodied in a single instrument or in two or more related instruments and whatever its particular designation.”[6]

Thus, as a matter of international law, a ‘treaty’ need not be expressly denominated as such.  Other international agreements that States intend to be binding also qualify, and indeed the name they give to the legal instrument, or the form it takes, is irrelevant.[7]  What matters is whether the agreement fulfills the elements of the VCLT definition.  If it does, it is binding upon the States and must be performed by them in good faith, in accordance with Article 26 of that convention.[8]

Under the definitional requirements of Article 2(1)(a) of the VCLT, an international agreement must be 1) “concluded between States” [9]; 2) “in written form”; and 3) “governed by international law”.  The UK-US CLOUD Agreement — the first concluded pursuant to the CLOUD Act — clearly satisfies these requirements.  Its parties are the United Kingdom and the United States, and they denominate it an “Agreement”.  Further, it consists of a written text, uses verbs of legal intentionality (e.g., shall) and it has been signed by the UK Minister of Justice and the US Attorney General. The agreement will take effect following an exchange of notes between the parties “indicating that each has taken the steps necessary to bring the agreement into force.”[10] Finally, it contains a procedure for termination traditionally found in international agreements.

The UK’s domestic approval step is ratification by Parliament.[11] The US counterpart procedure, specified in the CLOUD Act itself, is for the executive to submit the agreement to Congress for a 180-day period of review; if neither house of Congress objects during that time period, the agreement may enter into force.[12]

The UK-US CLOUD Act agreement also meets the third requirement of being ‘governed by international law’.  This means, according to the negotiating history of the Vienna Convention, that an agreement must intend to create legal rights and obligations or to address a specific legal situation.[13] Clearly, the UK-US CLOUD Agreement arises in the context of international relations between the two States.[14] The agreement expressly states that its purpose is “the establishment of a system of access to electronic data that is comprehensively governed by binding, appropriate and substantial safeguards.”[15]


II.      Does a CLOUD Act Agreement Qualify as a Treaty or International Agreement under US Law?

States also define treaties under their own domestic laws in order to specify the procedural requirements for their national approval.  The US Constitution grants to the President the “Power, by and with the Advice and Consent of the Senate, to make Treaties, provided two thirds of the Senators present concur.”[16]

In the centuries since the promulgation of the US Constitution, the US legal system has devised alternative methods for authorizing another category of binding international agreements, and for approving them by means that are less time-consuming than the Senate advice and consent procedure.[17]  The United States began to conclude executive agreements with foreign states in the nineteenth century.  Today the vast majority – more than 90% — of US international agreements are categorized by the US Department of State as executive agreements rather than treaties.[18]

The term ‘executive agreement’ is not defined in US law or by the VCLT, but scholars have explained its contours.  An executive agreement is “a treaty that has been concluded and ratified by the executive branch without formal approval by a legislative body, in a State in which treaties are usually ratified only with such approval.  The term executive agreement refers only to the status of the agreement within the domestic law of the State in question.”[19]

The distinction in US law  between ‘treaties’ and ‘executive agreements’ is thus essentially procedural, depending on whether the legal instrument is submitted for Senate advice and consent and Presidential ratification.[20] The United States views both ‘treaties’, as referred to in the Constitution, and binding international agreements approved by other procedural means, as ‘treaties’ in the international law sense of that term.[21]

The US President must have authority under US law to enter into a treaty or executive agreement.  His power derives either from the US Constitution itself or from legislation passed by the US Congress specifically authorizing him to negotiate a type of international agreement.  In some cases, Congress attaches strings to a statutory authorization by requiring the Executive to submit a resulting international agreement to Congress for a certain period of time before the President may actually bring it into force.[22]

In the United States, treaties and other international agreements are not enacted into domestic law, unlike in many other States.  Rather, the US Constitution provides that “all treaties made, or which shall be made, under the authority of the United States, shall be the supreme law of the Land.”[23]  In other words, they become part of US law without the need for transposition.  The United States Supreme Court has ruled that the domestic legal effect of an executive agreement is the same as a treaty.[24]

The US executive generally strives during negotiations of treaties and international agreements to ensure that the international obligations to be assumed do not exceed the limits of existing US law.  However, where a change to US law is needed in order to give full effect the agreement, the US Congress must enact implementing legislation.[25] For example, in order to give effect to the Genocide Convention, Congress first had to criminalize the offense of genocide in US criminal law.[26]

Sometimes Congress is asked to change an existing provision of US law in order that an international agreement may be successfully completed. During negotiations between the United States and the EU on an executive agreement to protect privacy interests in law enforcement proceedings, for instance, the EU insisted upon a provision enabling an EU citizen to seek redress in US courts in the event that a US law enforcement agency had improperly accessed or disclosed his personal information.  At that time, however, the US Privacy Act afforded judicial redress only to US citizens.  Only after the US Congress enacted the 2015 Judicial Redress Act[27] expanding access to foreign citizens was the United States in a position to agree to the inclusion of such a provision in the agreement.[28]

A CLOUD Act agreement is categorized under US law as an “executive agreement” – and not a “treaty” — because the CLOUD Act itself calls for the conclusion of international agreements in that form.[29] The Act also specifies the domestic procedural requirements for approval of agreements done under its authority.  The US executive must submit to Congress a series of certifications that a CLOUD Act agreement fulfills certain privacy and due process requirements, and the Congress must be afforded a mandatory period to review an agreement before it may enter into force.[30]   On January 10, 2020, after completing the certification requirements for the UK-US CLOUD Agreement, the US executive submitted it to Congress. Unless Congress affirmatively disapproves the agreement, the President will be authorized to bring it into force on July 8, 2020.[31]


III.       How do the Two Parts of the CLOUD Act Relate to One Another?

The first part of the CLOUD Act states that US law enforcement authorities may obtain electronic evidence stored outside the United States by means of a judicially-authorized warrant served upon a cloud service provider with a US presence.  The second empowers the US Executive to conclude international agreements allowing foreign states to obtain e-evidence located in the United States directly from cloud service providers.  How do these two dimensions of the Act – one unilateral, the other consensual – relate to each other?

States traditionally rely on international agreements such as mutual legal assistance treaties to organize international cooperation on judicial matters and to preclude incursions into their judicial sovereignty that otherwise would result from a foreign state’s unilateral legal process.[32]  The second part of the CLOUD Act is not intended to displace MLATs, but rather to offer an additional type of international agreement specifically designed for securing e-evidence.[33]

The UK-US CLOUD Agreement fulfills this function, but also acknowledges the possible continued use of unilateral process.  In a provision entitled “Compatibility and Non-Exclusivity”, it states that the Agreement is “without prejudice to and shall not affect other legal authorities and mechanisms for the Issuing Party to obtain or preserve electronic evidence from the Receiving Party and from Covered Providers subject to the jurisdiction of the receiving Party, including legal instruments and practices under the domestic law either Party as to which the Party does not invoke this Agreement; requests for mutual legal assistance; and emergency disclosures.”[34]

Not all States with which the United States has concluded agreements on access to foreign-located evidence have accepted this result, however.  For example, the MLAT between the Federal Republic of Germany and the United States contains an express provision limiting a Party’s use of unilateral compulsory process in deference to a treaty-based request.  Only if reliance on a treaty-based requests causes undue delay in production of evidence may the requesting State resort to its unilateral process.[35]

Similarly, the United States also concluded an executive agreement with the European Union in order to obtain, for purposes of its Terrorist Finance Tracking Program (TFTP), access to international bank transaction data held by the SWIFT company[36] in Europe. Initially, the US Treasury had utilized domestic administrative subpoenas to obtain the same data from a US-located SWIFT database, but public disclosure of SWIFT’s compliance with unilateral US process generated sovereignty and privacy concerns in Brussels.  The resulting 2010 Agreement established a system whereby Europol, the EU police cooperation agency, would verify US Treasury requests for data in order that they be given binding legal effect in EU territory.  SWIFT then would transmit responsive data directly from Europe to the US Treasury.[37]  The agreement is the exclusive means for the US Treasury to receive such data from EU territory.

Nothing in the CLOUD Act would preclude incorporation into a future CLOUD agreement of a ‘first resort’ provision like that in the Germany-US MLAT.  Nor would the United States otherwise be precluded from agreeing to consider a CLOUD agreement the exclusive means of obtaining information from a foreign jurisdiction, as it effectively did in the case of the EU-US TFTP Agreement. Whether any of those parties with which the United States pursues CLOUD Act agreements will seek to exclude or delay US resort to unilateral domestic procedures remains to be seen.  They will have to weigh their sovereign sensitivities against their strong desire for rapidly completing an agreement urgently sought by their own law enforcement authorities.



A CLOUD Act executive agreement fulfills the VCLT requirements to be characterized as a binding international agreement. It also qualifies as a binding international agreement under U.S. law.

The United States Government presumably sees the agreement with the United Kingdom as a template for its ongoing negotiations with Australia and the European Union, as well as for future partners.  However, agreements with other partners do not necessarily need to be identical to the UK-US one in order to be regarded as binding international agreements under international law and US law. This would be the case, for example, irrespective of whether the EU and the US choose to conclude a comprehensive CLOUD/e-evidence agreement, as the EU seems to desire, or instead a framework agreement requiring additional implementing legal instruments between the US and individual EU member states.

The UK-US CLOUD Agreement establishes agreed procedures in order to obtain e-evidence from the other’s territory, but it does not make these procedures exclusive. It may come as a rude shock to other partners that concluding a CLOUD Act agreement along the lines of the UK-US one would do nothing to preclude the United States from utilizing its unilateral legal process to obtain e-evidence stored in their territory by cloud service providers.

Concluding this new generation of agreements on international assistance in criminal matters is a necessity to address the challenges created by the rampant globalization of criminal evidence.[38] Flexibility and creative legal thinking will be key to  building a new, successful, international legal regime permitting law enforcement authorities of democratic States to gain access to communications and other records necessary for criminal investigations, in a way consistent with privacy, human rights, and the sovereign concerns of all involved States.


About the Authors

Theodore Christakis is Professor of Law at the University Grenoble Alpes and a Senior Fellow with the Cross-Border Data Forum. He is a member of the Institut Universitaire de France, the French National Digital Council and the French National Committee for Data Ethics. He is co-Director of the Grenoble Alpes Data Institute and Chair on the Legal and Regulatory Implications of Artificial Intelligence within the Multidisciplinary Institute in Artificial Intelligence. He has advised Governments, International Organisations and the private sector on issues concerning International and European law, Human Rights, Cyber security law and Data protection.

Kenneth Propp was for many years the principal US Department of State negotiator of law enforcement information sharing agreements between the United States and the European Union and its member states, including the 2003 Agreements on Mutual Legal Assistance and Extradition.  From 2011-15 he was Legal Counselor at the US Mission to the European Union in Brussels.  Currently, he teaches European Union law at Georgetown University Law Center, and is a Senior Fellow with the Future Europe Initiative at the Atlantic Council and with the Progressive Policy Institute.

The authors would like to thank Duncan Hollis and Peter Swire for their useful comments on a previous version of this paper.


