Digital Evidence and Electronic Signature Law Review(2023)
被引用0|浏览0
摘要
With the rise in cloud computing, law enforcement is increasingly in need of digital evidence stored across borders.This data is often controlled by US service providers, or physically located in a data center, outside of the jurisdiction.The current system for cross-border data requests, mutual legal assistance treaties (MLAT), is incapable of meeting the increasing demand for digital evidence, resulting in unworkable delays in accessing evidence for the investigation of serious crime.As a result, governments may turn to hacking, unilateral extraterritorial reach of production orders, and data localization, to access digital evidence more easily.These methods can lead to foreign policy tensions, a splintering and inefficient internet, and possible human rights' abuses.New reforms have emerged in the US and Europe to address deficiencies in the MLAT system but have yet to be implemented.This thesis will begin by considering the concerns of stakeholders involved -law enforcement, service providers, and data subjects -and the nature of data and technology of cloud computing.By engaging in a comparative analysis of areas of transnational law that involve similar conflicts of law and conducting a doctrinal analysis of well-accepted doctrines of sovereignty and jurisdiction under public international law, this thesis will formulate a theory of data sovereignty for law enforcement access to data across borders.This thesis will then utilize this theory of data sovereignty to critically assess emerging approaches to reform the MLAT system, including the US Cloud Act, the Council of Europe Cybercrime Convention Additional Protocol, and the EU E-Evidence Proposal.Ultimately, the thesis will determine whether these principles of data sovereignty can be utilized to identify a harmonized approach to law enforcement access to cross-border data that simultaneously: (1) offers enhanced certainty to internet service providers by eliminating conflicts of laws; (2) respects individual privacy and other human rights; and (3) recognizes sometimes overlapping, yet legitimate, state interests in accessing and protecting data.