A substantive expansion of the bill's scope. v3 expands the types of illicit material covered to include 'intimate visual depictions of minors' in addition to child pornography and child obscenity. It also refines the definition of 'approved vendor' to explicitly require compliance with cybersecurity standards and adds 'Tribal' agencies to the definition of 'covered agency'.
Safe Cloud Storage Act
- Sponsor
- Rep. Lee, Laurel M. [R-FL-15]
- Committees
- Judiciary Committee (primary)
- Last action
- Sep 17, 2026
Bottom line
The bill provides liability protection for cloud vendors storing child sexual abuse material for law enforcement, under strict security and oversight conditions, aiming to modernize evidence management.
What it actually does
This bill amends the PROTECT Our Children Act of 2008 to establish limited liability for cloud service providers that contract with law enforcement agencies to store digital child pornography, child obscenity, or intimate visual depictions of minors. It sets stringent cybersecurity, operational, and reporting requirements for these 'approved vendors' to ensure the secure handling and storage of such sensitive evidence.
Proponents argue
Supporters argue that the bill is essential for modernizing law enforcement's ability to securely store and manage digital evidence related to child exploitation. By offering limited liability, it incentivizes private sector cloud providers to partner with agencies, ensuring that critical evidence is protected with advanced cybersecurity measures and remains accessible for investigations and prosecutions.
Opponents contend
Critics might express concerns about the potential for private entities to handle such highly sensitive and illegal material, even with safeguards. They may argue that granting limited liability, despite the exceptions for misconduct, could reduce accountability or that the oversight mechanisms might not be robust enough to prevent misuse or breaches.
The bill is concise and can be read quickly, allowing sufficient time for evaluation of its core provisions and implications.
Section 202(b)
Limited Liability for Approved Vendors
This provision grants limited civil and criminal liability protection to 'approved vendors' (cloud service providers) when performing contractual obligations to store child pornography, child obscenity, or intimate visual depictions of minors for law enforcement. This protection does not apply if the vendor engages in intentional misconduct, negligent conduct, acts with actual malice, or for purposes unrelated to their contractual duties.
Supporters argue
Supporters argue that this provision is crucial to incentivize cloud providers to offer their services to law enforcement, as the risk of liability for handling such sensitive material is a significant barrier. This enables modernization of evidence storage, which is increasingly digital.
Critics contend
Critics might express concern that granting limited liability could reduce accountability for private entities handling highly sensitive and illegal content, even with safeguards. They might argue that the exceptions for misconduct need to be robustly enforced to prevent potential abuses.
Tradeoffs
This provision balances the need to encourage private sector participation in secure evidence storage with the imperative to maintain accountability for handling illegal and sensitive material, ensuring that gross negligence or malicious acts are still subject to legal action.
Section 202(c)
Vendor Cybersecurity Requirements
Approved vendors must comply with the NIST Cybersecurity Framework, minimize employee access to sensitive material, employ end-to-end encryption for data storage and transfer, and undergo independent annual cybersecurity audits. They are also required to promptly address any issues identified by these audits and can only access the stored material with the contracting agency's consent for maintenance or technical support.
Section 202(d) and (e)(1)
Evidence Retention and Data Sovereignty
Covered agencies must retain evidence in compliance with FBI security policies, applicable laws, or for the duration of the statute of limitations or sentence imposed. Additionally, approved vendors must ensure that all stored child pornography, child obscenity, or intimate visual depictions of minors remain within the United States, with a narrow exception for transfers outside the U.S. if deemed necessary for investigative purposes and with express agency consent.
The bill defines 'child pornography' by referencing section 2256(8) of title 18, United States Code, and 'intimate visual depiction of a minor' by referencing section 223(h) of the Communications Act of 1934 (47 U.S.C. 223(h)), including digital forgeries.
Section 202(a)(2) and (a)(5)
Why it matters:This is standard legislative practice to ensure consistency with existing federal law and avoid redundancy, rather than an attempt to obscure information.
Case for: Using established legal definitions ensures consistency with existing federal law regarding child exploitation material, avoiding ambiguity and potential legal challenges in prosecutions and investigations.
Case against: A casual reader might not immediately grasp the full scope of what is covered without looking up the referenced statutes, potentially leading to an incomplete understanding of the types of material being stored and protected under the bill.
Estimated impact: Ensures the bill's scope aligns precisely with existing federal prohibitions on child sexual abuse material, impacting all cases involving such evidence by providing clear legal definitions for the material being handled.
Approved vendors are required to file a notification letter with the Criminal Division of the Department of Justice within 30 days of entering a contract with a covered agency. This letter must include vendor and agency contact information and contract duration. Furthermore, if a covered agency breaches its contract or terminates it without lawful evidence transfer, the approved vendor must notify the DOJ (for federal agencies) or the appropriate State Attorney General (for state/local agencies) within 30 days, and continue to preserve the evidence until a lawful transfer of custody occurs.
Section 202(e)(2) and (e)(3)
Why it matters:These provisions establish critical administrative oversight and accountability mechanisms, which are often placed in later sections of a bill as standard practice for regulatory details.
Case for: These provisions ensure federal or state oversight of contracts for storing highly sensitive evidence, providing a critical backstop in case of agency non-compliance or contract failure. This enhances accountability and safeguards the integrity of investigations by preventing evidence from being lost or mishandled.
Case against: Some might argue that these notification requirements add administrative burden to both vendors and government agencies, potentially delaying contract initiation or complicating contract termination processes, without a clear demonstration of their necessity over other oversight mechanisms.
Estimated impact: Establishes a federal and state oversight mechanism for contracts involving the storage of child sexual abuse material, enhancing accountability and safeguarding evidence integrity across numerous jurisdictions.