Received
Decided
Refused
Request Reference FOI/P049/2026
Requester Type Other
Department of Public Expenditure, Infrastructure, Public Service Reform and Digitalisation

I am making this request under the Freedom of Information Act 2014. I request access to records held by your Department/Organisation (including OGCIO) concerning the storage of data on cloud platforms subject to United States jurisdiction and any related legal, data protection, or risk assessments. I am particularly interested in the following legislation and how it impacts the data of Irish Government departments and Offices. a. The Electronic Communications Privacy Act (1986) b. The CLOUD Act, Clarifying Lawful Overseas Use of Data Act (2018) c. The Foreign Intelligence Surveillance Act and the FISA Amendments Act (2008) Specifically, I request the following: 1. Does your organisation store any data relating to Irish citizens on cloud platforms which are subject to U.S. jurisdiction (for example, Microsoft, Amazon, or Google)? If so, please list the cloud service providers used. 2. Does your organisation store any emails relating to Irish citizens with cloud email providers subject to U.S. jurisdiction (for example, Microsoft 365 or Gmail)? 3. Please release any Data Protection Impact Assessments (DPIAs), transfer impact assessments, or other data protection assessments carried out in relation to these providers. 4. If you store data with a cloud provider subject to U.S. jurisdiction, please release any Board, Management Committee, or senior governance decisions, briefing documents, risk assessments, or legal advice (where not legally privileged) concerning risks posed by the following United States legislation: a. The Electronic Communications Privacy Act (1986) b. The CLOUD Act, Clarifying Lawful Overseas Use of Data Act (2018) c. The Foreign Intelligence Surveillance Act and the FISA Amendments Act (2008) 5. Does your organisation have any agreement, memorandum of understanding, contractual clause, or other arrangement with the United States Government or any U.S. authority to provide notification of requests for data made under any of the above legislation? If so, please provide the wording of that agreement or the relevant extracts. 6. Please provide an estimate of how many requests for your organisation’s data have been made under the above U.S. legislation. Please provide any related reports. 7. Does your organisation hold any estimate of how many emails or other documents have been released by your cloud providers to U.S. law enforcement authorities as a result of warrants or other legal processes issued under the above legislation? If so, please provide approximate numbers of emails and documents released. 8. Please provide an estimate of the number of requests that have been made directly to your cloud providers for your organisation’s data under the above legislation, insofar as this information is known to you. 9. Please detail how many Irish citizens have had emails or data relating to them released to Immigration and Customs Enforcement or the Department of Homeland Security by your organisation’s cloud providers. 10. Does your organisation store any data or communications relating to legal cases (including litigation files, legal advice, or case management records) on a cloud platform subject to U.S. jurisdiction? 11. Please provide details of your policy in relation to restricting the release of legally privileged documents under the above acts. 12. Please provide the relevant sections of any agreements or contracts you have with cloud providers dealing with requests made under Section 702 of the Foreign Intelligence Surveillance Act. If any part of this request is considered unclear or overly broad, I would welcome the opportunity to refine it. If any records are withheld, please specify the statutory exemption relied upon and provide the reasoning for refusal. Revised request I am making this request under the Freedom of Information Act 2014.I request access to records held by your Department/Organisation concerning the storage of data on cloud platforms subject to United States jurisdiction and any related legal, data protection, or risk assessments. When referring to agreements relating to data and records held by your organisation I include your data which is held by other Government organisations on your behalf. I am requesting records held by you referring to, analysing, assessing, or otherwise considering the implications for Irish Government Departments and Offices of the following United States legislation: • Electronic Communications Privacy Act • CLOUD Act (Clarifying Lawful Overseas Use of Data Act 2018) • Foreign Intelligence Surveillance Act and the FISA Amendments Act Specifically, I request access to the following records: 1. Records of any agreements your organisation has for the storage of data or electronic records with cloud platforms subject to U.S. jurisdiction, including records listing or identifying the cloud service providers used (e.g. Microsoft, Amazon, Google). 2. Records of security protocols for the storage or processing of emails your organisation has with cloud email providers subject to U.S. jurisdiction (e.g. Microsoft 365, Gmail). 3. Records of how many emails are stored with providers subject to U.S. jurisdiction (e.g. Microsoft 365, Google, etc.). 4. Records of all Data Protection Impact Assessments (DPIAs), Transfer Impact Assessments (TIAs), or other data protection, privacy, or compliance assessments carried out in relation to cloud providers subject to U.S. jurisdiction. 5. Records of any Board, Management Committee, audit, senior governance, or executive decision records, including minutes, briefing notes, submissions, memoranda, risk assessments, or legal advice (excluding legally privileged material if claimed), concerning risks arising from the above-listed U.S. legislation in the context of cloud storage or processing.6. Records relating to any agreements, memoranda of understanding, contractual clauses, side letters, or other arrangements between the organisation and the United States Government or any U.S. authority concerning notification of data access requests made under the above legislation, including the relevant wording or extracts.7. Records showing the number of requests made for the organisation’s data under the above U.S. legislation, including any reports, logs, summaries, or statistical records reflecting such requests. 8. Records containing detail of or estimates of estimates, statistics, reports, correspondence, or notifications concerning emails or other documents released by cloud providers to U.S. law enforcement authorities under the above legislation. 9. Records containing estimates, statistics, correspondence, or notifications known to the organisation concerning requests made directly to its cloud providers under the above legislation for the organisation’s data. 10. Records of warrants or the number of individual warrants requesting the release of your cloud data whose emails or data were released by cloud providers to U.S. authorities, including U.S. Immigration and Customs Enforcement (ICE) or the U.S. Department of Homeland Security, insofar as such records are given to you by the cloud providers.11. Records of any requests or submissions your organisation has made to the U.S. Department of Homeland Security relating to ICE warrants. 12. Records of agreements or contracts your organisation has for the storage of data or communications relating to legal cases (including litigation files, legal advice, or case management records) on cloud platforms subject to U.S. jurisdiction. 13. Copies of policies, procedures, or guidance documents relating to the treatment, restriction, or protection of legally privileged material in the context of requests made under the above U.S. legislation. 14. Copies of relevant sections of any agreements or contracts with cloud providers that address requests made under Section 702 of the Foreign Intelligence Surveillance Act. 15. Records of any other advice received by your organisation related to: • Electronic Communications Privacy Act • CLOUD Act (Clarifying Lawful Overseas Use of Data Act 2018)