Microsoft Corp. v. United States
The landmark cross-border email case that exposed the territorial limits of the original Stored Communications Act and prompted Congress to enact the CLOUD Act.
Executive Summary
Federal agents investigating suspected drug trafficking obtained a Stored Communications Act warrant directing Microsoft to disclose information from a customer email account. Microsoft produced non-content information stored in the United States but refused to produce email content stored at a data center in Dublin, Ireland. The Second Circuit held that the 1986 statute did not authorize the warrant's extraterritorial application and ordered the foreign-stored content protected from disclosure. The Supreme Court granted review, but Congress enacted the CLOUD Act after oral argument. The new law expressly required covered providers to preserve and disclose data within their possession, custody, or control regardless of whether it is stored inside or outside the United States. The government obtained a new warrant, the dispute became moot, and the Supreme Court vacated the Second Circuit judgment.
The case remains essential history. It shows how distributed cloud architecture defeated assumptions embedded in a territorial, server-centered statute and led Congress to replace the disputed rule with a control-based framework.
Key Results at a Glance
Facts and the Dublin Data Center
In December 2013, federal investigators applied in the Southern District of New York for a § 2703 warrant covering an account believed to be used in illegal drug trafficking. A magistrate judge found probable cause and issued the warrant.
Microsoft's system stored account data at different locations. Non-content records responsive to the warrant were stored in the United States. Email content was stored in Dublin based on automated account-location and network-management processes.
Microsoft produced the domestic non-content records but moved to quash the warrant insofar as it demanded communications content stored in Ireland. The dispute concerned statutory reach—not whether probable cause existed.
The Stored Communications Act Framework
The Stored Communications Act, enacted in 1986, governs compelled provider disclosure of stored electronic communications and associated records. Section 2703 establishes different forms of legal process depending on the information sought and applicable circumstances.
| Information Category | Typical SCA Process | Operational Caution |
|---|---|---|
| Basic subscriber information | May be available through subpoena authority specified by statute | Request only authorized fields and verify current statutory text |
| Other non-content records | May require a § 2703(d) order or warrant depending on the request | Constitutional law may demand more than the statutory minimum |
| Stored communications content | Search warrant based on probable cause is the ordinary route | Particularize account, time period, offenses, and content sought |
| Preservation | § 2703(f) request can preserve existing records while process is obtained | Preservation does not itself authorize disclosure |
Procedural History
| Stage | Result |
|---|---|
| Magistrate judge and district court | Required compliance with the warrant |
| Civil contempt order | Entered by stipulation after Microsoft refused full compliance, enabling appellate review |
| Second Circuit panel, 2016 | Reversed, quashed the warrant as to Irish-stored content, and vacated contempt |
| Second Circuit rehearing, 2017 | Rehearing en banc denied by an evenly divided court |
| Supreme Court | Granted certiorari and heard argument in February 2018 |
| Congress and new warrant | CLOUD Act enacted; government obtained replacement process |
| Supreme Court, April 2018 | Vacated the Second Circuit judgment and remanded for dismissal as moot |
The Second Circuit's 2016 Analysis
The panel applied the presumption that federal statutes operate domestically unless Congress clearly indicates extraterritorial reach. It found no clear direction in the pre-CLOUD Act SCA authorizing a § 2703 warrant to reach communications content stored abroad.
The court treated compelled disclosure of the Irish-stored content as an extraterritorial application. Although Microsoft could retrieve the information from the United States, the protected data was stored in Ireland and the statute's relevant privacy interests would be invaded there under the panel's analysis.
Extraterritoriality and Cloud Architecture
Traditional warrants are territorially constrained. Cloud providers, however, can move, shard, replicate, and remotely retrieve data across national borders. The dispute exposed the difficulty of applying location-based legal concepts to data managed through global infrastructure.
The government emphasized that Microsoft would gather and disclose the material in the United States. Microsoft emphasized that the compelled acquisition would reach private communications stored in another sovereign nation. The panel resolved the statutory ambiguity against extraterritorial application.
The Statute's Privacy-Protective Focus
The Second Circuit concluded that the SCA's relevant focus was protecting the privacy of stored communications. It rejected the view that the statute functioned only like a subpoena directed at a domestic company.
The “warrant” label mattered because Congress selected a legal instrument traditionally associated with probable cause, particularity, and territorial limits. The panel found that this choice did not clearly authorize a global production duty.
That reasoning is historically important but cannot be used to override Congress's later express language in § 2713.
Judge Lynch's Concurrence
Judge Lynch agreed that the statute as written did not reach the Irish-stored content. He emphasized, however, that the policy questions were close and that server location could be an unstable or manipulable basis for access rules.
The concurrence urged Congress to modernize the statute and balance law-enforcement needs, user privacy, provider responsibility, and foreign sovereign interests. Congress did so less than two years later through the CLOUD Act.
The Supreme Court and Mootness
The Supreme Court granted certiorari to decide whether a U.S. provider had to disclose communications within its control when the provider stored them abroad. The Court heard oral argument on February 27, 2018.
Before decision, Congress enacted the CLOUD Act. The government obtained a new warrant under the amended law and no longer relied on the original process. Microsoft agreed that no live controversy remained.
Congress's CLOUD Act Response
The Clarifying Lawful Overseas Use of Data Act amended the SCA in March 2018. Its central provision, codified at 18 U.S.C. § 2713, requires covered electronic communication and remote computing service providers to preserve, back up, or disclose responsive information within their possession, custody, or control regardless of whether it is located inside or outside the United States.
The Act also created a framework for executive agreements permitting qualifying foreign governments to make certain direct requests to providers, subject to statutory safeguards and certification. It did not create unlimited cross-border access or eliminate judicial process.
| Before the CLOUD Act Dispute | After the CLOUD Act |
|---|---|
| Statute did not expressly address foreign-stored data | § 2713 expressly covers data regardless of location |
| Second Circuit focused on server location and extraterritoriality | Provider possession, custody, or control is central |
| Foreign evidence often prompted MLAT analysis | Domestic SCA process, MLATs, and qualifying executive-agreement channels may coexist |
| Original Microsoft warrant was quashed by the panel | Government obtained a new warrant under amended law |
Current Operational Rule
For a provider covered by the SCA, foreign storage alone generally does not defeat an otherwise valid obligation when the responsive material is within the provider's possession, custody, or control. Investigators should use the correct statutory process and should not need to identify a particular server before serving process.
Control is not the same as existence. Providers cannot disclose data they do not possess or control, and data may be unavailable because of retention limits, encryption, deletion, account architecture, or another entity's custody. Prompt preservation remains important.
Foreign-Law Conflicts and Comity
The CLOUD Act provides a defined motion-to-quash or modify process in certain circumstances involving a customer who is not a United States person and a material risk that disclosure would violate the law of a qualifying foreign government. Courts consider specified comity factors.
Not every foreign-law objection fits that statutory mechanism. Providers and government counsel may also need to evaluate MLATs, executive agreements, data-protection laws, blocking statutes, diplomatic concerns, provider policies, and other bases for modification.
Practical Guidance for Investigators and Agencies
Cross-Border Provider-Process Checklist
| Question | Why It Matters |
|---|---|
| Which provider entity possesses, controls, or can retrieve the data? | Determines service, jurisdiction, and § 2713 relevance |
| Is the request for content or non-content records? | Determines the required legal process |
| Has a preservation request been sent? | Reduces loss during warrant preparation |
| Is the account and time period particularized? | Supports probable cause and avoids overbreadth |
| Are data known or likely to be stored abroad? | Flags foreign-law and comity issues |
| Is the subscriber a U.S. person? | May affect statutory challenge procedures |
| Would an MLAT or executive-agreement channel be more appropriate? | Ensures lawful and efficient cross-border coordination |
| Can the production be authenticated and traced? | Supports admissibility, discovery, and evidentiary integrity |
Litigation and Discovery Checklist
- Identify the exact SCA provision, warrant, order, subpoena, or preservation authority used.
- Separate communications content from subscriber and transactional information.
- Establish which provider entity had possession, custody, or control.
- Document known storage locations without assuming server location determines current authority.
- Review probable cause, particularity, time limits, account identifiers, and minimization.
- Preserve provider objections, compliance correspondence, certifications, and production logs.
- Analyze any foreign-law conflict, comity motion, MLAT, or executive agreement.
- Verify integrity, completeness, time zones, account attribution, and chain of custody.
- Do not cite the vacated Second Circuit judgment as current controlling law.
- Check the current statutory text, case law, provider guidance, and DOJ resources before reliance.
Frequently Asked Questions
What did Microsoft Corp. v. United States originally hold?
The Second Circuit held that the original SCA did not authorize a § 2703 warrant compelling disclosure of email content stored in Ireland.
Is that holding still controlling?
No. The Supreme Court vacated the judgment after the CLOUD Act and a replacement warrant made the dispute moot.
What does current § 2713 provide?
A covered provider must comply with SCA preservation, backup, and disclosure obligations for information within its possession, custody, or control regardless of whether the information is located inside or outside the United States.
Did the Supreme Court decide who was right?
No. It issued a per curiam mootness decision and did not resolve the merits of the original statutory dispute.
Does the CLOUD Act eliminate warrants?
No. Investigators must still use the process required for the particular data. Stored communications content generally requires a probable-cause warrant.
Does server location never matter?
It no longer creates the categorical limitation adopted by the vacated Microsoft panel. It may still matter to control, foreign-law conflicts, comity, provider operations, and international relations.
Is the CLOUD Act a remote-hacking law?
No. Section 2713 concerns compelled provider preservation and disclosure. Direct government access to a device or server raises separate legal authority and Fourth Amendment questions.
Primary Authorities and Current Law
Historical Second Circuit opinion addressing the original SCA, extraterritoriality, provider control, and email stored in Ireland.
Read the vacated Second Circuit opinion
Supreme Court opinion vacating the Second Circuit judgment and remanding for dismissal as moot after enactment of the CLOUD Act and issuance of a new warrant.
Read the Supreme Court opinion
Current statutory rule requiring covered providers to comply for data within their possession, custody, or control regardless of location.
Read 18 U.S.C. § 2713
Official federal materials addressing the statute, executive agreements, and cross-border evidence.
Review DOJ CLOUD Act resources
Final Assessment
Microsoft Corp. v. United States is a rare case in which the litigation's greatest legal effect came through legislation rather than a final merits ruling. The Second Circuit identified a gap between a 1986 statute and global cloud computing. Congress closed that gap by adopting an express possession-custody-or-control rule for data stored anywhere.
For investigators, the modern task is not to rely on the vacated territorial holding. It is to select the correct legal process, establish probable cause and particularity when content is sought, preserve volatile information, identify the controlling provider, anticipate foreign-law conflicts, and maintain a complete evidentiary record.