Law enforcement requests your data — what they can access and how

What law enforcement can actually access from your accounts.

Short answer

Every major platform publishes a transparency report showing how many government requests they receive and how often they comply. What those reports do not show is what a standard request actually returns, and how wide the gap is between what users assume is protected and what is routinely handed over. The gap is significant and varies substantially by platform.

What platforms can produce

Each platform holds different data and is subject to different legal frameworks. The useful question is what each specific platform can actually produce under a legal request, since general statements about encryption or privacy rarely survive contact with a subpoena.

Google holds: search history, Gmail content and metadata, location history from Android and Maps, YouTube viewing history, Drive documents, Chrome browsing history if sync is enabled, and device identifiers. A standard US legal request for a Google account can produce most of this depending on the scope of the request. Google publishes the number of requests they receive and their compliance rate. The compliance rate for US requests is high.

Apple holds: iCloud backups of iPhone data including messages if iCloud backup is enabled, iCloud Drive documents, Photos, iCloud email content, App Store purchase history, device identifiers, and Find My location data. Apple does not hold the content of end-to-end encrypted iMessages between Apple devices, but it does hold iCloud backups that contain those messages if the user has iCloud backup enabled. The backup is the gap in end-to-end encryption that most users are unaware of.

Meta holds: Facebook and Instagram message content for non-end-to-end-encrypted conversations, post history, account information, device identifiers, IP address logs, and friend and follower networks. WhatsApp messages are end-to-end encrypted and Meta cannot produce their content. Meta can produce WhatsApp metadata: account registration information, connected phone numbers, and IP addresses associated with the account.

Signal holds account registration date and the date of last connection, and nothing else: no message content, no contact lists, no group memberships, and no call logs. This has been verified in court proceedings where Signal was subpoenaed and produced a two-line response. The architecture is deliberately built to hold nothing worth producing. The comparison of what each service holds under a legal request is the relevant metric, not the privacy policy language.

Proton holds: encrypted email content that they cannot read, account creation metadata, and, in response to valid Swiss legal orders, the IP address associated with account access. In a 2021 case involving an environmental activist, Proton produced the account creation IP address under a Swiss court order. The email content was not produced. The metadata was. The legal framework for cross-border data requests applies to metadata specifically.

How requests actually work

A subpoena is the lowest threshold. It requires no judicial approval in the US for basic subscriber information: name, address, payment information, account creation date, and IP address logs. This is routine and fast.

A court order under the Stored Communications Act requires a judge to find that the information is relevant to an investigation. It can compel non-content records: connection logs, IP addresses, account metadata. It cannot compel content without a higher standard.

A search warrant requires probable cause reviewed by a judge. It can compel content of communications stored on the platform. Email, messages, documents. Platforms challenge overbroad warrants with variable success. Most comply with properly scoped warrants.

Emergency requests bypass normal process when a platform believes there is imminent risk to life. These are submitted directly by law enforcement without judicial process. Platforms have discretion on compliance but most respond quickly to credible emergency requests. The emergency request mechanism has been abused by attackers who impersonate law enforcement. Documented cases of journalist account compromise include fake emergency requests used to obtain account data.

What you can do about it

Use end-to-end encrypted services for the communications that actually matter, while keeping in mind that the encryption protects content but not metadata, and that the platform can usually still produce that metadata under a valid request.

Disable iCloud backup if you use an iPhone and the content of your messages is sensitive. iCloud backup breaks the end-to-end encryption of iMessages by creating an accessible copy of the messages on Apple’s servers. Disable it and back up locally to your computer instead. This changes what Apple can produce under a legal request significantly.

Use Signal for communications where content protection matters. A legal request to Signal returns essentially nothing worth processing, because the architecture leaves nothing on the server side worth producing. Other end-to-end encrypted platforms hold varying amounts of metadata that may be more significant than it appears. The protocol for source communications accounts for both content and metadata exposure.

Build a threat model that accounts for legal process as a realistic vector. Most people’s threat models underweight legal process relative to hacking as a threat, when in practice legal requests are the primary mechanism by which law enforcement accesses account data and they succeed far more often than technical attacks.

Frequently asked questions

Will I be notified if law enforcement requests my data?

Platforms typically notify users of legal requests unless the request includes a non-disclosure order. Non-disclosure orders are common in investigations where notification would compromise the investigation. In practice, you may not know a request was made until after the investigation is complete or the case becomes public.

Does a VPN protect my account data from legal requests?

A VPN masks your IP address from the platforms you connect to, which affects what IP address is logged in their records. It does not affect what account data the platform holds or their obligation to produce it under a valid legal request. The legal request is directed at the platform, not at your network connection. A VPN does not protect account data from legal process..

Can a platform notify me when my account is the target of a legal request?

Some can, some cannot, and many are explicitly prohibited from doing so. Most US legal requests come with a non-disclosure component (a gag order under 18 USC 2705(b)) that legally prevents the platform from notifying the account holder. Platforms publish aggregate statistics on how often they are gagged versus free to notify. Where notification is allowed, platforms like Google, Twitter, and Cloudflare have generally followed through on it, sometimes after a delay. The realistic expectation is that you will not be told about a request involving an active investigation, and that any notification you do receive arrives after the fact.

What is the difference between a subpoena, a court order, and a search warrant for account data?

Each compels a different category of data under a different evidentiary standard. A subpoena (lowest standard) usually obtains basic subscriber information: name, email, IP logs, payment data. A court order under 18 USC 2703(d) obtains additional non-content records, including transactional data and communication logs. A search warrant (highest standard, requires probable cause) is needed for actual content of communications stored on the platform. The category of legal process determines what the platform can and must hand over, and platforms that conflate these in their public reporting often understate the precision of what is happening.


There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.

Similar Posts