• Skip to main content

New Hdr Right

Enjuris
Finding answers after your accident
Contributor loginSearch
Get help Call Now

Nav Menu

  • Find a Lawyer
  • Accident Resources
        • Personal Injury Law
          • You've been hurt. Now what?
          • Do I have a claim?
          • Finding the best attorney to represent you
          • Dealing with insurance
          • Laws by state
          • View all
        • Accident Types
          • Car accident
          • Truck accident
          • Workplace injury
          • Wrongful death
          • View all
        • Workers' Comp
          • Common work injuries
          • Finding the best workers’ comp lawyers
          • How workers’ comp benefits work
          • Personal injury vs. workers’ compensation
          • View all
        • Injury Guides
          • Spinal cord / column
          • Brain Injury
          • Occupational injuries
          • Whiplash
          • View all
        • More
          • Blog
          • Questions & answers
          • Tell your story
          • Forms and worksheets
          • Videos
          • For students
          • Our Safety Allies
          • About us
          • Legal dictionary
  • Attorney Marketing
    • VOICES program
    • Contributor plan
    • Partner plan
    • Social media marketing
    • All plans
    • Enjuris badges
Accident Help (Home) » Personal Injury Law » Your Data is on Their Servers. Who Gets to See It?

Your Data is on Their Servers. Who Gets to See It?

Evidence in the cloud

How subpoenas, warrants, and privacy laws decide who can reach digital records

Not so long ago, any evidence gathered in a typical legal dispute would sit in a filing cabinet, desk drawer, or even a shoebox in a closet. If the government or an opposing party wanted it, they’d come to your office and request access. Today, the most revealing records of our lives—emails, text messages, photographs, location histories, search queries, financial transactions, private messages and even wearable device data such as the Oura ring—exist on servers owned by huge corporations such as Google, Apple, Meta, Microsoft, and Amazon. These records are housed in data centers that might be hundreds or thousands of miles away, but they’re accessible at the touch of a button or a few keystrokes. 

This raises a deceptively simple question: When your personal information is held by a company instead of in your hands, who gets to decide whether the government or a litigant may see it? 

The answer is not simple. It involves the Constitution, decades-old statutes, and privacy laws that are still being amended to catch up to the technology.

What is the “Third-party Doctrine”?

The Third-party Doctrine is a legal rule in the U.S. that an individual forfeits their Fourth Amendment expectation of privacy for any information they voluntarily share with a third party, such as a bank, phone company, or internet provider. 

But let’s back up a bit… what are our Fourth Amendment rights? The Fourth Amendment of the U.S. Constitution protects citizens against unreasonable search and seizure by the government. It guarantees a right to privacy in your person, home, papers and effects. If the government wants to obtain evidence from you, it must obtain a warrant based on probable cause in order to conduct a search or make an arrest.

The third-party doctrine, however, states that an individual forfeits their rights to this type of privacy, and the protection against a warrantless search, if they’ve voluntarily shared the sought-after information with a third party.

Legal precedent for the third-party doctrine

There are two cases that set precedent for the third-party doctrine. 

In U.S. v. Miller, 425 U.S. 435 (1976), federal investigators subpoenaed bank records from a defendant’s bank without a warrant. The records were maintained under the Bank Secrecy Act of 1970. The subpoena included microfilms of checks and deposit slips. 

The Supreme Court ruled that bank customers do not have a reasonable expectation of privacy for their financial records. The records are business documents that belong to the bank—they are not considered the defendant’s private papers. Therefore, the government does not need a warrant to obtain them. 

In another case, Smith v. Maryland, 442 U.S. 735 (1979), police suspected the defendant of having robbed a woman and making threatening phone calls. They requested the phone company to install a “pen register” at its central offices to record phone numbers dialed from the defendant’s phone.

The Supreme Court ruled that the use of a pen register did not constitute a search under the Fourth Amendment. Since the numbers dialed by individuals are routinely shared with telephone companies in order to complete calls, a person has no legitimate expectation of privacy in the numbers they dial. 

In other words, the logic behind these rulings was that you assume the risk that the third party could share your information. Under this view, a search warrant is unnecessary because a record is no longer private (in the constitutional sense) once it’s been turned over to the third party. 

These two precedents formed the basis for the third-party doctrine. However, the principle is continually being challenged because we’re now in the digital era. Far more information is accessible through internet service providers, tech companies, and financial institutions. They are being asked to hand over individuals’ digital footprints—but does the government need a warrant? 

When we apply this literally in the modern era, the doctrine can be unsettling because of the sheer amount of information held by these types of companies. Almost everything we do today passes through a third party. This could include email on Gmail’s servers, location pings from your phone to a wireless carrier, documents in your cloud drive… all of this is, technically, information shared with a company. Based on the conclusion of the third-party doctrine, this would mean the vast majority of our digital lives (which is close to our whole lives) is outside the Fourth Amendment protection against unreasonable searches.

Where does case law stand now on the third-party doctrine?

The law evolves over time. Technology, society, and other factors change, and the law has to change with them. The Supreme Court began to narrow the third-party doctrine in 2018. 

Carpenter v. United States, 585 U.S. 296, 312 (2018), held that police must obtain a warrant to access long-term Cell-Site Location Information (CSLI). The Court reasoned that cell phone location logs track a user’s movements, which means the third-party doctrine is inapplicable because carrying a phone is an indispensable part of modern life. The Court emphasized that today’s technology allows people to track people’s movements retroactively, which was previously impossible. Records that show a phone’s “pings” to a location tower create a detailed map of the person’s movements, which is different from a list of dialed phone numbers. Sharing this information with a wireless carrier doesn’t strip away its constitutional protection. 

One of the biggest issues in Carpenter relates to a geofence warrant. This type of warrant can compel a company (like Google, for example) to identify each device present in a defined area during a specific window of time. Instead of starting with a single suspect, the police would start with a location and work backward. This sweeps in any person with a phone who happened to be nearby. 

But then, on June 29, 2026, the Supreme Court further clarified this question in Chatrie v. United States. The Chatrie case involved a geofence warrant in which police asked Google to provide data for all devices within a specific area during a robbery. The government argued that the doctrine applied because the consumer opts in to Google “Location History” tracking. The Supreme Court said that Location History data is an “automatic price of conventional cell-phone usage” and that users reasonably view it as their own, and not shared information. 

Ultimately, the court in Chatrie held that obtaining a person’s location data through a geofence warrant is a “search” under the Fourth Amendment. Justice Kagan described location data as resembling a personal journal of a user’s movements, and that these deserve protection like emails, photographs or documents, even when held by a third-party company, and even when the data covers only a limited period. 

The ruling doesn’t ban geofence warrants outright, but it requires that they satisfy the Fourth Amendment, which means law enforcement must generally show probable cause. The practical effect is that the simple fact your data sits on a company’s server no longer means the government may sweep it up freely. 

The Chatrie case was remanded to the U.S. Court of Appeals for the Fourth Circuit to determine the constitutionality of each step of the geofence search and evaluate if any legal exceptions (like the “good faith” exception) might still allow the evidence to be admitted. 

The practical effect of the Chatrie ruling is that the simple fact that your data exists on a company’s server no longer means the government can “sweep it up” freely.

The Stored Communications Act

The Stored Communications Act (SCA) was established in 1986 as part of the broader Electronic Communications Privacy Act. There are parts of the act that are a little antiquated (it was written when email was brand-new), but it remains the central rulebook for electronic communications. 

The SCA serves two crucial purposes:

  • It generally prohibits a provider from voluntarily handing over the content of your communications. In other words, the communications company (like Apple or Gmail) cannot provide the actual text of your emails or messages to the government or a private party, except under limited exceptions.
  • It sets forth the legal process the government must use to compel different types of data. The level of process rises depending on the sensitivity of the information.
  • Subpoena
    Lowest bar, can be used for basic subscriber information like your name, address, and how you pay for services
  • Court order
    Required for transactional records, like activity logs
  • Warrant
    Based on probable cause and signed by a judge, which is required for the content of communications

Subpoenas in civil lawsuits

People tend to associate a demand for data with a criminal investigation, but there are lots of reasons why data could be sought in a personal injury or other civil lawsuit. A couple of examples include divorce cases or contract disputes. You might need a “paper trail” to prove that someone agreed to something or failed to do something. Often, this exists only in cloud evidence. 

The SCA creates an important nuance in these types of situations. The law bars a provider from disclosing content to a private party, so you cannot subpoena Google or Meta directly to force them to hand over someone’s emails or private messages in a civil case. Courts typically quash these types of subpoenas. 

But, the data can be demanded from the person who controls the account. The litigant may subpoena an individual, who is then obligated to log in, retrieve their own messages, and produce them to the court or opposing counsel. The provider is never involved. 

This is why the fight in civil litigation is usually over what the party must turn over from their own accounts, not over what data can be obtained from the tech company.

Would you be told if someone asks a company for your data?

You’d like to believe that if someone requests your data from a tech company, you’d receive some type of notice. But you might not, actually. When the government obtains a warrant or order, it’s usually alongside a gag order (also called a non-disclosure order). This legally prohibits the provider from notifying you, on the theory that warning a target could let them destroy evidence or flee. 

Some tech providers have pushed back on indefinite gag orders and now publish a transparency report, which discloses how many government demands they receive. Some have a policy that they must notify a user as soon as there is no longer a legal bar to doing so. But there is no universal guarantee of notice—it’s entirely possible that a company could receive a demand for your account, comply, and be silent on the issue indefinitely.

The CLOUD Act

Cloud storage does not have national borders. The email in your account might physically sit on a server in Ireland or Singapore—or anywhere. This creates a legal question: Can a U.S. warrant reach data stored overseas? 

The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a 2018 U.S. federal law that empowers the government to compel a U.S.-based tech company to produce electronic data requested under a warrant or subpoena, regardless of whether the data is stored in the U.S. or overseas. In other words, the Act clarifies that a U.S. provider must produce data in its “possession, custody, or control” in response to a valid U.S. legal process, regardless of where the data is physically stored. 

The law also creates a framework under which the U.S. and other nations may have agreements allowing foreign governments to seek data from U.S. providers under certain terms. The practical result is that you can store your information on an overseas server, but this does not protect it from the reach of a U.S. court.

Are there privacy laws for the consumer’s protection?

Although procedural law focuses on how the government and litigants can obtain data, there are other considerations for how data is limited. Europe has a General Data Protection Regulation (GDPR) that restricts transferring data outside the EU, and can expose companies to penalties for disclosures under U.S. discovery rules. This can put a tech company in a bind, and courts weigh these concerns on a case-by-case basis. 

Within the U.S., there is a growing patchwork of state privacy laws (with California’s being the most robust) that give consumers rights to access and delete data, and impose obligations on businesses. 

These laws usually carve out exceptions for complying with legal process, so they rarely block a valid subpoena. However, they do shape how companies handle and retain data in the first place. This, in turn, affects what evidence even exists for the process of discovery. 

In general, the constitutional protection for cloud data is growing, not shrinking. Based on Carpenter and Chatrie, we can interpret signals that the courts will treat sensitive digital records as private, even in the hands of a large tech company. The other thing to remember is that the type of data matters—the content has the strongest protection, while basic account details have the least. If it’s a civil dispute, expect the demand to be to you, not to the provider (but don’t assume that you’ll receive notice if another party does seek to obtain your data from the tech company). 

If you ever receive a subpoena, a preservation demand, or notice that your accounts are implicated in an investigation or lawsuit, the most important step is to talk to a qualified attorney promptly. The rules in this area are unsettled and changing fast, and the right move depends heavily on the specific facts of your situation.

Downloads:
Free personal injury guides for download to print or save. View all downloads.

Tell your story:
Tell your story - What would you want others to know? Tell us what happened in your accident, and how life has changed for you.

Find an attorney:
Search our directory for personal injury law firms.
See our guide Choosing a personal injury attorney.

Footer Form

Need an attorney? Our Enjuris Partners are ready to help FIND OUT IF YOU HAVE A CASE
Start here

© 2026 Enjuris. All rights reserved.

Reader survey

X/Twitter Facebook LinkedIn YouTube Blog feed Instagram TikTok Reddit
Learn about

Car accident attorneys
Defective product attorneys
Personal injury attorneys
Medical malpractice attorneys
Wrongful death attorneys
Workers compensation attorneys
Birth injury attorneys

Personal injury lawyers: Partner with us Lawyer online marketing

System overview
Video
Powered by

SEO Advantage

3690 West Gandy Blvd., Suite 444
Tampa, FL 33611
Attorney SEO services


Enjuris is a platform dedicated to helping people who are dealing with life-altering accidents and injuries. We support students, families, caregivers and communities with resources, personal stories and a national directory of partner attorneys.

Copyright © 2026 Enjuris.com. All rights reserved. The accuracy, completeness, or currency of information on this site is not guaranteed. The information provided is not legal advice, does not constitute a lawyer referral service, and no attorney-client relationship is or will be formed by use of this site. For state-specific information, particularly regarding attorney advertising, refer to the Terms of Use. Your use of this website constitutes acceptance of the Terms of Use and Privacy Policy.

Press Enter to Search