Skip to content

Blog

European digital sovereignty, in depth.

Longer-form writing on what sovereignty is, what the EU is doing about it, and how to build systems that stay under European control.

Policy14 June 202610 min read

Digital sovereignty: what it is, why it matters, and what the EU is doing about it

Digital sovereignty is the ability to decide how your data and the systems that process it are used, and to make that decision stick, even against a foreign government or a supplier on another continent. It is not protectionism, and it is not a demand that everything be built at home. It is the difference between renting your critical infrastructure on someone else’s terms and being able to keep running it on your own.

Europe starts from deep dependence. A handful of mostly US firms control roughly two-thirds of the European cloud market, and by one European Parliament estimate the EU imports well over 80% of its digital products, services and infrastructure. That dependence is also legally fragile: almost every transatlantic data transfer ultimately rests on a single adequacy decision, the EU–US Data Privacy Framework, which in turn rests on a US executive order that any president can rewrite.

We have been here before. The European Court of Justice struck down Safe Harbor in 2015 and Privacy Shield in 2020; the framework that replaced them was upheld by the EU General Court in September 2025 and is, once again, on appeal before the Court of Justice. This article sets out what sovereignty actually means, why the dependence is a genuine risk rather than a slogan, and how Europe’s answer has shifted from regulating the dependence to building an alternative.

Read the full article

Three kinds of sovereignty

It helps to separate three ideas that are often blurred together. Data sovereignty is about control and jurisdiction: who can lawfully compel access to information, regardless of where it is stored. It is not the same as data residency, which only asks where the bytes physically sit. Digital, or technological, sovereignty is broader, the capacity to build and operate the technology stack itself, from chips and networks to cloud platforms, software and AI models. Strategic autonomy is the political goal the other two enable: the freedom to act, and to keep acting, without being coerced or cut off through infrastructure you do not control.

The distinction matters because most “sovereign” marketing addresses only residency. A datacentre in Frankfurt satisfies residency, but if the company operating it answers to a parent in another jurisdiction, the same data can be residency-compliant and sovereignty-exposed at once. Sovereignty is about who holds the leverage, not where the disk happens to spin. Keeping the three ideas apart is what lets you tell a genuine guarantee from a reassuring label.

Why the dependence is a real problem

The dependence is structural, not incidental. A small number of mostly American firms, Amazon, Microsoft and Google, hold the majority of the European cloud infrastructure market, while European providers are left with a low double-digit share that has barely moved in years. The same pattern repeats up and down the stack, in operating systems, productivity suites, search, browsers, advanced chips and the foundational AI models that everything else is now being built on.

That would matter less if the legal ground were stable, but it is not. United States law reaches American providers extraterritorially. The CLOUD Act compels a provider to disclose data in its control regardless of where that data is stored, and intelligence authorities such as FISA Section 702 operate without the protections or redress that European law assumes. Because the bridge that currently legitimises transatlantic transfers rests on a revocable executive order rather than a statute, it can be weakened with a signature. In 2025, upheaval at the US privacy oversight board that underpins the framework’s redress mechanism was a sharp reminder of how thin that foundation is.

Dependence becomes a concrete operational risk the moment the supplier’s home government, not yours, can change the rules, raise the price, or order a service withheld. Recent European debate has openly discussed scenarios that were once dismissed as paranoia, from a foreign administration leaning on a provider, to the fear of a remote “kill switch” over critical services. You do not need to believe the worst case to conclude that resting essential functions on infrastructure you cannot govern is a risk worth removing.

There is an economic dimension too. When the core of the digital economy is rented from abroad, the margins, the data network effects and the high-value engineering jobs largely accrue elsewhere, and Europe is left maintaining the dependency rather than capturing the value it creates. Sovereignty, in this framing, is not only about security; it is about whether the continent builds or merely consumes the technologies that now underpin every industry, from banking to healthcare to defence.

US hyperscalers (AWS, Microsoft, Google)70%
European providers15%
Other / regional15%
Approximate share of the European cloud infrastructure market: a few US hyperscalers hold the majority, European providers a stubbornly low double-digit share.

A short history of broken bridges

The legal arrangement that lets personal data flow from the EU to the United States has been built and rebuilt three times, and twice demolished by Europe’s own highest court. Safe Harbor governed transfers from 2000 until the Court of Justice struck it down in 2015. Its replacement, Privacy Shield, lasted from 2016 until the Schrems II judgment invalidated it in 2020, again because US surveillance law gave Europeans no equivalent protection and no meaningful way to seek redress.

The current Data Privacy Framework, adopted in July 2023, was upheld by the EU General Court in September 2025, but that decision is under appeal to the Court of Justice, the same court that has twice ruled against earlier arrangements. The lesson is not that any single framework is doomed, but that anything resting on the goodwill of another jurisdiction’s domestic politics is inherently provisional. An organisation that has built its data flows on the assumption that the bridge will always stand has taken on a risk it neither controls nor can price, and that it may have to unwind under deadline if the court rules again.

Safe Harbor
2000–2015
Struck down
Privacy Shield
2016–2020
Struck down
Data Privacy Framework
2023–
On appeal · C-703/25 P
Three transatlantic data-transfer frameworks. Two were struck down by the Court of Justice; the third is once more under appeal.

The rules Europe has built

Europe’s legislative response has two layers. The first is protective. The GDPR, in force since 2018, restricts moving personal data outside the European Economic Area, and the Schrems II ruling made clear that contractual clauses alone cannot cure exposure to foreign surveillance, a transfer needs supplementary technical measures to be lawful. The second layer pushes control deeper into the stack. The Data Governance Act and the Data Act, most of which applies from 12 September 2025, make data portable between providers and, crucially, require cloud services to take measures against unlawful access by non-EU governments, with the switching fees that entrench lock-in due to disappear entirely by 2027.

Alongside them sits a wave of structural regulation. NIS2 raises the baseline for cybersecurity, governance and incident reporting across thousands of essential and important entities, though by 2026 several member states, the Netherlands among them, were still finishing transposition into national law. The AI Act, in force since August 2024, phases in through 2025 to 2027; in a sign of how contested the pace has become, lawmakers agreed in May 2026 to push its heaviest high-risk obligations back further still. The Digital Markets Act and Digital Services Act, meanwhile, take direct aim at the dominance of a handful of non-EU “gatekeeper” platforms.

Taken together, these rules are not merely consumer protection. They are a deliberate attempt to make European control of data the default condition of doing digital business in the Union, and to give regulators, courts and customers concrete levers when it is not. The effect is cumulative: each instrument narrows the room in which an organisation can treat sovereignty as optional.

  1. 2015
    CJEU strikes down Safe Harbor
  2. 2018
    GDPR applies across the EU
  3. 2020
    Schrems II strikes down Privacy Shield
  4. 2022
    DGA, DMA, DSA and NIS2 adopted
  5. 2023
    EU–US Data Privacy Framework adopted
  6. 2024
    AI Act enters into force
  7. 2025
    Data Act becomes applicable
  8. 2026
    European Technology Sovereignty Package
A decade of EU data and digital-sovereignty milestones, from the fall of Safe Harbor to the 2026 European Technology Sovereignty Package.

From regulating to building

Regulation alone cannot manufacture an alternative, and Europe has begun to admit as much. Two influential 2024 reports, Enrico Letta’s on the future of the single market and Mario Draghi’s on competitiveness, both placed digital dependence at the centre of Europe’s economic problem. Draghi argued for additional investment on the order of hundreds of billions of euros a year, a scale the continent has not attempted in a generation, and warned that without it Europe would remain a taker of other people’s technology. Policy has started, slowly, to follow.

In June 2026 the European Commission unveiled a European Technology Sovereignty Package, pairing a second Chips Act with a Cloud and AI Development Act intended to at least triple the EU’s datacentre capacity over the next five to seven years. Around it sit the AI Continent Action Plan, the €200 billion InvestAI programme and a series of large “AI gigafactories”, and, more concretely, a €180 million sovereign-cloud framework awarded in April 2026 to several European provider groupings and graded against formal, published sovereignty levels rather than marketing claims. The direction of travel, from buying capability abroad to building it at home, is unmistakable even where the budgets remain modest against the scale of the problem.

It is worth being honest that not everything has worked. The EU’s cloud certification scheme had its strongest sovereignty requirements, the ones that would have demanded immunity from non-EU law for the most sensitive workloads, stripped out after objections from some member states and US providers, and has been stuck ever since. Gaia-X, the federated-cloud project once held up as Europe’s answer, is widely judged to have underdelivered. Industrial and infrastructural sovereignty is proving far harder to legislate than data protection, because it has to be built, funded and bought, not merely required.

The scale of the bet

The figures give a sense of both the ambition and the gap. The original Chips Act set out to mobilise more than €43 billion in public and private investment and to double Europe’s share of global semiconductor production to a fifth by 2030, a target it is not currently on course to meet. InvestAI, launched in early 2025, aims to mobilise €200 billion for artificial intelligence, including a dedicated €20 billion fund for the “gigafactories” that would train large models on European soil. The 2026 Cloud and AI Development Act sets a goal of at least tripling the Union’s datacentre capacity within five to seven years.

Set against the Draghi report’s estimate that closing Europe’s competitiveness gap requires hundreds of billions of euros in additional investment every single year, even these sums are a down payment rather than a settlement. But the significance is directional. For the first time the European response to digital dependence is being counted in fabs, datacentres and compute, not only in articles and recitals. Sovereignty has acquired a capital budget, and with it a constituency that wants to see the money turn into capacity.

Sovereignty is not isolation

It is worth heading off the obvious objection. Sovereignty in this sense is not autarky, and it is not a boycott of American technology. The aim is not to cut Europe off but to remove single points of foreign control over things that matter, so that a change of weather in another capital cannot disrupt a hospital, a bank or a government service. Open standards, interoperability, open-source software and the freedom to switch providers are part of the same agenda; they are what keep sovereignty from collapsing into a different kind of lock-in.

Framed that way, sovereignty is less a political slogan than a risk-management discipline. It asks a familiar question, the same one any board asks about a critical supplier, and applies it to the digital foundations most organisations have stopped thinking of as a choice at all.

What it means for you

For an organisation, the politics resolve into a simpler question. European control of data is becoming both a legal expectation and a commercial one, written into procurement rules, sectoral guidance and the due-diligence questionnaires that customers increasingly send before they sign. The sensible response is not to wait for the next court ruling, but to ask whether your own stack would survive one.

That pressure is already arriving through ordinary commercial channels. Public bodies now score sovereignty in their tenders, regulated sectors fold it into supervision, and private buyers ask for data-flow and sub-processor detail as a condition of the contract. An answer that amounts to “our provider assures us it is fine” is becoming harder to give with a straight face. The organisations that will find this transition easy are the ones that treated it as an architecture question early, rather than a compliance scramble under deadline later.

That turns out to be a question of engineering as much as policy: where your data physically flows, which companies touch it along the way, and who could be compelled to hand it over or to surrender the keys. It is the subject of our companion piece, which follows a single request through the full stack, from DNS to the AI model, and shows exactly where sovereignty is won or lost.

Sources

  1. 1.Regulation (EU) 2016/679 (GDPR), EUR-Lex
  2. 2.Judgment C-311/18, Schrems II, Court of Justice (EUR-Lex)
  3. 3.Implementing Decision (EU) 2023/1795, EU–US Data Privacy Framework adequacy decision (EUR-Lex)
  4. 4.EU–US data transfers, European Commission
  5. 5.Judgment T-553/23, Latombe v Commission, General Court, 3 September 2025 (EUR-Lex)
  6. 6.Appeal C-703/25 P, Latombe v Commission, Court of Justice (EUR-Lex)
  7. 7.Regulation (EU) 2022/868 (Data Governance Act), EUR-Lex
  8. 8.Regulation (EU) 2023/2854 (Data Act), EUR-Lex
  9. 9.Directive (EU) 2022/2555 (NIS2), EUR-Lex
  10. 10.Regulation (EU) 2024/1689 (AI Act), EUR-Lex
  11. 11.Digital Omnibus: simpler digital rules, European Commission (19 November 2025)
  12. 12.Regulation (EU) 2022/1925 (Digital Markets Act), EUR-Lex
  13. 13.Regulation (EU) 2022/2065 (Digital Services Act), EUR-Lex
  14. 14.Strengthening Europe’s tech sovereignty, European Commission (3 June 2026)
  15. 15.Cloud and AI Development Act, European Commission
  16. 16.InvestAI: mobilising €200 billion for AI, European Commission (11 February 2025)
  17. 17.Commission advances cloud sovereignty through strategic procurement (17 April 2026)
  18. 18.EUCS cloud services certification scheme, ENISA
  19. 19.The Draghi report on EU competitiveness, European Commission (September 2024)
  20. 20.Letta report, “Much more than a market”, European Research Area (April 2024)
  21. 21.The European Chips Act, European Commission
  22. 22.European cloud providers’ market share holds steady at 15%, Synergy Research Group
Engineering14 June 202612 min read

Sovereignty lives in the whole data flow: infrastructure, CDN, DNS and keys

Data sovereignty is not about where your bytes physically sit. It is about who can lawfully compel access to them. Those are different questions, and confusing them is the most common mistake in “sovereign” architecture.

Jurisdiction follows the operator, not the server. A datacentre in Frankfurt run by a US-owned company is still reachable under the US CLOUD Act, which compels disclosure of data in a provider’s “possession, custody, or control” regardless of where it is stored. A legal opinion commissioned by the German interior ministry in late 2025 reached the same conclusion: physical location is irrelevant when the provider answers to a US parent. Asked under oath in June 2025 whether French citizens’ data was safe from US authorities, Microsoft France replied, “No, I cannot guarantee that.”

So sovereignty cannot be bought as a checkbox or a “region”. It is a property of the entire path a request and its data travel, from infrastructure and network to storage, keys and the model, every hop where someone could hold the plaintext or compel the keys. And it is brittle: a single foreign-jurisdiction dependency anywhere in the chain can undo all the rest. Reaching it means mapping the full data flow and interrogating each layer in turn. This article walks that path from the first DNS lookup to the last model call.

Read the full article

Residency is not sovereignty

The starting point is a distinction that most procurement conversations get wrong. Data residency asks where data is stored; data sovereignty asks who can lawfully reach it. The two come apart precisely because jurisdiction attaches to the operator, not to the rack. The US CLOUD Act, codified at 18 U.S.C. § 2713, requires a provider subject to US jurisdiction to disclose data in its “possession, custody, or control,” in the statute’s words, “regardless of whether” it is stored inside or outside the United States. Control follows the corporate chain, so a European subsidiary that a US parent can instruct is treated as within reach even if the bytes never leave Frankfurt.

This is not a theoretical reading. A legal opinion commissioned by the German interior ministry and surfaced in late 2025 concluded that the physical location of data is legally irrelevant when the provider is subject to US jurisdiction. Europe’s own data-protection regulators, the EDPB and EDPS, had already advised that under GDPR Article 48 a foreign authority’s order is not, by itself, a lawful basis to transfer data out of the EU. And when Microsoft’s French arm was asked under oath before the French Senate in June 2025 whether it could guarantee that French data would never be handed to US authorities, its answer was simply that it could not.

This is why the wave of “EU sovereign cloud” offerings deserves a careful read rather than a reflexive yes. The strongest of them add EU-resident staff, local operations and customer-held keys, real improvements that reduce day-to-day exposure. But where the operating company remains a wholly-owned subsidiary of a US parent, the control chain that the CLOUD Act follows still terminates in the United States, and the strongest in-product mitigations come at a cost: a provider that genuinely cannot read your data also cannot index it, search it, or run many of its own features over it. The honest test is not the brochure but the architecture.

None of this makes such offerings worthless; for many workloads an EU-staffed, EU-operated region is a real improvement over an ordinary US-region deployment. But it should be read as risk reduction, not risk removal. The only configuration that takes the jurisdictional exposure off the table entirely is one in which no company subject to a foreign order sits anywhere in the control path, and in which the keys are held by you. Everything that follows is about finding, hop by hop, where that condition quietly breaks.

Follow the request: it starts at DNS

Trace a single request and the exposures appear in order. The very first step is name resolution, and it decides who even learns the request is happening. Two different parties matter here. The registry and registrar that hold the domain sit under a jurisdiction: .eu is operated by a Belgian non-profit appointed under EU law, while .com is administered by a US company. Separately, the resolver that answers the lookup can log every name a user asks for. Encrypted DNS, whether DoH or DoT, hides those queries from the network in between, but not from the operator of the resolver itself, so pointing your users at a large US public resolver simply relocates the observation to a US company.

The sovereign alternative is now concrete rather than aspirational. DNS4EU, a publicly-backed European resolver service, went live in 2025, operating inside EU borders with encrypted transport and filtering options; the non-profit Quad9 made a similar move years earlier by relocating to Switzerland. The point is not that DNS is the biggest risk, it rarely carries content, but that it is the first place control can quietly leave Europe, and the easiest to fix.

The CDN sees the plaintext

The next hop is usually a content-delivery network, and it is the one most people underestimate. A CDN is a reverse proxy: to cache and accelerate, it must terminate TLS at the edge, which means it decrypts every request, the bodies, the API payloads, the session tokens and cookies, before it forwards anything to your origin. Put a US-incorporated CDN such as Cloudflare, Akamai or Fastly in front of European data and you have placed the plaintext, and by default the TLS private key, in the hands of a US-jurisdiction operator. Residency settings do not change that; the company answering a legal order is the same company.

The mitigations are real but partial. Keyless SSL keeps the private key on hardware you control; regional or in-country processing confines where TLS is terminated and logs are kept. They narrow the exposure without changing the incorporation of the operator, which is the thing a court order actually reaches. European and EEA alternatives exist, among them Bunny.net, Gcore, CDN77 and OVHcloud, and for the most sensitive paths you terminate TLS on infrastructure you operate yourself. The diagram below contrasts the two routes a request can take through the same set of layers.

Convenient default — reachable under the US CLOUD ActYouDNS.com · US resolverCDN · TLSplaintext at edgeCloudprovider holds keysAI modelUS APISovereign path — no compellable US partyYouDNS.eu · DNS4EUCDN · TLSEU CDN / self-hostedCloudyou hold the keysAI modelEU / local
The same request through two stacks. In the convenient default (top), DNS, CDN, cloud and model each sit with a US-jurisdiction operator and fall within CLOUD Act reach. In the sovereign path (bottom), every hop is EU-operated and you hold the keys, so there is no party that can be compelled.

It comes down to the keys

When data comes to rest, the decisive question is who holds the keys, because encryption is only as sovereign as its key custody. With “bring your own key” (BYOK) you nominally own the key, but the provider’s key-management system still performs the decryption inside its boundary, so a provider compelled by a court can in principle use it. With “hold your own key” (HYOK) the keys never leave your environment; the provider only ever handles ciphertext and cannot satisfy an order it is technically incapable of executing. That difference, where the cryptographic operation actually happens, is the whole game.

Encryption has three states, and each needs its own answer. Data in transit is protected by TLS; data at rest by disk and key-management encryption; data in use, the hardest, by confidential computing, which runs the computation inside an attested hardware enclave (a Trusted Execution Environment) sealed off from the host operating system, the hypervisor and even the cloud administrator. Europe’s regulators reached the same conclusion from the legal side: in their post-Schrems II guidance they rank strong encryption under the data exporter’s sole control above any contractual or organisational promise, precisely because a contract cannot stop a lawful order while mathematics can.

BYOKProvider can decrypt

Bring your own key — you own the key, but the provider’s system performs the decryption, so a provider under legal order can still use it.

HYOKProvider sees only ciphertext

Hold your own key — the keys never leave your environment, so the provider cannot comply with an order it is technically unable to satisfy.

In transit
TLS
At rest
Disk / KMS encryption
In use
Confidential computing (TEE)
Key custody decides who can be compelled. Under BYOK the provider can still decrypt; under HYOK it only ever sees ciphertext. The three encryption states each need their own control.

Identity, certificates and the edge

Two layers near the edge are easy to forget. The first is the certificate authority and the emerging European identity rules: the updated eIDAS regulation introduces qualified website authentication certificates, which attest who is behind a site. They add identity, not confidentiality, so they supplement rather than replace ordinary TLS, but they are part of the same effort to keep the trust anchors of the web within a European legal frame. The second is everything that terminates or inspects traffic on your behalf, web application firewalls, bot management, API gateways. Each is another place where plaintext is seen, and each deserves the same jurisdictional question as the CDN.

Who can log in matters too

Encryption answers who can read the data; operational sovereignty answers who can touch the system. A provider’s support and site-reliability engineers usually hold privileged access in order to keep services running, and that access is itself reachable by whatever legal order binds their employer. This is why the more serious sovereign designs insist that operations be performed only by EU-resident, EU-employed staff, that privileged actions be logged and approved by the customer, and that no administrator outside Europe can quietly assume control of a running system. The question to ask is not only where the data lives, but who, sitting where and employed by whom, can obtain a shell on the machine that processes it.

The same logic runs through the everyday tooling: bastion hosts, secrets managers, CI/CD runners and remote-support agents. Each is a door, and a door is only as sovereign as the person who can be compelled to open it. Mapping those doors, and closing the ones that lead outside Europe, is as much a part of sovereignty as encrypting the disk behind them.

The dependencies you forget

Most sovereignty leaks are not dramatic; they are mundane third-party includes that nobody reviews. A German court awarded damages in 2022 simply for loading Google Fonts, because doing so sent the visitor’s IP address to a US server when the fonts could be self-hosted. European data-protection authorities, starting with Austria, reached the same verdict about Google Analytics: configuring it differently did not cure the underlying transfer. The same exposure hides in tag managers, embedded maps, CAPTCHAs, A/B-testing scripts, error and performance telemetry, package and container registries, transactional email providers, and the logs and backups quietly shipped to a US SaaS for safekeeping.

The newest and fastest-growing version of this is the AI layer. Every prompt, document or code snippet sent to a US-operated model API is an egress of exactly the kind the rest of this article is about, often carrying the most sensitive content an organisation has, and frequently added to a product in an afternoon without a data-flow review. Sovereignty here means inference that runs on EU-hosted infrastructure or entirely locally, on open-weight models you can run yourself, so that neither the data going in nor the model weights themselves sit under foreign control. It is the same principle as the CDN and the keys, applied to the layer that is currently growing fastest.

The supply chain underneath belongs in the same picture. The base images, language runtimes, package registries and build pipelines that assemble your software are mostly hosted on US infrastructure, and a dependency pulled in at build time is a trust relationship every bit as real as one made at run time. Mirroring critical artefacts inside the EU, pinning and verifying them, and keeping the build itself on European infrastructure are the unglamorous half of sovereignty, the half that rarely makes it onto a slide but quietly decides whether the finished system is as European as its hosting region claims.

How to reach it

The method is unglamorous and reliable: draw the real data-flow diagram, end to end, and refuse to skip a hop. For every step, the registrar, the resolver, the CDN, the load balancer, the compute, the storage, the key manager, the logging pipeline, the analytics, the email, the backups and the model, ask three questions. Who operates it? Under whose law does that operator fall? And who, at that hop, can read the plaintext or compel the keys? Wherever the answer points outside Europe, replace the component with an EU-operated one or bring it in-house, and make sure you, not the provider, hold the keys.

Two principles keep the exercise honest. Sovereignty is defence in depth, so a single overlooked dependency, one analytics tag, one US-hosted log sink, can quietly undo everything upstream of it; the chain is only as strong as its weakest link. And sovereignty is a property you design in, not a certificate you buy at the end. That is how we build: on our own cloud in the Netherlands and Germany, or entirely on your infrastructure, with European and local models, and with no US-jurisdiction provider anywhere in the path that could be compelled to hand over your data or your keys.

Sources

  1. 1.18 U.S.C. § 2713 (CLOUD Act disclosure obligation), Legal Information Institute, Cornell Law School
  2. 2.CLOUD Act, Public Law 115-141, Division V (govinfo.gov)
  3. 3.EDPB–EDPS Joint Response on the US CLOUD Act (10 July 2019)
  4. 4.EDPB Recommendations 01/2020 on measures that supplement transfer tools
  5. 5.Judgment C-311/18, Schrems II, Court of Justice (EUR-Lex)
  6. 6.Audition de Microsoft, commission d’enquête, Sénat français (10 June 2025)
  7. 7.Legal opinion on US authorities’ access to cloud data (Universität zu Köln / BMI), via FragDenStaat
  8. 8.AWS launches the AWS European Sovereign Cloud, Amazon (January 2026)
  9. 9.DNS4EU, the European public DNS resolver
  10. 10.EURid, the .eu registry
  11. 11.Regulation (EU) 2024/1183 (eIDAS 2.0 / European Digital Identity), EUR-Lex
  12. 12.Confidential Computing Consortium: data in use and Trusted Execution Environments
  13. 13.Austrian DSB: EU–US transfers via Google Analytics unlawful (noyb)
  14. 14.LG München I, 3 O 17493/20, 20 January 2022 (Google Fonts), full text on rewis.io
  15. 15.Reforming Intelligence and Securing America Act (FISA §702), Public Law 118-49 (govinfo.gov)