Pulse · Documents · United States · United States Congress
Safe Cloud Storage Act
SUMMARY
Safe Cloud Storage Act
This bill limits the civil and criminal liability of vendors that contract with law enforcement agencies to provide digital storage services (e.g., cloud-based storage) for storing, maintaining, and processing child sexual abuse material (CSAM) in investigations of online child sexual exploitation.
Under current law, the National Center for Missing & Exploited Children (NCMEC) receives reports of online child sexual exploitation via its CyberTipline, evaluates and prioritizes the reports, and refers the reports to law enforcement agencies to investigate. Currently, federal law limits the liability of vendors that contract directly with the NCMEC to store and transfer CSAM. However, federal law does not limit the liability of vendors that contract with law enforcement agencies to assist in investigations.
This bill establishes liability protections for vendors that contract with federal, state, and local law enforcement agencies to store, maintain, and process CSAM in investigations of online child sexual exploitation. Specifically, the bill prohibits a civil claim or criminal charge in federal or state court against such a vendor, so long as the vendor has not engaged in intentional misconduct or negligent conduct, acted with malice or reckless disregard, or acted for a purpose unrelated to its contractual duties.
The bill requires vendors to comply with cybersecurity requirements for CSAM that is stored, maintained, or processed. The bill also requires vendors to comply with storage requirements for CSAM that is retained as evidence.
FULL TEXT
[Congressional Bills 119th Congress] [From the U.S. Government Publishing Office] [H.R. 7834 Reported in House (RH)]
Union Calendar No. 703 119th CONGRESS 2d Session H. R. 7834
[Report No. 119-804]
To limit liability for certain entities storing child sexual abuse material for law enforcement agencies, and for other purposes.
IN THE HOUSE OF REPRESENTATIVES
March 5, 2026
Ms. Lee of Florida (for herself, Ms. Dean of Pennsylvania, Mr. Cohen, and Mr. Knott) introduced the following bill; which was referred to the Committee on the Judiciary
September 8, 2026
Additional sponsors: Mr. McGuire and Ms. Hageman
September 8, 2026
Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed [Strike out all after the enacting clause and insert the part printed in italic] [For text of introduced bill, see copy of bill as introduced on March 5, 2026]
A BILL
To limit liability for certain entities storing child sexual abuse material for law enforcement agencies, and for other purposes.
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled,
SECTION 1. SHORT TITLE.
This Act may be cited as the ``Safe Cloud Storage Act''.
SEC. 2. STORAGE OF CHILD PORNOGRAPHY AND CHILD OBSCENITY.
(a) In General.--Title II of the PROTECT Our Children Act of 2008 (34 U.S.C. 21101 et seq.) is amended by inserting after section 201 the following:
``SEC. 202. MODERNIZING LAW ENFORCEMENT'S ABILITY TO STORE CHILD PORNOGRAPHY AND CHILD OBSCENITY AND LIMITED LIABILITY FOR APPROVED VENDORS.
``(a) Definitions.--In this section:
``(1) Approved vendor.--The term `approved vendor' means an organization, corporation, or entity that-- ``(A) offers digital storage services, including remote or cloud-based storage, and analytical and forensic tool processing support; and ``(B) has been contractually retained by a covered agency to support the duties of such agency by-- ``(i) storing digital child pornography or child obscenity;
``(ii) making such child pornography or child obscenity available to the contracting agency, or any law enforcement or prosecutorial agency designated by the contracting agency, upon request; and ``(iii) providing maintenance, technical and analytical assistance, and forensic tool processing support upon request by the contracting agency.
``(2) Child pornography.--The term `child pornography' has the meaning given that term in section 2256(8) of title 18, United States Code.
``(3) Child obscenity.--The term `child obscenity' has the meaning given that term in section 21101(2) of title 34, United
States Code.
``(4) Covered agency.--The term `covered agency' means a United States Federal, State, or local law enforcement or prosecutorial agency.
``(5) Local.--The term `local' means any political subdivision of a State.
``(6) State.--The term `State' means any of the 50 States of the United States, the District of Columbia, the Commonwealth of Puerto Rico, the United States Virgin Islands, Guam, American Samoa, or the Commonwealth of the Northern
Mariana Islands.
``(b) Limited Liability for Approved Vendors.-- ``(1) Limited liability for law enforcement approved vendors.--Except as provided in paragraph (2), a civil claim or criminal charge may not be brought in any Federal or State court against an approved vendor relating to the approved vendor's performance of any contractual obligation or service described in subsection (a)(1).
``(2) Intentional, reckless, or other misconduct.--A civil claim or criminal charge may be brought in any Federal or State court against an approved vendor if the approved vendor-- ``(A) engaged in-- ``(i) intentional misconduct; or ``(ii) negligent conduct; or ``(B) acted, or failed to act-- ``(i) with actual malice;
``(ii) with reckless disregard to a substantial risk of causing injury without legal justification; or ``(iii) for a purpose unrelated to the performance of any responsibility or function described in subsection (a)(1)(B).
``(c) Vendor Cybersecurity Requirements.--With respect to any child pornography or child obscenity stored, maintained, or processed by an approved vendor, such approved vendor shall-- ``(1) secure such child pornography or child obscenity in a manner that is consistent with the most recent version of the Cybersecurity Framework developed by the National Institute of Standards and Technology, or any successor thereto;
``(2) only access the child pornography or child obscenity upon consent of the law enforcement or prosecutorial agency contracting the service and for the purpose of providing maintenance, technical assistance, and forensic tool processing support in the cloud;
``(3) minimize the number of employees that may be able to obtain access to such child pornography or child obscenity and maintain a list of employees who have obtained such access;
``(4) employ end-to-end encryption for data storage and transfer functions, or an equivalent technological standard;
``(5) undergo an independent annual cybersecurity audit to determine whether such child pornography or child obscenity is secured as required by paragraph (1), including by assessing compliance with the National Institute of Standards and Technology Special Publication 800-53, Revision 5 (relating to security and privacy controls for information systems and organizations) or any successor documents or revisions; and ``(6) promptly address all issues identified by an audit described in paragraph (5).
``(d) Evidence Storage.--Any covered agency that stores child pornography and child obscenity pursuant to a contract with an approved vendor shall ensure that such evidence is retained-- ``(1) in compliance with the security policy of the Criminal Justice Information Services Division of the Federal
Bureau of Investigation, or any other similar and appropriate division within the Federal Bureau of Investigation;
``(2) for a period consistent with the evidence retention requirements applicable to the investigating or prosecuting covered agency under the relevant Federal, State, or local law, rule of criminal procedure, or prosecutorial policy; or ``(3) in the absence of such law, rule, or policy, for a period not less than the applicable statute of limitations or the duration of any sentence imposed, including the period of post-conviction review.
``(e) Additional Requirements for Approved Vendors.-- ``(1) Location of data.-- ``(A) In general.--Except as provided in subparagraph (B), each approved vendor shall ensure that child pornography and child obscenity stored pursuant to this section remains in the United States.
``(B) Exception.--Child pornography and child obscenity under this section may be transferred outside the United States only with the express consent of the contracting covered agency if such agency deems the transfer necessary for investigative purposes.
``(2) Notification letter.-- ``(A) In general.--Approved vendors shall file a notification letter with the Criminal Division of the Department of Justice not later than 30 days after entering into a contract described in subsection (a)(1)(B).
``(B) Contents.--The notification letter described in subparagraph (A) shall include the entity name and point of contact information of the approved vendor, the name of the contracting covered agency, the period of performance of the contract, and an acknowledgment by the approved vendor that the approved vendor will notify the Child Exploitation and Obscenity Section of the Criminal Division of the Department of Justice of any changes to the information in the letter.
``(3) Breach of contract.-- ``(A) In general.--If a covered agency fails to make required payment under a contract, breaches any material term of such contract, or otherwise terminates such contract without establishing lawful transfer of the evidence, the approved vendor shall, not later than
30 days after the failure, breach, or termination, notify the Criminal Division of the Department of Justice in the case of a breach by a Federal agency, or the appropriate State attorney general in the case of a breach by a State or local agency.
``(B) Maintenance of evidence.--Upon making a notification under subparagraph (A), the approved vendor shall continue to preserve and maintain the integrity of the evidence until a prompt and lawful transfer of custody occurs to the Criminal Division of the Department of Justice or another Federal, State, or local law enforcement agency with jurisdiction.
``(f) Rule of Construction.--Nothing in this section shall be construed to-- ``(1) limit bona fide use by the contracting covered agency of child pornography or child obscenity being stored by the approved vendor, which includes providing such child pornography or child obscenity to any other party as necessary for an investigation or prosecution;
``(2) limit the obligation of the contracting covered agency to comply with a constitutional or statutory obligation, court order, or request from a victim made pursuant to section
3509(m)(3) of title 18, United States Code; or ``(3) authorize or require the audit, assessment, or compliance verification of a governmental entity or any system administered by a governmental entity.''.
(b) Clerical Amendment.--Section 1(b) of the PROTECT Our Children
Act of 2008 (Public Law 110-401; 122 Stat. 4229) is amended by inserting after the item relating to section 201 the following:
``Sec. 202. Modernizing law enforcement's ability to store child pornography and child obscenity and limited liability for approved vendors.''. Union Calendar No. 703
119th CONGRESS
2d Session
H. R. 7834
[Report No. 119-804]
A BILL
To limit liability for certain entities storing child sexual abuse material for law enforcement agencies, and for other purposes.
September 8, 2026
Reported with an amendment, committed to the Committee of the Whole House on the State of the Union, and ordered to be printed
Машинный черновик — GigaChat-3-Ultra, 17.09.2026. Экспертом ещё не проверен: даты, адреса норм и санкции сверяйте с текстом.
Паспорт акта
- Юрисдикция
- США
- Официальное наименование
- Safe Cloud Storage Act (H.R. 7834)
- Рабочее название
- Safe Cloud Storage Act
- Вид и уровень акта
- законопроект, федеральный закон США
- Дата принятия
- 2026-03-05
- Вступление в силу
- не указана
- Действующая редакция
- версия от 2026-09-08 с поправками комитета
- Статус
- законопроект: принят Палатой представителей и направлен далее; текст приведён как «Reported with an amendment... ordered to be printed»
- Регулятор
- Министерство юстиции США (Criminal Division), ведомства-исполнители на федеральном уровне/уровне штатов/местном уровне
- Связанные акты
- PROTECT Our Children Act of 2008; правила хранения улик CJIS ФБР; NIST Cybersecurity Framework; SP 800-53 Rev. 5
Предмет и цель
- Проблема
- отсутствие ограничения гражданской и уголовной ответственности поставщиков цифровых хранилищ, которые по контракту с правоохранительными органами хранят материалы сексуального насилия над детьми для расследований.
- Цель
- ограничить ответственность таких поставщиков при соблюдении требований безопасности и процедурных условий, обеспечить надлежащее хранение доказательств CSAM.
- Сфера действия
- поставщики цифровых услуг хранения и аналитико-криминалистической поддержки, заключившие контракт с федеральными, региональными или местными правоохранительными органами США для работы с CSAM.
- Исключения
- умышленные нарушения, грубая небрежность, злой умысел, безрассудное пренебрежение существенным риском, действия вне договорных обязанностей; аудит систем госорганов актом не санкционируется и не требуется.
Субъекты
| Роль | Кто именно | Критерии отнесения | Оценка числа адресатов |
|---|---|---|---|
| поставщик | approved vendor — организация, корпорация или иной субъект, предоставляющий услуги цифрового хранения (включая удалённое/облачное) и поддержку аналитических/криминалистических инструментов по контракту с covered agency. | наличие контракта с федеральным/региональным/местным правоохранительным органом на хранение CSAM, обеспечение доступа к данным по запросу, оказание техподдержки и криминалистической обработки по запросу. | — |
- Группы особой защиты
- несовершеннолетние (жертвы сексуальной эксплуатации); косвенно — целостность доказательств для правосудия.
Нормы 11
Каждая строка — одна норма: кто что должен, через что она меняет поведение, во что обходится и чем подкреплена.
-
Поставщик освобождается от гражданских исков и уголовных обвинений за исполнение обязательств по хранению/содержанию/обработке CSAM для правоохранительных органов, если отсутствуют умышленные проступки, небрежность, злой умысел, безрассудство или действия вне договора.
- Механизм воздействия
- распределение риска
- Издержки: канал
- нет прямых издержек
- Событие-триггер
- постоянно (в период исполнения контракта)
- Санкция
- сохранение возможности иска/обвинения при нарушениях из п. (2)
- Отсылка к иным актам
- да; Title 18 § 2256(8); Title 34 § 21101(2)
- Форма исполнения
- смешанная
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- требует проверки
-
Обеспечить защиту хранимых/обслуживаемых/обрабатываемых материалов CSAM в соответствии с актуальной версией Cybersecurity Framework NIST.
- Механизм воздействия
- операционные издержки
- Издержки: канал
- содержательные; административные
- Издержки: характер
- регулярные
- Событие-триггер
- постоянно
- Санкция
- утрата льготы по ограничению ответственности (см. 2(b)(2))
- Отсылка к иным актам
- NIST Cybersecurity Framework
- Форма исполнения
- цифровая
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- требования ГОСТ Р ИСО/МЭК 27001/27002 и приказы ФСТЭК/ФСБ сопоставимы по сути, но отличаются рамками и механизмами признания соответствия
-
Доступ к материалам CSAM только с согласия заказчика-правоохранительного органа и исключительно для обслуживания, технической помощи и криминалистической обработки.
- Механизм воздействия
- операционные издержки
- Издержки: канал
- административные
- Издержки: характер
- по событию
- Событие-триггер
- по обращению/по запросу
- Санкция
- утрата льготы по ограничению ответственности
- Форма исполнения
- цифровая
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- требует проверки
-
Минимизировать число сотрудников с доступом к CSAM и вести их перечень.
- Механизм воздействия
- операционные издержки
- Издержки: канал
- административные
- Издержки: характер
- регулярные
- Событие-триггер
- постоянно
- Санкция
- утрата льготы по ограничению ответственности
- Форма исполнения
- смешанная
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- принципы минимизации доступа есть в режимах гостайны/персданных, прямой аналогии по ведению перечня применительно к CSAM нет
-
Применять сквозное шифрование для хранения и передачи либо эквивалентный технологический стандарт.
- Механизм воздействия
- капитальные; операционные издержки
- Издержки: канал
- капитальные; содержательные
- Издержки: характер
- разовые; регулярные
- Событие-триггер
- до начала деятельности; постоянно
- Санкция
- утрата льготы по ограничению ответственности
- Форма исполнения
- цифровая
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- требования криптографической защиты существуют (СКЗИ), однако обязательность end-to-end зависит от класса системы и режима допуска
-
Ежегодно проходить независимый аудит кибербезопасности по критериям NIST SP 800-53 Rev. 5 (или преемникам) и подтверждать соответствие CF NIST.
- Механизм воздействия
- операционные издержки
- Издержки: канал
- прямые платёжные; административные; содержательные
- Издержки: характер
- регулярные
- Событие-триггер
- ежегодно
- Санкция
- утрата льготы по ограничению ответственности
- Отсылка к иным актам
- NIST SP 800-53 Rev. 5
- Форма исполнения
- смешанная
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- ежегодные аудиты информбезопасности предусмотрены отдельными регуляториками, но единый контур «CF + SP 800-53» отсутствует
-
Незамедлительно устранять все выявленные аудитом недостатки.
- Механизм воздействия
- операционные издержки
- Издержки: канал
- содержательные; административные
- Издержки: характер
- по событию
- Событие-триггер
- по событию (результаты аудита)
- Санкция
- утрата льготы по ограничению ответственности
- Форма исполнения
- смешанная
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- устранение замечаний регулятора предусмотрено общими нормами о защите информации, единых сроков «незамедлительно» нет
-
Обеспечивать хранение CSAM-доказательств согласно политике CJIS ФБР, установленным законом/правилами срокам, а при их отсутствии — не менее срока давности или длительности наказания с посткондиционным периодом.
- Механизм воздействия
- операционные издержки
- Издержки: канал
- административные
- Издержки: характер
- регулярные; по событию
- Событие-триггер
- постоянно; по событию (окончание дела)
- Санкция
- риск недопустимости доказательства; дисциплинарная/процессуальная ответственность ведомств
- Отсылка к иным актам
- политика CJIS ФБР; федеральные/штатные законы и правила уголовного процесса
- Форма исполнения
- смешанная
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- УПК РФ устанавливает правила хранения вещественных доказательств и электронных носителей; детализация уровня CJIS отличается
-
Хранить данные CSAM в США; вывоз за рубеж — только с явного согласия агентства-заказчика для следственных нужд.
- Механизм воздействия
- ограничение модели; барьер входа
- Издержки: канал
- капитальные; операционные
- Издержки: характер
- разовые; регулярные
- Событие-триггер
- до начала деятельности; по событию
- Санкция
- утрата льготы по ограничению ответственности
- Форма исполнения
- цифровая
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- локализация персональных данных существует (ФЗ-152), но специальный запрет локализации CSAM-эвиденса не выделен
-
Направлять уведомление в Criminal Division DOJ не позднее 30 дней после заключения контракта с указанием сторон, сроков и обязательства сообщать об изменениях.
- Механизм воздействия
- административные издержки
- Издержки: канал
- административные
- Издержки: характер
- разовые; по событию
- Событие-триггер
- до начала деятельности; по событию (изменения)
- Санкция
- утрата льготы по ограничению ответственности
- Форма исполнения
- бумажная/цифровая (письмо)
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- уведомительный порядок взаимодействия ИТ-провайдеров с правоохранительными органами фрагментарен; единого уведомления типа этого нет
-
При неоплате, существенном нарушении или расторжении контракта заказчиком — уведомить DOJ (для федеральных контрактов) или генпрокурора штата (для региональных/местных) в течение 30 дней и сохранять целостность доказательств до законной передачи.
- Механизм воздействия
- операционные издержки; распределение риска
- Издержки: канал
- административные
- Издержки: характер
- по событию
- Событие-триггер
- по событию (нарушение/расторжение)
- Санкция
- утрата льготы по ограничению ответственности; возможная гражданская ответственность за утрату/уничтожение эвиденса
- Форма исполнения
- смешанная
- Вступление в силу
- со вступлением закона в силу
- Российский аналог
- обязанности по сохранности изъятого/доступного следствия имущества регулируются УПК РФ и ведомственными актами; специального уведомления Минюста/Генпрокуратуры поставщиком нет
Details
| Country | United States |
| Body | United States Congress |
| Type | law / bill |
| Language | en |
| Document date | 2026-09-08 |
| Size | 11 890 знаков |
| Versions | 1 |
| First seen | 2026-09-17 |
| Last checked | 2026-09-18 02:07 |
| congress | 119 |
| billType | HR |
| number | 7834 |
| policyArea | Crime and Law Enforcement |
| subjects | ['Civil actions and liability', 'Computer security and identity theft', 'Crimes against children', 'Digital media', 'Domestic violence and child abuse', 'Evidence and witnesses', 'Law enforcement... |
| latestAction | 2026-05-21 Held at the desk. |
| textVersion | rh |
Topics
Why this document is in the base
Selection matched on the following, total weight 13.
-
child sexual abuse material
текст
Content regulation
…tal storage services (e.g., cloud-based storage) for storing, maintaining, and processing child sexual abuse material (csam) in investigations of online child sexual exploitation. under current...…
-
csam
текст
Content regulation
…loud-based storage) for storing, maintaining, and processing child sexual abuse material (csam) in investigations of online child sexual exploitation. under current law, the national c…
-
csam
текст
Content regulation
…mits the liability of vendors that contract directly with the ncmec to store and transfer csam. however, federal law does not limit the liability of vendors that contract with law enfo…
-
csam
текст
Content regulation
…t with federal, state, and local law enforcement agencies to store, maintain, and process csam in investigations of online child sexual exploitation. specifically, the bill prohibits a…
-
csam
текст
Content regulation
…ntractual duties. the bill requires vendors to comply with cybersecurity requirements for csam that is stored, maintained, or processed. the bill also requires vendors to comply with s…
-
csam
текст
Content regulation
…ned, or processed. the bill also requires vendors to comply with storage requirements for csam that is retained as evidence. full text [congressional bills 119th congress] [from the u…
-
cybersecurity
текст
Cybersecurity
…r a purpose unrelated to its contractual duties. the bill requires vendors to comply with cybersecurity requirements for csam that is stored, maintained, or processed. the bill also requires ve…
-
cybersecurity
текст
Cybersecurity
…ormance of any responsibility or function described in subsection (a)(1)(b). ``(c) vendor cybersecurity requirements.--with respect to any child pornography or child obscenity stored, maintaine…
Dropped as boilerplate or single passing mentions: privacy
Summary
Закон ограничивает гражданскую и уголовную ответственность поставщиков цифровых хранилищ, которые по контракту с правоохранительными органами хранят материалы сексуального насилия над детьми для расследований. Защита не действует при умышленных нарушениях, грубой небрежности или действиях вне договорных обязанностей. Поставщики обязаны соблюдать требования кибербезопасности NIST (включая шифрование), ежегодный аудит, хранить данные в США (с исключениями) и уведомлять Минюст в течение 30 дней после заключения контракта; доказательства хранятся согласно правилам хранения улик.