S 3023 United States Senate · 119th Congress

Safe Cloud Storage Act

This bill creates a legal framework for cloud storage providers to securely store and share digital evidence of child sexual abuse material (CSAM) used in law enforcement investigations. It designates "approved vendors" (cloud companies contracted by U.S. law enforcement) and grants them limited civil/criminal liability protection when following strict cybersecurity protocols, such as using NIST standards, end-to-end encryption, and annual audits. The bill requires all CSAM evidence stored via approved vendors to remain within the U.S., mandates detailed notification procedures to the Department of Justice, and sets requirements for evidence retention and transfer. It directly affects cloud storage companies working with law enforcement agencies and ensures their services meet rigorous security and privacy standards during investigations.
Bill status passed 3 of 5 stages cleared
Introduction
Oct 2025
Committee Review
Feb 2026
Senate Passage
May 2026
House Passage
President
Introduced Oct 21, 2025 Last action May 21, 2026
Maddy AI version diff · 1 comparison

What changed between versions

Introduced in Senate Engrossed in Senate · 8 edits · May 20, 2026
MODERATE
The Engrossed version of S 3023 (Safe Cloud Storage Act) significantly expands scope by adding 'intimate visual depictions of minors' (including digital forgeries/deepfakes) alongside child pornography and child obscenity as covered material. It also relaxes the data-location requirement to allow overseas transfer with agency consent, makes it easier to sue vendors by clarifying that negligence alone is sufficient to pierce liability protection, and adds a rule of construction preserving agencies' ability to share evidence and comply with victim requests.
Scope change
The bill's scope expands in three ways: (1) it now covers intimate visual depictions of minors including digital forgeries, not just child pornography and child obscenity; (2) 'covered agency' explicitly includes local agencies in addition to Federal and State ones; and (3) the data-location requirement is no longer absolute, permitting overseas transfer with agency consent for investigative needs.
SCOPE

Intimate visual depictions of minors (including digital forgeries) are now covered material under the cloud storage framework, defined by reference to 47 U.S.C. 223(h). This brings non-consensual intimate images and deepfakes of minors into the bill's scope.

ELIGIBILITY

'Approved vendor' is redefined as a 'cloud service provider' that must both comply with security requirements AND be contractually retained by a 'covered agency.' The term 'covered agency' is newly defined to explicitly include Federal, State, and local law enforcement or prosecutorial agencies, broadening who can contract for these services.

ENFORCEMENT

The liability exception is restructured with an explicit 'OR' between the two prongs. Previously it was ambiguous whether both negligent conduct AND actual malice/recklessness were required. Now either intentional misconduct or negligent conduct alone (prong A), OR actual malice, reckless disregard, or unrelated purpose (prong B), is sufficient to allow a civil claim or criminal charge against a vendor.

REQUIREMENT

The data-location requirement now includes an exception: child pornography, child obscenity, and intimate visual depictions of minors may be transferred outside the United States with the express consent of the contracting covered agency if deemed necessary for investigative purposes. Previously the requirement was absolute.

Approved vendors must now maintain a list of employees who have obtained access to stored material, in addition to minimizing the number of such employees.

A new rule of construction (subsection f) clarifies that nothing in the section limits an agency's bona fide use of stored material (including sharing with other parties for investigation or prosecution) or its obligation to comply with court orders, constitutional obligations, or victim requests under 18 U.S.C. 3509(m)(3).

TECHNICAL

The annual cybersecurity audit must now specifically assess compliance with NIST Special Publication 800-53 Revision 5 (security and privacy controls for information systems), adding a concrete technical standard beyond the general Cybersecurity Framework reference.

Notification letters are now directed specifically to the Criminal Division of the Department of Justice (rather than just 'the Department of Justice'), and updates must be sent to the Child Exploitation and Obscenity Section specifically.

Floor votes

How they voted

This bill passed the Senate by voice vote (no roll call recorded).
Full legislative history

Actions timeline

Total actions
12
Key actions
4
Committee
3
May 20, 2026
Upper · Passed
Passed Senate with an amendment by Unanimous Consent. (text of amendment in the nature of a substitute: CR S2427-2428)
upper
May 20, 2026
Upper · Passed
Passed/agreed to in Senate: Passed Senate with an amendment by Unanimous Consent.
upper
Feb 24, 2026
Upper · Passed
Committee on the Judiciary. Reported by Senator Grassley with an amendment in the nature of a substitute. Without written report.
upper
Feb 5, 2026
Upper · Passed
Committee on the Judiciary. Ordered to be reported with an amendment in the nature of a substitute favorably.
upper
Oct 21, 2025
Committee
Read twice and referred to the Committee on the Judiciary.
upper
Oct 21, 2025
Introduced
Introduced in Senate
upper
1 primary · 9 co-sponsors

Sponsors