Safe Cloud Storage Act
What changed between versions
Intimate visual depictions of minors (including digital forgeries) are now covered material under the cloud storage framework, defined by reference to 47 U.S.C. 223(h). This brings non-consensual intimate images and deepfakes of minors into the bill's scope.
'Approved vendor' is redefined as a 'cloud service provider' that must both comply with security requirements AND be contractually retained by a 'covered agency.' The term 'covered agency' is newly defined to explicitly include Federal, State, and local law enforcement or prosecutorial agencies, broadening who can contract for these services.
The liability exception is restructured with an explicit 'OR' between the two prongs. Previously it was ambiguous whether both negligent conduct AND actual malice/recklessness were required. Now either intentional misconduct or negligent conduct alone (prong A), OR actual malice, reckless disregard, or unrelated purpose (prong B), is sufficient to allow a civil claim or criminal charge against a vendor.
The data-location requirement now includes an exception: child pornography, child obscenity, and intimate visual depictions of minors may be transferred outside the United States with the express consent of the contracting covered agency if deemed necessary for investigative purposes. Previously the requirement was absolute.
Approved vendors must now maintain a list of employees who have obtained access to stored material, in addition to minimizing the number of such employees.
A new rule of construction (subsection f) clarifies that nothing in the section limits an agency's bona fide use of stored material (including sharing with other parties for investigation or prosecution) or its obligation to comply with court orders, constitutional obligations, or victim requests under 18 U.S.C. 3509(m)(3).
The annual cybersecurity audit must now specifically assess compliance with NIST Special Publication 800-53 Revision 5 (security and privacy controls for information systems), adding a concrete technical standard beyond the general Cybersecurity Framework reference.
Notification letters are now directed specifically to the Criminal Division of the Department of Justice (rather than just 'the Department of Justice'), and updates must be sent to the Child Exploitation and Obscenity Section specifically.