
The Law Council of Australia has concluded that Australia's encryption laws are unlikely to be compatible with the United States' CLOUD Act , as well as the European Union's General Data Protection Regulation
In a statement to the Joint Parliamentary Committee on the Review of the Intelligence and Security Services Encryption Act, the Law Council said Australian authorities should continue to collect dataonce Canberra and Washington reach an agreement.
The Legal Counsel, examining the 2018 legislation, stated that it believes the law could prevent Australia from entering an executive agreement with the US under the CLOUD Act.
“In this context, the requirements of the Assistance and Access Act and the CLOUD Act clearly differ, as US law does not allow for the ordering of decryption , as is now permitted under Australian law,” it said.
The CLOUD Act was passed in March 2018 in the US. The legislation was an attempt to ensure that US law enforcement could access data held overseas by US companies.
It has two basic elements. First, it clarifies that companies subject to US jurisdiction must disclose data in response to valid legal processes, regardless of where such data is stored.
Second, it establishes a simplified alternative solution to the Mutual Legal Assistance Treaties (MLATs), allowing the conclusion of agreements between the US government and other countries that permit orders for the disclosure of electronic evidence directly to the communications service provider (CSP) or the other nation that is a contracting party to the agreement.
MLATs provide that law enforcement in a nation may use national legal provisions to seek evidence from a CSP on behalf of a foreign subpoena, using the local legal framework. The use of MLAT to gather evidence can take months, according to the US Department of Justice.

“The CLOUD Act authorizes executive agreements that lift restrictions under U.S. law on companies disclosing electronic data directly to foreign authorities in investigations of serious crimes. This would allow U.S.-based global CSPs to respond directly to foreign legal processes in many cases.”
However, the CLOUD law states that before entering into an agreement, the US Attorney General is required to certify that the other nation “provides strong and substantive protection of privacy and political freedoms, in the context of data collection and the activities of the foreign government that will be subject to the agreement.”
“The Law Council considers that the current encryption law in Australia regarding the storage and access to telecommunications data would not be insufficient to allow Australia to benefit from entering into an ‘executive agreement’ with the US. This means that law enforcement agencies in Australia would be limited to seeking access to data held by a service provider in the US, through the existing and time-consuming MLAT process.”
“The reason for this is that whatever laws Australia may pass, they are not enough to force a US service provider to do anything that is not permitted by US law,” the document adds.
The EU GDPR applies to any Australian organisations that operate or offer goods or services in the EU or monitor the behaviour of EU citizens
Although Australia's encryption legislation discourages actions that could be requested from a service provider, to do anything that would create «vulnerability» or «weakness» in the system, when a provider attempts to comply with a data inspection notice, it may jeopardize the security of personal information,” the Legal Counsel said.
This contravenes the provisions of the GDPR which require service providers and other data controllers to implement appropriate technical and organizational measures and to provide protection and security for personal data within the EU.
