Historically the United States has been very strong in establishing the legislative background to achieve the programs desired by the Executive Branch. In the area of surveillance and intelligence gathering the prime legislation is Foreign Intelligence Surveillance Act (FISA).
Europe has historically been strong in regulatory practices, stemming from the need to provide a regulatory structure for the nation states that comprise the European Union. In the data privacy area, the General Data Protection Regulation (GDPR) is the prime regulatory initiative.
Contention between US legislation and EU regulation has long been an area of concern. The Safe Harbor mechanism provided some agreement between the two jurisdictions until 2015 when the European Court of Justice declared it invalid. In 2016 the EU-US Privacy Sheild Framework was established to manage transmission of data between the EU and the US. As a result of Schrems-II initiative the Privacy Shield Framework was declared invalid.
Background
It is generally considered by most identity and access management professionals that Europe is at the pinnacle when it comes to regulatory guidance for privacy protection. The GDPR provides the guidelines for protecting the private data of citizens in the bloc by providing transparency and redress for users, and a mechanism for punishing contravention
The General Data Protection Regulation provides guardrails for any European organization collecting and storing personal identity information on European citizens whether it be for workforce purposes or customer management. It requires that user data is only used for the purpose for which it was collected, and it also requires that data is periodically refreshed or deleted. It also affords users of on-line services the ability to review and correct information being stored by organizations, and request deletion if they so desire. It is an important component of user consent strategies for organizations maintaining user data, collected by a web application, for tracking and marketing actions.
It is generally recognized that the United States are at the forefront of surveillance and intelligence gathering. The Foreign Intelligence Surveillance Act (FISA) first came into effect in 1978 and was amended in 2008 and 2017. Of particular concern is Section 702 (FISA2) that specifically addresses non-US persons, outside the protections afforded US persons. Probable-cause requirements are minimized and less controls are placed on surveillance methods. While this section was initially a response to 9/11 and was time-limited, it has been extended and updated with the current legislation extending to September 30, 2027.
This means that any organization using US carriage services or cloud infrastructure for personal identifying data storage or transmission, that would normally be protected under the safeguards of GDPR compliance, is vulnerable to US surveillance activity, which could contravene the regulation.
Current Status
While FISA-2 is in effect, organizations utilizing infrastructure owned and operated by US organizations face the risk that surveillance operations could capture data, including personal identifying data, that the subject users would be unable to validate and would have no vehicle for redress.
The glaring problem for EU organizations is the contravention of the GDPR if they don’t adequately protect the personal data that they have collected. While they have committed to ensuring the information they collect is only used for the purpose for which it is collected, should a US surveillance action capture the data in their possession, it will be used for non-sanctioned purposes and compromised individuals will have no actionable rights.
It is unlikely that this situation will change under the current administration, so caution is advised in any IAM project deployment.
Recommendation
The current contention between GDPR and FISA-2 means that European organizations may be in violation of EU regulation and could be held liable if personal identifiable data, provided to them by staff or customers, is collected via a US surveillance operation.
Organizations should review their current IAM environments and planned deployments to determine if any US-owned repositories are being used, or to be used for IAM data storage. This includes availability zones located outside the USA.
Consideration should be given to relocating IAM data storage to other jurisdictions. .
If it is not practical to relocate a data repository, file encryption should be deployed to encrypt data-at-rest. Data in transit should be protected via TLS keys or the corporate PKI, provided it is suitably protected from compromise.
For cloud native deployments in a microservices environment, authentication sidecars should contain basic identity data with no personal identifiable information (PII). If PII is required for an access decision it could be provided at runtime via a secure API to a local data repository.
Conclusion
Concern regarding the uncertainty and lack of coherence emanating from the US Executive level extends to Identity and Access Management (IAM) professionals developing an architecture to guide the design of a robust identity fabric for their respective companies.
While the Foreign Intelligence Surveillance Act has provided some controls under former administrations it is unlikely the current administration would consider themselves constrained by the processes dictated by the Act and would leverage the lax restrictions of FISA-2 on surveillance over non-US persons.
Organisations outside the United States should take steps to understand the impact of potential surveillance by US agencies on their data storage and transmission activity. This might preclude the use of infrastructure operated by US companies.