S. 3023 (119th)Bill Overview

Safe Cloud Storage Act

Crime and Law Enforcement|Crime and Law Enforcement
Cosponsors
Support
Bipartisan
Introduced
Oct 21, 2025
Discussions
Bill Text
Current stageCommittee

Read twice and referred to the Committee on the Judiciary.

Introduced
Committee
Floor
President
Law
Congressional Activities
01 · The brief
Plain-English summaryWhat this bill actually does

This bill (Safe Cloud Storage Act) amends the PROTECT Our Children Act to allow U.S. law enforcement agencies to contract with ‘‘approved vendors’’ to store and analyze child sexual abuse material (CSAM) in cloud or remote storage. It creates limited liability protection for those approved vendors for actions taken while performing their contractual duties, while preserving civil or criminal claims where vendors engage in intentional misconduct, negligence, actual malice, reckless disregard, or act for an unrelated purpose.

Why people may split

Scope and oversight of liability protections: liberals seek stronger transparency/oversight; conservatives want broader protections to incentivize cooperation.

Watch point

Relative to its intended legislative type, this bill is a substantive statutory change that is moderately well-specified: it defines covered actors, limits liability with enumerated exceptions, and prescribes technical, notification, and retention requirements tied into existing law.

This bill (Safe Cloud Storage Act) amends the PROTECT Our Children Act to allow U.S. law enforcement agencies to contract with ‘‘approved vendors’’ to store and analyze child sexual abuse material (CSAM) in cloud or remote storage.

It creates limited liability protection for those approved vendors for actions taken while performing their contractual duties, while preserving civil or criminal claims where vendors engage in intentional misconduct, negligence, actual malice, reckless disregard, or act for an unrelated purpose.

The bill imposes cybersecurity and evidence-handling requirements on approved vendors (NIST Cybersecurity Framework compliance, end-to-end encryption or equivalent, minimized employee access, annual independent audits, CJIS-aligned evidence retention), requires that such data remain in the United States, and mandates notification to the Department of Justice about contracts and custodial problems.

Passage45/100

On substance the bill addresses a concrete operational problem (storing and analyzing CSAM for law enforcement) and contains technical safeguards that could attract bipartisan support; however, the creation of a broad safe harbor for private vendors storing illegal content and the requirement to keep such data within the United States are politically and legally sensitive elements that raise opposition risks and could prompt significant amendment or delay. Without additional compromise features (sunset, pilot, or narrower immunity) its path is moderate-to-difficult.

CredibilityPartially aligned

Relative to its intended legislative type, this bill is a substantive statutory change that is moderately well-specified: it defines covered actors, limits liability with enumerated exceptions, and prescribes technical, notification, and retention requirements tied into existing law. It integrates with existing statutory references and includes several operational requirements for vendors.

Contention45/100

Scope and oversight of liability protections: liberals seek stronger transparency/oversight; conservatives want broader protections to incentivize cooperation.

02 · What it does

Who stands to gain, and who may push back.

Likely benefits vs burdens50% / 50%
CitiesLocal governments

These are examples from the analysis, not a ranked list of the most-affected groups.

Likely helped
  • CitiesMay increase law enforcement capacity to store, analyze, and retain CSAM by enabling private cloud vendors to offer sec…
  • Potential benefitCould encourage private-sector participation (including specialized forensic/analytic vendors) by clarifying legal expo…
  • Potential benefitEstablishes uniform cybersecurity, auditing, and U.S.-storage requirements that supporters may say raise baseline data-…
Likely burdened
  • Potential burdenLimits on civil and criminal claims could reduce private accountability for vendors that mishandle CSAM, potentially co…
  • Potential burdenCompliance requirements (NIST alignment, annual independent audits, U.S.-only storage, encryption standards, restricted…
  • Local governmentsThe requirement to keep material and analytics within the United States and the liability shield for contracted vendors…
03 · Why people split

Why the argument around this bill splits.

Scope and oversight of liability protections: liberals seek stronger transparency/oversight; conservatives want broader protections to incentivize cooperation.
Progressive65%

A mainstream liberal observer would likely appreciate the intent to help law enforcement investigate and prosecute child sexual exploitation while keeping material secured, but would be cautious about broad liability shields and private companies handling CSAM.

They would focus on preserving victims’ rights, clear accountability, transparency about oversight, and strong privacy and chain-of-custody protections.

They would welcome clauses that preserve liability for negligence and intentional misconduct but want further clarity on who qualifies as an ‘‘approved vendor,’’ how DOJ oversight will function, and safeguards preventing mission creep or misuse of access to sensitive material.

Split reaction
Centrist75%

A centrist/ moderate would likely view the bill as a pragmatic update to allow law enforcement to use modern cloud tools while keeping accountability mechanisms.

They would welcome the cybersecurity requirements and retention rules aligned with CJIS, and see the liability carve-out (subject to negligence and intentional misconduct exceptions) as balancing vendor willingness to cooperate with accountability.

However, they would want clearer procedural details (how vendors become ‘‘approved,’’ oversight by DOJ or inspectors general, fiscal impacts) and guardrails to prevent unintended legal gaps or evidence-handling problems.

Leans supportive
Conservative80%

A mainstream conservative would likely favor strengthening law enforcement tools to investigate child exploitation and appreciate liability protections that reduce legal risk for private vendors assisting agencies.

They would welcome requirements that data stay in the United States and that vendors follow federal cybersecurity standards.

At the same time, they may be wary of prescriptive operational rules (annual independent audits, specific encryption language) if perceived as creating burdensome regulation or cost, but would generally support measures that make it easier for providers to cooperate without fear of frivolous litigation.

Leans supportive
04 · Can it pass?

The path through Congress.

Introduced

Reached or meaningfully advanced

Committee

Reached or meaningfully advanced

Floor

Still ahead

President

Still ahead

Law

Still ahead

Passage likelihood45/100

On substance the bill addresses a concrete operational problem (storing and analyzing CSAM for law enforcement) and contains technical safeguards that could attract bipartisan support; however, the creation of a broad safe harbor for private vendors storing illegal content and the requirement to keep such data within the United States are politically and legally sensitive elements that raise opposition risks and could prompt significant amendment or delay. Without additional compromise features (sunset, pilot, or narrower immunity) its path is moderate-to-difficult.

Scope and complexity
52%
Scopemoderate
52%
Complexitymedium
Why this could stall
  • How courts would interpret the immunity exceptions (e.g., standards for 'negligent' or 'reckless' conduct) and how that will affect litigation risk and stakeholder support.
  • The reaction of major technology companies and civil‑liberties organizations — whether industry supports the liability protection coupled with security requirements or opposes data localization and added obligations.
05 · Recent votes

Recent votes on the bill.

No vote history yet

The bill has not accumulated any surfaced votes yet.

06 · Go deeper

Go deeper than the headline read.

Included on this page

Scope and oversight of liability protections: liberals seek stronger transparency/oversight; conservatives want broader protections to ince…

On substance the bill addresses a concrete operational problem (storing and analyzing CSAM for law enforcement) and contains technical safe…

Unlocked analysis

Relative to its intended legislative type, this bill is a substantive statutory change that is moderately well-specified: it defines covered actors, limits liability with enumerated exceptions, and prescribes technical,…

Go beyond the headline summary with full stakeholder mapping, legislative design analysis, passage barriers, and lens-by-lens tradeoff breakdowns.

Perspective breakdownsPassage barriersLegislative design reviewStakeholder impact map
Open full analysis