Cloud vendors storing child abuse evidence get broad legal immunity
S. 3023 — Safe Cloud Storage Act · Filed by Marsha Blackburn (R-TN) · 9 cosponsors · Introduced Oct 21, 2025 · Passed chamber
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill creates a legal shield for cloud storage companies that contract with law enforcement to store child sexual abuse material (CSAM) as evidence. It limits lawsuits against these vendors to cases involving intentional misconduct, actual malice, or reckless disregard—blocking ordinary negligence claims. The bill requires vendors to meet cybersecurity standards, keep data in the US, and notify the Justice Department, but protects them from civil and criminal liability for storing and handling CSAM on behalf of police and prosecutors.
Why we flagged it
The bill's operative mechanism is a liability carve-out for cloud vendors storing CSAM evidence. While framed as modernizing law enforcement capability, the core function is to restrict civil and criminal remedies against private contractors.
What the text implies
- Vendors may face reduced incentive to invest in security beyond minimum NIST standards, since negligence claims are barred even if a breach exposes CSAM to unauthorized parties.
- Victims of child exploitation whose images are stored may lose the ability to sue vendors for mishandling or unauthorized access, even if negligence caused harm.
The full analysis lists 5 implications of this text.
Who stands to gain
cloud service providers contracting with law enforcement; technology vendors offering CSAM storage and forensic processing