Why it is hard (if not impossible) to run a privacy-focused company in the US

When people think of tech companies, they typically think of Silicon Valley. This is where some of the biggest tech companies got their start and its where most of them have their headquarters. This is no accident. The available talent in the US, the easy access to capital and investors, and a general entrepreneurial spirit have created a unique set of conditions for tech companies to thrive and prosper.

However, for privacy companies, the many advantages of the US are canceled out by the absence of strong national online privacy laws. Below are some of the reasons we feel that the US is still an unsuitable environment for a privacy company.

A lack of adversarial oversight

The Foreign Intelligence Surveillance Act of 1978 was passed in response to the Watergate abuses of government surveillance. It created a special secret tribunal(nouvelle fenêtre) that decides whether to approve government wiretaps, data collection, and other requests for covert surveillance. The 2016 battle between Apple and the FBI over decrypting the San Bernadino shooter’s iPhone is an example of the type of case the FISA court usually hears. Experts speculate(nouvelle fenêtre) the FBI made the debate public after Apple refused to comply with a sealed court request.

The secrecy surrounding these courts makes effective oversight difficult. Critics claim that the FISA courts act as rubber stamps for authorities, pointing to the fact that between the court’s creation in 1978 and 2014(nouvelle fenêtre), FISA court judges approved 33,942 surveillance applications while only rejecting 11 and modifying 504. The 2015 Freedom Act(nouvelle fenêtre) introduced reforms that increased transparency into court deliberations and rulings, but the majority of applications are still approved.

The FISA courts are the sole arbiters of what constitutes a legitimate surveillance target. They are the only institutional check that keeps the NSA and the FBI from violating your privacy during investigations. So it is concerning to say the least to see the court side so overwhelmingly with law enforcement.

Secretive, warrantless subpoenas

FISA court rulings at least pay lip service to the idea of judicial review. National security letters (NSLs), on the other hand, are secret subpoenas which do not require court approval of any kind. An FBI agent simply needs to clear an internal FBI standard before they can issue a letter.

With national security letters, the FBI can compel organizations to turn over vast amounts of personal data and metadata without a warrant. This includes every record associated with the customer’s account. These letters are almost always served in secrecy and they come with indefinite gag orders that bans any discussion of the NSL and its investigation.

There is evidence(nouvelle fenêtre) that the FBI has repeatedly(nouvelle fenêtre) abused NSLs to demand information that it cannot legally obtain, such as browsing data and email content. This should not be surprising. The secrecy and lack of supervision that surrounds national security letters invites such overreach. Even if they do not keep records of a user’s online activity, a VPN could be compelled by a NSL to share the user’s screen name, email, and payment details and begin collecting logs. The user and the general public would never know.

Lack of strong digital privacy laws

The NSA’s and FBI’s online surveillance both rely on the data collected by private enterprises. The US has no national legislation equivalent to the EU’s GDPR which has allowed large organizations to surreptitiously collect, monitor, and sell their users’ data. California just passed a new online privacy law(nouvelle fenêtre) modeled on the EU’s GDPR(nouvelle fenêtre), which gives users more control over what is done with their data, but it fails to set major fines for violations. This lack of legal teeth makes it unlikely that it will provide anything more than empty promises.

Until there is a national privacy law that gives users control of their data and punishes large corporations for violating their users’ trust, corporations will continue to collect and sell as much user data as they can. The different surveillance and law enforcement techniques that the NSA and FBI have at their disposal would not be so threatening if these companies did not have so much data on their users.

Protecting privacy from Switzerland

Simply put, the US does not offer the legal privacy protections nor the level of accountability and transparency that exists in Switzerland(nouvelle fenêtre). As Swiss companies, Proton Mail and Proton VPN are not subject to FISA courts and they cannot compel us to cooperate with the FBI or NSA. It is illegal for us to comply with any request for data unless it is supported by a Swiss court order. To secure approval from a Swiss court, law enforcement must meet a higher legal threshold than with FISA courts. Finally, as an organization with a significant amount of EU users, we comply with the GDPR and its “privacy by design(nouvelle fenêtre)” principle.

We are also regularly audited by independent security experts, and our latest security audit(nouvelle fenêtre) results confirm our no logs policy.

For these reasons, Proton Mail and Proton VPN continue to be headquartered in Geneva, Switzerland. It is a home that offers us unique security advantages, advantages that we, in turn, offer to our users.

Best Regards,
The Proton VPN Team

You can follow us on social media to stay up to date on the latest Proton VPN releases:

Twitter (nouvelle fenêtre)| Facebook(nouvelle fenêtre) | Reddit(nouvelle fenêtre)

To get a free Proton Mail encrypted email account, visit: proton.me/mail(nouvelle fenêtre)

Articles similaires

Apps like discord
en
  • Vie privée, approfondissements
Here's why you might want to consider a Discord alternative — and the pros and cons of seven other apps like Discord that you may want to switch to instead.
Computer screen showing the World Series 2024 logo
en
Find out where to watch the World Series, when it starts, and how to securely stream it online with Proton VPN.
Computer screen with a shield that has a lock on it, demonstrating secure network access via a dedicated IP address
en
Learn what network access control is and how a business VPN can help keep your business data safe against hackers.
Telegram security
en
  • Vie privée, approfondissements
Is Telegram safe to use? As we’ll discuss in this article, that very much depends on how you use it.
A vote going into a US ballot box for the 2024 US presidential election
en
Find out how to watch the 2024 US election results live from abroad and which broadcasters are streaming news coverage online.
en
Anyone can use Proton VPN’s Chrome and Firefox browser extensions for free, making it easy to protect your privacy and bypass censorship.