Why it is hard (if not impossible) to run a privacy-focused company in the US

When people think of tech companies, they typically think of Silicon Valley. This is where some of the biggest tech companies got their start and its where most of them have their headquarters. This is no accident. The available talent in the US, the easy access to capital and investors, and a general entrepreneurial spirit have created a unique set of conditions for tech companies to thrive and prosper.

However, for privacy companies, the many advantages of the US are canceled out by the absence of strong national online privacy laws. Below are some of the reasons we feel that the US is still an unsuitable environment for a privacy company.

A lack of adversarial oversight

The Foreign Intelligence Surveillance Act of 1978 was passed in response to the Watergate abuses of government surveillance. It created a special secret tribunal(new window) that decides whether to approve government wiretaps, data collection, and other requests for covert surveillance. The 2016 battle between Apple and the FBI over decrypting the San Bernadino shooter’s iPhone is an example of the type of case the FISA court usually hears. Experts speculate(new window) the FBI made the debate public after Apple refused to comply with a sealed court request.

The secrecy surrounding these courts makes effective oversight difficult. Critics claim that the FISA courts act as rubber stamps for authorities, pointing to the fact that between the court’s creation in 1978 and 2014(new window), FISA court judges approved 33,942 surveillance applications while only rejecting 11 and modifying 504. The 2015 Freedom Act(new window) introduced reforms that increased transparency into court deliberations and rulings, but the majority of applications are still approved.

The FISA courts are the sole arbiters of what constitutes a legitimate surveillance target. They are the only institutional check that keeps the NSA and the FBI from violating your privacy during investigations. So it is concerning to say the least to see the court side so overwhelmingly with law enforcement.

Secretive, warrantless subpoenas

FISA court rulings at least pay lip service to the idea of judicial review. National security letters (NSLs), on the other hand, are secret subpoenas which do not require court approval of any kind. An FBI agent simply needs to clear an internal FBI standard before they can issue a letter.

With national security letters, the FBI can compel organizations to turn over vast amounts of personal data and metadata without a warrant. This includes every record associated with the customer’s account. These letters are almost always served in secrecy and they come with indefinite gag orders that bans any discussion of the NSL and its investigation.

There is evidence(new window) that the FBI has repeatedly(new window) abused NSLs to demand information that it cannot legally obtain, such as browsing data and email content. This should not be surprising. The secrecy and lack of supervision that surrounds national security letters invites such overreach. Even if they do not keep records of a user’s online activity, a VPN could be compelled by a NSL to share the user’s screen name, email, and payment details and begin collecting logs. The user and the general public would never know.

Lack of strong digital privacy laws

The NSA’s and FBI’s online surveillance both rely on the data collected by private enterprises. The US has no national legislation equivalent to the EU’s GDPR which has allowed large organizations to surreptitiously collect, monitor, and sell their users’ data. California just passed a new online privacy law(new window) modeled on the EU’s GDPR(new window), which gives users more control over what is done with their data, but it fails to set major fines for violations. This lack of legal teeth makes it unlikely that it will provide anything more than empty promises.

Until there is a national privacy law that gives users control of their data and punishes large corporations for violating their users’ trust, corporations will continue to collect and sell as much user data as they can. The different surveillance and law enforcement techniques that the NSA and FBI have at their disposal would not be so threatening if these companies did not have so much data on their users.

Protecting privacy from Switzerland

Simply put, the US does not offer the legal privacy protections nor the level of accountability and transparency that exists in Switzerland(new window). As Swiss companies, Proton Mail and Proton VPN are not subject to FISA courts and they cannot compel us to cooperate with the FBI or NSA. It is illegal for us to comply with any request for data unless it is supported by a Swiss court order. To secure approval from a Swiss court, law enforcement must meet a higher legal threshold than with FISA courts. Finally, as an organization with a significant amount of EU users, we comply with the GDPR and its “privacy by design(new window)” principle.

We are also regularly audited by independent security experts, and our latest security audit(new window) results confirm our no logs policy.

For these reasons, Proton Mail and Proton VPN continue to be headquartered in Geneva, Switzerland. It is a home that offers us unique security advantages, advantages that we, in turn, offer to our users.

Best Regards,
The Proton VPN Team

You can follow us on social media to stay up to date on the latest Proton VPN releases:

Twitter (new window)| Facebook(new window) | Reddit(new window)

To get a free Proton Mail encrypted email account, visit: proton.me/mail(new window)

Protect your privacy and security online
Get Proton VPN free

Related articles

What is AirTag stalking?
In an era of “smart devices” that often double as spy devices, AirTags are tracking tools that are open about their function and can be vital in helping locate lost items (as anyone who has lost their car keys can attest to). However, as a recent cla
How to fix a "Your connection is not safe" error
As you surf the web using your browser, you’ll no doubt encounter websites that your browser will refuse to load, instead showing some variation of an error message, such as Your connection is not private or Warning: Potential Security Risk Ahead. 
Your search history is a window into your inner life. Anyone with access to it knows what your hobbies and interests are, your sexual orientation and preferences, the things that worry you (for example your medical concerns), your political affiliati
how to flush dns blog
  • Privacy deep dives
A DNS cache is a record of all the websites you’ve visited over a set amount of time. Simply put, your DNS cache is a list of websites you visited in the past that’s stored on your device. Your computer uses it to speed up visits to those same websit
Is Temu legit?
  • Privacy basics
Temu has become an unavoidable brand. Unknown to most up to a year ago, the online retailer exploded onto the digital scene in the United States with lavish ads and a riveting social media campaign, and has started its takeover in Europe now, too. As
We examIne whether the controversial Chinese video platform is safe to use
  • Privacy basics
In this article, we take an in-depth look at whether the wildly popular social media platform TikTok is safe to use. Several countries recently banned government officials from using TikTok, and now the US House of Representatives has passed the Pro