[codicts-css-switcher id=”346″]

Global Law Experts Logo
cross-border evidence requests usa

Our Expert in USA

  • GOLD

How U.S. Authorities Obtain Cross‑border Evidence in White‑collar Investigations (USA 2026): What Companies & Executives Must Do

By Global Law Experts
– posted 41 minutes ago

Cross-border evidence requests usa are now a defining feature of white-collar enforcement, and 2026 continues a trend toward faster cooperation, more cloud-native data and tighter coordination among the Department of Justice, the Securities and Exchange Commission and foreign prosecutors. When a U. S. investigation touches records, custodians or servers abroad, the question is often not whether prosecutors can reach that evidence, but which legal pathway they will use and how quickly your company must respond. This practitioner guide explains the mechanics of mutual legal assistance treaties, letters rogatory, the CLOUD Act and domestic subpoenas, sets realistic timelines, and gives in-house teams concrete steps to preserve privilege, maintain chain of custody and lawfully disclose data.

It is written for general counsel, compliance officers, corporate security leaders and executives who may have only hours to make the right first decisions.

Who should read this: in-house counsel, general counsel, compliance officers, corporate security, CISOs and executives facing or preparing for cross-border evidence requests.

What you’ll get: practical steps, timing expectations, decision points, scripts and escalation paths to preserve privilege and respond lawfully.

How U.S. Authorities Obtain Cross-Border Evidence: Overview

U.S. prosecutors and regulators have a menu of tools to gather evidence that sits outside American borders. Each tool carries different legal authority, different actors, and dramatically different timelines. Understanding this menu is the foundation of any corporate response, because the mechanism dictates where the pressure will fall, what deadlines apply, and whether foreign law will interfere with disclosure. Companies that treat all cross-border evidence requests usa as a single category routinely make avoidable mistakes in preservation, privilege and communication.

Pathways at a Glance

There are four principal routes U.S. authorities use to obtain foreign-located evidence:

  • Mutual legal assistance treaties (MLATs). Treaty-based requests for criminal assistance, channeled government-to-government through designated central authorities. This is the primary formal route for compelling criminal evidence abroad.
  • Letters rogatory. Requests issued by a court to a foreign court for judicial assistance, often routed through diplomatic channels or, in civil and commercial matters, under the Hague Evidence Convention. More common in civil and fact-finding contexts.
  • Direct provider requests under the CLOUD Act and executive agreements. Domestic legal process served on a U.S.-based provider can reach data the provider controls regardless of storage location, and qualifying executive agreements allow certain foreign governments to serve certain demands directly on covered providers.
  • Mutual administrative assistance. Agency-to-agency cooperation between regulators (for example, securities or tax authorities) that supplements criminal channels.

Who Does What, DOJ OIA, Prosecutors, State Department and Foreign Central Authorities

The U.S. central authority for incoming and outgoing MLAT requests is the Department of Justice’s Office of International Affairs (OIA). OIA reviews whether a request meets treaty requirements, transmits it to the foreign central authority, and manages the diplomatic and procedural traffic back and forth. Federal prosecutors, Assistant U.S. Attorneys and DOJ trial attorneys, draft the substantive request, define the scope of evidence sought and coordinate with OIA on sequencing.

The Department of State maintains official texts of mutual legal assistance treaties the United States has concluded and has historically played a role in transmitting letters rogatory through diplomatic channels. On the receiving side, each treaty partner designates its own central authority, typically a ministry of justice or prosecutor general’s office, that executes the request under local law. For companies, the practical takeaway is that cross-border evidence requests usa pass through multiple gatekeepers, each introducing review time and each applying its own legal standards. When you are notified, identify which actor is driving the request, because that determines your counterparties and your realistic response window.

MLATs: Process, Timeline, and What Companies Can Expect

The mutual legal assistance treaty is a workhorse of international white collar investigations. It is formal, treaty-grounded and slower than most in-house teams expect. Knowing how the MLAT process actually unfolds lets you plan preservation, manage executive expectations and avoid premature disclosure.

What Is an MLAT? Treaty vs. Agreement

A mutual legal assistance treaty is a bilateral or multilateral agreement under which signatory states commit to assist one another in criminal matters, gathering witness testimony, producing documents, executing searches, freezing assets and serving process. Unlike informal cooperation, an MLAT creates an obligation on the requested state to render assistance, subject to the treaty’s limits and local law. The Department of State publishes official texts of many of these treaties, which define their scope, the offenses covered and any grounds for refusal.

Step-by-Step MLAT Process and Realistic Timelines

The MLAT process generally moves through four stages:

  1. Request drafting. The prosecutor prepares a detailed request specifying the evidence, its relevance, the applicable offenses and the legal basis. OIA reviews it for treaty compliance.
  2. Transmission and review. OIA sends the request to the foreign central authority, which examines it under domestic law and treaty terms.
  3. Execution. The foreign authority uses local procedures, court orders, subpoenas, searches, to gather the evidence. This is often where the longest delays occur.
  4. Return. The collected evidence is authenticated and transmitted back through central authorities to the requesting prosecutor.

Realistic timelines vary widely by country and complexity. Straightforward document requests to well-resourced treaty partners may take several months. Complex matters involving searches, contested scope or less-responsive jurisdictions routinely run from many months to a year or longer. For corporate planning, assume that cross-border evidence requests usa routed through an MLAT will not resolve quickly, and that preservation obligations will outlast the request by a wide margin.

Common Operational Issues

Several recurring problems complicate MLAT execution and, by extension, the company caught in the middle:

  • Translation. Requests and returned evidence must often be translated, adding cost and delay and creating opportunities for scope ambiguity.
  • Scope disagreements. The requested state may interpret the request narrowly, or local law may bar production of categories of data the U.S. prosecutor expected to receive.
  • Confidentiality. MLAT requests are frequently confidential. A company may learn of an investigation only indirectly, and improper disclosure can breach confidentiality obligations or tip off other custodians.
  • Dual criminality and local defenses. Some treaties require that the conduct be criminal in both jurisdictions; local privilege or data-protection rules may further restrict what is handed over.

Practical tip: designate a single internal liaison to track the request, and engage local counsel in the executing jurisdiction early, before the foreign authority begins compelling production from your entities or employees.

Letters Rogatory and the Hague Evidence Convention: Civil-Process Tools

Where MLATs dominate criminal matters, letters rogatory and the Hague Evidence Convention govern much of the civil and fact-finding landscape, and they frequently intersect with corporate investigations that straddle regulatory, civil and criminal exposure.

Letters Rogatory Basics, When Used

A letter rogatory is a formal request from a court in one country to the judiciary of another, asking the foreign court to perform some judicial act, typically taking testimony or compelling the production of documents. Historically transmitted through diplomatic channels, letters rogatory are most common in civil and commercial litigation and in fact-finding where no criminal treaty applies. They depend on the receiving court’s willingness to assist and on local procedural rules, which makes them less predictable than treaty-based criminal assistance. For companies, letters rogatory often appear in parallel civil proceedings or shareholder actions that shadow a white-collar probe.

Hague Evidence Convention Mechanics and Reservations

The Hague Convention on the Taking of Evidence Abroad in Civil or Commercial Matters streamlines letters of request among contracting states. Under the Convention, a judicial authority in one contracting state sends a letter of request to a designated central authority in another, which arranges execution under local procedure. Crucially, many contracting states have entered declarations, particularly under Article 23, limiting pre-trial discovery of documents, so the breadth of U.S.-style document discovery is often sharply curtailed abroad. The Hague Conference on Private International Law publishes the Convention text and the current status of contracting states and their declarations, which should always be checked before relying on this route.

When Letters Rogatory Are Faster or Slower Than MLATs

Neither route is reliably fast. Hague-based letters of request can be comparatively efficient in jurisdictions with responsive central authorities and no restrictive declarations. Traditional diplomatic-channel letters rogatory are frequently the slowest option, sometimes taking a year or more. In criminal matters, the MLAT will generally be the preferred and more enforceable mechanism; letters rogatory come into play when the matter is civil, when no treaty exists, or when a parallel civil proceeding needs evidence. Corporate counsel should map which proceedings are driving each cross-border evidence request to anticipate the applicable channel.

Subpoenas, the CLOUD Act, and Direct Provider Access

One of the most consequential shifts in cross-border evidence gathering over the past decade concerns cloud subpoenas overseas and direct access to provider-held data. This is where domestic legal process, foreign storage and conflicting laws collide, and where companies can face the fastest-moving deadlines.

Can a U.S. Subpoena Reach Data Stored Overseas?

The question of whether U. S. legal process could compel a provider to produce communications stored abroad came to a head in Microsoft Corp. v. United States (the “Microsoft Ireland” case), in which the Second Circuit held in 2016 that a Stored Communications Act warrant did not reach emails stored on servers in Ireland. That decision set up a Supreme Court case, United States v. Microsoft Corp. , which the Court dismissed as moot in 2018 after Congress enacted the CLOUD Act. The practical result today is that, for much provider-held data, a provider’s possession, custody or control, not the physical location of a server, is the operative question. The Stored Communications Act, codified at 18 U. S. C.

§ 2703, remains the statutory mechanism for compelling provider production of stored communications, subject to the type of legal process required (warrant, court order or subpoena) for different categories of data.

The CLOUD Act, Executive Agreements and Provider Compliance

The Clarifying Lawful Overseas Use of Data Act, enacted as part of the Consolidated Appropriations Act, 2018 (Public Law No. 115-141), did two things. First, it confirmed that U. S. providers must disclose data in their possession, custody or control in response to valid U. S. legal process, regardless of where the data is stored. Second, it created a framework for executive agreements under which qualifying foreign governments can serve certain demands directly on U. S. providers, and vice versa, bypassing the slower MLAT route for data covered by the agreement. Qualifying partners must meet baseline rule-of-law and privacy standards established by the statute.

The CLOUD Act also includes a comity mechanism allowing covered providers, in defined circumstances, to move to quash or modify process that would create a conflict with the law of a qualifying foreign government. For companies, this means cross-border evidence requests usa can, where the CLOUD Act applies, move at the speed of a domestic subpoena rather than the pace of a treaty request, compressing preservation and response windows considerably.

Practical Steps for Dealing with Cloud Providers

When data lives with a SaaS vendor, cloud host or email provider, your response depends on coordinating with the provider’s legal process team:

  • Issue a preservation request immediately. Many major providers accept preservation demands that freeze data pending legal process; this protects evidence from routine deletion cycles.
  • Identify the provider’s legal process contact. Know in advance which vendors hold which data and how each receives and processes legal demands.
  • Review provider transparency and notice policies. Some providers notify account holders of legal process unless a nondisclosure order applies; understand whether and when your company will be told.
  • Map custody and control. Confirm whether the provider or your company controls the data, because that determines who must respond and under which authority.

Privilege, Data Protection and Conflicts with Foreign Law

Collecting evidence across borders creates two persistent risks that can damage a company far more than the underlying investigation: inadvertent waiver of privilege and violation of foreign data-protection law. Both must be managed from the first hour.

Privilege Preservation, Common Pitfalls in Cross-Border Collections

Privilege is jurisdiction-specific and fragile in international collections. Common mistakes include collecting data without filtering privileged material, routing sensitive documents through personnel in jurisdictions that do not recognize attorney-client privilege for in-house counsel, and mixing privileged and non-privileged material in productions that are then transmitted abroad. To preserve privilege, segregate legal advice early, use counsel-directed collection protocols, apply privilege review before any cross-border transfer, and document the basis for each withholding. Because some civil-law jurisdictions do not extend privilege to in-house counsel communications, treat documents created or held abroad with particular care.

Data Protection Laws and Conflict Analysis

Foreign data-protection regimes, most prominently the EU General Data Protection Regulation, restrict the transfer of personal data and can directly conflict with a U.S. demand. The company may face a genuine dilemma: comply with U.S. process and risk a foreign penalty, or comply with foreign law and risk U.S. consequences. A structured conflict analysis identifies the categories of personal data implicated, the lawful bases for transfer, available derogations, and whether the CLOUD Act comity mechanism or MLAT channeling can relieve the conflict. Document the analysis contemporaneously; it is both a defense and a roadmap.

Tactical Use of Foreign Counsel and Ring-Fencing Data

Engage qualified local counsel in each affected jurisdiction to advise on privilege, blocking statutes and data-protection constraints. Ring-fence sensitive data by collecting and reviewing it within the jurisdiction where it resides, exporting only what is lawfully transferable and non-privileged. This disciplined approach reduces exposure on both sides.

Immediate Steps for Companies and Executives When You’re Notified

The first 24 hours after learning of a cross-border evidence request often shape the outcome. Preservation failures and clumsy communications in that window are difficult to repair. The guidance below is the operational core of responding to cross-border evidence requests usa.

The 24-Hour Checklist

  • Issue a legal hold. Suspend routine deletion and distribute a written hold to all relevant custodians, IT and third-party providers.
  • Instruct IT to preserve, not collect. Direct IT to freeze mailboxes, cloud tenants, backups and device images without altering metadata or chain of custody.
  • Serve preservation requests on providers. Send preservation demands to SaaS and cloud vendors holding relevant data.
  • Identify the mechanism and actor. Determine whether the request arrives via subpoena, MLAT, provider process or foreign order, and who is driving it.
  • Assess confidentiality. Check whether a nondisclosure order or treaty confidentiality obligation limits who may be told.
  • Engage outside and local counsel. Retain U.S. white-collar counsel and foreign counsel in each affected jurisdiction.
  • Protect privilege. Flag likely privileged repositories before any collection begins.

Treat chain of custody as sacrosanct: record who accessed what, when and how, from the outset. For context on the broader practice, see the Global Law Experts White‑Collar Crime, United States practice area page.

Notification and Communication Templates

Control the internal narrative. Executives and boards need enough information to govern responsibly without creating discoverable commentary or breaching confidentiality. A disciplined approach communicates on a need-to-know basis, uses privileged channels for legal analysis, and avoids speculation in writing. Employee communications should be limited, factual and coordinated with the legal hold, typically a short notice directing custodians to preserve materials and route questions to legal. Board and executive briefings should be delivered through counsel where possible to maintain privilege and consistency.

When to Engage Foreign Counsel and Regulatory Counsel

Engage foreign counsel promptly when evidence or custodians sit in the foreign jurisdiction, when local law may restrict disclosure, or when a local court process or foreign regulator is involved. Engage dedicated regulatory counsel when a parallel SEC, enforcement or sector regulator may act on the same facts. Early engagement helps prevent the company from taking a position in one forum that undermines its defense in another. To find practitioners by jurisdiction and specialty, consult the Global Law Experts, Lawyer directory: USA + White‑Collar Crime.

Tactical Playbook: Responding to Specific Scenarios

The right response depends on the exact shape of the demand. The three scenarios below cover common fact patterns in cross-border white-collar matters, each with a decision path, timing reality and escalation points.

Scenario A, U.S. Grand Jury Subpoena for Overseas Emails

A grand jury subpoena seeks emails stored abroad but held by a U.S.-based provider or within the company’s control. Because the CLOUD Act ties disclosure to possession, custody or control, the location of the server will often not excuse non-production. First, preserve and map the data. Second, assess whether production would violate foreign data-protection law or a blocking statute, and whether a comity challenge or motion to quash is viable. Third, negotiate scope and timing with prosecutors, narrowing date ranges and custodians, before litigating. Timelines here can be measured in weeks rather than months, so move decisively.

Scenario B, Foreign Prosecutor Requests Evidence Held in the U.S. (Inbound MLAT)

When a foreign government seeks evidence located in the United States, the request typically arrives through OIA as an inbound MLAT, executed via U.S. legal process. If your company is the custodian, you may receive a subpoena or order issued to satisfy the foreign request. Verify the legal basis, confirm whether confidentiality obligations apply, and assess U.S. privilege and any conflicting obligations. Engage counsel to confirm the production is properly authorized and to negotiate scope, just as you would with a domestic demand.

Scenario C, Provider Receives Conflicting Legal Processes

A provider holding your company’s data may face a U.S. demand and a conflicting foreign court order. The CLOUD Act’s comity framework allows covered providers, in defined circumstances, to raise conflicts with the law of a qualifying foreign government, and the company should coordinate closely with the provider’s legal team. Document the conflict, preserve all data, and consider whether MLAT channeling, a comity motion or negotiation can resolve the clash without exposing the company to penalties in either jurisdiction. Where personal data is involved, fold the data-protection analysis into the conflict assessment.

Comparison Table: MLAT vs. Letters Rogatory vs. CLOUD Act vs. Domestic Subpoena

The table below summarizes the four principal mechanisms behind cross-border evidence requests usa, helping compliance teams anticipate the authority, pace and trade-offs of each approach. Timelines are general estimates and vary significantly by jurisdiction and matter.

Mechanism Typical use Issuing authority Typical timeline Pros Cons Preferred when
MLAT Criminal evidence located abroad Prosecutor via DOJ OIA to foreign central authority Months to a year or more Enforceable; treaty-backed Slow; scope and local-law limits Compelling criminal evidence overseas
Letters rogatory / Hague Civil and fact-finding abroad Court to foreign court or central authority Months to over a year Available absent a treaty Unpredictable; discovery declarations Civil matters; no criminal treaty
CLOUD Act / executive agreement Provider-held data across borders Domestic process on U.S. provider Weeks Faster; custody-based reach Comity and data-protection conflicts Data held by a U.S. provider
Domestic subpoena Data in company custody or control Grand jury, agency or court Days to weeks Fast; familiar procedure Foreign law may restrict production Evidence within company control

Costs, Delays and When to Seek Judicial Relief

Cross-border evidence gathering is expensive and often slow, and companies should budget and plan accordingly rather than being surprised mid-response.

Common Cost Drivers

The principal cost drivers include certified translation of requests and returned evidence, retention of local counsel in each affected jurisdiction, forensic collection and review across multiple data environments, privilege review before cross-border transfer, and compliance audits to confirm lawful handling of personal data. Delays compound costs: the longer a matter runs, the more custodians depart, systems migrate and data-retention schedules threaten evidence.

Grounds for Seeking Judicial Relief in the U.S.

When a demand is overbroad, unduly burdensome or conflicts with foreign law, a motion to quash or modify may be appropriate. The CLOUD Act’s comity provision offers a statutory basis for covered providers, in defined circumstances, to challenge process that conflicts with a qualifying foreign government’s law. Separately, 28 U. S. C. § 1782 permits interested persons to apply to U. S. courts for evidence for use in foreign or international tribunals; it is a tool for assisting foreign proceedings, not a mechanism for U. S. prosecutors to compel foreign evidence, and companies sometimes encounter it when they are the target of a foreign litigant’s U. S. discovery application.

Before litigating, weigh the cost, the likelihood of success, the relationship with enforcement authorities and the risk that resistance invites broader scrutiny.

Practical Tools: Templates, Scripts and Preservation Language

The short snippets below give in-house teams a starting point. Adapt them to the facts and have counsel review before use.

Short Preservation Template for IT and Security

“Effective immediately, suspend all automatic deletion, archiving and overwriting for the following custodians, mailboxes, cloud tenants and systems [list]. Preserve data in place, including metadata and backups. Do not collect, move or alter any materials without instruction from Legal. Confirm receipt and completion to [name].”

Executive Notification Script

“We have received a cross-border evidence request relating to [general subject]. Legal has issued a litigation hold and engaged outside and local counsel. Please route all related questions to [counsel] and avoid discussing the matter in writing. We will brief the board through counsel. Treat this as confidential.”

Suggested Language for Foreign Counsel Engagement

“We retain you to advise on local privilege, data-protection and blocking-statute issues, and to represent the company’s interests in any local process arising from this matter, coordinating with U.S. counsel under privilege.”

Conclusion and Next Steps

Responding to cross-border evidence requests usa in 2026 demands speed, discipline and a clear grasp of which mechanism is in play, MLAT, letters rogatory, CLOUD Act or domestic subpoena. The decisive actions are familiar but easy to neglect under pressure: issue a legal hold and preserve data in place within the first hours, identify the mechanism and the actor driving it, protect privilege before any cross-border transfer, run a data-protection conflict analysis, and engage U. S. and local counsel early. Escalate to the board through counsel, document every decision, and resist the temptation to produce quickly before scope and legal conflicts are resolved.

For deeper tactical guidance, consult supporting resources on preserving privilege in cross-border investigations, responding to MLAT requests, and working with foreign counsel during a U. S. white-collar probe.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jan Lawrence Handzlik at Handzlik & Associates APC, a member of the Global Law Experts network.

Sources

  1. U.S. Department of Justice, Office of International Affairs (OIA)
  2. U.S. Department of State
  3. Congress.gov, H.R. 1625, Consolidated Appropriations Act, 2018 (including the CLOUD Act)
  4. Cornell Law School LII, 18 U.S.C. § 2703 (Stored Communications Act)
  5. Hague Conference on Private International Law, Evidence Convention
  6. Cornell Law School LII, 28 U.S.C. § 1782
  7. American Bar Association

FAQs

How can U.S. prosecutors obtain evidence located in another country?
Through MLATs, letters rogatory (often under the Hague Evidence Convention in civil matters), mutual administrative requests between agencies, or via the CLOUD Act and executive agreements that enable certain direct requests to U.S. providers. Each route involves different actors, timelines and legal constraints.
An MLAT is a treaty-based request for criminal assistance between designated central authorities, for the United States, the DOJ Office of International Affairs. Execution varies by country, commonly taking several months and often a year or more for complex evidence.
Not automatically, but after the CLOUD Act, U.S. legal process can reach provider-held data based on the provider’s possession, custody or control under 18 U.S.C. § 2703, regardless of storage location. Conflicts with foreign law may still complicate or limit execution.
Issue a legal hold, preserve data and metadata in place, instruct IT not to alter chain of custody, serve preservation requests on providers, assess privilege and data-protection conflicts, and engage U.S. and local counsel, following the 24-hour checklist in this guide.
Promptly when evidence or custodians sit in the foreign jurisdiction, when local law may restrict disclosure, or when a local court process or foreign regulator is involved. Early engagement helps prevent inconsistent positions across jurisdictions.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How U.S. Authorities Obtain Cross‑border Evidence in White‑collar Investigations (USA 2026): What Companies & Executives Must Do

Send welcome message

Custom Message