Privacy Law Directory
How privacy laws, surveillance laws, MLATs, and intelligence alliances interact across 38 jurisdictions
About This Directory
A living directory covering 38 jurisdictions, last updated July 29, 2026. Each page covers surveillance laws, intelligence agencies, MLATs, data sharing agreements, data retention, cable infrastructure, age verification, encryption policy, and commercial surveillance procurement, not just data protection legislation. Organized around the alliances, conventions, and data-sharing frameworks that determine how intercepted communications and stored data actually move between governments: the signals-intelligence alliances (Five, Nine, and Fourteen Eyes, the Pacific SSPAC, and Europe’s Maximator), the Club de Berne and its separate Counter Terrorism Group, the EU law-enforcement frameworks (Europol, Schengen, Prüm), the mutual legal assistance treaties and conventions (bilateral MLATs, the 1959 European Convention, the Budapest Convention, and the US CLOUD Act), and the regional blocs (ASEAN, Mercosur, the Nordic-Baltic circle, and the Five Power Defence Arrangements).
Contrary to popular belief and heavy marketing, you are NOT protected by the country's privacy laws if you are foreign traffic to the service. Foreign traffic falls under surveillance laws, MLATs, and other data sharing agreements in every jurisdiction below. Think of jurisdictions like an attack surface, the more you add, the more possible MLATs and data sharing agreements you become subject to and these agreements and treaties are designed to simplify data requests and sharing.
You are also not necessarily protected by E2EE, either, because the data most requested is the metadata that cannot be encrypted.
(see Metadata Is Enough: Why Encrypted Email Still Tells Them Almost Everything with examples of it in action).
Nearly every nation here exempts its intelligence agencies from privacy laws when targeting foreigners. These exemptions, combined with alliances that let partner nations collect on each other’s populations and share results back, structurally bypass domestic protections. Commercial surveillance adds another layer: data brokers, IXP monitoring, and spyware vendors sell directly to governments without judicial oversight.
Why MLATs Matter
Mutual Legal Assistance Treaties (MLATs) let governments compel production of evidence located in another country’s jurisdiction. Country A asks Country B to obtain data and hand it back. The MLAT itself defines what can be requested and how, not the domestic privacy laws of either country.
The asymmetry: a French citizen whose data is held by a US company (Gmail, Microsoft, etc.) may have strong GDPR protections that would make it difficult for France to obtain that data domestically. But France can submit an MLAT request to the US DOJ, which compels the US company to produce the data under the terms of the treaty, routing around the stronger domestic standard entirely.
The reverse also works. US law enforcement can use MLATs to obtain data held abroad that might be harder to get domestically. The Fourth Amendment imposes warrant requirements, probable cause standards, and exclusionary rules. But if data is obtained via MLAT, US courts have generally held that the Fourth Amendment’s exclusionary rule doesn’t apply to evidence produced under treaty obligations, unless US agents were so involved that it was essentially a joint operation.
Corrections: updates@codamail.com.
United States
The United States is the lead nation of the Five Eyes and the core node of the Nine and Fourteen Eyes, of SSPAC, and of Five Eyes Plus; a member of the Quad; a party to the Budapest Convention (2007), to the OAS Inter-American mutual-assistance convention, and to the three near-universal UN assistance conventions (the 1988 Vienna drug convention, UNTOC, and UNCAC); and the hub of the global MLAT and CLOUD Act network, with reciprocal CLOUD Act agreements in force with the United Kingdom and Australia and an operational agreement with Europol. It runs warrantless global foreign collection under FISA Section 702 and Executive Order 12333. The CLOUD Act is designed to surpass MLATs in speed and compels US providers and partners to the Act to produce data anywhere it is located. The NSA taps submarine cables and internet backbones worldwide in partnership with many other countries. The US has no comprehensive privacy law, instead, a sector-specific patchwork (HIPAA, FERPA, GLBA, COPPA, ECPA), no data-retention mandate, and no encryption restrictions, with consumer protection left to an uneven set of state laws.
- United States Federal Privacy & Surveillance Laws
- MLATs: 65+ partner countries; full set in the US DOJ list of Mutual Legal Assistance Treaties, plus reciprocal CLOUD Act agreements with the UK and Australia.
- California (CCPA/CPRA)
- US State Privacy Laws Overview
Five Eyes Alliance
The Five Eyes is the core anglophone signals intelligence alliance under the UKUSA Agreement (1946). Member nations share raw signals intelligence by default and can collect on each other’s citizens and share it back, a structure that critics argue functions as a mechanism to circumvent domestic legal restrictions on surveilling one’s own population.
- United Kingdom (also SSPAC, FPDA, Club de Berne, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States; full set in UK Treaties Online.
- Canada (also SSPAC, Budapest)
- MLATs: Antigua and Barbuda, Argentina, Australia, Austria, Bahamas, Barbados, Belgium, Brazil, China, Cuba, Czech Republic, France, Germany, Greece, Hong Kong, Hungary, India, Israel, Italy, Jamaica, Kazakhstan, Kenya, Luxembourg, Mexico, Netherlands, Norway, Peru, Poland, Portugal, Romania, Russia, South Africa, South Korea, Spain, Sweden, Switzerland, Thailand, Trinidad and Tobago, Ukraine, United Kingdom, United States, and Uruguay (40+). Full set in the Canada Treaty Information database.
- Australia (also SSPAC, FPDA, Budapest)
- MLATs: Argentina, Austria, Brazil, Canada, China, Ecuador, Finland, France, Greece, Hong Kong (suspended 2020), Hungary, India, Indonesia, Israel, Italy, Republic of Korea, Luxembourg, Malaysia, Mexico, Monaco, the Netherlands, the Philippines, Portugal, Spain, Sweden, Switzerland, Thailand, the United Arab Emirates, the United Kingdom, the United States, and Vietnam (31). Full set in the Attorney-General’s register.
- New Zealand (also SSPAC, FPDA, Budapest)
- MLATs: Republic of Korea, China, and Hong Kong (suspended); full set in New Zealand Treaties Online.
Nine Eyes Alliance
The Nine Eyes extends the Five Eyes by four European nations who share signals intelligence as “third party” partners under the UKUSA framework. Unlike Five Eyes members, third-party partners are not automatically exempt from being targeted by NSA collection.
- Denmark (also Maximator, NB8, EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: no standalone US treaty (covered by the EU-US agreement); Danish treaties searchable in Retsinformation (Traktater).
- France (also SSPAC, Maximator, EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States (1998), plus judicial-cooperation conventions with Francophone and Maghreb states; full set in the French treaty database.
- Netherlands (also Maximator, EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States (1981) and the Benelux Treaty (Belgium, Luxembourg); full set in the Verdragenbank.
- Norway (also NB8, Club de Berne, Schengen/Prüm/Europol, Council of Europe, Budapest, 1959 Convention)
- MLATs: no standalone US treaty (via the Council of Europe conventions and the 2003 EU-Norway agreement); Norwegian treaties in the traktatregisteret.
Fourteen Eyes Alliance (SIGINT Seniors Europe)
SIGINT Seniors Europe, commonly known as the Fourteen Eyes, adds five more nations to the Nine Eyes framework. The alliance was formed in 1982 during the Cold War and expanded after September 2001 to include counterterrorism cooperation.
- Germany (also Maximator, EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, Switzerland, Morocco, and Tunisia (plus a statutory power to assist any state); treaties published in the Bundesgesetzblatt Teil II via recht.bund.de.
- Belgium (also EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States (1988) and the Benelux Treaty (Netherlands, Luxembourg); full set in the FPS Foreign Affairs treaties database.
- Italy (also EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States (1982); full set in the ITRA treaties archive.
- Sweden (also Maximator, NB8, EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, Hungary, Poland, France, and the United Kingdom; full set in Sveriges internationella överenskommelser (SÖ).
- Spain (also EU, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, plus judicial-cooperation treaties with Ibero-American states; full set in the BOE legislation database.
European Union (Europol / Schengen / Prüm)
All EU member states are subject to the GDPR, the ePrivacy Directive, and the Law Enforcement Directive, but Article 2(2) exempts national security, an exemption every member state uses. On the surveillance side they are bound into a shared law-enforcement data-sharing architecture, Europol, the Schengen Information System, the Prüm biometric network, and the European Investigation Order, and their security services participate in the Club de Berne. The member states listed here are not part of any Eyes alliance; those that are (Denmark, France, and the Netherlands in the Nine Eyes; Germany, Belgium, Italy, Sweden, and Spain in the Fourteen Eyes) appear under those headings above.
- European Union Framework (the foundational framework page)
- Austria (also Council of Europe, Budapest, 1959 Convention)
- MLATs: United States (1995); intra-Europe assistance runs through the 1959 Convention (Austria maintains few standalone bilaterals).
- Czechia (also Council of Europe, Budapest, 1959 Convention)
- MLATs: United States; full set in the Czech treaty database.
- Estonia (also NB8, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, its Baltic neighbours, and Russia; full set in the Riigi Teataja treaties database.
- Finland (also NB8, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States; full set in the Finlex treaty series.
- Greece (also Council of Europe, Budapest, 1959 Convention)
- MLATs: United States; full set in the Government Gazette database.
- Hungary (also Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, plus an extensive inherited bilateral network; full set in net.jogtar.hu.
- Ireland (Europol; outside Schengen; Council of Europe, 1959 Convention)
- MLATs: searchable in the Irish Treaty Series.
- Latvia (also NB8, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, its Baltic neighbours, Russia, and Poland; full set in likumi.lv.
- Lithuania (also NB8, Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, its Baltic neighbours, and Russia; full set in the e-Seimas database.
- Luxembourg (also Council of Europe, Budapest, 1959 Convention)
- MLATs: United States and the Benelux Treaty (Belgium, the Netherlands); full set in Legilux.
- Poland (also Council of Europe, Budapest, 1959 Convention)
- MLATs: United States; full set in the treaty database (Internetowa Baza Traktatowa).
- Portugal (also Council of Europe, Budapest, 1959 Convention)
- MLATs: searchable in the Diário da República.
Asia-Pacific Partners (SSPAC)
SIGINT Seniors of the Pacific (SSPAC) is the Asia-Pacific counterpart to SIGINT Seniors Europe. Founded by the Five Eyes nations alongside South Korea, Singapore, and Thailand, later joined by France (2013) and India (2008). Members share counterterrorism intelligence through the CRUSHED ICE secure network. Like Nine Eyes third-party partners, SSPAC members are not automatically exempt from being targeted by NSA collection.
- Singapore (also FPDA, ASEAN)
- MLATs: no full US treaty (a limited drug-crimes agreement only), Switzerland (2016), the ASEAN MLAT (2004), and its domestic MACMA regime; statutes in Singapore Statutes Online.
- South Korea (also Five Eyes Plus, 1959 Convention)
- MLATs: United States, plus the 1959 European Convention (acceded 2011); full set in the Korea Law Information Center.
- India (also BRICS, SCO, Quad)
- MLATs: 39 partners including the United States and the United Kingdom; full set in the Indian Treaties Database.
- Thailand (also ASEAN)
- MLATs: United States and the ASEAN MLAT (2004); full set in the MFA treaty database.
Other Partners and Transit States
The jurisdictions below are not members of the numbered Eyes alliances, SSPAC, or the EU, but each participates in intelligence data sharing, has its traffic transit through partner nations’ cable-tapping infrastructure, or maintains its own foreign surveillance capabilities with few restrictions on non-citizen targeting. The recurring pattern across this directory applies here as well: privacy laws protect domestic populations while foreign traffic faces minimal legal barriers to interception.
- Switzerland (also Club de Berne; Schengen/Prüm/Europol associate; Council of Europe, Budapest, 1959 Convention)
- MLATs: United States (1973), Australia (1991), Canada (1993), Peru (1997), Ecuador (1997), Hong Kong (1999), Egypt (2000), the Philippines (2002), Brazil (2004), Mexico (2005), Algeria (2006), Chile (2006), Argentina (2009), Colombia (2011), Indonesia (2019), Kosovo (2022), and Panama (2023), plus supplementary treaties with Germany, Austria, France, and Italy (17). Full set in Fedlex chapter 0.351.
- Iceland (also NB8; Schengen/Prüm/Europol associate; Council of Europe, Budapest, 1959 Convention)
- MLATs: no standalone US treaty (assistance via the Council of Europe conventions and the EEA); Icelandic treaties in Stjórnartíðindi.
- Liechtenstein (Schengen/Prüm/Europol associate; Council of Europe, Budapest, 1959 Convention)
- MLATs: United States (2002/2003); other treaties in gesetze.li.
- Israel (bilateral NSA raw-data sharing; Kilowatt Group; Budapest, 1959 Convention)
- MLATs: United States (1998); party to the 1959 European Convention; full set in the Israel Treaty Series (Kitvei Amana) database.
- Japan (Five Eyes Plus, Quad, Budapest)
- MLATs: United States (2006), the Republic of Korea, and China; full set in the MOFA treaties database.
- Turkey (bilateral NSA SIGINT partner; Council of Europe, Budapest, 1959 Convention)
- MLATs: United States, plus a wide bilateral network; treaties published in the Official Gazette (Resmî Gazete).
- Malaysia (also ASEAN, FPDA)
- MLATs: United States, China, Australia, India, Hong Kong, and the ASEAN MLAT (2004); statutes via the Attorney General’s Chambers.
- Brazil (also Mercosur, BRICS, Budapest)
- MLATs: United States, Canada, Chile, China, Colombia, Ecuador, Germany, Grenada, Guyana, Hong Kong, India, Ireland, Italy, Jordan, Kazakhstan, Mexico, Morocco, the Netherlands, Nigeria, Panama, Paraguay, the Philippines, Romania, Spain, Sweden, Thailand, Ukraine, the United Arab Emirates, Uruguay, and Vietnam (30+), plus the Inter-American Convention and the Mercosur MLA Protocol. Full set in the Concórdia treaty database.
1959 European Convention on Mutual Assistance
The European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30) is the general framework for cross-border criminal evidence in Europe. As of 2026 it has 51 parties: all 46 Council of Europe member states plus five non-members, Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation (which remains a party despite its 2022 expulsion from the Council of Europe).
Budapest Convention on Cybercrime
The Budapest Convention on Cybercrime (2001, ETS 185) provides for the expedited preservation and cross-border disclosure of stored computer and subscriber data, the category of data an email or messaging provider holds. As of 2026 it has 82 parties: 45 Council of Europe member states (every member except Ireland, which signed but has not ratified) plus 37 non-member states across the Americas, Africa, and the Asia-Pacific, among them the United States, Canada, Australia, Japan, Brazil, and Israel.
Global Mutual Assistance Conventions (UN and OAS)
Three near-universal United Nations conventions each carry their own mutual-legal-assistance machinery, so evidence can move between two countries that share no bilateral MLAT and no regional convention at all. The 1988 Vienna Convention (the UN Convention against Illicit Traffic in Narcotic Drugs and Psychotropic Substances) obliges its 192 parties to provide the widest measure of mutual assistance in drug-trafficking investigations, including banking, financial, and business records. The UNTOC (UN Convention against Transnational Organized Crime, the “Palermo Convention,” 2000) functions through its Article 18 as a de facto worldwide MLAT for organized-crime cases, spanning 193 parties. The UNCAC (UN Convention against Corruption, 2003) does the same for corruption offences across 192 parties, including tracing, freezing, and confiscation of assets. Like Interpol and the Egmont Group, these networks are effectively universal, so no roster is given; the practical point is that a “no MLAT with that country” assurance says nothing about drug, organized-crime, or corruption investigations, where these conventions supply the treaty basis on their own.
The OAS Inter-American Convention on Mutual Assistance in Criminal Matters (1992, in force 1996) is the regional instrument of the Americas, with 27 parties: Antigua and Barbuda, Argentina, the Bahamas, Bolivia, Brazil, Canada, Chile, Colombia, Costa Rica, Dominica, Ecuador, El Salvador, Grenada, Guatemala, Guyana, Honduras, Jamaica, Mexico, Nicaragua, Panama, Paraguay, Peru, Suriname, Trinidad and Tobago, the United States (2001), Uruguay, and Venezuela; status is tracked in the OAS signatures chart (A-55). The United States, Canada, and Brazil are the parties covered in this directory.
Council of Europe
The Council of Europe is a 46-member human-rights and rule-of-law organisation, distinct from the European Union. It is the parent body of the two mutual-assistance conventions above, the 1959 Convention and the Budapest Convention, both concluded under its treaty system. It is also the home of the European Convention on Human Rights and the European Court of Human Rights in Strasbourg, which has repeatedly found mass-surveillance regimes in breach of the Convention (among them the United Kingdom’s bulk interception in Big Brother Watch and Sweden’s FRA cable-tapping in Centrum för Rättvisa). Every European jurisdiction in this directory is a member; the Russian Federation was expelled in 2022. Non-European parties to its conventions, such as the United States, Israel, Japan, and Brazil, are not members.
Maximator (European SIGINT)
Maximator is a European signals-intelligence alliance kept secret from 1976 until its disclosure in 2020, comprising Denmark, France, Germany, the Netherlands, and Sweden. Members pooled intercepted communications, including intelligence derived from the rigged Crypto AG cipher devices. All five are listed under the Nine and Fourteen Eyes above.
Club de Berne and the Counter Terrorism Group
The Club de Berne, founded in 1969, is the forum of the heads of the domestic intelligence and security services of the 27 EU member states together with Norway and Switzerland. It is a broad, all-source intelligence-sharing body for the strategic direction of European intelligence cooperation, not a counterterrorism-specific one. The Counter Terrorism Group (CTG) is a separate offshoot, created in September 2001 after the 11 September attacks and dedicated specifically to sharing terrorism intelligence; its membership overlaps the Club’s and additionally includes the United Kingdom. Since 2016 the two have run a joint operational platform in The Hague with a common database and real-time information system. Every EU member state on this page takes part in the Club de Berne, along with Norway and Switzerland; the CTG adds the UK.
A separate and older channel is the Kilowatt Group, a counter-terrorism intelligence-sharing club dating to the early 1970s that exchanges information among Western services, reported as some 17 European countries and the United States, over the “Kilowatt” encrypted telegram system. Its significance in this directory is Israel: not a Club de Berne or CTG member, Israel participates in Kilowatt, giving it a standing counter-terrorism exchange with the European services outside the EU frameworks.
Europol
Europol is the EU Agency for Law Enforcement Cooperation, constituted by the 27 EU member states. It also maintains operational cooperation agreements (permitting personal-data exchange and liaison officers) with seventeen non-EU states, Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States, with Denmark participating under a separate agreement owing to its Justice and Home Affairs opt-out. Because Europol in turn cooperates with the FBI, data routed through it can flow onward to US law enforcement.
Schengen Information System
The Schengen Area comprises twenty-nine states whose police share real-time alerts through the Schengen Information System: Austria, Belgium, Bulgaria, Croatia, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, the Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden, and Switzerland. The four non-EU members (Iceland, Liechtenstein, Norway, and Switzerland) participate as associated states; Ireland and Cyprus are EU states outside the Schengen Area.
Prüm Framework
The Prüm framework automates cross-border exchange of DNA profiles, fingerprints, and vehicle-registration data. It binds all 27 EU member states together with the four non-EU Schengen-associated states (Iceland, Liechtenstein, Norway, and Switzerland), thirty-one in all; the Prüm II Regulation (2024) extends it to facial images and police records.
Regional Frameworks
Beyond the SIGINT alliances, several regional blocs move intelligence and evidence across borders. Their members appear under their biggest alliance above; the rosters are:
- Nordic-Baltic Eight (NB8): Denmark, Estonia, Finland, Iceland, Latvia, Lithuania, Norway, and Sweden, the five Nordic states plus the three Baltic states, for cybersecurity and hybrid-threat cooperation.
- ASEAN: the 2004 ASEAN Mutual Legal Assistance Treaty binds all ten member states (Brunei, Cambodia, Indonesia, Laos, Malaysia, Myanmar, the Philippines, Singapore, Thailand, and Vietnam); those covered here are Malaysia, Singapore, and Thailand.
- Mercosur: the San Luis mutual-assistance protocol covers Argentina, Brazil, Paraguay, and Uruguay; Brazil is covered here.
- Five Power Defence Arrangements (FPDA): a 1971 consultative defence pact linking the United Kingdom, Australia, New Zealand, Malaysia, and Singapore, with a counter-terrorism and maritime intelligence-sharing dimension.
- Benelux Treaty: the 1962 Benelux Treaty on Extradition and Mutual Assistance in Criminal Matters (amended 1974) provides a streamlined assistance framework among its three members, Belgium, the Netherlands, and Luxembourg, layered beneath the EU instruments.
- Global CBPR Forum: the cross-border data-transfer certification system grown out of the APEC CBPR rules (2022), with nine members, Australia, Canada, Japan, Mexico, the Philippines, Singapore, South Korea, Chinese Taipei, and the United States, plus the United Kingdom as an associate; a trade-facilitation channel for personal data rather than a law-enforcement one, but part of the same cross-border plumbing.
Strategic Blocs (BRICS, SCO, Quad)
Several jurisdictions here also belong to strategic and political blocs that carry security and intelligence dimensions, though not the formal mutual-assistance machinery of the frameworks above:
- BRICS: eleven members as of 2026, Brazil, Russia, India, China, South Africa, Egypt, Ethiopia, Iran, Saudi Arabia, the United Arab Emirates, and Indonesia; covered here: Brazil and India.
- Shanghai Cooperation Organisation (SCO): a Eurasian security bloc of ten members, China, Russia, India, Pakistan, Kazakhstan, Kyrgyzstan, Tajikistan, Uzbekistan, Iran, and Belarus; covered here: India.
- Quad: the security dialogue among the United States, Japan, India, and Australia; covered here: India and Japan (Australia and the United States appear under the Eyes headings above).
Cable Infrastructure and Interception Points
The physical layer beneath the alliances: the documented submarine-cable and backbone taps, internet-exchange interception, and cable chokepoints through which cross-border traffic is collected. Programs are named where public disclosure (largely the Snowden documents and subsequent court findings) has identified them.
Backbone and Submarine-Cable Taps
- United States: Room 641A (the NSA fibre-optic splitter in AT&T’s San Francisco facility exposed by whistleblower Mark Klein), with similar rooms in 10+ cities; the Upstream corporate-access programs FAIRVIEW (AT&T), STORMBREW, BLARNEY, and OAKSTAR; and PRISM.
- United Kingdom: Tempora (GCHQ bulk cable interception at the Bude landing station in Cornwall) with the Edgehill decryption effort, plus the Oman cable base; the take is shared with some 250 NSA analysts.
- Germany: Operation Eikonal (a BND-NSA tap on traffic at DE-CIX Frankfurt) and continuing BND bulk interception at the exchange.
- Denmark: Operation Dunhammer (the Danish FE giving the NSA access to Danish landing cables, run from the Sandagergård facility with XKeyscore).
- Sweden: FRA cable-tapping of the Baltic cables (ruled in breach of the ECHR in Centrum för Rättvisa).
- Belgium: Operation Socialist (GCHQ’s compromise of Belgacom/BICS to reach EU and roaming traffic).
- Canada: Levitation (CSE mass-monitoring of file-sharing downloads), alongside XKeyscore.
- Australia: access to the SEA-ME-WE cable systems and XKeyscore, with Pine Gap for satellite collection.
- New Zealand: interception of the Southern Cross Cable, the Waihopai station, and XKeyscore.
- Switzerland: NDB cable reconnaissance (Kabelaufklärung) of cross-border fibre, plus the Onyx satellite system.
- Singapore: the SID’s tapping of SEA-ME-WE-3 via SingTel, making Singapore a collection platform for maritime Southeast Asia.
- Brazil: NSA collection under FAIRVIEW and STORMBREW (the interception of President Rousseff and Petrobras).
Internet Exchange Point (IXP) Taps
- DE-CIX (Frankfurt): the world’s largest internet exchange, subject to BND interception; the transit traffic of Austria, Czechia, Estonia, Hungary, Lithuania, Luxembourg, and Poland passes through it.
- AMS-IX (Amsterdam), LINX (London), BIX (Budapest), and MyIX (Malaysia) are the other major exchanges named across this directory.
Cable Chokepoints and Landing Hubs
Strategic points where cross-border traffic is physically concentrated: Crete (Greece, the Europe-Middle East-Asia hub), Sicily (Italy, the Mediterranean hub), Sines and Carcavelos (Portugal, a three-continent Atlantic hub), the Strait of Gibraltar (Spain), the Strait of Malacca (Malaysia), and the Baltic cables C-Lion1 and BCS East-West Interlink (Finland and Estonia), repeatedly cut or sabotaged since 2023.
Directory Information
This directory covers 41 pages across 38 country jurisdictions, including dedicated coverage of US federal and state privacy laws, the EU framework, and international partners. It is maintained by CodaMail as a public resource for understanding the global privacy and surveillance landscape. Pages are updated as new legislation, enforcement actions, and intelligence disclosures warrant revision.
This directory grew from The Myth of Jurisdictional Privacy, through Your Phone is a Military Target and the Data Broker Directory (1,700+ entities across 17 categories).
