The bill aims to improve criminal investigations and preserve evidence by allowing vetted private vendors to handle CSAM under strict cybersecurity and retention rules, but it trades off reduced vendor liability and increased reliance on contractors against heightened risks to victim privacy, potential accountability gaps, and complications for cross‑border investigations.
Law enforcement agencies (federal, state, and local) can contract vetted private vendors to securely store and forensically process child sexual abuse material (CSAM), improving evidence handling and strengthening investigations and prosecutions.
Government contractors and law enforcement benefit from mandatory NIST-based cybersecurity safeguards and annual independent audits for approved vendors, raising technical protections for highly sensitive evidence and reducing risk of unauthorized access.
Agencies are required to retain evidence consistent with applicable retention rules or at least through relevant statutes of limitations or sentences, preserving material needed for prosecution, appeals, and case continuity.
Victims and the public may lose avenues for redress because limits on civil and criminal suits against vendors reduce accountability when sensitive material is mishandled or misconduct falls outside narrow exceptions.
Allowing private contractors to store CSAM, even with controls, creates a substantial risk that a data breach or safeguard failure could expose victims and retraumatize them if material is leaked.
Requiring that evidence remain in the United States could complicate multi‑jurisdictional investigations and forensic cooperation with foreign partners, potentially slowing or limiting some cross-border probes.
Based on analysis of 2 sections of legislative text.
Authorizes law enforcement to use designated private cloud/forensic vendors to store and process child pornography/obscenity, grants vendors limited liability, and requires NIST-based cybersecurity safeguards.
Official title: To limit liability for certain entities storing child sexual abuse material for law enforcement agencies, and for other purposes.
Introduced March 5, 2026 by Laurel Lee · Last progress March 5, 2026
Authorizes federal, state, and local law enforcement and prosecutors to use designated "approved vendors" to store, maintain, and perform forensic processing on child pornography and defined child obscenity material in the cloud. It creates limited liability protections for those approved vendors when performing covered law-enforcement services, preserves liability for intentional or grossly negligent misconduct, and imposes cybersecurity and access-control requirements for how vendors must protect and allow access to such material. The bill adds the definitions and authorities into the PROTECT Our Children Act framework, sets a liability shield with specific exceptions for misconduct, and requires vendors to follow the most recent NIST Cybersecurity Framework and other access controls for any stored or processed materials. No funding, criminal penalties, or implementation timelines are specified in the provided text.