The bill strengthens secure, audited storage and custody of digital child sexual-abuse evidence to aid investigations and protect victims, while creating privacy risks, reduced vendor incentives to prevent misuse, higher domestic-data costs, and additional administrative burdens.
Law enforcement can store and access digital child sexual-abuse evidence more quickly and securely through vetted cloud vendors, improving investigations and prosecutions.
Approved vendors must meet NIST cybersecurity standards and undergo annual audits, reducing the risk of data breaches of sensitive evidence.
Clear retention and custody rules help preserve evidence for prosecution and appeals, supporting victims' cases and judicial reliability.
Storing intimate visual depictions and digital forgeries—even with safeguards—creates substantial privacy and abuse risks if access controls or audits fail.
Liability shields for vendors may reduce incentives to prevent improper access or misuse unless high misconduct thresholds are met.
A U.S.-only data residency requirement could raise costs and complicate cross-border investigations, burdening state and local agencies and vendors.
Based on analysis of 2 sections of legislative text.
Creates an "approved vendor" program allowing contracted cloud providers to store/process child sexual material under NIST-based controls and limits their liability when compliant.
Official title: Limit liability for certain entities storing child sexual abuse material for law enforcement agencies, and for other purposes.
Introduced October 21, 2025 by Marsha Blackburn · Last progress May 21, 2026
Creates a federal "approved vendor" program that lets law enforcement and prosecutors contract with cloud service providers to store, maintain, and process child sexual material and intimate visual depictions of minors, subject to specified cybersecurity, access, auditing, and operational requirements tied to NIST standards. The bill limits civil and criminal liability for those approved vendors when they perform the covered services, except for conduct that is intentional, reckless, malicious, or otherwise specifically excluded, and conditions immunity on meeting the statutory security and operational rules.