KIP Viewer







German DSA Documents: Data-Risk Briefing


German
institutions in the House Judiciary DSA document production

What
the records show, whose data appears, how Congress obtained it,
and why German organizations should care

Status: Evidence-based interim assessment, 16
July 2026. This is a journalistic analysis, not legal advice.

Executive conclusion

The material does not look like a conventional
leak. The House Judiciary Committee says it issued
document subpoenas to technology companies and
received tens of thousands of pages of internal records and
communications with foreign regulators. The public appendices
contain company-specific Bates numbers that usually identify the
producer.

For the German material reviewed here, the principal producers
were TikTok, Meta, Google and Microsoft. One
Commission decision was probably supplied by X, but the relevant
pages have no visible Bates stamp, so that attribution is not
conclusive.

The main risk demonstrated for German organizations is
recipient-copy exposure: if a German regulator,
NGO, university, media company or employee communicates with a
large technology platform, the platform retains its own copy,
recipient metadata, attachments and internal annotations. A U.S.
congressional committee can subpoena that copy from the technology
company without subpoenaing the German sender.

This was probably not a CLOUD Act process. The
disclosed process was legislative oversight by Congress, not a
criminal search warrant or Stored Communications Act order. The
CLOUD Act is relevant only as a comparison: it confirms that
location abroad does not necessarily protect data controlled by a
covered provider, but it was not the stated authority for these
subpoenas.

1. What exactly do
the documents show?

German actor What the underlying record shows What it does not show Source and producer
LfM NRW A redacted @medienanstalt-nrw.de recipient
appears on European Commission Code of Practice task-force
mailings, a 2024 mailing about converting the Code into a DSA Code
of Conduct, and a Rapid Response System election mailing.
No reviewed page shows LfM NRW submitting a Rapid Response
System notification, requesting a takedown or replying.
Appendix V Part 1, p. 208, TT_HJC_008468;
Appendix V Part 2, p. 32, TT_HJC_017392; Appendix
VI–VII, pp. 268–269, TT_HJC_016542–016544.
TikTok production.
MA HSH Matthias Forsterling, with a partially redacted
@MA-HSH.de address, was invited to a Commission
subgroup on “empowerment of fact-checkers.” Proposed work included
platform–fact-checker agreements, EU coverage, a common
repository, funding, metrics and technical solutions.
The reviewed kick-off distribution does not clearly establish
that Forsterling or MA HSH joined or participated.
Appendix V Part 1, pp. 280–282,
META-119HJC-0000752–0000755. Meta
production.
BNetzA A December 2024 TikTok email refers to a direct meeting with
BNetzA “on the German election.” TikTok’s privileged EU-election
review also names BNetzA among Digital Services Coordinators it
engaged.
The meeting’s substance and outcome are not disclosed. TikTok
reports five Rapid Response System notifications overall, but does
not attribute them to BNetzA.
Appendix VI–VII, pp. 424–427,
TT_HJC_013475–013478, and pp. 289–301. TikTok
production.
BNetzA in the X case The Commission’s final X decision records BNetzA’s preliminary
view that German satire accounts were clearly marked and that X’s
checkmark explanation was accessible. The Commission rejected this
as insufficiently exculpatory.
The relevant pages do not reveal which company produced the
decision.
Appendix VI–VII, p. 1053. Likely X production, but
unproven because no Bates prefix is visible.
Amadeu Antonio Stiftung TikTok says the foundation supplied localized signals about
extremist ideologies and actors in Germany and Austria, plus
specific audio files and songs, to improve moderation “at
scale.”
The passage does not identify the actors, songs, affected
accounts or number of enforcement actions.
Appendix VI–VII, p. 758, within
TT_HJC_014687–014691. TikTok
production.
German law enforcement, Youthprotect and
FSM
TikTok told the Commission that German law enforcement
submitted two Israel–Hamas-related notices: one livestream had
already ended; a second notice concerning four videos resulted in
an account ban. Youthprotect e.V. and FSM each reported a video
that TikTok removed.
The police bodies, users and content are not named. The record
does not establish that the notices were legally binding
orders.
Appendix I–II, pp. 257–258, TT_HJC_006293–006294.
TikTok production.
DPA and Microsoft Bing Microsoft’s Bing risk assessment says DPA supplied timely,
verified fact-checking data before Germany’s 2025 election. Bing
intended to use the data for “defensive search interventions”
addressing information manipulation; implementation began in April
2025.
It does not disclose which queries or results changed, or
whether an intervention meant demotion, annotation,
authoritative-source promotion or another treatment.
Appendix VI–VII, p. 989, MSFT_JUD_000002572.
Microsoft production.
TU Dortmund Christina Elmer, with a partially redacted
@tu-dortmund.de address, appears on Commission
generative-AI subgroup distributions.
Inclusion on a mailing list does not establish a moderation
request or decision.
Appendix V Part 1, including pp. 328, 384 and 397.
Meta production.

Additional, less sensitive German references include a
TikTok-supported Federal Health Ministry COVID-19 campaign and an
event agenda naming BNetzA official Dr Julia Marquier. No
institutional reference to the Bayerische Landeszentrale
für neue Medien
or an @blm.de address was
detectable in the keyword/OCR review; literal “BLM” hits referred
to Black Lives Matter. This is an absence finding, not proof that
no image-only or OCR-resistant reference exists.

2.
Whose confidential or personal information appears?

Identifiable people
and affiliations

The public appendices expose or partially expose:

  • Matthias Forsterling, MA HSH, with the
    organizational email domain visible but the local part
    substantially redacted.
  • Christina Elmer, TU Dortmund, again with the
    institutional domain visible and the local part redacted.
  • Dr Julia Marquier, BNetzA, with title and
    professional role.
  • One or more unidentified LfM NRW recipients,
    whose local email components are redacted but whose institutional
    domain is visible.
  • Numerous Commission, platform, NGO, fact-checking and academic
    participants in long To: and CC: lists.
    Many names and domains remain readable even where individual email
    components are obscured.

Names, professional affiliations, meeting attendance and
professional email addresses can be personal data under the GDPR
when they identify or make a natural person identifiable. Public
professional information does not automatically cease to be
personal data.

Confidential
institutional and operational information

The appendices also disclose:

  • nonpublic recipient lists and organizational networks;
  • meeting dates, attendance and internal scheduling;
  • Rapid Response System routing, escalation and timing
    mechanics;
  • confidential platform responses to Commission requests for
    information;
  • specific notice and enforcement outcomes;
  • platform risk assessments and moderation methodologies;
  • the operational roles of German NGOs, regulators, law
    enforcement and DPA;
  • platform internal commentary and, in some exhibits, material
    labelled privileged or restricted.

Many TikTok pages are marked “CONTAINS BUSINESS
CONFIDENTIAL INFORMATION”
and “CONFIDENTIAL
TREATMENT REQUESTED.”
Meta pages frequently state
“NOT FOR DISTRIBUTION – MEMBERS & STAFF
ONLY.”
Those legends did not prevent selected pages from
appearing in the public appendices.

Important
distinction: what Congress received versus what the public can
see

The public PDFs contain extensive redactions. The report does
not clearly disclose:

  • whether the Committee received unredacted originals;
  • which party applied each redaction;
  • what data-protection or confidentiality review occurred before
    publication; or
  • whether affected German third parties were notified.

Therefore, the public appendices demonstrate exposure, but not
necessarily the full extent of the information originally produced
to Congress.

3. How was the material
obtained?

Type of subpoena

These were congressional oversight document
subpoenas
issued by the U.S. House Committee on the
Judiciary. They were not:

  • criminal grand-jury subpoenas;
  • search warrants;
  • court-issued discovery subpoenas;
  • Stored Communications Act orders under 18 U.S.C. § 2703;
    or
  • CLOUD Act orders.

The Committee’s February 2025 cover letters sought:

  1. communications between each company and foreign governments
    concerning compliance with foreign content laws, regulations,
    judicial orders or other government-initiated efforts; and
  2. the company’s internal communications discussing those
    foreign-government communications.

The Committee said the companies were within its jurisdiction
and possessed records relevant to legislative oversight. Its press
release said the subpoenas were necessary to permit disclosure
“without interference by foreign governments.” See the House
Judiciary announcement and subpoena links
.

Companies subpoenaed

The report says document subpoenas were issued to ten
companies:

  • Alphabet, Amazon, Apple, Meta, Microsoft, Rumble,
    TikTok and X
    on or around 26 February 2025;
  • Reddit on 17 April 2025; and
  • OpenAI on 5 November 2025.

Being subpoenaed does not prove that every company supplied
documents used in this report. For the German-specific evidence
reviewed, visible Bates prefixes show actual productions by
TikTok, Meta, Google/Alphabet and Microsoft. X is
a likely source for one unstamped Commission decision. No
German-specific material in this review could be confidently
attributed to Amazon, Apple, Rumble, Reddit or OpenAI.

Bates-prefix source key

Prefix Producing company
TT_HJC TikTok
META-119HJC Meta
GOOG-HJCFG Google/Alphabet
MSFT_JUD Microsoft

An Outlook-formatted email does not establish
that Microsoft produced it. For example, the LfM NRW emails carry
TikTok Bates numbers; the MA HSH email carries a Meta Bates
number. Microsoft is directly evidenced only where the pages carry
MSFT_JUD.

4. What made
the subpoenas legally possible?

The principal authority was Congress’s legislative and
oversight power
, implemented through House rules—not the
CLOUD Act.

  • House Judiciary Committee Rule IV allows its
    Chair to authorize and issue a subpoena, after consultation with
    the Ranking Minority Member, for an investigation within the
    Committee’s jurisdiction. It expressly relies on clause
    2(m) of House Rule XI
    . See the Judiciary
    Committee’s rules for the 119th Congress
    .
  • The cover letters cited House Rule X,
    including the Committee’s jurisdiction over civil liberties, as
    the legislative basis for investigating effects on American
    speech.
  • Failure to comply with a valid congressional subpoena can
    potentially lead to contempt proceedings. 2 U.S.C. §§
    192–194
    address refusal to produce papers and
    certification to a U.S. attorney. See the official
    U.S. Code, Title 2, Chapter 6
    .

Unlike a criminal warrant, a congressional subpoena does not
require a judge to find probable cause before issuance. Its
validity instead depends on matters including committee
jurisdiction, legislative purpose, pertinence, procedural
compliance and applicable constitutional or privilege
objections.

5. Was the CLOUD Act
involved?

Probably not. Nothing in the report or subpoena cover
letters identifies the CLOUD Act as the basis for
production.

The CLOUD Act amended the Stored Communications Act. Among
other things, 18 U.S.C. § 2713 requires covered
communications and remote-computing providers to comply with
obligations under that chapter for material within their
possession, custody or control, regardless of whether it is stored
inside or outside the United States. The CLOUD Act also provides a
framework for qualifying foreign governments to obtain electronic
evidence under bilateral executive agreements, particularly for
serious-crime investigations. See the statutory
text of 18 U.S.C. § 2713
and the U.S.
Department of Justice CLOUD Act overview
.

That framework does not match what happened here:

  • the requester was a congressional committee, not a criminal
    law-enforcement authority;
  • the instruments were House oversight subpoenas, not § 2703
    warrants or orders; and
  • the material appears mainly to be the companies‘ own business
    records, employee mailboxes, regulatory correspondence and
    internal analyses—not customer mailbox contents demanded from a
    neutral cloud host.

The practical lesson resembles the CLOUD Act’s “possession,
custody or control” logic, but the legal authority is
different.

6.
What data risk does this demonstrate for German companies and
institutions?

Risks directly
demonstrated by the records

  1. A recipient can disclose the sender’s copy. A
    German organization may never receive a U.S. subpoena, yet its
    email can be produced from TikTok’s, Meta’s, Google’s, Microsoft’s
    or X’s systems.
  2. Metadata can be as revealing as message
    content.
    Recipient lists reveal who participates in a
    policy network, even when individual addresses are partly
    redacted.
  3. Attachments and internal annotations expand the
    exposure.
    The platform may hold not only the original
    message but agendas, risk assessments, internal forwarding chains
    and staff commentary.
  4. Confidentiality labels are not a publication
    guarantee.
    Material marked business-confidential,
    restricted or privileged still appears in the public appendices,
    albeit with redactions.
  5. Redaction may not prevent re-identification.
    A visible name, job title, date, meeting topic and institutional
    domain can identify a person even when the email local part is
    blacked out.
  6. Operational partnerships can become public.
    The DPA–Bing and Amadeu Antonio Stiftung–TikTok passages reveal
    how German third parties supplied data or signals used in platform
    interventions.

Risks the records do
not prove

  • They do not show Microsoft opening or exporting German
    customers‘ Microsoft 365 mailboxes.
  • They do not show that Congress obtained data directly from
    German servers.
  • They do not establish that any technology company violated the
    GDPR, contractual confidentiality or German law.
  • They do not reveal which corporate entity made each transfer,
    where the responsive data was stored, or which GDPR transfer
    mechanism was used.
  • They do not show mass disclosure of ordinary German platform
    users‘ private messages; the reviewed German examples concern
    institutional and business communications.

7. GDPR and
cross-border-transfer questions

If personal data subject to the GDPR was transferred from an
EEA controller or processor directly in response to a U.S.
congressional demand, Article 48 GDPR is potentially
relevant
.

Article 48 says that a third-country court judgment or
administrative-authority decision requiring disclosure may be
recognized or enforceable only if based on an international
agreement, such as a mutual legal assistance treaty, without
prejudice to other Chapter V transfer grounds. The EDPB’s final
2025 guidance says a foreign request does not itself supply a
lawful basis: the controller must assess both a legal basis under
Article 6 and a valid Chapter V transfer ground. See the EDPB
Guidelines 02/2024 on Article 48 GDPR, version 2.1
.

However, the appendices are insufficient to conclude that
Article 48 was breached because they do not identify:

  • the legal entity that responded;
  • whether the relevant processing was subject to the GDPR;
  • whether the data was already held as a U.S. corporate
    record;
  • whether an EU entity transferred data to a U.S. parent for the
    response;
  • the Article 6 basis or Chapter V mechanism relied upon;
    or
  • whether the companies negotiated scope, applied redactions or
    used a non-waiver/confidentiality agreement.

The strongest legally defensible conclusion is therefore:
the records raise Article 48 and international-transfer
questions; they do not answer them.

8.
Questions German organizations should ask now

German organizations that correspond with large U.S. platforms
should ask:

  1. Which corporate entity receives and stores the
    communication?
  2. In which jurisdictions are copies, backups and internal
    forwards accessible?
  3. Can the U.S. parent search or export the records under
    “possession, custody or control”?
  4. What policy governs notice when a foreign authority or
    legislature requests the data?
  5. Will the platform notify the German sender before production,
    unless legally prohibited?
  6. How are third-party names, addresses, attachments and trade
    secrets minimized or redacted?
  7. What Article 6 and Chapter V bases would be used for a
    disclosure to a third-country authority?
  8. Can sensitive communications be routed through a channel with
    agreed retention, deletion and disclosure rules?

9. Journalism-safe
formulation

Supported:

U.S. congressional subpoenas to major technology platforms
exposed previously nonpublic communications and operational
details involving German regulators, NGOs, academics and media
organizations. The German institutions were generally not the
subpoena targets; their information appeared in copies held by the
platforms.

Not supported by the reviewed records:

Microsoft secretly extracted German institutional emails under
the CLOUD Act.

LfM NRW, MA HSH or BNetzA ordered the documented removals.

The documents were anonymously leaked.

Primary sources