German
institutions in the House Judiciary DSA document production
What
the records show, whose data appears, how Congress obtained it,
and why German organizations should care
Status: Evidence-based interim assessment, 16
July 2026. This is a journalistic analysis, not legal advice.
Executive conclusion
The material does not look like a conventional
leak. The House Judiciary Committee says it issued
document subpoenas to technology companies and
received tens of thousands of pages of internal records and
communications with foreign regulators. The public appendices
contain company-specific Bates numbers that usually identify the
producer.
For the German material reviewed here, the principal producers
were TikTok, Meta, Google and Microsoft. One
Commission decision was probably supplied by X, but the relevant
pages have no visible Bates stamp, so that attribution is not
conclusive.
The main risk demonstrated for German organizations is
recipient-copy exposure: if a German regulator,
NGO, university, media company or employee communicates with a
large technology platform, the platform retains its own copy,
recipient metadata, attachments and internal annotations. A U.S.
congressional committee can subpoena that copy from the technology
company without subpoenaing the German sender.
This was probably not a CLOUD Act process. The
disclosed process was legislative oversight by Congress, not a
criminal search warrant or Stored Communications Act order. The
CLOUD Act is relevant only as a comparison: it confirms that
location abroad does not necessarily protect data controlled by a
covered provider, but it was not the stated authority for these
subpoenas.
1. What exactly do
the documents show?
| German actor | What the underlying record shows | What it does not show | Source and producer |
|---|---|---|---|
| LfM NRW | A redacted @medienanstalt-nrw.de recipientappears on European Commission Code of Practice task-force mailings, a 2024 mailing about converting the Code into a DSA Code of Conduct, and a Rapid Response System election mailing. |
No reviewed page shows LfM NRW submitting a Rapid Response System notification, requesting a takedown or replying. |
Appendix V Part 1, p. 208, TT_HJC_008468;Appendix V Part 2, p. 32, TT_HJC_017392; AppendixVI–VII, pp. 268–269, TT_HJC_016542–016544.TikTok production. |
| MA HSH | Matthias Forsterling, with a partially redacted@MA-HSH.de address, was invited to a Commissionsubgroup on “empowerment of fact-checkers.” Proposed work included platform–fact-checker agreements, EU coverage, a common repository, funding, metrics and technical solutions. |
The reviewed kick-off distribution does not clearly establish that Forsterling or MA HSH joined or participated. |
Appendix V Part 1, pp. 280–282,META-119HJC-0000752–0000755. Metaproduction. |
| BNetzA | A December 2024 TikTok email refers to a direct meeting with BNetzA “on the German election.” TikTok’s privileged EU-election review also names BNetzA among Digital Services Coordinators it engaged. |
The meeting’s substance and outcome are not disclosed. TikTok reports five Rapid Response System notifications overall, but does not attribute them to BNetzA. |
Appendix VI–VII, pp. 424–427,TT_HJC_013475–013478, and pp. 289–301. TikTokproduction. |
| BNetzA in the X case | The Commission’s final X decision records BNetzA’s preliminary view that German satire accounts were clearly marked and that X’s checkmark explanation was accessible. The Commission rejected this as insufficiently exculpatory. |
The relevant pages do not reveal which company produced the decision. |
Appendix VI–VII, p. 1053. Likely X production, but unproven because no Bates prefix is visible. |
| Amadeu Antonio Stiftung | TikTok says the foundation supplied localized signals about extremist ideologies and actors in Germany and Austria, plus specific audio files and songs, to improve moderation “at scale.” |
The passage does not identify the actors, songs, affected accounts or number of enforcement actions. |
Appendix VI–VII, p. 758, withinTT_HJC_014687–014691. TikTokproduction. |
| German law enforcement, Youthprotect and FSM |
TikTok told the Commission that German law enforcement submitted two Israel–Hamas-related notices: one livestream had already ended; a second notice concerning four videos resulted in an account ban. Youthprotect e.V. and FSM each reported a video that TikTok removed. |
The police bodies, users and content are not named. The record does not establish that the notices were legally binding orders. |
Appendix I–II, pp. 257–258, TT_HJC_006293–006294.TikTok production. |
| DPA and Microsoft Bing | Microsoft’s Bing risk assessment says DPA supplied timely, verified fact-checking data before Germany’s 2025 election. Bing intended to use the data for “defensive search interventions” addressing information manipulation; implementation began in April 2025. |
It does not disclose which queries or results changed, or whether an intervention meant demotion, annotation, authoritative-source promotion or another treatment. |
Appendix VI–VII, p. 989, MSFT_JUD_000002572.Microsoft production. |
| TU Dortmund | Christina Elmer, with a partially redacted@tu-dortmund.de address, appears on Commissiongenerative-AI subgroup distributions. |
Inclusion on a mailing list does not establish a moderation request or decision. |
Appendix V Part 1, including pp. 328, 384 and 397. Meta production. |
Additional, less sensitive German references include a
TikTok-supported Federal Health Ministry COVID-19 campaign and an
event agenda naming BNetzA official Dr Julia Marquier. No
institutional reference to the Bayerische Landeszentrale
für neue Medien or an @blm.de address was
detectable in the keyword/OCR review; literal “BLM” hits referred
to Black Lives Matter. This is an absence finding, not proof that
no image-only or OCR-resistant reference exists.
2.
Whose confidential or personal information appears?
Identifiable people
and affiliations
The public appendices expose or partially expose:
- Matthias Forsterling, MA HSH, with the
organizational email domain visible but the local part
substantially redacted. - Christina Elmer, TU Dortmund, again with the
institutional domain visible and the local part redacted. - Dr Julia Marquier, BNetzA, with title and
professional role. - One or more unidentified LfM NRW recipients,
whose local email components are redacted but whose institutional
domain is visible. - Numerous Commission, platform, NGO, fact-checking and academic
participants in longTo:andCC:lists.
Many names and domains remain readable even where individual email
components are obscured.
Names, professional affiliations, meeting attendance and
professional email addresses can be personal data under the GDPR
when they identify or make a natural person identifiable. Public
professional information does not automatically cease to be
personal data.
Confidential
institutional and operational information
The appendices also disclose:
- nonpublic recipient lists and organizational networks;
- meeting dates, attendance and internal scheduling;
- Rapid Response System routing, escalation and timing
mechanics; - confidential platform responses to Commission requests for
information; - specific notice and enforcement outcomes;
- platform risk assessments and moderation methodologies;
- the operational roles of German NGOs, regulators, law
enforcement and DPA; - platform internal commentary and, in some exhibits, material
labelled privileged or restricted.
Many TikTok pages are marked “CONTAINS BUSINESS
CONFIDENTIAL INFORMATION” and “CONFIDENTIAL
TREATMENT REQUESTED.” Meta pages frequently state
“NOT FOR DISTRIBUTION – MEMBERS & STAFF
ONLY.” Those legends did not prevent selected pages from
appearing in the public appendices.
Important
distinction: what Congress received versus what the public can
see
The public PDFs contain extensive redactions. The report does
not clearly disclose:
- whether the Committee received unredacted originals;
- which party applied each redaction;
- what data-protection or confidentiality review occurred before
publication; or - whether affected German third parties were notified.
Therefore, the public appendices demonstrate exposure, but not
necessarily the full extent of the information originally produced
to Congress.
3. How was the material
obtained?
Type of subpoena
These were congressional oversight document
subpoenas issued by the U.S. House Committee on the
Judiciary. They were not:
- criminal grand-jury subpoenas;
- search warrants;
- court-issued discovery subpoenas;
- Stored Communications Act orders under 18 U.S.C. § 2703;
or - CLOUD Act orders.
The Committee’s February 2025 cover letters sought:
- communications between each company and foreign governments
concerning compliance with foreign content laws, regulations,
judicial orders or other government-initiated efforts; and - the company’s internal communications discussing those
foreign-government communications.
The Committee said the companies were within its jurisdiction
and possessed records relevant to legislative oversight. Its press
release said the subpoenas were necessary to permit disclosure
“without interference by foreign governments.” See the House
Judiciary announcement and subpoena links.
Companies subpoenaed
The report says document subpoenas were issued to ten
companies:
- Alphabet, Amazon, Apple, Meta, Microsoft, Rumble,
TikTok and X on or around 26 February 2025; - Reddit on 17 April 2025; and
- OpenAI on 5 November 2025.
Being subpoenaed does not prove that every company supplied
documents used in this report. For the German-specific evidence
reviewed, visible Bates prefixes show actual productions by
TikTok, Meta, Google/Alphabet and Microsoft. X is
a likely source for one unstamped Commission decision. No
German-specific material in this review could be confidently
attributed to Amazon, Apple, Rumble, Reddit or OpenAI.
Bates-prefix source key
| Prefix | Producing company |
|---|---|
TT_HJC |
TikTok |
META-119HJC |
Meta |
GOOG-HJCFG |
Google/Alphabet |
MSFT_JUD |
Microsoft |
An Outlook-formatted email does not establish
that Microsoft produced it. For example, the LfM NRW emails carry
TikTok Bates numbers; the MA HSH email carries a Meta Bates
number. Microsoft is directly evidenced only where the pages carry
MSFT_JUD.
4. What made
the subpoenas legally possible?
The principal authority was Congress’s legislative and
oversight power, implemented through House rules—not the
CLOUD Act.
- House Judiciary Committee Rule IV allows its
Chair to authorize and issue a subpoena, after consultation with
the Ranking Minority Member, for an investigation within the
Committee’s jurisdiction. It expressly relies on clause
2(m) of House Rule XI. See the Judiciary
Committee’s rules for the 119th Congress. - The cover letters cited House Rule X,
including the Committee’s jurisdiction over civil liberties, as
the legislative basis for investigating effects on American
speech. - Failure to comply with a valid congressional subpoena can
potentially lead to contempt proceedings. 2 U.S.C. §§
192–194 address refusal to produce papers and
certification to a U.S. attorney. See the official
U.S. Code, Title 2, Chapter 6.
Unlike a criminal warrant, a congressional subpoena does not
require a judge to find probable cause before issuance. Its
validity instead depends on matters including committee
jurisdiction, legislative purpose, pertinence, procedural
compliance and applicable constitutional or privilege
objections.
5. Was the CLOUD Act
involved?
Probably not. Nothing in the report or subpoena cover
letters identifies the CLOUD Act as the basis for
production.
The CLOUD Act amended the Stored Communications Act. Among
other things, 18 U.S.C. § 2713 requires covered
communications and remote-computing providers to comply with
obligations under that chapter for material within their
possession, custody or control, regardless of whether it is stored
inside or outside the United States. The CLOUD Act also provides a
framework for qualifying foreign governments to obtain electronic
evidence under bilateral executive agreements, particularly for
serious-crime investigations. See the statutory
text of 18 U.S.C. § 2713 and the U.S.
Department of Justice CLOUD Act overview.
That framework does not match what happened here:
- the requester was a congressional committee, not a criminal
law-enforcement authority; - the instruments were House oversight subpoenas, not § 2703
warrants or orders; and - the material appears mainly to be the companies‘ own business
records, employee mailboxes, regulatory correspondence and
internal analyses—not customer mailbox contents demanded from a
neutral cloud host.
The practical lesson resembles the CLOUD Act’s “possession,
custody or control” logic, but the legal authority is
different.
6.
What data risk does this demonstrate for German companies and
institutions?
Risks directly
demonstrated by the records
- A recipient can disclose the sender’s copy. A
German organization may never receive a U.S. subpoena, yet its
email can be produced from TikTok’s, Meta’s, Google’s, Microsoft’s
or X’s systems. - Metadata can be as revealing as message
content. Recipient lists reveal who participates in a
policy network, even when individual addresses are partly
redacted. - Attachments and internal annotations expand the
exposure. The platform may hold not only the original
message but agendas, risk assessments, internal forwarding chains
and staff commentary. - Confidentiality labels are not a publication
guarantee. Material marked business-confidential,
restricted or privileged still appears in the public appendices,
albeit with redactions. - Redaction may not prevent re-identification.
A visible name, job title, date, meeting topic and institutional
domain can identify a person even when the email local part is
blacked out. - Operational partnerships can become public.
The DPA–Bing and Amadeu Antonio Stiftung–TikTok passages reveal
how German third parties supplied data or signals used in platform
interventions.
Risks the records do
not prove
- They do not show Microsoft opening or exporting German
customers‘ Microsoft 365 mailboxes. - They do not show that Congress obtained data directly from
German servers. - They do not establish that any technology company violated the
GDPR, contractual confidentiality or German law. - They do not reveal which corporate entity made each transfer,
where the responsive data was stored, or which GDPR transfer
mechanism was used. - They do not show mass disclosure of ordinary German platform
users‘ private messages; the reviewed German examples concern
institutional and business communications.
7. GDPR and
cross-border-transfer questions
If personal data subject to the GDPR was transferred from an
EEA controller or processor directly in response to a U.S.
congressional demand, Article 48 GDPR is potentially
relevant.
Article 48 says that a third-country court judgment or
administrative-authority decision requiring disclosure may be
recognized or enforceable only if based on an international
agreement, such as a mutual legal assistance treaty, without
prejudice to other Chapter V transfer grounds. The EDPB’s final
2025 guidance says a foreign request does not itself supply a
lawful basis: the controller must assess both a legal basis under
Article 6 and a valid Chapter V transfer ground. See the EDPB
Guidelines 02/2024 on Article 48 GDPR, version 2.1.
However, the appendices are insufficient to conclude that
Article 48 was breached because they do not identify:
- the legal entity that responded;
- whether the relevant processing was subject to the GDPR;
- whether the data was already held as a U.S. corporate
record; - whether an EU entity transferred data to a U.S. parent for the
response; - the Article 6 basis or Chapter V mechanism relied upon;
or - whether the companies negotiated scope, applied redactions or
used a non-waiver/confidentiality agreement.
The strongest legally defensible conclusion is therefore:
the records raise Article 48 and international-transfer
questions; they do not answer them.
8.
Questions German organizations should ask now
German organizations that correspond with large U.S. platforms
should ask:
- Which corporate entity receives and stores the
communication? - In which jurisdictions are copies, backups and internal
forwards accessible? - Can the U.S. parent search or export the records under
“possession, custody or control”? - What policy governs notice when a foreign authority or
legislature requests the data? - Will the platform notify the German sender before production,
unless legally prohibited? - How are third-party names, addresses, attachments and trade
secrets minimized or redacted? - What Article 6 and Chapter V bases would be used for a
disclosure to a third-country authority? - Can sensitive communications be routed through a channel with
agreed retention, deletion and disclosure rules?
9. Journalism-safe
formulation
Supported:
U.S. congressional subpoenas to major technology platforms
exposed previously nonpublic communications and operational
details involving German regulators, NGOs, academics and media
organizations. The German institutions were generally not the
subpoena targets; their information appeared in copies held by the
platforms.
Not supported by the reviewed records:
Microsoft secretly extracted German institutional emails under
the CLOUD Act.
LfM NRW, MA HSH or BNetzA ordered the documented removals.
The documents were anonymously leaked.
Primary sources
- House
Judiciary DSA Report II - House
announcement and February 2025 subpoena cover letters - House
Judiciary Committee Rules, 119th Congress - Appendix
Sections I–II - Appendix
Section V, Part 1 - Appendix
Section V, Part 2 - Appendix
Sections VI–VII - EDPB
Guidelines 02/2024 on Article 48 GDPR - 18
U.S.C. § 2713 - U.S.
DOJ CLOUD Act resources
