German institutions in the House Judiciary DSA document production
What the records show, whose data appears, how Congress obtained it, and why German organizations should care
Status: Evidence-based interim assessment, 16 July 2026. This is a journalistic analysis, not legal advice.
Executive conclusion
The material does not look like a conventional leak. The House Judiciary Committee says it issued document subpoenas to technology companies and received tens of thousands of pages of internal records and communications with foreign regulators. The public appendices contain company-specific Bates numbers that usually identify the producer.
For the German material reviewed here, the principal producers were TikTok, Meta, Google and Microsoft. One Commission decision was probably supplied by X, but the relevant pages have no visible Bates stamp, so that attribution is not conclusive.
The main risk demonstrated for German organizations is recipient-copy exposure: if a German regulator, NGO, university, media company or employee communicates with a large technology platform, the platform retains its own copy, recipient metadata, attachments and internal annotations. A U.S. congressional committee can subpoena that copy from the technology company without subpoenaing the German sender.
This was probably not a CLOUD Act process. The disclosed process was legislative oversight by Congress, not a criminal search warrant or Stored Communications Act order. The CLOUD Act is relevant only as a comparison: it confirms that location abroad does not necessarily protect data controlled by a covered provider, but it was not the stated authority for these subpoenas.
1. What exactly do the documents show?
| German actor | What the underlying record shows | What it does not show | Source and producer |
|---|---|---|---|
| LfM NRW | A redacted @medienanstalt-nrw.de recipient
appears on European Commission Code of Practice task-force
mailings, a 2024 mailing about converting the Code into a DSA Code
of Conduct, and a Rapid Response System election mailing. |
No reviewed page shows LfM NRW submitting a Rapid Response System notification, requesting a takedown or replying. | Appendix V Part 1, p. 208, TT_HJC_008468;
Appendix V Part 2, p. 32, TT_HJC_017392; Appendix
VI–VII, pp. 268–269, TT_HJC_016542–016544.
TikTok production. |
| MA HSH | Matthias Forsterling, with a partially redacted
@MA-HSH.de address, was invited to a Commission
subgroup on “empowerment of fact-checkers.” Proposed work included
platform–fact-checker agreements, EU coverage, a common
repository, funding, metrics and technical solutions. |
The reviewed kick-off distribution does not clearly establish that Forsterling or MA HSH joined or participated. | Appendix V Part 1, pp. 280–282,
META-119HJC-0000752–0000755. Meta
production. |
| BNetzA | A December 2024 TikTok email refers to a direct meeting with BNetzA “on the German election.” TikTok’s privileged EU-election review also names BNetzA among Digital Services Coordinators it engaged. | The meeting’s substance and outcome are not disclosed. TikTok reports five Rapid Response System notifications overall, but does not attribute them to BNetzA. | Appendix VI–VII, pp. 424–427,
TT_HJC_013475–013478, and pp. 289–301. TikTok
production. |
| BNetzA in the X case | The Commission’s final X decision records BNetzA’s preliminary view that German satire accounts were clearly marked and that X’s checkmark explanation was accessible. The Commission rejected this as insufficiently exculpatory. | The relevant pages do not reveal which company produced the decision. | Appendix VI–VII, p. 1053. Likely X production, but unproven because no Bates prefix is visible. |
| Amadeu Antonio Stiftung | TikTok says the foundation supplied localized signals about extremist ideologies and actors in Germany and Austria, plus specific audio files and songs, to improve moderation “at scale.” | The passage does not identify the actors, songs, affected accounts or number of enforcement actions. | Appendix VI–VII, p. 758, within
TT_HJC_014687–014691. TikTok
production. |
| German law enforcement, Youthprotect and FSM | TikTok told the Commission that German law enforcement submitted two Israel–Hamas-related notices: one livestream had already ended; a second notice concerning four videos resulted in an account ban. Youthprotect e.V. and FSM each reported a video that TikTok removed. | The police bodies, users and content are not named. The record does not establish that the notices were legally binding orders. | Appendix I–II, pp. 257–258, TT_HJC_006293–006294.
TikTok production. |
| DPA and Microsoft Bing | Microsoft’s Bing risk assessment says DPA supplied timely, verified fact-checking data before Germany’s 2025 election. Bing intended to use the data for “defensive search interventions” addressing information manipulation; implementation began in April 2025. | It does not disclose which queries or results changed, or whether an intervention meant demotion, annotation, authoritative-source promotion or another treatment. | Appendix VI–VII, p. 989, MSFT_JUD_000002572.
Microsoft production. |
| TU Dortmund | Christina Elmer, with a partially redacted
@tu-dortmund.de address, appears on Commission
generative-AI subgroup distributions. |
Inclusion on a mailing list does not establish a moderation request or decision. | Appendix V Part 1, including pp. 328, 384 and 397. Meta production. |
Additional, less sensitive German references include a
TikTok-supported Federal Health Ministry COVID-19 campaign and an
event agenda naming BNetzA official Dr Julia Marquier. No
institutional reference to the Bayerische Landeszentrale
für neue Medien or an @blm.de address was
detectable in the keyword/OCR review; literal “BLM” hits referred
to Black Lives Matter. This is an absence finding, not proof that
no image-only or OCR-resistant reference exists.
2. Whose confidential or personal information appears?
Identifiable people and affiliations
The public appendices expose or partially expose:
- Matthias Forsterling, MA HSH, with the organizational email domain visible but the local part substantially redacted.
- Christina Elmer, TU Dortmund, again with the institutional domain visible and the local part redacted.
- Dr Julia Marquier, BNetzA, with title and professional role.
- One or more unidentified LfM NRW recipients, whose local email components are redacted but whose institutional domain is visible.
- Numerous Commission, platform, NGO, fact-checking and academic
participants in long
To:andCC:lists. Many names and domains remain readable even where individual email components are obscured.
Names, professional affiliations, meeting attendance and professional email addresses can be personal data under the GDPR when they identify or make a natural person identifiable. Public professional information does not automatically cease to be personal data.
Confidential institutional and operational information
The appendices also disclose:
- nonpublic recipient lists and organizational networks;
- meeting dates, attendance and internal scheduling;
- Rapid Response System routing, escalation and timing mechanics;
- confidential platform responses to Commission requests for information;
- specific notice and enforcement outcomes;
- platform risk assessments and moderation methodologies;
- the operational roles of German NGOs, regulators, law enforcement and DPA;
- platform internal commentary and, in some exhibits, material labelled privileged or restricted.
Many TikTok pages are marked “CONTAINS BUSINESS CONFIDENTIAL INFORMATION” and “CONFIDENTIAL TREATMENT REQUESTED.” Meta pages frequently state “NOT FOR DISTRIBUTION – MEMBERS & STAFF ONLY.” Those legends did not prevent selected pages from appearing in the public appendices.
Important distinction: what Congress received versus what the public can see
The public PDFs contain extensive redactions. The report does not clearly disclose:
- whether the Committee received unredacted originals;
- which party applied each redaction;
- what data-protection or confidentiality review occurred before publication; or
- whether affected German third parties were notified.
Therefore, the public appendices demonstrate exposure, but not necessarily the full extent of the information originally produced to Congress.
3. How was the material obtained?
Type of subpoena
These were congressional oversight document subpoenas issued by the U.S. House Committee on the Judiciary. They were not:
- criminal grand-jury subpoenas;
- search warrants;
- court-issued discovery subpoenas;
- Stored Communications Act orders under 18 U.S.C. § 2703; or
- CLOUD Act orders.
The Committee’s February 2025 cover letters sought:
- communications between each company and foreign governments concerning compliance with foreign content laws, regulations, judicial orders or other government-initiated efforts; and
- the company’s internal communications discussing those foreign-government communications.
The Committee said the companies were within its jurisdiction and possessed records relevant to legislative oversight. Its press release said the subpoenas were necessary to permit disclosure “without interference by foreign governments.” See the House Judiciary announcement and subpoena links.
Companies subpoenaed
The report says document subpoenas were issued to ten companies:
- Alphabet, Amazon, Apple, Meta, Microsoft, Rumble, TikTok and X on or around 26 February 2025;
- Reddit on 17 April 2025; and
- OpenAI on 5 November 2025.
Being subpoenaed does not prove that every company supplied documents used in this report. For the German-specific evidence reviewed, visible Bates prefixes show actual productions by TikTok, Meta, Google/Alphabet and Microsoft. X is a likely source for one unstamped Commission decision. No German-specific material in this review could be confidently attributed to Amazon, Apple, Rumble, Reddit or OpenAI.
Bates-prefix source key
| Prefix | Producing company |
|---|---|
TT_HJC |
TikTok |
META-119HJC |
Meta |
GOOG-HJCFG |
Google/Alphabet |
MSFT_JUD |
Microsoft |
An Outlook-formatted email does not establish
that Microsoft produced it. For example, the LfM NRW emails carry
TikTok Bates numbers; the MA HSH email carries a Meta Bates
number. Microsoft is directly evidenced only where the pages carry
MSFT_JUD.
4. What made the subpoenas legally possible?
The principal authority was Congress’s legislative and oversight power, implemented through House rules—not the CLOUD Act.
- House Judiciary Committee Rule IV allows its Chair to authorize and issue a subpoena, after consultation with the Ranking Minority Member, for an investigation within the Committee’s jurisdiction. It expressly relies on clause 2(m) of House Rule XI. See the Judiciary Committee’s rules for the 119th Congress.
- The cover letters cited House Rule X, including the Committee’s jurisdiction over civil liberties, as the legislative basis for investigating effects on American speech.
- Failure to comply with a valid congressional subpoena can potentially lead to contempt proceedings. 2 U.S.C. §§ 192–194 address refusal to produce papers and certification to a U.S. attorney. See the official U.S. Code, Title 2, Chapter 6.
Unlike a criminal warrant, a congressional subpoena does not require a judge to find probable cause before issuance. Its validity instead depends on matters including committee jurisdiction, legislative purpose, pertinence, procedural compliance and applicable constitutional or privilege objections.
5. Was the CLOUD Act involved?
Probably not. Nothing in the report or subpoena cover letters identifies the CLOUD Act as the basis for production.
The CLOUD Act amended the Stored Communications Act. Among other things, 18 U.S.C. § 2713 requires covered communications and remote-computing providers to comply with obligations under that chapter for material within their possession, custody or control, regardless of whether it is stored inside or outside the United States. The CLOUD Act also provides a framework for qualifying foreign governments to obtain electronic evidence under bilateral executive agreements, particularly for serious-crime investigations. See the statutory text of 18 U.S.C. § 2713 and the U.S. Department of Justice CLOUD Act overview.
That framework does not match what happened here:
- the requester was a congressional committee, not a criminal law-enforcement authority;
- the instruments were House oversight subpoenas, not § 2703 warrants or orders; and
- the material appears mainly to be the companies‘ own business records, employee mailboxes, regulatory correspondence and internal analyses—not customer mailbox contents demanded from a neutral cloud host.
The practical lesson resembles the CLOUD Act’s “possession, custody or control” logic, but the legal authority is different.
6. What data risk does this demonstrate for German companies and institutions?
Risks directly demonstrated by the records
- A recipient can disclose the sender’s copy. A German organization may never receive a U.S. subpoena, yet its email can be produced from TikTok’s, Meta’s, Google’s, Microsoft’s or X’s systems.
- Metadata can be as revealing as message content. Recipient lists reveal who participates in a policy network, even when individual addresses are partly redacted.
- Attachments and internal annotations expand the exposure. The platform may hold not only the original message but agendas, risk assessments, internal forwarding chains and staff commentary.
- Confidentiality labels are not a publication guarantee. Material marked business-confidential, restricted or privileged still appears in the public appendices, albeit with redactions.
- Redaction may not prevent re-identification. A visible name, job title, date, meeting topic and institutional domain can identify a person even when the email local part is blacked out.
- Operational partnerships can become public. The DPA–Bing and Amadeu Antonio Stiftung–TikTok passages reveal how German third parties supplied data or signals used in platform interventions.
Risks the records do not prove
- They do not show Microsoft opening or exporting German customers‘ Microsoft 365 mailboxes.
- They do not show that Congress obtained data directly from German servers.
- They do not establish that any technology company violated the GDPR, contractual confidentiality or German law.
- They do not reveal which corporate entity made each transfer, where the responsive data was stored, or which GDPR transfer mechanism was used.
- They do not show mass disclosure of ordinary German platform users‘ private messages; the reviewed German examples concern institutional and business communications.
7. GDPR and cross-border-transfer questions
If personal data subject to the GDPR was transferred from an EEA controller or processor directly in response to a U.S. congressional demand, Article 48 GDPR is potentially relevant.
Article 48 says that a third-country court judgment or administrative-authority decision requiring disclosure may be recognized or enforceable only if based on an international agreement, such as a mutual legal assistance treaty, without prejudice to other Chapter V transfer grounds. The EDPB’s final 2025 guidance says a foreign request does not itself supply a lawful basis: the controller must assess both a legal basis under Article 6 and a valid Chapter V transfer ground. See the EDPB Guidelines 02/2024 on Article 48 GDPR, version 2.1.
However, the appendices are insufficient to conclude that Article 48 was breached because they do not identify:
- the legal entity that responded;
- whether the relevant processing was subject to the GDPR;
- whether the data was already held as a U.S. corporate record;
- whether an EU entity transferred data to a U.S. parent for the response;
- the Article 6 basis or Chapter V mechanism relied upon; or
- whether the companies negotiated scope, applied redactions or used a non-waiver/confidentiality agreement.
The strongest legally defensible conclusion is therefore: the records raise Article 48 and international-transfer questions; they do not answer them.
8. Questions German organizations should ask now
German organizations that correspond with large U.S. platforms should ask:
- Which corporate entity receives and stores the communication?
- In which jurisdictions are copies, backups and internal forwards accessible?
- Can the U.S. parent search or export the records under “possession, custody or control”?
- What policy governs notice when a foreign authority or legislature requests the data?
- Will the platform notify the German sender before production, unless legally prohibited?
- How are third-party names, addresses, attachments and trade secrets minimized or redacted?
- What Article 6 and Chapter V bases would be used for a disclosure to a third-country authority?
- Can sensitive communications be routed through a channel with agreed retention, deletion and disclosure rules?
9. Journalism-safe formulation
Supported:
U.S. congressional subpoenas to major technology platforms exposed previously nonpublic communications and operational details involving German regulators, NGOs, academics and media organizations. The German institutions were generally not the subpoena targets; their information appeared in copies held by the platforms.
Not supported by the reviewed records:
Microsoft secretly extracted German institutional emails under the CLOUD Act.
LfM NRW, MA HSH or BNetzA ordered the documented removals.
The documents were anonymously leaked.
Primary sources
- House Judiciary DSA Report II
- House announcement and February 2025 subpoena cover letters
- House Judiciary Committee Rules, 119th Congress
- Appendix Sections I–II
- Appendix Section V, Part 1
- Appendix Section V, Part 2
- Appendix Sections VI–VII
- EDPB Guidelines 02/2024 on Article 48 GDPR
- 18 U.S.C. § 2713
- U.S. DOJ CLOUD Act resources