Published since 2012, our biannual report makes public the number of requests we receive and how we respond.
What Dropbox received
Search warrants require a showing of probable cause, must meet specificity requirements regarding the location to be searched and the items to be seized, and must be reviewed and signed by a judge or magistrate. Search warrants may be issued by local, state, or federal governments, and may only be used in criminal cases. In response to valid search warrants, we may produce non-content and content information.
We provided some information in response to 77.1% of the search warrants received.
When Dropbox complies with a search warrant, we notify the users named in the request unless prohibited by law. The shaded portion of the pie chart above represents users to whom we gave notice. 10.7% of the search warrants we received were accompanied by court orders for non-disclosure of indefinite duration. These gag orders may prevent us from ever notifying 11.1% of the affected Dropbox users identified in search warrants we received of the fact that law enforcement requested their information.
The numbers above include search warrants directed at Dropbox subsidiaries. In the relevant half, we did not receive any search warrants directed to Dropbox subsidiaries.
What Dropbox received
Unlike a search warrant, a subpoena only allows access to basic subscriber information. Subpoenas do not require judicial review and are typically issued by government attorneys or grand juries. We do not provide content information in response to subpoenas.
We provided some information in response to 81.5% of the subpoenas received.
When Dropbox complies with a subpoena, we notify the users named in the request unless prohibited by law. The shaded portion of the pie chart above represents users to whom we gave notice. 9.3% of the subpoenas we received were accompanied by court orders for non-disclosure of indefinite duration. These gag orders may prevent us from ever notifying 9.6% of the affected Dropbox users identified in subpoenas we received of the fact that law enforcement requested their information.
The numbers above include subpoenas directed at Dropbox subsidiaries. In the relevant half, we received 3 subpoenas directed to Dropbox Sign/Dropbox Fax and 2 subpoenas directed to DocSend.
What Dropbox received
Court orders are issued by judges and may take a variety of forms, such as a 2703(d) order under the Electronic Communications Privacy Act. We do not provide content information in response to court orders.
We provided some information in response to 31.8% of the court orders we received.
When Dropbox complies with a court order, we notify the users named in the request unless prohibited by law. The shaded portion of the pie chart above represents users to whom we gave notice. 4.5% of the court orders we received were accompanied by court orders for non-disclosure of indefinite duration. These gag orders may prevent us from ever notifying 10.5% of the affected Dropbox users identified in court orders of the fact that law enforcement requested their information.
The numbers above include court orders directed at Dropbox subsidiaries. In the relevant half, we did not receive any court order directed at Dropbox subsidiaries.
What Dropbox received
National security process includes National Security Letters and orders issued under the Foreign Intelligence Surveillance Act. We received between 0 and 249 requests. We’d like to be more specific, but Dropbox is not permitted by the US government to report the exact number received.
A note about national security process
National Security Letters (“NSLs”) are requests from the Federal Bureau of Investigation for information relevant to a national security investigation. An NSL doesn’t require a court order, but may only request a user’s “name, address, length of service and local and long distance toll billing records”.
Foreign Intelligence Surveillance Act orders (“FISA orders”) are orders issued by the Foreign Intelligence Surveillance Court (“FISC”) for information relevant to a national security investigation. A FISA order may request a user’s non-content and content information.
What Dropbox received
A preservation request is a government request to preserve user data pending the receipt of formal legal process. When we receive these requests, we will temporarily retain a snapshot of the relevant user data for 90 days, but we do not disclose user data in response to preservation requests. To obtain preserved data, valid legal process is required.
We received 1323 preservation requests from U.S. law enforcement, affecting 1316 accounts. We received 92 preservation requests from international law enforcement, affecting 267 accounts.
The numbers above include preservation requests directed at Dropbox subsidiaries. In the relevant half, we received 1 preservation request directed to Dropbox Sign/Dropbox Fax, and 1 preservation request directed to DocSend.
What Dropbox received
Dropbox may voluntarily disclose information to law enforcement if we have a good faith belief that someone is at imminent risk of death or serious physical injury and we have information which may help prevent the threat. We require that law enforcement provides a written summary of the emergency and explanation of how the information requested will assist them in preventing the emergency. Every emergency disclosure request is carefully scrutinized on a case by case basis to determine if the standard for disclosure has been met, and if so, any information disclosed is limited to that which would avert or mitigate the emergency. Dropbox receives emergency disclosure requests for user data from law enforcement around the world.
What Dropbox Received
Pen Registers or Trap and Trace orders (“PRTTs”) are court orders that authorize the government to obtain certain non-content information (specifically, dialing, routing, addressing, and signaling information relating to communications) of a specific account on a prospective basis for a period of up to 60 days.
The authorizing statute for PRTTs requires that such orders include a provision that prevents service providers like Dropbox from notifying users of these requests for an indefinite period of time. These gag orders may prevent Dropbox from ever notifying all of the affected Dropbox users identified in PRTT orders of the fact that law enforcement requested their information.
What Dropbox received
Government removal requests include court orders and written requests from law enforcement and government agencies seeking the removal of content from accounts based on the local laws of their respective jurisdictions.
“No action taken” may be due to circumstances where we were not able to review the content because the link provided to us was invalid or the content no longer existed, or where, upon review, the content was found not to violate our Acceptable Use Policy.
AK
7
AL
57
AR
26
AZ
28
CA
186
CO
29
CT
20
DC
83
DE
38
FL
280
GA
60
HI
9
IA
15
ID
20
IL
200
IN
76
KS
14
KY
22
LA
47
MA
52
MD
106
ME
2
MI
13
MN
100
MO
44
MS
16
MT
13
NC
84
ND
5
NE
55
NH
12
NJ
142
NM
3
NV
38
NY
177
OH
91
OK
50
OR
42
PA
80
RI
12
SC
52
SD
14
TN
43
TX
234
UT
17
VA
164
VT
1
WA
44
WI
50
WV
20
WY
4
A note about international requests
International requests include any formal legal process from a non-US government seeking user data. At this time, we accept US and Irish government requests. We may also respond to requests made pursuant to international agreements on legal cooperation in criminal matters, including Mutual Legal Assistance Treaties or letters rogatory.
Child sexual exploitation and abuse has no place on Dropbox. This kind of material violates our Terms of Service and Acceptable Use Policy, and we will swiftly disable any accounts found with this content. Dropbox uses a variety of tools, including industry-standard automated detection technology, and human review to find potentially violating content and action it as appropriate. We also encourage our users to report inappropriate content they come across through our reporting tool or by completing this form. When we become aware of instances of apparent child sexual abuse material, we disable the account and make a report to the National Center for Missing and Exploited Children (NCMEC), in accordance with applicable law.
From July through December 2023, we submitted 33,963 CyberTip reports to the National Center for Missing and Exploited Children (NCMEC) and disabled access to 31,474 distinct accounts and 273,565 individual pieces of violative content under our policies against child sexual abuse and exploitation material.
Our team takes extreme care in enforcing our policies. When a user thinks we made a mistake in our enforcement, they may contact Dropbox support to request a review of that decision. In the relevant half, we received 2,256 appeals from accounts disabled under Dropbox’s child sexual exploitation and abuse policy. We reinstated access in 2.6% of those cases.
Dropbox’s Terms of Service and Acceptable Use Policy prohibit publishing, sharing, or storing content that contains or promotes terrorism or violent extremism, including terror or violent extremist propaganda. Dropbox relies on a combination of proactive and reactive tools to detect terrorism or violent extremism content and enforce our policies. These tools include leveraging industry-standard hash matching detection technology, a trusted flagger program, external reports from members of the public and our users, and manual review by highly trained analysts. We strongly encourage those who come across terror or violent extremist content on Dropbox to report it through our reporting tool. When we find terror or violent extremist content that violates our policies, we will disable access to that content and take steps to prevent it from being further shared. When warranted, such as when accounts appear to be used solely for purposes of disseminating terrorist or violent extremist propaganda, we may also disable the associated account.
From July through December 2023, Dropbox disabled access to 854 pieces of terror or violent extremist content and disabled 493 accounts. We received 286 public reports of potential terror content and took no action on 5 reports. When Dropbox takes no action pursuant to a report, it may be because the provided link was invalid, the content no longer existed, or the content did not violate our Acceptable Use Policy.
Users who believe we’ve made a mistake in actioning their accounts can ask us to review that determination by contacting Dropbox support. From July through December 2023, Dropbox received 0 appeals from users who claimed their content or accounts were disabled in error under our terrorism and violent extremism policy.
From July through December 2023, Dropbox received 0 removal orders issued pursuant to EU Regulation 2021/784 (addressing terror content online).
“Account did not exist”: The identifiers provided in the request were not associated with valid Dropbox accounts.
All Writs Act Orders: All Writs Act Orders are issued by United States judges pursuant to the All Writs Act of 1789. The statute gives courts the power to “issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law.”
Content: Content refers to the content of communications, which includes any information concerning the substance, purport, or meaning of the communication. It includes the files stored in a person’s Dropbox account and the filenames associated with those files. A search warrant is required to compel the production of content. Often, search warrants will also seek basic subscriber information or other non-content records, in addition to the content of communications.
Emergency disclosure requests: Dropbox may voluntarily disclose information to law enforcement if we have a good faith belief that someone is at imminent risk of death or serious physical injury and we have information that may help prevent the threat. We require that law enforcement provides a written summary of the emergency and explanation of how the information requested will assist them in preventing the emergency.
“No information provided”: Common reasons that no information was provided in response to legal process include: (1) the request was a duplicate; (2) Dropbox objected to the request; (3) law enforcement withdrew the request; or (4) the request failed to accurately identify an account.
Non-content: Non-content records generally describes any available information other than the content of communications. It includes basic subscriber information, defined in Section 2703 of the Electronic Communications Privacy Act, and other information reflecting usage of an account. “Non-content” information does not include the files that people store in their Dropbox accounts.
Non-disclosure order: At their discretion, judges can issue court orders preventing or delaying Dropbox from notifying a user of a government request for their information. These orders often cite subsection 2705(b) of the Electronic Communications Privacy Act and can extend for any length of time.
Non-US requests: Non-US requests include any formal legal process from a non-US governmental entity seeking user data. At this time, we accept US and Irish government requests. We may also respond to requests made pursuant to international agreements on legal cooperation in criminal matters, including Mutual Legal Assistance Treaties or letters rogatory.
Preservation: A preservation request is a government request to preserve user data pending the receipt of formal legal process. When we receive these requests, we will temporarily retain a snapshot of the relevant user data for 90 days, but we do not disclose user data in response to preservation requests. To obtain the preserved data, valid legal process is required and those subsequent requests are (and always have been) included in the report.
User Notice: Our policy is to provide notice to users about requests for their information unless we are prohibited from doing so by law. In limited cases, we may delay notice to the user until after we have complied, and in those cases we note the date we produced user records.
Our tracking and reporting methods may evolve as we continually strive to improve the accuracy and clarity of our report.