PRISM
SecurityWhat is PRISM?
PRISM is a surveillance program operated by the U.S. National Security Agency (NSA). Based on court orders, it provides the NSA with a standardized electronic process for obtaining requested data from major Internet companies such as Google, Facebook, Microsoft, and Apple.
Established: 2007
Revealed: 2013 by Edward Snowden
Codename: US-5334
Legal basis: FISA Amendments Act, Section 702 (2008)
What is monitored
- Emails and messages
- Stored files and photos
- Video and audio chats
- Social media activity
- Cloud storage contents
Companies involved
Named in the published PRISM documents (as of 2013):
- Microsoft (since 2007) – Outlook, OneDrive, Skype
- Yahoo (since 2008)
- Google (since 2009) – Gmail, Drive, YouTube
- Facebook (since 2009) – Facebook, Instagram, WhatsApp
- Apple (since 2012) – iCloud, iMessage, FaceTime
- Dropbox (since 2012)
Often suspected or discussed:
- Amazon (AWS)
- Twitter/X
How it works
PRISM established standardized procedures through which participating companies could provide requested data electronically without requiring the NSA to negotiate every request individually.
Legally: The NSA presents its surveillance programs and procedures to the Foreign Intelligence Surveillance Court (FISA Court) for approval—not individual surveillance targets. Once those procedures are approved, the NSA can request information on specific targets within that legal framework.
The FISA Court operates in secret. People whose data is collected are generally never informed, and companies are typically prohibited from disclosing such requests.
Who it applies to
Officially: Non-U.S. persons located outside the United States.
In practice: Data relating to U.S. citizens may also be collected when they communicate with targeted non-U.S. persons.
Impact
Privacy: Communications using U.S.-based online services may, under the legal conditions of Section 702, become subject to surveillance measures.
Business: European organizations storing customer data on U.S. servers cannot guarantee that those data are beyond the reach of U.S. government authorities.
Legal remedies: Individuals generally do not learn that they have been subject to surveillance and therefore have very limited practical opportunities to challenge it.
Legal developments in the EU
- 2015: The Court of Justice of the European Union invalidated the Safe Harbor framework.
- 2020: The Court invalidated the Privacy Shield framework.
- 2023: EU–U.S. Data Privacy Framework adopted (its legal status continues to be debated).
Reason: PRISM and other U.S. surveillance programs were considered incompatible with the level of data protection required under EU law.
What can you do?
Avoid U.S.-based services (highly effective)
Instead of Gmail: Mailbox.org, Posteo, Tuta (formerly Tutanota) or other European providers
Instead of Google Drive: Self-hosted Nextcloud
Instead of WhatsApp: Signal or Matrix
Limitation: This approach is most effective only if the people you communicate with also use these alternatives.
End-to-end encryption (moderately effective)
Use Signal for messaging and providers such as Tuta or Proton Mail for email.
Important: Metadata—such as who communicates with whom, when, and how often—can still remain visible. With some services, backups may also be stored without end-to-end encryption.
Self-hosting (very effective)
Operate your own mail server, cloud storage, or website on infrastructure located in Germany or another trusted jurisdiction.
Dragons@Work offers: Migration & Self-Hosting Service
VPN (limited effectiveness)
A VPN encrypts the connection between you and your Internet provider. Once data reaches a U.S.-based service, however, a VPN does not prevent access under PRISM.
Related programs
- Tempora: GCHQ (United Kingdom) interception of fiber-optic communications
- XKeyscore: NSA system for searching collected intelligence data
- Upstream: NSA collection at major Internet backbone infrastructure
Technical details
Encryption: PRISM operates at the server side, where data are often available in unencrypted form. Only true end-to-end encryption protects message contents from server-side access.
Metadata: Even with strong end-to-end encryption, metadata such as IP addresses, timestamps, communication frequency, and device identifiers may still be available.
Sources
Snowden documents
Sources archived on: 2026-08-02