PRISM

Security
Also known as: PRISM Program, NSA PRISM, US-5334
Classified NSA surveillance program that provides standardized access to data held by U.S. technology companies based on Section 702 orders

What is PRISM?

PRISM is a surveillance program operated by the U.S. National Security Agency (NSA). Based on court orders, it provides the NSA with a standardized electronic process for obtaining requested data from major Internet companies such as Google, Facebook, Microsoft, and Apple.

Established: 2007
Revealed: 2013 by Edward Snowden
Codename: US-5334
Legal basis: FISA Amendments Act, Section 702 (2008)

What is monitored

  • Emails and messages
  • Stored files and photos
  • Video and audio chats
  • Social media activity
  • Cloud storage contents

Companies involved

Named in the published PRISM documents (as of 2013):

  • Microsoft (since 2007) – Outlook, OneDrive, Skype
  • Yahoo (since 2008)
  • Google (since 2009) – Gmail, Drive, YouTube
  • Facebook (since 2009) – Facebook, Instagram, WhatsApp
  • Apple (since 2012) – iCloud, iMessage, FaceTime
  • Dropbox (since 2012)

Often suspected or discussed:

  • Amazon (AWS)
  • Twitter/X
  • LinkedIn

How it works

PRISM established standardized procedures through which participating companies could provide requested data electronically without requiring the NSA to negotiate every request individually.

Legally: The NSA presents its surveillance programs and procedures to the Foreign Intelligence Surveillance Court (FISA Court) for approval—not individual surveillance targets. Once those procedures are approved, the NSA can request information on specific targets within that legal framework.

The FISA Court operates in secret. People whose data is collected are generally never informed, and companies are typically prohibited from disclosing such requests.

Who it applies to

Officially: Non-U.S. persons located outside the United States.

In practice: Data relating to U.S. citizens may also be collected when they communicate with targeted non-U.S. persons.

Impact

Privacy: Communications using U.S.-based online services may, under the legal conditions of Section 702, become subject to surveillance measures.

Business: European organizations storing customer data on U.S. servers cannot guarantee that those data are beyond the reach of U.S. government authorities.

Legal remedies: Individuals generally do not learn that they have been subject to surveillance and therefore have very limited practical opportunities to challenge it.

  • 2015: The Court of Justice of the European Union invalidated the Safe Harbor framework.
  • 2020: The Court invalidated the Privacy Shield framework.
  • 2023: EU–U.S. Data Privacy Framework adopted (its legal status continues to be debated).

Reason: PRISM and other U.S. surveillance programs were considered incompatible with the level of data protection required under EU law.

What can you do?

Avoid U.S.-based services (highly effective)

Instead of Gmail: Mailbox.org, Posteo, Tuta (formerly Tutanota) or other European providers
Instead of Google Drive: Self-hosted Nextcloud
Instead of WhatsApp: Signal or Matrix

Limitation: This approach is most effective only if the people you communicate with also use these alternatives.

End-to-end encryption (moderately effective)

Use Signal for messaging and providers such as Tuta or Proton Mail for email.

Important: Metadata—such as who communicates with whom, when, and how often—can still remain visible. With some services, backups may also be stored without end-to-end encryption.

Self-hosting (very effective)

Operate your own mail server, cloud storage, or website on infrastructure located in Germany or another trusted jurisdiction.

Dragons@Work offers: Migration & Self-Hosting Service

VPN (limited effectiveness)

A VPN encrypts the connection between you and your Internet provider. Once data reaches a U.S.-based service, however, a VPN does not prevent access under PRISM.

  • Tempora: GCHQ (United Kingdom) interception of fiber-optic communications
  • XKeyscore: NSA system for searching collected intelligence data
  • Upstream: NSA collection at major Internet backbone infrastructure

Technical details

Encryption: PRISM operates at the server side, where data are often available in unencrypted form. Only true end-to-end encryption protects message contents from server-side access.

Metadata: Even with strong end-to-end encryption, metadata such as IP addresses, timestamps, communication frequency, and device identifiers may still be available.

Sources

Sources archived on: 2026-08-02