Executive Summary

Encryption plays a critical role in data privacy and security by safeguarding online communications, enabling free speech, and protecting financial transactions, among other things. The Center for Cybersecurity Policy & Law, along with the vast majority of the cybersecurity community, believes weakening encryption would jeopardize the security, privacy, civil liberties, and vital social interests of every organization and individual.

While encryption protects individuals against crimes, like identity theft or unlawful surveillance, law enforcement and national security agencies argue that encryption makes it more challenging, or impossible, for law enforcement to investigate crimes and threats to public safety. Some argue, in the digital age, investigation necessarily requires digital evidence, including intercepted and decrypted communications related to public safety, terrorism, and child sex abuse materials (CSAM).

Opponents of encryption have framed this as a debate with two opposing sides, when we are actually united by a common cause against the same adversaries. Encryption protects everyone, including children and other vulnerable populations. Technology companies, including social media sites and messaging applications, do not want to be conduits to criminal activities or have illicit materials on their platforms.

The authors of this paper believe that it is time to rethink the conversation. As such, government and law enforcement must take a practical, incremental approach to policies and legislation that affect law enforcement and online security, rather than mandating ubiquitous surveillance that can circumvent encryption.

This paper will:

  • Examine the historic discussion and arguments around encryption policy.
  • Review recurring themes among proposals in the context of current policies and legislation.
  • Establish how the modern encryption debate should proceed.
  • Address the potential challenges should the discourse remain unaltered.

To download the paper in Japanese click here.

To download the paper in Korean click here.

To download the paper in Spanish click here.

To download the paper in Turkish click here.

Heather West, Zack Martin & Ivy Orecchio

Read Next

EU’s Cyber Resilience Act Enters Into Force

New product cybersecurity requirements are coming to the EU single market after years of intense debate and negotiation in Brussels, as the European Union’s Cyber Resilience Act officially enters into force.

Through the Looking Glass: An Updated Vision for the Office of the National Cyber Director

The ONCD was established to advise the President on cybersecurity and has matured into a key component of cybersecurity policymaking. However, changes are needed to ensure the efficacy of the office, especially as it relates to other agencies.

The U.S. Data Security EO with Lee Licata and Grant Dasher (Part 2)

For the first time in the Distilling Cyber Policy podcast, Alex and Jen are re-joined by guests from earlier this season: Lee Licata, from the Department of Justice, and Grant Dasher, from CISA.