Law & jurisdiction
What is MLAT?
An MLAT is a treaty through which one country formally requests another to gather evidence on its behalf. Requests routinely take six to eighteen months, most treaties require dual criminality, and many exclude civil matters entirely — which is why offshore jurisdiction is particularly effective against speculative civil discovery.
Why MLAT matters
Requests routinely take six to eighteen months, most treaties require dual criminality, and many exclude civil matters entirely — which is why offshore jurisdiction is particularly effective against speculative civil discovery.
MLAT in practice
When an MLAT request lands on your server, the first thing you'll notice is a sudden change in availability: the hoster tells you the instance is under legal hold, and you lose the out-of-band VNC console. You stop taking snapshots because they'd be evidence. Your cost is time: requests routinely take six to eighteen months, during which you can't migrate or rebuild without tipping off the requester. Getting it wrong means the evidence you held becomes admissible against you, and dual criminality means even legitimate activity can look suspicious.
What people get wrong about MLAT
People assume MLATs are fast, like a subpoena. The misconception is that a request lands within weeks. The correction is that these routinely take six to eighteen months, and most treaties require dual criminality, so the requesting state must show the act is a crime in both jurisdictions. That delay is exactly why offshore hosting works: by the time a request completes, your operation has moved on.
MLAT — common questions
How long does an MLAT request take?
Requests routinely take six to eighteen months. That's not a delay you can accelerate; it's the treaty process moving through two governments. Meanwhile, you have time to move data, change infrastructure, and render the request moot, especially if your hosting is offshore and the request has to cross borders.
Does dual criminality protect me?
It helps, but not fully. Dual criminality means the act must be a crime in both the requesting and requested countries. So if your activity is legal offshore but not in the requesting state, the request can fail. But it's not a blanket shield: many treaties interpret dual criminality broadly, and your activity might still be illegal in both places.
Where MLAT comes up
- What is an MLAT and why does it matter for hosting? A mutual legal assistance treaty is the formal channel through which one country asks another to gather evidence on its behalf. It matters because a foreig…
- What is offshore hosting? Offshore hosting means placing a server in a jurisdiction other than your own — usually one outside the Fourteen Eyes intelligence-sharing alliances and ou…
- Offshore vs onshore hosting: what actually changes Offshore hosting means placing a server in a jurisdiction other than your own, usually one outside the Fourteen Eyes alliances and outside EU data-retentio…
More from law & jurisdiction
- Warrant canary
- A warrant canary is a regularly republished statement that a provider has not received a secret legal demand; its disappearance implies that one has arrived.
- KYC
- KYC is the set of identity-verification duties imposed on regulated financial institutions before providing services.
- No-KYC hosting
- No-KYC hosting is server hosting that requires no identity verification — no government ID, billing address, phone number or payment card.
- Offshore hosting
- Offshore hosting means placing a server in a jurisdiction other than your own, typically one outside the Fourteen Eyes alliances and outside EU data-retention rules.
- Five Eyes
- The Five Eyes is a signals-intelligence sharing alliance between the United States, United Kingdom, Canada, Australia and New Zealand.
- Fourteen Eyes
- The Fourteen Eyes is the widest of the signals-intelligence sharing groupings, comprising the Five Eyes plus Denmark, France, the Netherlands, Norway, Belgium, Germany, Italy, Spain and Sweden.
- DMCA
- The DMCA is United States copyright statute whose notice-and-takedown procedure and safe harbour apply to service providers situated in the United States.
- Data retention
- Data retention laws require communications providers to store connection metadata for a defined period so that authorities can obtain it later.