TL;DR: New research from privacy company Proton shows Google, Apple, and Meta disclosed data on 3.5 million user accounts to U.S. authorities between late 2014 and early 2025. That's a 770% increase. When you add FISA requests, the number climbs to 6.7 million. Apple's disclosures shot up 927%. And these companies comply with 80-90% of requests. The government doesn't need to hack your phone. It just asks nicely.
The Numbers Don't Lie
Proton published updated research on April 1, 2026 tracking government data requests to the three biggest tech companies over the past decade. The headline number (770% increase) is bad enough. The company-by-company breakdown is worse.[1]
- Google: 557% increase in disclosed accounts
- Meta: 668% increase
- Apple: 927% increase
In the first half of 2025 alone, these three companies disclosed data from more than 282,000 U.S. accounts. That's over 1,500 accounts per day.[1]
Raphael Auphan, Proton's COO, put it bluntly: "All that's required for the government to find out just about everything it could ever need is a request message to Big Tech in California."[2]
FISA Makes It Worse
Those 3.5 million accounts? That's just routine requests: subpoenas, court orders, and the like. Proton's analysis also tracked disclosures under the Foreign Intelligence Surveillance Act, and the FISA numbers are where things get genuinely alarming.[1]
Between 2014 and 2024, FISA content requests exploded:
- Meta: 2,486% increase in FISA content requests
- Google: 649% increase
- Apple: 443% increase (data only available from 2018)
When you combine routine disclosures and FISA, the total reaches roughly 6.7 million account disclosures through the end of 2024. That's 6.7 million times these companies opened the door and let the government walk through your data.[1]
The 80-90% Compliance Rate
Here's the part that should make you reconsider what you store in the cloud: Google, Apple, and Meta comply with government data requests 80-90% of the time.[2]
Your emails. Your files. Your messages. Your photos. Your location history. When the government asks, Big Tech says yes almost every time.
This isn't about whether these companies want to protect your privacy. Meta generates 98% of its revenue from advertising. Google pulls in 77% from ads. Their business model is built on collecting your data. The government just gets to cut in line.[3]
Europe Isn't Better
If you're thinking GDPR protects Europeans from this, think again. EU member states requested data on 231,199 accounts in the first half of 2025 alone, up 40% year-over-year.[1]
Over the past decade, EU government data requests have surged over 1,100%. Germany leads the pack with 101,811 account requests in H1 2025, followed by France (36,831), Poland (24,373), and Spain (20,984).[1]
GDPR was designed to protect citizens from corporations. Nobody wrote rules to protect them from their own governments using corporations as a surveillance pipeline.
Why This Matters Right Now
This research drops at a particularly ugly moment for surveillance accountability:
- FISA Section 702 expires in 18 days (April 20, 2026). Congress is fighting over whether to renew the warrantless surveillance authority that enables many of these FISA requests. The Government Surveillance Reform Act would require warrants. A clean extension would keep the current system, and these numbers, growing.
- The data broker loophole is still open. Federal agencies can buy data from brokers that they'd otherwise need a warrant to collect. The 6.7 million figure doesn't even include data the government purchased from third parties: only what it formally requested through legal channels.
- ICE is building surveillance infrastructure at scale. A $28.7 billion surveillance arsenal that combines facial recognition, license plate readers, and social media monitoring. The same companies handing over account data are building the tools to process it.
What You Can Actually Do
The math here is simple: if you store data with companies that comply with 80-90% of government requests, that data isn't really private.
- Use end-to-end encrypted services. Proton can only share metadata (IP address, email address, recipient) when it receives government requests. It literally cannot access your email content, files, or calendar entries because of end-to-end encryption. Signal offers the same protection for messaging.
- Minimize what you store. Google doesn't need 10 years of your search history. Go into your account settings and delete it. Turn off location history. Apple doesn't need your entire photo library in iCloud. Store it locally and encrypted.
- Use a VPN. Even end-to-end encrypted services can be compelled to share IP addresses. A reputable VPN adds a layer between you and metadata collection.
- Tell Congress to fix this. Section 702 expires April 20. Call your representative and demand warrant requirements for government data access. The SAFE Act and Government Surveillance Reform Act both address the problem. Clean extensions make it permanent.
The Bottom Line
6.7 million accounts. 770% growth. Compliance rates above 80%. These aren't abstract numbers. They represent real people whose emails, messages, photos, and files were handed over, usually without the person ever knowing it happened.
Big Tech built the largest data collection infrastructure in human history. The government realized it didn't need to build its own. It just needed to ask.
References
- Proton: A 770% Surge in Big Tech Data Requests (April 1, 2026)
- Proton: Authorities Worldwide Can See More Than Ever, With Big Tech as Their Eyes
- The Hill: Government Requests for Social Media User Data Up 770 Percent in Past Decade
- Bloomberg: US Government Requests for Social Media User Data Are Soaring (April 1, 2026)