Not necessarily talking about encryption or security of data, that should already be an inherent part of cloud systems.
I am talking about protections on unauthorized access by agencies (even for national security) meaning no more blanket access to all email/files/etc rather explicit machine read systems that only access data that has a warranted access and useful to the investigations.
Human access should not be allowed unless the data has already been warranted, filtered by the system and useful in the investigation that the NSA/DOJ/ etc might be using.
A big problem right now with it is blanket access and collecting content in bulk to sift through. There should be no way a human can go into an email box or cloud files and read everything for instance unless the person themselves is under investigation, email communication with that person can only be pulled from other innocent people's boxes that are part of the investigation, not everything. As is it right now they just collect everything and store it. It should also have heavy encryption and 3-5 approvals/logs/access audits per individual human access so there is a minimized threat of people searching business ideas for personal gain. This would prevent the one time email or document share with someone that they allows access to all their data. Explicit access and heavily verified across judicial, audits and multiple users 3-5 at least approving or seeing the access within the security organization.
NSA and CIA etc are patriots and like their freedoms as well, I am sure they don't want colleagues stealing ideas, business plans and random people's personal info when they go civilian. It is currently too sweeping and broad due to terrorism threats that have yet to take away as many freedoms as our own internal legal overreaches.
For example, right now let's say I am some crooked agent or politician, I could have one email or call to a person and justify looking at all their data. This might be someone who is in a competitive company or business information they want to find out. Steps like the above would minimize those abuses which are bound to happen. Take for instance oil mining or product plans, these types of competitive environments are very susceptible to snooping and corporate espionage without heavy controls on access to data.
Protection for international users in the same as US persons. Noone will trust storing data on our servers and cloud systems if they know all their data is being filtered and easily accessible by a single agent.
Also, extremely fast audits, judicial warranting. There is no reason it should take a long time with today's tools. I imagine the NSA and others are collecting all this data because the bureaucracy makes it difficult to get approvals in time, so they go in bulk as a fail safe. I dont' envy them the work is very hard and it is justified when true threats exist, these people typically aren't evil and most have the best intentions. But with great access to information comes a power that is hard to contain if not verified.
Timed release/removal of information that is not needed now, not indefinite storage. Will this make us less safe? Maybe but freedoms are not easy, it takes work to be free. Authoritarian is easy.
Maybe something like a Bill of Data Rights that also applies to international people in addition to the US. We would really revolutionize rights and data rights in the world, it would attract alot of business to data storage in the US. However currently data is free-er in other places sadly.