US extraterritorial law

The US CLOUD Act and your EU-hosted data

The CLOUD Act is the reason "our data is in an EU region" is not the reassurance it sounds like. It lets US authorities compel a US-based provider to hand over data it controls, wherever in the world that data physically sits. This page explains what the law actually says, who it binds, and why an EU datacentre operated by a US company does not put your data beyond its reach.

This is general information about the CLOUD Act, not legal advice. For a binding view on your exposure, ask a qualified lawyer.

What the CLOUD Act is, and who it binds

The Clarifying Lawful Overseas Use of Data Act, passed in the US in 2018, amended the Stored Communications Act to settle a simple question: can a US provider be forced to produce data it holds abroad? The answer it wrote into law is yes. A provider subject to US jurisdiction must produce data in its "possession, custody, or control", whether that data is stored in the United States or in a datacentre in the EU.

"Subject to US jurisdiction" is the load-bearing phrase. It covers companies incorporated in the US, and it reaches non-US subsidiaries and affiliates of US parents where the parent has control. An EU-registered subsidiary of a US cloud provider does not, on its own, escape it. This is a question of corporate control, not server location.

Why an EU region does not solve it

The instinctive fix is to pick the provider’s Frankfurt or Paris region. That satisfies data residency, and residency is real: the bytes are in the EU. But the CLOUD Act does not turn on where the bytes are. It turns on whether the entity that controls them answers to a US court.

If that entity is a US company or its controlled subsidiary, an EU region changes the storage location and nothing about the legal reach. The order is served on the provider, not on the datacentre. This is the gap between residency and legal sovereignty, and it is the gap the CLOUD Act lives in.

The conflict with GDPR

Here two legal systems collide. Article 48 of the GDPR says a judgment or decision of a non-EU authority requiring a transfer of personal data is only enforceable if it rests on an international agreement, such as a mutual legal assistance treaty. A bare CLOUD Act order is not that. So a US provider can face a US order to produce and an EU rule that says complying would be an unlawful transfer.

The provider is caught between the two, and so, indirectly, are you as its customer. This tension is not hypothetical: it is the core of why European regulators and the EDPB treat US-controlled providers as carrying a residual access risk that contractual clauses alone cannot fully remove.

What actually reduces the exposure

Two levers change the picture, and encryption is only half of one. Holding your own encryption keys, entirely outside the provider’s control, means an order served on the provider yields ciphertext it cannot read. That helps, as long as the keys never touch the provider’s key-management service.

The other lever is the one residency cannot offer: using a provider that is not subject to US jurisdiction in the first place. A European provider with no US parent and no US operations has nothing for a US order to compel. That is the reasoning behind French state doctrine and the SecNumCloud immunity criterion, and it is why the destination provider’s ownership, not just its regions, belongs on your checklist.

What is contested, and what is settled

How aggressively the CLOUD Act is used against EU-stored data, and how often, is genuinely uncertain: the orders are not public, and providers report them only in aggregate. Some argue the practical risk to ordinary commercial workloads is low. That may be true today, but it is a statement about enforcement frequency, not about legal reach, and the two should not be blurred.

What is not contested is the reach itself. The law is explicit that location of storage is not a defence, and the US Supreme Court case that prompted it (Microsoft v. United States) was rendered moot precisely because Congress legislated the answer. Betting on low enforcement is a risk decision; assuming the reach does not exist is a factual error.

Common questions about the CLOUD Act

Does the CLOUD Act apply if my data never leaves the EU?
Yes, if the provider that holds it is subject to US jurisdiction. The law is written specifically to cover data stored outside the United States. An EU storage region controls where the data sits, not whether a US-controlled provider can be compelled to produce it. Storage location is not a defence under the Act.
Can contractual clauses stop a CLOUD Act order?
No contract between you and a provider can override a lawful US order served on that provider. Clauses can require notice where the law permits it, and commit the provider to challenge overbroad requests, but they cannot remove an obligation US law imposes directly on the provider. Only a provider outside US jurisdiction removes the obligation itself.
Is a US provider’s EU "sovereign" partnership enough?
It depends entirely on control. Some US providers operate EU offerings through a local partner that holds the operations and the keys. Whether that genuinely removes US reach turns on who controls the operating entity and the encryption keys in practice, not on the branding. Read the control structure, not the label.