Pillars
    12 min read

    The CLOUD Act and Its Implications for European Businesses

    Last reviewed: 1 February 2026

    The Clarifying Lawful Overseas Use of Data (CLOUD) Act, enacted in 2018, grants US law enforcement the authority to compel US-based technology companies to provide data stored on servers regardless of physical location. For European organisations, this creates a tension with GDPR and raises fundamental questions about data control.

    Understanding the CLOUD Act is essential for technical leaders evaluating US-headquartered cloud and SaaS providers. However, the practical risk it presents varies significantly depending on the type of data, the specific provider, and the organisation's risk tolerance.

    This guide provides a factual overview of the CLOUD Act, addresses common misconceptions, and outlines practical considerations for European organisations.

    What the CLOUD Act Does

    The CLOUD Act amends the Stored Communications Act to clarify that US law enforcement can compel US-based service providers to produce data in their possession, custody, or control, regardless of where that data is physically stored.

    Key provisions include:

    **Extraterritorial reach**: US authorities can demand data stored on servers outside the United States if the provider is subject to US jurisdiction.

    **Provider scope**: Any provider incorporated in the US, or that has sufficient contacts with the US, falls under the Act's scope. This includes the major cloud providers (AWS, Microsoft Azure, Google Cloud) and most prominent SaaS companies.

    **Legal process requirements**: Requests must go through proper legal channels—warrants for content, subpoenas for metadata. The Act does not grant arbitrary access; standard legal protections apply.

    **Comity provisions**: Providers can challenge requests that conflict with foreign law, and the Act provides a framework for executive agreements between the US and other countries to streamline requests.

    The Act was partly a response to the Microsoft Ireland case, where Microsoft challenged a warrant for data stored in Irish data centres. The CLOUD Act resolved this by making clear that location does not limit US authority over US-based providers.

    The GDPR Conflict

    The CLOUD Act creates a direct tension with GDPR:

    **GDPR Article 48**: Prohibits transfer of personal data based on foreign government requests unless there is an international agreement (such as a mutual legal assistance treaty) or the request is recognised under EU law.

    **Conflicting obligations**: A US provider receiving a CLOUD Act request for data of EU residents faces conflicting legal obligations—comply with US law or violate GDPR.

    **No resolution mechanism**: Unlike some international legal conflicts, there is no established mechanism for resolving CLOUD Act-GDPR conflicts. The EU-US Data Privacy Framework addresses commercial data transfers but does not resolve government access conflicts.

    **Provider liability**: Providers caught in this conflict bear legal risk in both jurisdictions. This has led some providers to advocate for clearer international frameworks.

    In practice, how providers navigate this conflict varies. Some have committed to challenging requests that conflict with foreign law. Others have been less transparent about their approach. The European Data Protection Board has taken the position that CLOUD Act requests should be resisted unless proper legal channels are followed, but enforcement is limited.

    Common Misconceptions

    Discussion of the CLOUD Act often includes exaggerations and misunderstandings:

    **"The US government can access any data at any time"**: CLOUD Act requests require legal process. US authorities cannot simply demand data without warrants or subpoenas, and providers can challenge overbroad requests.

    **"Using EU regions protects against the CLOUD Act"**: Physical data location does not change the provider's legal obligations. EU region deployment provides data residency but not jurisdictional protection.

    **"The CLOUD Act is used constantly against European businesses"**: Published data on actual CLOUD Act use against European organisations is limited. The threat is real but should not be overstated. Most requests target criminal investigations, not commercial espionage.

    **"All US providers are equally risky"**: Provider policies, transparency reports, and technical architectures vary. Some providers have stronger track records of challenging problematic requests.

    **"European providers are immune"**: European providers can face similar pressures through different mechanisms. No provider is entirely immune from government access requests.

    **"Encryption doesn't help"**: Client-side encryption with customer-managed keys can limit provider access, though this has operational implications and may not address all scenarios.

    Practical Risk Assessment

    The relevance of CLOUD Act risk depends on organisational context:

    **Factors increasing relevance**: - Processing highly sensitive personal data (health, financial, legal) - Handling data that could be relevant to US government interests - Operating in sectors with geopolitical sensitivity - Regulatory requirements specifying data sovereignty - Contractual commitments to clients regarding data location

    **Factors decreasing relevance**: - Processing only routine business data - Data already public or low sensitivity - Strong contractual protections with providers - Use of client-side encryption - Sector with no particular US government interest

    For many organisations, the practical risk of a CLOUD Act request is low. For others—particularly those handling sensitive data or operating in strategic sectors—it represents a material concern that affects provider selection.

    Risk assessment should be proportionate. Not every system requires the same level of protection, and resources should focus on genuinely sensitive workloads.

    Mitigation Options

    Organisations concerned about CLOUD Act exposure have several options:

    **Provider selection**: Choosing providers incorporated in jurisdictions not subject to similar extraterritorial access laws reduces exposure. European-headquartered providers are not subject to the CLOUD Act (though they may face other pressures).

    **Technical controls**: Client-side encryption with customer-managed keys limits what providers can disclose. Zero-knowledge architectures provide stronger protection but require more operational investment.

    **Contractual provisions**: While contracts cannot override law, provisions requiring notification of requests (where legally permitted), commitment to challenge conflicting requests, and transparency reporting provide some comfort.

    **Hybrid approaches**: Using European providers for sensitive workloads while accepting US providers for less sensitive systems balances protection with practicality.

    **Monitoring and audit**: Maintaining visibility into where data flows and how providers handle access requests supports ongoing risk management.

    No mitigation fully eliminates the risk for organisations using US-based providers. The question is whether residual risk is acceptable given organisational requirements.

    The Evolving Legal Landscape

    The CLOUD Act situation is not static:

    **EU-US Data Privacy Framework**: The successor to Privacy Shield addresses commercial data transfers but does not resolve CLOUD Act conflicts. Its durability is also uncertain given previous legal challenges.

    **Executive agreements**: The CLOUD Act provides for bilateral agreements that would streamline cross-border requests. A UK-US agreement exists; EU-US negotiations are ongoing but slow.

    **European legislative responses**: Various EU legislative proposals have addressed data sovereignty concerns, though none directly counteract the CLOUD Act.

    **Provider responses**: Major providers continue to develop technical and policy responses to address customer concerns, though fundamental jurisdictional issues remain.

    Technical leaders should monitor developments without over-reacting to individual announcements. The legal landscape will continue to evolve, and today's assessments may need revision.

    Key Takeaways for Technical Leaders

    • The CLOUD Act allows US authorities to compel US providers to produce data regardless of storage location
    • This creates direct tension with GDPR, with no established resolution mechanism
    • Practical risk varies significantly based on data sensitivity and organisational context
    • EU data residency does not protect against CLOUD Act—provider jurisdiction is what matters
    • Mitigation options include European provider selection, encryption, and contractual provisions, but none fully eliminate risk

    Audit your technology stack

    This guide covers one topic. Your Technology Stack Audit scores your entire technology stack as one system, ranks what to fix first, and maps how your tools depend on each other. One-off €99.

    Audit my technology stack — €99