US CLOUD Act
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a United States federal law enacted in March 2018. It amends the Stored Communications Act (1986) and governs when and how US law enforcement can compel technology and cloud companies to disclose customer data — including data stored on servers outside the United States.
How it works
Under the CLOUD Act, US-based cloud providers (or foreign providers with a sufficient US presence, such as a US subsidiary or US-based operations) can be served with a warrant requiring them to produce data they “control, possess, or have access to,” regardless of where that data is physically stored. The key principle is control, not location: a warrant can reach data held in a Frankfurt, Paris, or Amsterdam data centre if the provider is a US entity.
This is why a US-headquartered cloud company is, under US law, capable of complying with data requests for European-customer data hosted in European data centres — even without the customer’s knowledge or consent.
Why it matters
The CLOUD Act is central to the European sovereignty debate because it creates a legal pathway for US government access to data held by US-owned cloud providers, irrespective of EU data-protection or location requirements. This creates a tension with EU law:
- GDPR restricts cross-border data transfers and limits access by foreign governments.
- The EU-US Data Privacy Framework (2023) attempts to reconcile this, but its adequacy remains contested and legally fragile (it has faced challenges similar to its invalidated predecessors, Safe Harbour and Privacy Shield).
- SecNumCloud (France) and the proposed EUCS (EU Cloud Certification Scheme) include “non-exEU ownership” / immunity-from-foreign-law requirements precisely to counter CLOUD Act exposure.
How US companies are responding
In response, US hyperscalers launched “sovereign” offerings (AWS European Sovereign Cloud, Microsoft Cloud for Sovereignty, Oracle Sovereign Cloud, T-Systems’ sovereign offering on Google Cloud) that attempt to ring-fence operational control inside the EU. These offerings typically:
- Store data in EU data centres operated by EU entities.
- Restrict operational access to EU-based, EU-cleared staff.
- Use encryption with keys held under EU control.
However, because the parent company remains US-headquartered, these structures do not fully insulate data from CLOUD Act warrants. True legal insulation generally requires a provider that is headquartered and operated entirely outside US jurisdiction. Check the european.cloud cloud provider directory to find a suitable one.