US CLOUD Act
In shortUS providers must hand over data even when it sits in Frankfurt.
At a glance
- Instrument
- Clarifying Lawful Overseas Use of Data Act, enacted in March 2018 as part of an appropriations bill
- Who is covered
- Providers of electronic communication and storage services subject to US jurisdiction, including subsidiaries under effective control
- Trigger
- Possession, custody or control of the data, not where it is stored
- Conflict
- Article 48 GDPR recognises third-country orders only through a mutual legal assistance treaty; the CLOUD Act provides no such route
- Are customers told?
- Not necessarily — orders can carry a non-disclosure obligation
- What works
- A provider with no US parent, or encryption whose keys the provider does not hold
The Clarifying Lawful Overseas Use of Data Act was enacted in March 2018. It ended a dispute Microsoft had carried for years up to the Supreme Court: must a US corporation hand over emails held on a server in Ireland?
The legislature's answer is yes. What matters is not where the data sits but the company's control over it. That retired an assumption a large part of European procurement practice rested on — the assumption that a data centre in the EU brings a legal order with it.
Who the statute covers
The CLOUD Act applies to any provider of electronic communication or storage services subject to US jurisdiction. That means American corporations, and it means their subsidiaries where the parent exercises effective control.
That last clause is the difficult one in practice. A German company with a German managing director, German staff and German data centres can still be covered if the group parent holds access rights, runs operating processes or issues instructions. Conversely, arrangements exist in which a European operator alone controls the data and the US corporation only supplies technology. The difference is contractual and organisational rather than technical — and it is the heart of what separates a Sovereign cloud from a cloud with a European address.
The conflict with the GDPR
Article 48 GDPR says, in substance: a judgment or an authority's order from a third country is a permissible basis for a transfer only where a mutual legal assistance treaty carries it. The CLOUD Act deliberately provides no such route; it creates a direct path from the US authority to the company.
A US provider with European customers therefore stands between two legal orders that contradict each other, and both carry severe sanctions. In practice the legal order where the management sits, and where prison sentences are possible, tends to win.
What this means for a decision
It does not mean American providers hand over data freely. There is judicial review, there are internal procedures and transparency reports, and providers have repeatedly challenged individual orders in court.
It means the risk does not sit with you, and you may never learn about it. Orders can carry a non-disclosure obligation that forbids notifying the customer.
For most companies that is bearable. For health data, defence projects, live negotiations and design data it frequently is not. The difference lies not in the technology but in what a single access would cost.
What actually helps
Choice of provider. A provider with no US parent takes the question off the table. It is the only measure that works completely — and it is why a provider's ownership chain deserves regular review rather than a single check at signing.
Key control. Encryption defeats a disclosure order only if the party disclosing cannot make the data readable. Keys held in-house, or deposited with an independent third party, turn a disclosure into the handover of unusable blocks. What to watch for is set out under Key control.
Data classification. Not all data needs the same answer. An hour spent deciding which categories would genuinely cause harm replaces most debates of principle and turns a question of worldview into a procurement question.
What does not help
A server location on its own. A contractual assurance that "data does not leave the EU" — it describes normal operation, not an order. And a certificate that examines operational security while saying nothing about the ownership chain; which Certifications cover what is an entry of its own.
Related rules
The CLOUD Act is not the only norm in play. FISA 702 concerns surveillance of non-US persons by US intelligence agencies and was the reason the Court of Justice struck down the previous adequacy decision in Schrems II. The CLOUD Act governs the law-enforcement route, FISA 702 the intelligence route. Assessing a provider requires looking at both.
Common questions
- Does a data centre in Germany rule out the CLOUD Act?
- No. The order is addressed to the company, not the building. What counts is whether an entity subject to US jurisdiction possesses, has custody of, or controls the data. A German location changes nothing as long as the parent exercises effective control over the subsidiary.
- Does the CLOUD Act reach the German subsidiary of a US group?
- Usually yes, where the parent exercises effective control — over management, access rights or operating processes. Simply incorporating a German entity does not sever the link.
- Does encryption help against a CLOUD Act order?
- Only if the provider does not hold the key. Buying storage and key management from the same company moves the problem rather than solving it. Keys held in-house or by an independent third party are the only technical answer.
- How often do such orders actually happen?
- Large providers publish transparency reports with orders of magnitude, but no attribution to individual customers. For risk assessment what matters is therefore not frequency but what a single access would cost your company.
Sources
See also
Related terms
- FISA 702US intelligence agencies may access Europeans' data held by American providers, and those affected are not told.
- Schrems IISince 2020 you must assess yourself whether data is safe in the recipient country — the provider cannot do it for you.
- Sovereign cloudSovereign cloud is not a protected term. Ask which of the four layers the provider actually means.