Tutorials  /  Security

The CLOUD Act and Its Impact on European Companies

LLudwig · August 2026 ·13 min read ·Security, Tutorial

Every procurement review of a US cloud service eventually reaches the same question: can American authorities demand our data even though it sits in a European data centre? The CLOUD Act is the law that made that question concrete, and it is the reason "the data stays in Frankfurt" is no longer a complete answer. This guide explains what the act says, which providers it reaches, and where it collides with European data protection law.

What is the CLOUD Act?

The CLOUD Act, short for Clarifying Lawful Overseas Use of Data Act, is a 2018 US federal law that obliges providers under US jurisdiction to produce data they control, regardless of where that data is physically stored.

It was enacted in March 2018 as part of a larger appropriations act and settled a dispute that had reached the US Supreme Court: in the so-called Microsoft Ireland case, a provider argued that a US warrant could not reach e-mail content stored in a Dublin data centre. The CLOUD Act answered the question legislatively, and the case was dismissed as moot.

Technically the act does two things. First, it amends the Stored Communications Act (part of the Electronic Communications Privacy Act, 18 U.S.C. § 2701 et seq.) by adding a clarification that the storage location of the data is irrelevant to the production obligation. The operative wording is short:

text
A provider of electronic communication service or remote computing service
shall comply with the obligations of this chapter to preserve, backup, or
disclose the contents of a wire or electronic communication and any record
or other information pertaining to a customer or subscriber within such
provider's possession, custody, or control, regardless of whether such
communication, record, or other information is located within or outside
of the United States.

That excerpt reflects the provision added as 18 U.S.C. § 2713; check the current text on an official source such as the US Government Publishing Office before quoting it in a document of your own.

Second, the act creates a framework for bilateral executive agreements (18 U.S.C. § 2523) under which a qualifying foreign government may serve orders directly on US providers, and vice versa, bypassing the slower mutual legal assistance treaty route. The agreements are the part of the CLOUD Act that is still evolving.

Which companies does the CLOUD Act apply to?

The CLOUD Act applies to providers of electronic communication or remote computing services that fall under US jurisdiction — US-incorporated companies above all, and, where the test of possession, custody or control is met, their foreign subsidiaries.

Two points matter for a European reader. The obligation runs against the provider, not against you as the customer: nobody will serve a US warrant on a German manufacturing company for data held at its own site. And the decisive criterion is not the location of the servers but corporate control over the data. A European subsidiary of a US group can be within reach if the US parent has practical or legal control over the data; how far that reaches has not been exhaustively settled by the courts, and legal opinions in the EU differ. Treat it as a risk to assess, not a settled fact in either direction.

graph TD
    A["Which company operates the service that holds your data?"] --> B{"Is the provider incorporated in the United States, or a subsidiary a US parent controls?"}
    B -->|Yes| C["US jurisdiction is plausible. CLOUD Act production orders are possible."]
    B -->|No| D{"Does the provider have US presence, US staff or US infrastructure that could establish jurisdiction?"}
    D -->|Yes| C
    D -->|"No or unclear"| E["US jurisdiction is unlikely. Verify subprocessors and support arrangements."]
    C --> F{"Can the provider access your data in plaintext?"}
    F -->|Yes| G["Content can be produced. Assess GDPR Chapter V exposure."]
    F -->|No| H["Only ciphertext and metadata can be produced. Residual risk remains in metadata."]
    E --> I["Re-assess whenever the subprocessor list changes."]
Constellation Typical assessment
US provider, US data centre Clearly in scope
US provider, EU data centre In scope; storage location does not exclude the order
EU subsidiary of a US group Contested; depends on control over the data
EU provider with US subsidiary Depends on whether the US entity has access to the data
EU provider, no US nexus Generally out of scope of the CLOUD Act

What can US authorities actually demand?

Under the CLOUD Act, US authorities can compel a provider to preserve and disclose stored content and subscriber records that the provider controls, using the instruments of the Stored Communications Act — a judicially issued warrant for content, and lower-threshold instruments for metadata and subscriber information.

Three properties of that process shape the risk for a European customer:

  • Metadata is easier to obtain than content. Account identifiers, log data and connection records are typically available under a lower legal standard than message or file content. Metadata alone can be highly revealing.
  • You may never learn about it. US law allows courts to attach non-disclosure orders to production demands, so the provider can be barred from telling the affected customer for a period of time.
  • The safeguards for foreigners are narrow. The act gives providers a route to challenge an order where the target is not a US person and disclosure would risk violating the law of a government that has a qualifying executive agreement with the US. Since the EU as a whole has no such agreement in force at the time of writing, that mechanism offers European customers less than its existence suggests. Verify the current list of agreements with the US Department of Justice, which maintains a CLOUD Act resource page.

Where does the CLOUD Act collide with the GDPR?

The conflict sits in Article 48 GDPR, which provides that a judgment or decision of a third-country authority requiring a transfer of personal data is only recognisable or enforceable in the EU if it is based on an international agreement such as a mutual legal assistance treaty.

A direct CLOUD Act order served on a provider is not such an agreement. The European Data Protection Board and the European Data Protection Supervisor examined exactly this in their joint response to the LIBE committee on the impact of the CLOUD Act, published in July 2019, and concluded that the act does not by itself provide a lawful basis for a transfer under EU law. A provider caught between both regimes therefore faces a genuine conflict of laws, and the controller — that is, your company — carries the GDPR-side responsibility for the transfer.

The exposure is not theoretical. Infringements of the transfer rules in Chapter V fall into the higher fine tier of Article 83(5) GDPR, up to 20 million euros or four percent of total worldwide annual turnover, whichever is higher. This is not legal advice, and whether a given constellation constitutes an infringement depends on the facts; the point is that the risk sits with the controller, not with the provider that received the order.

SEC

Matching infrastructure at centron

Security by default: cloud firewalls filter traffic before it reaches the instance, managed centrally. Explore cloud firewalls →

What does the CLOUD Act mean for your infrastructure?

For most organisations the CLOUD Act is a procurement and architecture question rather than a compliance checklist. These are the levers that actually change the picture:

  • Provider jurisdiction. Establish which legal entity operates the service, where it is incorporated, and which group it belongs to. This is the single largest factor and the only one you control at the point of purchase.
  • The subprocessor chain. A European provider that runs support, monitoring or backup through a US-controlled subprocessor reopens the question. Read the subprocessor list and the change-notification clause.
  • Key management. If the provider cannot decrypt your data, a production order yields ciphertext. Customer-held keys, external key management and confidential computing shift the boundary — but only for content, not for metadata the platform necessarily generates.
  • Metadata minimisation. Consider what the platform must know to operate: account names, IP addresses, billing records, access logs. Reducing what accumulates reduces what can be produced.
  • Contractual commitments. Look for a clear obligation to challenge unlawful orders, to notify you as far as legally permitted, and to publish transparency reports. Also look for what is not promised.
  • Documentation. Where you do use a US-controlled service, record the assessment. Supervisory authorities ask how the risk was evaluated, not whether it was zero.

centron operates as a German company from German data centres and holds a BSI C5:2020 Type 1 attestation without qualification for ccloud³ and Managed Cloud, alongside ISO/IEC 27001, ISO 9001 and ISO 14001 certifications. Those are statements about security management and audited controls; the jurisdictional question above is a separate assessment that you should make on the basis of the corporate structure of any provider you consider.

The CLOUD Act governs access to stored data for criminal law enforcement, whereas FISA Section 702 governs foreign intelligence collection — two different statutes with different thresholds, and conflating them leads to poor risk assessments.

Instrument Purpose Reaches
CLOUD Act (2018) Criminal law enforcement Providers under US jurisdiction, data worldwide
FISA Section 702 Foreign intelligence Certain US electronic communication service providers
MLAT / mutual legal assistance Cross-border evidence via state channels State-to-state requests
EU e-Evidence package Intra-EU production and preservation orders Service providers offering services in the EU

The CJEU decision in Schrems II (C-311/18, July 2020) invalidated the Privacy Shield largely because of US surveillance law, in particular FISA 702 and Executive Order 12333 — not because of the CLOUD Act. The EU–US Data Privacy Framework adequacy decision of July 2023 addresses signals intelligence safeguards; it does not remove the Article 48 GDPR question raised by law enforcement production orders. A provider's DPF certification therefore answers a different question than the one this guide is about.

On the European side, the e-Evidence Regulation (EU) 2023/1543 and the accompanying Directive (EU) 2023/1544 create a comparable direct-order mechanism inside the EU, with application dates set out in the Official Journal text — check the exact date there before relying on it. A negotiated EU–US agreement on cross-border access to electronic evidence has been under discussion since 2019; verify its current status with the European Commission rather than with secondary sources, as it has moved slowly.

Where do the binding statements come from?

For the text of the law, use the official US Code as published by the US Government Publishing Office, and the Department of Justice CLOUD Act resource pages for the current list of executive agreements. For the European assessment, the authoritative starting points are the GDPR text itself, the EDPB and EDPS joint response of July 2019, and the guidance of your national supervisory authority; in Germany, the positions of the Datenschutzkonferenz and the publications of the Bundesamt für Sicherheit in der Informationstechnik are the usual reference points.

Whether a specific provider is within reach of the CLOUD Act is a question about that provider's corporate structure and contracts, and it is a legal question. This guide sets out the criteria; applying them to your own situation, and deciding what follows, belongs with qualified counsel and your data protection officer.

More on compliance

Jetzt 200 € Guthaben sichern

Testen Sie Ihr Setup auf ccloud³

Registrieren Sie sich in der ccloud³ und erhalten Sie 200 € Startguthaben für Ihr Projekt – z. B. für eine PostgreSQL-VM mit automatischen Backups.

Ludwig Technische Redaktion

Schreibt bei centron über Linux-Administration, Container und Datenbanken – mit Fokus auf Anleitungen, die im Betrieb tatsächlich funktionieren.

Kategorie Security
Teilen
Noch offene Fragen?

Unser Team hilft Ihnen bei Ihrem konkreten Setup weiter – von Menschen, die die Plattform selbst betreiben.

War dieses Tutorial hilfreich?

Ihre Antwort wird anonym gespeichert und hilft uns, die Tutorials zu verbessern.

Kommentare

Noch keine Kommentare – stellen Sie die erste Frage zu diesem Tutorial.

Zum Kommentieren anmelden

Kommentare stehen centron-Kunden offen. Melden Sie sich in Ihrem Konto an, um eine Frage zu diesem Tutorial zu stellen.

Weiterlesen

Das könnte Sie auch interessieren

Jetzt kostenlos anfangen

Melden Sie sich an und erhalten Sie in den ersten 60 Tagen ein Guthaben von 200 € bei centron.

Dieses Werbeangebot gilt nur für neue Konten. Angebot ausschließlich für Gewerbetreibende.

Jetzt loslegen Sales kontaktieren