Legal jurisdiction

CLOUD Act

The CLOUD Act is a US law. It lets US authorities request data from US companies, even when the data sits on servers in Europe.

The CLOUD Act is a US law from 2018. It lets US government agencies request data from any company under US jurisdiction. This includes data stored in Europe, on European servers. The company’s headquarters decides which laws apply, not the server’s location. This is why a European data center does not always mean European data protection. If a cloud provider has a US A subsidiary is a company owned or controlled by another, larger company. What looks like a European brand can be a subsidiary of a US parent. Learn more → , the CLOUD Act can still reach your data.

Frequently asked questions

What is the CLOUD Act in simple terms?

The CLOUD Act is a US law from 2018. Its full name is the Clarifying Lawful Overseas Use of Data Act. It says US law enforcement can order a company to hand over data. This applies even if the data sits on a server in another country.

Before this law, the rules were unclear. A 2016 case involved Microsoft and emails stored in Ireland. US courts had to decide if American law reached data stored abroad. Congress answered by passing the CLOUD Act. The rule became simple: the company's home country matters, not the server's location.

Does the CLOUD Act apply to companies operating in Europe?

Yes, in two situations. First, it applies to any company based in the US, no matter where in the world it operates. Second, it can apply to a European company if a US parent company actually controls it.

This means a European-sounding brand is not automatically safe from the CLOUD Act. A company can have European offices and European customers. But if a US parent owns it and controls its data, US law can still reach that data.

Can the CLOUD Act reach data stored on servers in the EU?

Yes. This is exactly the problem the law was written to solve. Before the CLOUD Act, server location seemed to matter a lot. The CLOUD Act removed that idea for companies under US jurisdiction. It doesn't matter where their data centers are.

This is why "EU data residency" from a US company can be misleading. It tells you where your files sit. It does not tell you which government can force the company to hand them over. Those are two separate questions, which is also why data residency and data sovereignty are different ideas.

Is the CLOUD Act compatible with GDPR?

The two laws often conflict. GDPR normally requires a clear legal reason before a company can send personal data to a foreign government. A CLOUD Act request comes from US law, not EU law. So it doesn't automatically meet GDPR's requirements.

This puts companies in a difficult position. A US order tells them to hand over data. GDPR tells them not to, without a proper legal basis. Neither law overrules the other. No single court can settle the conflict for both sides at once.

How is the CLOUD Act different from FISA 702?

The CLOUD Act is a law enforcement tool. It works like a search warrant. Police or prosecutors can use it to request specific data for a specific investigation. It reaches data held abroad, as long as a US company controls it.

FISA 702 is different. It is a surveillance tool, not a criminal investigation tool. It lets US intelligence agencies collect large amounts of foreign communications at once. There is no warrant naming one person. The two laws work in different ways. But together, they are the most common reasons US companies can be forced to share European data with the US government.