The US CLOUD Act: Why a US Law Can Reach Your Data in Europe
When people entrust documents to a cloud service, they usually ask one question: where are the servers? For the US CLOUD Act, that is the wrong question. The 2018 law does not attach to where data sits but to the company that controls it - which is how it reaches data centres in Frankfurt or Dublin. Here is what the CLOUD Act actually allows, what it does not, and how to tell whether your provider is within its reach.
Last reviewed: August 20, 2026
What is the US CLOUD Act?
CLOUD Act is short for Clarifying Lawful Overseas Use of Data Act, a US federal law passed in March 2018. It obliges communications and cloud providers subject to US jurisdiction to disclose stored data to US law enforcement regardless of which country the data is in. What matters is solely whether the data is in the provider's possession, custody or control - the statute's own wording.
The name is slightly misleading: the law is only indirectly about "the cloud" in the marketing sense. It amends a 1986 statute, the Stored Communications Act, which governs when US authorities may demand stored content from providers. The CLOUD Act's contribution is to make clear that this obligation does not stop at the border.
The backstory: Microsoft v. United States
The trigger was a court case known as "Microsoft Ireland". In 2013, a US court in a drug investigation demanded the emails of an account that Microsoft stored in its Dublin data centre. Microsoft refused, arguing that a US warrant does not reach servers in Ireland - that is what the mutual legal assistance process between states is for.
The dispute went up through the courts: an appeals court sided with Microsoft in 2016, and by 2018 the case sat before the Supreme Court. Before the justices could rule, Congress passed the CLOUD Act and answered the question by statute - the storage location is irrelevant. The case was declared moot. The legal position has been unambiguous ever since, which is exactly why it is worth knowing.
It is corporate control that counts, not server location
The point most discussions miss: the CLOUD Act attaches to the company, not to the server. It covers whoever is subject to US jurisdiction - US companies including their foreign subsidiaries, and in principle also foreign firms with a sufficient business presence in the United States.
A Frankfurt data centre run by the German subsidiary of a US group is therefore within reach: the data is under the group's control, and that is precisely what the law asks about. Choosing "Region: EU" or "data residency: Germany" changes nothing here - it determines where the data sits, not whose law the provider must follow.
The reverse also holds: a provider whose ultimate parent is in the EU, with no US parent above it, is simply not an addressee of a CLOUD Act order. If US authorities want data held there, they must go through the state-to-state legal assistance route, in which the local authorities and courts take part.
What the CLOUD Act allows - and what it does not
The CLOUD Act is not a surveillance programme and not bulk access. It changes nothing about the fact that US authorities need formal legal process for every disclosure: for content such as emails or files, a judge must issue a warrant based on probable cause, directed at specific accounts. Suspicionless or blanket collection is not what the law provides for.
Orders are issued in specific criminal investigations - fraud, drug offences, cybercrime and the like. The large providers publish transparency reports about such requests; each one concerns individual, named accounts.
Providers can push back only within narrow limits. The law lets them challenge an order where the person concerned is not a US person and disclosure would conflict with the law of a country that has concluded a CLOUD Act agreement with the United States. Such agreements exist so far with the United Kingdom and Australia - there is none with the EU or Germany, though negotiations have been running since 2019. For data in the EU, this safeguard therefore remains largely theoretical.
The CLOUD Act and the GDPR: an unresolved conflict
Seen from Europe, the CLOUD Act cuts across the GDPR. Under Article 48 GDPR, a judgment or decision of a third-country authority requiring the disclosure of personal data may only be recognised if it is based on an international agreement, such as a mutual legal assistance treaty. A CLOUD Act order is precisely not that: it travels straight from a US court to the provider, bypassing the treaty route.
The European Data Protection Board and the European Data Protection Supervisor concluded in a joint assessment in 2019 that a disclosure based on the CLOUD Act alone will, as a rule, find no legal basis in the GDPR. An affected provider is caught between two legal systems: comply with the US order and it may breach the GDPR - refuse, and it faces sanctions in the United States.
The European Court of Justice's Schrems II ruling of 2020 strikes the same nerve. It struck down the then EU-US data transfer framework because US surveillance law permits access that Europeans cannot effectively contest - that concerned intelligence powers above all, not the CLOUD Act itself. The successor framework agreed in 2023 addresses those intelligence-access concerns; the CLOUD Act's disclosure obligations towards law enforcement continue unaffected.
What this means for you in Germany and the EU
First, the sober framing: the probability that US investigators take an interest in a private person's utility bills in Germany is practically zero. CLOUD Act orders presuppose a specific US criminal investigation. If none concerns you, this law will in all likelihood never touch your data.
The real issue sits one level deeper. If your documents live with a US-controlled provider, then in the decisive moment US law applies US standards to the disclosure - with no German or EU court involved, and without you necessarily ever learning of it, because US orders can come with a gag order that forbids the provider to tell you. And for anyone handling other people's data professionally - a medical practice, a law office, a business with customer records - the unresolved legal conflict is itself the risk, whether or not an order ever arrives.
In short: for most private individuals the CLOUD Act is not an acute access problem but a fundamental control problem - the question of which legal system your documents ultimately answer to. If that matters to you, the clean solution lies in the choice of provider.
How to tell whether a service is exposed to the CLOUD Act
Whether a service is subject to the CLOUD Act rarely appears on its pricing page. The line "your data is stored in Germany" answers the wrong question. Look for the ultimate parent company instead: the legal notice, the privacy policy or the company's Wikipedia entry will almost always tell you who ultimately owns the provider and where that company is incorporated.
For the big names the answer is simple: Microsoft, Google, Amazon with AWS, Apple and Dropbox are US companies subject to US jurisdiction - together with their European subsidiaries and data centres. That is not an accusation but a legal consequence of where they are incorporated; some of these very providers have fought overbroad access in court for years, as the Microsoft case shows.
Questions worth asking yourself - or the provider:
- Who ultimately owns the provider, and where is that parent company incorporated?
- Is the "European" service just the EU subsidiary of a US group?
- Does the provider state plainly whether it is subject to the CLOUD Act - or does it only advertise server locations?
- Who are the subprocessors, for storage or AI processing for instance, and where are they based?
What an EU data centre buys you - and what it does not
None of this makes an EU data centre worthless. It keeps the data physically in Europe, places the processing under European data protection supervision, shortens network paths and satisfies many compliance requirements. The one thing the location cannot do is change the legal system its operator answers to. "Data residency: Germany" at a US-controlled provider means German hardware under US jurisdiction.
Offerings marketed as a "sovereign cloud" deserve a second look too. Where a US group remains the operator or your contracting party, nothing changes about its legal reachability. Arrangements in which an independent European company runs the service and merely licenses the technology can genuinely differ - there, the details decide.
The robust difference lies with the provider itself: a company incorporated in the EU with no US parent is not an addressee of a CLOUD Act order. If US authorities want data held there, the route runs through a legal assistance request to the local authorities - with judicial oversight in that country. For a broader look at the options for personal documents, see our guide comparing document management approaches.
How PaperHero handles this
PaperHero made this question a selection criterion for every service provider involved: your documents are stored and processed exclusively by companies domiciled in Germany or France that belong to no US group. A disclosure order under the CLOUD Act therefore has no addressee that holds your documents.
That holds in every hosting tier: EU Hosting, German Hosting and PaperHero Hosting differ in where the AI processing runs, not in this ground rule. For payments, PaperHero uses Stripe and Apple - both handle the transaction and see no document content.
Frequently asked questions
Is the CLOUD Act compatible with the GDPR?
There is an open conflict. Under Article 48 GDPR, a provider may generally only disclose personal data on the basis of a third-country order if an international agreement, such as a mutual legal assistance treaty, provides for it. No such agreement on the CLOUD Act exists between the US and the EU. The European data protection bodies therefore consider a disclosure based on the CLOUD Act alone to be, as a rule, incompatible with the GDPR - and the conflict remains unresolved to this day.
Does an EU data centre protect against the CLOUD Act?
No. The CLOUD Act explicitly does not turn on where data is stored, but on whether the provider is subject to US jurisdiction and controls the data. A US group's Frankfurt data centre therefore remains within reach. Protection comes not from the location of the servers but from a provider that belongs to no US group.
Does the CLOUD Act affect me as a private individual?
Directly only if US authorities are investigating a specific criminal case that touches you or your circle - which for the vast majority of people in Europe never happens. The law still matters, though: it decides which legal system your data answers to, whether a court in your own country is involved in any access, and whether you would ever find out. If you want to avoid that, choose a provider with no US corporate ties.
What is the difference between the CLOUD Act and the Patriot Act?
The Patriot Act of 2001 broadly expanded US surveillance and investigative powers after September 11, including for intelligence agencies. The CLOUD Act of 2018 settles a narrower point: providers under US jurisdiction must disclose stored data even when it sits abroad. In public debate, access to data overseas used to be attributed to the Patriot Act - today, the CLOUD Act is the legal basis that matters for it.
Will I be notified if my data is handed over?
You cannot rely on it. US orders can be accompanied by a court-imposed gag that forbids the provider to inform the person concerned. Some providers notify users where they are legally allowed to - but under US law you have no entitlement to be told.
Does encryption protect against the CLOUD Act?
Partly. A provider must hand over what it holds. If it manages the encryption keys itself, it can hand over readable data. With genuine end-to-end encryption, where only you hold the keys, it can only deliver ciphertext. The CLOUD Act contains no obligation to break encryption. What matters, then, is who holds the keys.
Does the CLOUD Act also apply to European companies?
It can. The law covers whoever is subject to US jurisdiction - which, beyond US firms and their subsidiaries, can in principle include European companies with a substantial business presence in the United States, such as their own US branch. A provider that is based and operates exclusively in Europe, by contrast, is not an addressee of a CLOUD Act order.