CLOUD Act: Why Hosting in Europe Doesn't Protect You from US Law

The CLOUD Act gives US authorities access to data held by US-based providers worldwide. Microsoft admitted this under oath before the French Senate in 2025. Here's what it means for your European cloud stack, and which providers actually stand outside US reach.

11 min readLire en françaisAuf Deutsch lesen
CLOUD Act: Why Hosting in Europe Doesn't Protect You from US Law

TL;DR

The CLOUD Act, passed in March 2018, gives the US Department of Justice the right to demand any data held by a company under US jurisdiction, regardless of where that data is stored. On June 10, 2025, Microsoft France admitted under oath before the French Senate that it could not guarantee European citizens' data would never be transmitted to US authorities. Storing your data in Frankfurt, Paris or Dublin doesn't help if your provider's parent company is American. Only a handful of European providers (Scaleway, Outscale, STACKIT, Hetzner, IONOS, Infomaniak, Clever Cloud) sit fully outside CLOUD Act reach.

On June 10, 2025, before the French Senate inquiry commission on European digital sovereignty, Anton Carniaux, director of public and legal affairs at Microsoft France, took the oath. Senator Dany Wattebled asked him a direct question: could he guarantee that data of French citizens hosted by Microsoft would never be transmitted to US authorities without an explicit French government request?

His answer, recorded in the Senate transcript: "No, I cannot guarantee it."

That single sentence ends an eight-year-old debate over "sovereign cloud" from American hyperscalers. It confirms what European lawyers and digital sovereignty advocates have been saying since 2018: a US law called the CLOUD Act gives American authorities the right to demand any data held by any company under US jurisdiction, regardless of where that data sits physically. Your data center in Frankfurt is no more European, in the legal sense, than one in Virginia.

This article explains what the CLOUD Act actually says, why it works the way it does, what the European response has been (and why most of it has failed), and which providers in 2026 sit genuinely outside its reach.

What the law actually says

The CLOUD Act, formally the Clarifying Lawful Overseas Use of Data Act, was adopted on March 23, 2018, as part of the Consolidated Appropriations Act of that year (Public Law 115-141). It tucks neatly into Title 18 of the US Code, Chapter 121, the section that governs stored communications. Its core operative text fits in two sentences:

A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.

The legal test is not where the data is. It is who has "possession, custody, or control" of the data. If that entity is subject to US jurisdiction, the location of the bytes is irrelevant. This is a fundamental shift in how digital sovereignty needs to be understood.

The law was rushed through Congress in response to a Supreme Court case (Microsoft Corp. v. United States) where Microsoft had refused, on territorial grounds, to hand over emails stored in Dublin. The Court was about to rule. Congress legislated first, and the case became moot in April 2018.

Four US tools, often conflated

The CLOUD Act is not the only US legal instrument that touches European data. Confusing it with the others muddles the conversation. Four distinct mechanisms exist:

CLOUD Act warrants (18 U.S.C. § 2713) require a federal judge to find probable cause and target a specific person in a criminal investigation. They are subject to gag orders, can run for renewable periods, and can be challenged through a "comity analysis" if the target is a non-US person and disclosure conflicts with the laws of a "qualifying foreign government". So far, only the United Kingdom and Australia qualify. The European Union has been negotiating an executive agreement since 2019, without result.

FISA Section 702 (50 U.S.C. § 1881a) authorizes mass surveillance certified annually by the Attorney General and the Director of National Intelligence, targeting non-US persons abroad for foreign intelligence. There is no individualized warrant, no notice, and no meaningful EU recourse. This was the primary reason the Court of Justice of the EU invalidated the Privacy Shield in Schrems II. FISA 702 was reauthorized in April 2024 and expires again on April 20, 2026.

National Security Letters (18 U.S.C. § 2709) are administrative orders issued by the FBI without judicial review. They can demand metadata only and are systematically accompanied by indefinite gag orders.

FISA Section 215 (50 U.S.C. § 1861) covers the collection of business records for foreign intelligence purposes.

For a European CTO, all four matter. But the CLOUD Act is the one that most directly forces a private company to hand over your data on demand, not for intelligence purposes, but for ordinary criminal investigations.

Why "data in Frankfurt" doesn't help

The Microsoft Ireland case is instructive precisely because it established the principle the CLOUD Act then codified. In December 2013, a US magistrate judge issued a warrant requiring Microsoft to produce emails associated with a drug trafficking investigation. The emails were stored exclusively in Dublin. Microsoft refused on territorial grounds. The Second Circuit Court of Appeals sided with Microsoft in July 2016. The Supreme Court granted certiorari, heard oral arguments in February 2018, and was preparing to rule when Congress adopted the CLOUD Act on March 23, 2018. The case was declared moot. The DOJ promptly reissued the warrant under the new law. Microsoft complied.

What this teaches: the question is not where the server is, who built the data center, or which flag flies outside the front door. The question is who controls the entity that holds your data. If that entity, or its parent company, is subject to US jurisdiction, the CLOUD Act applies. Microsoft France, an entity of Microsoft Inc., falls squarely under it. AWS Frankfurt, an entity of Amazon.com Inc., does too. Google Belgium, an entity of Alphabet Inc., as well.

What Microsoft admitted before the Senate

The June 10, 2025 testimony at the French Senate is now part of the legal record. Anton Carniaux took the oath. Asked whether Microsoft could guarantee that European data would never be transmitted to US authorities, he answered: "No, I cannot guarantee it." His colleague Pierre Lagarde, technical director for public sector, added that since January 2025 European customer data "does not leave the EU under normal conditions". The question, of course, was about abnormal conditions.

This admission carries institutional weight. It is not an opinion piece from a privacy advocate or a marketing slide from a competitor. It is sworn testimony from the executive responsible for Microsoft's legal and public affairs in France, given in response to a question from an elected senator, recorded in the official record. It confirms what the law has said since 2018.

Microsoft has spent considerable energy marketing its "EU Data Boundary" since 2024 and its "Microsoft Sovereign Cloud" announced in June 2025. These initiatives may reduce the volume of European data physically leaving the EU. They cannot change the legal status of Microsoft Inc. as a Delaware corporation subject to US warrants.

The Court of Justice of the European Union has already ruled on this question. In Data Protection Commissioner v. Facebook Ireland and Schrems (Case C-311/18, July 16, 2020), commonly known as Schrems II, the Court invalidated the EU-US Privacy Shield. Paragraph 184 of the judgment is unambiguous: US surveillance laws, specifically FISA Section 702 and Executive Order 12333, do not provide a level of protection essentially equivalent to that guaranteed by Article 47 of the Charter of Fundamental Rights.

The Court allowed Standard Contractual Clauses to continue, but only with documented Transfer Impact Assessments and supplementary measures when the law of the third country creates risk. The European Data Protection Board, in its Recommendations 01/2020, identified end-to-end encryption with keys held exclusively within the EEA as the principal effective supplementary measure. Crucially, encryption managed by the US provider does not qualify. The provider can be compelled to produce the key.

The Data Privacy Framework adopted in July 2023 does not change this analysis. It is being challenged before the Court of Justice in the Latombe case, with the appeal filed on October 31, 2025. In January 2025, the Trump administration paralysed the Privacy and Civil Liberties Oversight Board, which the framework's adequacy decision cited thirty-one times. The trajectory is clear.

For broader context on how European businesses are responding, see our guide to digital sovereignty.

Why European responses haven't worked

France adopted a blocking statute on July 26, 1968 (loi 68-678) to prevent French companies from handing economic and commercial data to foreign authorities without going through proper diplomatic channels. The Gauvain report, delivered to the French Prime Minister on June 26, 2019, was blunt: "The blocking statute does not work. And in truth, it has never really been enforced." A February 2022 decree created an alert mechanism overseen by the Service de l'information stratégique et de la sécurité économiques (SISSE), but enforcement remains sporadic.

The EU Regulation 2271/96 (the "Blocking Statute") was adopted in 1996 and reactivated in 2018 against US sanctions on Iran. The Court of Justice ruled in Bank Melli Iran v. Telekom Deutschland (Case C-124/20, December 21, 2021) that its Article 5 has direct effect. But the regulation only covers specifically annexed US extraterritorial sanctions against Cuba and Iran. It does not cover the CLOUD Act.

The institutional response is shifting. The Draghi report (September 9, 2024) explicitly calls for "EU sovereign control of key elements for security and encryption" in cloud services. The EU Cloud and AI Development Act, with its Call for Evidence opened in April 2025, is expected to define standards for "highly secure EU-based cloud and AI computing capacity". The EuroStack initiative, launched in early 2025 and now backed by over 300 European CEOs, asks for 300 billion euros of investment by 2035.

Whether these initiatives produce binding legal protection within the next 24 months is uncertain. What is certain is that CTOs cannot wait for them.

Which providers actually sit outside CLOUD Act reach

Faced with this reality, the European cloud market sorts into four tiers.

Tier 1: Structural immunity. Providers that meet four cumulative criteria: 100 percent European ownership, no US subsidiary, exclusively European staff with data access, and European-held encryption keys. Scaleway (France, Iliad Group), Outscale (France, Dassault Systèmes, the first public cloud qualified SecNumCloud 3.2 in December 2023), STACKIT (Germany, Schwarz Group), Hetzner (Germany, family-owned), IONOS (Germany, United Internet, listed Frankfurt 2023), UpCloud (Finland), Clever Cloud (France), Infomaniak (Switzerland, with the caveat that Switzerland is not in the EU but operates under its own data protection law), Exoscale (Switzerland, A1 Telekom Austria).

Tier 2: European with structural US exposure. OVHcloud is the complex case. Listed on Euronext Paris with the Klaba family as majority owner, OVHcloud operates a US subsidiary (OVHcloud US LLC) running two data centers in Virginia and Oregon with around 200 staff. The company's official position is that the CLOUD Act does not apply to OVH France. AWS publicly disagrees on its own compliance page. On September 25, 2025, in The King v. OVH Canada, an Ontario court compelled OVH Canada to produce data stored on servers in France, the UK, and Australia. The practical conclusion: OVHcloud is a sovereign provider for services qualified under SecNumCloud, operated in its Trusted Zones (Roubaix, Gravelines, Strasbourg) with EU-exclusive staff and strict logical isolation. Outside these qualified perimeters, residual exposure cannot be ruled out.

Tier 3: Hyperscaler/EU joint ventures. Bleu (Capgemini and Orange, deploying Azure and Microsoft 365), S3NS (Thales majority, Google capped below 24 percent equity), Delos Cloud (SAP-owned, operated by Arvato Systems on Microsoft tech). S3NS obtained SecNumCloud 3.2 in December 2025. These arrangements isolate the European operation from the US parent's mass operations and reduce CLOUD Act exposure significantly. Residual risk: the software stack still comes from a US editor, so a commercial rupture (the SAP-Microsoft talks in 2024, the OpenDesk replacement at the International Criminal Court in October 2025) can leave the platform unavailable.

Tier 4: US hyperscalers with "EU Data Boundary" or "European Sovereign Cloud" branding. Microsoft Azure, AWS European Sovereign Cloud (generally available January 15, 2026, first region Brandenburg, 7.8 billion euros investment), Google Cloud, Oracle, IBM Cloud, Salesforce. All share the same structural flaw: the US parent can receive a CLOUD Act warrant covering data processed by the European subsidiary. Marketing brochures cannot override the corporate law of Delaware.

For a deeper comparison of European cloud providers and pricing, see our European cloud providers vs AWS guide. For the broader framework of cloud sovereignty levels, see our four levels of cloud sovereignty guide.

The CTO's six-question test

Before signing any cloud contract, run your provider through six binary questions:

  1. Capital. Is the parent company incorporated in the EU/EEA and majority-owned (over 60 percent) by EU/EEA entities?
  2. US subsidiary. Does the group operate a US legal entity with active operations, US staff, or US customer contracts?
  3. Operational staff. Are the system administrators with access to data and keys exclusively residents of the EU/EEA, subject to EU labour law?
  4. Encryption. Are encryption keys (at rest and in transit) held exclusively in the EEA, in a Hardware Security Module under your control or under the provider's control without US access?
  5. Source code. Is the critical software layer European or open-source auditable, or does it depend on a US editor that can be constrained by export controls?
  6. Continuity. In case of a US service rupture (sanctions, embargo, export controls), can the system continue to operate in degraded mode for at least 12 months without external dependency?
Six "yes" answers indicate Tier 1. Five "yes" with one isolated US software dependency indicate Tier 3 mitigation. Four or fewer place the provider in Tier 4 territory.

The practical playbook

For workloads handling sensitive data under GDPR Article 9, strategic data, intellectual property, or critical infrastructure: migrate to Tier 1 providers within the next 90 days, or to Tier 3 providers if Microsoft or Google software dependencies are non-substitutable. Activate client-side encryption with European key management (HSM solutions from Thales Luna, Atos, Utimaco).

For workloads on Tier 4 providers, document an exit plan within 12 months. This means knowing the migration duration, cost, target Tier 1 alternative, and blocking dependencies (typically proprietary US software licences). Review the plan every 12 months.

Trigger events that should accelerate the migration: a Court of Justice ruling invalidating the Data Privacy Framework in the Latombe case, US renewal of FISA 702 beyond April 20, 2026 without substantive reforms, publication of the Cloud and AI Development Act with binding "EU sovereign control" criteria, or an acquisition of your current Tier 2 provider by a non-EU entity (the Solvinity acquisition by Kyndryl announced in November 2025 illustrates this latter risk).

The Microsoft Senate testimony did not change the law. The law has been clear since March 2018. What changed is the publicly available evidence that a hyperscaler executive, under oath, cannot guarantee what their marketing has been promising. Plan accordingly.

Key Takeaways

  • The CLOUD Act of 2018 extends US jurisdiction over any data held by US-based providers worldwide, replacing territory with corporate control as the legal test.
  • On June 10, 2025, Microsoft France stated under oath before the French Senate that it could not guarantee European citizens' data would never be transmitted to US authorities, ending the marketing debate over "sovereign cloud" from US hyperscalers.
  • The European response, including the French blocking statute and EU Regulation 2271/96, has consistently failed to deter US extraterritorial demands.
  • Schrems II (CJEU, 2020) confirmed that US surveillance laws do not provide protection equivalent to GDPR Article 47, undermining all data transfers from the EU to US providers.
  • Only providers with 100 percent European ownership, no US subsidiary, exclusively European staff, and European-held encryption keys offer structural immunity from the CLOUD Act.

Frequently Asked Questions

Is the CLOUD Act compatible with the GDPR?
No. The Court of Justice of the EU ruled in Schrems II (July 2020) that US surveillance laws, including FISA 702 and the EO 12333, do not provide protection equivalent to GDPR Article 47. The CLOUD Act compounds this by allowing the US Department of Justice to compel any US-based provider to disclose data wherever it is stored. European Data Protection Authorities consistently treat data transfers to US-controlled providers as presumptively non-compliant with the GDPR, unless supplementary technical measures (specifically end-to-end encryption with EU-held keys) are applied.
Does data localization in Europe protect me from the CLOUD Act?
No. The CLOUD Act applies based on who has "possession, custody, or control" of the data, not on where the data is physically stored. AWS Frankfurt, Azure Paris, and Google Belgium are all subsidiaries of US companies and remain subject to US jurisdiction. The Microsoft Ireland case established this principle, and Congress codified it in 2018.
Which European cloud providers are truly outside the CLOUD Act?
Providers with 100 percent European ownership, no US subsidiary, EU-exclusive staff with data access, and European-held encryption keys offer structural immunity. In 2026, this includes Scaleway, Outscale, STACKIT, Hetzner, IONOS, Clever Cloud, UpCloud, Infomaniak, and Exoscale. OVHcloud is sovereign for SecNumCloud-qualified services in its Trusted Zones, but has residual US exposure via its US subsidiary outside those perimeters. Joint ventures like Bleu, S3NS, and Delos Cloud mitigate exposure but remain dependent on US software editors.
What about the French blocking statute and EU Regulation 2271/96?
Both exist on paper. The French law (loi 68-678 of 1968) has been described by the Gauvain report of 2019 as "never really enforced". EU Regulation 2271/96 only covers specifically annexed US extraterritorial sanctions against Cuba and Iran. Neither offers practical protection against CLOUD Act warrants. A CTO planning around their deterrent effect is planning around nothing.
What is the practical impact of the Microsoft Senate testimony of June 10, 2025?
Anton Carniaux, director of public and legal affairs at Microsoft France, under oath before the French Senate inquiry commission, stated "No, I cannot guarantee" that data of French citizens would never be transmitted to US authorities. This is the first time a senior executive of a US hyperscaler has admitted, in formal testimony, the limit of "sovereign cloud" marketing. The legal status of US providers in Europe has not changed since 2018, but the public proof has now been recorded.

Related Posts

Help us map the European stack.

Submit a tool or suggest an edit. We review every entry.