Cloud Act
LawWhat is the Cloud Act?
The Cloud Act (Clarifying Lawful Overseas Use of Data Act) is a U.S. law enacted in 2018. It allows U.S. authorities to require U.S. companies to disclose data regardless of the country in which the data is physically stored.
Enacted: March 23, 2018
Effective: March 23, 2018
What this means in practice
If a U.S. company operates servers in Germany, U.S. authorities can still access the data stored there. This can place the company in a conflict between U.S. law and European data protection law.
Affected are:
- All U.S. companies and their subsidiaries
- Cloud providers (Amazon AWS, Microsoft Azure, Google Cloud)
- Software as a Service providers (Microsoft 365, Salesforce, Zoom)
- Communication services (WhatsApp, Facebook, Gmail)
The company is often not even allowed to inform the affected person that their data has been requested (gag order).
Background
The Cloud Act originated from a legal dispute between Microsoft and the U.S. Department of Justice. The FBI requested emails stored on a Microsoft server in Ireland. Microsoft refused, arguing that U.S. laws do not apply outside the United States.
The case reached the Supreme Court. Before a decision could be issued, Congress passed the Cloud Act, explicitly granting U.S. authorities worldwide access powers.
How it works
Request
- A U.S. authority (FBI, NSA, DEA, etc.) applies for a court order.
- A U.S. court reviews the requirements under U.S. law, not whether the request is compatible with the data protection law of the country where the data is stored.
- The company receives an order to disclose the data.
- The company must comply within a short period (often 14 days).
- The order is often accompanied by a gag order.
No notification
In most cases, the affected person never learns that their data has been disclosed. Under a gag order, the company may not even discuss the request internally except with those directly involved.
No review under European law
The U.S. court reviews the request under U.S. law—not whether the disclosure complies with the laws of the country in which the data is stored.
Who is affected?
Companies
All U.S. corporations:
- Examples: Microsoft, Google, Amazon, Facebook, Apple, Cloudflare
- Location irrelevant: Yes—even if the subsidiary is registered in the EU
U.S. subsidiaries:
- Examples: WhatsApp (Facebook), LinkedIn (Microsoft), GitHub (Microsoft)
- Location irrelevant: Yes—also applies to European subsidiaries
Cloud providers:
- Examples: AWS, Azure, Google Cloud, Oracle Cloud
- Issue: Even if a German company uses only EU data centers, the operator is a U.S. company, so the Cloud Act still applies.
Types of data
- Emails and messages
- Stored files and backups
- Customer data and contracts
- Metadata (who communicates with whom)
- Usage statistics
- Billing information
Conflicts with EU law
GDPR
The General Data Protection Regulation (GDPR) prohibits the transfer of personal data to third countries without an adequate level of protection. The United States is not generally regarded as providing an adequate level of protection.
The Cloud Act therefore directly conflicts with the GDPR. Companies subject to both legal frameworks are caught between them.
Blocking statutes
Some EU countries have laws prohibiting companies from disclosing data to foreign authorities without a local court order.
The Cloud Act does not recognize these national laws. U.S. companies must choose between the two legal systems and generally comply with U.S. law because failure to do so may result in penalties in the United States.
CJEU judgments
In 2020, the Court of Justice of the European Union declared the EU–U.S. Privacy Shield invalid (Schrems II).
The main reason: U.S. surveillance programs such as PRISM and legal powers such as the Cloud Act are not compatible with fundamental rights guaranteed by EU law.
Legal situation for companies
Dilemma
German companies using U.S. cloud services face a difficult situation:
- Use U.S. services: Possible GDPR violation
- Refuse cooperation with U.S. authorities: The cloud provider may terminate services or face penalties under U.S. law
- Switch to EU providers: Often higher costs and fewer features
Recommendations from authorities
The Federal Commissioner for Data Protection and Freedom of Information and several German state data protection authorities advise against using U.S. cloud services for sensitive data.
Particularly sensitive:
- Health data
- Employee data
- Customer data of EU citizens
- Trade secrets
Fines
GDPR violations related to the use of U.S. services may result in fines of up to 4 percent of worldwide annual turnover or €20 million.
The first cases already exist: In 2021, the Austrian Data Protection Authority prohibited the use of Google Analytics because of the Cloud Act.
What companies can do
Choose EU providers
Examples:
- Hetzner (Germany) instead of AWS
- IONOS (Germany) instead of Microsoft 365
- Nextcloud (self-hosted) instead of Google Drive
Advantage: No Cloud Act, EU data protection law applies.
Disadvantage: Potentially fewer features or higher costs.
Self-hosting
Operate your own servers in Germany or elsewhere in the EU. This provides full control over data and removes dependence on U.S. companies.
Effort: High—requires IT expertise.
End-to-end encryption
Encrypt data before uploading it to the cloud. The cloud provider cannot decrypt it and therefore cannot disclose its contents to authorities.
Problem: Practical mainly for stored files. Much harder to implement for collaboration tools and email. Metadata remains visible.
Hybrid approach
Store non-sensitive data in U.S. cloud services while keeping sensitive data self-hosted or with EU providers. This requires careful data classification.
What individuals can do
Avoid U.S. services
Email:
- U.S.: Gmail, Outlook.com
- EU: Mailbox.org, Posteo, Tuta
Cloud storage:
- U.S.: Google Drive, Dropbox, OneDrive
- EU: Nextcloud (self-hosted), STRATO HiDrive
Messaging:
- U.S.: WhatsApp, Facebook Messenger
- EU: Signal, Matrix (federated)
Video conferencing:
- U.S.: Zoom, Google Meet, Microsoft Teams
- EU: Jitsi (self-hosted), BigBlueButton
Communicate consciously
For sensitive communication, consider which services the other party uses. If they reply through Gmail, your emails will still be stored on U.S. servers.
Exceptions and limitations
Bilateral agreements
The Cloud Act allows bilateral agreements between the United States and other countries, establishing rules for reciprocal data requests.
Agreements currently exist with the United Kingdom and Australia. An EU–U.S. agreement has been discussed but not implemented.
Notification requirement
In some cases, the government of the country where the data is stored must be informed. This happens only if:
- Both countries have an agreement
- The data concerns only citizens of the other country
- There are no national security concerns
In practice, notification is rare.
Political dimension
U.S. position
The U.S. government argues that the Cloud Act is necessary to combat crime and terrorism. Without it, criminals could simply store their data abroad to avoid U.S. law enforcement.
EU position
The EU considers the Cloud Act to be an infringement of European sovereignty. Access to data should occur through international mutual legal assistance rather than unilateral orders.
The EU is working on its own digital sovereignty strategy with a focus on European cloud providers.
China and Russia
Similar laws exist in China (Cybersecurity Law) and Russia (Data Localization Law). These require data relating to Chinese or Russian citizens to remain within those countries while also granting authorities access.
This contributes to the fragmentation of the Internet into separate spheres of influence.
Technical background
Server location
In the past, the assumption was: data stored on German servers is governed by German law. The Cloud Act changes this. What matters is not where the hardware is located, but who owns or controls the company.
Encryption
The Cloud Act generally requires providers to disclose data that they possess or control. If the provider holds the decryption keys, this may include decrypted data.
Only true end-to-end encryption, where the provider does not possess the keys, protects the content—although metadata can still be accessed.
Future
Trend toward data localization
More and more countries require data relating to their citizens to remain within their borders. The Cloud Act is accelerating this development.
European cloud initiatives
Gaia-X and other EU initiatives aim to establish European cloud alternatives. Their success has so far been limited because U.S. hyperscalers continue to dominate in technology and pricing.
Sources
Analysis
Sources archived on: 2026-08-02