Cloud Act

Law
Also known as: CLOUD Act, Clarifying Lawful Overseas Use of Data Act, US Cloud Act
US law that allows U.S. authorities to access data held by U.S. companies worldwide, regardless of where the servers are located

What is the Cloud Act?

The Cloud Act (Clarifying Lawful Overseas Use of Data Act) is a U.S. law enacted in 2018. It allows U.S. authorities to require U.S. companies to disclose data regardless of the country in which the data is physically stored.

Enacted: March 23, 2018
Effective: March 23, 2018

What this means in practice

If a U.S. company operates servers in Germany, U.S. authorities can still access the data stored there. This can place the company in a conflict between U.S. law and European data protection law.

Affected are:

  • All U.S. companies and their subsidiaries
  • Cloud providers (Amazon AWS, Microsoft Azure, Google Cloud)
  • Software as a Service providers (Microsoft 365, Salesforce, Zoom)
  • Communication services (WhatsApp, Facebook, Gmail)

The company is often not even allowed to inform the affected person that their data has been requested (gag order).

Background

The Cloud Act originated from a legal dispute between Microsoft and the U.S. Department of Justice. The FBI requested emails stored on a Microsoft server in Ireland. Microsoft refused, arguing that U.S. laws do not apply outside the United States.

The case reached the Supreme Court. Before a decision could be issued, Congress passed the Cloud Act, explicitly granting U.S. authorities worldwide access powers.

How it works

Request

  1. A U.S. authority (FBI, NSA, DEA, etc.) applies for a court order.
  2. A U.S. court reviews the requirements under U.S. law, not whether the request is compatible with the data protection law of the country where the data is stored.
  3. The company receives an order to disclose the data.
  4. The company must comply within a short period (often 14 days).
  5. The order is often accompanied by a gag order.

No notification

In most cases, the affected person never learns that their data has been disclosed. Under a gag order, the company may not even discuss the request internally except with those directly involved.

No review under European law

The U.S. court reviews the request under U.S. law—not whether the disclosure complies with the laws of the country in which the data is stored.

Who is affected?

Companies

All U.S. corporations:

  • Examples: Microsoft, Google, Amazon, Facebook, Apple, Cloudflare
  • Location irrelevant: Yes—even if the subsidiary is registered in the EU

U.S. subsidiaries:

  • Examples: WhatsApp (Facebook), LinkedIn (Microsoft), GitHub (Microsoft)
  • Location irrelevant: Yes—also applies to European subsidiaries

Cloud providers:

  • Examples: AWS, Azure, Google Cloud, Oracle Cloud
  • Issue: Even if a German company uses only EU data centers, the operator is a U.S. company, so the Cloud Act still applies.

Types of data

  • Emails and messages
  • Stored files and backups
  • Customer data and contracts
  • Metadata (who communicates with whom)
  • Usage statistics
  • Billing information

Conflicts with EU law

GDPR

The General Data Protection Regulation (GDPR) prohibits the transfer of personal data to third countries without an adequate level of protection. The United States is not generally regarded as providing an adequate level of protection.

The Cloud Act therefore directly conflicts with the GDPR. Companies subject to both legal frameworks are caught between them.

Blocking statutes

Some EU countries have laws prohibiting companies from disclosing data to foreign authorities without a local court order.

The Cloud Act does not recognize these national laws. U.S. companies must choose between the two legal systems and generally comply with U.S. law because failure to do so may result in penalties in the United States.

CJEU judgments

In 2020, the Court of Justice of the European Union declared the EU–U.S. Privacy Shield invalid (Schrems II).

The main reason: U.S. surveillance programs such as PRISM and legal powers such as the Cloud Act are not compatible with fundamental rights guaranteed by EU law.

Dilemma

German companies using U.S. cloud services face a difficult situation:

  • Use U.S. services: Possible GDPR violation
  • Refuse cooperation with U.S. authorities: The cloud provider may terminate services or face penalties under U.S. law
  • Switch to EU providers: Often higher costs and fewer features

Recommendations from authorities

The Federal Commissioner for Data Protection and Freedom of Information and several German state data protection authorities advise against using U.S. cloud services for sensitive data.

Particularly sensitive:

  • Health data
  • Employee data
  • Customer data of EU citizens
  • Trade secrets

Fines

GDPR violations related to the use of U.S. services may result in fines of up to 4 percent of worldwide annual turnover or €20 million.

The first cases already exist: In 2021, the Austrian Data Protection Authority prohibited the use of Google Analytics because of the Cloud Act.

What companies can do

Choose EU providers

Examples:

  • Hetzner (Germany) instead of AWS
  • IONOS (Germany) instead of Microsoft 365
  • Nextcloud (self-hosted) instead of Google Drive

Advantage: No Cloud Act, EU data protection law applies.
Disadvantage: Potentially fewer features or higher costs.

Self-hosting

Operate your own servers in Germany or elsewhere in the EU. This provides full control over data and removes dependence on U.S. companies.

Effort: High—requires IT expertise.

End-to-end encryption

Encrypt data before uploading it to the cloud. The cloud provider cannot decrypt it and therefore cannot disclose its contents to authorities.

Problem: Practical mainly for stored files. Much harder to implement for collaboration tools and email. Metadata remains visible.

Hybrid approach

Store non-sensitive data in U.S. cloud services while keeping sensitive data self-hosted or with EU providers. This requires careful data classification.

What individuals can do

Avoid U.S. services

Email:

  • U.S.: Gmail, Outlook.com
  • EU: Mailbox.org, Posteo, Tuta

Cloud storage:

  • U.S.: Google Drive, Dropbox, OneDrive
  • EU: Nextcloud (self-hosted), STRATO HiDrive

Messaging:

  • U.S.: WhatsApp, Facebook Messenger
  • EU: Signal, Matrix (federated)

Video conferencing:

  • U.S.: Zoom, Google Meet, Microsoft Teams
  • EU: Jitsi (self-hosted), BigBlueButton

Communicate consciously

For sensitive communication, consider which services the other party uses. If they reply through Gmail, your emails will still be stored on U.S. servers.

Exceptions and limitations

Bilateral agreements

The Cloud Act allows bilateral agreements between the United States and other countries, establishing rules for reciprocal data requests.

Agreements currently exist with the United Kingdom and Australia. An EU–U.S. agreement has been discussed but not implemented.

Notification requirement

In some cases, the government of the country where the data is stored must be informed. This happens only if:

  • Both countries have an agreement
  • The data concerns only citizens of the other country
  • There are no national security concerns

In practice, notification is rare.

Political dimension

U.S. position

The U.S. government argues that the Cloud Act is necessary to combat crime and terrorism. Without it, criminals could simply store their data abroad to avoid U.S. law enforcement.

EU position

The EU considers the Cloud Act to be an infringement of European sovereignty. Access to data should occur through international mutual legal assistance rather than unilateral orders.

The EU is working on its own digital sovereignty strategy with a focus on European cloud providers.

China and Russia

Similar laws exist in China (Cybersecurity Law) and Russia (Data Localization Law). These require data relating to Chinese or Russian citizens to remain within those countries while also granting authorities access.

This contributes to the fragmentation of the Internet into separate spheres of influence.

Technical background

Server location

In the past, the assumption was: data stored on German servers is governed by German law. The Cloud Act changes this. What matters is not where the hardware is located, but who owns or controls the company.

Encryption

The Cloud Act generally requires providers to disclose data that they possess or control. If the provider holds the decryption keys, this may include decrypted data.

Only true end-to-end encryption, where the provider does not possess the keys, protects the content—although metadata can still be accessed.

Future

Trend toward data localization

More and more countries require data relating to their citizens to remain within their borders. The Cloud Act is accelerating this development.

European cloud initiatives

Gaia-X and other EU initiatives aim to establish European cloud alternatives. Their success has so far been limited because U.S. hyperscalers continue to dominate in technology and pricing.

Sources

Sources archived on: 2026-08-02