If your cloud provider is based in the US, a valid US court order can compel that company to retrieve your company’s data on servers anywhere in the world.

Companies including Google, Microsoft, and Amazon are vulnerable to this intrusion, made possible by the CLOUD Act, a 2018 law that gives American law enforcement officials global tentacles.

It’s especially a problem for EU businesses. If your US provider hands over your emails or files, that could constitute a violation of the GDPR for leaking personal data, which can impose penalties of up to €20 million or 4% of global annual revenue, whichever is higher.

That’s the reality that American companies obscure when they say “GDPR-compliant” and “European sovereign cloud” in their marketing. A US provider’s EU data center is still run by a company under US jurisdiction. For your business, this means that procurement decisions carry a compliance liability you may not have priced in. For your customers, it means the personal data they entrusted to you may end up in a legal process they have no say in (and may never even learn about).

Here’s a plain explanation of the CLOUD Act, why this invasive legislation matters for businesses, and how to limit your exposure. your data sits no longer decides who can reach it.

What is the CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act(jendela baru)) is a US federal law that came into force in 2018. It allows federal law enforcement — primarily the Department of Justice and FBI, but also federal, state, and local police — to obtain a warrant, court order, or subpoena compelling technology companies under US jurisdiction to hand over data, regardless of where in the world that data is physically stored. 

For example, if the FBI obtains a warrant compelling Microsoft to hand over a European business’s emails, Microsoft must comply — even if a European court disagrees with the request.

The CLOUD Act has a legitimate policing purpose. It’s designed to help federal law enforcement to investigate serious crimes such as terrorism, child exploitation, and cybercrime. It’s not designed for intelligence-gathering, which runs through a separate US authority (FISA Section 702), often confused with it.

That legitimate purpose doesn’t, however, remove the structural problem for businesses: The CLOUD Act can put a US-jurisdiction provider in a position where fulfilling a lawful US order means breaching EU law. It leaves businesses caught between two compliance regimes with no way to satisfy both.

What’s the origin of the CLOUD Act?

The CLOUD Act was passed in 2018 by the US government to amend the Stored Communications Act (SCA) of 1986. This amendment was, in large part, a response to an ongoing court case(jendela baru), the ‘Microsoft-Ireland’ case. 

In 2013, Microsoft challenged a federal warrant demanding the emails of a customer under investigation for drug trafficking — emails stored by Microsoft on servers in Ireland. This case hinged on a thorny legal question: Could a US warrant issued under the SCA reach digital communications controlled by a US-based company, but stored on a data server outside the US?

In 2018, the case was pending appeal in the Supreme Court when the US Congress passed the CLOUD Act. This both mooted the ‘Microsoft-Ireland’ case and resolved the question of the US government’s extraterritorial powers over data stored on foreign soil, at least on paper.

What powers does the CLOUD Act give the US government?

The CLOUD Act empowered the US government to request targeted data, wherever it was stored, by strengthening extraterritorial SCA orders to US providers. The Act clarified that US law enforcement can use warrants, subpoenas, and court orders to access electronically stored communications data located outside the US, if the storage provider is subject to US jurisdiction, and the requested data is relevant and material to an ongoing criminal investigation. A CLOUD Act request goes straight to the provider, bypassing the much slower MLAT (Mutual Legal Assistance Treaty)(jendela baru) process that the US government relied on previously.

The CLOUD Act also empowered governments who were willing to sign up to a bilateral executive agreement with the US government, which would let law enforcement in partner countries make direct, cross-border, case-specific requests for data from US-based service providers.

Executive agreements speed up evidence-gathering in serious criminal cases like terrorism and child exploitation, where the MLAT process could take months. At time of writing, only two executive agreements exist: between the US and the UK (entered into force in October 2022(jendela baru)), and between the US and Australia (entered into force January 2024(jendela baru)). Negotiations between the US government and the EU and Canada(jendela baru) have been initiated but are not yet concluded.

Tech providers do have one safety mechanism: They can challenge or ask to modify a US order under “comity” — the legal principle that courts defer to other jurisdictions’ laws — if complying would mean breaking a foreign law, particularly one covered by an executive agreement. Outside the UK and Australia, this common-law comity challenge is the only option on the table.

However, as The Electronic Privacy Information Center (EPIC) argues(jendela baru), even with comity, the CLOUD Act leaves customers, businesses included, with little real recourse. Providers aren’t required to notify a customer whose data was accessed, customers have no independent right to challenge a request (that depends entirely on the provider choosing to object), and executive agreements explicitly rule out creating any new remedy for the people affected.

The CLOUD Act vs GDPR

In Europe, where Proton’s own research shows over 74% of all publicly listed companies depend on US-based tech services, the CLOUD Act is of particular concern because it clashes with the EU’s General Data Protection Regulation (GDPR).

Under Article 48(jendela baru) of the GDPR, a foreign court order or decision of an administrative authority (including an SCA order) to transfer or disclose personal data will not be automatically recognized or enforced in the EU, unless made under an international agreement, such as an MLAT. 

While there hasn’t been a case of GDPR fining a company in connection with a CLOUD Act order, there is precedent for regulators acting on this category of risk: In 2023, Ireland’s Data Protection Commission fined Meta a record €1.2 billion(jendela baru) for EU-US transfers exposed to US surveillance law — specifically FISA Section 702, not the CLOUD Act.

For US-based cloud providers, this means that if the US government requests data that they process but that’s controlled by European businesses, to comply with the CLOUD Act might mean breaching GDPR. Under Article 28(jendela baru), the provider (processor) may only act on the controller’s documented instructions, and “disclosing data to a foreign government” isn’t among those instructions.

The exposure isn’t limited to the provider. If the provider discloses a customer’s data in response to a compelled order without the international-agreement basis Article 48 requires (which, since no CLOUD Act executive agreement exists between the US and the EU at present, means an MLAT) the business that owns that data carries its own liability, not just the vendor it hired to store it.

Why data location doesn’t mean data sovereignty

In June 2025(jendela baru), Microsoft France’s own director of public and legal affairs, Anton Carniaux, was asked under oath in the French Senate(jendela baru) whether he could guarantee French citizens’ data would never be handed to US authorities without French consent. 

His answer: “No. I cannot guarantee that.” He added that “it has never happened before”, which doesn’t, of course, mean it couldn’t happen in the future. 

The message was clear: Data sovereignty is no longer about where data is stored, but who controls that data. The location of your data servers and the governments which have authority over them are no longer necessarily the same thing.

This fact sits uncomfortably next to the “GDPR compliant” cloud offerings US cloud giants (or ‘hyperscalers’) are marketing to European businesses. These “European sovereign cloud” products are run by companies headquartered in the US, or controlled by a US parent company, and GDPR’s protections only extend as far as US law allows.

How zero-access encryption architecture mitigates exposure to the CLOUD Act

If your cloud storage provider is subject to US jurisdiction and US law enforcement demands access to your data (with legitimate legal reasons), neither you nor your provider can stop it from happening. At this point, your data’s only defense is encryption. 

Encryption makes data unreadable and unusable by cybercriminals and governments alike, scrambling it into ‘cipher text’ that only someone with the right key can read.

However, the encryption offered by most US cloud providers comes with a fatal caveat: They retain the decryption keys themselves. That means they can read your data, or be compelled to hand over a readable copy to a third party such as US law enforcement.

For real protection against file and message data exposure, either to cybercriminals or governments, you need end-to-end encryption or zero-access encryption, which prevents the provider from accessing the data.

A provider that uses zero-access encryption doesn’t have the key to decrypt files it handles and stores on its servers. It may still be forced to disclose data when law enforcement demands it, even if data is stored in a jurisdiction that enforces a strict standard of data protection, such as Switzerland. But the files handed over would be encrypted and unreadable.

How Proton protects businesses from the CLOUD Act

Proton is shielded from the CLOUD Act in two key ways:

  • Swiss jurisdiction, which limits who can compel Proton to hand over data
  • And strong encryption, which limits what they can do with whatever Proton hands over

Proton is headquartered in Geneva, Switzerland, outside of US jurisdiction and the reach of CLOUD Act orders. US authorities can’t resort to a bilateral shortcut, either: Switzerland isn’t party to any CLOUD Act executive agreement.

This doesn’t remove legal process altogether. Switzerland has its own mutual legal assistance framework, which lets Swiss authorities cooperate with foreign investigations. But any request has to clear Swiss law first, under Swiss courts — it can’t be a warrant served directly on the provider.

Proton’s legal history shows that we’re willing and able to challenge Swiss law. In 2020, we challenged a Swiss data retention law that we believed to be an improper attempt to use telecommunications laws to undermine privacy. In 2021, the Federal Administrative Court ruled that email services aren’t telecommunications providers, and therefore aren’t subject to the law’s retention requirements.

And even a successful Swiss order has limits on what it can get. Proton’s end-to-end and zero-access encryption means message content and files are unreadable to Proton itself, and there’s no key to hand over, regardless of who’s asking. The content of your emails, docs, files, and other data stays out of reach.

<Explore Proton for Business>


Frequently asked questions about the CLOUD Act

Does the CLOUD Act override GDPR?

The CLOUD Act doesn’t override GDPR, but it does conflict with it. A CLOUD Act order can put a US provider in a position where complying breaches GDPR Article 48 (no automatic recognition of a foreign order without an international agreement). Neither law defers to the other, and the provider — and any European company they serve — is caught between them.

Is the CLOUD Act only for US companies?

The CLOUD Act doesn’t only apply to businesses headquartered in the US, or controlled by a US parent company. It also reaches any provider with sufficient US legal presence or business nexus. A US subsidiary, US-based staff or offices, or businesses purposefully directed at US customers can be enough to bring an organization headquartered outside the US within reach of the CLOUD Act.

Can I refuse a CLOUD Act request?

The customer (controller) generally isn’t the one served — the provider is. The provider can raise a comity challenge if complying breaks foreign law, or push back if a request is legally deficient. But if legal remedies are exhausted and the order remains valid, a provider would be forced to comply.

What’s the difference between the CLOUD Act and an MLAT?

When digital evidence is requested via a Mutual Legal Assistance Treaty (MLAT), this request is judicially reviewed, a thorough and slow process. The executive agreements enabled by the CLOUD Act let law enforcement bypass the MLAT process if requesting data from a partner country. So far, only the UK and Australia have executive agreements with the US.

Does encryption stop CLOUD Act requests?

Encryption doesn’t stop a legal order, but if a provider stores customer data with end-to-end encryption or zero-access encryption then they will not have any readable data to give to the authorities because they don’t have the decryption keys. They would thus hand over only encrypted files.