If you’re a European company evaluating SaaS vendors, you’ve probably been told the CLOUD Act doesn’t matter as long as the vendor offers EU data residency. This is technically wrong and the technicality matters. Here’s what’s actually going on, what the practical consequences are, and what to ask in your next vendor review.
What the CLOUD Act is
The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) is a 2018 United States federal statute. It does two things:
-
Extraterritorial reach. It clarifies that US law-enforcement subpoenas, warrants, and national-security letters can compel any US-incorporated company to disclose data the company holds — including data physically stored in another country. The location of the bytes doesn’t matter; the company’s legal jurisdiction does.
-
Executive agreements. It allows the US to negotiate bilateral agreements with foreign governments that streamline mutual legal-assistance requests. The UK and Australia have signed; the EU has not.
Both parts of the statute are relevant to European companies, but the first part is what creates the operational risk: a US-incorporated company can be compelled to disclose data about its European customers, in the United States, regardless of where the data physically resides.
Why “EU data residency” doesn’t fix it
EU data residency means the bytes are stored on servers physically located inside the European Union. AWS-EU, Azure-EU, GCP-EU, and Salesforce-EU all offer this. Slack, Microsoft Teams, and Google Chat can claim it.
But the bytes physically being in Frankfurt doesn’t change the corporate jurisdiction of the company storing them. AWS is Amazon Web Services Inc., a Delaware corporation. Azure is Microsoft Corporation, a Washington corporation. GCP is Google LLC, a Delaware corporation. All three are subject to US law, including the CLOUD Act, regardless of where their datacenters happen to be.
The practical consequence: if the US government issues a CLOUD Act subpoena to AWS for data about a European customer, AWS is legally compelled to comply. That data could be in Frankfurt, Stockholm, or Athens — the location is not the legal protection. The legal protection would be the corporate jurisdiction. AWS doesn’t have an EU corporate jurisdiction. AWS-Europe, the marketing label, is not a separate legal entity with EU sovereignty; it’s a regional configuration of an American company.
Schrems II made this concrete
In July 2020, the Court of Justice of the European Union ruled in Schrems II that the EU-US Privacy Shield agreement was invalid for personal-data transfers, citing exactly this concern: US government surveillance authorities (including under FISA Section 702 and the CLOUD Act) provide insufficient protection for EU personal data when held by US-jurisdictional companies. The CJEU was specific: even when standard contractual clauses are in place, transfers to US-controlled processors may not meet GDPR adequacy if the US company can be compelled to disclose the data without effective EU oversight.
This isn’t an abstract concern. It is the legal basis on which European Data Protection Authorities can — and have — fined European companies for using US-controlled SaaS for personal data, even when “EU data residency” is configured.
The compliance reality, not the marketing reality
The reality on the ground: European companies are using US-controlled SaaS for personal data every day. DPAs are signed. Standard Contractual Clauses are attached. Data Protection Impact Assessments are filled out. The compliance posture is “we acknowledge the risk and have mitigated it as far as practical.”
This works as a defensible posture as long as no one tests it. When a Data Protection Authority audits, when a customer’s procurement team asks specific questions, when a CLOUD Act subpoena actually lands and becomes public, the posture gets retested. Increasingly, the test is being failed. Some recent examples:
- The Austrian DPA ruled in 2022 that Google Analytics violates GDPR specifically because the data is exposed to US surveillance under FISA 702.
- The French CNIL issued similar guidance for Google Analytics in 2022.
- Italian, Norwegian, Finnish, and Danish DPAs have followed.
- The EDPB’s recommendations after Schrems II explicitly require “additional measures” beyond SCCs for transfers to US-jurisdictional companies.
The trajectory is clear. The “EU data residency” defensible posture is eroding.
What this means for procurement
If you’re writing a procurement requirement for a SaaS vendor in 2026, the operationally meaningful question isn’t “is the data stored in the EU?” — that’s table stakes and not legally protective. The operationally meaningful questions are:
-
What is the corporate jurisdiction of the entity that holds the data? EU? US? UK? China? The answer determines which government can compel disclosure.
-
Are sub-processors EU-only, or are some US-jurisdictional? A “sovereign-in-Europe” SaaS that uses Stripe, Cloudflare, or Datadog has CLOUD Act exposure through its sub-processor chain.
-
What is the parent corporate structure? A French subsidiary of a US company is still part of the US legal jurisdiction in CLOUD Act terms.
-
What is the contractual commitment to remain so? Companies can be acquired. A “European-owned” company today can be a “US-acquired subsidiary” tomorrow. The contractual commitment to retain EU corporate jurisdiction is the durable thing.
-
What is the transparency commitment around government data requests? Quarterly transparency reports with counts (and zero-counts) are an operational signal. No commitment is a different signal.
The procurement-checklist takeaway
If your vendor is a US-incorporated entity with EU data residency, you have CLOUD Act exposure, regardless of marketing. Your DPIA should reflect that. Your customer contracts should reflect that. If sovereignty matters in your contract or in your customer’s contract, “EU region of a US cloud” is not the right answer — the right answer is an EU-incorporated entity with EU-only sub-processors and a contractual commitment to remain so.
That is what we built. The EU Pledge spells out the corporate-jurisdiction commitment in writing, in your DPA. The sub-processor list is EU-only by mandate, not by configuration. Both are public, both are dated, both are part of the contract.
If you’re working through a vendor review and the CLOUD Act question is on your checklist for the first time, this is what’s behind it.