CLOUD Act and EU data residency: what location, operator, contract and keys each change
Eurokommerz, Vienna, since 2006: Private AI/ML · IT Managed Services · Enterprise Training · AI Hardware & Software
- 18 U.S.C. § 2713, added by the CLOUD Act in 2018, requires providers of electronic communication or remote computing services to meet their obligations to preserve, back up or disclose data in their possession, custody or control, regardless of whether it is located within or outside the United States
- Data residency fixes where data and backups are stored; whether the provider is subject to US jurisdiction is, in the Justice Department’s words, a fact-specific inquiry into its contacts with the United States
- GDPR Article 48 recognises a third-country order to transfer or disclose personal data only if it is based on an international agreement, and Data Act Article 32 sets similar rules for non-personal data held in the Union
- The comity motion of § 2703(h) is open only where the foreign government has a CLOUD Act executive agreement in force; the Justice Department lists agreements with the United Kingdom and Australia, and as of October 2026 EU-US talks that began in 2019 are ongoing
- An EU operator, a contract under a Member State’s law and keys held by the customer narrow who can be compelled and what can be handed over; none of them changes access by EU authorities or your own company’s position under US law
Eurokommerz × Vixen.UNO: EU Cloud Talk to an expert →
How the CLOUD Act applies to data stored in the EU
Section 2713, which the CLOUD Act added to the US Stored Communications Act in 2018, requires a provider of electronic communication service or remote computing service to meet the act’s obligations to preserve, back up or disclose data within its “possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States”. An EU data centre does not by itself put data out of reach of a US order. Whether an order can reach the data depends on whether a company that holds or controls it is subject to US jurisdiction, and that turns on the operator, its owners and their US contacts, not on where the servers stand.
Residency fixes where data and backups are stored. The operator’s jurisdiction decides whether a US order can reach the provider, the contract sets who may administer the systems and from where, and customer-held keys limit what any provider can hand over.
Data sovereignty vs data residency
Data residency describes location: the country or data centre where data, backups and logs are stored and processed. Data sovereignty is about control, meaning which jurisdiction the operator answers to, which law governs the contract, who can administer the systems and from where, and who holds the encryption keys. For jurisdiction, Article 28 of the Data Act requires providers of data processing services to publish on their websites “the jurisdiction to which the ICT infrastructure deployed for data processing of their individual services is subject”, with a general description of their measures against international governmental access to, or transfer of, non-personal data held in the Union that would conflict with Union or national law, and to list those websites in their contracts.
The Commission’s proposal for a Cloud and AI Development Act (June 2026) defines four sovereignty assurance levels “to be used by public sector bodies based on their risk assessments”. Level 1 covers data “processed and stored in infrastructure located in the Union”, and the higher levels add independence from third countries, ownership and control from the EU, and control over the software supply chain (Commission page, last updated 3 June 2026).
What the CLOUD Act says: § 2713 and comity motions under § 2703(h)
The Clarifying Lawful Overseas Use of Data (CLOUD) Act was enacted on 23 March 2018 as Division V of Public Law 115-141. A remote computing service is “the provision to the public of computer storage or processing services by means of an electronic communications system” (§ 2711(2)). For a foreign company providing services in the United States, the Justice Department’s white paper of April 2019 calls the question of US jurisdiction a “fact-specific inquiry turning on the nature, quantity, and quality of the company’s contacts with the United States”. On subsidiaries it adds: “Whether a company exercises sufficient control over data held by a subsidiary is a fact-dependent inquiry.”
A provider served with legal process for the contents of communications may move to quash or modify it within 14 days under § 2703(h)(2). The court may grant the motion only if the customer is not a US person and does not reside in the United States, disclosure would make the provider violate the laws of a “qualifying foreign government”, and the interests of justice call for it. Such a government has an executive agreement with the United States in force under § 2523 and laws that give providers comparable rights (§ 2703(h)(1)).
The Justice Department’s CLOUD Act resources page (updated 24 October 2023) lists two agreements, with the United Kingdom (signed 3 October 2019) and Australia (signed 15 December 2021), and none with the EU or a Member State. EU-US talks on cross-border access to electronic evidence started in September 2019 and resumed in March 2023; as of October 2026 the Commission’s e-evidence page describes them as ongoing. Without an executive agreement, a provider cannot base a § 2703(h)(2) motion on a conflict with EU or Member State law; for such process the act leaves the common law standards on comity as they were (Pub. L. 115-141, div. V, § 103(c)).
CLOUD Act and GDPR: Article 48, the EDPB-EDPS view and Data Act Article 32
Under Article 48 of the GDPR, a judgment of a third-country court or a decision of a third-country administrative authority requiring a controller or processor to transfer or disclose personal data “may only be recognised or enforceable in any manner if based on an international agreement, such as a mutual legal assistance treaty”, without prejudice to the other grounds for transfer in Chapter V. The guidelines of the European Data Protection Board (EDPB) on Article 48, in their final version adopted on 4 June 2025, add that a request from a foreign authority “does not in itself constitute a legal basis for the processing or a ground for the transfer.”
In a joint response to the European Parliament dated 10 July 2019, the EDPB and the European Data Protection Supervisor (EDPS) wrote that providers whose processing is subject to the GDPR “will be susceptible to facing a conflict of laws” between US and EU law. Unless a CLOUD Act warrant is recognised or made enforceable through an international agreement, “the lawfulness of such processing cannot be ascertained”, they concluded, apart from cases of the data subject’s vital interests. An international agreement with strong procedural and substantive fundamental rights safeguards, they wrote, “appears the most appropriate instrument”.
For non-personal data held in the Union, Article 32 of the Data Act (Regulation (EU) 2023/2854, applicable since 12 September 2025) sets similar rules. Providers of data processing services take “all adequate technical, organisational and legal measures, including contracts” against third-country governmental access that would conflict with EU or national law. Without an international agreement, such access is allowed only under the conditions of Article 32(3), which include review of the provider’s reasoned objection by a court of the requesting country. The provider hands over the minimum data permissible and informs the customer before complying, except where the request serves law enforcement, for as long as necessary to keep that activity effective. The Commission’s Digital Omnibus proposal of 19 November 2025 would adjust Article 32 to take in bodies now governed by the Data Governance Act; as of 6 October 2026 the European Parliament’s Legislative Observatory lists it as “Awaiting committee decision”, so the 2023 text applies.
The EU-US Data Privacy Framework and Case T-553/23
In Implementing Decision (EU) 2023/1795 of 10 July 2023, the Commission concluded that the United States ensures an adequate level of protection for personal data transferred under the EU-US Data Privacy Framework to participating US organisations, so such transfers need no further authorisation (recitals 7 and 8). On 3 September 2025 the General Court dismissed an action for annulment of the decision (Case T-553/23). An appeal, Case C-703/25 P, was brought on 31 October 2025; as of 6 October 2026 we found no judgment in it and could not confirm its status on the Court’s own website. How these rules apply to a given provider and data set is a legal assessment for your legal department.
What residency, an EU operator and customer-held keys each change
“EU operator” in the table means a provider under EU jurisdiction with a contract under a Member State’s law.
| QUESTION | RESIDENCY ALONE | EU OPERATOR | CUSTOMER-HELD KEYS |
|---|---|---|---|
| Where data and backups sit | in the EU | in the EU, as written in the contract | no change |
| Reach of a § 2713 order | unchanged if the provider is subject to US jurisdiction | depends on the operator’s US contacts and on who controls the data | content only as ciphertext if the provider cannot decrypt it; account records and logs stay readable |
| Admin and support access | not limited by location | defined in the contract: who, from where, with which rights | protects copies at rest; a running VM is decrypted on the host |
| Notice of a foreign request | Data Act Article 32(5) for non-personal data held in the Union | the same, plus any notice the contract adds | a request for readable data goes to the key holder |
| Requests from EU authorities | apply, including European Production Orders | apply in the same way | apply to the key holder as well |
18 U.S.C. § 2713; Justice Department CLOUD Act white paper (April 2019); Data Act Articles 28 and 32; Regulation (EU) 2023/1543.
The operator’s jurisdiction and ownership decide whether a US court can require it to disclose data, and the contract sets the rest in writing: governing law, subprocessors, who may administer the platform and from where, and what happens when a request arrives. Under Article 28(3)(a) GDPR, a processor acts only on documented instructions from the controller, “including with regard to transfers of personal data to a third country”, unless Union or Member State law requires otherwise. Our comparison of IaaS, private cloud and hybrid covers which of the three fits which workload.
Customer-held keys protect data that the provider only stores. If backups and archives are encrypted before they reach the provider and the keys stay with you, the provider holds ciphertext, and the Justice Department says the CLOUD Act “does not create any new authority for law enforcement to compel service providers to decrypt communications”. Account records stay readable to the provider, and § 2713 also covers “any record or other information pertaining to a customer or subscriber”, such as billing data and connection logs. Without confidential computing, a virtual machine on the provider’s hosts is decrypted by those hosts while it runs, so keys kept elsewhere protect stored copies, not data in use.
Our EU Cloud keeps data and backups in the EU, on a platform run by a European operator. Tell us which systems and data classes you plan to host and what your contracts require on location and access.
What residency, operator and keys do not change
If your own company is subject to US jurisdiction, the choice of provider does not change that. The Justice Department’s white paper says that “companies subject to U.S. jurisdiction may be compelled, pursuant to a court order, to produce data subject to their control regardless of where the data is stored”, and it quotes the department’s guidance that “prosecutors should seek data directly from the enterprise, if practical, and if doing so will not compromise the investigation.”
An operator under EU jurisdiction answers to EU and national orders. From 18 August 2026, Regulation (EU) 2023/1543 lets an authority of a Member State order a service provider offering services in the Union, and established or represented in another Member State, to produce or preserve electronic evidence in criminal proceedings “regardless of the location of the data”.
Data leaving through SaaS applications, email, support tickets, telemetry or cloud AI APIs is outside all three measures; our comparison of a private LLM and a cloud API covers the AI case. Residency and jurisdiction do not make a platform secure or available either. Patching, access control, restorable backups and an exit plan are needed with any operator; our guide to the Data Act and cloud switching covers the exit.
What to ask a cloud provider about jurisdiction and access
- The legal entity that signs the contract, the law that governs it, and the companies that own or control that entity.
- The provider’s Data Act Article 28 page on the jurisdiction of its ICT infrastructure, and the contract clause that lists it.
- Where data, backups, logs and support copies are stored, and from which countries administrators and support staff reach them.
- The subprocessors named in the contract and the procedure for authorising changes under Article 28(2) GDPR.
- A contractual duty to inform you of a third-country request before complying, where the law allows, and to challenge unlawful requests.
- Who generates and holds the keys for storage and backups, and which systems see data in clear.
- How all data comes back to you at the end of the contract, in which formats and within which periods.
We fill in your supplier questionnaire, and an NDA comes before any technical detail. Send us the questionnaire you use for cloud providers through the form below.
General information on EU and US law as of October 2026, not legal advice for an individual case.
What we do
Our EU Cloud service hosts IaaS or a private cloud in Baltneta’s Tier-3 data centres in Lithuania, with ISO 27001 and PCI DSS Level 1, and data and backups stay in the EU. The platform is operated by Baltneta, a European operator, and the contract with Eurokommerz is governed by Austrian law. Our engineering partner Vixen.UNO handles migration and support; the scope of its engineers’ access is defined by the contract and can be limited by agreement, and subprocessors are named in the contract. Our security and compliance page lists the documents we sign, including a data processing agreement under Article 28 GDPR on request. The first call is free of charge, and the price of the technical assessment is fixed before work begins.
FAQ
What is the US CLOUD Act?
Does the CLOUD Act apply to data stored in the EU?
How does the CLOUD Act relate to the GDPR?
What is the difference between data sovereignty and data residency?
Does encryption protect data from CLOUD Act requests?
Is the EU-US Data Privacy Framework still valid?
Send us the systems and data classes you plan to host, what your contracts and your legal department require on location, operator and administrative access, and the provider you use today. We reply within one business day to arrange a first call, from which you leave with two or three configuration options and an indicative monthly invoice. The first call is free of charge.
Talk to an expertWe reply within one business day