Sovereignty

CLOUD Act: what it means for a European company

What the US law allows, why a datacentre in Europe does not necessarily escape it, and how to reduce your telephony's exposure.

7 min

What the CLOUD Act allows

The CLOUD Act, enacted in the United States in 2018, lets US authorities compel a provider subject to US law to hand over data it controls, regardless of where it is stored.

The trigger is not the datacentre's location, but the fact that the provider falls under US law: a US company, a subsidiary, or an entity under its control. Data hosted in a European region is within scope if the provider is subject to that law.

The request can come with a confidentiality clause preventing the provider from informing its customer. That is precisely what makes a contractual non-disclosure commitment weaker than a structural guarantee.

Location does not decide

What decides exposure is the law applicable to the provider and its parent companies, not the datacentre's address. Hosting in Europe with a provider subject to US law remains exposed.

Why a datacentre in Europe is not enough

Many offers highlight a European region. That is useful for GDPR, but on its own it does not address extraterritorial risk.

The question to ask is: who owns and controls the entity that operates the service, and which non-European subsidiaries are in the loop? An effective legal separation of non-European entities is one of the criteria that SecNumCloud and the highest levels of the European framework check.

Hidden dependencies matter too: identity, DNS, transactional email or AI model APIs can reopen exposure even on a European foundation.

FISA 702, Schrems II and the Data Privacy Framework

The CLOUD Act is not the only framework at play. Surveillance under FISA section 702 is the origin of the Court of Justice of the European Union's Schrems I and Schrems II rulings.

The EU-US Data Privacy Framework, an adequacy decision of July 2023, currently governs transfers to certified US companies. It is in force, but contested and revocable: an adequacy decision can be invalidated, as the two previous ones were.

For a European company, relying on a revocable adequacy is a continuity risk: if it falls, the transfers concerned must be reviewed urgently.

Reducing your telephony's exposure

Against extraterritorial risk, the most robust response is not contractual but architectural: reduce the number of links subject to a non-European law.

Map the voice chain

Telecom, speech recognition, language model, speech synthesis, hosting, identity: who is subject to which law.

Remove network egress

Data that never leaves your network has no path to be transferred.

Keep control of the keys

Encryption with keys under European control, ideally brought by the customer.

For organisations that require no call data to leave, the disconnected on-premise edition of Natalia Analytics processes calls on site, in the customer's datacentre, with no outbound connection.

Frequently asked questions

Does the CLOUD Act apply if my data is in France?

Yes, if the provider hosting it is subject to US law. The trigger is the law applicable to the provider and its parent companies, not the datacentre's location. Hosting in France with a provider that falls under US law remains in scope.

Does a contractual commitment protect against the CLOUD Act?

Imperfectly. A foreign disclosure law can override a contractual commitment, and the request may come with a ban on informing the customer. A structural guarantee — data that never leaves your network — is more robust than a non-disclosure clause.

Does the Data Privacy Framework settle the question?

It governs transfers to certified US companies, but it is a contested and revocable adequacy decision. The two previous frameworks were invalidated by the Court of Justice of the European Union. Relying on it alone carries a continuity risk should it be invalidated.

Measure your telephony's exposure

We map your voice chain link by link, without overselling.

Request a demo