Why does this matter?
Almost every European business works with American software: Microsoft 365, Google Workspace, AWS, and now also AI services such as ChatGPT and Claude. Most providers offer storage in Europe, and that is reassuring. But for US law, what counts is not where the server is, but who delivers the service. Anyone who puts sensitive business data with a US provider needs to know what that involves and what it does not.
Two laws, often lumped together
When people say that "the US government can get at your data", they usually mean two different laws.
| CLOUD Act (2018) | FISA, Section 702 | |
|---|---|---|
| Who requests? | Judicial authorities and police | Intelligence services |
| What for? | Criminal investigations | Foreign intelligence |
| About whom? | Anyone who turns up in an investigation | Non-Americans outside the US |
| Which test? | An order per case, issued by a judge for the content of communications | No order per person. A special court approves the programme annually |
| Data in Europe? | Yes, as long as the provider has control over it | Yes, it concerns US providers of communication services |
Section 702 is the provision over which the European Court of Justice struck down the two previous arrangements for transfers to the US (Safe Harbor in 2015 and Privacy Shield in 2020). The legal basis of Section 702 expired in June 2026 because the US Congress did not renew it in time. The current authorisations do remain valid until March 2027, and a renewal is being negotiated. So in practice nothing has changed for now.
Where your data is, or who has control over it
Two terms are often confused here:
- Data residency: your data is on a server in the EU.
- Data sovereignty: your data is in the EU, and only parties under European law have legal, operational and technical control over it.
A US provider with a data centre in Belgium or Frankfurt offers residency, not sovereignty. That became very concrete in June 2025 when a lawyer from Microsoft France was asked under oath in the French Senate whether he could guarantee that data of French citizens would never end up with the US government without the agreement of the French government. His answer: "No, I cannot guarantee that." He added that it had not happened up to that point.
Meanwhile, US providers are also launching "sovereign" European versions of their cloud, with a European subsidiary and European staff. That reduces the risk. Whether it is legally sufficient as long as the parent company remains American has not yet been settled.
So can the US always get at your data?
No. But you cannot rule it out.
- A legal procedure is required each time. A US agency cannot simply look in.
- The provider can challenge an order, among other things when it conflicts with the law of the country where the data is stored. The large providers say they do so and publish figures on the requests they receive.
- The GDPR does not automatically recognise such an order. Under Article 48, an order from outside the EU is only valid if it is based on an international agreement. The provider is then caught between two laws.
- You are not always notified. The provider can be obliged to keep silent about a request.
For personal data, a European-American framework has existed since 2023, the Data Privacy Framework. The General Court of the EU declared it valid on 3 September 2025. An appeal against that ruling is pending before the Court of Justice.
The forgotten risk: no longer being able to access your own data
Most attention goes to others reading along. At least as important is availability: what if a provider denies you access, because of sanctions, a dispute or a discontinued service, and your backups are with that same provider? A copy of your most important data outside that one provider is therefore useful, regardless of any law.
When do you choose what?
Working entirely without American software is not realistic for most businesses, and not necessary either. Choose per type of data how much control you need.
| Type of data | Examples | Reasonable choice |
|---|---|---|
| Ordinary | Planning, general emails, marketing material | US provider, business plan, storage in the EU |
| Sensitive | Customer data, contracts, HR matters | Same, with a data processing agreement, agreements that nothing is retained, and where possible an encryption key that you manage yourself |
| Crown jewels | Recipes and formulas, designs, an acquisition in preparation, data for which your customer contractually excludes it | A provider that falls entirely under European law, or your own infrastructure |
About that encryption key: with many cloud services you can supply your own key, but the provider manages it from then on. In that case it can still hand over the data in readable form. Only when you keep the key yourself is that no longer possible. You are then responsible yourself for not losing it.
What counts is not where the server is, but who delivers the service.
Related terms
- EU hosting and zero retention: the two measures with which you reduce the risk.
- Open-weights model: a language model you can run yourself on European infrastructure.
- Data Act: makes switching cloud providers easier.
- AI Act: the European rules for AI systems.
Sources: Cleary Gottlieb on the CLOUD Act and the GDPR · Congressional Research Service on FISA 702 · EU-US Data Privacy Framework · GDPR (Regulation 2016/679)
This article is not legal advice. The rules were checked on 6 October 2026. For a specific situation, it is best to consult a lawyer.