Why does this matter?

Almost every European business works with American software: Microsoft 365, Google Workspace, AWS, and now also AI services such as ChatGPT and Claude. Most providers offer storage in Europe, and that is reassuring. But for US law, what counts is not where the server is, but who delivers the service. Anyone who puts sensitive business data with a US provider needs to know what that involves and what it does not.

Two laws, often lumped together

When people say that "the US government can get at your data", they usually mean two different laws.

CLOUD Act (2018)FISA, Section 702
Who requests?Judicial authorities and policeIntelligence services
What for?Criminal investigationsForeign intelligence
About whom?Anyone who turns up in an investigationNon-Americans outside the US
Which test?An order per case, issued by a judge for the content of communicationsNo order per person. A special court approves the programme annually
Data in Europe?Yes, as long as the provider has control over itYes, it concerns US providers of communication services

Section 702 is the provision over which the European Court of Justice struck down the two previous arrangements for transfers to the US (Safe Harbor in 2015 and Privacy Shield in 2020). The legal basis of Section 702 expired in June 2026 because the US Congress did not renew it in time. The current authorisations do remain valid until March 2027, and a renewal is being negotiated. So in practice nothing has changed for now.

Where your data is, or who has control over it

Two terms are often confused here:

A US provider with a data centre in Belgium or Frankfurt offers residency, not sovereignty. That became very concrete in June 2025 when a lawyer from Microsoft France was asked under oath in the French Senate whether he could guarantee that data of French citizens would never end up with the US government without the agreement of the French government. His answer: "No, I cannot guarantee that." He added that it had not happened up to that point.

Meanwhile, US providers are also launching "sovereign" European versions of their cloud, with a European subsidiary and European staff. That reduces the risk. Whether it is legally sufficient as long as the parent company remains American has not yet been settled.

So can the US always get at your data?

No. But you cannot rule it out.

For personal data, a European-American framework has existed since 2023, the Data Privacy Framework. The General Court of the EU declared it valid on 3 September 2025. An appeal against that ruling is pending before the Court of Justice.

The forgotten risk: no longer being able to access your own data

Most attention goes to others reading along. At least as important is availability: what if a provider denies you access, because of sanctions, a dispute or a discontinued service, and your backups are with that same provider? A copy of your most important data outside that one provider is therefore useful, regardless of any law.

When do you choose what?

Working entirely without American software is not realistic for most businesses, and not necessary either. Choose per type of data how much control you need.

Type of dataExamplesReasonable choice
OrdinaryPlanning, general emails, marketing materialUS provider, business plan, storage in the EU
SensitiveCustomer data, contracts, HR mattersSame, with a data processing agreement, agreements that nothing is retained, and where possible an encryption key that you manage yourself
Crown jewelsRecipes and formulas, designs, an acquisition in preparation, data for which your customer contractually excludes itA provider that falls entirely under European law, or your own infrastructure

About that encryption key: with many cloud services you can supply your own key, but the provider manages it from then on. In that case it can still hand over the data in readable form. Only when you keep the key yourself is that no longer possible. You are then responsible yourself for not losing it.

What counts is not where the server is, but who delivers the service.

How Sevendays handles this: for each customer we look at which data is sensitive. We keep the searchable business data on European infrastructure, and with the external language models we request agreements under which nothing is retained or used for training. You can read what that involves under EU hosting and zero retention. That is how our AI platform works on your own data.

Related terms

Sources: Cleary Gottlieb on the CLOUD Act and the GDPR · Congressional Research Service on FISA 702 · EU-US Data Privacy Framework · GDPR (Regulation 2016/679)

This article is not legal advice. The rules were checked on 6 October 2026. For a specific situation, it is best to consult a lawyer.