Skip to main content
Data Protection / GDPR

US CLOUD Act

The US CLOUD Act of 2018 obliges US providers of electronic communication and cloud services to hand over data they control when served with a lawful order, even where that data is stored on servers inside the EU.

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) was enacted on 23 March 2018 as part of the Consolidated Appropriations Act. Its core provision, 18 U.S.C. § 2713, amends the Stored Communications Act: providers of electronic communication or remote computing services must disclose content and subscriber data in response to an order under 18 U.S.C. §§ 2703 et seq. even when the data is stored outside the United States. What matters is solely whether the provider holds the data in its "possession, custody, or control". The statute was prompted by United States v. Microsoft Corp., the dispute over emails held on Irish servers, which the Supreme Court declared moot in April 2018 once the law had entered into force. Because the territorial reach follows control rather than storage location, European subsidiaries of US groups can also fall within scope wherever the US parent retains effective access.

Seen from Europe, this disclosure duty collides with Art. 48 GDPR. Under that provision, a judgment or decision of a third-country authority requiring the transfer of personal data may only be recognised and enforced if it rests on an international agreement, typically a mutual legal assistance treaty, without prejudice to the other grounds in Chapter V. In their joint response to the LIBE Committee of 10 July 2019, the European Data Protection Board and the European Data Protection Supervisor made clear that a CLOUD Act order does not in itself create a lawful basis for a transfer. Absent a treaty route, only the derogations in Art. 49 GDPR remain, and these must be construed narrowly and are unsuited to recurring or bulk requests; the public interest under Art. 49(1)(d) GDPR must moreover be recognised in Union or Member State law, not merely in the third country. On top of that, disclosure may amount to processing without a legal basis under Art. 6 GDPR and, where the provider acts as a processor, to a breach of the duty to act only on documented instructions under Art. 28 and Art. 29 GDPR.

The conflict remains unresolved. The CLOUD Act provides in 18 U.S.C. § 2523 for executive agreements with qualifying partner states; such agreements exist with the United Kingdom and with Australia, whereas the EU-US negotiations on cross-border access to electronic evidence, opened in 2019, have not been concluded. The statutory route for challenging an order because it conflicts with foreign law presupposes exactly such an agreement, which leaves parties in the EU relying in practice on the general comity considerations of US courts. On the European side, Regulation (EU) 2023/1543 on European production and preservation orders creates a dedicated framework for cross-border requests and applies from 18 August 2026. Neither the adequacy decision for the EU-U.S. Data Privacy Framework nor Executive Order 14086 settles the question, since both concern intelligence access rather than law-enforcement production orders. Controllers should therefore assess the exposure in their transfer impact assessment and mitigate it through contractual safeguards, encryption with keys held in-house, data minimisation or European alternatives.

Legal Basis

CLOUD Act 2018, in particular 18 U.S.C. § 2713 and § 2523 and 18 U.S.C. §§ 2701 et seq. (Stored Communications Act); Art. 48 and Art. 44 to 49 GDPR; Art. 6, Art. 28 and Art. 29 GDPR; Clause 15 of the Standard Contractual Clauses (Implementing Decision (EU) 2021/914); EDPB/EDPS joint response to the LIBE Committee of 10 July 2019

Practical Example

A German pharmaceutical company uses the collaboration platform of a US group and has contractually agreed that all data is stored in an EU data centre. While preparing the transfer impact assessment, the privacy coordinator finds that the contracting entity is an Irish subsidiary whose support is partly delivered from the United States and whose US parent retains administrative access, so the CLOUD Act is relevant despite the EU storage location. She documents the data categories, reviews the transparency report the provider publishes on government requests, and negotiates sharper contractual terms: prompt notification of any production order to the extent legally permitted, judicial challenge of manifestly disproportionate orders, and disclosure limited to what is strictly required, mirroring Clause 15 of the Standard Contractual Clauses. For the particularly sensitive study data she additionally introduces client-side encryption with in-house key management, records the outcome in the record of processing activities and schedules an annual review.

FAQ

Yes. The decisive factor is not where the data sits but whether the US provider has effective control over it. A European subsidiary can be caught as well if the US parent is able to access the data. EU hosting alone therefore does not remove the risk.
Not straightforwardly under the GDPR. Art. 48 GDPR recognises orders from third-country authorities only where they rest on an international agreement such as a mutual legal assistance treaty. Without such a basis, only the narrow derogations of Art. 49 GDPR remain, and they do not support recurring requests. The provider is left in a genuine conflict of legal duties.
No. The adequacy decision of 10 July 2023 and the underlying Executive Order 14086 address access by US intelligence agencies, not criminal-law production orders under the CLOUD Act. The exposure to government disclosure demands therefore remains part of the risk assessment even where the provider is certified under the framework.

How preeco supports you

Learn how our software supports you with this topic.

Learn more