Cloud Act: definition
The Cloud Act (Clarifying Lawful Overseas Use of Data Act) is a US law enacted in 2018. It allows United States authorities to compel a service provider subject to US law to disclose data in its custody or control, regardless of where that data is physically stored. A provider governed by US law can therefore be targeted by such a request even when the servers concerned sit outside the United States. This page is descriptive and does not constitute legal advice.
What the law provides
Before the Cloud Act, the reach of US access requests was contested when data was stored abroad. The law clarified this point: what matters is the connection between the provider and US law, not the location of the servers. A provider subject to this jurisdiction can be required to produce data held in a data center located, for example, in Europe.
The text sets out procedural mechanisms and, in some cases, cross-border agreements to frame these requests. It does not grant automatic or unlimited access: a legal basis and a procedure are still required. The structuring point remains, however, that the provider's legal ties can take precedence over the physical location of the data.
Consequence for data residency in Europe
The practical consequence bears directly on data sovereignty. Choosing a European storage region is not enough to place data beyond the reach of the Cloud Act if the entity that controls it falls under US law. European residency protects location, not necessarily legal control.
Major infrastructure and AI-assistant providers (Microsoft, Google, AWS, as well as services such as ChatGPT or Claude) are cited here as neutral examples: several fall, to varying degrees, under US law. This reality feeds the discussion about where an organization chooses to let its information live, a topic developed in the article your memory should not live inside any AI.
FAQ
Does the Cloud Act apply to data stored in Europe?
It can apply if the provider controlling that data falls under US law, even when the servers are located in Europe. What matters is the provider's legal ties, not only the location of the servers.
Is European data residency enough to escape the Cloud Act?
No. Residency concerns where data is stored. If the controlling entity is subject to US law, a European location is not enough to rule out a request based on the Cloud Act.