Why the US CLOUD Act is a problem and a risk for Europe and the rest of the world: A law with far-reaching consequences
Xpert Pre-Release
Available in 27 languages 📢
Prefer Xpert.Digital on GoogleⓘPublished on: April 16, 2025 / Updated on: April 16, 2025 – Author: Konrad Wolfenstein

Why the US CLOUD Act is a problem and a risk for Europe and the rest of the world: A law with far-reaching consequences – Image: Xpert.Digital
How the CLOUD Act undermines trust in US technology (Reading time: 46 min / No advertising / No paywall)
Why the US CLOUD Act is a problem and a risk for Europe and the rest of the world: A law with far-reaching consequences
This article analyzes the US Clarifying Lawful Overseas Use of Data (CLOUD) Act of 2018 and its far-reaching consequences for global data protection, data sovereignty, and international cooperation. The CLOUD Act empowers US authorities to demand that US communications and cloud service providers disclose data in their possession, custody, or control, regardless of where the data is physically stored—including outside the US. This extraterritorial reach fundamentally conflicts with data protection regimes such as the European Union's General Data Protection Regulation (GDPR), particularly its rules on international data transfers (Article 48 GDPR).
The analysis shows that the CLOUD Act creates significant legal uncertainty for globally operating companies facing conflicting legal requirements. It undermines trust in US technology providers and established data transfer mechanisms, a problem exacerbated by the European Court of Justice's Schrems II ruling. Beyond Europe, the law poses risks of government surveillance, industrial espionage, and conflicts with local legal systems worldwide.
Global dependence on major US cloud providers (AWS, Microsoft Azure, Google Cloud) is immense, particularly in North America and Europe. At the same time, countries like China and Russia are developing closed digital ecosystems with strong local providers and strict regulation, which reduces their dependence. Other nations and regions, including the EU with initiatives like Gaia-X and the Data Act, are pursuing different risk mitigation strategies, ranging from data localization laws and the promotion of local alternatives to negotiating bilateral agreements with the US.
Despite the legitimate need to expedite cross-border law enforcement—a core objective of the CLOUD Act given the slowness of traditional mutual legal assistance procedures—many critics argue that the law fails to satisfactorily balance effective crime prevention with the protection of fundamental rights and national sovereignty. The report concludes with recommendations for businesses and policymakers on navigating this complex landscape.
Related to this:
- Dependent on the US cloud? Germany's battle for the cloud: How they plan to compete with AWS (Amazon) and Azure (Microsoft)
The US CLOUD Act and its impact on European data sovereignty
The ongoing digitalization and the associated shift of data processing and storage to the cloud infrastructures of global providers have fundamentally changed the way businesses and public administrations operate. In particular, the services of the major US hyperscalers – Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) – have become an integral part of the digital infrastructure of many countries. This development offers enormous potential for efficiency and innovation, but simultaneously creates new and complex challenges for data protection, data security, and the safeguarding of national sovereignty.
This problem was significantly exacerbated by the passage of the US Clarifying Lawful Overseas Use of Data (CLOUD) Act in March 2018. This US federal law grants American law enforcement and investigative agencies broad powers to access data stored and managed worldwide by US companies or companies under US jurisdiction. The core issue lies in the explicit extraterritorial scope of the law: US authorities can demand the release of data even if it resides on servers outside the United States.
This legal provision leads to direct and fundamental conflicts with established data protection regimes in other countries, most notably the European Union's General Data Protection Regulation (GDPR). The possibility of access by US authorities circumventing internationally agreed mutual legal assistance procedures and potentially without compliance with strict European data protection standards raises significant concerns regarding government surveillance, industrial espionage, and the erosion of digital sovereignty. The CLOUD Act is therefore widely regarded as problematic and a risk to businesses and citizens not only in Europe but worldwide.
This article aims to provide a comprehensive and well-founded analysis of the US CLOUD Act and its global impact. It analyzes the core mechanisms of the Act and its extraterritorial dimension. Particular focus is placed on a detailed examination of the potential conflicts with the EU General Data Protection Regulation (GDPR) and the resulting implications for European data sovereignty, also in light of the case law of the European Court of Justice (ECJ), especially the Schrems II ruling. Furthermore, the risks and potential negative consequences for countries outside Europe are highlighted. The report maps the global landscape of dependence on US cloud providers, identifies regions with high and low dependence, and comparatively analyzes the strategies that different countries are pursuing to address the challenges posed by the CLOUD Act.
The structure of this article follows this objective: After this introduction, the second chapter explains in detail the core provisions and extraterritorial scope of the CLOUD Act. The third chapter addresses the conflict between the CLOUD Act, the GDPR, and European data sovereignty. Chapter four examines the global risks and implications outside Europe. The fifth chapter maps the global dependence on US cloud providers, while the sixth chapter compares national strategies and responses to the CLOUD Act. A synthesis of the findings and a conclusion form the seventh chapter, followed by recommendations for action in the eighth chapter.
The US CLOUD Act: Core provisions and extraterritorial scope
The Clarifying Lawful Overseas Use of Data (CLOUD) Act represents significant legislation regarding cross-border data access by US authorities. To fully understand its implications, a close examination of its legal basis, its operation, and especially its extraterritorial claims is essential.
Legal basis and functionality
The CLOUD Act was enacted on March 23, 2018, as part of a comprehensive budget bill (Consolidated Appropriations Act, 2018, Public Law 115-141, Division V) and took effect immediately. It does not create an entirely new legal framework but primarily amends existing laws, particularly the Stored Communications Act (SCA) of 1986, which is part of the Electronic Communications Privacy Act (ECPA). The SCA governs the conditions under which U.S. government agencies may access stored electronic communications data held by service providers.
The core of the CLOUD Act, codified in, among other places, 18 U.S.C. §§ 2713 and 2523, obligates providers of electronic communication services (ECS) and remote computing services (RCS) subject to U.S. jurisdiction to comply with orders to secure, back up, or disclose the content of electronic communications, as well as metadata or other information about customers or subscribers. This obligation applies to data that is in the provider's possession, custody, or control. U.S. jurisdiction can also extend to providers whose principal place of business is not in the U.S., but who have a sufficient connection to the United States, for example, through business relationships, a branch office in the U.S., or contracts with U.S. customers.
The crucial clarification provided by the CLOUD Act is that this obligation to disclose data applies regardless of whether the data in question is located within or outside the United States.
The catalyst for this legislation was primarily the legal dispute United States v. Microsoft Corp. (often referred to as the "Microsoft Ireland Case"). In this case, Microsoft refused to hand over a customer's emails stored on a server in Ireland to the FBI, arguing that US warrants had no extraterritorial effect and the Security Customer Authentication (SCA) did not apply to data outside the US. The case reached the Supreme Court, but was mooted by the passage of the CLOUD Act, which decided the legal question in favor of the government.
It is important to emphasize that, according to the US government and supporting organizations, the CLOUD Act does not constitute a license for mass surveillance or arbitrary data access. Access orders (typically warrants based on "probable cause" or subpoenas) must still comply with the rule-of-law requirements of US law, be specific, and be subject to judicial review. They are limited to data that could be relevant in connection with specific criminal investigations ("serious crime, including terrorism"). Furthermore, the CLOUD Act explicitly does not create an obligation for providers to decrypt data if they only possess it in encrypted form and do not control the keys.
Extraterritorial application and claim to jurisdiction
The central and most controversial innovation of the CLOUD Act is the legal anchoring of the extraterritorial scope of US access orders. The law clarifies that the obligation to hand over data exists for providers under US jurisdiction, regardless of the physical location where the data is stored.
This position is based on the established legal principle that a state can compel companies under its jurisdiction to disclose information under its control, even if that information is stored abroad. The CLOUD Act codifies this principle specifically for electronic communications data in the context of the SCA.
This very unilateral claim to extraterritorial access is the main source of international concern and legal conflicts, particularly in relation to the European Union and its General Data Protection Regulation (GDPR). It is perceived as an infringement on the sovereignty of other states and as a potential circumvention of established international legal assistance procedures.
Executive agreements as an alternative to mutual legal assistance treaties
In addition to clarifying the extraterritorial scope of US orders, the CLOUD Act introduces a second important mechanism: It authorizes the US executive branch (president or government) to conclude bilateral agreements, so-called "Executive Agreements", with "qualified" foreign governments.
The stated aim of these agreements is to accelerate and streamline cross-border data access for the purpose of prosecuting serious crimes (including terrorism). They are intended to provide an alternative or complement to traditional Mutual Legal Assistance Treaties (MLATs), whose procedures are often criticized as being too slow and bureaucratic to keep pace with the speed of digital crime.
The core mechanism of these Executive Agreements is to eliminate legal obstacles (“conflicts of law” or “legal restrictions”) that might prevent providers from complying with lawful orders from the partner country. Specifically, such an agreement would allow, for example, a US provider to directly comply with an order from the United Kingdom without violating US law (e.g., SCA restrictions on disclosure), and vice versa. The authorities of each country could thus use their own national procedures to request data from the provider in the other country.
The US can only conclude such agreements with states deemed "qualified." This requires certification by the US Attorney General and the Secretary of State to Congress that the partner country in question has robust substantive and procedural safeguards for privacy and civil liberties and applies them in practice. The partner country must respect the rule of law, non-discrimination, and data protection.
To date, the US has concluded such Executive Agreements with the United Kingdom (signed in 2019, in effect since October 2022) and Australia (signed in December 2021). Negotiations with the European Union were announced in 2019 and are ongoing, but are proving difficult due to the complex legal situation (GDPR, Schrems II) and the involvement of 27 member states.
Important safeguards for these agreements are provided in the CLOUD Act itself: Orders issued under such an agreement must not be targeted at U.S. persons (citizens or permanent residents) or persons residing in the U.S. They must be specific (e.g., targeting a particular person or account) and subject to independent review or oversight (e.g., by a court).
Legal avenues for providers
The CLOUD Act explicitly provides a mechanism by which providers can legally challenge US access orders under certain conditions (so-called "motion to quash or modify"). This right exists if the provider "reasonably believes" that two cumulative conditions are met:
- The customer or subscriber in question is not a US person and does not reside in the USA.
- The required disclosure would create a "material risk" that the provider would violate the laws of a "qualified foreign government." A "qualified foreign government" is one with which the US has an Executive Agreement under the CLOUD Act.
If the provider files such an appeal, the competent US court can modify or revoke the order. However, this only occurs if the court determines that (a) disclosure would actually violate the law of the qualifying foreign state, (b) granting the appeal serves the interests of justice, and (c) the interests of justice require it, considering the totality of the circumstances.
To assess what the "interests of justice" require, the law lists specific factors that the court must weigh ("compassion analysis"). These include, among others: the interests of the US and the foreign government, the likelihood and nature of penalties that the provider would face abroad, the connections of the individual and the provider to the US and abroad, the importance of the information for the investigation, and the availability of alternative means of obtaining the information.
This legal provision, however, raises questions regarding its practical effectiveness. Focusing the explicit ground for challenge on legal conflicts with qualified foreign governments (i.e., those with an Executive Agreement) could weaken the position of providers seeking to invoke the laws of countries without such an agreement, such as the EU GDPR in its current form without an EU-US agreement. While the possibility remains of invoking general principles of international courtesy and common law comity, the specific legal mechanism is narrower. This could tempt US courts to give less weight to conflicts with the laws of non-agreement states or to view the challenge process as less clearly defined.
Furthermore, the practical relevance of the appeal option is generally limited. The burden of proof lies with the provider, who must demonstrate that they "reasonably believe" the conditions are met. Even if a conflict of law is proven, the court can overturn the order, but is not obligated to do so. The decision is based on a balancing of vague legal concepts such as "interests of justice" and "the totality of the circumstances," which grants the court broad discretion. There is a risk that US interests, particularly in law enforcement or security matters, will be systematically given greater weight than foreign data protection interests, especially if no bilateral agreement exists that formally recognizes these interests. The European Data Protection Board (EDPB) therefore views this mechanism with skepticism, emphasizing that it merely provides an option for appeal, not an obligation, and thus does not offer sufficient protection for the rights of EU citizens.
Related to this:
- Europe's digital dependence on the USA: Cloud dominance, distorted trade balances and lock-in effects
Conflict zone: CLOUD Act vs. EU GDPR and data sovereignty
The extraterritorial scope of the US CLOUD Act and the associated access powers for US authorities lead to significant tensions and direct legal conflicts with the data protection regime of the European Union, in particular the General Data Protection Regulation (GDPR). These conflicts affect core principles of EU data protection law and raise fundamental questions about data sovereignty.
Direct conflict with the GDPR (Art. 6, Art. 48)
The fundamental conflict arises from the fact that the CLOUD Act allows US authorities to order the transfer of data – including personal data of EU citizens – from the EU to the USA, without this order necessarily being based on one of the legal bases for data processing or international data transfer provided for in the GDPR.
The conflict with Article 48 GDPR (‘Transfers or disclosures not permitted under Union law’) is particularly relevant. This article stipulates that decisions by courts or administrative authorities of a third country that require a controller or processor to transfer or disclose personal data are recognized or enforceable only if they are based on an international agreement – such as a Mutual Legal Assistance Treaty (MLAT) – in force between the requesting third country (here, the USA) and the Union or a Member State. An order based solely on the CLOUD Act, without being legitimized by such an international agreement, does not meet this condition. From the GDPR's perspective, it does not constitute a valid legal basis for the transfer.
Furthermore, such a transfer lacks a valid legal basis under Article 6 of the GDPR, which sets out the conditions for the lawfulness of processing (including transferring) personal data. The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have clarified in their joint assessment that the usual legal bases do not apply here
- Article 6(1)(c) GDPR (compliance with a legal obligation): This legal basis is not applicable because the "legal obligation" arises from the CLOUD Act, i.e., from the law of a third country, and not from Union law or the law of a Member State, as required by Article 6(3) GDPR. An exception would only exist if the US order were enshrined in EU law by a MLAT.
- Article 6(1)(e) GDPR (performance of a task carried out in the public interest): This legal basis is also excluded, as the task (here, compliance with the US order) is not defined in Union law or in the law of a Member State.
- Article 6(1)(f) GDPR (legitimate interests): While a provider might have a legitimate interest in complying with a CLOUD Act order to avoid sanctions under US law, the EDPB/EDPS considers that this interest is regularly outweighed by the interests or fundamental rights and freedoms of the data subjects (protection of their data). The authorities argue that otherwise, the data subjects could be deprived of their protection under the EU Charter of Fundamental Rights (in particular, the right to an effective remedy, Article 47).
- Article 6(1)(d) GDPR (protection of vital interests): This legal basis could theoretically be applicable in very narrowly defined exceptional cases, for example, if the data is needed to avert an immediate danger to the life or health of a person. However, it does not provide a basis for routine data disclosures in the context of law enforcement measures.
This clash of legal norms creates an irresolvable conflict for providers subject to both US jurisdiction (and thus the CLOUD Act) and EU legislation (GDPR). If they comply with a CLOUD Act order without a MLAT basis, they violate the GDPR and risk substantial fines (up to 4% of their global annual turnover) as well as civil lawsuits. If they refuse to disclose data, citing the GDPR, they risk sanctions under US law.
Assessment by the EDSA/EDPS and legal uncertainty
The European data protection authorities, coordinated within the EDPB, and the EDPS have taken a clear stance on this conflict. In their joint legal assessment of July 2019, they concluded that the CLOUD Act, as such, does not constitute a sufficient legal basis under the GDPR for the transfer of personal data to the USA.
They emphatically stress that providers subject to EU law may not transfer personal data to US authorities solely on the basis of a direct order under the CLOUD Act. Such a transfer is only permissible if it is based on a recognized international agreement, typically the EU-US MLAT or a bilateral MLAT between a member state and the US. The MLAT process ensures the necessary rule-of-law guarantees and the involvement of the judicial authorities of the requested state.
The possibility provided for in the CLOUD Act for providers to challenge an order ("motion to quash") is considered by the EDPB and the EDPB to be an insufficient safeguard. They point out that this is merely an option for the provider, not an obligation, and that the outcome of such proceedings before a US court is uncertain and offers no guarantee of the protection of EU citizens' rights under EU standards.
This clear stance from the relevant European data protection authorities exacerbates the legal uncertainty for companies that use or offer US cloud services. They must be aware that using such services is potentially non-compliant with the GDPR if the provider cannot guarantee that it will not disclose data in violation of the GDPR based on a CLOUD Act order.
Implications of Schrems II and US surveillance laws
The problems of the CLOUD Act must be seen in the context of the broader debate on data transfers to the USA and the surveillance laws there, which has reached a new dimension through the Schrems II ruling of the ECJ of 16 July 2020.
In this ruling, the European Court of Justice (ECJ) declared the EU-US Privacy Shield agreement invalid. The main reason for this was the far-reaching powers of US intelligence agencies (in particular under Section 702 of the Foreign Intelligence Surveillance Act – FISA – and Executive Order 12333) to access personal data of EU citizens transferred to the US. The ECJ found that these access rights did not meet the requirements of necessity and proportionality under the EU Charter of Fundamental Rights and that EU citizens lacked effective legal protection against such access in the US.
Although the CLOUD Act is formally an instrument of law enforcement and not intelligence surveillance, it reinforces the concerns raised by Schrems II. It establishes another legal mechanism for extraterritorial access to data by US authorities. From a European perspective, this mechanism also lacks the necessary rule-of-law foundation in EU law (Article 48 GDPR), unless it is based on a Multilateral Agreement on Data Protection (MLAT) or a future agreement deemed adequate. The combination of access rights from surveillance laws (FISA 702, EO 12333) and the CLOUD Act (law enforcement) creates an overall picture of far-reaching US government access to data stored globally by US providers.
This has direct implications for the use of other transfer mechanisms such as Standard Contractual Clauses (SCCs). The Schrems II ruling obliges data exporters, when using SCCs for transfers to third countries such as the USA, to assess on a case-by-case basis whether the law and practices of the destination country guarantee a level of protection that is "substantially equivalent" to that guaranteed in the EU. If not, supplementary measures must be taken to close any gaps in protection. The existence of laws such as FISA Section 702 and the CLOUD Act makes it extremely difficult for companies to demonstrate that US law offers such an equivalent level of protection. This significantly complicates the legally compliant use of US cloud services for processing personal data from the EU. The CLOUD Act acts as an amplifier of the Schrems II problem, as it expands the range of legal US access options and further undermines the argument for a “substantial equivalence” of the level of protection.
Erosion of European data sovereignty and loss of trust
Beyond the purely legal conflicts, the CLOUD Act is widely perceived as a threat to Europe's digital sovereignty. Data sovereignty refers to the right and ability of states, organizations, or individuals to exercise control over their data, particularly regarding where it is stored, how it is processed, and who can access it. The CLOUD Act undermines this principle by allowing a foreign power (the USA) potentially unilateral access to data stored on European territory or originating from European citizens and businesses, provided that this data is managed by a provider under US jurisdiction.
The possibility of such access, potentially occurring without compliance with European procedures (such as MLATs) and without the knowledge or notification of the individuals or companies concerned, leads to a significant loss of trust in US technology providers. This distrust not only concerns the protection of personal data as defined by the GDPR, but also extends to the security of sensitive corporate data, such as trade secrets, research and development data, financial information, and intellectual property. The fear of industrial espionage or the unintentional leakage of competitively critical information through government access is a key factor prompting companies to seek alternatives to US providers or to implement additional safeguards.
EU responses: Data Act and Gaia-X (status and challenges)
In response to the challenges of digitalization and the dominance of non-European technology providers, the European Union has launched various initiatives to strengthen digital sovereignty and define its own European approach to data management. Two key components are the Data Act and the Gaia-X initiative.
The EU Data Act, published in the Official Journal in December 2023 and applicable from September 12, 2025, aims to increase fairness in the data economy and improve access to and use of data, particularly industrial data. It is intended to promote innovation and increase data availability. Specifically, the Data Act gives users of connected products (e.g., IoT devices, smart machines) more control over the data generated by these devices and facilitates switching between different cloud providers by, for example, removing barriers to switching providers and prohibiting unfair contractual clauses. Also relevant in the context of the CLOUD Act are the provisions that provide safeguards against unlawful data transfer requests from third-country authorities, thus strengthening EU data sovereignty.
The Gaia-X initiative, launched in 2019, pursues the ambitious goal of creating a federated, secure, and sovereign European data infrastructure. Gaia-X aims to establish an ecosystem in which data can be shared and processed in accordance with European values and standards – transparency, openness, security, interoperability, and data sovereignty. It is intended to offer an alternative to the dominant hyperscalers and reduce dependence on non-European providers.
However, Gaia-X is still in an early implementation phase (“ramp-up phase”) and faces significant challenges. While initial pilot projects and use cases exist, such as Catena-X for the automotive industry and testbeds in partner countries like Japan, widespread market penetration is still pending. Hurdles include the technical complexity of the federated approach, ensuring genuine interoperability between different providers, governance issues within the Gaia-X Association (the implementing organization), and slow adoption, particularly in highly regulated sectors like healthcare. Furthermore, criticism has been voiced that the original vision of a purely European cloud has been diluted by the inclusion of large US hyperscalers in the Gaia-X Association, and that the project suffers from excessive bureaucracy. It currently seems unlikely that Gaia-X can directly compete with AWS, Azure, and GCP. Its significance may lie more in serving as a framework for standards and trust within specific European data spaces.
These European initiatives, however, also reveal a strategic inconsistency. On the one hand, Gaia-X and the Data Act aim to reduce dependence on US providers and strengthen control over data in Europe. On the other hand, the European Commission is simultaneously negotiating an Executive Agreement with the US under the CLOUD Act. Such an agreement, if reached, would legalize and potentially simplify direct data access by US authorities under certain conditions—institutionalizing precisely the mechanism that originally triggered sovereignty concerns. This reflects the EU's dilemma: to simultaneously pursue digital autonomy and establish the necessary pragmatic cooperation with the US in law enforcement on an efficient footing, without compromising its own high data protection principles (in particular, the requirements of the Schrems II ruling and Article 48 of the GDPR). Resolving this tension is a key challenge for future transatlantic data policy.
🎯📊 Integration of an independent and cross-data-source AI platform 🤖🌐 for all business needs

Integration of an independent and cross-data-source AI platform for all business needs - Image: Xpert.Digital
AI Game Changer: The most flexible AI platform - Tailor-made solutions that reduce costs, improve your decisions and increase efficiency
Independent AI platform: Integrates all relevant company data sources
- This AI platform interacts with all specific data sources
- From SAP, Microsoft, Jira, Confluence, Salesforce, Zoom, Dropbox and many other data management systems
- Rapid AI integration: Tailor-made AI solutions for businesses in hours or days, instead of months
- Flexible infrastructure: Cloud-based or hosting in your own data center (Germany, Europe, free choice of location)
- Maximum data security: its use in law firms is irrefutable proof
- Deployment across a wide variety of enterprise data sources
- Choice of own or different AI models (DE, EU, USA, CN)
Challenges that our AI platform solves
- Lack of fit of conventional AI solutions
- Data protection and secure management of sensitive data
- High costs and complexity of individual AI development
- Shortage of qualified AI specialists
- Integration of AI into existing IT systems
More information here:
Economic espionage and data protection: Is US technology still trustworthy?
Global risks and implications outside Europe
The problems raised by the CLOUD Act are not limited to the relationship between the US and Europe. The law has potentially far-reaching implications for countries and regions worldwide, particularly regarding government surveillance, economic espionage, conflicts with local laws, and general trust in global digital infrastructure.
State surveillance and civil liberties
The CLOUD Act has faced criticism from civil liberties organizations such as the Electronic Frontier Foundation (EFF) and the American Civil Liberties Union (ACLU) from the outset. A key criticism is that the law potentially undermines the safeguards against inappropriate government searches and seizures (enshrined in the Fourth Amendment to the US Constitution for US citizens). In particular, the possibility of establishing bilateral arrangements through Executive Agreements, which would allow foreign authorities direct access to data held in the US and potentially circumvent the usual judicial review by US courts, is considered problematic. Furthermore, under the CLOUD Act, individuals subject to data requests are not necessarily required to be notified of the access, which limits their recourse to legal remedies.
For individuals outside the US, the protection afforded by the US Constitution is already less extensive. The CLOUD Act makes it easier for US authorities to access their data stored with US providers, regardless of location. This fuels global fears about an expansion of US government surveillance. There are concerns that the CLOUD Act's mechanism, particularly the Executive Agreements, could serve as a model for other countries, including those with lower rule-of-law standards and less robust protection of civil liberties. A parallel has already been drawn to China's National Intelligence Law, which also grants Chinese authorities far-reaching access to corporate data. This could accelerate global trends toward increased government surveillance and control of digital communications.
Economic espionage and intellectual property protection
The access rights granted under the CLOUD Act are not limited to the communication content or metadata of private individuals. They can potentially also encompass highly sensitive corporate data stored with US cloud providers. This includes trade secrets, financial data, customer databases, prototypes, research and development data, and other intellectual property (IP).
Even though the stated purpose of the CLOUD Act is to combat serious crime, there are concerns that its far-reaching access rights could be abused, for example, for economic espionage on behalf of US companies or to gain strategic economic advantages. The mere possibility of such access by a foreign government undermines the trust of companies worldwide in the security and confidentiality of their critical data when it is stored with US providers. This risk represents a significant disadvantage for many companies, particularly in technology-intensive or security-critical industries, when using US cloud services.
Conflicts with local legal systems
Similar to the EU GDPR, the extraterritorial scope of the CLOUD Act can also conflict with the data protection laws, confidentiality obligations, or other legal provisions of numerous other countries. Globally operating cloud providers, especially those headquartered or with a strong presence in the USA, are therefore potentially exposed to a network of conflicting legal obligations.
There are numerous examples of countries with their own data protection regimes that are potentially in conflict with the CLOUD Act:
- Switzerland: The revised Federal Act on Data Protection (revFADP) is strongly based on the GDPR and also contains rules for international data transfers that require adequate protection in the destination country.
- Brazil: The Lei Geral de Proteção de Dados Pessoais (LGPD) also has extraterritorial effect and subjects the processing of data of Brazilian citizens to strict rules, including for international transfers.
- India: The Digital Personal Data Protection Act (DPDP Act, often still referred to as PDPB) also contains provisions on data transfers and may impose localization requirements for certain “critical” data.
- China: The Cybersecurity Law (CSL) and the Personal Information Protection Law (PIPL) stipulate strict rules for data security and cross-border transfers and include data localization requirements.
- Russia: Federal Law No. 152 “On Personal Data” mandates the storage of personal data of Russian citizens on servers in Russia (data localization).
These examples illustrate that the CLOUD Act is not just a bilateral problem between the US and the EU, but a global challenge to the coherence of international legal systems in the digital space.
Impact on international data transfers and trust in US technology providers
The existence of the CLOUD Act and the associated uncertainties and legal disputes have significant implications for international data transfer mechanisms and general trust in US technology providers.
The law contributes to the erosion of trust in established instruments for transatlantic data transfers, such as the former EU-US Privacy Shield or the currently widely used Standard Contractual Clauses (SCCs). As outlined in the context of Schrems II, the CLOUD Act makes it more difficult to assume that the US provides a level of protection for personal data that is "essentially equivalent" to EU law.
This is forcing companies worldwide to reassess the risks of using US cloud services more carefully. They must examine whether and how they can ensure compliance with their local data protection laws when transferring data to or having it processed by US providers. This is increasingly leading to the exploration of alternative solutions, such as using local or regional cloud providers that are not subject to US jurisdiction, or implementing additional technical and organizational safeguards (such as end-to-end encryption with proprietary key management, data pseudonymization, or strict data localization for certain data types).
The legal uncertainty created by the CLOUD Act and similar laws in other countries, and the resulting protective measures, could also reinforce a trend toward the "Balkanization" of the internet. This refers to the increasing fragmentation of the global digital space along national or regional borders, characterized by stricter data localization requirements, differing technical standards, and more difficult cross-border data flows. The CLOUD Act acts as a key driver of this global trend toward greater digital sovereignty. By unilaterally enshrining extraterritorial access to data and thus potentially overriding the legal systems of other states, the US is provoking countermeasures. These manifest themselves in the form of data localization laws, government support for local cloud ecosystems, and the tightening of national rules for international data transfers. The CLOUD Act is therefore accelerating, perhaps unintentionally, a development away from an open, globally networked data space toward more nationally or regionally controlled digital territories.
Related to this:
Mapping global dependence on US cloud providers
To assess the scope of the CLOUD Act, an understanding of the global market shares and resulting dependencies on the major US cloud providers – Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) – is essential. The market dominance of these players significantly determines how many companies and organizations worldwide could potentially be affected by CLOUD Act requests.
Market shares of US hyperscalers (AWS, Azure, GCP)
Numerous market analyses confirm the overwhelming dominance of the three major US hyperscalers in the global market for cloud infrastructure services (Infrastructure-as-a-Service, IaaS, and Platform-as-a-Service, PaaS). Together, AWS, Microsoft Azure, and GCP controlled approximately 66% to 70% of global revenue in this segment at the end of 2023 and the beginning of 2025, respectively (depending on the source and the precise market definition).
The approximate market shares for the fourth quarter of 2024 can be summarized as follows (based on data from various sources; exact figures may vary slightly, but the trend is consistent):
- Amazon Web Services (AWS): approximately 30-33%. AWS remains the clear market leader, its pioneering role in cloud computing securing it a sustained lead. However, in recent years there has been a slight tendency towards stagnation or even a slight decline in market share, while the competition is catching up.
- Microsoft Azure: approximately 21-24%. Azure has established itself as a strong number two and is experiencing continuous growth, often driven by integration with other Microsoft products and a strong position in the enterprise sector.
- Google Cloud Platform (GCP): approximately 11-12%. GCP is number three and also shows significant growth, albeit from a smaller base. Google is investing heavily in areas such as AI and data analytics to gain market share.
Besides these three giants, there are other relevant players whose market shares are significantly smaller. These include Alibaba Cloud, which, with approximately 4% global market share, plays a smaller role but dominates the cloud market in China. Other providers with global or regional focuses include IBM, Salesforce, Oracle, Tencent Cloud, and Huawei Cloud (both strong in China), as well as specialized providers.
The following table summarizes the estimated global market shares of the leading cloud infrastructure providers (IaaS/PaaS) for the end of 2024 / beginning of 2025 and illustrates the dominance of the US hyperscalers:
Estimated Global Cloud Market Shares (IaaS/PaaS) Q4 2024/Early 2025
Current data on the global IaaS/PaaS cloud market in the fourth quarter of 2024 and the beginning of 2025 show a clear dominance of US hyperscalers. AWS holds the largest market share at 30 to 33 percent, with a stable to slightly declining trend. Microsoft Azure follows with 21 to 24 percent and is experiencing further growth. Google Cloud Platform (GCP) secures 11 to 12 percent of the market with a positive trend. The Chinese provider Alibaba Cloud maintains a stable global market share of approximately 4 percent. The remaining providers, including IBM, Oracle, Tencent, and Huawei, together share 27 to 34 percent of the market with varying growth trends. The overall position of the US hyperscalers is noteworthy, as they collectively control approximately 62 to 69 percent of the global cloud market and are experiencing slight growth.
These figures underscore the significant global dependence on the three major US providers. A large portion of the world's cloud infrastructure is therefore potentially subject to the jurisdiction of the CLOUD Act.
Regions/countries with high dependency
The dependence on US cloud providers varies geographically, but is very high in many important economic regions:
- North America (especially the USA and Canada): As the home of the hyperscalers and with the highest cloud penetration, the dependence is naturally greatest here. AWS has a particularly strong market position in the USA. Canada also shows high investments in cloud and AI, often via US platforms.
- Europe: Despite concerns regarding GDPR and the CLOUD Act, reliance on AWS, Azure, and GCP in Europe remains extremely high. Their combined market share on the continent is estimated at over 70%. Interestingly, according to one analysis, Azure even appears to be ahead of AWS in some European countries, such as the Netherlands (reportedly 67% market share), Poland (49%), and Japan (49%). Major European economies like Germany, the United Kingdom, and France are investing heavily in cloud technologies and artificial intelligence, with US platforms playing a central role. This discrepancy between high market dependency and the political pursuit of digital sovereignty represents a key area of tension.
- India: The Indian cloud market exhibits strong growth momentum and a heavy reliance on US providers, with a market structure similar to that in the US: AWS leads (approx. 52%), followed by Azure (approx. 35%) and GCP (approx. 13%). At the same time, there is a strong political will for digitalization in India and an increasing drive for data localization, particularly for sensitive data such as financial data. This could promote the growth of local providers in the long term.
- Latin America: Cloud usage is growing in countries like Brazil, but it remains heavily dominated by global US players. AWS is actively expanding in the region, for example with a new region in Mexico. Local data protection laws such as the Brazilian LGPD and specific data localization requirements, such as in the financial sector, could influence market dynamics, but so far have done little to change the fundamental dependency.
- Australia: As a technologically advanced country with close political and economic ties to the US, Australia exhibits high cloud adoption. The existence of a CLOUD Act Executive Agreement between the US and Australia suggests an acceptance of US access mechanisms and indicates a high degree of dependence on US providers.
- Other regions (e.g., Africa, parts of Southeast Asia): Cloud markets are still developing in many emerging and developing countries. Global US providers often dominate here as well, due to their economies of scale and technological lead. At the same time, the drive for digital sovereignty and data localization is also increasing in these regions, as examples from Vietnam and Indonesia demonstrate.
Countries with lower dependency and alternative ecosystems (China, Russia)
In contrast to the widespread dependence on US hyperscalers, largely independent digital ecosystems have developed, particularly in China and Russia, which are dominated by local providers.
- China: The Chinese cloud market is the second largest in the world, but it is heavily regulated and difficult for foreign providers to access. Domestic technology companies clearly dominate: Alibaba Cloud holds a market share of approximately 36%, followed by Huawei Cloud with around 19% and Tencent Cloud with approximately 15-16% (as of Q2/Q3 2024). US providers such as AWS or Azure play only a minor role in the mainland Chinese market. This development is driven by strict government regulation, particularly the Cybersecurity Law (CSL) and the Personal Information Protection Law (PIPL), which, among other things, mandate data localization requirements and tightly control cross-border data flows. China is also pursuing its own ambitious artificial intelligence strategy, which builds on the capabilities of its domestic cloud providers.
- Russia: Similar to China, but for different reasons (particularly Western sanctions and an active government policy to promote digital sovereignty), Russia has seen a growing decoupling from Western technology providers. The Russian cloud market is dominated by local providers, most notably Yandex Cloud, but also providers like SberCloud (now possibly operating under a different name, e.g., Cloud.ru), VK Cloud, and the state-controlled telecommunications company Rostelecom play a significant role. Russian data protection law (Federal Law No. 152) mandates strict data localization for the personal data of Russian citizens, which makes the use of foreign cloud services more difficult and favors local providers. Yandex Cloud explicitly advertises its compliance with these local laws to attract international companies seeking to operate in the Russian market. Government programs such as "Digital Economy of the Russian Federation" and the "GosTech" platform further promote the use of domestic cloud solutions by government agencies and businesses.
- European Union (Potential vs. Reality): The EU finds itself in a unique situation. On the one hand, there are clear political efforts to reduce dependence on US providers and to establish its own digital sovereignty. Initiatives such as Gaia-X and legislative acts like the Data Act aim in this direction. There are also a number of European cloud providers (e.g., OVHcloud, Deutsche Telekom/T-Systems, IONOS). On the other hand, as shown above, the actual market penetration of US hyperscalers in Europe is extremely high. European alternatives have so far failed to achieve comparable market shares, which is often attributed to economies of scale and the technological maturity of US offerings. The EU thus remains a region of high dependence coupled with a strong political will for change.
These examples show that less dependence on US hyperscalers is possible, but this is usually based on a combination of strong government regulation, targeted support for domestic industries and, in some cases, politically motivated market protectionism.
🎯🎯🎯 Benefit from Xpert.Digital's extensive, five-fold expertise in one comprehensive service package | BD, R&D, XR, PR & Digital Visibility Optimization

Benefit from Xpert.Digital's extensive, five-fold expertise in a comprehensive service package | R&D, XR, PR & Digital Visibility Optimization - Image: Xpert.Digital
Xpert.Digital possesses in-depth knowledge across various industries. This allows us to develop tailored strategies precisely aligned with the requirements and challenges of your specific market segment. By continuously analyzing market trends and monitoring industry developments, we can act proactively and offer innovative solutions. The combination of experience and expertise generates added value and provides our clients with a decisive competitive advantage.
More information here:
Digital race for sovereignty: Lessons from the CLOUD Act
National strategies and responses to the CLOUD Act
Given the challenges the US CLOUD Act poses to data protection, sovereignty, and legal certainty, states worldwide have developed diverse strategies to manage the associated risks and protect their interests. These strategies range from regulatory measures and technological approaches to international negotiations.
Comparison of national approaches
Several basic approaches can be observed, which are often combined:
- Data localization: One of the most direct responses is the introduction of laws mandating that certain types of data—often personal data or information classified as critical—must be physically stored and processed within national borders. Prominent examples include Russia with Federal Law No. 152, China with requirements under its Cybersecurity Law and PIPL, and, to some extent, India (particularly for payment data). Countries like Vietnam and Indonesia are also pursuing similar approaches. The motives are manifold: strengthening national sovereignty and control over data, improving national security by restricting access by foreign powers, and also economic protectionism to promote the domestic IT industry. However, from a technological and economic perspective, strict data localization is often inefficient, as it undermines the advantages of globally distributed cloud architectures (such as scalability, redundancy, and cost-efficiency) and leads to higher costs for businesses. The number of countries with such restrictions has increased significantly in recent years.
- Strengthening domestic regulation and international standards: Many countries are focusing on strengthening their own data protection legislation to establish high standards of protection and clearly regulate the conditions for international data transfers. The EU, with its GDPR, is a pioneer in this area. Other countries have followed suit or modernized their laws, often based on the GDPR, such as Switzerland (revFADP), Brazil (LGPD), the United Kingdom (UK GDPR), and Canada (PIPEDA). The goal is often to be recognized by the EU as a country with an "adequate level of data protection" to facilitate data flows with Europe. At the same time, these laws serve to protect the rights of their own citizens and create a legal framework that can potentially be invoked in case of conflict with laws such as the CLOUD Act.
- Promoting local/regional providers and ecosystems: Another approach is the active industrial policy promotion of domestic or regional cloud providers and digital ecosystems to create alternatives to the dominant US hyperscalers and reduce technological dependence. The EU's Gaia-X initiative is an example of this, although its success has been limited so far. In China and Russia, this approach, combined with strong regulation, has been more successful and has led to markets dominated by local providers. The challenge is that local providers often cannot achieve the same economies of scale, the same investment volume, or the same global reach as the US giants.
- Use of International Agreements (Executive Agreements vs. MLATs): States can attempt to regulate data access in law enforcement through international agreements. The CLOUD Act itself provides the mechanism of Executive Agreements for this purpose. Countries such as the United Kingdom and Australia have chosen this path and concluded bilateral agreements with the US, which are intended to enable accelerated, direct data access under certain conditions. These agreements promise efficiency gains compared to the often slow traditional mutual legal assistance procedures (MLATs). However, other countries or regions, such as the EU, are hesitant to conclude such an agreement, partly due to concerns about compatibility with their own high data protection standards (GDPR, Schrems II). They continue to rely primarily on the established MLAT process, which provides for greater involvement of the judicial authorities of the requested state, even though it is considered inefficient. The choice between these approaches represents a balancing act between efficiency in law enforcement and the protection of fundamental rights and sovereignty.
- Technical and organizational measures (TOMs) by companies: Regardless of government strategies, companies themselves are taking measures to mitigate the risks of the CLOUD Act. These include the use of strong encryption methods, ideally with the customer having sole control over the cryptographic keys (Bring Your Own Key – BYOK, Hold Your Own Key – HYOK), the careful selection of the storage location (e.g., data centers within the EU), the implementation of strict access controls, the use of pseudonymization or anonymization techniques, cooperation with local partners or system integrators who manage the data on behalf of the customer, or the implementation of hybrid cloud architectures in which particularly sensitive data remains in the company's own data center (on-premise).
Case studies: EU, Switzerland, Brazil, China, Russia
The application of these strategies can be illustrated using specific country examples:
- The EU is pursuing a multi-pronged approach. Strong regulation (GDPR, Data Act) forms the basis. Initiatives like Gaia-X aim to strengthen sovereignty but face challenges. Simultaneously, negotiations are underway with the US regarding a CLOUD Act agreement, highlighting the ambivalence between the claim to sovereignty and the need for cooperation. The high dependence on US providers remains.
- Switzerland: Its data protection law (revFADP) is closely aligned with the GDPR and uses similar mechanisms for international data transfers (adequacy decisions, SCCs). In response to Schrems II, Switzerland implemented its own agreement with the US (Swiss-US Data Privacy Framework). Nevertheless, the fundamental risk posed by the CLOUD Act remains, as Swiss companies using US services are potentially affected.
- Brazil: With the LGPD, it has created a comprehensive data protection law with extraterritorial effect and established an independent data protection authority (ANPD). There are specific rules for international data transfers and the use of cloud services, particularly in the regulated financial sector. However, the precise interpretation and enforcement, also with regard to conflicts with laws such as the CLOUD Act, are still under development.
- China: It consistently relies on state control, strict data localization, and the promotion of a closed domestic market dominated by national champions. Data protection (in the sense of PIPL) also serves state control and national security.
- Russia: Pursues a similar strategy of digital sovereignty through strict data localization, promotion of domestic providers and increasing technological decoupling from the West, reinforced by geopolitical factors.
Technical and organizational measures of companies
For companies that use US cloud services or operate globally, implementing robust technical and organizational measures is crucial for minimizing risk. These include:
- Transparency and risk assessment: Proactive communication with customers about jurisdictional risks and conducting thorough risk analyses (Data Transfer Impact Assessments – TIAs) to assess the sensitivity of the data and the potential impact of access.
- Careful vendor selection: Examination of alternatives to US providers, particularly European or local providers not subject to US jurisdiction. Evaluation of the vendors' compliance commitments and security architectures.
- Encryption and key management: Strong encryption is used for data both at rest and in transit. Control over the cryptographic keys is crucial. Only if the customer manages the keys exclusively (HYOK) can they effectively prevent access by the provider (and thus potentially by US authorities). Solutions where the provider manages the keys (Bring Your Own Key – BYOK can be misleading here) do not offer complete protection. It should be noted, however, that data for active processing in the cloud often needs to be stored decrypted in memory, which represents a potential access window.
- Access controls and governance: Implementation of strict Identity and Access Management (IAM) policies to restrict data access to the absolute minimum. Examination of whether access by personnel from certain jurisdictions (e.g., USA) to data in other regions (e.g., EU) can be prevented through technical and organizational measures.
- Hybrid and multi-cloud strategies: Migrating particularly sensitive data and workloads to a private cloud or on-premises infrastructure, while less critical applications remain in the public cloud. This enables differentiated risk management.
- Legal structuring: In some cases, establishing legally separate subsidiaries in different jurisdictions can be considered to break the "control" of the US parent company over data in other regions. However, this is complex and requires careful legal structuring.
- Responding to inquiries: Developing clear internal processes for handling inquiries from authorities. This includes verifying the legality of the inquiry and being prepared to challenge orders if they conflict with local laws (e.g., GDPR).
However, it must be noted that technical and organizational measures have their limits. As long as a company subject to US jurisdiction ultimately has possession, custody, or control of the data or the keys necessary for decryption, the fundamental legal risk of being compelled to surrender them under the CLOUD Act remains. Even strong encryption can be circumvented if the provider can be forced to hand over the keys or has access to the management level. A purely technical solution cannot completely eliminate the legal problem of sovereignty claims.
The following table provides a comparative overview of the different national strategies:
Comparison of National Strategies for Mitigating CLOUD Act Risks
Different countries and regions worldwide have developed varying strategic approaches to address the risks posed by the US CLOUD Act. The data localization strategy, as practiced in China, Russia, and parts of India and Vietnam, mandates the strict domestic storage of data. While this increases national control and sovereignty and fosters local industry, it often proves inefficient, costly, and stifling to innovation, and it restricts access to global services.
The EU with the GDPR, Switzerland with the FADP, Brazil with the LGPD, and the UK with the GDPR, on the other hand, are focusing on strengthening their own regulations with high data protection standards, clear rules for international data transfers, and strong supervisory authorities. This strategy protects citizens' rights and creates a legal framework for disputes, but it does not directly resolve the fundamental jurisdictional conflict and places a heavy burden of compliance requirements on companies.
Some regions actively promote local providers and digital ecosystems, such as the EU with the Gaia-X project or China and Russia with their industrial policies. These measures reduce dependence on foreign providers and strengthen technological sovereignty, but are often associated with limited competitiveness against large international providers and prove to be lengthy and costly.
The UK and Australia have concluded Executive Agreements with the US under the CLOUD Act, while the EU is still negotiating. These bilateral agreements allow for accelerated data access for law enforcement agencies and provide legal certainty for providers, but can circumvent national data protection standards and legitimize US access to data.
Many countries implicitly adhere to the traditional MLAT (Mutual Legal Assistance Treaty) process, which offers established legal assistance procedures with stronger rule-of-law guarantees, but is considered slow, bureaucratic and ineffective for digital evidence.
Companies worldwide are also implementing technical and organizational measures such as hold-your-own-key encryption, strict access controls, hybrid cloud solutions, and comprehensive risk analyses. While these measures can mitigate risks and demonstrate compliance, they often fail to address the fundamental jurisdictional problem and are complex and potentially costly to implement.
Related to this:
A problematic law with far-reaching consequences
The analysis of the US CLOUD Act and its global impact reveals a complex web of legal conflicts, technological dependencies, geopolitical tensions, and strategic responses. While conceived with the understandable goal of more efficient law enforcement in the digital age, the law, in its current form, proves highly problematic and poses significant risks to individuals, businesses, and states worldwide.
Summary of the core problems of the CLOUD Act
The main criticisms and problem areas can be summarized as follows:
- Conflict with national sovereignty and legal systems: The explicit extraterritorial claim of the CLOUD Act, which grants US authorities access to data regardless of its storage location, fundamentally clashes with the understanding of sovereignty held by other states and their legal systems. This becomes particularly clear in the conflict with the EU GDPR, especially Article 48, which links the recognition of foreign government orders to international agreements.
- Legal uncertainty and conflict of laws: For globally operating companies, especially cloud providers, the law creates significant legal uncertainty. They face potentially conflicting legal obligations – on the one hand, the US order to disclose data, and on the other hand, the data protection or confidentiality laws of the country where the data is stored or whose citizens are affected. This leads to a dilemma with potential sanctions on both sides.
- Erosion of trust: The CLOUD Act significantly undermines trust in US technology providers. The possibility of US authorities accessing data by circumventing local procedures or without the knowledge of those affected fuels distrust regarding data security and confidentiality. This applies to both personal data and sensitive corporate information and is exacerbated by parallel concerns regarding US surveillance laws (the Schrems II issue).
- Risks beyond law enforcement: Although the stated purpose is to combat serious crime, concerns exist about the misuse of access rights for purposes of state surveillance or economic espionage. These risks are difficult to control and contribute to a loss of trust.
- Promoting global fragmentation: The unilateral approach of the CLOUD Act acts as a catalyst for global fragmentation trends in the digital space. It provokes counter-reactions in the form of data localization laws and the promotion of national digital ecosystems, which encourages a "Balkanization" of the internet and hinders the free global flow of data.
Overview of the global dependency landscape
Market share analysis reveals a massive global dependence on the three major US cloud hyperscalers: AWS, Microsoft Azure, and GCP. Particularly in North America and Europe, they control over two-thirds of the cloud infrastructure services market. This high concentration creates a broad potential attack surface for the CLOUD Act.
In contrast, countries like China and Russia have established largely independent digital ecosystems through strong state regulation, promotion of domestic providers, and market protectionism. They demonstrate that less dependence is possible, albeit often at the cost of limited global connectivity and potentially less freedom of choice.
The European Union finds itself in an ambivalent position: On the one hand, it is highly dependent on US providers, while on the other hand, there is strong political will and concrete initiatives (Gaia-X, Data Act) to strengthen digital sovereignty and promote alternatives. However, the success of these efforts remains uncertain.
Outlook on future developments
The trends triggered by the CLOUD Act and similar developments are likely to continue:
- The prevalence of data localization laws is likely to increase as more and more countries try to maintain control over data within their territory.
- Efforts to build regional or national cloud alternatives will continue, even though success in competition with established hyperscalers remains difficult. Initiatives like Gaia-X could evolve into standardization frameworks for data spaces.
- The US is expected to seek further executive agreements with strategic partners to facilitate data access. However, negotiations with the EU remain complex.
- Legal disputes surrounding international data transfers, particularly in the context of Schrems II and its successor regulations (such as the EU-US Data Privacy Framework), will continue. The question of an "adequate level of protection" in the US remains a pressing issue.
- For companies, the development and implementation of robust compliance strategies and technical solutions for risk reduction (encryption, hybrid models, etc.) is becoming increasingly important in order to operate in this complex environment.
In conclusion, it must be acknowledged that the CLOUD Act addresses a real problem: the need for law enforcement agencies to access evidence stored across borders in a timely manner in the digital age. Traditional MLAT procedures are often too slow and inefficient. However, any sustainable solution must find a way to reconcile this legitimate law enforcement need with fundamental rights to data protection and privacy, as well as states' sovereignty. The CLOUD Act, in its current form, fails to strike this balance, according to many international observers and stakeholders. It represents a US-centric solution that does not adequately consider the concerns and legal systems of other countries, thus creating more problems than it solves. An internationally coordinated solution based on mutual respect for legal systems and strong fundamental rights guarantees remains a pressing need.
Recommendations for action
The analysis of the CLOUD Act and its global impact yields concrete recommendations for action for European companies and organizations as well as for political decision-makers.
For European companies and organizations:
- Conducting comprehensive risk analyses: Companies should systematically assess their dependence on US cloud providers. This includes classifying the processed data according to sensitivity and analyzing the potential risks in the event of data access by US authorities. Conducting Data Transfer Impact Assessments (TIAs), as required in the context of Schrems II, is essential.
- Careful selection of cloud providers: It is advisable to actively consider European or other non-US cloud providers as alternatives that are not subject to US jurisdiction or are subject to less stringent regulations. Providers should be evaluated based on their contractual commitments regarding CLOUD Act requests, their technical safeguards, and their compliance certifications.
- Robust contract design: Contracts with cloud providers should contain clear provisions on data processing, storage locations, security measures and handling of official requests, in accordance with Article 28 GDPR.
- Implementation of strong technical measures: The use of end-to-end encryption, where the cryptographic keys remain exclusively under the customer's control (Hold Your Own Key – HYOK), is an important security measure. Strict access controls (Identity and Access Management) and, where appropriate, pseudonymization or anonymization techniques should be implemented.
- Using hybrid or multi-cloud strategies: For particularly sensitive data, using private clouds or on-premises infrastructures can be beneficial, while less critical workloads can remain in the public cloud. This enables differentiated risk management.
- Obtaining specific legal advice: In view of the complex and constantly evolving legal situation, obtaining specialized legal advice to assess specific risks and develop a viable compliance strategy is essential.
For political decision-makers (especially in the EU):
- Strengthening European digital sovereignty: Consistently promoting initiatives like Gaia-X and supporting the development of competitive European cloud providers are necessary to create genuine technological alternatives and reduce dependency. The Data Act should be used to ensure fair market conditions and control over data.
- A clear stance in international negotiations: Negotiations on a potential EU-US CLOUD Act Executive Agreement must ensure that the high European data protection standards (GDPR, EU Charter of Fundamental Rights, Schrems II provisions) are fully upheld. This includes robust guarantees for the rule of law, proportionality, transparency, and effective legal protection for data subjects. The priority of established mutual legal assistance procedures (MLATs) or equivalent safeguards should be enshrined.
- Promoting global standards: The EU should advocate at international level for the development of harmonized rules and standards for cross-border data access by public authorities, based on the rule of law, respect for fundamental rights and mutual respect between national legal systems.
- Education and support for businesses: Policymakers and regulatory authorities should provide clear guidance and practical support to businesses to help them assess risks and implement compliance measures in dealing with the CLOUD Act and international data transfers.
We are here for you - Consulting - Planning - Implementation - Project Management
☑️ SME support in strategy, consulting, planning and implementation
☑️ Creation or realignment of the AI strategy
☑️ Pioneer Business Development
I would be happy to serve as your personal advisor.
You can contact me by filling out the contact form below or simply call me on +49 7348 4088 965 .
I'm looking forward to our joint project.
Xpert.Digital - Konrad Wolfenstein
Xpert.Digital is a hub for industry focusing on digitalization, mechanical engineering, logistics/intralogistics and photovoltaics.
With our 360° Business Development solution, we support renowned companies from new business to after-sales.
Market intelligence, smarketing, marketing automation, content development, PR, mail campaigns, personalized social media and lead nurturing are part of our digital tools.
You can find more information at: www.xpert.digital - www.xpert.solar - www.xpert.plus






























