All posts

Is your cloud storage subject to the US CLOUD Act? A plain-English guide for EU businesses

If your cloud provider is a US company, the CLOUD Act reaches your data — even when it sits on servers in Frankfurt or Dublin. The 2018 law compels US firms to hand over data they control, anywhere on earth, on a valid US demand. EU servers and "sovereign cloud" branding don't change who can be comp

If your cloud provider is a US company, the CLOUD Act reaches your data — even when it sits on servers in Frankfurt or Dublin. The 2018 law compels US firms to hand over data they control, anywhere on earth, on a valid US demand. EU servers and "sovereign cloud" branding don't change who can be compelled.

That's the whole article in four sentences. The rest is the why, the how do I check, and the one architecture that makes the question disappear.

I'm Bram, co-founder of Beebeeb. We build encrypted storage where we genuinely cannot read your files, so I've spent more hours than any sane person should inside this exact legal mess. Let me save you the reading.

What the CLOUD Act actually says

The Clarifying Lawful Overseas Use of Data Act passed in 2018. The acronym is friendly. The substance is not: a US company must produce data in its possession, custody, or control when a US legal demand requires it — no matter where the data physically lives.

The word that does the work is control. Not location. Congress wrote this law for one reason: a US provider had argued in court that data on an Irish server sat beyond American reach. The CLOUD Act exists to kill that argument. Servers in Europe do not put a US company outside US jurisdiction. The company is the hook. The datacentre is scenery.

So the question for your business isn't "where is my data?" It's "who controls my data, and what passport does that entity carry?"

A US-headquartered provider spinning up a region in eu-central-1 is still a US company. A European subsidiary, a joint venture, a "data trustee" arrangement — none of these automatically cut that control. We'll get to why that distinction turned into a public brawl.

Where it collides with GDPR

Here's the vice a European business sits in.

GDPR, Article 48, says a court order from a non-EU country is not on its own a lawful basis to ship personal data out of the EU. The CLOUD Act says a US provider must comply with a valid US demand. One provider. Two laws. Opposite instructions. Obey one, breach the other.

This isn't theoretical tension dressed up for a blog post. In June 2025, in front of the French Senate, Microsoft France's legal director, Anton Carniaux, was asked under oath whether he could guarantee that data held in Microsoft's French infrastructure would never be passed to US authorities. He couldn't — "No, I cannot guarantee that." And that's not a Microsoft flaw — it's the structure. No US company can give that guarantee, because the law binding them isn't theirs to repeal.

The honest summary: if your processor is a US company, paper GDPR compliance and real CLOUD Act exposure live side by side. You can have a beautiful Data Processing Agreement and a back door you are contractually unable to close.

The Schrems II → DPF → Schrems III timeline, briefly

You don't need the full case law. You need the shape of the uncertainty.

  • Schrems II (2020) struck down Privacy Shield, the framework that legalised EU-to-US personal data transfers. The court's logic: US surveillance law left Europeans with no meaningful redress.
  • The EU-US Data Privacy Framework (2023) is the replacement, and the legal basis most companies lean on today when they send data to US providers.
  • It's already under fire. The General Court dismissed the Latombe case against the DPF on 3 September 2025; an appeal landed on 31 October 2025. A "Schrems III" challenge is being prepared. Many privacy lawyers expect the DPF to fall within two to four years.

Read that last bullet twice. The legal basis your transfers rest on has, by expert consensus, a 2-to-4-year expected shelf life. Sign a multi-year contract on top of it and you're building on a foundation with a published demolition window. The risk isn't a raid tomorrow. It's a framework that keeps collapsing and getting rebuilt, forcing you to re-paper and re-architect every couple of years.

"Sovereign cloud" and the washing problem

The demand is real, so the hyperscalers are selling the cure. In 2026 the sovereignty market is large and growing fast — Gartner puts worldwide sovereign-cloud spending near $80B for the year, up about 36% on 2025, with Europe the fastest-moving region at roughly 83% growth. Supply has shown up to meet it.

AWS European Sovereign Cloud went live on 15 January 2026 in Brandenburg, Germany: a separate German parent entity, EU-resident-only operations, a roughly 15% price premium, around 90 services against 240+ in the main cloud. Microsoft, in parallel, has been rolling out its own sovereign options — M365 Local and Foundry Local — on top of an EU Data Boundary and a European oversight board. These are serious pieces of engineering, and for some workloads they genuinely lower the risk.

But here's the sentence nobody on the sales side will say out loud: no law repeals the CLOUD Act. A US-parented provider with EU servers, EU staff and an EU joint venture is still, somewhere up the corporate chain, compellable. The structure can raise the cost and friction of compulsion. It cannot make a US company stop being a US company.

That's why "sovereignty washing" became a named fight in 2026. When the European Commission recognised S3NS — a JV built on Google technology — as "sovereign," CISPE secretary general Francisco Mingorance called it "an own goal that institutionalises sovereignty washing." The Register and other trade press ran the row through the spring. The EU is, in effect, arguing with itself about whether its own sovereignty labels mean anything.

I'll plant my flag where the evidence does: the enemy is the category lie, not any one vendor. When a US-controlled service wraps itself in a European flag in its marketing while the control chain runs straight to a US courtroom, that's the thing to be sceptical of. The fix isn't better branding. It's a different answer to "who holds the keys."

Regulators are closing in on the same point from a dozen angles. The EU Data Act became fully applicable on 12 September 2025 and bans cloud egress and switching fees outright from 12 January 2027, with a mandatory switching right. NIS2 — whose national-transposition deadline for member states was 17 October 2024, with enforcement and Commission infringement steps ramping through 2025–2026 — together with EU regulation 2024/2690 mandates cryptographic policy and cryptographic agility. DORA (in force since January 2025) demands exit procedures and a register of critical ICT providers for financial firms. The direction of travel is one-way: away from lock-in, toward provable control. France is moving large parts of its public sector off Microsoft — its Gendarmerie has run on a custom Linux build for years, and the city of Lyon has been shifting off proprietary tools. All 27 member states signed a digital-sovereignty declaration in November 2025. This is not a fringe view anymore.

Is my provider exposed? A 60-second checklist

Run your provider through these. Any "yes" in the first three puts CLOUD Act exposure on the table.

  1. Is the entity that controls your data a US company, or a subsidiary/JV of one? Check the contracting entity in your terms, not the marketing site. If the ultimate parent is US-incorporated, the answer is yes — EU servers notwithstanding.
  2. Can your provider technically hold the keys to decrypt your data? If they can read your files to power search, previews, server-side AI, or "we'll email you a reset link that restores your files," they hold decryption capability. And capability is exactly what can be compelled.
  3. Does your transfer mechanism depend on the DPF? If your DPA's lawful basis is the Data Privacy Framework, your legal footing has that multi-year demolition window.
  4. Can you get a straight, in-writing answer to "could you be compelled to hand over our data to a non-EU authority?" If you get a paragraph of reassurance instead of a clean "no, because we cannot read it," read that as a soft yes.
  5. Is encryption zero-knowledge, or just "encrypted at rest"? Encrypted-at-rest means the provider holds the key and decrypts on their servers. Compellable. Zero-knowledge means the key never leaves your device.

Questions 2 and 5 are the whole game. Everything else is mitigation. These two are the exit.

The exit: EU ownership plus zero-knowledge

Most of this article is about shrinking exposure. There's exactly one way to remove it.

You cannot be compelled to produce what you do not have. If your provider never holds the key that decrypts your data, then a court order — American, European, whoever — produces ciphertext. Unreadable bytes. The provider can be perfectly honest, fully cooperative, and still have nothing useful to hand over, because the architecture handed them nothing useful to begin with.

This is the design choice behind Beebeeb, and it isn't a marketing pose — it's the thing we couldn't undo even if we wanted to. Files are encrypted on your device with AES-256-GCM before they ever reach us. Logging in runs through OPAQUE — a password-authenticated key exchange — with an Argon2id key-stretch tuned to 256 MiB of memory, so we never see your password and the key that unlocks your files is derived on your device, not ours. We store ciphertext we cannot read. Our security model is built so that "we comply with lawful demands" and "your files stay private" are both true at the same time, because for us complying just means handing over bytes nobody can open.

Then stack jurisdiction on top. Beebeeb is operated by Initlabs B.V., a Netherlands company (KvK 95157565), with data stored in Falkenstein, Germany, under EU law. We are not a US company and not a US subsidiary, so the CLOUD Act's control hook never attaches to us in the first place. Zero-knowledge removes the capability. EU ownership removes the jurisdiction. Belt and braces.

And because "trust me" is the worst possible note for a privacy product, our clients and encryption core are open source — verify the crypto yourself instead of taking my word for it. In the spirit of the honesty this brand is built on: the server is private, an independent security audit is planned but not yet completed, and our mobile and desktop apps are coming soon. The web app, the bb CLI for push/pull/sync, and WebDAV mount are live today.

Credit where it's due — this isn't a one-vendor idea. Proton Drive is open-source, audited, and offers genuinely zero-knowledge storage with a 5 GB free tier. Tresorit is a real zero-knowledge product with EU regions and a 3 GB free Basic plan. They're good products, full stop. If you're weighing options, our head-to-heads on Beebeeb vs Proton Drive and Beebeeb vs Tresorit lay out the differences without spin — our edges are jurisdiction, open clients, the CLI and WebDAV workflow, and scale, not "they're bad." The line that actually settles the CLOUD Act question is the same for all three of us: nobody holds your keys, so nobody can be forced to surrender your plaintext.

What I'd actually do if I ran an EU business

Don't rip everything out on Monday. Do this instead. Find the data that would genuinely hurt if a foreign authority read it — client files, contracts, the personal data you're accountable for under GDPR. Move that data to a provider that fails the compulsion test by design: not in the US, and not holding your keys. Leave the low-stakes stuff wherever it's convenient.

The point isn't paranoia. It's that the legal ground keeps shifting, the "sovereign" labels keep getting challenged, and the one thing immune to all of it is an architecture where the answer to "can you hand it over?" is "we physically can't." If you want to see where that lands on cost, our pricing starts with 5 GB free using the exact same encryption as the paid plans — the free tier isn't a weaker product, just a smaller one. (Need room to grow? Up to 99 TB self-serve, custom quote beyond.)

Build on the thing that can't be subpoenaed open. That's the whole strategy.

Files only you can read

Beebeeb is end-to-end encrypted, zero-knowledge cloud storage — stored in Falkenstein, Germany, open source, with a 14-day free trial on every plan. Encryption happens on your device; we only ever hold ciphertext we can’t read.

Join the waitlist See pricing How the encryption works