All posts

The US CLOUD Act, Explained for Europeans: How a US Warrant Reaches Your EU-Hosted Data

A US warrant doesn't cross the Atlantic — it just needs the company to be American. Here's exactly how the CLOUD Act reaches EU-hosted data, and the two things that put data beyond it.

What the CLOUD Act actually does

The CLOUD Act — Clarifying Lawful Overseas Use of Data, signed into US law on March 23, 2018 — lets a US legal order compel a US-incorporated company to hand over data it controls, no matter which country the servers sit in. A warrant served in Washington reaches a hard drive in Frankfurt because it never has to leave US soil. It binds the company, and the company goes and fetches the bytes. That is the whole mechanism, and it is why "our datacenter is in Europe" answers the wrong question.

It amended the older Stored Communications Act to settle exactly what the US v. Microsoft "Ireland" case had left open: can a US provider be forced to produce data stored abroad? The Act's answer is yes. If a provider is incorporated in the United States, or has enough business there, it must produce data in its custody or control on a valid US order — Frankfurt, Dublin, Paris, the location is irrelevant. The law does not reach into European soil. It reaches the company, and the company is American.

Why "our datacenter is in Frankfurt" doesn't protect you

This is the part the marketing is built to obscure. AWS, Microsoft Azure, and Google Cloud all offer EU regions. You pick Frankfurt in a dropdown, sign a data-residency commitment, watch your data stay in Europe. None of that changes who controls the company running the region. The relevant question was never where is the data. It is who can be compelled to produce it. For a US provider, the answer is the parent company, under US jurisdiction — and that order can carry a gag clause that legally bars them from telling you it happened.

You don't have to take a privacy company's word for this. Take Microsoft's. On June 10, 2025, before a French Senate committee, Microsoft France's director of public and legal affairs Anton Carniaux was asked under oath whether he could guarantee French citizens' data would never be handed to the US government. His answer: "Non, je ne peux pas le garantir." No, I cannot guarantee it. In fairness, Carniaux added that Microsoft contests requests it considers unjustified and that no such demand had, to his knowledge, ever been served. But "we'd fight it and it hasn't happened yet" is a policy. "It is not legally possible" is the only promise that survives a court order, and it's the one he couldn't make.

The carve-out that sounds reassuring and mostly isn't

The Act does include a safety valve. A provider may move to quash a demand if it reasonably believes the target is not a US person and doesn't live in the US, and producing the data would risk breaking a foreign country's law, and that country has a qualifying executive agreement with the US. Those conditions are cumulative. They depend on a bilateral agreement existing. And the motion is discretionary — filed in a US court, by a US company weighing its own commercial interests. It's an appeal a provider can choose to make, not a wall the law builds for you. For a European whose files sit with a US company, that is thin cover.

This isn't a fringe worry anymore

European institutions have stopped treating this as hypothetical. On May 27, 2026, the European Commission presented its Tech Sovereignty Package, which proposes restricting US cloud platforms for sensitive public-sector data — healthcare, finance, judicial systems — across all 27 member states, with the CLOUD Act named as a driver. The three US hyperscalers it targets hold roughly 70% of Europe's cloud market. The proposal currently covers public-sector bodies, so a private clinic or law firm doesn't automatically fall under it. The direction of travel is not subtle.

And the transatlantic data deal doesn't close the gap. The EU–US Data Privacy Framework survived its first challenge when the General Court dismissed the Latombe case on September 3, 2025 — but that was appealed on October 31, 2025, with no hearing date set as of mid-2026. The Framework governs whether transfers are lawful under GDPR. It does nothing to remove a US provider's obligation under US law to comply with a US warrant. Two separate questions; the second one is the one that touches your files.

What actually puts data beyond US reach

Two independent moves close the gap, and the strongest posture uses both.

  • Non-US jurisdiction. If no US-incorporated entity sits anywhere in the chain that controls your data, there is no American company for a US court to compel. Beebeeb is operated by Initlabs B.V., incorporated in the Netherlands (KvK 95157565), with data on dedicated servers in Falkenstein, Germany, through a German infrastructure provider with no US parent. There is no US entity to serve.
  • Zero-knowledge encryption. Jurisdiction settles who can be ordered; encryption settles what can be produced. Your files are encrypted on your device with AES-256-GCM before they leave it. The keys are derived from your passphrase with Argon2id and never reach our servers. We hold ciphertext. If a German court served us a valid order tomorrow, we could produce account metadata — we could not produce readable files, because we have never been able to read them. That limit cuts both ways: lose your passphrase and recovery phrase, and we cannot recover your data either. We document exactly what we hold and what we don't on our security page.

Either move alone leaves a seam. A European provider that holds your keys can still be compelled to decrypt under its own jurisdiction. A US provider with client-side encryption removes file-content exposure but still answers US orders for everything else it holds — metadata, access logs, account records. You want both seams closed.

If you're auditing your own setup

Ask one question about every cloud service you run: who is the legal entity that controls this data, and whose courts can compel it? If the answer is a US corporation, the CLOUD Act applies no matter which region you picked. That holds whether your files live on iCloud — see our honest Beebeeb-vs-iCloud comparison for where Apple's Advanced Data Protection helps and where it doesn't — or on Dropbox, where we lay out the jurisdiction and key-custody picture in our guide to EU alternatives to Dropbox.

The CLOUD Act is worth understanding precisely. Once you do, "stored in the EU" stops sounding like an answer and starts sounding like the question it actually leaves open.

Files only you can read

Beebeeb is end-to-end encrypted, zero-knowledge cloud storage — stored in Falkenstein, Germany, open source, with a 14-day free trial on every plan. Encryption happens on your device; we only ever hold ciphertext we can’t read.

Join the waitlist See pricing How the encryption works