Your data is stored in Ireland. The server is owned by an American company. US law applies.

Literal meaning: The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a 2018 US law that requires US-based technology companies to provide US law enforcement and government agencies with data stored on their servers, regardless of where that data is physically located — including in EU jurisdictions where GDPR provides data protection rights.

Origin: The law was passed in response to the Microsoft Ireland case, in which the US Department of Justice sought email data stored on Microsoft servers in Ireland. The case raised the question of whether US legal process could compel a US company to produce data stored outside the US. The CLOUD Act resolved this by establishing that US companies must comply with US government data requests regardless of storage location.

US legislation that requires American cloud providers to share data with US authorities — creating a structural conflict with EU data protection law.

The Appeal: From a US law enforcement perspective, the CLOUD Act resolves a genuine operational problem: criminal investigations increasingly require access to data stored globally, and jurisdictional fragmentation was impeding law enforcement. The law also creates a bilateral executive agreement mechanism that allows the US to negotiate data-sharing arrangements with other countries.

The Friction: The conflict with GDPR is structural, not incidental. Brussels Effect establishes GDPR as a de facto global standard; the CLOUD Act establishes that US law overrides that standard for US cloud providers. Any EU organisation using US cloud infrastructure — Microsoft Azure, Amazon Web Services, Google Cloud — operates in an infrastructure that is legally required to comply with US government data requests, regardless of GDPR protections. Vendor Lock-in intensifies this: organisations that are deeply embedded in US cloud infrastructure cannot easily exit to EU-based alternatives. The EU’s response has been to develop “sovereign cloud” initiatives that seek to create EU-controlled infrastructure — with limited success to date.

Why This Matters: CLOUD Act names the legal conflict at the heart of EU digital infrastructure. Once you know the law exists, any claim that EU organisations’ data is protected by GDPR when stored in US cloud services requires qualification: it is protected from commercial data extraction, but not from US government access.

Related terms: Brussels Effect · Vendor Lock-in · Surveillance Capitalism · Privacy Washing · Algorithmic Violence


Read more:

Created with AI assistance (Claude, ChatGPT, Lumo) using cartographic prompting — a research method developed within Project Digitale Alertheid, HAN CMD, 2026.