What is the US CLOUD Act?
A plain-English guide to the law that lets US authorities reach data stored anywhere in the world — and why “EU-headquartered” alone doesn’t mean “CLOUD Act-free.”
The short version
The Clarifying Lawful Overseas Use of Data Act — the CLOUD Act — is a US law passed in 2018. It lets US law enforcement legally compel any company subject to US jurisdiction to hand over data it controls, no matter which country that data is physically stored in. Before the CLOUD Act, companies could sometimes argue that data held on foreign servers was outside the reach of a US warrant. The CLOUD Act closed that gap: jurisdiction now follows the company, not the data centre.
Why “hosted in the EU” isn’t enough
Cloud providers like AWS, Microsoft Azure, and Google Cloud all offer EU regions, and many US SaaS products now advertise “EU data residency.” That helps with GDPR data-residency requirements, but it does not remove US legal jurisdiction over the company itself. If the provider is a US company — or a foreign subsidiary controlled by one — US authorities can still compel it to disclose data it controls, even when that data physically sits in Frankfurt or Dublin. The CLOUD Act reaches the company, not the server rack.
Why “EU-headquartered” isn’t automatically enough either
The inverse assumption is just as common, and just as incomplete: that a company founded and headquartered in an EU member state is automatically outside the CLOUD Act’s reach. What actually determines exposure is who ultimately owns the company and where its underlying infrastructure lives. A genuinely EU-founded company can still be a subsidiary of a US parent, or it can run its product on US-owned cloud infrastructure — either of which can bring US jurisdiction back into the picture, regardless of where the company’s registered office sits.
That’s why EU Alts verifies ownership and hosting facts per listing rather than inferring exposure from headquarters country alone — see the “Verified” badge on individual startup pages for the specifics we’ve confirmed on each entry.
How this relates to GDPR and Schrems II
GDPR governs how personal data must be protected and where it can legally be transferred. The 2020 Schrems II ruling from the Court of Justice of the EU struck down the EU-US Privacy Shield framework, finding that US surveillance laws — including the CLOUD Act and FISA 702 — create a structural conflict with EU data protection guarantees that a Data Processing Agreement or Standard Contractual Clauses alone can’t fully resolve. In practice, using a CLOUD Act-exposed provider for EU personal data recreates the same legal uncertainty Schrems II was about, no matter how much paperwork sits on top of it.
Frequently asked questions
What is the US CLOUD Act?
The Clarifying Lawful Overseas Use of Data (CLOUD) Act is a 2018 US law that lets US law enforcement compel any company subject to US jurisdiction to produce data it controls, regardless of where that data is physically stored. It overrides the 'data lives on an EU server, so EU law applies' assumption: jurisdiction follows the company, not the data centre.
Does hosting data in an EU region protect me from the CLOUD Act?
No. If the provider is a US company — or a foreign subsidiary of a US company — US authorities can compel it to disclose data it controls even when that data sits in an EU data centre. Choosing an 'EU region' on AWS, Azure, or Google Cloud reduces latency and can help with GDPR data-residency requirements, but it does not remove US legal jurisdiction over the provider.
Is a company automatically CLOUD Act-exposed just because it's headquartered outside the US?
Not necessarily, but EU headquarters alone isn't proof of safety either. What actually matters is who ultimately owns the company and where the underlying infrastructure provider is based. A company can be founded and headquartered in the EU while being a subsidiary of a US parent, or while running on US-owned cloud infrastructure — either of which can bring it back under US jurisdiction.
How does the CLOUD Act relate to GDPR and Schrems II?
GDPR governs how personal data must be protected and where it can be transferred; Schrems II (the 2020 CJEU ruling that struck down the EU-US Privacy Shield) confirmed that US surveillance laws, including the CLOUD Act, create a fundamental conflict with EU data protection guarantees. In practice, using a CLOUD Act-exposed provider for EU personal data creates the same legal uncertainty that Schrems II flagged, regardless of any Data Processing Agreement (DPA) or Standard Contractual Clauses (SCCs) layered on top.
How does EU Alts verify CLOUD Act exposure?
Rather than assuming EU headquarters means CLOUD Act-free, EU Alts researches and records each listed company's actual ownership structure and hosting location, and marks the entry 'Verified' only once an admin has confirmed those facts. Entries not yet verified are shown as pending, not asserted as compliant.