Last updated: 28 August 2026. This page explains a legal matter as accurately as public sources allow. It does not constitute legal advice.
What this is about
The Clarifying Lawful Overseas Use of Data Act, known as the CLOUD Act, is a United States statute enacted in 2018. It requires providers of communication and cloud services that fall under US jurisdiction to disclose data in their possession, custody or control — irrespective of whether that data is held inside or outside the United States.
The operative provision is 18 U.S.C. § 2713. What matters under it is not where a server stands, but who has legal and actual control over the data.
Why “servers in Europe” does not answer the question
Many providers advertise data centres in the EU. That is a genuine advantage for latency, for availability and for a range of data protection questions. For the CLOUD Act it is beside the point.
If a company falls under US jurisdiction, the disclosure obligation reaches all data it controls — including data held in Frankfurt, Dublin or Vienna. A European data centre operated by an American corporation does not change that.
Whether, and when, this also extends to European subsidiaries of American corporations is not settled law. An expert opinion prepared by the University of Cologne for the German Federal Ministry of the Interior, and a paper by the German Bundestag research service, affirm corporate control. Other voices, among them the Cross-Border Data Forum, deny that this follows automatically. We are not aware of any published US court decision ordering disclosure of data held by an EU subsidiary under § 2713. Anyone claiming certainty here — in either direction — is going beyond what the evidence supports.
The conflict with the GDPR
Article 48 of the General Data Protection Regulation provides that decisions of a court or authority of a third country requiring disclosure of personal data may only be recognised or enforced if based on an international agreement.
This is where the real difficulty arises, and it is structural: a provider under US jurisdiction faces a conflict of laws it cannot itself resolve. It can either comply with the US order or comply with the GDPR. It cannot do both. The European Data Protection Board and the European Data Protection Supervisor set this out precisely in their joint response to the LIBE Committee.
This conflict cannot be removed by contract, nor by choosing a server location. It is a property of the legal situation, not a failing of any particular provider.
One detail that is rarely mentioned: § 2703(h) of the CLOUD Act provides a route to challenge an order. That route is only open in relation to states with which the United States has concluded an executive agreement. To date these are the United Kingdom and Australia. For Austrian data, this protective mechanism has no effect. What remains is the weaker, judge-made balancing exercise under the doctrine of comity.
How often does this happen?
The providers’ own transparency reports are more useful here than their competitors’ advertising.
For the second half of 2025, Microsoft reports disclosures of content data to US law enforcement concerning three non-US enterprise customers whose data was held outside the United States. One of those three customers was, by Microsoft’s own account, located in the EU or EFTA. The same report states that none of these disclosures involved Azure content data. Amazon Web Services reports no such cases for the first half of 2026.
These figures refute two common claims at once. “This happens constantly” is false. The cases are very few. “This has never happened” is equally false. It has happened, and a European corporate customer was among those affected.
What European courts say
The French Conseil d’État addressed the question in March 2026 and arrived at a formulation more honest than most marketing statements from either camp: the risk of access cannot be entirely excluded — but in view of the safeguards in place, it is acceptable.
A ruling of the Karlsruhe Higher Regional Court on procurement law and a decision of the German data protection conference point in the same direction. European case law therefore treats the CLOUD Act as a real but limited risk — neither as grounds for exclusion nor as a nullity.
What this means for SUSI
By default we use a model provider established in the EU whose processing runs through European endpoints. That provider is not subject to US jurisdiction. In regular operation the question therefore does not arise.
It arises in two cases:
- Where your organisation has models from American providers enabled and your staff select them. Which models compute in which legal jurisdiction is labelled within the service — European models carry the suffix “(EU)”. Enabling them is your organisation’s decision, not the individual user’s.
- In two add-on functions of our EU provider, image generation and web research, which according to that provider may involve processing steps outside the EU. We can switch both off for your environment. This is not a setting someone at your end can undo by accident — it is a property of the environment, and it can be recorded contractually.
What we do not claim
We do not say that your data will be seized at an American provider. The figures above show this happens very rarely, and we have no reason to make more of it than it is.
We do not say that American providers are insecure. They operate substantial security organisations, in most cases larger than ours.
We do not say that this legal situation leaves us entirely untouched. On a view taken in the expert opinion referred to above, operating a website addressed in part to American visitors may bring a company within the reach of US jurisdiction. We consider that unlikely, and we have no US subsidiary, no US parent company and no US infrastructure — but a blanket “this does not concern us” would be a stronger statement than we can substantiate.
What we do say is this: the conflict of laws exists, it is structural, and it cannot be contracted away. Avoiding it means changing the legal jurisdiction, not the server location. That is precisely why our default configuration looks the way it does.
Sources
- 18 U.S.C. § 2713 — wording of the disclosure obligation
- Regulation (EU) 2016/679, Article 48
- European Data Protection Board and European Data Protection Supervisor, joint response to the LIBE Committee, 10 July 2019
- Microsoft, Law Enforcement Requests Report, second half of 2025
- Amazon Web Services, Information Request Report, first half of 2026
- Conseil d’État, decision of 20 March 2026, nos. 503159 and 504171
- Karlsruhe Higher Regional Court, decision 15 Verg 8/22
- German Data Protection Conference, decision of 31 January 2023
- University of Cologne, expert opinion for the German Federal Ministry of the Interior, March 2025
- German Bundestag research service, WD 3-3000-105/23
Further information on how we process your data is set out in our privacy policy.