Last updated: 28 August 2026. This page explains a legal matter as accurately as public sources allow. It does not constitute legal advice.

What this is about

The Clarifying Lawful Overseas Use of Data Act, known as the CLOUD Act, is a United States statute enacted in 2018. It requires providers of communication and cloud services that fall under US jurisdiction to disclose data in their possession, custody or control — irrespective of whether that data is held inside or outside the United States.

The operative provision is 18 U.S.C. § 2713. What matters under it is not where a server stands, but who has legal and actual control over the data.

Why “servers in Europe” does not answer the question

Many providers advertise data centres in the EU. That is a genuine advantage for latency, for availability and for a range of data protection questions. For the CLOUD Act it is beside the point.

If a company falls under US jurisdiction, the disclosure obligation reaches all data it controls — including data held in Frankfurt, Dublin or Vienna. A European data centre operated by an American corporation does not change that.

Whether, and when, this also extends to European subsidiaries of American corporations is not settled law. An expert opinion prepared by the University of Cologne for the German Federal Ministry of the Interior, and a paper by the German Bundestag research service, affirm corporate control. Other voices, among them the Cross-Border Data Forum, deny that this follows automatically. We are not aware of any published US court decision ordering disclosure of data held by an EU subsidiary under § 2713. Anyone claiming certainty here — in either direction — is going beyond what the evidence supports.

The conflict with the GDPR

Article 48 of the General Data Protection Regulation provides that decisions of a court or authority of a third country requiring disclosure of personal data may only be recognised or enforced if based on an international agreement.

This is where the real difficulty arises, and it is structural: a provider under US jurisdiction faces a conflict of laws it cannot itself resolve. It can either comply with the US order or comply with the GDPR. It cannot do both. The European Data Protection Board and the European Data Protection Supervisor set this out precisely in their joint response to the LIBE Committee.

This conflict cannot be removed by contract, nor by choosing a server location. It is a property of the legal situation, not a failing of any particular provider.

One detail that is rarely mentioned: § 2703(h) of the CLOUD Act provides a route to challenge an order. That route is only open in relation to states with which the United States has concluded an executive agreement. To date these are the United Kingdom and Australia. For Austrian data, this protective mechanism has no effect. What remains is the weaker, judge-made balancing exercise under the doctrine of comity.

How often does this happen?

The providers’ own transparency reports are more useful here than their competitors’ advertising.

For the second half of 2025, Microsoft reports disclosures of content data to US law enforcement concerning three non-US enterprise customers whose data was held outside the United States. One of those three customers was, by Microsoft’s own account, located in the EU or EFTA. The same report states that none of these disclosures involved Azure content data. Amazon Web Services reports no such cases for the first half of 2026.

These figures refute two common claims at once. “This happens constantly” is false. The cases are very few. “This has never happened” is equally false. It has happened, and a European corporate customer was among those affected.

What European courts say

The French Conseil d’État addressed the question in March 2026 and arrived at a formulation more honest than most marketing statements from either camp: the risk of access cannot be entirely excluded — but in view of the safeguards in place, it is acceptable.

A ruling of the Karlsruhe Higher Regional Court on procurement law and a decision of the German data protection conference point in the same direction. European case law therefore treats the CLOUD Act as a real but limited risk — neither as grounds for exclusion nor as a nullity.

What this means for SUSI

By default we use a model provider established in the EU whose processing runs through European endpoints. That provider is not subject to US jurisdiction. In regular operation the question therefore does not arise.

It arises in two cases:

What we do not claim

We do not say that your data will be seized at an American provider. The figures above show this happens very rarely, and we have no reason to make more of it than it is.

We do not say that American providers are insecure. They operate substantial security organisations, in most cases larger than ours.

We do not say that this legal situation leaves us entirely untouched. On a view taken in the expert opinion referred to above, operating a website addressed in part to American visitors may bring a company within the reach of US jurisdiction. We consider that unlikely, and we have no US subsidiary, no US parent company and no US infrastructure — but a blanket “this does not concern us” would be a stronger statement than we can substantiate.

What we do say is this: the conflict of laws exists, it is structural, and it cannot be contracted away. Avoiding it means changing the legal jurisdiction, not the server location. That is precisely why our default configuration looks the way it does.

Sources

Further information on how we process your data is set out in our privacy policy.