Sovereignty
A business protects itself from the CLOUD Act by choosing who holds its data, not merely by moving its servers. The 2018 US law allows a US authority, in the course of a proceeding, to require a provider subject to US jurisdiction to produce the data that provider holds or controls, including when that data is stored outside the United States. It does not create automatic access to European datacenters.
Updated October 202611 min readOfficial sources cited
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) amends US law on stored communications. Three limits help avoid misreadings.
The real risk is therefore narrower than is often claimed, and more lasting: a targeted request, addressed to the provider, in the course of a proceeding.
The law also provides for agreements between governments to govern certain cross-border requests. This aspect does not change the purchasing question: who, in your chain, is a US provider with control of the data?
The order is addressed to the provider and covers the data in its possession or control. The customer then depends on what the provider does with the request.
Under 18 U.S.C. § 2703(h), the provider may move to quash or modify the order if it believes that the customer is not a “United States person”, does not reside in the United States, and that disclosure would create a material risk of violating the laws of a “qualifying foreign government”. It has 14 days after service to do so.
A “qualifying foreign government” is a country that has concluded an executive agreement with the United States that has entered into force. The US Department of Justice publishes agreements with the United Kingdom, signed on 3 October 2019, and with Australia, signed on 15 December 2021. No agreement is in force with the European Union; EU–US negotiations on electronic evidence resumed in 2023. The Department’s page mentions no agreement with France.
The consequence: the challenge mechanism specific to § 2703(h) presupposes such an agreement. A French business should not count on this remedy as an established protection.
The law’s criterion is control, not geography. Take an industrial SME with two sites that has chosen a European data region with a US software vendor. Its messages are stored in Europe. But the company that administers the service and can restore a mailbox remains American. Faced with an order, the storage region does not change the question: are these data under its control?
On 10 June 2025, before the French Senate commission of inquiry on public procurement, the director of public and legal affairs of Microsoft France was asked whether he could guarantee under oath that the data of French citizens entrusted to Microsoft via Ugap would never be transmitted, following an order from the US government, without the explicit consent of the French authorities. His answer: “No, I cannot guarantee it, but, once again, it has never happened yet.” Both halves of the sentence matter. The first describes the legal framework; the second, the practice observed by the company.
The GDPR approaches the question from the other end. Under Article 48, a judgment of a court or a decision of an authority of a third country requiring the transfer or disclosure of personal data may only be recognised or enforceable if it is based on an international agreement, such as a mutual legal assistance treaty, in force between that country and the Union or the Member State.
A US provider operating in Europe may therefore find itself caught between two legal systems: a US order on one side, and on the other a European rule that does not recognise it without an international agreement. Article 48 does not settle this conflict on the provider’s behalf. For the buyer, the issue is concrete: ask how this provider handles such a request, whether it challenges it, and whether it informs the customer when the law allows.
As of 5 October 2026, transfers from the European Union to certified US organisations can still rely on adequacy decision (EU) 2023/1795, known as the Data Privacy Framework. This decision is in force. It is being challenged, and changes in US law have led the European Data Protection Board to ask the Commission to assess their effects. Until it is withdrawn or annulled, it remains effective.
The litigation continues. According to a commentary by the law firm WilmerHale published on 1 December 2025, the General Court of the European Union dismissed the action for annulment on 3 September 2025, and an appeal was lodged before the Court of Justice on 31 October 2025. The law firm DAC Beachcroft sums up the situation in one phrase: stability for now, uncertainty ahead. These points are reported here on the basis of lawyers’ commentaries.
The Data Privacy Framework governs transfers within the meaning of the GDPR. It does not take a US provider out of the scope of the CLOUD Act. A prudent business documents this legal basis and plans what to do if it falls. This monitoring belongs in the record of transfers, not in a slogan.
Choose the operator. If the company that bills, backs up and administers the service is European, and does not depend on a US group for possession of the data, a CLOUD Act order is not addressed to it. This is the main lever.
Read the list of subcontractors. A European operator that sends emails, backups or support to a US subcontractor reintroduces a provider subject to US law. The list of subcontractors is part of the protection. The common mistake: checking the main hosting provider and forgetting the ticketing tool or the backup.
Distinguish the software vendor from the operator. Using software whose vendor is American is not the same as entrusting the data to that vendor. Zimbra is published by Synacor, in the United States. When it is installed and backed up by a European hosting provider, in that provider’s facilities, the operational holder of the mailboxes is the hosting provider. The contract must prohibit the vendor from accessing content, and state who applies the patches.
Treat support as access. A technician who opens a mailbox or a backup is processing data. Where that technician is located, the record of the access and its reason matter as much as the location of the disk.
Encrypt with a key you hold, where the service allows it. Encryption at rest with a key held by the provider protects against disk theft. It does not prevent the provider from reading the data to deliver the service, nor from producing them if compelled to. Encryption with a key that only you hold changes the picture for content. On a full suite, it does not always cover every stage: some stages require the service to process the content, and encryption there is then in the hands of the software vendor or the operator (filtering and quarantine, indexing for search, document processing in a CRM). The right questions are therefore: at which stages does the provider manage the key, how long do the data remain there, and who can access them? The scope has to be read.
Keep an exit. Regular exports, open formats, and a restore test. Legal protection without a recoverable copy is incomplete.
Nor is the CLOUD Act the only criterion. A business with data of low sensitivity, which depends on advanced Microsoft 365 or Google Workspace features and documents the Data Privacy Framework in its record, can reasonably stay. The choice becomes questionable when it has not been made: no one has named the holder of the data or planned an exit. The pages European cloud or American cloud and Microsoft 365 or a sovereign solution explore this trade-off.
Example: a 25-person accounting firm that goes through this exercise often finds that the email service is clearly identified, but that the e-signature tool, file sharing with clients or the backup were added without checking the operator. These are the lines to regulate first.
The checks specific to each suite are on the pages GDPR and Microsoft 365 and GDPR and Google Workspace; the general criteria, in what is a sovereign cloud.
No. The law targets the provider subject to US law that has possession or control of the data, wherever they are stored. The location of the disk remains useful, but it does not answer the question of the operator.
§ 2703(h) provides for a motion to quash or modify, within 14 days of service. This remedy presupposes an executive agreement in force with the country concerned. The US Department of Justice page mentions no agreement with France, and none is in force with the European Union.
It sets a European rule: a foreign decision is recognised only if it is based on an international agreement in force. It places the US provider in a conflict of laws, without resolving it on the provider’s behalf.
Dedicace Software, a French company, operates Klytic. Hosting is provided in any geographical area corresponding to the applicable jurisdiction, subject to the availability of the required services, for example in Europe or Mauritius, or on the customer’s servers. The email software is Zimbra, published in the United States: protection comes from the operator and the operating contract, not from the vendor’s nationality. The software vendor has no access to the data and cannot compel Klytic to hand them over.
The data are held entirely by the customer, or by Klytic on the customer’s behalf, in a geographical area that falls under the applicable jurisdiction. They are encrypted natively, or according to the customer’s choice. The key is held by the customer, or kept in the customer’s account, and Klytic has no access to it.
Some stages rely on encryption managed by Klytic, because the service has to process the content: emails and documents processed in the CRM, and emails placed in quarantine by the filtering, which are encrypted in the database. The exception is the email service: if the customer has not enabled encryption with its own key, its emails are stored encrypted with a key managed by Klytic. Conversely, emails encrypted by the customer can be indexed for search if the customer has given its key to its email client.
In transit, emails are encrypted from the moment they pass through Klytic MTA filtering, then between the platform’s servers, and on every access to the mailbox: webmail, email client or mobile, from the company network as well as from outside. Only one stage does not depend on Klytic: sending to another domain. Encryption is maintained there when the recipient’s server supports it, which is often the case; otherwise, the message makes this last journey in clear text, as with any email provider. To guarantee confidentiality all the way to the recipient in every case, the message itself must be encrypted (S/MIME or PGP).
Access to files is tightly restricted through limited access rights, and a connection audit raises an alert in the event of a fraudulent attempt. As with any provider, the contract must describe this possession, this encryption and their scope. See also the page hosting and sovereignty.
Klytic does not hold the SecNumCloud qualification. None of these statements constitutes general immunity: a French operator remains subject to French law.
This page describes a general framework. It does not constitute legal advice.
Legal status as of 5 October 2026. This text does not replace a contract review. The EU–US adequacy decision (EU) 2023/1795 is in force. It is being challenged. The ANSSI catalogue is authoritative for SecNumCloud.
Accessed in October 2026.
Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.
Welcome offer
No-commitment trial. An advisor calls you back to understand your needs and prepare your Klytic workspace.