Sovereignty & data residency

Cloud Act: why "hosted in Europe" is not enough

You ask a vendor where your data goes. The answer comes back polished: "our servers are in Europe." It sounds like a complete answer. It is only half of one. Server location tells you where the data sits. It tells you nothing about who can legally compel its disclosure. Since 2018, an American law has made that second question the one that actually decides your exposure, and it is the question almost no vendor volunteers to answer.

This guide explains what the Cloud Act says, who it really applies to, why the Data Privacy Framework does not neutralise it, and how to verify in practice whether a SaaS or AI tool sits outside US jurisdiction.

What the Cloud Act actually says

The Cloud Act (Clarifying Lawful Overseas Use of Data Act) was signed into law on 23 March 2018, as part of the Consolidated Appropriations Act. It did not appear out of nowhere: it settled a case the US Supreme Court was in the middle of hearing.

That case began in December 2013, when Microsoft was served with a warrant under the Stored Communications Act for emails held in a datacenter in Dublin. Microsoft refused to hand them over, arguing that a US warrant could not reach data stored in Ireland. The dispute climbed all the way to the Supreme Court, which heard argument in February 2018. Before the Court could rule, Congress passed the Cloud Act, and the case was declared moot.

What the Cloud Act changed fits in one clause. It amended the Stored Communications Act so that a provider must preserve, back up or disclose the content and records in its possession, custody or control, "regardless of whether such communication, record, or other information is located within or outside of the United States".

The sentence that changed cloud compliance

Before 2018, the debate was about where the servers were. After 2018, the legal test is control, not geography. A datacenter in Paris or Frankfurt is no longer an answer to the question.

Who is actually subject to it

The Cloud Act does not target "American companies" as a label. It reaches any provider subject to US jurisdiction, which is a broader category than most European buyers assume. Three situations are commonly caught:

The practical consequence is uncomfortable but simple: what determines your exposure is the legal nationality of the company operating the service, and of the group that controls it. Server location is a detail by comparison.

This is not an abstract question about cloud contracts. It applies to every tool in your stack: the CRM that holds your pipeline, the note-taking app that holds your meetings, the AI assistant you paste documents into, the dictation tool you speak your files into. That last one is the case almost nobody anticipates, because dictated audio is often the most confidential thing a professional produces in a day.

Not a theoretical risk: Microsoft before the French Senate

If this still reads as academic, one hearing settled it. In June 2025, testifying under oath before a French Senate committee of inquiry, the legal director of Microsoft France acknowledged that he could not guarantee that the data of French citizens hosted by the company would never be handed over to US authorities without France's consent.

That admission came from a hyperscaler with substantial European datacenters and an extensive sovereignty offering of its own. It is not a competitor's claim, it is the vendor's own answer, given under oath. For any organisation handling confidential files, that single exchange is worth more than a hundred marketing pages about European hosting.

The Data Privacy Framework answers a different question

When you press a US vendor on transfers, the answer is usually the Data Privacy Framework (DPF), the adequacy decision adopted by the European Commission on 10 July 2023. A US company self-certifies, and can then receive personal data from the European Union with no further formality. On paper, the transfer is lawful. Two things are worth knowing before you rely on it.

First, it is the third framework of its kind, and the previous two were struck down. Safe Harbor was invalidated by the Court of Justice of the European Union in October 2015 (Schrems I), and the Privacy Shield in July 2020 (Schrems II), both on the grounds that US surveillance did not offer Europeans protection essentially equivalent to EU law. The DPF survived its first challenge: on 3 September 2025, the EU General Court dismissed the action brought by Philippe Latombe, a member of the French National Assembly and a commissioner at the CNIL (case T-553/23). But that judgment was appealed on 31 October 2025 and is now pending before the Court of Justice as case C-703/25 P. As of August 2026 the appeal has not been decided, and commentators do not expect a ruling before late 2026 at the earliest. Building your confidentiality on a mechanism that has already been invalidated twice is a bet, not a guarantee.

Second, and more fundamentally, the DPF does not neutralise the Cloud Act. The two instruments answer different questions. The DPF makes the commercial transfer of data to the United States lawful. The Cloud Act governs access by US authorities to data a provider already holds. A vendor can be impeccably DPF-certified and still receive a valid US order compelling disclosure. The compliance of the transfer does not protect you from the access.

The other authority: FISA Section 702

The Cloud Act is not the only route. Section 702 of the Foreign Intelligence Surveillance Act allows US intelligence agencies to compel electronic communication service providers to hand over the communications of non-US persons located outside the United States. Europeans, in other words. It was precisely the inadequacy of the safeguards around this surveillance that led the Court of Justice to strike down the Privacy Shield in Schrems II.

Section 702 has been in legislative turbulence through 2026. It was last reauthorised in April 2024 by the Reforming Intelligence and Securing America Act, with an unusually short two-year sunset, and Congress has not settled a long-term renewal since. That instability changes nothing operationally for a European customer: as the Brennan Center has documented, collection continues under existing certifications issued by the FISA court, which run into March 2027 irrespective of the statutory sunset. Planning on the assumption that this authority will lapse is not a strategy.

What sovereignty actually means, in four checks

"Sovereign" has become a marketing word. Here is how to test it, in the order that matters.

  1. Who owns the publisher. Look up the company in the national registry: legal form, registered office, share capital, and above all whether a US parent or a US-controlled group sits above it. A European brand can be a wholly owned subsidiary. This check takes five minutes and answers the main question.
  2. Who operates the sub-processors, and where. The vendor's own hosting is rarely the whole story. Ask for the sub-processor list and read it: the model provider, the database, the authentication layer, the payment processor. One US link in that chain is enough to bring the data it touches back within scope.
  3. Content versus metadata. These are almost always handled differently. A vendor may genuinely process your documents in France and still route account data, email, authentication, billing, through American SaaS providers. That may be perfectly acceptable to you, but you should know it rather than discover it. Ask the vendor to draw the line explicitly.
  4. What the contract actually commits to. A data processing agreement under Article 28 of the GDPR should name the sub-processors, state where each one processes data, and commit the vendor to notifying you before changing any of them. A vendor unwilling to name its chain is telling you something.

The trap specific to AI tools

There is one failure mode that European buyers of AI tools hit again and again, and it is worth stating on its own.

A vendor can be a genuine European company, hosting its application on genuine European infrastructure, and still send every one of your documents to the United States. It happens at the model call. If the product's intelligence comes from an API operated by OpenAI, Anthropic, Google or a US-controlled cloud, then your content leaves the European perimeter at the exact moment the product becomes useful. The European hosting is real, and it is also beside the point: it holds the interface, not the payload.

For voice dictation this is close to being the default. Most tools on the market, including several presented as privacy-first, transcribe by calling a US speech-to-text API. The dictated audio, which is often the most confidential thing a professional produces in a day, is sent straight into scope.

The question that cuts through

"Which AI models do you use, which company operates them, and on which infrastructure do they run?" A vendor that processes your content on its own European infrastructure answers in one sentence. A vendor that resells a US API takes a paragraph, and still does not answer.

Six questions to put to any vendor, in writing

  1. Which legal entity publishes the service, and is it controlled by a non-European parent company?
  2. Where is my content processed, and by which companies? Not "in Europe", but the named list.
  3. Which AI models do you use, and who operates them? The point of failure specific to AI products.
  4. Which of my data is content and which is account metadata, and are they handled differently?
  5. Are you, or any of your sub-processors, subject to the Cloud Act or another extraterritorial law? A European vendor with no US parent can answer no, plainly.
  6. Do you provide a DPA under Article 28 that names your sub-processors and commits you to notifying changes?

The answers should arrive in writing and without hedging. Where they do not, you have your answer anyway. If you want the GDPR side of the same analysis, our guide on voice dictation and GDPR covers the obligations that apply to the tool itself, and our article on the AI Act explains why AI regulation says nothing at all about any of this.

Where Fast Dictate stands

Fast Dictate is built to answer those six questions in one page rather than in a sales call.

A vendor that will not draw the line for you is drawing it somewhere you would not like.

We would rather publish where the boundary sits, including the part that is not perfectly sovereign, than let you find out from a sub-processor list two years into a contract. See the detail on our Security page and our pricing.

Frequently asked questions

Does hosting data in Europe protect it from US authorities?

No, not on its own. The Cloud Act requires a provider subject to US jurisdiction to disclose the data in its possession, custody or control regardless of whether that data sits inside or outside the United States. A datacenter in Paris operated by a US-controlled company remains within reach. What determines exposure is the legal nationality of the company operating the service.

Is the European subsidiary of a US company subject to the Cloud Act?

In practice, yes. The test is control, not incorporation. Where a US parent controls its European entity, the data held by that entity is generally treated as being within the parent's control, and a US order can reach it. No court has ruled directly on the point, but Microsoft France gave the practical answer under oath before the French Senate in June 2025. Setting up an EU entity is not by itself a shield.

Does the Data Privacy Framework protect against the Cloud Act?

No. The DPF makes a commercial transfer of personal data to the United States lawful. The Cloud Act concerns access by US authorities to data a provider already holds. A vendor can be fully DPF-certified and still be compelled to disclose. Compliance of the transfer does not protect you from the access.

How can I check whether a SaaS or AI tool is genuinely outside US jurisdiction?

Four checks: the ownership of the publisher in the company registry; the sub-processor list, and in particular who operates the AI models and where; the distinction between your content and your account metadata; and a DPA that names the sub-processors and commits the vendor to notifying you of changes.

Try Fast Dictate for free →

Related articles

Privacy & GDPR

Voice dictation and GDPR: where does your voice go?

By Pierrick Michel · August 2026