← Back to blog

The CLOUD Act explained: UK and EU data sovereignty in 2026

July 23, 2026
The CLOUD Act explained: UK and EU data sovereignty in 2026

The Clarifying Lawful Overseas Use of Data Act, universally known as the CLOUD Act, is a U.S. federal law enacted on 23 march 2018 that requires American electronic communication service providers to disclose data held on their servers in response to lawful U.S. legal process, regardless of where that data is physically stored. It amended the Stored Communications Act (SCA) to resolve a long-standing ambiguity about extraterritorial data access, and it introduced a framework for bilateral executive agreements enabling qualifying foreign governments to request data directly from U.S. firms. For UK and EU organisations, the law creates a direct conflict with domestic data protection obligations, particularly under the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

The CLOUD Act's two core functions are:

  • Mandatory disclosure: U.S. providers must produce data in their possession, custody, or control in response to a valid SCA warrant, irrespective of the country where the data resides.

  • Executive agreements: The U.S. executive branch may conclude bilateral agreements with qualifying foreign governments, enabling those governments to request data directly from U.S. providers without routing through mutual legal assistance treaty (MLAT) processes.

  • Comity provisions: Providers may file a motion to quash or modify a warrant where disclosure would conflict with the laws of a country that has an executive agreement with the United States.

  • Scope of providers: Any provider subject to U.S. jurisdiction, including foreign companies with a significant U.S. legal presence, falls within the Act's reach.

  • Privacy safeguards: Executive agreements require independent judicial oversight, must address serious crimes only, and cannot target U.S. persons.


What is the legislative background behind the CLOUD Act?

The CLOUD Act did not emerge in a vacuum. Its origins lie in a structural deficiency in the Stored Communications Act, which was enacted as Title II of the Electronic Communications Privacy Act of 1986 (ECPA). The SCA was written for a pre-cloud era, when data was stored domestically on local servers. As global cloud infrastructure expanded, U.S. law enforcement agencies found themselves unable to compel disclosure of data stored in foreign data centres, even when that data was held by a U.S.-based provider.

The pivotal dispute was United States v. Microsoft Corporation, in which the U.S. government sought the contents of an MSN.com email account stored in a Microsoft data centre in Ireland. Microsoft refused to comply, arguing that the SCA did not authorise extraterritorial warrants. The case reached the U.S. Supreme Court, but Congress passed the CLOUD Act as part of the Consolidated Appropriations Act, 2018, before the Court could issue a ruling. On 17 April 2018, the Supreme Court declared the Microsoft case moot in light of the new legislation.

Key legislative milestones:

DateEvent
1986Electronic Communications Privacy Act (ECPA) and Stored Communications Act enacted
U.S. government issues warrant to Microsoft for data stored in Ireland
2016Second Circuit Court of Appeals rules SCA warrants cannot compel overseas disclosure
2018 (January)Identical CLOUD Act bills introduced in the U.S. House and Senate
23 March 2018CLOUD Act signed into law as part of the Consolidated Appropriations Act, 2018
17 April 2018U.S. Supreme Court rules United States v. Microsoft moot

The Act also addressed a reciprocal problem: foreign governments had no efficient mechanism to obtain data held by U.S. providers. Prior to 2018, they were confined to MLATs and letters rogatory, both of which U.S. and foreign officials criticised as slow and ill-suited to the volume of digital evidence requests in modern criminal investigations.


The CLOUD Act operates through two distinct legal pillars, each addressing a different dimension of cross-border data access.

Infographic contrasting CLOUD Act mechanisms and impacts

Mandatory disclosure under the SCA is the Act's most consequential provision for non-U.S. organisations. Under 18 U.S.C. § 2713, a provider of electronic communication service or remote computing service must comply with obligations to preserve, back up, or disclose data within its possession, custody, or control, regardless of whether that data is located inside or outside the United States. The possession, custody, or control standard is the operative trigger: corporate structure or technological control over data is sufficient to create a compliance obligation, even if the data physically resides on servers in Frankfurt or London.

Executive agreements represent the second pillar. The U.S. Attorney General, with the concurrence of the Secretary of State, may certify a bilateral agreement with a foreign government that meets defined standards. Before any such agreement enters into force, Congress has a mandatory 180-day review period and may block it by enacting a joint resolution of disapproval. Agreements must satisfy the following conditions:

  • The partner country must have domestic laws affording robust substantive and procedural protections for privacy and civil liberties.
  • The partner government must adopt procedures to minimise acquisition, retention, and dissemination of information concerning U.S. persons.
  • The agreement cannot create an obligation for providers to be capable of decrypting data.
  • All orders issued under the agreement must be subject to independent review or oversight, grounded in credible and articulable facts, and must identify a specific person, account, or identifier.

Comity provisions allow providers to challenge U.S. warrants on the grounds that disclosure would violate the laws of a country with an executive agreement with the United States. In practice, this avenue is rarely used. The legal complexity, evidentiary burden, and cost of establishing citizenship and data ownership make comity objections difficult to mount successfully.


How does the CLOUD Act conflict with EU and UK data sovereignty laws?

The tension between the CLOUD Act and European data protection law is structural, not incidental. The European Data Protection Board (EDPB) has confirmed that GDPR Article 48 prohibits the recognition or enforcement of any foreign court judgment or decision requiring the transfer of personal data unless it is based on an international agreement, such as an MLAT, that is in force between the requesting country and the EU. A U.S. CLOUD Act warrant, absent such an agreement, does not constitute a valid legal basis for processing under Article 6(1)(c) GDPR.

Diverse hands discussing data sovereignty documents

The EDPB and the European Data Protection Supervisor (EDPS) issued a joint assessment concluding that, without a formal EU-U.S. international agreement containing strong fundamental rights safeguards, service providers subject to GDPR cannot lawfully base the disclosure of personal data on a CLOUD Act request. This creates a genuine conflict of laws: a provider may face legal liability in the United States for non-disclosure and simultaneous liability in the EU for disclosure.

Key conflict points for organisations operating in the UK and EU:

  • GDPR Article 48 restricts recognition of foreign data access orders that conflict with EU law, absent an applicable international agreement.
  • UK Data Protection Act 2018 mirrors GDPR principles on cross-border transfers, creating equivalent restrictions for UK-established controllers.
  • Chapter V GDPR governs international data transfers and requires an adequate legal basis; a bare CLOUD Act warrant does not satisfy this requirement.
  • Conflict of laws dilemma: Providers caught between a U.S. warrant and GDPR obligations face potential penalties in both jurisdictions simultaneously.
  • EDPB position: The Board recommends that EU companies refer direct requests from third-country authorities to the applicable MLAT process rather than complying directly.

What does the CLOUD Act mean in practice for UK cloud service providers?

Any provider with a U.S. legal presence, including foreign companies with significant U.S. operations, falls within the CLOUD Act's scope. This is not limited to American technology giants. A UK-based cloud provider that operates a U.S. subsidiary, maintains U.S.-registered entities, or processes data through U.S.-based infrastructure may be subject to U.S. warrants compelling disclosure of data held anywhere in the world.

The possession, custody, or control standard means that legal or technological control over data, rather than its physical location, determines compliance obligations. A UK data controller whose data is processed by a U.S. parent company's platform faces the same exposure as if the data were stored in Virginia. For UK organisations assessing foreign cloud compliance risks, this distinction is operationally significant.

Best practices for UK providers navigating CLOUD Act obligations:

  • Conduct a thorough jurisdictional analysis to determine whether any group entity or infrastructure component creates a U.S. legal nexus.
  • Review contractual arrangements with U.S.-based sub-processors to understand disclosure obligations and notification rights.
  • Assess whether data subject categories and processing purposes would make CLOUD Act disclosure particularly high-risk under UK GDPR.
  • Establish an internal escalation protocol for responding to U.S. legal process, including legal counsel review before any disclosure.
  • Consider whether the comity challenge mechanism is viable for specific data categories, accepting that this route carries significant legal cost and uncertainty.
  • Evaluate data architecture to determine whether technical measures can reduce the volume of data accessible to U.S.-controlled entities.

Technical and practical solutions to reduce CLOUD Act exposure

Technical safeguards are, in practice, more reliable than legal arguments alone when managing CLOUD Act risk in a multinational context. The most direct mitigation is end-to-end encryption where the service provider does not hold the decryption keys. If a provider cannot access plaintext data, it cannot produce readable content in response to a warrant, regardless of the legal obligation to disclose. The CLOUD Act itself does not require providers to build decryption capabilities, and executive agreements are expressly prohibited from imposing such a requirement.

Sovereign or localised data centres outside U.S. jurisdiction reduce, though do not eliminate, CLOUD Act exposure. Physical data location is not the operative legal test, but removing U.S.-controlled entities from the data processing chain does reduce the likelihood that the possession, custody, or control standard is met. Organisations should also consider cross-border data management strategies that segment data by jurisdiction and processing purpose.

Practical technical and operational safeguards include:

  • End-to-end encryption with client-managed keys, ensuring providers hold no plaintext data.
  • Data residency controls that restrict processing to non-U.S.-controlled infrastructure.
  • Jurisdictional segmentation of data by legal entity, ensuring no U.S. group company has possession, custody, or control of sensitive European or UK data.
  • Access control architecture that prevents U.S.-based personnel or systems from accessing data subject to GDPR or UK Data Protection Act obligations.
  • Contractual protections requiring sub-processors to notify the data controller immediately upon receipt of any U.S. legal process and to challenge such process where legally permissible.
  • Regular legal audits of the corporate and technical structure to identify new U.S. nexus points created by acquisitions, partnerships, or infrastructure changes.

How sovereign cloud solutions address CLOUD Act risks for UK organisations

Sovereign cloud refers to cloud infrastructure that is owned, operated, and legally governed within a specific national jurisdiction, ensuring that data remains subject exclusively to that jurisdiction's laws. Unlike conventional public cloud services provided by U.S.-headquartered technology companies, a sovereign cloud platform is structured to eliminate the U.S. legal nexus that triggers CLOUD Act obligations.

IT engineer inspecting server equipment in data center

The legal and compliance benefits for UK and EU organisations are direct. Data processed exclusively through a sovereign cloud provider with no U.S. parent, no U.S. subsidiary, and no U.S.-controlled infrastructure does not fall within the possession, custody, or control of any entity subject to U.S. jurisdiction. A valid U.S. warrant cannot compel disclosure from a provider that has no legal presence in the United States and no corporate or technological connection to U.S. entities.

Islandedgetech's approach to sovereign cloud infrastructure illustrates this model in practice. Through products including EdgePod, Ackee, and Abeng, Islandedgetech provides data residency on local soil, governed exclusively by Jamaican law and the Data Protection Act 2020. No U.S. entity holds possession, custody, or control of client data, which means the CLOUD Act's mandatory disclosure provisions do not apply. For organisations in sectors handling sensitive personal data, including healthcare, finance, and public administration, this architecture removes a category of legal risk that contractual protections alone cannot fully address.

Key features of sovereign cloud solutions relevant to CLOUD Act risk:

  • Local data residency: Data is stored and processed within a defined national jurisdiction, under that jurisdiction's laws exclusively.
  • No U.S. legal nexus: The provider has no U.S. parent company, subsidiary, or infrastructure component that could trigger CLOUD Act obligations.
  • Domestic legal compliance: Processing remains subject to local data protection law, such as Jamaica's Data Protection Act 2020, without conflict from U.S. extraterritorial statutes.
  • Operational resilience: Local infrastructure reduces dependence on foreign service continuity and eliminates exposure to U.S. regulatory or law enforcement disruption.
  • Audit and accountability: Sovereign providers operate under domestic regulatory oversight, providing a clear and auditable compliance framework.

Organisations seeking to understand how sovereign cloud infrastructure addresses these obligations can review Islandedgetech's published compliance framework.


The United States v. Microsoft Corporation case remains the most significant legal precedent directly preceding the CLOUD Act. Microsoft's refusal to produce emails stored in its Irish data centre forced a direct confrontation between U.S. law enforcement authority and European data sovereignty principles. The Second Circuit Court of Appeals ruled in Microsoft's favour in 2016, finding that the SCA did not authorise extraterritorial warrants. Congress's legislative response, the CLOUD Act, effectively reversed that outcome by amending the SCA to extend its reach globally.

Post-enactment, the legal landscape has continued to develop. The Schrems II ruling by the Court of Justice of the European Union in july 2020 invalidated the EU-U.S. Privacy Shield framework, finding that U.S. surveillance laws, including the CLOUD Act, did not provide adequate protection for EU data subjects. The ruling placed the burden on data controllers and processors to assess, on a case-by-case basis, whether the legal framework of the destination country ensured adequate protection. CLOUD Act exposure became a mandatory consideration in transfer impact assessments following Schrems II.

The EDPB's subsequent guidelines on Article 48 GDPR, updated in december 2024, reinforced the position that direct compliance with a CLOUD Act warrant, absent an applicable international agreement, is incompatible with GDPR obligations. These guidelines have direct operational implications for any UK or EU organisation whose data is processed by a U.S.-connected provider.


How does the CLOUD Act compare with previous U.S. data access laws?

The CLOUD Act did not create new surveillance powers. Its purpose, as the U.S. Department of Justice has stated, was to clarify existing lawful access and address the inefficiencies of the MLAT system. Understanding what changed, and what did not, is essential for accurate legal risk assessment.

Prior to the CLOUD Act, the primary mechanisms for cross-border data access were:

  • MLATs: Bilateral treaties providing a structured process for cross-border evidence sharing in criminal cases, reviewed by the U.S. Department of Justice and a federal court before disclosure is authorised. Widely criticised as slow and resource-intensive.
  • Letters rogatory: Discretionary requests between courts of different countries, available to both governments and private litigants, and generally considered the least efficient method of obtaining evidence abroad.
  • ECPA/SCA warrants: Domestic warrants under the Stored Communications Act, whose extraterritorial reach was legally contested until the CLOUD Act resolved the ambiguity.

The CLOUD Act introduced a third category: executive agreements that remove legal restrictions on qualifying foreign governments' ability to seek data directly from U.S. providers, bypassing the MLAT process entirely for covered requests. The United Kingdom and the United States concluded the first such agreement under the CLOUD Act framework, entering into force in october 2022. This agreement allows UK law enforcement to serve legal process directly on U.S. providers for data related to serious crime investigations, without requiring U.S. government intermediation.

The Budapest Convention on Cybercrime, to which the United States is a party, provided an earlier framework for international cooperation on electronic evidence. The CLOUD Act's mandatory disclosure provision was designed to align U.S. law with Article 18(1) of the Budapest Convention, which requires parties to compel service providers to produce specified data in their possession or control.


What are the implications for individual privacy rights under UK and EU law?

For individuals whose personal data is processed by U.S.-connected cloud providers, the CLOUD Act creates a material privacy risk that domestic data protection law cannot fully neutralise. Under GDPR and the UK Data Protection Act 2018, data subjects hold rights including access, rectification, erasure, and restriction of processing. None of these rights can be exercised against a U.S. law enforcement authority that has obtained data pursuant to a CLOUD Act warrant.

The EDPB has noted that CLOUD Act requests are targeted rather than systematic, governed by procedural safeguards including judicial authorisation and probable cause requirements. However, the absence of a formal EU-U.S. international agreement covering CLOUD Act requests means that individuals cannot rely on GDPR mechanisms to challenge or prevent disclosure. The comity challenge mechanism available to providers is not a data subject right; it is a procedural option available to the provider, exercised at the provider's discretion and cost.

UK data subjects face an additional layer of complexity following Brexit. The UK GDPR, which mirrors the EU GDPR in its cross-border transfer provisions, applies to UK-established controllers and processors. The UK-U.S. CLOUD Act executive agreement, in force since october 2022, addresses the reciprocal access question for UK law enforcement but does not resolve the conflict between U.S. CLOUD Act warrants and UK data protection obligations for UK data subjects whose data is held by U.S. providers.

Organisations processing sensitive categories of personal data, including health data, financial records, and communications content, carry the greatest exposure. The data sovereignty implications of relying on U.S.-connected infrastructure for such data categories warrant careful legal and technical review.


What legislative developments are shaping the CLOUD Act's future in the UK and EU?

The CLOUD Act framework is not static. Several legislative and diplomatic developments are likely to reshape its application in the UK and EU context over the coming years.

EU-U.S. negotiations on a formal international agreement covering CLOUD Act requests have been ongoing since the EDPB and EDPS issued their joint assessment recommending such an agreement as the most appropriate instrument for ensuring adequate protection for EU data subjects. The European Commission has recommended this route, but no agreement was in force as of mid-2026. Until such an agreement is concluded, the legal conflict between CLOUD Act obligations and GDPR Article 48 remains unresolved for EU-established organisations.

The EU's e-Evidence Regulation, which entered into force in 2023 and applies from 2026, establishes a new framework for cross-border access to electronic evidence within the EU. It creates European Production Orders and European Preservation Orders, enabling judicial authorities in one EU member state to obtain electronic evidence from service providers established in another. The e-Evidence Regulation does not resolve the CLOUD Act conflict directly, but it establishes a parallel EU framework that may inform future EU-U.S. negotiations.

UK legislative developments following Brexit include ongoing review of the UK's adequacy decisions and international data transfer framework. The UK-U.S. CLOUD Act executive agreement addresses UK law enforcement access to U.S.-held data, but the UK government has not yet concluded a formal agreement resolving the conflict between U.S. CLOUD Act warrants and UK data protection obligations for UK data subjects.

Proposed CLOUD Act amendments in the United States have focused on strengthening privacy safeguards, expanding the range of countries eligible for executive agreements, and improving transparency about the volume and nature of requests. None of these proposals had been enacted as of mid-2026, but the Cross-Border Data Forum's 2025 FAQ update reflects active engagement from policy stakeholders on these questions.

For organisations seeking to reduce dependence on the outcome of these negotiations, the most reliable path is architectural: structuring data processing through providers with no U.S. legal nexus, as detailed in Islandedgetech's guidance on common cloud compliance mistakes that leave organisations exposed to extraterritorial law.


Key takeaways

The CLOUD Act's mandatory disclosure provision, grounded in the possession, custody, or control standard, means that physical data location is legally irrelevant: any U.S.-connected provider can be compelled to produce data stored anywhere in the world.

PointDetails
Enacted 23 march 2018The CLOUD Act amended the Stored Communications Act to extend U.S. data access obligations globally, regardless of storage location.
GDPR Article 48 conflictAbsent an applicable international agreement, CLOUD Act warrants do not constitute a valid legal basis for processing under GDPR.
Possession, custody, or controlLegal or technological control over data, not its physical location, determines whether a provider must comply with a U.S. warrant.
UK-U.S. executive agreementThe UK and U.S. concluded a CLOUD Act executive agreement in force from october 2022, covering UK law enforcement access to U.S.-held data.
Sovereign cloud as mitigationProviders with no U.S. legal nexus fall outside the CLOUD Act's mandatory disclosure scope, offering the most reliable structural protection.

Protect your data from extraterritorial reach

https://islandedgetech.com

The legal conflict between the CLOUD Act and UK/EU data sovereignty obligations will not be resolved by contractual clauses or policy statements alone. Organisations that process sensitive personal data through U.S.-connected cloud infrastructure carry a compliance risk that persists regardless of where their servers are physically located.

Islandedgetech's sovereign cloud infrastructure is built to eliminate this risk at the architectural level. Through EdgePod, Ackee, and Abeng, Islandedgetech provides data residency under Jamaican law, with no U.S. entity holding possession, custody, or control of client data. The CLOUD Act's mandatory disclosure provisions cannot reach data that sits entirely outside U.S. jurisdiction. For organisations in healthcare, finance, and public administration, that distinction carries direct legal and operational weight.

Explore Islandedgetech's sovereign cloud solutions to understand how local data infrastructure removes extraterritorial exposure and supports compliance with domestic data protection obligations.