Your cloud contract says your data sits in the EU. Frankfurt, Amsterdam, Dublin, pick a region. For a US provider, the country is not the question that matters.
What the CLOUD Act actually says
The CLOUD Act is a US law from 2018. In plain words: a company under US law can be ordered to hand over your files. The country those files sit in makes no difference. The law covers anything in that company’s “possession, custody, or control”. An EU region changes how fast your searches run. It does not change who can be ordered to open them.
The law was written for that. It ended the old argument that files kept abroad were out of reach.
The admission under oath
For years vendors answered with reassurance. Transfers are rare, sovereignty clauses protect you. Then in June 2025 the French Senate asked Microsoft France a direct question. Can you promise French citizens’ data will never go to US authorities without French agreement?
Under oath: no such promise could be made.
That is not a scandal about one vendor. Any provider under US law would answer the same way.
But we have an EU sovereignty offering
Sovereign cloud products are real and they cut real risk. Local staff, support inside the EU, promises about daily handling. None of it rewrites a US law. While a US company controls the machines, the question stays open.
For most work that risk is fine. Marketing files, public documentation, data you could recreate. The CLOUD Act is no reason to move your website.
When it stops being fine
The sums change when the documents are the business.
- Bid prices and margins. A builder’s tender calculations are the company. No commercial director signs off on “a foreign authority may compel access.”
- Client files under professional secrecy. A law firm has to tell clients that privileged papers are out of a third country’s reach. On a US cloud it cannot.
- Supplier terms and framework deals. A rebate structure negotiated over a decade should not sit on machines someone else can be ordered to open.
Europe pushes from the other side. Schrems II is the court ruling that makes you check every transfer of personal data out of the EU. Sending files to a US provider is that transfer, and your data protection officer has to defend it on paper.
The shortest way out
There are two honest ways to close the question.
The first is the legal route. Impact assessments, extra safeguards, encryption where you hold the keys, a review each time the case law moves. Serious companies do this. It costs money, never quite finishes, and the risk never reaches zero.
The second is to keep the documents inside your building. Files that never leave your premises never cross a border. There is nothing to assess, because there is no transfer.
That is the thinking behind Perimeter. A box in your server room. It reads your own documents and answers with the page the answer came from. It never talks to the internet. For some documents only one answer works: no one outside your walls.
Your IT lead can check how it is built. The security brief is written for that.