Skip to main content

Guide

The CLOUD Act Explained — What UK Businesses Need to Know

The US CLOUD Act gives American authorities legal access to your data — even if it sits in a London data centre. If you use Microsoft, Google, or Amazon for anything, this guide explains exactly what that means and what your options are.

By Ben Gray · 10 April 2026 · 15 min read

What Is the CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act was signed into US law on 23 March 2018. It amends the Stored Communications Act (1986) to explicitly state that US law enforcement can compel US-headquartered companies to provide data stored anywhere in the world.

Before the CLOUD Act, there was legal ambiguity about whether a US warrant could reach data stored outside the US. The landmark Microsoft Corp. v. United States case (2018) — where Microsoft refused to hand over emails stored in Ireland — was heading to the Supreme Court when Congress passed the CLOUD Act, rendering the case moot.

The Act resolved the ambiguity in the government's favour: if a company is incorporated in the US or has sufficient contacts with the US, a valid legal process (warrant, subpoena, or court order) can compel disclosure of data regardless of where it is stored.

Who Is Affected?

The CLOUD Act applies to any company that is:

  • Headquartered in the United States, or
  • Subject to US jurisdiction (has offices, employees, or significant business operations in the US)

This includes every major cloud and SaaS provider that UK businesses use:

CompanyProducts AffectedHQ
MicrosoftAzure, M365, Teams, Outlook, OneDrive, Copilot, GitHubRedmond, WA
GoogleGCP, Workspace, Gmail, Drive, Meet, GeminiMountain View, CA
AmazonAWS (EC2, S3, RDS, Lambda, etc.)Seattle, WA
AppleiCloud, iMessage, Apple BusinessCupertino, CA
MetaWhatsApp Business, WorkplaceMenlo Park, CA
SalesforceCRM, Slack, TableauSan Francisco, CA
OracleOCI, NetSuite, MySQL HeatWaveAustin, TX
OpenAIChatGPT, GPT API, DALL-ESan Francisco, CA

The GDPR Conflict

GDPR Article 48 states that court orders from third countries (including the US) are not, by themselves, a legal basis for transferring personal data. A US CLOUD Act warrant is exactly this — a third-country court order demanding data transfer.

This creates an irreconcilable conflict. US providers must comply with CLOUD Act requests (or face contempt of court). But doing so may violate GDPR (penalties up to 4% of global turnover or €20 million).

The European Data Protection Board (EDPB) has been clear: CLOUD Act compliance does not constitute a lawful basis for data transfer under GDPR. Providers caught between the two regimes face legal jeopardy on both sides of the Atlantic.

The Schrems II connection

The CJEU's Schrems II ruling (2020) invalidated the EU-US Privacy Shield partly because US surveillance law (including the CLOUD Act) does not provide adequate protection for EU citizens' data. The current EU-US Data Privacy Framework (2023) is already under legal challenge and may face a similar fate.

The EU Data Centre Myth

Microsoft's “EU Data Boundary” and Google's “EU data residency” options are frequently cited as solutions. They are not.

The CLOUD Act does not care where the data is physically stored. It cares who controls it. If the company controlling the data is subject to US jurisdiction, the data is reachable — regardless of which continent the server sits on.

Microsoft storing your email in a Dublin data centre does not prevent the US Department of Justice from obtaining a warrant for that email. Microsoft is a US company. The warrant follows the company, not the server.

What Data Can Be Accessed?

A CLOUD Act warrant can compel disclosure of:

  • Email content and attachments
  • Files stored in cloud services (OneDrive, Google Drive, S3)
  • Chat messages (Teams, Slack, WhatsApp Business)
  • Database contents (RDS, Cloud SQL, Cosmos DB)
  • AI prompts and responses (ChatGPT, Copilot, Gemini)
  • Authentication logs and metadata
  • Backup data
  • Any data the provider can technically access

End-to-end encryption?

If you hold the encryption keys and the provider cannot decrypt the data, a CLOUD Act warrant cannot compel disclosure of readable content — the provider can only hand over encrypted data. This is why Bring Your Own Keys (BYOK) and self-hosted encryption matter. But note: most cloud services do not offer true BYOK where the provider has zero access to keys.

Sector-Specific Implications

Healthcare (NHS)

Patient data on Microsoft or Google infrastructure is accessible under the CLOUD Act. This creates a tension with the Caldicott principles, the common law duty of confidentiality, and DSPT requirements. The NHS DSPT V8 does not explicitly address CLOUD Act risk, but Standards 8-10 (data security) are harder to evidence when your data is subject to foreign government access.

Legal (SRA-regulated firms)

Legal professional privilege (LPP) is a fundamental right. Client communications stored on US-controlled infrastructure are technically accessible to US authorities. While a US court might recognise foreign privilege claims, there is no guarantee — and the SRA expects firms to take reasonable steps to protect client confidentiality.

Financial Services (FCA/PRA)

DORA requires financial entities to manage ICT third-party concentration risk. Relying on US cloud providers for critical functions creates both concentration risk and jurisdictional risk. The FCA's operational resilience framework expects firms to understand and mitigate these exposures.

What to Do About It

1. Audit your current exposure

List every service you use. For each one, determine whether the provider is subject to US jurisdiction. Our Sovereignty Score tool does this in 3 minutes.

2. Classify your data by sensitivity

Not all data carries the same risk. Marketing materials on Google Drive are different from patient records on Azure. Focus migration effort on the highest-sensitivity data first.

3. Move sensitive data to non-US infrastructure

Self-hosted or EU-headquartered providers are outside CLOUD Act jurisdiction. Nextcloud replaces OneDrive. Stalwart replaces Exchange. Mattermost replaces Teams. Jitsi replaces Zoom. These are not compromises — they are feature-equivalent alternatives with better jurisdiction.

When self-hosted, these tools give you full data sovereignty. Nextcloud (Nextcloud GmbH, Germany), Stalwart (Stalwart Labs Ltd, UK), and the underlying open-source projects are maintained independently of US jurisdiction. Because Genitco hosts these on EU infrastructure that we operate, your data has no US nexus — there is no US incorporated company in the chain that can receive a CLOUD Act warrant.

4. Implement BYOK encryption

If you must use US providers for some services, ensure you hold the encryption keys. True BYOK (where the provider cannot decrypt your data) limits what can be disclosed under a CLOUD Act warrant to encrypted, unreadable data.

5. Document your risk assessment

UK GDPR requires data controllers to conduct transfer impact assessments (TIAs) for data processed by US providers. Document your assessment, your mitigations, and your rationale. If the ICO asks, you need to show you considered the risk.

How exposed is your organisation?

Take our free Sovereignty Score assessment to see exactly where your data sits and what a foreign government could reach.

Global infrastructure·Your data, never ours·AI and infrastructure you control·GDPR by design