Most “EU data” guarantees rest on a quiet assumption: that data in a European data centre is beyond the reach of foreign authorities. For data handled by a US-owned company, that assumption is wrong, and it is worth understanding precisely why.
What the CLOUD Act says
The CLOUD Act, signed into US law in 2018, added 18 U.S.C. § 2713 to the Stored Communications Act. It requires a provider to disclose data in its “possession, custody, or control”, in the statute’s own words, “regardless of whether” that data “is located within or outside of the United States.” Physical location, by design, is not the deciding factor.
It follows the company, not the server
The obligation binds any provider subject to US jurisdiction: companies incorporated in the US, and foreign companies with meaningful US operations. US courts read “control” broadly, the practical ability or legal right to obtain data is enough. A US parent that can instruct its European subsidiary to produce data is treated as controlling it, even if the data never physically leaves Europe.
A contract cannot override a statute
Data-residency clauses, standard contractual clauses and “sovereign cloud” programmes are private agreements. They limit which staff touch data day to day; they do not remove the legal duty to comply with a valid US order. The EU’s own regulators, the EDPB and EDPS, concluded that such contracts have no force against US judicial or administrative demands.
Asked under oath before the French Senate in June 2025 whether it could guarantee that French data would never be passed to US authorities, Microsoft answered plainly that it could not.
What removes the exposure
The exposure disappears only when no US-jurisdiction company is anywhere in the path. That is the design principle behind our products: hosted on our sovereign cloud in the Netherlands and Germany, or entirely on your own infrastructure, built on Mistral and local models, with no US provider that can be compelled.