The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) is a US law, enacted in 2018, that addresses how US law enforcement obtains electronic data held by communications and cloud providers. It makes clear that a provider subject to US jurisdiction can be required, through proper US legal process, to disclose data in its possession, custody or control even when the data is stored outside the US. It also allows the US to make agreements with other countries so their authorities can request data directly from US providers in serious criminal cases. For buyers, it is the law behind many data sovereignty questions in contracts and security reviews. This entry is general information, not legal advice; confirm your position with counsel.
At a glance
- The CLOUD Act turns on the provider’s jurisdiction and control of the data, not only on where the data is stored.
- Requests still go through US legal process, such as warrants, court orders and subpoenas.
- Providers can challenge some orders that would conflict with the laws of a qualifying foreign country.
- The US has signed executive agreements with some countries for reciprocal access in serious crime investigations.
- Data residency and encryption choices can reduce, but do not necessarily eliminate, exposure.
What problem it solves
Before the CLOUD Act, it was unclear whether a US warrant could reach email or files a US provider stored on servers abroad. Courts disagreed, and a major case on the question was pending at the Supreme Court when Congress passed the law, which made that case moot. Meanwhile, foreign governments investigating crimes often had to go through slow treaty processes to get data held by US companies.
The CLOUD Act settled both issues from the US side: US process can reach data a provider controls wherever it sits, and approved foreign partners get a faster route. For businesses, it means the provider’s nationality and corporate structure, not just the cloud region, shape who can compel access to data.
How it works
US orders. Investigators obtain a warrant, subpoena or court order under existing US law. The provider must disclose data within its possession, custody or control, wherever it is stored.
Challenges. For content data, a provider can move to modify or quash an order when the customer is not a US person and does not reside in the US, and disclosure would risk violating the law of a country with a qualifying agreement. A court weighs the interests involved.
Executive agreements. The US can sign agreements with countries that meet privacy and civil liberties standards. Their authorities can then request data directly from US providers in serious crime cases, within set limits. The Justice Department lists signed agreements with the United Kingdom and Australia.
Provider practices. Many large providers publish how they respond to government requests, including whether they notify customers and challenge overbroad requests.
Legal routes for cross-border data requests
The CLOUD Act has no levels. Its closest structure is the set of routes by which governments obtain data held by providers, summarized here in general terms.
| Route | When it applies | How it works | What a buyer can ask to see |
|---|---|---|---|
| US legal process | US authorities seek data from a provider subject to US jurisdiction | Warrant, subpoena or court order under US law, wherever the data is stored | The provider’s law enforcement request policy and transparency report |
| Motion to modify or quash | An order for a non-US person’s content data conflicts with a qualifying country’s law | Provider asks a US court to weigh the conflict | Whether the provider commits to challenge such orders |
| Executive agreement | A partner country’s authorities investigate serious crime | Direct request to a US provider under the agreement’s limits | Which agreements apply to your data’s jurisdictions |
| Mutual legal assistance treaty | Countries without an agreement, or cases outside one | Government-to-government request through treaty channels | Generally handled between governments, not providers |
When it matters for buyers
- When customers or regulators outside the US ask about data sovereignty. They may ask whether US authorities can reach their data.
- When choosing between US-based and local providers. Jurisdiction can matter as much as data location.
- When negotiating data processing terms. Clauses on government requests, notification and challenge are worth reviewing.
- When handling personal data under GDPR or similar laws. Transfer assessments often consider the CLOUD Act.
- When deciding who holds encryption keys. Customer-held keys can limit what a provider can produce.
Our public cloud overview covers how providers structure regions, sovereign offerings and key management.
Questions to ask vendors
- Which legal entities operate the service we would buy, and which countries’ laws apply to them?
- Where is our data stored and processed, including backups, logs and support access?
- How do you respond to government requests for customer data, and will you notify us where the law allows?
- Do you commit to challenging requests you consider overbroad or in conflict with local law?
- Can we hold our own encryption keys, and can your staff access our data in readable form?
- Do you publish a transparency report on government requests?
How it differs from data residency
Data residency is about where data is physically stored and processed. The CLOUD Act is about which government can compel a provider to hand data over, which depends on the provider’s jurisdiction and control of the data. Data stored in one country can still be reachable under US process if a US-reachable provider controls it, so residency alone may not answer a sovereignty question. That tension is common in GDPR transfer assessments involving personally identifiable information (PII), and is part of broader data security compliance decisions in cloud computing.
