What Is CLOUD Act (Clarifying Lawful Overseas Use of Data Act)?

Related problems: A European customer asks whether US authorities can access their data in our cloud; Not sure whether keeping data in an overseas region protects it from US legal demands; Need to answer data sovereignty questions in security reviews and contracts

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) is a US law, enacted in 2018, that addresses how US law enforcement obtains electronic data held by communications and cloud providers. It makes clear that a provider subject to US jurisdiction can be required, through proper US legal process, to disclose data in its possession, custody or control even when the data is stored outside the US. It also allows the US to make agreements with other countries so their authorities can request data directly from US providers in serious criminal cases. For buyers, it is the law behind many data sovereignty questions in contracts and security reviews. This entry is general information, not legal advice; confirm your position with counsel.

At a glance

  • The CLOUD Act turns on the provider’s jurisdiction and control of the data, not only on where the data is stored.
  • Requests still go through US legal process, such as warrants, court orders and subpoenas.
  • Providers can challenge some orders that would conflict with the laws of a qualifying foreign country.
  • The US has signed executive agreements with some countries for reciprocal access in serious crime investigations.
  • Data residency and encryption choices can reduce, but do not necessarily eliminate, exposure.

What problem it solves

Before the CLOUD Act, it was unclear whether a US warrant could reach email or files a US provider stored on servers abroad. Courts disagreed, and a major case on the question was pending at the Supreme Court when Congress passed the law, which made that case moot. Meanwhile, foreign governments investigating crimes often had to go through slow treaty processes to get data held by US companies.

The CLOUD Act settled both issues from the US side: US process can reach data a provider controls wherever it sits, and approved foreign partners get a faster route. For businesses, it means the provider’s nationality and corporate structure, not just the cloud region, shape who can compel access to data.

How it works

US orders. Investigators obtain a warrant, subpoena or court order under existing US law. The provider must disclose data within its possession, custody or control, wherever it is stored.

Challenges. For content data, a provider can move to modify or quash an order when the customer is not a US person and does not reside in the US, and disclosure would risk violating the law of a country with a qualifying agreement. A court weighs the interests involved.

Executive agreements. The US can sign agreements with countries that meet privacy and civil liberties standards. Their authorities can then request data directly from US providers in serious crime cases, within set limits. The Justice Department lists signed agreements with the United Kingdom and Australia.

Provider practices. Many large providers publish how they respond to government requests, including whether they notify customers and challenge overbroad requests.

The CLOUD Act has no levels. Its closest structure is the set of routes by which governments obtain data held by providers, summarized here in general terms.

Route When it applies How it works What a buyer can ask to see
US legal process US authorities seek data from a provider subject to US jurisdiction Warrant, subpoena or court order under US law, wherever the data is stored The provider’s law enforcement request policy and transparency report
Motion to modify or quash An order for a non-US person’s content data conflicts with a qualifying country’s law Provider asks a US court to weigh the conflict Whether the provider commits to challenge such orders
Executive agreement A partner country’s authorities investigate serious crime Direct request to a US provider under the agreement’s limits Which agreements apply to your data’s jurisdictions
Mutual legal assistance treaty Countries without an agreement, or cases outside one Government-to-government request through treaty channels Generally handled between governments, not providers

When it matters for buyers

  • When customers or regulators outside the US ask about data sovereignty. They may ask whether US authorities can reach their data.
  • When choosing between US-based and local providers. Jurisdiction can matter as much as data location.
  • When negotiating data processing terms. Clauses on government requests, notification and challenge are worth reviewing.
  • When handling personal data under GDPR or similar laws. Transfer assessments often consider the CLOUD Act.
  • When deciding who holds encryption keys. Customer-held keys can limit what a provider can produce.

Our public cloud overview covers how providers structure regions, sovereign offerings and key management.

Questions to ask vendors

  • Which legal entities operate the service we would buy, and which countries’ laws apply to them?
  • Where is our data stored and processed, including backups, logs and support access?
  • How do you respond to government requests for customer data, and will you notify us where the law allows?
  • Do you commit to challenging requests you consider overbroad or in conflict with local law?
  • Can we hold our own encryption keys, and can your staff access our data in readable form?
  • Do you publish a transparency report on government requests?

How it differs from data residency

Data residency is about where data is physically stored and processed. The CLOUD Act is about which government can compel a provider to hand data over, which depends on the provider’s jurisdiction and control of the data. Data stored in one country can still be reachable under US process if a US-reachable provider controls it, so residency alone may not answer a sovereignty question. That tension is common in GDPR transfer assessments involving personally identifiable information (PII), and is part of broader data security compliance decisions in cloud computing.

Frequently Asked Questions

Does storing data outside the US protect it from the CLOUD Act?
Not necessarily. The law is about whether the provider is subject to US jurisdiction and has possession, custody or control of the data, not only where the data sits. A provider within US jurisdiction may be required to disclose data stored abroad, subject to legal process and challenges.
Does the CLOUD Act let US authorities skip legal process?
No. It works through existing US legal process, such as warrants, court orders and subpoenas, depending on the type of data sought. It changed where that process can reach, not the need for it.
Can a provider challenge a CLOUD Act request?
In some cases. A provider can ask a court to modify or quash an order for content data about a non-US person when disclosure would risk violating the law of a country that has a qualifying agreement with the US. Courts weigh the competing interests.
Does the CLOUD Act conflict with GDPR?
It can create tension. A provider could face a US order and EU restrictions on transferring personal data at the same time. How that tension is handled depends on the facts, agreements between governments and the provider's approach, so ask counsel and the provider.
What can we do to reduce exposure?
Common measures include choosing providers based on jurisdiction, encrypting data with keys you control, reviewing how a provider handles government requests and reading its transparency reports. None removes legal risk entirely, so treat them as part of a broader assessment.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.