All articles

The CLOUD Act explained: what “data in Europe” does and doesn’t mean

Published on

Almost every SaaS vendor now puts “data in Europe” on its website. Calio included. It is a fair selling point, but it does not answer the question underneath it: can a US authority reach my data? To know that, you need to know what the CLOUD Act actually turns on — and it is not where the disk sits.

What the CLOUD Act is

In March 2018 the US Congress passed the Clarifying Lawful Overseas Use of Data Act, attached to a spending bill. The trigger was a court case. US law enforcement demanded emails from Microsoft that were stored on a server in Dublin. Microsoft refused: that data is in Ireland, go to an Irish court. The case was before the Supreme Court when the new statute took the question away.

The heart of it is a single sentence added to the Stored Communications Act. A provider must preserve and disclose data in its possession, custody, or control — regardless of whether that data is located inside or outside the United States.

Note what it does not say. It says nothing about where the server is. The hook is the provider: if it falls under US jurisdiction, a US order can reach it, and then the order covers whatever data it controls, anywhere in the world.

Why “data centre in Amsterdam” doesn’t answer the question

A data centre in Amsterdam tells you something about latency, about energy, and about the GDPR question of whether data leaves the EEA. About the CLOUD Act it tells you very little. The question that matters there is: which legal entity operates that machine, and what law is it subject to?

So a Dutch supplier running on American cloud infrastructure — even infrastructure located in the EU — has not removed that question. It has moved it to its subcontractor. That is not cause for panic. It is cause for writing down, precisely, who is in the chain.

The bind: Article 48 GDPR

For a supplier served with such an order, a problem arises that it cannot solve on its own. Article 48 GDPR provides that a judgment of a court or a decision of an authority in a third country is only recognisable or enforceable if it is based on an international agreement, such as a mutual legal assistance treaty.

The European supervisory authorities — the EDPB and the EDPS — spelled out what that means in their joint assessment of 10 July 2019. Without such a treaty, or another ground under the GDPR, a provider subject to EU law cannot base a transfer on a CLOUD Act request. Two things are needed rather than one: a legal basis for the processing (Article 6) and a valid ground for the transfer (Chapter V).

The result is a genuine bind. One legal order demands disclosure, the other forbids it. Anyone telling you this is settled is wrong.

What the CLOUD Act is not

Three misconceptions are stubborn enough to name separately.

It is not open access. Content of communications requires a warrant from a US judge, on probable cause. This is criminal procedure, not an open tap.

It is not the same as intelligence law. FISA section 702 and Executive Order 12333 concern intelligence gathering, have different thresholds, and were the reason the Court of Justice invalidated the Privacy Shield in Schrems II. That debate runs alongside the CLOUD Act, not through it.

And it is not something the Data Privacy Framework covers. That framework — adequacy decision of 10 July 2023, upheld by the General Court in the Latombe case on 3 September 2025, and since then under appeal at the Court of Justice — governs the conditions under which you may transfer data to the United States. It says nothing about the powers of US law enforcement over an American provider. (Position at time of publication, 2 August 2026.)

There is an escape route in the statute itself. A provider can move to quash an order where the customer is not a US person and does not reside in the US, and disclosure would create a material risk of violating the law of a qualifying foreign government. That last part means a country that has concluded an executive agreement with the United States. Those exist with the United Kingdom (signed 2019, in force since 2022) and Australia (signed 2021, in force since 2024). Negotiations with the EU have been running for years. For a Dutch customer that door is, in practice, still closed.

Four questions for your supplier

Enough theory. What can you do with this as a hairdresser, physiotherapist or consultant with a few hundred client records in a scheduling tool?

  1. Which legal entity stands behind the service, and where is it established? Not the brand and not the data centre: the entity you have a contract with.
  2. Who are the subprocessors, and which country are they from? This is the question that yields the most and gets asked the least. A supplier who has this in order has the list ready.
  3. Who holds the keys? “Stored encrypted” at a party that holds the key itself is no protection against an order served on that same party.
  4. What happens when a request comes in? Does the supplier push back? Are you notified, as far as that is allowed? Is there a transparency report?

If you get no answer to the second question, you know enough.

Where Calio stands

Then the question you are right to ask of an article hosted on a supplier’s own website: how does this work here?

Calio is a Dutch service with no establishment in the United States. A US order cannot be served on us directly. The application and the database run in a data centre in Amsterdam.

That is not the end of the story, and we would rather not dress it up. Our hosting provider and the party where our backups are stored are American companies with European entities and data centres. For delivering confirmation and reminder emails we use an American service that sends from Ireland. The language model behind the AI search helper runs at Mistral AI in France, and only ever receives the sentence a guest types in.

What that means: “EU data centre” makes the CLOUD Act question smaller here, not zero. That holds for nearly every European SaaS, and a supplier claiming otherwise has either not read the statute or is hoping you won’t. Exactly which parties these are and what they do is listed in our data processing agreement — deliberately boring and complete.

What we can promise is the only thing a supplier can honestly promise: that we write down who is in the chain, that we announce changes to it thirty days in advance, and that we don’t pretend a flag on a landing page settles a question of law.

In short

  • The CLOUD Act hooks onto the provider, not the location of the data. An EU data centre owned by an American company is squarely within its reach.
  • Article 48 GDPR forbids disclosure on a foreign order without a treaty basis. The supplier is caught between two legal orders.
  • The Data Privacy Framework and Schrems II address a different question: transfers and intelligence law, not criminal process.
  • The practical gain is not a flag on a website, but a supplier who can name their chain.

Frequently asked questions

Can US authorities reach my data if my supplier is Dutch?

Not directly: a US order can only be served on a provider subject to US jurisdiction. But if that Dutch supplier runs on infrastructure owned by an American company, the question moves to that subcontractor — because the CLOUD Act looks at who holds the data, not at the country the server sits in.

Is an EU data centre enough to comply with the GDPR?

It helps, but it is not the whole story. Storage location determines whether there is a transfer to a third country; Article 48 GDPR governs whether a foreign order may be acted on at all. Those are two separate questions.

What is the difference between the CLOUD Act and Schrems II?

The CLOUD Act concerns criminal process against providers: law enforcement demands data with a warrant. Schrems II was about intelligence law (FISA 702 and Executive Order 12333) and led to the Privacy Shield being invalidated. Different regimes with different thresholds — they are often lumped together.

What can a small business realistically do about this?

Ask your supplier which legal entity stands behind the service, which subprocessors are in the chain and where their parent companies are based, who holds the encryption keys, and what happens when a government request arrives. A supplier who cannot answer the second question has already told you something.

Sources

This article explains regulation in plain language and is not legal advice. For your own situation, consult a lawyer.

Scheduling, with your data in Europe

Booking link in 2 minutes, calendar connected, subprocessors written down. No credit card needed.

Start free