The CLOUD Act and European banks

The CLOUD Act, the Clarifying Lawful Overseas Use of Data Act, is a United States law signed on March 23, 2018. It lets US authorities compel providers subject to US jurisdiction to disclose data in their possession or control, whether that data sits on a server in the United States or in Frankfurt, as the Center for Strategic and International Studies explains.

For a European bank this turns a cloud contract into a question of jurisdiction. A data center in Germany settles where the data is. It does not settle which state can demand it, and BaFin and the ECB ask the bank to assess that risk before it signs.

Where the law came from

The trigger was a drug investigation in 2013. US authorities served Microsoft with a warrant for emails stored on servers in Ireland, and Microsoft refused, arguing that the Stored Communications Act did not reach data held abroad. Congress answered with the CLOUD Act, which amended that law, and the Supreme Court sent the case back as moot in April 2018, according to Wikipedia's account.

The Act also created executive agreements, a faster route than mutual legal assistance treaties, through which partner states can request data directly from providers in each other's countries. The first agreement, with the United Kingdom, entered into force on July 8, 2020. The EU Council authorized the Commission to negotiate an EU agreement in June 2019. One obstacle is Article 48 of the GDPR, under which a foreign court order alone does not make a transfer of personal data lawful unless it rests on an international agreement.

What it means for a bank's cloud contract

The BaFin notice on cloud outsourcing asks a bank to assess the laws of every jurisdiction involved, including the rules on law enforcement, and the location of the provider's head office. The ECB's guide on cloud outsourcing asks for a list of permitted countries that weighs legal and political risk. A US parent company is therefore a data point in the bank's risk assessment, even when every server is in the EU.

Microsoft France made the gap visible in June 2025. Asked under oath in a French Senate inquiry whether he could guarantee that French citizens' data would not reach US authorities without French consent, its director of public and legal affairs answered, as The Register reported: "No, I cannot guarantee that, but, again, it has never happened before." He added that Microsoft resists requests it considers unfounded.

Technical answers to the CLOUD Act

Encryption with keys the bank holds itself limits what a provider can hand over, since CSIS notes that the Act does not oblige providers to decrypt data. Confidential computing extends that protection to data while it is processed. Sovereign cloud offerings go further on the operator side and put operations and administrator access in an EU entity, which the page on sovereign cloud for banks examines clause by clause.

None of these measures removes the legal question for a provider with a US parent. They decide what the provider could produce if it received an order, and the bank's risk assessment has to describe that in writing.

Upcoming events on digital infrastructure

Does the CLOUD Act apply to data stored in the EU?

Yes, when the data is held by a provider subject to US jurisdiction that has possession or control of it. The location of the server does not decide the question, which is why a German data center run by a US-owned company is still in scope.

How does the CLOUD Act relate to the GDPR?

They pull in different directions. Article 48 GDPR recognizes a foreign court order as a basis for a transfer only where an international agreement exists, and the European Data Protection Board and the European Data Protection Supervisor described a possible conflict with the CLOUD Act in a joint response in 2019. A provider can challenge an order that conflicts with the law of a partner country, but that route exists only for countries with an executive agreement.

Is the CLOUD Act the same as the Patriot Act?

No. The Patriot Act of 2001 expanded surveillance powers after the September 11 attacks. The CLOUD Act of 2018 amended the Stored Communications Act to settle whether US warrants reach data stored abroad, and added the executive agreements with partner states.

The CLOUD Act and Finance Loop

Finance Loop brings the data protection officers and cloud architects of European banks together with the providers they buy from, in its Digital Infrastructure & Sovereignty track. Finance Loop gives a law firm or provider with an answer to the jurisdiction question a place to present it to banks through a sponsored webinar, and membership connects the people who negotiate these clauses.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.