What is the CLOUD Act vs GDPR conflict, and how does it affect your business cloud in 2026?
The US CLOUD Act (2018) lets American courts demand any data held by US companies worldwide. The GDPR (2018) bars the transfer of EU personal data without equivalent protection. Both apply at once to Microsoft Azure, Google Workspace, and AWS - even for data hosted in Frankfurt or Dublin. The CJEU's Schrems II ruling (2020) confirmed the conflict is real and still open. The only clean exit is a cloud provider whose parent is not American.
The essentials
Both texts came into force in 2018, just weeks apart. Seven years on, the US CLOUD Act and the European GDPR still coexist with no formal way to reconcile them. Any European business that hosts its data with Microsoft, Google, AWS, Oracle, Salesforce or Apple faces both texts at once. One allows US access. The other bars it in practice. This clash has been known since 2018. The CNIL and the EDPB have documented it. It is still open in 2026.
For a director or Data Protection Officer in 2026, the question is no longer "are the CLOUD Act and GDPR in tension?" (yes, openly). The real question is: "what is my concrete risk if I keep using a US cloud for personal or sensitive data?" The answer depends on four things: the data category you process, the supervisory authority in charge, the strength of your Standard Contractual Clauses, and your ability to show that your extra safeguards really work.
This article maps the legal conflict in 2026. It covers the Schrems rulings, the real status of the Data Privacy Framework, and the credible cloud alternatives you can switch to. It does so without falling for the "sovereign cloud" marketing that blurs the jurisdictional question on purpose.
Where does the CLOUD Act × GDPR conflict originate?
The CLOUD Act came into force on 23 March 2018, signed by President Trump. Its stated aim was to settle the United States v. Microsoft case (the famous Dublin Email Warrant case). That case had pitted the Department of Justice against Microsoft since 2013. Microsoft had refused to hand over emails stored in Dublin under a US federal warrant. The Supreme Court was about to rule when Congress passed the law in a hurry to make the point clear: yes, a US warrant can reach data stored abroad by a US service provider.
The GDPR entered into force on 25 May 2018, two months later. Its Article 48 says that no court or administrative decision from a third country can justify a personal data transfer. The only exception is a transfer based on an international agreement in force (such as MLAT). The CLOUD Act rests on no such agreement. It claims extraterritorial reach on its own.
So the clash is stark: two fundamental laws, two opposing extraterritorial reaches, no resolution mechanism. As early as 2018, lawyers called this an open "conflict of laws". In such a case, the company that receives the request must choose which of the two laws to break, and accept the criminal or administrative risk that follows.
What the CLOUD Act technically authorises
The CLOUD Act gives US judicial authority two powers:
- Extended subpoena - it can require the production of data held, controlled or maintained by an electronic communication service provider, wherever it is stored worldwide, as long as the provider is under US jurisdiction (headquarters, significant subsidiary, operational presence).
- Bilateral executive agreements - they let a qualifying foreign country ask a US operator directly for the data of one of its citizens, without going through MLAT, once an inter-governmental agreement is in place. The United Kingdom signed such an agreement in 2019, Australia in 2021. The European Union has not signed.
The second power is worth a look. In theory, it would let a European state recover its own data through a US-EU executive agreement. But this agreement has never been concluded. The reason is plain: it would accept that normal sovereignty is turned upside down.
What did Schrems II decide - and why did Privacy Shield collapse?
On 16 July 2020, the Court of Justice of the European Union issued ruling C-311/18 (Schrems II). It is one of the most far-reaching decisions in European digital law of the past decade. It carries three key lessons:
- The Privacy Shield is struck down. This mechanism was negotiated in 2016 to enable EU-US transfers after Safe Harbor was struck down in 2015. The court found it did not protect enough against US surveillance programmes (notably FISA 702 and Executive Order 12333).
- Standard Contractual Clauses (SCCs) stay valid in principle. But they do not suffice on their own for transfers to the US. The exporter must check, case by case, whether the destination country's law offers essentially equal protection. It must then add supplementary measures (encryption, pseudonymisation, stronger contractual guarantees).
- National supervisory authorities (CNIL, DPC, ICO after Brexit) must step in if they find a transfer fails to comply with GDPR. They cannot hide behind a Commission adequacy decision.
This ruling forced the whole industry to rework its contracts with US clouds. In practice, most businesses kept using AWS, Microsoft 365 and Google Workspace. They relied on the new SCCs of June 2021 and on one-sided promises from the hyperscalers ("transparency reports", server-side encryption, oversight on requests). But the CNIL stated, in its 10 February 2022 deliberation on Google Analytics, that these guarantees are not enough for European personal data.
GDPR fines after Schrems II
A few concrete examples to measure real risk:
- 2022, CNIL vs French site operator using Google Analytics: data transfer to Google LLC (US) without sufficient guarantees, public formal notice, obligation to cease use.
- 2022, Austrian authority (DSB): similar decision, Google Analytics deemed incompatible with GDPR for US transfers.
- 2023, Irish DPC vs Meta: record fine of 1.2 billion euros for massive transfer of user data to Meta US without sufficient legal basis.
- 2024, CNIL vs several French SMEs: fines of 50,000 to 200,000 euros for use of Zoom and Microsoft Teams not configured in EU-only mode on sensitive data.
The rule is clear in 2026: the more sensitive the data (health, HR, identifiers, private communications), the more concrete the GDPR risk of using a US cloud. For non-personal operational data (technical logs, aggregated metrics), the risk stays theoretical.
The July 2023 Data Privacy Framework: fragile promise
The Data Privacy Framework (DPF) replaced Privacy Shield in July 2023, after three years of talks between Brussels and Washington. It adds two new safeguards:
- A Civil Liberties Protection Officer within the Office of the Director of National Intelligence. This officer reviews whether intelligence programmes that target EU citizens are proportionate.
- A Data Protection Review Court, independent in theory, with the power to fix problems. Any EU citizen who believes a US surveillance programme targets them can bring a case to it.
On paper, this is progress. In practice, Max Schrems and his NGO noyb filed an appeal with the CJEU in September 2023. They argue that the "Data Protection Review Court" is not a true independent tribunal in the European sense (judges named by the executive, closed hearings, decisions with no public reasons, no right of appeal). The Schrems III ruling is expected by late 2026 or 2027.
Most specialised lawyers predict the CJEU will strike down the DPF. If it does, EU-US transfers break in law again. Every business that relies on the DPF then falls into GDPR violation, after the fact. So the legal continuity risk on US clouds is not only about rules. It is also about timing.
Map of credible alternatives in 2026
A European business that wants out of the CLOUD Act × GDPR conflict has three families of alternatives. None is perfect. But each one removes at least the US extraterritorial reach.
Family 1: European infrastructure cloud
For compute, storage, serverless, managed databases, credible European actors in 2026 are:
| Provider | Country | SIGINT status | Advantage | Limitation |
|---|---|---|---|---|
| OVHcloud | France | 9 Eyes | Full catalogue, many certifications | French Intelligence Law applies |
| Scaleway | France | 9 Eyes | Excellent price/perf ratio, dev ecosystem | Smaller catalogue, same legal framework |
| Hetzner | Germany | 14 Eyes | Unbeatable pricing, solid infra | German BND-Gesetz applies |
| IONOS | Germany | 14 Eyes | MS compatibility, good for SMBs | Limited catalogue outside classical EU |
| Infomaniak | Switzerland | Outside 14 Eyes | Protective LRens jurisdiction | Limited catalogue, higher prices |
| Exoscale | Switzerland | Outside 14 Eyes | More tech-friendly than Infomaniak | Fewer managed services |
In this segment, Switzerland stays the most protective option on jurisdiction, but its catalogue is narrow. For heavy compute at the best price, Hetzner or OVH stay competitive, with a jurisdictional risk you can manage (14 Eyes framework, but strict GDPR).
Family 2: Collaboration and productivity
To replace Microsoft 365 and Google Workspace:
- Proton Business (Switzerland) - Mail, Drive, Calendar, VPN. Zero-knowledge by construction. IMAP/SMTP compatible via Bridge. The most mature in 2026. See our Proton Drive review for the storage side.
- Tresorit Business (Switzerland) - Drive + collaboration + e-signature. Ernst & Young audit. Higher enterprise pricing. Full breakdown in our Tresorit review.
- Infomaniak kSuite Pro (Switzerland) - Mail, Drive, Meet, Calendar. Good price/quality ratio but less audited than Proton.
- Nextcloud Hub (Germany, self-hosted or via partner SaaS) - Open source, full control possible if self-hosted, more usage friction.
Family 3: Specialised privacy cloud for cold storage
For encrypted archiving or long-term sensitive storage, outside the daily collaborative flow:
- pCloud Business (Switzerland) - Affordable lifetime, Crypto add-on for zero-knowledge. See our pCloud 2026 review.
- Filen Business (Germany) - Open source, AES-256, aggressive pricing. Younger than Proton/Tresorit.
- Icedrive Business (UK) - Convenient but 5 Eyes jurisdiction - avoid for sensitive data.
The "sovereign cloud" marketing trap
Since 2022, several European and North American actors have sold offers labelled "sovereign" or "EU-only". Three typical cases deserve a careful read:
- Microsoft Cloud for Sovereignty - announced in 2022, deployed via partners in France, Germany and Spain. It does not remove the CLOUD Act. Microsoft Corporation stays bound by US law, and a partner operator cannot refuse a transfer asked for by the parent company. The marketing talks about "isolation". The legal reality stays that of a subsidiary of a US company.
- Bleu (Capgemini × Orange × Microsoft) and S3NS (Thales × Google Cloud) - Franco-American joint ventures that run Microsoft Azure and Google Cloud technologies on infrastructure operated by French staff. They carry the SecNumCloud label issued by ANSSI, which includes an immunity requirement from extra-European laws. On paper, the question is solved. In practice, source code and updates still come from Redmond and Mountain View. Full operational autonomy is not shown in public.
- AWS European Sovereign Cloud - announced late 2023, first live region in Germany late 2025. Staff are European only and support is European, but AWS Inc. stays the legal owner. In theory, the DOJ can subpoena AWS Inc. for European Sovereign Cloud data.
The only way to truly escape the CLOUD Act is to use an operator whose parent company is not American and has no significant US entity. OVH, Scaleway, Hetzner, Infomaniak, Proton, Tresorit and Mailfence meet this condition. The "sovereign" offers from US hyperscalers do not.
Our 2026 decision matrix
For a European SMB or mid-cap in 2026, here is the simple framework to apply.
Non-personal operational data (technical logs, metrics, non-sensitive source code): AWS, Azure, GCP remain defensible, GDPR risk is low. Economic bonus if you are already committed.
Personal customer and employee data (CRM, HR, communications, customer support): leave US hyperscalers. Choose a European infrastructure cloud (OVH, Scaleway, Hetzner) plus a non-US collaborative suite (Proton, Infomaniak, Tresorit). The switching cost is real, but so is the GDPR risk.
Sensitive data, health data, strategic R&D: Swiss jurisdiction mandatory + client-side zero-knowledge encryption + native clients (no dynamic web app). See E2E vs zero-knowledge cloud storage for the technical grid.
Journalistic data, whistleblowers, activists: Switzerland + Tor + protected identity + redundant backups across two different non-14-Eyes jurisdictions. See 5/9/14 Eyes and your cloud privacy for the 2026 world map.
Further reading
- Best encrypted cloud storage services 2026 - full provider comparison - which services avoid the CLOUD Act × GDPR conflict by design
- 5/9/14 Eyes and your cloud privacy - the 2026 world map
- E2E vs zero-knowledge cloud storage - the cryptographic grid
- Proton Drive vs Tresorit vs pCloud - Swiss comparator 2026
- pCloud 2026 review - 8 months lifetime + Crypto test
- Encrypted cloud quiz - find in 60 seconds the CLOUD Act-free provider that fits your profile
- Priviy methodology - how we score jurisdiction × crypto × audit
- Wikidata Priviy Q140050544
- Primary sources: CJEU ruling C-311/18 (Schrems II); CLOUD Act 18 U.S.C. § 2713; EU Regulation 2016/679 (GDPR) art. 44-50; CNIL deliberation 10 February 2022 on Google Analytics
Article published 5 June 2026. Methodology: reading of primary texts (CLOUD Act, GDPR art. 44-50, rulings C-362/14 Schrems I and C-311/18 Schrems II), review of CNIL and DPC deliberations 2020-2025, consultation of EDPB recommendations 01/2020 on supplementary measures post-Schrems II, and cross-checking with 2024 transparency reports of hyperscalers and European actors. No claim to confidential proprietary sources.
Related guides
To dig deeper, see what data sovereignty means.
Frequently asked questions
- What is the conflict between the US CLOUD Act and GDPR - and which one wins?
- The CLOUD Act (2018) lets US courts force American companies to hand over data stored anywhere in the world. GDPR (2018) bans the transfer of EU personal data to countries without adequate protection. Both apply at once to Microsoft, Google, and AWS. Neither gives way. Schrems II (CJEU 2020) struck down Privacy Shield over this exact conflict. In 2026, no legal fix exists. The only escape is to use a provider whose parent company is not American.
- Does the CLOUD Act really apply to a Microsoft cloud hosted in Frankfurt?
- Yes. The Clarifying Lawful Overseas Use of Data Act of 2018 targets electronic communication service providers under US jurisdiction. The place where data is stored does not matter. Microsoft Corporation is a US parent company. A US federal warrant can force it to deliver its European customers' data hosted in Frankfurt, Amsterdam or Dublin. The European subsidiary does not build a watertight wall. Effective control still flows back to the Redmond headquarters.
- Doesn't GDPR protect against this extraterritoriality?
- In principle, GDPR bans the transfer of personal data to a third country without equivalent guarantees (Article 44). The Schrems II ruling (CJEU, 16 July 2020) struck down the Privacy Shield. The reason: US law allows intelligence access (FISA 702, EO 12333) that GDPR cannot accept. But in practice, businesses keep using AWS and Microsoft 365 under Standard Contractual Clauses (SCCs) and extra commitments. It is a grey zone the CJEU has not tested since 2020.
- Does the Data Privacy Framework (2023) settle the issue?
- Only in part, and only for now. The DPF replaced Privacy Shield in July 2023 with stronger guardrails (Civil Liberties Protection Officer, Data Protection Review Court). Max Schrems and NOYB filed an appeal with the CJEU in September 2023. They consider the DPF too weak. Schrems III is expected by 2026-2027. If the court strikes it down, EU-US transfers break in law again. In 2026, the DPF holds, but informed businesses no longer treat it as a long-term plan.
- Concretely, does my business risk a GDPR fine if I stay on AWS?
- The risk depends on the data category and on which supervisory authority has jurisdiction. The French CNIL and the Irish DPC have fined European businesses under GDPR for using Google Analytics (CNIL 2022, several hundred thousand euros) or Meta (DPC 2023, 1.2 billion euros). For corporate cloud, case law is rarer but it exists. A US cloud used for health data, HR data or sensitive customer records exposes you to fines up to 4% of global turnover. For non-sensitive operational data, the risk is low but not nil.
- What are the credible alternatives to AWS / Azure / Google Cloud in 2026?
- There are three families of alternatives. (1) European sovereign infrastructure cloud - OVHcloud (France), Scaleway (France), Hetzner (Germany), IONOS (Germany). These actors are GDPR-bound and CLOUD Act-free, but they sit in 9 or 14 Eyes territory. (2) Swiss cloud - Infomaniak, Exoscale, Proton Business - outside the EU and outside 14 Eyes, with protective LRens jurisdiction. (3) Specialised privacy cloud for collaboration and storage - Tresorit Business, Proton Drive Business, pCloud Business - zero-knowledge by design. The choice depends on the use case. Heavy compute = OVH or Hetzner. Sensitive document work = Tresorit or Proton.
- What about the Gaia-X / EUCS project? Does it change anything?
- Gaia-X is a European cloud federation initiative launched in 2020 with sovereign goals. In 2026, industrial take-up stays limited. The EUCS (European Cybersecurity Certification Scheme) label still has not settled the question of immunity from extra-European laws. France and Germany have been at odds on this point since 2023. The US-cloud industry lobbies to keep American hyperscalers eligible at the highest level. As long as this question stays open, Gaia-X brings no new jurisdictional guarantee. For now, it is better to pick an actor whose jurisdiction is clear (Swiss, German or French, depending on your case).
Store your files privately → pCloud
Swiss privacy · 10 GB free · optional zero-knowledge Crypto



