Independent comparison · no paid rankings
Home / Blog / Cloud Act: what it really changes for a European website
Guide

Cloud Act: what it really changes for a European website

Hosted in Germany at a US subsidiary: the Cloud Act lets US authorities request certain data. Understand legal risk — and what EU hosts and encryption do or do not change.

4 min read Updated Jul 19, 2026

Paris law firm: client data on AWS Paris region. DPO question: "Does Cloud Act still apply?" Short answer: potentially yes — because the provider is subject to US law, not because the disk is in Paris.

The CLOUD Act (2018) lets US authorities requisition certain data held by cloud providers under US jurisdiction — including stored abroad. For a European site, the stake is not general panic: map who can be compelled, on what, and whether your data allows it.

What Cloud Act changes — concretely

The law targets US providers and entities they control — not every host with an EU datacenter. An order may target the content itself: emails, files, metadata depending on the case. It may also create a conflict of laws between a US order and EU blocking, while transparency stays limited: gag orders sometimes prevent the provider from notifying the client.

SetupTypical Cloud Act exposure
AWS / Azure / GCP EU regionYes (US entity)
OVHcloud / Infomaniak / Hetzner (EU)Not US CLOUD Act; other frameworks possible
US CDN proxies all trafficAnalyze processing, logs
Encryption, client keys onlyReduces exploitable data

An EU datacenter does not exclude US reach if the contract is signed with a US-subject entity.

Questions to ask before signing

Before validating a contract, clarify the legal identity of the contracting party: is it a US company or a European subsidiary? Map subprocessors — backups, support, monitoring — that may sit in the United States. Verify location of production, backup copies, and logs, as our investigation on real location describes. Request notification clauses in case of a government order, when the law allows. Finally, specify encryption: who holds the keys, is there a client KMS, and does your project require SecNumCloud or reinforced sovereignty? See SecNumCloud criteria for that last point.

Compare directory profiles: OVHcloud, Scaleway, and Infomaniak document sovereignty positioning differently from AWS Paris region.

Proportional mitigations

For low-sensitivity brochure-site data, a European host with a solid DPA often suffices; Cloud Act weighs little in practice. For sensitive data, defense secrets, or certain health data, avoid the US chain, consider SecNumCloud or HDS under the French framework, encrypt with client keys, and have legal review the contract. For a US CDN or SaaS, map processing; anonymization or EU-only routing can sometimes reduce exposure.

Cross-check GDPR: choosing a host and Cloud Act and contract.

What Cloud Act does not do

The law does not let anyone read your data: a US procedure is required. It does not replace your GDPR compliance as controller. It does not make illegal using AWS in an EU region — it requires risk analysis and documented guarantees. For most brochure sites, the practical risk stays low; for regulated or sensitive workloads, the analysis becomes part of your compliance file.

The peak: cloud region reassures — contract jurisdiction binds

For public sites, real risk varies with data sensitivity. For critical data, illusion becomes liability.

Decide and move forward without blind spots

Identify the contracting entity and parent company first, then map backups, CDN, and third-party support. Assess data sensitivity and sector obligations that apply to your activity. Choose a European host or encryption and key-holding guarantees if a US provider remains unavoidable. Finally, document your transfer risk analysis, as the guide Transfers outside the EU reminds.

Consult the comparator and sovereign cloud investigation to refine your shortlist.

Frequently asked questions

Does Cloud Act apply if my data is in France?

Yes, it is possible if the provider is subject to US law. Disk location alone does not always exclude an order targeting data stored in the European Union.

Does a pure European host avoid Cloud Act?

It reduces US-linked risk, provided there is no US parent company and no US-subject subprocessor. Read the contract, not just the marketing.

Does encryption protect from Cloud Act?

Encryption with keys held only by you limits exploitable access. Keys hosted at a US provider remain exposed.

SecNumCloud frames reinforced hosting against extraterritorial access for certain sensitive workloads. It is not automatic for every website.


Cloud Act for a European website: not "US banned" — it is knowing who, legally, can receive an order on your data, wherever it sleeps.

Compare European hosts

Filter by compliance, location and use case — then open the sheets to verify the real scope.

Browse the directory
Blog

Related reading

All articles →