Paris law firm: client data on AWS Paris region. DPO question: "Does Cloud Act still apply?" Short answer: potentially yes — because the provider is subject to US law, not because the disk is in Paris.
The CLOUD Act (2018) lets US authorities requisition certain data held by cloud providers under US jurisdiction — including stored abroad. For a European site, the stake is not general panic: map who can be compelled, on what, and whether your data allows it.
What Cloud Act changes — concretely
The law targets US providers and entities they control — not every host with an EU datacenter. An order may target the content itself: emails, files, metadata depending on the case. It may also create a conflict of laws between a US order and EU blocking, while transparency stays limited: gag orders sometimes prevent the provider from notifying the client.
| Setup | Typical Cloud Act exposure |
|---|---|
| AWS / Azure / GCP EU region | Yes (US entity) |
| OVHcloud / Infomaniak / Hetzner (EU) | Not US CLOUD Act; other frameworks possible |
| US CDN proxies all traffic | Analyze processing, logs |
| Encryption, client keys only | Reduces exploitable data |
An EU datacenter does not exclude US reach if the contract is signed with a US-subject entity.
Questions to ask before signing
Before validating a contract, clarify the legal identity of the contracting party: is it a US company or a European subsidiary? Map subprocessors — backups, support, monitoring — that may sit in the United States. Verify location of production, backup copies, and logs, as our investigation on real location describes. Request notification clauses in case of a government order, when the law allows. Finally, specify encryption: who holds the keys, is there a client KMS, and does your project require SecNumCloud or reinforced sovereignty? See SecNumCloud criteria for that last point.
Compare directory profiles: OVHcloud, Scaleway, and Infomaniak document sovereignty positioning differently from AWS Paris region.
Proportional mitigations
For low-sensitivity brochure-site data, a European host with a solid DPA often suffices; Cloud Act weighs little in practice. For sensitive data, defense secrets, or certain health data, avoid the US chain, consider SecNumCloud or HDS under the French framework, encrypt with client keys, and have legal review the contract. For a US CDN or SaaS, map processing; anonymization or EU-only routing can sometimes reduce exposure.
Cross-check GDPR: choosing a host and Cloud Act and contract.
What Cloud Act does not do
The law does not let anyone read your data: a US procedure is required. It does not replace your GDPR compliance as controller. It does not make illegal using AWS in an EU region — it requires risk analysis and documented guarantees. For most brochure sites, the practical risk stays low; for regulated or sensitive workloads, the analysis becomes part of your compliance file.
The peak: cloud region reassures — contract jurisdiction binds
For public sites, real risk varies with data sensitivity. For critical data, illusion becomes liability.
Decide and move forward without blind spots
Identify the contracting entity and parent company first, then map backups, CDN, and third-party support. Assess data sensitivity and sector obligations that apply to your activity. Choose a European host or encryption and key-holding guarantees if a US provider remains unavoidable. Finally, document your transfer risk analysis, as the guide Transfers outside the EU reminds.
Consult the comparator and sovereign cloud investigation to refine your shortlist.
Frequently asked questions
Does Cloud Act apply if my data is in France?
Yes, it is possible if the provider is subject to US law. Disk location alone does not always exclude an order targeting data stored in the European Union.
Does a pure European host avoid Cloud Act?
It reduces US-linked risk, provided there is no US parent company and no US-subject subprocessor. Read the contract, not just the marketing.
Does encryption protect from Cloud Act?
Encryption with keys held only by you limits exploitable access. Keys hosted at a US provider remain exposed.
SecNumCloud and Cloud Act — link?
SecNumCloud frames reinforced hosting against extraterritorial access for certain sensitive workloads. It is not automatic for every website.
Cloud Act for a European website: not "US banned" — it is knowing who, legally, can receive an order on your data, wherever it sleeps.