Privacy in the cloud era
Why the location of your data is only half the story
Data in a European data centre is not automatically safe from US access. If your cloud provider falls under US law, the CLOUD Act can compel access to your data, even when it physically sits in Frankfurt or Amsterdam. Where your data lives says less about its safety than who has legal say over it.
Location and control are two different things
I recently spoke to a contact who was convinced his data was in good shape. It sat in a data centre in Frankfurt. “Europe, so GDPR, so safe,” he said. Sounds like a watertight plan. And he isn’t the only one saying it.
When I pointed out that the cloud provider was American, he looked surprised. “But the servers are in Germany, aren’t they?” They are. That is still only half the story. And that gap, between where your data physically sits and who has legal say over it, is where things keep going wrong in practice.
Data has a physical location and a legal home. The legal home determines who can reach it, under what circumstances, and on the basis of which law.
That sounds abstract and it is more concrete than you think. Say your company stores customer data with a large US cloud provider, in a data centre in Amsterdam or Frankfurt. The servers are in Europe, the data falls under the GDPR, and so far everything looks fine.
The provider itself falls under US law. Those two things can collide.
The CLOUD Act, introduced in the US in 2018, requires American companies to hand data to US authorities on request, including data physically stored in Europe. That is not a theoretical risk. It is simply the law, and it applies wherever the servers stand.
So if you use AWS, Microsoft Azure or Google Cloud, there is a real chance your data falls under US jurisdiction. Not because you did anything wrong, but because that is where the provider is based.
The GDPR: a step forward, and not the destination
The GDPR changed a lot when it arrived in 2018. Companies have to be transparent about what they do with personal data, ask permission where it is needed, and the fines for breaches can run high. That had an effect: privacy awareness in Europe has grown considerably.
There is a nuance that often gets missed. The GDPR is about protecting the data of EU citizens, rather than only about where that data physically sits. In theory your data is protected even when it is processed outside Europe. In practice it gets complicated the moment several jurisdictions are in play.
Because which law applies then? The law of the country where the data sits? Of the country where the provider is based? Of the country of the customer whose data it is? The answer is that it depends. And that is exactly the problem.
A fragile compromise between Europe and the US
After the Schrems II ruling in 2020, where the European Court invalidated the Privacy Shield because protection for EU citizens was insufficient, there was real uncertainty about how data could legally move between Europe and the US.
A new agreement arrived in 2023: the EU-US Data Privacy Framework. The US has committed to more limited and more transparent access by intelligence services, and an independent appeal mechanism for EU citizens has been set up. Those are steps forward.
The system leans heavily on trust and political goodwill. The CLOUD Act still exists. And the European Court has already struck down two comparable agreements. There is no guarantee that the current framework holds if political relations shift or another case is brought.
That makes the situation fragile. Not acutely dangerous, and uncertain enough to take seriously.
How a Dutch provider can fall under US jurisdiction overnight
Take Solvinity, a Dutch hosting provider that runs critical digital infrastructure including DigiD and MijnOverheid. As long as Solvinity was an independent Dutch company, the data of Dutch citizens fell under Dutch and European law. The US government had no access. That looked set to change when Kyndryl announced its acquisition of Solvinity in November 2025.
Overnight, all that data would have fallen under the jurisdiction of an American company. Which means the CLOUD Act would apply. What looked impossible the day before, US authorities reaching confidential data of Dutch citizens including names, addresses and income details, became a real risk. Beyond access through Kyndryl, the worst case included access to DigiD being blocked altogether.
This is not a hypothetical scenario. It shows how quickly control over digital infrastructure and sensitive citizen data can shift to a foreign power. The bigger danger sits one level up: the Netherlands losing control over its own digital sovereignty, and the continuity of vital services such as those run by Logius coming under threat. The State Secretary blocked the acquisition on 26 May 2026.
Solvinity and its owner Vitruvian Partners contested that decision. In an emergency hearing on 14 July 2026 the Rotterdam court rejected their request and saw no reason to suspend the ban. The formal objection procedure is still running, with a decision expected around the end of September. So the acquisition is off for now, and the last word has not been said.
The blind spots: encryption, backups and processing agreements
In my work in cybersecurity I regularly speak to organisations who believe they have it covered because they picked a European region in their cloud settings. Frankfurt, Amsterdam, Dublin. It feels safe. And to a degree it is.
There are a few blind spots I keep running into.
The first is encryption. Plenty of organisations encrypt their data in the cloud, which is good. Encryption only works if you hold the keys yourself. If the cloud provider holds them, which is the case in many default configurations, then the provider has access too. And through the CLOUD Act, potentially so do US authorities.
The second is backups. Production data sits neatly in Europe, and where do the backups sit? That question can surprisingly often not be answered on the spot. Backups sometimes replicate automatically to other regions, including outside Europe, without anyone consciously choosing that.
The third is processing agreements. The GDPR requires you to have a processing agreement with any processor handling personal data on your behalf. Such an agreement settles responsibilities rather than technical reality. If the provider falls under US law, a processing agreement offers no protection against a CLOUD Act request.
What you can do today
I am not writing this to frighten anyone or to suggest that the large cloud providers are a risk by definition. For most uses the risk is manageable, and the benefits of scale, reliability and functionality are real.
Choosing deliberately is a different thing from not thinking about it. That distinction matters.
A few things worth having clear:
- Know which jurisdiction your provider falls under, not only which region your data sits in.
- Check who manages the encryption keys. In many cases you can take that over yourself, and you have to ask for it explicitly.
- Map where your backups sit, and under what conditions.
- Think about what you would do if a provider received a request to hand over data. How would you find out, and what are your options?
- Review regularly who owns your data and who owns your provider. An acquisition can change the legal context overnight.
For organisations working with sensitive data, in healthcare, education, government, or sectors with strict compliance requirements, European alternatives are worth evaluating seriously. Not because American is bad by definition, but because a European provider simply does not fall under the CLOUD Act. That is a structural difference rather than a marketing story.
Europe’s search for digital sovereignty
Behind this discussion sits a broader question that has occupied Europe for several years. How dependent are we as a continent on technology infrastructure that falls outside our own legal reach?
Initiatives such as Gaia-X, a European project for secure, transparent and interoperable data infrastructure, are an attempt to change that. The goal is an alternative to American and Chinese tech giants, with more control for European companies and governments. Execution is complex and progress is slower than hoped, and the direction is clear. Europe wants less strategic dependency.
That is a practical question rather than a geopolitical hobby. It is about who ultimately controls data that European companies and citizens depend on.
What it comes down to
My contact with his data in Frankfurt made a reasonable choice. He simply hadn’t asked all the questions. Which is understandable: the subject is complex, the rules keep moving, and the large providers are good at keeping the technical and legal details in the background.
The core is simple. Where your data sits is part of the story. Who has legal say over it is the other part, and what happens when those two collide is the part nobody plans for.
So the next time you sign a cloud contract, or review one you already have, ask the legal questions alongside the technical ones. Who is really in control? Which law applies? What happens when the two conflict? And what happens if your provider changes owner?
Privacy takes more than ticking boxes. It takes asking one more question, especially when the answer is more complicated than you hoped.
Where this meets the commercial side
Selling into an organisation that has thought this through is a different conversation from selling into one that hasn’t. If your team is having that conversation, get in touch.



