Seven months after the CLOUD Act was signed and five months after GDPR took effect, the CLOUD Act GDPR conflict remains exactly what it looked like in March: two legal systems issuing instructions that cannot both be followed, with no court ruling, no executive agreement in force, and no authoritative guidance that resolves it. Every vendor presentation claiming to have solved it is selling something. What can be done is narrower and more useful than a solution. The conflict falls on specific parties in specific circumstances, the probability of it reaching any given organisation is low, and the cost of being able to explain your position in one page is close to nothing. That is the work.
What the CLOUD Act actually changed
It clarified rather than expanded. US providers must preserve and disclose communications and records in their possession, custody or control when served with lawful process, and the statute says plainly that this applies whether the information is located inside or outside the United States. The Supreme Court case that would have tested the pre-existing position was held moot in April once the new statute existed, and the appellate decision underneath it was vacated. The question that had been live for four years simply stopped being live. The Act also built two release valves. The first is a framework for executive agreements with qualifying foreign governments, allowing reciprocal direct requests under agreed standards. The second is a comity mechanism letting a provider move to quash where the target is not a US person and does not reside in the United States, and where disclosure would create a material risk of violating the laws of a qualifying foreign government. The detail that matters for anyone assessing this today is that the comity remedy is tied to the agreements, and no agreement is yet in force. Negotiations with the United Kingdom are reportedly furthest advanced. Until one concludes, the statutory route designed to accommodate conflicting foreign law is unavailable, and providers are left with ordinary common law comity arguments, which are discretionary and slow.
Why European law says no
GDPR addresses this directly and unhelpfully. A judgment or decision of a third-country authority requiring a transfer or disclosure of personal data is only recognisable or enforceable if it is based on an international agreement such as a mutual legal assistance treaty, and any such transfer must still satisfy the rest of the transfer rules. Read plainly, a US warrant served on a provider is not, by itself, a lawful basis for handing over European personal data. The derogations do not close the gap cleanly either. "Important reasons of public interest" means a public interest recognised in Union or member state law, not a foreign one. Necessity for legal claims is narrow and occasional by design. The Board's draft guidance on the derogations reads them strictly and warns against using them as a routine transfer route. And the obvious alternative basis fails on its own terms, because a legal obligation under the regulation means an obligation under Union or member state law, which a US statute is not. The supervisory institutions have said as much. In a joint response to a European Parliament committee this summer, the Board and the Supervisor set out the view that the CLOUD Act sits in tension with the regulation in the absence of an international agreement, and pointed to mutual legal assistance as the route that European law contemplates. That is not a court ruling and it does not bind anyone, but it tells you what a supervisory authority will say if asked. Meanwhile the Commission has proposed its own cross-border evidence instrument, which would let member state authorities compel production directly from providers offering services in the Union. It is early in the legislative process. Its existence matters because it is simultaneously a parallel regime and Europe's negotiating position.
Who is actually in the impossible position
Not, in most cases, you. The party caught between the two obligations is the provider with a US nexus: incorporated there, owned from there, or otherwise within reach of US process. It receives the order, it carries the contempt risk for refusing, and it carries the regulatory risk for complying. That is a genuinely unresolvable position and it is the provider's to manage. The second party at risk is a multinational controller with establishments on both sides. A group that responds to a US request by having its European entity ship data to its US entity has performed the transfer itself, and cannot point at a provider. For a customer of a cloud service, the exposure is different and more mundane. You may not be told. You may be unable to tell a regulator or a customer what happened to data you are accountable for. And you may have made contractual commitments about disclosure that you cannot keep. Those are real problems, and none of them is solved by changing provider. It is also worth keeping the volumes in view. This is criminal process aimed at identified accounts, overwhelmingly consumer communications services, not a mechanism for sweeping up an enterprise tenant's finance system. Providers publish request statistics, and the enterprise share is small. The scenarios that should concern a corporate buyer are narrow: an investigation that touches an individual employee, and a non-disclosure order that prevents the provider telling you about it.
Map the parties
Identify providers, entities, records and control relationships
Read commitments
Examine request, notification and challenge terms
Assess safeguards
Check minimisation, key access and processing limits
Name the response owner
Set legal escalation and case-specific assessment
Revisit the position
Review changes to agreements and applicable law
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for a Legal Conflict Assessment
- Map which of your providers have a US nexus, and how. Incorporation, ownership, group structure and the location of the staff who can access the data. A European-registered subsidiary of a US parent is still within a parent's control for these purposes.
- Read the government-request clause in each contract. What you want is a commitment to redirect requests to you where legally possible, to notify you where notification is not prohibited, to challenge overbroad or unlawful orders, and to disclose only the minimum required.
- Treat key custody as the only technical mitigation that changes the outcome. Where the provider cannot decrypt, compelled disclosure produces material the requesting authority cannot read. That is a real difference, and it is also an operational commitment you have to be able to run.
- Minimise what the exposed system holds. Data that is not in the service cannot be produced from it. This is the least glamorous control available and the most reliably effective.
- Write your position down before anyone asks. One page: which providers, which exposure, which mitigations, which risks you have accepted and why. Customers and regulators now ask, and an organisation that answers in a page is finished with the conversation in a meeting.
- Decide who handles a request if one arrives. Named legal contact, an escalation path, and a pre-agreed position on whether you would challenge. This is a half-day exercise that has no substitute at the moment it is needed.
- Do not confuse location with control. Storing data in a European or regional data centre does not remove a provider's obligation where the provider itself is within reach. Location helps with other requirements; it does not answer this one.
- Revisit when an executive agreement is concluded. The first agreement will change the analysis materially for providers and modestly for buyers, and it is the single external development worth monitoring here.
The Regional Angle
For most organisations in this region the conflict does not arise in the European form, because there is no general federal statute forbidding the disclosure. That sounds comfortable and is not, because the constraints that do bind here are sectoral and contractual rather than general, and they are stricter in specific places than a privacy law would be. Three sources matter. Financial and health regulators impose conditions on where data sits and who may access it, and a foreign authority's order is not an exception any of them contemplate. Government and critical sector classification rules restrict handling in ways that a compelled disclosure would plainly breach. And the financial free zones have their own data protection regimes with their own transfer rules, so a DIFC or ADGM entity inside a group faces a version of the European analysis while its mainland sibling does not, on the same shared infrastructure. The larger practical exposure is contractual. Regional businesses selling into Europe are being asked, in security schedules and vendor questionnaires this year, what their exposure to foreign lawful access is. The question is usually poorly drafted and nearly always scored. Organisations that can answer it factually are winning renewals against competitors who cannot. There is also a mirror-image problem that gets less attention than it deserves. Local authorities here have their own lawful access expectations, and an organisation holding its records with a foreign provider may find that responding to a domestic request is procedurally awkward, slow, or dependent on a support process that was never designed for it. Sovereignty arguments in this market are usually framed as keeping foreign governments out. Being able to satisfy your own is the half that gets forgotten. One point worth stating plainly because it recurs in tenders: the arrival of regional data centres from the large providers, announced but not yet open, will improve latency, residency and some regulatory positions. It will not alter this particular analysis, because the test is corporate control rather than geography.
The objection worth taking seriously
The objection is that this is a hypothetical being monetised. No enterprise customer of a major cloud provider has publicly had its data handed to a US authority over its objection. The published request volumes are dominated by consumer services. The probability that any specific mid-market company is affected is very small, and the cost of avoiding it entirely, by moving to providers without a US nexus, is large and paid in security, capability and money. An industry of sovereignty consulting has grown around a scenario that has not yet happened to anybody in the room. The harder version is that even granting the conflict, procurement cannot resolve it. Every credible provider has exposure to some government's process, the non-US alternatives are generally smaller and less well defended, and the trade being made is a remote legal risk for a concrete operational one. An organisation that migrates away from a well-run platform to a weaker one in the name of lawful access exposure has probably increased its total risk, not reduced it. Both points are largely right, and neither argues for doing nothing, because the recommended work is not migration. It is a documented position, three cheap mitigations and a named contact. That package costs a few days and satisfies the customers, regulators and boards who are going to ask regardless of how unlikely the underlying event is. The failure mode worth avoiding is not being raided by a foreign prosecutor. It is being asked a reasonable question by a European customer and having nothing to say.
Common Questions
Can a US authority compel data held in a European or regional data centre?
It can compel a provider within its jurisdiction to produce data in that provider's possession, custody or control, and the statute is explicit that location is not the determining factor. Whether the provider must comply where doing so would breach European law is the unresolved part, and it is currently argued case by case rather than settled by rule.
Does contracting with a provider's European entity solve the problem?
It helps with some questions and not with this one. The analysis turns on whether a US parent has control over the data, and corporate structure alone rarely establishes that it does not. It is a reasonable step, not an answer.
Does encryption protect us?
Only if the provider cannot decrypt. Service-managed encryption where the provider holds the keys offers no protection against compelled production. Customer-held keys change the outcome materially and impose real operational obligations, including the consequences of losing them.
What should we expect over the next twelve months?
Expect the first executive agreement to be concluded, most likely with the United Kingdom, which will give providers a comity route that currently does not exist and will become the template others are measured against. Expect the European cross-border evidence proposal to move slowly and to be used as leverage in the transatlantic negotiation. Expect further guidance from the European supervisory bodies rather than a court ruling, because providers have every incentive to narrow or settle these cases rather than test them. Expect transatlantic data arrangements generally to stay under scrutiny, with the annual review of the current adequacy framework held only this month. And expect the question to keep appearing in procurement long before it appears in litigation, which is where the practical cost sits for almost everyone.
Legal Conflict Assessment — we establish which of your providers and entities are genuinely exposed, what your contracts already commit you to, and put your position on one page before a customer or a regulator asks for it.
