{"id":248531,"date":"2026-05-18T14:30:49","date_gmt":"2026-05-18T12:30:49","guid":{"rendered":"https:\/\/spotler.com\/blog\/what-is-the-us-cloud-act"},"modified":"2026-05-18T14:30:49","modified_gmt":"2026-05-18T12:30:49","slug":"what-is-the-us-cloud-act","status":"publish","type":"blog","link":"https:\/\/spotler.com\/en-gb\/blog\/what-is-the-us-cloud-act","title":{"rendered":"What is the US CLOUD Act?"},"content":{"rendered":"<h2 class=\"wp-block-heading\"><em>Meaning, GDPR impact and US vs EU data hosting explained&nbsp;<\/em><\/h2>\n<p><strong>Everyone who is&nbsp;using cloud software&nbsp;or software as a service (Saas) \u2013 and&nbsp;that\u2019s&nbsp;basically the&nbsp;whole world&nbsp;\u2013&nbsp;you\u2019ve&nbsp;likely come&nbsp;across the&nbsp;US CLOUD Act&nbsp;in discussions around data privacy, GDPR, and data security.&nbsp;<\/strong><\/p>\n<p><strong>But what exactly is this law? Has anything changed in recent years? And what does it mean in practice when choosing between US and European software providers?&nbsp;<\/strong><\/p>\n<p><strong>In this article,&nbsp;we\u2019ll&nbsp;give you a clear and practical explanation so you can better understand the impact on your data and technology decisions.&nbsp;<\/strong><\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h2 class=\"wp-block-heading\">What is the US CLOUD Act?&nbsp;<\/h2>\n<p>The&nbsp;<a href=\"https:\/\/www.congress.gov\/bill\/115th-congress\/house-bill\/4943\" target=\"_blank\" rel=\"noreferrer noopener\">CLOUD Act<\/a>&nbsp;(Clarifying Lawful Overseas Use of Data Act)&nbsp;is a US law introduced in 2018. It allows American law enforcement authorities to request access to data from US-based technology companies,&nbsp;even if that data is stored outside the United States.&nbsp;<\/p>\n<p>In simple terms:&nbsp;If your data is processed or controlled by a company that falls under US&nbsp;jurisdiction, US authorities can legally request access to that data,&nbsp;regardless of where it is physically stored.&nbsp;<\/p>\n<p>This is where the complexity around international data privacy begins.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h2 class=\"wp-block-heading\">What does the CLOUD Act mean in practice?&nbsp;<\/h2>\n<p>Although the CLOUD Act is primarily used for serious criminal investigations, its implications go beyond law enforcement.&nbsp;The most important takeaway is:&nbsp;<\/p>\n<div id=\"image-block_5341a1fca96b250db9340ba4700ed622\" class=\"wp-block-quote-block sec-color-2\">\n<div class=\"quote-wrapper icon-bulb\">\n<div class=\"quote-icon\">\n<div class=\"icon icon-bulb\"><\/div>\n<\/p><\/div>\n<div class=\"quote-text\">\n<div class=\"quote-content\">\n<p>Where your data is stored is not the same as who controls your data<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p>\n<p>Many organisations assume that storing data in Europe automatically protects it.&nbsp;In reality, the&nbsp;legal&nbsp;jurisdiction&nbsp;of the provider plays a crucial role.&nbsp;<\/p>\n<p>If you use a US-based cloud or SaaS provider, that company may&nbsp;be required&nbsp;to provide access to data under US law. This can create tension with the&nbsp;<a href=\"https:\/\/gdpr.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">General Data Protection Regulation<\/a>&nbsp;(GDPR), which imposes strict rules on access to and&nbsp;processing of&nbsp;personal data.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h2 class=\"wp-block-heading\">What has changed? Why the CLOUD Act is back in focus&nbsp;<\/h2>\n<p>The law itself&nbsp;hasn\u2019t&nbsp;significantly changed, but the context around it has evolved.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\">Schrems II changed the playing field&nbsp;<\/h3>\n<p>In 2020, the European Court of Justice issued its ruling in the&nbsp;<a href=\"https:\/\/curia.europa.eu\/juris\/liste.jsf?num=C-311\/18\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Schrems II case<\/strong><\/a>, invalidating the Privacy Shield framework due to concerns about access to EU data by US authorities.&nbsp;<\/p>\n<h4 class=\"wp-block-heading\">The key takeaway from this ruling:&nbsp;<\/h4>\n<p>It is not enough for data to be stored in Europe. It must also be protected against access under foreign laws that conflict with GDPR.&nbsp;<\/p>\n<h4 class=\"wp-block-heading\">Increased scrutiny and buyer awareness&nbsp;<\/h4>\n<p>Since Schrems II:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>Organisations must better justify how they handle international data transfers<\/li>\n<li>Legal and compliance teams are more involved in vendor selection<\/li>\n<li>Buyers increasingly ask detailed questions about data access and&nbsp;jurisdiction&nbsp;<\/li>\n<\/ul>\n<p>At the same time,&nbsp;data sovereignty&nbsp;has become a real factor in procurement and vendor selection processes.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<figure class=\"wp-block-image size-full borderradius20\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"300\" src=\"https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker2.webp\" alt=\"\" class=\"wp-image-248501\" srcset=\"https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker2.webp 770w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker2-300x117.webp 300w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker2-768x299.webp 768w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker2-767x299.webp 767w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker2-488x190.webp 488w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker2-44x17.webp 44w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n<h2 class=\"wp-block-heading\">US vs EU data hosting:&nbsp;what\u2019s&nbsp;the real difference?&nbsp;<\/h2>\n<p>At first glance, US&nbsp;and European providers may seem similar. Both offer scalable cloud infrastructure and advanced capabilities.&nbsp;The real difference lies in&nbsp;<strong>legal&nbsp;jurisdiction&nbsp;and data access rights<\/strong>.&nbsp;<\/p>\n<h3 class=\"wp-block-heading\">US-based providers&nbsp;<\/h3>\n<p>US providers (including&nbsp;hyperscalers&nbsp;and many SaaS platforms) offer powerful, globally distributed infrastructure. However, they are subject to US law, including the CLOUD Act.&nbsp;<\/p>\n<p>This means:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>Data may be requested by US authorities through legal procedures<\/li>\n<li>Jurisdiction&nbsp;applies regardless of where the data is stored<\/li>\n<li>Additional&nbsp;safeguards are&nbsp;required&nbsp;to meet GDPR obligations&nbsp;<\/li>\n<\/ul>\n<p>For many organisations, this is manageable\u2014but it requires awareness and proper risk assessment.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h3 class=\"wp-block-heading\">EU-based providers&nbsp;<\/h3>\n<p>European providers&nbsp;operate&nbsp;fully under EU law and are directly aligned with GDPR requirements.&nbsp;<\/p>\n<p>In practice, this means:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>Data is governed exclusively by European legislation<\/li>\n<li>Lower exposure to foreign government access requests<\/li>\n<li>Simpler and more predictable compliance processes&nbsp;<\/li>\n<\/ul>\n<p>For organisations&nbsp;prioritising&nbsp;transparency and control, this can be a decisive advantage.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h3 class=\"wp-block-heading\">The key insight&nbsp;<\/h3>\n<p>This is not about \u201cgood\u201d versus \u201cbad\u201d providers.&nbsp;Choosing a software provider is also choosing the legal framework under which your data is governed.&nbsp;And that makes it a strategic decision. Not just a technical one.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<figure class=\"wp-block-image size-full borderradius20\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"300\" src=\"https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker4.webp\" alt=\"\" class=\"wp-image-248510\" srcset=\"https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker4.webp 770w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker4-300x117.webp 300w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker4-768x299.webp 768w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker4-767x299.webp 767w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker4-488x190.webp 488w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker4-44x17.webp 44w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n<h2 class=\"wp-block-heading\">Comparison: US vs EU data hosting<\/h2>\n<style type=\"text\/css\">\n@media only screen and (max-width: 767px) {.overflow-x-scroll {overflow-x: scroll !important;}}\n<\/style>\n<div class=\"overflow-x-scroll\">\n<table style=\"width: 100%; border-collapse: separate; border-spacing: 0; border-radius: 20px; overflow: hidden; border: 1px solid #002a4d;\">\n<thead>\n<tr>\n<th style=\"background: #23afe6; color: #ffffff; padding: 18px 20px; width: 30%; font-weight: bold;\">&nbsp;<\/th>\n<th style=\"background: #23afe6; color: #ffffff; padding: 18px 20px; width: 35%; font-weight: bold;\">US-based providers<\/th>\n<th style=\"background: #23afe6; color: #ffffff; padding: 18px 20px; width: 35%; font-weight: bold;\">EU-based providers<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 20px; font-weight: bold; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Legal jurisdiction<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">US law (incl. CLOUD Act)<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">EU law (GDPR)<\/td>\n<\/tr>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 20px; font-weight: bold; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Government access<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Possible via legal requests<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Limited to EU legal frameworks<\/td>\n<\/tr>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 20px; font-weight: bold; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Data location<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Global (including EU data centres)<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Primarily within the EU<\/td>\n<\/tr>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 20px; font-weight: bold; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Data sovereignty<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Not fully guaranteed<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Strongly enforced<\/td>\n<\/tr>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 20px; font-weight: bold; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">GDPR compliance complexity<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Higher (requires additional safeguards)<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Lower (natively aligned with GDPR)<\/td>\n<\/tr>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 20px; font-weight: bold; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Schrems II impact<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Significant (requires risk assessment)<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Limited<\/td>\n<\/tr>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 20px; font-weight: bold; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Transparency towards customers<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">More complex to explain<\/td>\n<td style=\"padding: 20px 20px 20px; vertical-align: text-top; border-bottom: 1px solid #002a4d;\">Clearer and easier<\/td>\n<\/tr>\n<tr>\n<td style=\"background: #e6f6fc; padding: 20px 20px 25px; font-weight: bold; vertical-align: text-top;\">Risk profile<\/td>\n<td style=\"padding: 20px 20px 25px; vertical-align: text-top;\">Dependent on safeguards and setup<\/td>\n<td style=\"padding: 20px 20px 25px; vertical-align: text-top;\">More predictable<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h3 class=\"wp-block-heading\">Why this matters for marketing and customer data&nbsp;<\/h3>\n<p>Marketing platforms process&nbsp;highly sensitive&nbsp;and valuable data, such as:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>Customer profiles<\/li>\n<li>Behavioural&nbsp;data<\/li>\n<li>Communication history<\/li>\n<li>Consent and preferences&nbsp;<\/li>\n<\/ul>\n<p>This makes questions around data access and&nbsp;jurisdiction&nbsp;critical\u2014not just for compliance, but for trust and commercial success.&nbsp;<\/p>\n<p>These topics increasingly come up in:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>RFP processes<\/li>\n<li>Security and compliance assessments<\/li>\n<li>Enterprise sales conversations&nbsp;<\/li>\n<\/ul>\n<p>If you&nbsp;can\u2019t&nbsp;clearly explain your setup, it can slow down&nbsp;or even block&nbsp;deals.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<figure class=\"wp-block-image size-full borderradius20\"><img loading=\"lazy\" decoding=\"async\" width=\"770\" height=\"300\" src=\"https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker1.webp\" alt=\"\" class=\"wp-image-248491\" srcset=\"https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker1.webp 770w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker1-300x117.webp 300w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker1-768x299.webp 768w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker1-767x299.webp 767w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker1-488x190.webp 488w, https:\/\/spotler.com\/wp-content\/uploads\/2026\/05\/blog-uscloudact-breaker1-44x17.webp 44w\" sizes=\"auto, (max-width: 770px) 100vw, 770px\" \/><\/figure>\n<h3 class=\"wp-block-heading\">Spotler\u2019s perspective on data privacy and control&nbsp;<\/h3>\n<p>At Spotler, we see data privacy as a fundamental part of modern marketing technology.&nbsp;As a European&nbsp;organisation, we&nbsp;operate&nbsp;in line with GDPR principles and&nbsp;prioritise&nbsp;transparency, control, and responsible data handling.&nbsp;<\/p>\n<p>This means we make conscious decisions about:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>Where data is stored<\/li>\n<li>Who has access to it<\/li>\n<li>Under which conditions it is processed&nbsp;<\/li>\n<\/ul>\n<p>So&nbsp;our customers can not only be compliant, but also confidently explain their data setup to stakeholders.&nbsp;It is not without reason that we are open and transparent about this in&nbsp;our&nbsp;<a href=\"https:\/\/trust.spotler.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Trust Center<\/a>.&nbsp;<\/p>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h3 class=\"wp-block-heading\">The bigger shift: from storage to control&nbsp;<\/h3>\n<p>The CLOUD Act highlights a broader shift in how organisations think about data.&nbsp;<\/p>\n<p>It\u2019s&nbsp;no longer enough to ask:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>Where is my data stored?&nbsp;<\/li>\n<\/ul>\n<p>You also need to understand:&nbsp;<\/p>\n<ul class=\"wp-block-list\">\n<li>Who can access it?<\/li>\n<li>Under which legal framework?<\/li>\n<li>How can I&nbsp;demonstrate&nbsp;control?&nbsp;<\/li>\n<\/ul>\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<h2 class=\"wp-block-heading\">Final thoughts&nbsp;<\/h2>\n<p>The US CLOUD Act does not mean your data is freely accessible.&nbsp;But it does mean that:&nbsp;<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-text-align-center\"><strong><em>Legal jurisdiction matters just as much as physical data location<\/em><\/strong><\/p>\n<\/blockquote>\n<p>For organisations&nbsp;operating&nbsp;in Europe, this makes the choice of technology partners more strategic than ever.&nbsp;Because in practice, choosing software also means choosing how your data is governed and protected.&nbsp;<\/p>\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<section class=\"faq-section sec-color-2 with-bg-option  sec-margin is-gutenberg-block-section\" \n             id=\"\"><\/p>\n<div class=\"container\">\n<div class=\"row justify-content-center\">\n<div class=\"col col-sm-12\">\n<h2 class=\"faq-sec-title sec-title\">Frequently Asked Questions about <span class=\"hide-mobile\"><br \/><\/span>the US CLOUD Act <\/h2>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"row justify-content-center\">\n<div class=\"col col-sm-12\">\n<div class=\"faq-list\">\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">What is the US CLOUD Act in simple terms? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>The US CLOUD Act is an American law introduced in 2018 that allows US authorities to request access to data from US-based technology companies. Even when that data is stored outside the United States.<\/p>\n<p>In practice, this means that a company operating under US jurisdiction may be legally required to provide access to data, regardless of whether the data is physically stored in Europe.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">Does the CLOUD Act override GDPR? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>Not directly. The CLOUD Act and GDPR are separate legal frameworks that can sometimes conflict with each other.<\/p>\n<p>GDPR places strict rules on how personal data can be accessed and transferred, while the CLOUD Act allows US authorities to request access to data from US companies. This creates legal and compliance challenges for organisations using US-based cloud providers.<\/p>\n<p>That is why many organisations now assess not only where data is stored, but also which jurisdiction applies to the provider managing the data.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">Can US authorities access data stored in Europe? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>Potentially, yes.<\/p>\n<p>If the company managing or controlling the data falls under US jurisdiction, American authorities may legally request access to that data under the CLOUD Act\u2014even when the data is hosted in an EU data centre.<\/p>\n<p>This is one of the main reasons why data sovereignty and jurisdiction have become important topics in Europe.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">Does using a US cloud provider automatically mean non-compliance with GDPR? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>No. Using a US-based provider does not automatically mean an organisation is non-compliant.<\/p>\n<p>However, organisations are expected to carefully assess the legal and technical safeguards surrounding international data access and transfers. Since the Schrems II ruling, companies must take a more active role in evaluating these risks.<\/p>\n<p>This often includes:<\/p>\n<ul>\n<li>Risk assessments<\/li>\n<li>Additional contractual safeguards<\/li>\n<li>Technical measures such as encryption and access controls<\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">What is the difference between data location and data sovereignty? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>Data location refers to the physical place where data is stored, such as a data centre in Germany or the Netherlands.<\/p>\n<p>Data sovereignty refers to the legal jurisdiction governing that data.<\/p>\n<p>This distinction is important because data stored in Europe may still fall under foreign laws if the provider is headquartered outside the EU.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">Why is Schrems II important in relation to the CLOUD Act? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>The Schrems II ruling by the European Court of Justice invalidated the Privacy Shield agreement between the EU and the US.<\/p>\n<p>One of the key concerns behind the ruling was the possibility of US government access to European data under laws such as the CLOUD Act.<\/p>\n<p>As a result, organisations are now expected to assess whether international data transfers provide adequate protection under GDPR.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">Are European cloud providers safer from a privacy perspective? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>European providers are generally more closely aligned with European privacy legislation such as GDPR because they operate fully under EU jurisdiction.<\/p>\n<p>This often results in:<\/p>\n<ul>\n<li>Lower exposure to foreign government access requests<\/li>\n<li>Simpler compliance processes<\/li>\n<li>Greater clarity around legal responsibilities<\/li>\n<\/ul>\n<p>However, organisations should still evaluate each provider individually based on their security measures, infrastructure, and compliance policies.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">Why are businesses increasingly asking about the CLOUD Act? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>Over the past few years, data privacy has become a much more strategic topic.<\/p>\n<p>Buyers, procurement teams, and compliance departments increasingly ask:<\/p>\n<ul>\n<li>Who can access our data?<\/li>\n<li>Under which laws?<\/li>\n<li>How is customer data protected?<\/li>\n<\/ul>\n<p>This is especially important in sectors handling sensitive customer information, such as marketing, SaaS, customer service, and e-commerce.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">What should organisations ask cloud or SaaS providers? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>When evaluating providers, organisations should ask questions such as:<\/p>\n<ul>\n<li>Under which jurisdiction does your company operate?<\/li>\n<li>Where is customer data stored?<\/li>\n<li>Who can access the data internally?<\/li>\n<li>What safeguards exist against unauthorised access?<\/li>\n<li>How do you support GDPR compliance?<\/li>\n<li>How do you respond to government data requests?<\/li>\n<\/ul>\n<p>Clear answers to these questions help organisations better assess privacy and compliance risks.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">Does the CLOUD Act only apply to large tech companies? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>No.<\/p>\n<p>The CLOUD Act can apply to any company that falls under US jurisdiction and is legally required to provide data access, regardless of company size.<\/p>\n<p>However, discussions around the law most commonly focus on major cloud and SaaS providers because they process large amounts of customer and business data.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"faq-item \" itemscope itemprop=\"mainEntity\" itemtype=\"https:\/\/schema.org\/Question\">\n<h4 class=\"faq-question\" itemprop=\"name\">What is the main takeaway for European organisations? <\/h4>\n<div class=\"faq-answer nmp-last-el\" itemscope itemprop=\"acceptedAnswer\" itemtype=\"https:\/\/schema.org\/Answer\">\n<div itemprop=\"text\">\n<p>The most important insight is that:<\/p>\n<p>Data protection is no longer only about where data is stored. It is also about who controls the data and under which legal framework.<\/p>\n<p>For European organisations, this makes data governance, provider selection, and transparency increasingly important strategic decisions.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"row justify-content-center\">\n<div class=\"col col-sm-12\">\n<div class=\"faq-sec-desc nmp-last-el\">\n<p><strong>Do you have any other questions?<\/strong><br \/>\nPlease feel <a href=\"https:\/\/spotler.com\/sales\">free to contact<\/a>. We will gladly answer your questions.<\/p>\n<\/div><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Discover what the US CLOUD Act means for GDPR, data sovereignty and choosing between US and EU cloud or SaaS providers.<\/p>\n","protected":false},"author":23,"featured_media":248525,"template":"","cat_industry":[],"cat_topic":[1623],"class_list":["post-248531","blog","type-blog","status-publish","has-post-thumbnail","hentry","cat_topic-data-privacy-en-gb"],"acf":[],"_links":{"self":[{"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/blog\/248531","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/users\/23"}],"version-history":[{"count":0,"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/blog\/248531\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/media\/248525"}],"wp:attachment":[{"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/media?parent=248531"}],"wp:term":[{"taxonomy":"cat_industry","embeddable":true,"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/cat_industry?post=248531"},{"taxonomy":"cat_topic","embeddable":true,"href":"https:\/\/spotler.com\/en-gb\/wp-json\/wp\/v2\/cat_topic?post=248531"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}