Skip to content
Decision support

Who decides whether the data may sit with an American provider

The CLOUD Act follows the provider's control over the data, not the address of the server. What decides the question is not the American statute but which of your own rules is the strictest.

Andreas Olsson10 min read

A screenprinted strongbox whose lock cylinder passes straight through it and continues out beyond the edge of the picture.

Key insights


  • The CLOUD Act ties disclosure to what the provider has in its possession, custody or control, whether or not the data sits inside or outside the United States. The location of the server is not what decides.
  • A provider's ability to ask for a US order to be quashed presupposes an executive agreement between governments. Among the agreements on record, none covers Sweden.
  • Sweden's cloud policy of May 2026 is advisory and states that each organisation must make its own independent assessment and is itself responsible for its use of cloud services.
  • The share of Swedish enterprises with at least ten employees buying cloud services during 2025 is put by Eurostat at 72.0 percent, and at 94.4 percent among those with at least 250 employees.
  • What a disclosure you are never told about would cost you is the question that separates readers: often nothing at all, but for a firm bound by professional secrecy a confidentiality incident.

The question rarely arrives as a matter of principle. It arrives as a decision with a date on it: a contract is to be signed, a migration approved, an archive moved, and somebody wants to know whether this particular material may sit there. The answer is then sought in the CLOUD Act, and that is where the enquiry takes the wrong turn. The American statute does not decide your question. It decides the provider's.

What follows is written from a Swedish position, and the distinction matters throughout: the CLOUD Act is national law in the United States, the General Data Protection Regulation and the Data Act are Union law that applies directly here, and the Swedish rules named below are national law that applies to Swedish organisations alone.

The CLOUD Act says nothing about where the server stands

The provision is short enough to read in full. Under 18 U.S.C. § 2713, introduced by the Clarifying Lawful Overseas Use of Data Act on 23 March 2018, a provider of electronic communication service or remote computing service shall comply with the obligations to preserve, back up or disclose the contents of a communication and any record pertaining to a customer or subscriber within that provider's possession, custody or control, regardless of whether the information is located within or outside of the United States.

There is nothing there about the address of the data centre. What binds is control, that is whether the provider can reach the data. A European hosting region does not change that, and it is why a guarantee about storage location does not answer the question it is so often given as the answer to.

The Swedish state's own description says the same thing without naming the statute. The Government's cloud policy, decided on 28 May 2026, states that companies in certain countries are under their respective national rules required, in certain circumstances, to hand data to their national authorities, even where that data is processed and stored outside those countries.

Two sources of different origin, an American statute and a Swedish government document, describe the same mechanism. That makes the rest of the discussion easier, because the disagreement is not about what the law says but about what it means for you.

For most organisations it is not a decision being taken for the first time either. According to Eurostat's survey of ICT usage in enterprises, 72.0 percent of Swedish enterprises with at least ten employees bought cloud services during 2025, and among enterprises with at least 250 employees the share was 94.4 percent. The population covers the business economy excluding agriculture, forestry, fishing and mining, and it excludes the financial sector, which has outsourcing rules of its own on top of the general ones. The question is rarely whether something should be moved. It is what already sits there.

The provider's objection requires an agreement between governments

The statute contains a safety valve, and it is smaller than it looks. Under 18 U.S.C. § 2703(h) a provider may within fourteen days move to modify or quash an order, but only where it reasonably believes both that the customer is not a United States person and does not reside in the United States, and that disclosure would create a material risk of the provider violating the laws of a qualifying foreign government.

The term qualifying foreign government is defined, and the definition is the whole point: it requires an executive agreement with the United States in force under 18 U.S.C. § 2523. The Department of Justice records on its CLOUD Act page agreements with the United Kingdom and Australia. The European Commission proposed in February 2019 that negotiations be opened with the United States and states on its page on cross-border access to electronic evidence that they are still ongoing.

Among the agreements recorded there, none covers Sweden. The provider can of course litigate on other grounds, but the route the legislator built for conflicts between legal orders is not open to a Swedish customer.

To that comes a detail that governs how the decision has to be taken rather than how it is to be justified. Under 18 U.S.C. § 2705(b) a court may order the provider not to notify any other person of the existence of the order, for such period as the court deems appropriate, among other things where there is reason to believe that notification would seriously jeopardise an investigation or lead to the destruction of evidence.

A disclosure nobody tells you about is not a risk you can discover after the fact.

That is why the question cannot be deferred to a future audit. A control that presupposes you will be told something does not work against a procedure built so that you are not told. The assessment therefore has to be made before the material is placed, and it has to be made on what a disclosure would cost, not on how likely it is.

Under oath the answer was no, and then came a second half

A statement often passed along in this debate comes from a transcript. In June 2025 Anton Carniaux, director of legal and public affairs at Microsoft France, was heard under oath by the French Senate's commission of inquiry into the cost and organisation of public procurement. He was asked whether the company could guarantee that data concerning French citizens would never be handed over following an instruction from the American government without French consent.

The answer sits in the commission's transcript: no, he could not guarantee it, but, again, it had never happened. He added that according to the company's transparency reports it had never occurred for a European company.

The second half does not always travel with the first, and dropping it is a mistake in both directions. Without it the quotation becomes a claim that disclosures happen routinely, which he did not say. With it the quotation becomes precisely the material a decision needs: the possibility is confirmed and cannot be excluded, while the outcome so far is described as a non-event. A decision built on frequency and a decision built on consequence land differently, and the difference is visible only when both halves remain.

The conclusion concerns a category and not a provider. The large American cloud providers are subject to the same provision, and none of them can contract away an obligation that follows from law in their home country.

Data protection moved, and it moved in the permissive direction

A common expectation is that the legal position has grown stricter. It has not.

The starting point was set early. In their joint response to the European Parliament's LIBE Committee in July 2019, the European Data Protection Board and the European Data Protection Supervisor held that a foreign court order does not as such make a transfer lawful under the General Data Protection Regulation, and that a provider subject to Union law cannot therefore base a disclosure on a CLOUD Act request without an international agreement. The derogations in Article 49 were described in the same response as narrow and to be interpreted restrictively.

Since then the case law has gone the other way. The Court of Justice did invalidate the then adequacy decision in Schrems II in July 2020, but in Latombe v Commission, Case T-553/23, the General Court dismissed in September 2025 the action against the EU-US Data Privacy Framework and confirmed that the United States, at the time the decision was adopted, ensured an adequate level of protection. That judgment is under appeal: Philippe Latombe lodged an appeal on 31 October 2025 and the case is pending before the Court of Justice.

In parallel came an obligation pointing the other way, and it falls on the provider rather than the customer. The Data Act has applied since 12 September 2025, according to the Swedish Post and Telecom Authority, and contains safeguards against third-country authorities gaining access to data in breach of Union law. That part concerns non-personal data, meaning the material that falls outside the General Data Protection Regulation and that a data protection assessment has therefore not covered.

The Swedish complementary provisions, by contrast, are recent. The inquiry report Increased and fair access to data, SOU 2025:118, was delivered in December 2025 proposing that the legislative amendments enter into force on 1 July 2026. That date has passed: the report went out for consultation in February 2026, the consultation period closed in May 2026, and the proposal is under preparation in the Government Offices. The Swedish Post and Telecom Authority states that pending complementary legislation its powers to act are limited.

The Government wrote a policy and handed the decision back

In May 2026 the Government decided Sweden's first cloud policy for public administration. It is addressed to state agencies under the Government together with municipalities and regions, and to private actors running publicly funded activities. It contains six principles: work risk-based ahead of cloud adoption, choose efficient cloud solutions, increase the benefit to the organisation, promote portability and a well-functioning market, maintain relevant control over data, operations and technology, and ensure sound requirements on suppliers.

The policy is advisory. It states that it may be used as support by public actors in their use of cloud services, and it places responsibility explicitly: each actor must make an independent assessment and is itself responsible for its use of cloud services.

The same message was repeated in the Government's answer to a written question on public agencies' dependence on American cloud services in July 2026: the assessment rests with the agencies themselves, and the Swedish Post and Telecom Authority has been tasked with guiding them. That the policy prohibits nothing is therefore not a gap in it. It is what the policy says it is.

There is one regime where the assessment lies with somebody other than the organisation itself, and it is Swedish national law. Under Chapter 4 of the Protective Security Act (säkerhetsskyddslagen 2018:585), whose provisions on outsourcing entered into force on 1 December 2021, an operator must in certain cases consult the supervisory authority before the procedure begins, and the supervisory authority may then, under Section 11, decide that the planned procedure may not be carried out. The same applies to a transfer under Section 17. What that means in practice, and which assumptions about prohibition do not hold, is set out in our review of AI in security-sensitive operations.

RegimeWhat it can end inWho it reaches
Protective Security Act, Chapter 4Duty to consult and a decision of prohibition before the procedure beginsOperators, on outsourcing and transfer
The cloud policyGuidance, with the assessment resting on the actorState agencies, municipalities, regions and publicly funded activities
The Data ActSafeguards imposed on the providerProviders of data processing services, for non-personal data
The GDPRRequirements of a legal basis and a basis for transferEveryone processing personal data

The table shows what each regime can result in, not how often it does. The point lies in how the rows differ: exactly one of them can end in an express prohibition of the particular planned procedure, decided before it begins. The others impose requirements on how you do it, not a ruling on whether you may, and that difference decides when the assessment has to be finished.

For most organisations nothing binds beyond data protection

There is a countervailing position that weighs more, and it argues that none of this needs doing.

For many Swedish organisations there is no professional secrecy, no statutory confidentiality and no protective security analysis binding the choice. The only regime that reaches them is the General Data Protection Regulation, and that route is currently open: the adequacy decision applies, the General Court has examined it and dismissed the action, and the Government's own cloud policy says that public administration will continue to be able to use market-leading products and services also where they come from companies domiciled outside the EU. For that reader the whole classification exercise answers a question that is already answered.

The objection holds, but only as long as its foundation does.

A decision resting on an adequacy decision is a decision you will be taking again.

The General Court examined the circumstances at the time the decision was adopted, the judgment is under appeal before the Court of Justice, and the preceding arrangement was invalidated by that same court in July 2020. That says nothing about how it goes this time, but it says something about what a decision resting on that ground alone is worth over time: it has an expiry date that is not written into the contract. An organisation that has once classified its material then only has to reread one line. One that has not gets to start from the beginning, under time pressure, and it is that sequence which makes the question expensive.

The question that gives different answers

Three questions settle the matter, and they are to be asked in this order.

The first: is there anything beyond data protection binding this particular material? Professional secrecy, statutory confidentiality, an undertaking in a client contract, a protective security analysis. If the answer is no for everything you hold, the decision is simple and can be documented on one page. If the answer is yes for a subset, it is that subset which is to be separated out, not the whole operation.

The second: can that rule end in a prohibition of what you are planning, decided in advance? The Protective Security Act can, through the duty to consult before outsourcing. Most others impose requirements on how you do it and leave the question of whether you may with you, in which case the decision is yours even if you would prefer it to sit elsewhere. Waiting for a ruling is in those cases not caution, because nobody has undertaken to give one.

The third, which is the one that actually separates readers: what would a disclosure you are never told about cost you? For an organisation without confidentiality undertakings the answer is often nothing at all. For a firm bound by professional secrecy the same event is a confidentiality incident affecting a client who was never asked. For an operation holding security-classified information it is something else again. Same technology, same provider, same statute, three different answers, and that is why a general recommendation on this question is always wrong for somebody.

A fourth criterion concerns not the material but the assessment. Whoever sets out the options should not hold a margin on which one you choose, and the list should contain the deployment that never leaves your own environment. That entry belongs there even when it does not win, because a list without it is not a comparison but a recommendation. How the sorting is done, and who owns it afterwards, is described on the page about AI governance and compliance.


Common questions

The CLOUD Act is a United States statute of 23 March 2018, enacted as Division V of Public Law 115-141. It introduced 18 U.S.C. § 2713, which provides that a provider of electronic communication service or remote computing service shall comply with the obligations to preserve, back up or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within that provider's possession, custody or control, regardless of whether the information is located within or outside of the United States.

Clarifying Lawful Overseas Use of Data Act. The core of the provision is that the obligation follows the provider's control over the data rather than where the data is stored. The Act was passed on 23 March 2018 as Division V of Public Law 115-141.

The statute is American and creates no obligations for Swedish organisations. It still bears on a Swedish decision, because it reaches providers under United States jurisdiction wherever the data is stored. Sweden's cloud policy for public administration, decided by the Government on 28 May 2026, describes the same mechanism and states that each actor must make an independent assessment and is itself responsible for its use of cloud services.

In Schrems II, Case C-311/18 of 16 July 2020, the Court of Justice invalidated the then adequacy decision on the Privacy Shield and held that standard contractual clauses may be used only after an assessment of the law of the receiving country. The CLOUD Act is part of the law such an assessment has to cover. The position today is different: on 3 September 2025 the General Court dismissed the action against the EU-US Data Privacy Framework in Case T-553/23, and that judgment has been under appeal before the Court of Justice since 31 October 2025.

The European Data Protection Board and the European Data Protection Supervisor replied to the European Parliament's LIBE Committee on 10 July 2019 that a foreign court order does not as such make a transfer lawful under the General Data Protection Regulation, and that a provider subject to Union law cannot, absent an international agreement, base a disclosure on a CLOUD Act request. The derogations in Article 49 were described in the same response as narrow and to be interpreted restrictively.

The statute does not apply in the EU, but it reaches providers operating here. The European Commission proposed in February 2019 that negotiations be opened with the United States on cross-border access to electronic evidence and states that they are still ongoing. Since 12 September 2025 the Data Act has applied, containing safeguards against third-country authorities gaining access to non-personal data in breach of Union law.

They are two separate statutes. The USA PATRIOT Act was passed in 2001. The CLOUD Act was passed on 23 March 2018 as Division V of Public Law 115-141 and introduced 18 U.S.C. § 2713. It is the latter provision that governs disclosure of data held by a cloud provider, and it ties disclosure to what the provider has in its possession, custody or control.

Not in a way that settles the question for an individual organisation. The European Data Protection Board and the European Data Protection Supervisor have stated that a foreign court order does not as such make a transfer lawful and that a disclosure cannot be based on such a request absent an international agreement. At the same time the adequacy decision on the EU-US Data Privacy Framework stands, having been examined by the General Court in September 2025 and now under appeal before the Court of Justice. What may sit with the provider is therefore decided by which material it concerns and by which other rules bind the organisation.


If this lands on your desk, we should talk.

Ampliro Insights

New analysis, roughly weekly.

We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.

We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.