Kalufs
← All articles

Sovereignty and jurisdiction

US interests can reach your data inside a European data centre

Where your data is stored is not the same question as which law your provider must answer to. For an American cloud provider, US law can reach data held in a European data centre, and that changes what a promise of European hosting is actually worth.

Jurisdiction follows the provider, not the infrastructure

The FISA Amendments Act (Section 702, codified at 50 U.S.C. 1881a) lets the Attorney General and the Director of National Intelligence jointly authorise the acquisition of foreign intelligence information about non-US persons reasonably believed to be outside the United States, for up to a year at a time, without an individual court order for each target. Providers are compelled to assist, and a directive to a provider generally carries a non-disclosure obligation.

The CLOUD Act (18 U.S.C. 2523) lets a US order compel a provider to disclose data in its possession, custody or control, irrespective of where that data is stored. It was passed in March 2018 precisely to settle the dispute in United States v. Microsoft, where the government had obtained a warrant for an account whose e-mail was stored in Microsoft’s Dublin data centre. Microsoft contested it; the case reached the Supreme Court; and on 17 April 2018 the Court dismissed the appeal as moot because the CLOUD Act had meanwhile made the data producible regardless.

The legal obligation therefore lands on the American provider as custodian, no matter where the servers physically sit. The Swedish Armed Forces reached the same conclusion in its cloud strategy, noting that the location of a provider’s headquarters is decisive for which legislation applies. SVT, 30 May 2026

"Foreign intelligence" is broader than catching terrorists

Section 702 targets "foreign intelligence information". The statutory definition (50 U.S.C. 1801(e)) includes information the US needs to protect against attack, sabotage, international terrorism, weapons proliferation and clandestine intelligence activity. But it also includes, with respect to any foreign power or foreign territory, information relating to "the national defense or the security of the United States" or "the conduct of the foreign affairs of the United States".

The point is not that Section 702 equals "catching terrorists". A commercial tender, a strategic decision on energy policy, or the posture of a defence contractor can all bear on the conduct of US foreign affairs. This exposes commercially sensitive material to acquisition where the statutory conditions are met.

What they say, and what has been documented

Public reassurance

What has been documented

Whose interests prevail when obligations conflict?

We do not claim to know, request by request, what a provider would choose to do, and we do not assert that any specific file has been demanded or read. But the incentives are difficult to ignore.

A provider served with a Section 702 directive is required to maintain the secrecy of the acquisition. The customer is kept outside that process: the provider cannot offer the transparency needed to verify what happened to the customer’s data. A public promise to contest an order does not establish that a challenge will be made. Without evidence of action, it remains a marketing assurance.

When the choice is between breaking US law visibly and breaking European law invisibly, a reasonable reading of the incentives is that providers would not choose to be the first to publicly break US law. Notably, no US provider has ever publicly defied a Section 702 directive or a final CLOUD Act request. That is not proof of what any individual request has contained — it is a statement about what the incentives make predictable. Microsoft publishes figures showing compliance with national-security demands affecting thousands of accounts. That is an observable practice, not a hypothetical risk. A CEO’s promise to contest an order is a marketing assurance — not evidence that the company will withhold your data. Absent a documented case of refusal, the practical question is: how would my data fare in that situation, and how would I ever know?

Further reading

  1. 50 U.S.C. 1881a — Section 702 authorisation
  2. 50 U.S.C. 1801(e) — definition of foreign intelligence information
  3. United States v. Microsoft, No. 17-2 (2018)
  4. SVT: Försvaret nobbar techjättarnas moln (30 May 2026)
  5. Microsoft Sweden: Microsofts molntjänster och säkerhet (11 Feb 2021)
  6. Hamburg DPA: EU-Boundary nichts wert? (1 Aug 2025)
  7. Microsoft Government Requests for Customer Data Report
  8. Netherlands Court of Audit: Dutch central government in the cloud; Dark clouds looming (Jan 2025)
  9. PRISM programme overview (Wikipedia)
Discuss your needs