Data sovereignty

The CLOUD Act and your email: what US law actually reaches

Three ways to hold the same mailbox, and whose law reaches each one Whose law reaches it? Your mail US firm, EU disks Your own account EU firm, EU disks Control follows the operator, not the building

The US CLOUD Act is a 2018 statute that requires any provider subject to US jurisdiction to hand over communications data in its “possession, custody, or control” when served with valid US legal process, regardless of which country that data sits in. It created no new surveillance programme. It settled a jurisdictional question that had been litigated for years, and it settled it in favour of following the company rather than the hardware.

That one phrase — possession, custody, or control — is the whole thing. Almost everything people get wrong about the CLOUD Act and email comes from reading it as a question about where instead of a question about who.

What does the CLOUD Act actually say?

It amends the Stored Communications Act to add 18 U.S.C. § 2713, which obliges a provider of electronic communication or remote computing services to “preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider’s possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States.”

Two mechanics matter beyond that sentence. It resolved Microsoft Corp. v. United States, the fight over email stored in Microsoft’s Dublin datacenter, which the Supreme Court dismissed as moot in April 2018 once the new text made the answer explicit. And it added a comity provision letting a provider move to quash process where the account holder is not a US person, does not reside in the US, and disclosure would create a material risk of violating the law of a qualifying foreign partner government. That motion is narrow, discretionary, and decided by a US court. It is not a shield you can plan a business around.

The Act also built a framework for executive agreements under which qualifying foreign governments can serve demands directly on US providers. The UK–US agreement made under it entered into force in October 2022.

How aggressively any of this gets used is a fair debate. The scope is not really in dispute.

Why doesn’t an EU datacenter put email out of reach?

Because the obligation attaches to the entity, not the rack. A US-incorporated company running a European region still controls the data in it: it holds the access credentials, the keys where keys exist, and the operational ability to produce a copy on request. “Control” in § 2713 means precisely that ability.

This is the most expensive misconception in the market. “Your data stays in the EU” is a claim about geography and sometimes about contract. It is not a claim about jurisdiction. A European subsidiary of a US parent usually lands in the same place, because the parent’s control over the subsidiary is exactly what gets tested.

The inverse is true and said far less often. A provider incorporated in the EU with no US entity, no US infrastructure and no US-controlled parent is not reachable under § 2713 at all. US authorities would have to go through mutual legal assistance instead: slower, on the record, with a foreign court in the loop. That is the real difference, and it is a difference in who, not where.

What does this mean for email specifically?

Email is the worst case among data types, for three reasons.

It is a decade of everything, retained by default. A demand for one mailbox is a demand for years of context that nobody would have volunteered.

Its metadata is unusually rich and unusually less protected. Under US law, non-content records — headers, envelope addresses, timestamps, connection logs — are obtainable on a lower standard than contents, and the statute’s “record or other information pertaining to a customer” language covers them by name.

And a mailbox is full of other people’s data. Most of the personal information in your archive belongs to correspondents who never chose your provider. If you are a data controller, their exposure is your liability.

Encryption at rest shifts this only when the provider genuinely cannot decrypt. Zero-access designs, where the mailbox key is derived from a passphrase the provider never sees, are a materially different answer: ciphertext is not much use to a warrant. Even then the provider holds that ciphertext, so it can be ordered to produce it and to keep producing it going forward.

How does the CLOUD Act interact with GDPR?

Badly, and formally so. GDPR Article 48 recognises a third-country court or authority decision requiring the transfer of personal data only where it is based on an international agreement such as a mutual legal assistance treaty. A US warrant served on a provider is not based on one. The provider is squeezed from both sides: comply and breach Chapter V, refuse and risk US contempt.

Schrems II (Case C-311/18, judgment of 16 July 2020) is the same conflict approached from the European end. The Court of Justice annulled the Privacy Shield adequacy decision because US surveillance law and the redress available to Europeans fell short of EU standards, and it left standard contractual clauses standing only on condition that the exporter assess, case by case, whether the destination country’s law defeats them in practice. The EU–US Data Privacy Framework adopted in July 2023 is the third attempt at an adequacy bridge; its two predecessors were struck down in 2015 and 2020.

I am a founder, not a lawyer, and none of this is legal advice. It is the statutory text and the reported judgments, and both are worth reading in the original before you accept anyone’s summary, including mine.

What actually takes your mail out of scope?

Changing which entity controls the storage. Not the region flag, not the processing annex, not the trust page.

Three questions decide it. Where is the entity holding the stored bytes incorporated? Who can technically produce a readable copy without your cooperation? And whose account is that storage billed to, since the account holder is the party who can be served?

Storage-level custody is the version of this answer that survives scrutiny. When the archive lives in object storage in your own account, with an operator you picked in a jurisdiction you picked, a demand for your mail has to arrive at your door. You may still have to comply — nobody is above the law — but you will know it happened, you can contest it, and you can tell the people whose data was in it. That is not immunity. It is due process, which is the most anyone should honestly promise.

Routing is a separate question. Messages in flight pass through whoever operates your MX, wherever they are, and no storage arrangement fixes that. What custody fixes is the part that sticks around for twelve years.

Frequently asked questions

What is the US CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act, enacted in March 2018, amended the Stored Communications Act to add 18 U.S.C. § 2713. It requires a communications or cloud provider subject to US jurisdiction to preserve, back up or disclose customer data in its possession, custody or control when served with valid US legal process, regardless of whether that data is stored inside or outside the United States.

Does storing email in an EU datacenter protect it from the CLOUD Act?

No, not on its own. The obligation attaches to the provider, not the building. A US-incorporated company operating a Frankfurt region still controls the data there, because it holds the credentials and the technical ability to produce a copy. Region is a statement about geography; jurisdiction follows the entity that controls the storage.

Does the CLOUD Act override GDPR?

Neither overrides the other, which is the problem. GDPR Article 48 recognises a third-country authority order to transfer personal data only where it rests on an international agreement such as a mutual legal assistance treaty. A US warrant served directly on a provider is not that, so a provider caught between the two faces a genuine conflict of laws.

Does encryption put email beyond a CLOUD Act request?

Only if the provider cannot decrypt it. A provider that can render your mailbox in a browser holds the key by definition and can be compelled to produce readable mail. Where the key is derived from your passphrase and never leaves your control, the provider can still be compelled to hand over and preserve the ciphertext it holds.

What actually puts email outside US jurisdiction?

Changing which entity controls the stored bytes. If the archive lives in storage held in your own account, with an operator you chose that has no US presence, then a demand for your mail has to be served on you rather than answered quietly by a vendor. That is due process rather than immunity, and it is the realistic goal.