CLOUD Act, FISA and Co.: When EU Data Centers Fail to Protect European Data

Storing corporate data in European data centers operated by U.S. providers does not rule out access by U.S. authorities. A legal opinion by the University of Cologne, commissioned by the German Federal Ministry of the Interior and published in December 2025, confirms that U.S. authorities have extensive access to cloud data stored in Europe.

The physical location where data is stored is irrelevant under U.S. law. What matters is control over the data. This applies to Microsoft, Amazon AWS, Google Cloud – and in some cases also to European companies with relevant business relationships in the United States.

For companies subject to the GDPR, this creates a structural compliance problem. Standard contractual clauses, EU data center certifications, and the EU-US Data Privacy Framework cannot resolve this issue.

Background
The mentioned legal opinion confirms what is already well known among data protection experts: European data hosted in the EU by U.S. companies or their European subsidiaries remains subject, without restriction, to virtually unrestricted access by U.S. authorities.

Furthermore, the opinion even does not rule out that European companies operating through subsidiaries in the United States could be requested, if not “compelled,” by U.S. authorities to disclose data stored in the EU.

U.S. surveillance laws and regulations such as the CLOUD Act (Clarifying Lawful Overseas Use of Data Act of 2018), FISA Section 702 (Foreign Intelligence Surveillance Act), the Stored Communications Act (SCA), or Executive Order 12333 provide U.S. authorities with extensive powers to “compel” companies subject to U.S. jurisdiction to disclose data, or to gain access to data – including data stored abroad – belonging to non-U.S. citizens.

Data Protection Legal Assessment
The recent findings of the legal opinion shed light on the EU-US Data Privacy Framework (DPF), which was intended to establish an adequate level of data protection following the invalidation of the Privacy Shield. Whether this objective has been achieved is, given the available access and surveillance capabilities, certainly questionable.

Accordingly, the data protection organization NOYB, led by Max Schrems, had already announced some time ago that it intends to challenge the DPF in court, similar to its actions against Safe Harbour and the Privacy Shield. A third Schrems ruling therefore cannot be ruled out.

As long as U.S. providers remain technically capable and legally obliged to access European data, the use of U.S. service providers for processing personal data of Europeans remains problematic from a data protection perspective and highly questionable in terms of digital sovereignty.

Recommendations for Action
Companies using U.S. cloud services should review and document the following measures:
  • Conduct or update a Data Protection Impact Assessment (DPIA)
    When using U.S. service providers, conducting a DPIA is not optional but a legal requirement. Access rights and disclosure obligations based on various U.S. regulations must be explicitly assessed.
  • Carry out a Data Transfer Impact Assessment (DTIA/TIA): This assessment should take into account U.S. legal frameworks as well as the actual enforcement and application of these regulations.
  • Review and, if necessary, adjust technical and organizational safeguards
  • End-to-end encryption with exclusive key management by the customer (Customer-Managed Keys) significantly reduces access risk in practice – but does not eliminate it from a legal perspective.
  • Review cloud strategy from a risk perspective
    For particularly sensitive data (trade secrets, health data, attorney-client communications), the use of European providers without ties to U.S. corporate groups should be considered.
  • Update documentation and fulfill accountability obligations
    Companies should ensure that their decision to use U.S. service providers, including the underlying risk assessment, is properly documented and transparent.
Need for consulting?
GfDDE – Gesellschaft für Datenschutz und Datensicherheit – in Europa GmbH supports you in the legally compliant assessment of international cloud usage: from Data Transfer Impact Assessments to DPIAs and contract drafting.
Sources
Legal opinion of the University of Cologne (status March 2025, published December 2025): Legal assessment of U.S. law on global data access by U.S. authorities when using cloud services (FragDenStaat)

Heise online (10 December 2025): Legal opinion: U.S. authorities have extensive access to European cloud data

Security Insider (December 2025): U.S. Law Jeopardizes Data Sovereignty Despite EU Data Centers

RaKöllner (10 December 2025): University of Cologne Legal Opinion on U.S. Authorities’ Access to EU Data

Stiftung Datenschutz – DatenschutzWoche (15 December 2025): DatenschutzWoche 15.12.2025 – Cologne legal opinion and DSK resolutions

Borns IT- und Windows-Blog (11 December 2025): Legal opinion shows: European cloud content is not protected from U.S. access

Hearing of the French Senate (10 June 2025): Intelligence services and access to Microsoft Cloud – statement by Microsoft legal representative in France

GDPR (Regulation (EU) 2016/679), Articles 32, 35, 44–49, 48; DORA (Regulation (EU) 2022/2554), Articles 28, 30 — brief overview

More news

Phishing via a legitimate Microsoft address: Power BI abuse and GDPR obligations for companies

Since January 2026, a sophisticated phishing campaign has been active in which attackers send deceptive emails using the legitimate Microsoft sender address no-reply-powerbi@microsoft.com . This is technically possible due to a legitimate feature of Microsoft Power BI: when creating a dashboard, any external email address can be added as a subscriber, and the content of the automatically sent notification can be freely configured.

Read more…

How secure is encrypted data if the key is stored in the cloud?

A report published by Forbes in January 2026 provides the first public evidence that Microsoft has handed over BitLocker recovery keys to the FBI. This was made technically possible by the default configuration of modern Windows versions, which automatically upload recovery keys to the Microsoft cloud. For companies in the DACH region, this results in an immediate need for review:

Read more…