Data economy

The Cloud Act and European digital sovereignty: a conflict that remains unresolved

The battle for control over data is being fought on a legal front that is becoming increasingly complex, with rules that risk being incompatible. But it is the entire technological landscape that is at the heart of these sovereignty issues

 (Adpbe Stock)

3' min read

Translated by AI
Versione italiana

3' min read

Translated by AI
Versione italiana

The battle for control over European data is being fought on a legal battlefield fraught with obstacles, where two legal systems are pitted against one another with incompatible rules. On the one hand, there is the GDPR and the European Data Act, which protect data privacy and require consent for transfers outside the EU. On the other, the US Cloud Act, which since 2018 has allowed US authorities to request data from any provider subject to US jurisdiction, regardless of where that data is physically stored. A server in Frankfurt or Milan, if managed by Amazon, Microsoft or Google, remains potentially subject to a warrant issued by a US court.

The conflict is not merely theoretical. As highlighted by an analysis by Kiteworks, the two pieces of legislation impose directly conflicting obligations: the Cloud Act requires US providers to comply with US government requests wherever the data is located, whilst the European Data Act requires the same providers to prevent access that would be unlawful under EU law and to actively challenge such requests. A provider cannot comply with both laws when the US law requires disclosure that the European law prohibits.

Loading...

The issue has flared up again in recent weeks. In addition to the Supreme Court’s ruling, which jeopardises the autonomy of the Federal Trade Commission, the US Court of Appeals for the Fifth Circuit has further complicated the situation by declaring the structure of the federal agency responsible for overseeing privacy and commercial practices to be unconstitutional.

The decision could have repercussions for the Data Privacy Framework, the agreement which, from 2023, will allow the transfer of personal data from the EU to the US. That framework is based on the premise that the US authorities guarantee adequate protection: if the FTC is stripped of its powers, the entire system risks being undermined, reviving scenarios already experienced with the Schrems I and II judgements, which had invalidated the previous Safe Harbour and Privacy Shield agreements.

Europe has responded with a more comprehensive package of measures on technological sovereignty, presented by the Commission last June. The Chips Act 2.0 aims to strengthen production capacity in advanced semiconductors, whilst the Cloud and AI Development Act introduces a single European framework for assessing the sovereignty of cloud and AI infrastructure.

The previous month, the Commission had already announced stricter guidelines on the use of cloud services for sensitive public administration data, explicitly recommending that providers subject to non-European jurisdictions be avoided for classified or critical information.

But the rhetoric on sovereignty clashes with the reality of infrastructure. The main cloud contracts of the Italian and European public administrations continue, in fact, to rely on American hyperscalers. European alternatives do exist – including emerging solutions from national telecoms operators – but they suffer from a gap in scale, functionality and investment capacity that cannot be bridged by decree.

According to experts, the most effective technical solution is an architectural one: end-to-end encryption with keys controlled exclusively by the European customer. If the provider cannot access the encryption keys, it cannot technically comply with a warrant under the Cloud Act requiring readable data, thereby simultaneously meeting the technical impossibility required by US law and the protection obligation imposed by European law.

This is the approach set out in the Data Act, which requires cloud service providers to implement appropriate technical and organisational measures to prevent non-EU government access to data stored within the Union.

The problem is that many solutions marketed as ‘sovereign cloud’ by US providers do not meet this requirement. Locating servers in Europe is not enough if the encryption keys, management tools and operational expertise remain in the hands of US entities.

As Wire points out, “even if the data is hosted in Frankfurt or Paris, if it is managed by a US-based provider, it can be legally accessed by the US authorities without involving the user or any European public authority”.

For European businesses, the message is twofold. From a compliance perspective, relying on providers subject to the Cloud Act for sensitive data means exposing oneself to a regulatory risk that is no longer merely hypothetical. From a strategic perspective, dependence on non-European infrastructure limits the ability to exercise control over increasingly critical assets. The Data Act has lowered the barriers to changing providers, eliminating switching costs by January 2027 and imposing a two-month migration period. This presents an opportunity to reassess architectures and providers, but it requires investment in skills and planning that many organisations have not yet undertaken.

The outcome remains to be seen. Europe has the regulatory tools to assert its digital sovereignty, but translating these into operational independence is a long process, involving investment in infrastructure, skills development and strategic decisions that not everyone is prepared to make.

Copyright reserved ©
Loading...

Brand connect

Loading...

Newsletter

Notizie e approfondimenti sugli avvenimenti politici, economici e finanziari.

Iscriviti