The Cloud Act and European digital sovereignty: a conflict that remains unresolved
The battle for control over data is being fought on a legal front that is becoming increasingly complex, with rules that risk being incompatible. But it is the entire technological landscape that is at the heart of these sovereignty issues
The battle for control over European data is being fought on a legal battlefield fraught with obstacles, where two legal systems are pitted against one another with incompatible rules. On the one hand, there is the GDPR and the European Data Act, which protect data privacy and require consent for transfers outside the EU. On the other, the US Cloud Act, which since 2018 has allowed US authorities to request data from any provider subject to US jurisdiction, regardless of where that data is physically stored. A server in Frankfurt or Milan, if managed by Amazon, Microsoft or Google, remains potentially subject to a warrant issued by a US court.
The conflict is not merely theoretical. As highlighted by an analysis by Kiteworks, the two pieces of legislation impose directly conflicting obligations: the Cloud Act requires US providers to comply with US government requests wherever the data is located, whilst the European Data Act requires the same providers to prevent access that would be unlawful under EU law and to actively challenge such requests. A provider cannot comply with both laws when the US law requires disclosure that the European law prohibits.
The issue has flared up again in recent weeks. In addition to the Supreme Court’s ruling, which jeopardises the autonomy of the Federal Trade Commission, the US Court of Appeals for the Fifth Circuit has further complicated the situation by declaring the structure of the federal agency responsible for overseeing privacy and commercial practices to be unconstitutional.
The decision could have repercussions for the Data Privacy Framework, the agreement which, from 2023, will allow the transfer of personal data from the EU to the US. That framework is based on the premise that the US authorities guarantee adequate protection: if the FTC is stripped of its powers, the entire system risks being undermined, reviving scenarios already experienced with the Schrems I and II judgements, which had invalidated the previous Safe Harbour and Privacy Shield agreements.
Europe has responded with a more comprehensive package of measures on technological sovereignty, presented by the Commission last June. The Chips Act 2.0 aims to strengthen production capacity in advanced semiconductors, whilst the Cloud and AI Development Act introduces a single European framework for assessing the sovereignty of cloud and AI infrastructure.


