▷ European Sovereign Cloud vs the US CLOUD Act - EADTrust
Inicio > Sin categoría > European Sovereign Cloud vs the US CLOUD Act: Why It Matters Where Your Data Is Stored

European Sovereign Cloud vs the US CLOUD Act: Why It Matters Where Your Data Is Stored

European Sovereign Cloud vs the US CLOUD Act

Suscríbete:

There is a conversation that many companies are not having with their cloud providers, but should have before signing their next software contract. The question is straightforward: if a US authority calls your cloud provider at three in the morning and requests access to your documents, what happens?

If your provider is a US company: Amazon Web Services, Microsoft Azure, Google Cloud, DocuSign, Adobe… the answer is uncomfortable: it may be legally required to hand over that data even if it is physically hosted on a server in Frankfurt, Dublin or Madrid. Not because of bad faith. Because of the law. The law that makes this possible is called the CLOUD Act (Clarifying Lawful Overseas Use of Data Act) and came into force in the United States in 2018.

The European sovereign cloud is exactly the opposite. This article explains what the CLOUD Act is, why a European subsidiary of a US company does not solve the problem, what Spanish law requires of companies working with public authorities, and how the infrastructure that guarantees genuine data sovereignty works.

Sovereign cloud Do you really know which jurisdiction your company’s data falls under?

Concepts

CLOUD Act (Clarifying Lawful Overseas Use of Data Act)

A 2018 US federal law that allows US authorities to request data stored by US companies regardless of where that data is physically located. It applies to any company headquartered in the United States, including its European subsidiaries.

European sovereign cloud

Cloud computing infrastructure designed to ensure that data remains exclusively under European jurisdiction, with access restricted to EU-based personnel, an isolation architecture that prevents data from leaving the region and contractual protocols for challenging external government requests.

Oracle EU Sovereign Cloud

The cloud infrastructure on which EADTrust deploys its services, Signature Manager, eArchiving and EAD Enterprise Suite. Physically and logically isolated regions, operated exclusively by EU-based personnel, with backups located within the EU and CDNs disabled.

GDPR (General Data Protection Regulation, Regulation (EU) 2016/679)

The European framework for protecting personal data. It prohibits the transfer of personal data to third countries without appropriate safeguards. The Schrems II judgment invalidated the Privacy Shield because it did not provide safeguards equivalent to those of the GDPR against US surveillance programmes.

Royal Decree-Law 14/2019

Spanish legislation establishing that technical resources used for identification and signatures in public administration must be located within the territory of the European Union, and that special categories of data must be located within Spanish territory.

International data transfer

Any communication or transfer of personal data to a recipient established in a third country outside the EU. The GDPR prohibits such transfers unless the destination country has been declared adequate by the European Commission or appropriate safeguards are used.

The CLOUD Act: what it says and why it applies to servers in Europe

The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a 2018 US federal law that amends the US Stored Communications Act. Its most relevant provision for European companies is this: US companies can be compelled by a court or administrative order to provide data stored on their servers, regardless of where those servers are physically located.

This means that if you use AWS, Azure, Google Cloud, Salesforce, DocuSign, Adobe Sign or another service provided by a company headquartered in the United States, that company may be required by US authorities to provide the contents of your folders, contracts, communications or any data you have stored on its platform, even if the server is in Frankfurt and even if the contract includes clauses requiring data residency in Europe.

The key distinction is between the physical location of the data and the corporate jurisdiction of the organisation that stores it. The CLOUD Act does not directly apply to the European company whose data is stored on that server: it applies to the US provider that manages the server. The provider must comply with the order or challenge it in court, with the costs and uncertain outcomes that this entails.

Can the provider resist? In theory, yes: it can challenge the order if it believes that it violates the laws of the country where the data is stored. In practice, major US technology companies have handed over European users’ data to US authorities on multiple occasions, and cases in which they have successfully challenged such requests are the exception, not the rule.

Having the server located in Europe is not enough. What matters is who owns the server and under which law that company is incorporated. A European subsidiary of Amazon is still Amazon. An order issued to Amazon applies to all its servers, wherever they are located.

🌍 Key concept Having servers in Europe does not necessarily mean having European sovereignty The physical location of the server is only one part of the equation. Who controls the infrastructure and which laws govern the provider also matter.

The Schrems II issue and the invalidation of the Privacy Shield

The tension between European data protection and US extraterritoriality is not new. The Court of Justice of the European Union has addressed it on two occasions, with outcomes that the technology sector is still processing.

In July 2020, the Schrems II judgment declared the Privacy Shield invalid (the agreement that allowed the transfer of European citizens’ personal data to the US) precisely because US surveillance programmes, including access under the CLOUD Act, do not provide safeguards equivalent to those of the European GDPR.

The Data Privacy Framework that replaced the Privacy Shield in 2023 reduces some of that tension for personal data transfers, but it does not eliminate the structural problem: the CLOUD Act remains in force, continues to apply to US companies with servers in Europe, and does not provide a systematic challenge framework that guarantees the protection of European data.

For data that is not “personal” within the meaning of the GDPR, corporate contracts, intellectual property, trade secrets, business strategy, the Data Privacy Framework offers no additional protection. The CLOUD Act can apply to that data regardless of whether or not it is personal data.

What Spanish law says: where public administration data must be located

The Spanish legislature had already responded to this issue before the debate surrounding the CLOUD Act reached the media. Royal Decree-Law 14/2019, of 31 October, establishes very specific obligations regarding the location of Spanish public administration information systems.

The provision amending Law 39/2015 establishes that, in relation to the identification and signature systems provided for in the Law, the technical resources required for the collection, storage, processing and management of those systems must be located within the territory of the European Union and, where special categories of data are involved, within Spanish territory.

The new Article 46 bis of Law 40/2015, introduced by the same Royal Decree-Law, is even more direct: the information and communication systems used for the collection, storage, processing and management of the electoral roll, municipal registers, tax data and data relating to users of the national health system must be located and operated within the territory of the European Union, and the data referred to may not be transferred to a third country or international organisation.

The Public Sector Contracts Law (9/2017) adds an obligation that directly affects technology providers to the Spanish public administration: companies awarded public contracts involving the processing of personal data must submit, before the contract is formalised, a declaration specifying where the servers will be located and from where the associated services will be provided.

This means that if you want to sell technology services to the Spanish public administration or to any entity that manages regulated data, you must be able to demonstrate that your servers are located in the EU. A company whose main infrastructure is located in the US cannot meet this requirement with genuine guarantees, even if it has a European subsidiary.

What exactly the European sovereign cloud is and what it guarantees

The term “sovereign cloud” is used more often than it is explained. It is not simply a physical server in Europe. It is a set of technical, contractual and operational safeguards that, when combined, ensure that data cannot leave European jurisdiction without the customer’s authorisation.

Oracle EU Sovereign Cloud is the infrastructure on which EADTrust deploys its services: Signature Manager, eArchiving and EAD Enterprise Suite. Its technical features are specific and documented in the services’ T&Cs:

Physical and logical regional isolation. Oracle EU Sovereign Cloud data centre regions are physically and logically isolated from all other Oracle regions, including the US, Asia-Pacific, the Middle East and Africa. Backups remain within the EU. Data is not moved outside the specified region.

Exclusively European personnel. Only personnel who reside in the EU, are located in the EU while providing services and are directly employed by Oracle entities within the EU may manage and support these regions. Those personnel are subject to strict confidentiality agreements and annual privacy and data protection training.

CDNs disabled. Content delivery networks (CDNs), which cache content close to the end user to speed up delivery, are disabled for the electronic archiving service. CDNs are one of the most common mechanisms through which data travels outside the contracted region without the customer being aware of it. Disabling them ensures that no data leaves the EU.

Procedures for external government requests. Oracle EU Sovereign Cloud has strict procedures for responding to data requests from government agencies located outside its data centre regions. Where possible and permitted by law, customers are notified of such requests and those that are not applicable are challenged.

EAD Enterprise Suite Protect your digital processes with European sovereign cloud infrastructure Sign, archive and manage sensitive business documents using solutions designed to maintain control over your data and processes. Signature Manager eArchiving Notice Manager Discover Enterprise Suite →

What EADTrust contractually guarantees

The T&Cs of EADTrust services (Enterprise Suite, eArchiving) include specific contractual commitments that go beyond what most cloud providers include in their terms:

Access restricted to EU-based personnel

EADTrust undertakes to restrict access to the data centres where electronic documents are archived to personnel who reside in the European Union, are located in the European Union while providing the services and are directly employed by EADTrust or associated entities under the same conditions.

Confidentiality from third-country agencies

The prohibition on disclosure to unauthorised third parties expressly includes government agencies located outside the European Union. This is not a standard clause: it is an explicit contractual commitment that distinguishes the European sovereign cloud from US cloud service contracts.

Notification and challenge of government requests

EADTrust undertakes to notify the subscriber of government access requests, including but not limited to court requests, whenever legally possible, and to oppose any request considered inapplicable or inconsistent with its position as a data processor.

Operational independence architecture

The service architecture allows the entities operating the data centre regions to do so independently, without the need to transfer the subscriber’s electronic documents outside the European Union.

No international transfers of personal data

EADTrust will not carry out international transfers of personal data for which the subscriber is responsible and to which it has access, unless previously authorised in writing by the subscriber or duly regulated.

🇪🇺 Location Data within the European Union Information, infrastructure and backups remain hosted within the European Union.
🔐 Control Strictly controlled access Knowing where the data is located is not enough: there must also be control over who can access and manage the infrastructure.
⚖️ Jurisdiction Protection against extraterritorial laws Sovereignty also means analysing which laws may compel the provider to disclose information.

Data categories for which sovereignty is critical

Not all data has the same level of exposure to the risks posed by the CLOUD Act. The risk is greater when data has strategic, commercial or legal relevance that could be of interest to US competitors, litigants or regulatory authorities.

  • M&A transaction and due diligence data. Data rooms for mergers and acquisitions contain strategic information about valuations, transaction terms and internal financial statements. If that information is held on a US platform, a US authority or litigant with the appropriate means may access it through the CLOUD Act.
  • Contracts and confidentiality agreements. NDAs, technology licensing agreements, distribution agreements and any contracts containing trade secrets are potential targets of access requests.
  • Compliance and risk documentation. Internal compliance reports, audit records, risk management documentation and regulatory files may be subject to information requests in US regulatory proceedings involving European companies.
  • Special categories of data. The GDPR requires special categories of data (health, trade union membership, racial origin, religious beliefs and biometric data) to receive additional protection. Royal Decree-Law 14/2019 establishes that such data must be stored specifically within Spanish territory when linked to public administration identification systems.
  • Banking and insurance customer data. Customer financial information governed by MiFID II, PSD2 or DORA is subject to data residency and access requirements that are incompatible with the potential scope of the CLOUD Act.

Comparison table: what each type of infrastructure guarantees

AspectAWS / Azure / Google CloudOracle EU Sovereign Cloud (EADTrust)
Infrastructure ownerUS company subject to the CLOUD ActOracle EU entities, operated by EU-based personnel
Scope of the CLOUD ActYes, a US company with servers in Europe may be subject to itMitigated, operational independence architecture with no need to transfer data outside the EU
Personnel with access to the dataThe company’s global personnelOnly EU-based personnel employed by EU entities
BackupsMay be located outside the EURemain within the EU
CDNEnabled by defaultDisabled to ensure that data does not leave the region
Customer notification of government requestsDepends on the provider’s policyExplicit contractual commitment to notify and challenge
International data transfersPossible under the service termsExpressly prohibited by contract unless authorised by the subscriber
Compliance with Royal Decree-Law 14/2019 for public administrationsCannot be guaranteedYes
QTSP status under eIDASNo, they are not qualified trust service providersYes, EADTrust is included in the EU Trusted List
🛡️ EADTrust · Sovereign cloud Do you know whether the infrastructure your company uses meets these guarantees? We can help you assess your requirements for sovereignty, archiving and the protection of sensitive digital documents.

When does data sovereignty matter most?

The honest answer is that it matters whenever the data you process has strategic, commercial, legal or regulatory relevance and your company operates in markets where US competitors, litigants or regulators may have an interest in it.

The most common situations in which data sovereignty is critical are:

  • Sensitive corporate transactions. Any M&A transaction, divestment, restructuring or joint venture in which the terms of the agreement must not be accessible to the counterparty or third parties before completion.
  • Relationships with clients in the financial and insurance sectors. Banks, insurance companies and fund managers have specific regulatory obligations concerning the residency and protection of customer data that may be incompatible with the scope of the CLOUD Act.
  • Companies with a significant presence in the US that also operate in Europe. Companies with current or potential litigation involving US parties are the most obvious targets for requests under the CLOUD Act.
  • Law firms and consultancies. Professional secrecy and the confidentiality of client information are fundamental pillars of legal practice. Storing client documents on infrastructure subject to the CLOUD Act is a risk that bar associations in several countries are already discussing.
  • Companies working with the Spanish public administration. Royal Decree-Law 14/2019 and the Public Sector Contracts Law already establish the requirement for data to be located within the EU.

Frequently asked questions about the European sovereign cloud vs the US CLOUD Act

Is the fact that the server is located in Europe sufficient protection against the CLOUD Act?

No. The physical location of the server does not determine which law applies to its contents. What determines the applicability of the CLOUD Act is the corporate nationality of the organisation managing the server. If the provider is a US company, the CLOUD Act may apply to the data even if its server is located in Frankfurt.

Is Oracle a US company? How can it provide genuine sovereignty?

Oracle Corporation is headquartered in the US, but Oracle EU Sovereign Cloud operates through European legal entities with architecture, personnel and operational procedures that are independent from the rest of Oracle. The key is operational independence: the European entities can operate the data centres without needing to transfer data outside the EU, and the procedures for responding to external government requests are designed to maximise data protection under European law.

Does the CLOUD Act also affect electronic signature services such as DocuSign?

Yes. DocuSign is headquartered in San Francisco, California. Its data, even if it may be stored on European servers under certain plans, is managed by a US company subject to the CLOUD Act. What US providers cannot guarantee, even when operating through European subsidiaries, is protection against the extraterritorial reach of that law.

What obligations does a Spanish company contracting with the public administration have regarding data location? 

The Public Sector Contracts Law requires the successful tenderer to submit, before the contract is formalised, a declaration specifying where the servers will be located and from where the services will be provided. Royal Decree-Law 14/2019 also requires identification and signature systems used in dealings with public administrations to be located within the EU.

Is the European sovereign cloud more expensive than AWS or Azure?

Not necessarily in terms of total cost of ownership. EAD Factory operates on a flat-rate model: a fixed monthly or annual cost regardless of the volume of transactions. For companies with medium or high volumes of documents, signatures or archives, the point at which the flat rate becomes competitive with the transactional models offered by AWS or Azure arrives sooner than it may seem.

Your confidential data deserves a jurisdiction that protects it

The CLOUD Act is not a theoretical risk. It is a law currently in force that has been applied, has generated case law and continues to provide US authorities with a means of accessing European corporate data. The question is not whether you trust your cloud provider, you probably do, but whether you trust that US law will never require it to hand over your most confidential data.

The European sovereign cloud is not a niche option for companies with special requirements. It is the right choice for any company that processes strategically relevant data and has genuine confidentiality obligations towards its customers, partners or the public administration. EADTrust operates exclusively on Oracle EU Sovereign Cloud. All its services: Signature Manager, eArchiving, Notice Manager and EAD Enterprise Suite, ensure that your data remains within the European Union, under protocols that no US provider can replicate even if it wants to.

Fecha de publicación:

Última actualización:

17 de August de 2026

26 de August de 2026