data protection

US CLOUD Act vs EU Law: The Data Privacy Framework Survives Its First Court Test as US Cloud Giants Build Sovereign Versions

American cloud companies run most of Europe’s computing, and American law can reach their data. The CLOUD Act of 2018 lets US authorities require a provider to hand over data it controls, wherever it’s stored. In June 2025 a French Senate inquiry asked Microsoft France’s legal director a simple question. Could he guarantee that data about French citizens held by Microsoft would never be handed to US authorities without French approval? Anton Carniaux answered: “No, I cannot guarantee it.”

That answer is the whole EU–US data problem in five words. European law says personal data may only leave the EU for countries with adequate protection. The two have collided in court twice already. A third case is now on its way to the EU’s highest court.

The framework, for now

The current legal bridge is the EU–US Data Privacy Framework, adopted in 2023 after the Court of Justice struck down its two predecessors. A French MP, Philippe Latombe, challenged it at the EU General Court. He argued the new US Data Protection Review Court isn’t truly independent and that US intelligence still collects data in bulk.

On 3 September 2025 the General Court dismissed his case. Latombe appealed to the Court of Justice on 31 October 2025, as case C-703/25 P. His four grounds cover the review court’s independence, bulk collection, automated decision-making and data security. No hearing date has been published.

So the framework stands, for now. Companies transferring data under it are relying on a decision the same court has twice overturned in earlier forms. That’s the background risk every European compliance team prices in.

The industry answer: sovereign clouds

The big US providers have responded by building European versions of themselves.

AWS launched its European Sovereign Cloud on 15 January 2026, with its first region in Brandenburg. It’s run by a new parent company and German subsidiaries, operated only by EU residents, backed by more than €7.8 billion of investment in Germany. Local Zones are planned for Belgium, the Netherlands and Portugal.

Microsoft announced a Sovereign Public Cloud and Sovereign Private Cloud in June 2025, after pledging 40% more European data-centre capacity over two years. Google works through partners. In France, the Thales-controlled S3NS earned the government’s top SecNumCloud qualification at the end of 2025. In May 2026 Thales and Google announced a similar Thales-controlled sovereign cloud in Germany, in preview.

The design logic is the same each time: put EU staff and EU legal entities between the US parent and the data. Whether that fully closes the CLOUD Act gap is a legal question that no court has settled. Carniaux’s answer suggests the providers themselves don’t claim it does.

The government answer: the Cloud and AI Development Act

Brussels proposed its own response on 3 June 2026. The Cloud and AI Development Act aims to triple EU data-centre capacity in five to seven years, with acceleration zones for new sites. For public-sector cloud it sets four assurance levels. Non-EU providers would need level three or above and to be based in an approved jurisdiction, one with an EU adequacy decision and extra protections.

That last condition is the sharp one. If the United States counts as an approved jurisdiction because of the Data Privacy Framework, US providers can compete for sensitive public contracts. If the Court of Justice strikes the framework down again, they may not. The proposal is now with Parliament and the Council.

The older attempt at the same idea, the EU cloud security certification scheme known as EUCS, has been stuck since 2024 over exactly this question: whether the top level should require European headquarters. It hasn’t been formally adopted.

How it compares

Europe’s approach is legal: adequacy decisions, certification levels, court challenges. The US approach is jurisdictional: American companies, American law, wherever the servers are. China’s is territorial: data stays in China. Each of the three treats cloud as infrastructure that the state must be able to reach.

The difference is that Europe depends on the other side’s companies. Hence the sovereign clouds, which are a commercial workaround to a legal standoff. They’ll hold as long as the courts let them.