CLOUD Act and data sovereignty: why server location is not enough

CLOUD Act and data sovereignty: why server location is not enough

The CLOUD Act is a US law from 2018 – and yet it can affect data stored in a Swiss data centre. “Hosting in Switzerland” sounds like a protective shield. For your data sovereignty, it is a good start, but not the whole answer.

What matters is not only where a server is located, but who controls it and which law its operator is subject to. With AI tools that process contracts, customer data or internal minutes, this is not a question for the legal department alone.

Following on from our article on AI and data protection, we show what the CLOUD Act governs, how Switzerland approaches data transfers to the US and what you should ask your AI provider.

Key facts at a glance

  • The CLOUD Act obliges providers subject to US law to disclose data under their control when ordered to do so by the authorities – regardless of whether it is stored in the US or abroad.
  • For your data sovereignty, what counts is therefore not only the server location but also which law a provider is subject to.
  • The Conference of Swiss Data Protection Officers considers it possible for public authorities to place sensitive personal data in international cloud software only if the authority encrypts the data itself and the provider has no access to the key.
  • Data transfers to the US are not prohibited in principle: since 15 September 2024, an adequate level of protection has applied to organisations certified under the Swiss-US Privacy Framework (commonly known as the Swiss-U.S. Data Privacy Framework).
  • Five questions for your AI provider reveal where your data sovereignty stands.

What is the CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act, or CLOUD Act for short, was enacted in March 2018 and added a far-reaching clarification to the US Stored Communications Act.

One sentence with a long reach

Under 18 U.S.C. § 2713, providers of communication and cloud services must, when ordered, preserve or disclose content and customer data “within such provider’s possession, custody, or control”. This applies “regardless of whether such communication, record, or other information is located within or outside of the United States”.

In its 2021 report on the US CLOUD Act, the Federal Office of Justice speaks of extraterritorial effects. Its analysis suggests that such disclosure is compatible with Swiss and European data protection law “only in specific exceptional cases”.

Who the law covers – and what it does not allow

It covers providers that are subject to US jurisdiction. According to the US Department of Justice, these are not only American corporations; whether there are sufficient contacts with the US is assessed case by case.

However, the law is not a free pass. According to the Department, it does not create a new form of search warrant; such a warrant still requires probable cause and approval by a judge. Bulk data collection, it states, is not permitted either.

Why a Swiss server location is not enough

A Swiss data centre ensures that data is physically located in the country. The CLOUD Act, however, is tied not to location but to control.

What Swiss data protection officers say

This is also pointed out by privatim, the Conference of Swiss Data Protection Officers. A resolution published on 24 November 2025 states that US providers may be obliged to disclose customer data to US authorities “even if this data is stored in Swiss data centres”.

For public authorities, privatim draws a clear line: sensitive personal data, or personal data subject to a duty of confidentiality, belongs in international cloud software only if the authority encrypts it itself and the provider has no access to the key. This is an assessment for public bodies, not a law. Even so, it makes a useful benchmark.

A clear answer under oath

A hearing in the French Senate on 10 June 2025 proved revealing. A representative of a major US cloud provider was asked whether he could guarantee under oath that the data of French citizens would never be handed over on a US order without the explicit consent of the French authorities.

His answer: no, he could not guarantee that. Unfounded requests would be challenged, he said, and no such disclosure had occurred so far. This is not a quirk of one company, but a consequence of the law: anyone subject to US law must ultimately comply with a valid order.

Data to the US: what applies in Switzerland

The Swiss-US Privacy Framework

The good news: transferring personal data to the US is not prohibited in principle. Under Art. 16 of the Swiss Federal Act on Data Protection (FADP), personal data may be disclosed abroad if the Federal Council has decided that the legislation of the destination country guarantees an adequate level of protection.

For the US, this has applied since 15 September 2024, but only to organisations certified under the Swiss-US Privacy Framework. This is set out in Annex 1 to the Data Protection Ordinance. Without certification, other guarantees are needed, such as standard data protection clauses recognised by the Federal Data Protection and Information Commissioner (FDPIC).

Transfer and access are two different things

The framework governs when personal data may flow to the US. The CLOUD Act, by contrast, concerns data controlled by a provider subject to US law – even if that data never leaves Switzerland. So check both: the storage location and the law your provider is subject to.

Five questions for your AI provider

A few questions will tell you whether an AI tool is right for your data. The answers then belong in the contract.

1. Where are the provider and its parent company based?

The registered office is an important indication of which law a provider is subject to. Even data held by the Swiss subsidiary of a US group can be covered if the parent company controls it.

2. Who is involved as a sub-processor?

Ask to see the list. If a Swiss provider sources models or storage from a US service, the question comes back in through the back door. One alternative is open AI models that can be operated in Switzerland.

3. Who holds the keys?

Encryption offers the most protection when the provider does not manage the key itself. Ask who has technical access to plaintext – and in which cases.

4. Where are logs and backups kept, and who provides support?

Data is not only found in the main database. Logs, backup copies and remote maintenance access are easily overlooked. In short: data residency only counts if it applies to every copy.

5. What happens to your inputs?

Find out whether prompts and documents are used to train models. With international providers, the place of processing, the applicable law and the use of the content entered depend on the respective contractual terms.

Data sovereignty is a question of control, not of address

The CLOUD Act shows that anyone who wants data sovereignty has to think beyond the server location. Our article on data-sovereign AI covers the basics.

At BE BRAVE, we rely on our own infrastructure. All BE BRAVE offerings are operated on our own servers in Switzerland. Customer data, processing, logs and backups remain in Switzerland and are never used to train AI models.

With our own Swiss infrastructure, local processing and no training on customer data, several typical risks of international cloud and model providers do not arise – in particular unclear data residency, long chains of sub-processors and the use of inputs to improve models. Find out more under Data Sovereignty & Security.

Optionally, you can connect your own third-party systems. On activation, the data you select is transferred to the respective provider. From that point on, that provider’s data protection, security and data residency terms also apply; BE BRAVE’s Swiss hosting guarantee does not apply to copies of data in the third-party system.

This article is for general information only and does not constitute legal advice.

FAQ

Does the CLOUD Act also apply to data in Switzerland?

Yes, provided the provider is subject to US jurisdiction and controls the data. The storage location makes no difference.

Does Switzerland have a CLOUD Act agreement with the US?

No. The US Department of Justice lists such agreements with the United Kingdom and Australia. They allow authorities on both sides to request data directly from providers in the other country in cases of serious crime.

Is it prohibited to transfer personal data to the US?

No. Since 15 September 2024, an adequate level of protection has applied to organisations certified under the Swiss-US Privacy Framework. Otherwise, guarantees under Art. 16 FADP or an exception under Art. 17 FADP are required.

Does encryption protect against the CLOUD Act?

Encryption helps above all when only you hold the key – this is also what privatim focuses on. According to the US Department of Justice, the law does not create any new obligation to decrypt.

Seamless AI integration
Energy-efficient solutions
Traceable data flows and Swiss operations
headquartered in Switzerland
Immersion cooling designed for high power densities
Future-ready technology
Scalable for growth
Scalable for productive teams
Ready totransform yourAI infrastructure?