EU Sovereignty Score

The CLOUD Act and FISA 702 explained

The CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) and Section 702 of the Foreign Intelligence Surveillance Act (FISA) are US laws on US government access to data held by providers of communications and cloud services. They are aimed at providers, not at you as a customer. They still matter when you choose a vendor: the CLOUD Act speaks of data in the provider’s possession, custody or control, whether it is located inside or outside the United States. That makes the question who owns the vendor as relevant as the question where the data is stored.

Facts and dates last checked: 11 October 2026 · This page gives general information and is not legal advice; check the official texts for your situation and take legal advice where needed.

Timeline

  1. The CLOUD Act (Division V of Public Law 115-141) is approved. Sec. 103 adds 18 U.S.C. 2713 to the Stored Communications Act, and 18 U.S.C. 2703(h) with the comity analysis.

  2. In Case C-311/18 (Schrems II) the Court of Justice invalidates Decision 2016/1250 on the EU-US Privacy Shield. The standard contractual clauses of Decision 2010/87 remain valid.

  3. The European Commission adopts Implementing Decision (EU) 2023/1795 on the adequate level of protection under the EU-US Data Privacy Framework.

  4. The Reforming Intelligence and Securing America Act (RISAA, Public Law 118-49) is approved. Sec. 19 ends the authorities two years after enactment, that is on 20 April 2026. Sec. 25 widens the definition of electronic communication service provider.

  5. In Case T-553/23 (Latombe v Commission) the General Court dismisses the action for annulment of the 2023 decision. An appeal to the Court of Justice was lodged on 31 October 2025 (Case C-703/25 P).

  6. After a ten-day extension in April 2026 and a second one, passed on 30 April 2026, that ran until 12 June 2026, Title VII of FISA, including Section 702, expires without a further extension. The chair of the Senate Judiciary Committee confirmed on 8 June 2026 that no extension had been enacted at that point.

What the CLOUD Act does

Sec. 103 of the CLOUD Act adds 18 U.S.C. 2713 to the Stored Communications Act. A provider of electronic communication service or remote computing service must comply with the obligations of that chapter to preserve, back up or disclose data “within such provider’s possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States”. This covers the contents of communications and records or other information about a customer or subscriber.

The text of Sec. 2713 does not mention subsidiaries or parent companies. Whether data managed by a European entity falls within the “possession, custody, or control” of a US provider depends on the facts and is ultimately for a court. This page does not answer that question for any specific vendor.

Sec. 103(b) adds 18 U.S.C. 2703(h). Within 14 days of being served, a provider may move to modify or quash legal process that requires it to disclose the contents of communications. The condition is that the provider reasonably believes the customer is not a US person and does not reside in the United States, and that disclosure would create a “material risk” that the provider violates the laws of a “qualifying foreign government”. The court may modify or quash the process only if disclosure would cause such a violation and the interests of justice, on the totality of the circumstances, require it. The court weighs, among other things, the interests of the United States and of the foreign government, the likelihood of penalties for the provider, the location and nationality of the customer, and the provider’s ties to the United States. In the meantime the provider must preserve the data sought.

A “qualifying foreign government” is a foreign government with which the United States has an executive agreement under 18 U.S.C. 2523 that has entered into force, and whose laws give providers similar opportunities. This requires a determination and certification by the Attorney General to Congress. The statutory mechanism is therefore tied to such an agreement.

FISA Section 702

Section 702 is part of Title VII of FISA. On 24 April 2026 the chair of the House Intelligence Committee described it as a tool for gathering intelligence on foreign targets outside the United States. It is an intelligence authority, not an instrument for criminal legal process like the CLOUD Act. In Sec. 25 the Reforming Intelligence and Securing America Act (RISAA) widened the definition of electronic communication service provider to include “any other service provider who has access to equipment that is being or may be used to transmit …”, with some exclusions, for example for dwellings and food service establishments.

Sec. 19 of RISAA ties the end of these authorities to “two years after the date of enactment”. The Act was approved on 20 April 2024, so the statutory end date was 20 April 2026. In April 2026 Congress extended the authorities twice: first by ten days, then, on 30 April 2026, until 12 June 2026. In his remarks of 8 June 2026 the chair of the Senate Judiciary Committee said that Title VII, including Section 702, would expire on Friday (12 June 2026) and that no extension had been enacted. He warned that it is not certain whether previously issued authorisations would remain in effect.

Section 702 expired on 12 June 2026 without an extension. According to the Brennan Center, collection under certifications the FISA court approved earlier can continue until March 2027, and in September 2026 Congress was still negotiating a new reauthorisation. For a vendor choice this changes little: the CLOUD Act stays in force, and a new reauthorisation can restore the authority at any time. Check the current status on congress.gov.

Schrems II, the Data Privacy Framework and Latombe

On 16 July 2020 the Court of Justice, in Case C-311/18, invalidated Decision 2016/1250 (Privacy Shield). In the Court’s view, the US rules on access by public authorities were not limited to what is strictly necessary, data subjects had no actionable rights before the courts against the US authorities, and the Ombudsperson mechanism did not offer substantially equivalent judicial protection. The Court did find the standard contractual clauses of Decision 2010/87 valid, among other reasons because exporter and recipient must verify beforehand whether the required level of protection is respected in the third country.

On 10 July 2023 the Commission adopted Implementing Decision (EU) 2023/1795 on the adequate level of protection under the EU-US Data Privacy Framework (DPF). The decision rests on, among other things, the Executive Order of 7 October 2022 and an Attorney General regulation establishing the Data Protection Review Court (DPRC).

On 3 September 2025 the General Court, in Case T-553/23 (Latombe v Commission), dismissed the action for annulment. It confirmed that on the date the decision was adopted, the United States ensured an adequate level of protection for data transferred to US organisations. The applicant argued, among other things, that the DPRC is not independent and that the practice of the intelligence services is not circumscribed clearly and precisely enough. An appeal to the Court of Justice was lodged on 31 October 2025 (Case C-703/25 P, notice in OJ C/2025/6610). Follow the case on curia.europa.eu.

An adequacy decision and the CLOUD Act are separate matters. The first concerns the conditions for transferring personal data to a third country (Chapter V GDPR). The second concerns what US law can require of a provider.

Why the parent company matters

A data centre in Europe answers the question where data is stored. Sec. 2713, however, ties the obligation to the provider and to data within its possession, custody or control, “regardless” of location. In the comity analysis the statute also lists “the nature and extent of the provider’s ties to and presence in the United States” as a factor.

That is why the score looks not only at where the data centre or establishment is, but also at the country of the ultimate parent company. A European subsidiary of a US group can have a different exposure than its place of establishment suggests. Whether a given structure falls under the law is a legal question to be decided case by case.

What you can ask a vendor

Use the points below in tenders, questionnaires and contracts. They are meant to surface information, not to assess whether a vendor complies with a law.

  • Corporate structure: who is the ultimate parent company and in which country is it established? Which legal entity signs the contract, which entity operates the infrastructure and who has administrative access?
  • Transparency report: does the vendor regularly publish figures on government requests, broken down by country and type of request, and on the number of requests refused or challenged?
  • Contractual commitment: does the vendor commit to review requests and challenge them where there are legal grounds, and to inform you as far as the law allows?
  • Keys: who holds the encryption keys, where are they and can the vendor decrypt the data? Is a customer-held key possible, outside the vendor’s infrastructure?
  • Access from third countries: which staff or entities outside the EU have access to production systems, backups or support environments?
  • Transfers: on what basis is personal data transferred to the United States (for example DPF participation or standard contractual clauses) and what assessment has the vendor made?

How this relates to the five score dimensions

JES (jurisdiction) looks at the country where the vendor and its ultimate parent are established. A parent outside the EU means CLOUD Act exposure in the score. CKS (cryptographic key sovereignty) looks at who controls the keys. DRS (data residency) looks at where the data is and remains a separate dimension.

The score is not a legal or compliance assessment. It does not say whether a request can or cannot be executed in a specific case. For obligations under, for example, NIS2, DORA or the CRA, see the separate explainer for each law.

Want to know how your own software stack scores on digital sovereignty? Take the free assessment.

Take the free assessment

Frequently asked questions

Does the CLOUD Act apply to data in a European data centre?

Sec. 2713 applies to data within the provider’s possession, custody or control, whether it is located inside or outside the United States. Whether a specific provider or subsidiary falls under it depends on the facts.

Which data is covered?

The text names the contents of a wire or electronic communication and “any record or other information pertaining to a customer or subscriber”.

Can a provider resist a request?

Sec. 2703(h) offers, under conditions, a motion to modify or quash within 14 days for legal process seeking the contents of communications. It is tied to a “qualifying foreign government” with an executive agreement in force. Other defences are a legal question.

Is there a CLOUD Act agreement between the EU and the US?

The statute requires an executive agreement under 18 U.S.C. 2523.

Is Section 702 still in force?

Section 702 expired on 12 June 2026 without an extension. According to the Brennan Center, collection under certifications approved earlier can continue until March 2027, and Congress is negotiating a new reauthorisation. The CLOUD Act stays in force.

Is the Data Privacy Framework still valid?

Implementing Decision (EU) 2023/1795 was adopted on 10 July 2023. The General Court dismissed the action in Case T-553/23 on 3 September 2025. An appeal was lodged (C-703/25 P); check the current stage on curia.europa.eu.

Do I have to do anything as a buyer?

These laws are aimed at providers and governments, not at the customer. You can ask specifically about corporate structure, transparency report, contractual commitments and key management, and record the answers in your contract.

Sources