What is…
US CLOUD Act
The CLOUD Act (2018) is a US federal law that authorizes law enforcement agencies to require US companies to hand over data they store on behalf of customers — regardless of the physical location of the servers. This affects Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform and all other US companies and their subsidiaries.
The practical consequence is significant: if backup data is stored with a US cloud provider — even on a server in Frankfurt — a US authority can demand its disclosure. The provider is then faced with a conflict between US law (obligation to disclose) and EU law ( prohibition on disclosure to third parties without legal basis). European data protection authorities — including the Austrian DSB, the French CNIL and the Bavarian LDA — have ruled in several decisions that the use of US cloud services for certain data categories represents an inadequate level of protection.
The EU-US Data Privacy Framework (2023) is the attempt to resolve this conflict — but the successor to the Privacy Shield invalidated by the CJEU Schrems II ruling (2020) is legally fragile. Another Schrems ruling by the CJEU appears possible. For organizations that must ensure data sovereignty in the long term, on-premises storage or use of purely European cloud providers is the more robust strategy.
GDPR
The GDPR (General Data Protection Regulation, EU 2016/679) is the European regulation for the protection of personal data — particularly relevant for IT infrastructure in Art. 5 (principles), Art. 17 (right to erasure), Art. 28 (processors) and Art. 32 (security of processing).