Regulation
CLOUD Act explained: why 'servers in the EU' is not enough
The American law that means 'EU data storage' does not always mean what you think. Five minutes of reading that explains the basis for all our origin marking.
When we mark tools as Swedish, European, or global, this is the law behind it. CLOUD Act is the most important piece of the puzzle for understanding where your data actually is.
What the law says
CLOUD Act stands for Clarifying Lawful Overseas Use of Data Act and came in 2018. The law gives US authorities the right to demand data from American companies. It requires a US court order. It does not matter where in the world the data is stored. What matters is the company, not the server.
This means in practice: an American cloud provider with a data center in Stockholm can still be forced to hand over data from there. “We store in the EU” thus protects less than it sounds. It gives better speed and simpler GDPR work. But it does not make the data inaccessible to US law.
Who is affected?
- American companies and their subsidiaries. It also applies to EU-registered subsidiaries of American groups.
- In practice, it also applies to services where an American parent company controls the data. It is enough that the company owns, holds, or controls the information.
That is why we assess tools based on where the group is based, not just where the server stands. A tool marketed as Swedish but owned by an American company therefore gets the global marking from us.
What it does NOT mean
Here is the counterpoint: CLOUD Act is not an open door where US authorities read everyone’s email. It requires a court order in a criminal investigation. For most small businesses’ ordinary data, the risk is low in practice. The question matters most for sensitive personal data, trade secrets, and the public sector. There, even a theoretical possibility of access can be unacceptable.
How to reason practically
- Non-sensitive data (marketing texts, public material): choose any supplier. CLOUD Act rarely matters.
- Customer data and personal data: consider where the supplier is based. European alternatives such as Mistral or Nextcloud remove the question entirely.
- Sensitive or classified data (healthcare, legal, public sector): choose a Swedish or European supplier with operations in the EU, for example Berget. Also read our procurement checklist.
Want to see the status for each individual tool? We have a filterable CLOUD Act status for all reviewed tools. You can also filter by origin in the explore view.
Sources
Tools mentioned
Mistral (Le Chat)
Mistral AI
France's answer to ChatGPT and one of the few European AI models in the top class, with EU data storage.
- European model in top class
- EU data storage
- Slightly weaker than the largest American ones
Best for: Those who want a powerful AI chat within the EU.
Berget AI
Berget AI
Swedish AI platform that runs language models on servers in Sweden, for those who must have full control over where data ends up.
- AI models on Swedish servers
- Full data control, no CLOUD Act risk
- More technical, aimed at developers
Best for: Companies and public sector that require AI in Swedish or on EU servers.
Nextcloud
Nextcloud
German platform for files, collaboration, chat and calendar, Europe's great alternative to Google Workspace and Microsoft 365.
- Comprehensive: files, chat, calendar, documents
- German, can run on own EU servers
- Requires server operation
Best for: Companies that want control over files and collaboration within the EU.
Related articles
This is general information, not legal advice. See How we review.