Taught by Humans - < tbh />

What is the US CLOUD Act? And why it should affect the tech you choose

Laura Gemmell 16 June 2026Resource

Data PrivacyAIRegulationTools

The US CLOUD Act has been in force since 2018. It is not new, and it is not a reason to panic. But if your organisation uses US-based technology providers - and most do - it is worth understanding what it means in practice.


What Is The CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) was passed by the US Congress in March 2018. It allows US law enforcement to request data from US-based technology companies - regardless of where that data is physically stored.

That last part matters. If your data is held on servers in the UK or Europe, but the company running those servers is headquartered in the US, the CLOUD Act can still apply.

The purpose of the law is legitimate: it is designed to help with serious criminal investigations, including terrorism, cybercrime, and child exploitation. It is not a surveillance free-for-all. Requests must go through legal process and meet specific criteria.


What Does It Mean For UK Organisations?

Most of the tools used in UK workplaces - cloud storage, email platforms, project management software, AI tools - are provided by US companies. That includes Microsoft, Google, Amazon, OpenAI, and Anthropic.

Under the CLOUD Act, a valid US legal order could compel any of those companies to hand over data they hold, even if it relates to UK users and is stored on UK or European servers.

There is a US-UK Data Access Agreement (in force since October 2022), which creates a formal framework for cross-border data requests related to serious crime. This is a bilateral agreement with safeguards built in. It is not a backdoor.


How Does This Interact With UK GDPR?

This is where it gets complicated, and where there is genuine legal tension.

UK GDPR requires that personal data is processed lawfully, and that access by third parties is authorised and proportionate. The ICO's guidance suggests that UK data protection law determines lawfulness - which means a US legal order does not automatically make disclosure lawful under UK law.

In practice, this creates a conflict. A US company may be legally required to hand data over under US law, while simultaneously being restricted from doing so under UK law. There is no clean resolution to this tension, and it is an area that legal experts continue to debate.

What it means for you: If you are sharing personally identifiable information with US-based tools, this conflict is worth being aware of - particularly in regulated industries where data handling obligations are high.


What This Does Not Mean

It does not mean you need to stop using US tools immediately.

The CLOUD Act is focused on serious crime investigations. The realistic risk to most UK businesses is not that the US government will request access to their customer data. The more practical concern is understanding your data flows, knowing what you are sharing and with whom, and making considered choices about which tools handle sensitive information.

As CMS Law noted in a 2026 analysis (source), there is currently no UK government policy that prevents organisations from storing or processing data with US providers. This is an area to watch, not to act on dramatically.


What You Can Do

You do not need to overhaul your tech stack. A few practical steps are worth taking:

  • Know which of your tools are US-based and what data you share with them
  • Turn off data sharing and training settings where available - most enterprise tools offer this
  • Avoid putting personally identifiable information into tools where it is not necessary
  • Where you have a genuine choice between equivalent tools, consider whether an EU or UK-based option exists
  • If you handle sensitive regulated data, speak to your data protection officer or legal team

A Note On AI Tools Specifically

Most major AI tools - ChatGPT, Claude, Gemini, Copilot - are provided by US companies and subject to the CLOUD Act. Enterprise and business plans generally offer stronger data protections, including options to disable training on your data and, in some cases, EU-based data processing.

If data sovereignty is a specific concern, it is worth knowing that EU-headquartered AI alternatives do exist. Mistral is a French AI company, founded in 2023, that offers both open-source and commercial models.


Checklist

  • Do I know which of our tools are provided by US-headquartered companies?
  • Have I turned off data sharing or training settings where available?
  • Am I putting personally identifiable information into tools where I do not need to?
  • Do I have a Data Processing Agreement in place with key providers?
  • Have I flagged this to our data protection lead or legal team?

See Also

Enjoyed this?

Subscribe to our Thoughts by Humans newsletter for more insights delivered straight to your inbox.