Sovereign client safe. On your WordPress. Installed in 3 minutes.

News

CLOUD Act vs GDPR: where is your client data really in 2026

By Dragan Stamenkovic Updated 11 min de lecture
CLOUD Act vs RGPD : où sont vraiment vos données client en 2026

In brief: A SaaS “hosted in Europe” but published in the United States remains exposed to the CLOUD Act. Schrems II invalidated the Privacy Shield and complicated transfers. For a French firm, GDPR compliance is no longer just about server location — it also depends on the publisher’s jurisdiction. Here is the practical analysis.

“Your data remains in Europe.” This is the argument that all American SaaS companies have been feeding their European prospects since 2021. And it is technically true: their infrastructure runs on AWS Frankfurt, Azure Dublin, or Google Belgium. The lie is not in the sentence itself, but in what it implies. Because server location is only part of the equation. The other part is the publisher’s jurisdiction — and that is where the argument falls apart.

Play Pause
Play Pause
/
Unmute Mute
Settings Playback Accessibility
Announcements
Keyboard Animations
Enter Fullscreen Exit Fullscreen

The CLOUD Act, simply explained

The Clarifying Lawful Overseas Use of Data Act was passed by the U.S. Congress in March 2018, in the wake of a legal battle between Microsoft and the U.S. government regarding an email stored in Dublin. What the text says: any company falling under U.S. jurisdiction — which includes any company incorporated in the United States, as well as any subsidiary, and more broadly any entity with a substantial point of contact with the territory — must provide U.S. authorities, upon legal request, with the data it holds, regardless of where it is stored.

Specifically: if you use TaxDome, which is an American company, and U.S. authorities request your data as part of an investigation, TaxDome must comply. The fact that your servers are in Frankfurt changes nothing. The fact that your clients are French companies changes nothing. The fact that you yourself are French changes nothing.

Schrems II, the decision that changed everything

In July 2020, the Court of Justice of the European Union, following a referral by Austrian activist Max Schrems, invalidated the Privacy Shield, the framework agreement that had previously governed personal data transfers between the European Union and the United States. The reason cited: U.S. law, specifically FISA Section 702 and Executive Order 12333, permits government surveillance incompatible with European data protection standards.

“The requirements of United States domestic law, and in particular certain programs enabling access by the public authorities of that country to personal data transferred from the European Union to that country for national security purposes, entail limitations on the protection of personal data that are not framed in a manner that meets requirements substantially equivalent to those required under EU law.”

CJEU, Schrems II judgment, July 16, 2020, case C-311/18

Schrems II did not prohibit transfers to the United States. The Court upheld the validity of the Standard Contractual Clauses, but mandated that European data controllers perform a case-by-case assessment of the effective level of protection. In short: if you transfer data to an American subcontractor, you must document an impact analysis, implement additional technical measures if necessary, and be able to justify this in the event of an audit.

CLOUD Act et RGPD · les deux flux, les deux risques L’hébergement EU ne neutralise pas la juridiction de l’éditeur UNION EUROPÉENNE Cabinet français responsable de traitement Serveurs Frankfurt hébergement EU ÉTATS-UNIS Éditeur SaaS US incorporé aux États-Unis Autorités US CLOUD Act · FISA 702 FRONTIÈRE JURIDIQUE données contrat de sous-traitance contrôle opérationnel réquisition divulgation forcée des données EU Le Privacy Shield invalidé en 2020 (CJUE Schrems II) a déplacé la charge de l’analyse d’impact sur le responsable de traitement européen. Les Standard Contractual Clauses ne suffisent plus à elles seules.
Le double flux contractuel et juridique entre cabinet français, hébergeur EU et éditeur US

The 2023 Trans-Atlantic Data Privacy Framework: not the end of the story

In July 2023, the European Commission adopted a new adequacy decision for the United States, based on the Trans-Atlantic Data Privacy Framework. This agreement introduces new safeguards on the American side and, in theory, allows for easier transfers to certified organizations. This comes as an operational relief for many European companies.

However, the framework remains fragile. Max Schrems has already announced that he will challenge this new agreement, just as he did with the Safe Harbor in 2015 and the Privacy Shield in 2020. The probability of a new Schrems III ruling occurring in the coming years is not negligible. Building your compliance today on the assumption that the TDPF will last for ten years means taking a structural risk.

What this changes for a French firm in 2026

Concretely, several questions arise for any firm using a SaaS whose provider is American. The first is to determine whether the data processed is personal data within the meaning of the GDPR: for law firms, accounting firms, or brokers, the answer is almost always yes. The second is to know whether the provider has documented a post-Schrems II impact assessment: they should have done so in their updated DPA. The third is whether you, as the data controller, have conducted your own impact assessment: this is rarely the case.

In the event of a CNIL audit, this third analysis will be the one requested. The SaaS DPA is not enough — it documents the processor’s compliance, not yours. You must be able to demonstrate that you have evaluated the transfer risk, identified the necessary technical measures, and documented a reasoned decision.

yourfirm.com/clients/regulated
DUPONT vs SCI Beaulieu case · Pleading
Step 4/7 · Documents · 71% enforceable
Documents validated
12
+3 this week
Enforceable steps
5 / 7
71% enforceable
Timestamped audit
millisecond
PDF
Defense submissions.pdf · 3.2 MB
1h ago
VALIDATED
PDF
Ad litem mandate signed.pdf · 412 KB
6h ago
VALIDATED
DOC
Timestamped audit plea.docx · 244 KB
pending
PENDING

Standard Contractual Clauses are no longer sufficient

Standard Contractual Clauses, updated in 2021 by the European Commission, are the primary contractual tool for governing transfers outside the European Union. They cover the obligations of both the data controller and the processor. Many companies believe that simply signing them ensures compliance. This is a mistaken interpretation.

Schrems II explicitly stated that SCCs are not sufficient on their own: it is also necessary to assess whether the destination country offers an effectively equivalent level of protection and, if not, to implement supplementary measures. For the United States, the European Data Protection Board has published recommendations listing these measures: end-to-end encryption controlled by the sender, pseudonymization, transfer splitting, etc. Implementing these technical measures on a turnkey American SaaS is technically possible but operationally complex.

Verifying if a software provider is truly European

This is not always easy to verify. Here are a few common-sense rules. First, check the legal notice: is the company that publishes the service registered in a European country? Second, look at the control structure: is the ultimate shareholder European? A French company wholly owned by an American fund can legally remain under American influence. Third, examine the accounts: if the provider generates most of its revenue in the United States and has its actual management there, US authorities could have a substantial point of contact.

Pennylane, Yousign, Doctrine, and Tiime are French software publishers in the true sense: a French company, majority European shareholders, and French management. Clio is Canadian — close to the European Union but not European, and subject to a different legal framework than ours. TaxDome, SmartVault, and HoneyBook are American. Understanding these differences means you can stop relying on the false security of simply being “hosted in Europe.”

How Client Vault addresses this structural risk

Client Vault is published by a French company under French management, with European shareholding. The code is installed on the server of your choice — in practice, with a French host: OVH, Scaleway, Infomaniak, o2switch, or your own infrastructure. At no point do your data leave a perimeter that you control. American authorities have no point of contact to exert pressure: neither on the publisher, the host, nor the infrastructure.

This architecture renders much of the post-Schrems II impact analysis obsolete: there is no transfer outside the European Union to analyze. It is an administrative simplification that holds real economic value in the event of a CNIL audit: your GDPR file is shorter, more solid, and more defensible.

For WordPress agencies, this is also a direct sales argument. Many of your professional clients are unaware that using an American SaaS imposes additional GDPR obligations on them. Explaining the risk and offering a sovereign path that eliminates it is a value-added service you can clearly position.

Honest limitations

This reasoning does not apply to every tool. For non-critical tools — Slack for internal communication, Notion for team notes, Trello for lightweight project management — the calculation differs. The transfer risk exists, but data sensitivity is lower. Banning all American SaaS for all uses is an excessive response that is operationally unsustainable.

For critical business data, however — case files, patient records, client contracts, financial data — the risk warrants a genuine analysis. It is in this scope that the sovereign approach becomes fully relevant.

Let’s get acquainted

If you are a data controller or DPO and post-Schrems II compliance is on your mind, let’s discuss via video call. Twenty to thirty minutes to map your CLOUD Act exposure and see how a sovereign approach can simplify your impact assessment.

Frequently asked questions

What is the CLOUD Act and who is affected?

A 2018 American law that allows U.S. authorities to requisition data held by a company under their jurisdiction, regardless of server location. Any company using an American SaaS falls within this scope.

Is a SaaS hosted in Europe necessarily GDPR-compliant?

No. Server location is just one criterion among others. The publisher’s jurisdiction, the DPA, the post-Schrems II impact assessment, and additional technical measures count just as much.

What did Schrems II change in practice?

The 2020 CJEU ruling invalidated the Privacy Shield and imposed a case-by-case impact assessment for any transfer outside the EU. SCCs are no longer sufficient on their own: you must document a reasoned decision and, if necessary, add technical measures.

Is my firm at risk from the CLOUD Act?

Yes, as soon as it uses a SaaS whose publisher falls under US jurisdiction and that SaaS processes personal client data. The risk is proportional to the sensitivity of the data processed.

Are Standard Contractual Clauses sufficient?

Schrems II explicitly stated that they are not, in themselves. An assessment of the effective level of protection is required, along with additional measures where applicable. The European Data Protection Board has published detailed recommendations.

What should I do if my SaaS receives a US subpoena?

The publisher is required to comply under US law. You will generally be notified if the procedure allows it, but not always. The best protection remains structural avoidance: do not entrust critical data to an exposed publisher.

How can I verify if a publisher is truly European?

Examine the legal notices (place of incorporation), the chain of control (ultimate beneficial ownership), and the actual management. A French company owned by an American fund may remain under American influence within the meaning of the CLOUD Act.


Article written by Dragan Stamenkovic, founder of Client Vault. Article published on May 10, 2026. This article does not constitute legal advice.

{“@context”:”https://schema.org”,”@type”:”Article”,”headline”:”CLOUD Act vs RGPD : où sont vraiment vos données client”,”author”:{“@type”:”Person”,”name”:”Dragan Stamenkovic”},”datePublished”:”2026-05-10″,”dateModified”:”2026-05-10″,”publisher”:{“@type”:”Organization”,”name”:”Client Vault”},”mainEntityOfPage”:”https://clientvault.pro/blog/rgpd-cloud-act-donnees-client”}{“@context”:”https://schema.org”,”@type”:”FAQPage”,”mainEntity”:[ {“@type”:”Question”,”name”:”Qu’est-ce que le CLOUD Act et qui est concerné ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Loi américaine de 2018 permettant aux autorités américaines de réquisitionner les données détenues par toute entreprise relevant de leur juridiction.”}}, {“@type”:”Question”,”name”:”Un SaaS hébergé en Europe est-il forcément RGPD-compliant ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Non. La juridiction de l’éditeur, le DPA et l’analyse d’impact post-Schrems II comptent autant que la localisation.”}}, {“@type”:”Question”,”name”:”Qu’a changé Schrems II en pratique ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Invalidation du Privacy Shield, analyse d’impact obligatoire au cas par cas pour tout transfert hors UE.”}}, {“@type”:”Question”,”name”:”Mon cabinet est-il à risque CLOUD Act ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Oui dès lors qu’il utilise un SaaS américain pour traiter des données personnelles. Risque proportionnel à la sensibilité.”}}, {“@type”:”Question”,”name”:”Les Standard Contractual Clauses suffisent-elles ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Non en elles-mêmes selon Schrems II. Il faut évaluation du niveau de protection effectif et mesures supplémentaires.”}}, {“@type”:”Question”,”name”:”Que faire si mon SaaS reçoit une injonction américaine ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”L’éditeur s’exécute selon le droit US. Notification pas garantie. Meilleure protection : éviter de confier les données critiques à un éditeur exposé.”}}, {“@type”:”Question”,”name”:”Comment vérifier si un éditeur est vraiment européen ?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Examiner mentions légales, chaîne de contrôle actionnarial et direction effective.”}} ]}

You've read — now try it

Every method in this blog, already built in to Client Vault.

Online demo, no appointment, no sales pitch. Explore Solo and Pro at your own pace. Final purchase once your order is confirmed.