Skip to content
Independently verified · Quarterly re-audit
EU VETTED
INSIGHT

Picking 'European' isn't enough: where EU software still sits under the US CLOUD Act

We checked 232 EU- and privacy-first SaaS tools for US CLOUD Act exposure. Only 37% are fully clear of it, and in 6 categories, including payments, not one option is. The exposure rarely comes from the vendor being American; it comes from the stack underneath.

By EU Vetted Editorial Published Last updated DISCLOSURE Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

Only 37% of Europe's privacy-first tools are fully clear of the CLOUD Act

We assessed 232 EU- and privacy-first SaaS tools, across 25 software categories, for exposure to the US CLOUD Act: whether a US parent, US incorporation, or a core US sub-processor can place customer data under US extraterritorial reach. These are the tools European buyers reach for when they are deliberately trying to leave US software. Even so, only a minority are fully outside the law's reach.

CLOUD Act exposure Tools Share
None: EU operator, no US parent or notable US sub-processor 86 37%
Minor: a transient US sub-processor (CDN, maps); data at rest stays in the EU 58 25%
Material: US parent, or a core sub-processor is a US-owned hyperscaler 82 35%
Direct: the operator itself is US-incorporated 6 3%
Any exposure (minor + material + direct) 146 63%

So around three in five of these European alternatives still carry some US exposure (63%), and roughly one in three (38%) carry material or direct exposure: a US owner, US incorporation, or a US hyperscaler at the core of the stack. The figures are a live snapshot of our dataset, re-verified quarterly.

The company's flag is rarely the problem. The stack underneath is

The exposure seldom comes from the vendor being American. It comes from what runs underneath: hosting, sub-processors, and who provides the capital.

  • Strapi (France) and Storyblok (Austria) are European-built headless CMSs, yet both are classed material through their infrastructure and ownership chain.
  • Mollie (Netherlands), GoCardless, Klarna (Sweden), SumUp and Mangopay are European payment names, all material.
  • Cal.com is open-source and widely used in Europe, but the operating company is US-incorporated (direct).

Ownership tells the same story. Of the 232 tools, 56% are EU-owned, but 16% are EU-headquartered yet US-funded. Control, along with infrastructure choices, tends to follow the capital. Another 26% sit in non-EU but adequacy-adjacent jurisdictions such as Switzerland and the UK, and 2% are US-owned.

For a buyer, the practical lesson is simple: a European brand is not the same as leaving US jurisdiction. The sub-processor chain decides it, and it has to be read tool by tool.

Categories where no option is fully clear

In 6 of 25 categories, not a single tool we audited is free of CLOUD Act exposure:

Category Tools Fully clear Detail
Payments 13 0 9 of 13 material (Mollie, GoCardless, Klarna, SumUp, Mangopay…)
Accounting 9 0 Pennylane, sevdesk, Visma all material
Headless CMS 6 0 Strapi and Storyblok, both EU-built, material
Helpdesk and live chat 7 0 every tool carries at least a minor US sub-processor
Calendar and booking 5 0 Cal.com is direct (US-incorporated)

Payments is the sharpest case. Of the 13 European payment providers we list, none is fully clear: 9 are material. The reason is structural: the card-processing and cloud infrastructure underneath pulls even EU-owned providers into scope. It is the clearest example of the pattern in this whole dataset: European ownership, US exposure, decided downstream.

Per-category deep dives with the full per-platform tables: e-signature, cookie consent, web analytics, email marketing.

Where Europe does have clean options

The picture is not uniform. Several categories have strong fully-clear coverage:

The pattern is consistent: Europe has fully-sovereign options where the category is infrastructure-light and identity-owned (email, storage, secrets), and struggles where the category depends on deep payment rails or US-hosted platform infrastructure.

Why this matters now

Demand for this is established: IDC has identified protection from extraterritorial data requests as the leading driver of sovereign-cloud adoption in Europe. Policy is moving the same way: the EU Tech Sovereignty Package, announced on 27 May 2026, puts the question "is this actually EU-controlled?" into mainstream procurement.

What has been missing is a per-tool, per-category map of where a European buyer can and cannot actually escape the CLOUD Act today. The headline is not that Europe lacks alternatives (it often does not) but that availability is uneven, and that picking by flag alone leaves most buyers more exposed than they assume.

How we assess this

For each tool we record sourced, factual signals (operator jurisdiction, parent company, named sub-processors and hosting region) and classify CLOUD Act exposure on a four-level scale: none, minor, material, direct, each with a published definition. It is an editorial assessment based on public disclosures, not a vendor self-report, and we re-check it quarterly. Read the full method on our how we assess page.

Figures here are a live snapshot of our current dataset and shift as it grows and vendors change their disclosures. To check any individual tool, browse it in the directory: every listing carries its hosting region, sub-processor chain, CLOUD Act level and the date we last verified it. For providers we assess as carrying no material CLOUD Act exposure, start with our verified German cloud providers and French cloud providers.

Frequently asked questions

Does choosing a European tool remove US CLOUD Act exposure?
Not on its own. In our dataset of 232 EU- and privacy-first tools, 63% still carry some CLOUD Act exposure despite being European-facing, usually through their hosting, sub-processors or US funding, not because the vendor is American. Exposure has to be checked per tool, across ownership, hosting region and the sub-processor chain.
What does 'CLOUD Act exposure' mean on EU Vetted?
It is our four-level editorial classification of whether customer data could fall under US extraterritorial reach: none (EU operator, no US parent or notable US sub-processor), minor (a transient US sub-processor such as a CDN, with data at rest in the EU), material (a US parent or a core US-owned hyperscaler sub-processor), and direct (the operator itself is US-incorporated). It is based on public disclosures and re-checked quarterly.
Which software categories have no fully-clear option?
6 of the 25 categories we cover have no tool that is fully free of CLOUD Act exposure: payments, accounting, headless CMS, helpdesk and live chat, and calendar and booking. Payments is the starkest: none of the 13 European providers we list is fully clear, and 9 are classed material.
Where does Europe have genuinely clean options?
In infrastructure-light, identity-owned categories. Private email (11 of 12 clear), cloud hosting (13 of 18), file sharing (12 of 19) and password managers (7 of 11) all have strong fully-clear coverage. The gaps appear where a category depends on deep payment rails or US-hosted platform infrastructure.
METHODOLOGY

For every product we read the public DPA, sub-processors document, hosting region declaration, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology →