Skip to content

Does the US CLOUD Act reach a European company with a US parent?

A European operating company owned by a US parent is generally treated as within reach of the US CLOUD Act, because US courts ask who controls the data, not where it sits. No court has ruled on exactly this structure, and real orders are rare. Here is what the law, the case law and three government-commissioned opinions actually say.

By EU Vetted Editorial Published

Disclosure: Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

The short answer: probably yes, and no court has said so yet

A European operating company that is owned by a US parent company is generally treated as within reach of the US CLOUD Act. The reason is not the location of the servers and not the nationality of the engineers. It is that US law asks who has possession, custody or control of the data, and US courts have long held that a parent company controls what its wholly owned subsidiary holds.

Two qualifications belong next to that sentence. First, no US court has decided this exact structure for a European service provider; the case that led to the Act concerned Microsoft Corporation itself. Second, real orders for business data stored in Europe are rare. This is a question of legal exposure, and how much weight it deserves depends on what you are buying and for whom.

This page sets out what the statute says, how "control" has been interpreted, the best argument on the other side, and what changes the answer. It is an editorial explainer, not legal advice.

What the statute says, and what it does not

The CLOUD Act of 2018 added one sentence to the Stored Communications Act that matters here, 18 U.S.C. § 2713. A provider of electronic communication or remote computing services must preserve and disclose data "within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States."

Three things follow from the text.

  • Location is irrelevant. An EU data centre does not take data out of scope.
  • The addressee is a provider under US jurisdiction. The US Department of Justice has been explicit that the Act creates no new jurisdiction over foreign companies. A company that operates only in Europe and has no ties to the United States cannot be ordered to do anything.
  • The test is control. The Act does not define "possession, custody, or control". The phrase comes from decades of US discovery and subpoena practice, and that body of case law decides what it means.

How US courts read "control" between parent and subsidiary

US courts use two overlapping tests: whether the company has the legal right to obtain the data, and whether it has the practical ability to do so. The first full academic study of the phrase under the CLOUD Act, by Justin Hemmings, Sreenidhi Srinivasan and Peter Swire in the Journal of National Security Law & Policy, walks through the parent and subsidiary case directly. Its conclusion for a US parent with a wholly owned foreign subsidiary: the parent "would still almost certainly be found to have control over the subsidiary's data", because full ownership gives it the legal ability to direct how that data is used or transferred.

The direction matters. Where a subsidiary is asked for data held by its foreign parent, courts want more: interlocking management, routine access, or facts that justify treating the two as one. Where the parent is asked for what the subsidiary holds, the same study describes the courts' position as settled.

Government-commissioned opinions in Europe reach the same reading. The memorandum that Greenberg Traurig wrote for the Dutch National Cyber Security Centre and Ministry of Justice in 2022 puts the condition for staying out of reach in one sentence: "In no case can the EU Entity have a U.S. parent company, as the parent would be considered to have possession of or control over the data of its subsidiary." A 2025 opinion from the University of Cologne for the German federal administration says US courts can order US companies to instruct their foreign subsidiaries to hand over data, while noting that the reach to parent and affiliated companies is less clear-cut than the reach to the provider itself.

The best argument on the other side: "it is only a holding company"

A common structure, especially for venture-backed startups, is a US holding company with no staff that owns 100% of a European operating company. Vendors with this structure often argue that the holding cannot reach the subsidiary's customer data, and in German the argument is usually put as the absence of a Durchgriff, a right to reach through the holding into the operating company.

The argument deserves a fair hearing, and part of it is right.

  • What is right. Ownership alone is not the legal test. Courts look at control over the data, and corporate separateness counts as one factor. A pure holding company is also not obviously a "provider" in the sense of the Stored Communications Act, and that is a point a US court would have to decide.
  • What it misses. Durchgriff is a liability concept: it is about creditors reaching a shareholder through the corporate veil. The control test asks a different question. Under German company law the shareholders of a GmbH can issue binding instructions to its managing directors and can appoint and dismiss them at any time (§§ 37, 38 and 46 GmbHG). That is a legal right over the operating company, and it does not depend on the holding having employees. Other European company forms give a sole shareholder comparable powers.
  • The counterweight. Managing directors may refuse an instruction that would be unlawful, and Article 48 GDPR bars transfers to a third-country authority on the basis of that authority's order alone. The result is a conflict of laws whose outcome is uncertain.

That uncertainty is the accurate description of the position. It is not "out of reach", and it is not "certain to be compelled".

The channel people forget: the European company's own US customers

The parent is not the only route. A European provider can come under US jurisdiction in its own right if it has enough contacts with the United States. The Greenberg Traurig memorandum lists the factors US courts weigh: selling services to people or businesses in the US, marketing there, and working with US service providers. Its condition for staying out of reach includes "not selling products or services to customers in the US". The Cologne opinion goes further and says a website that addresses US customers, or simply does not exclude them, can be enough.

For a buyer this means the parent question and the customer question are separate. A European subsidiary that argues its holding company is irrelevant may still be reachable through its own US business.

How often does this actually happen?

Rarely, on the published evidence. Transparency figures cited in a 2026 white paper by the law firm CMS show Microsoft producing content for five non-US enterprise customers in the second half of 2024, none of them in the EU or EFTA, and Amazon Web Services reporting no disclosures of enterprise content stored outside the United States since 2020.

The other half of the picture is what providers are willing to promise. Asked under oath by a French Senate inquiry in June 2025 whether he could guarantee that data of French citizens would never be passed to US authorities without French consent, Microsoft France's legal director answered: "Non, je ne peux pas le garantir."

Both facts are true at once. The probability is low and the legal possibility is real. For most commercial workloads the first fact dominates. For public-sector, health, legal and defence workloads, procurement rules are increasingly written around the second, which is why frameworks such as France's SecNumCloud set limits on non-European ownership.

What changes the answer

  • No US parent. The cleanest position: a European operating company with European ultimate ownership and no US business ties.
  • Removing control structurally. A trustee or data-custodian model in which an independent European entity, not the US group, holds the legal and practical ability to release customer data. Articles of association that exclude shareholder instructions on disclosing customer data point in the same direction, but have not been tested.
  • Narrowing what can be reached. The Act is, in Greenberg Traurig's words, "encryption-neutral": it does not oblige a provider to be able to decrypt. Customer-held keys, end-to-end encryption and zero data retention reduce what an order could obtain, often to account and billing records.
  • Self-hosting. Running open-source or licensed software on infrastructure you control removes the vendor from the data path, provided hosting, access and support really are yours.

How EU Vetted records this

On every listing we record ownership and CLOUD Act exposure as two separate signals. A European operating company owned by a US parent company carries the ownership label "EU subsidiary, US parent". Its CLOUD Act exposure is recorded as material, the tier we use when a US parent or a US-owned hyperscaler sits in the core data path, and not as direct, which we reserve for operators that are themselves US-incorporated. Across the directory, 119 of 256 listings are currently at the material tier.

"Material" is an editorial risk tier, not a finding that any particular order applies or has been served. A vendor that disagrees has a right of reply on its listing, and a published structural measure that removes the parent's control over customer data would change the reading. The definitions are on how we assess, the cross-category numbers are in our CLOUD Act exposure analysis, and every listing shows its own ownership, hosting and sub-processor chain in the directory.

Sources

Frequently asked questions

Does the US CLOUD Act apply to a European subsidiary of a US company?
Generally yes, as a matter of legal exposure. The Act obliges providers subject to US jurisdiction to disclose data in their possession, custody or control wherever it is stored, and US courts treat data held by a wholly owned subsidiary as within the parent's control. No court has yet decided this exact structure for a European provider, and actual orders for EU-stored business data are rare.
Does it help if the US parent is only a holding company with no employees?
Less than it seems. Control in this context means the legal right or practical ability to obtain the data, and a sole shareholder keeps its rights to instruct and replace the subsidiary's managers whether or not it has staff. The stronger form of the argument is that a pure holding company is not itself a service provider under the Stored Communications Act, which is a point a US court would have to decide.
Is EU hosting enough to stay out of reach of the CLOUD Act?
No. The Act applies regardless of where the data is located. What matters is whether the company, or a company that controls it, is subject to US jurisdiction. A European provider with no US parent can also come within reach on its own if it has enough business contacts with the United States, for example by selling to US customers.
How often do US authorities actually obtain EU-stored business data this way?
Rarely, on the published numbers. The large US cloud providers report very few or no disclosures of enterprise content stored outside the United States in recent transparency reports. The exposure is a legal risk that buyers in regulated sectors have to account for, not a routine event.
What would take a European subsidiary of a US parent out of reach?
Removing the control: no US parent, or a structure in which the parent has no legal right and no practical ability to obtain customer data, such as an independent trustee model. Technical measures narrow the exposure without removing it: customer-held encryption keys, zero data retention, or self-hosting the software on infrastructure the customer controls.

Methodology

For every product we read the public DPA, sub-processors document, hosting region declaration, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology