Don’t do SECURITY. Do business SECURELY.

US CLOUD Act enacted

The US Clarifying Lawful Overseas Use of Data (CLOUD) Act has become law, with implications for data held by US providers outside the US.

The US Clarifying Lawful Overseas Use of Data (CLOUD) Act has been signed into law.

What does it do?

  • US law enforcement can require US-based service providers to disclose data in their possession, custody or control, regardless of where the data is stored.
  • It creates a framework for bilateral executive agreements allowing qualifying foreign governments to request data directly from US providers for serious crime investigations.

Why it matters to UK and EU organisations: if you use US-headquartered cloud or SaaS providers, storing data in a UK or EU region does not necessarily place it beyond US legal process. Factor this into supplier risk assessments and international transfer assessments, and consider technical measures such as encryption with customer-controlled keys for sensitive data.

Source: Consolidated Appropriations Act 2018, Division V – CLOUD Act (congress.gov)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights