Home›Guides›Sovereignty

Sovereignty

How can a business protect itself from the CLOUD Act?

A business protects itself from the CLOUD Act by choosing who holds its data, not merely by moving its servers. The 2018 US law allows a US authority, in the course of a proceeding, to require a provider subject to US jurisdiction to produce the data that provider holds or controls, including when that data is stored outside the United States. It does not create automatic access to European datacenters.

Updated October 202610 min readOfficial sources cited

What the law does, and what it does not do

The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) amends US law on stored communications. Three limits help avoid misreadings.

  • It targets a provider subject to US law. A French company that operates its own servers is not, on that basis alone, the recipient of a US order.
  • It presupposes a proceeding. It is not a permanent copy of European email services sent to a US administration.
  • It does not disappear because the disk is in Amsterdam, Dublin or Paris, as long as the US provider has possession or control of the data.

The real risk is therefore narrower than is often claimed, and more lasting: a targeted request, addressed to the provider, in the course of a proceeding.

The law also provides for agreements between governments to govern certain cross-border requests. This aspect does not change the purchasing question: who, in your chain, is a US provider with control of the data?

How an order applies

The order is addressed to the provider and covers the data in its possession or control. The customer then depends on what the provider does with the request.

Under 18 U.S.C. § 2703(h), the provider may move to quash or modify the order if it believes that the customer is not a “United States person”, does not reside in the United States, and that disclosure would create a material risk of violating the laws of a “qualifying foreign government”. It has 14 days after service to do so.

A “qualifying foreign government” is a country that has concluded an executive agreement with the United States that has entered into force. The US Department of Justice publishes agreements with the United Kingdom, signed on 3 October 2019, and with Australia, signed on 15 December 2021. No agreement is in force with the European Union; EU–US negotiations on electronic evidence resumed in 2023. The Department’s page mentions no agreement with France.

The consequence: the challenge mechanism specific to § 2703(h) presupposes such an agreement. A French business should not count on this remedy as an established protection.

Why the location of the disk is not enough

The law’s criterion is control, not geography. Take an industrial SME with two sites that has chosen a European data region with a US software vendor. Its messages are stored in Europe. But the company that administers the service and can restore a mailbox remains American. Faced with an order, the storage region does not change the question: are these data under its control?

On 10 June 2025, before the French Senate commission of inquiry on public procurement, the director of public and legal affairs of Microsoft France was asked whether he could guarantee under oath that the data of French citizens entrusted to Microsoft via Ugap would never be transmitted, following an order from the US government, without the explicit consent of the French authorities. His answer: “No, I cannot guarantee it, but, once again, it has never happened yet.” Both halves of the sentence matter. The first describes the legal framework; the second, the practice observed by the company.

The conflict with the Data Protection Act 2017

Mauritian law approaches the question from the other end. Under section 36 of the Data Protection Act 2017, a transfer of personal data outside Mauritius is permitted only with demonstrated appropriate safeguards, the explicit consent of the individual, or where it is necessary in one of the cases provided for by law, such as the performance of a contract or a legal obligation.

In Mauritius, the Data Protection Act 2017 is enforced by the Data Protection Office, headed by the Data Protection Commissioner (section 4). It applies to controllers and processors established in Mauritius or using means of processing there, and a controller not established in Mauritius must appoint a representative there (section 3(5)). No one may act as a controller or processor without being registered with the Commissioner (section 14).

A US provider serving Mauritian clients may therefore find itself caught between two legal systems: a US order on one side, and on the other a Mauritian law that governs any transfer of data out of the country. Section 36 does not settle this conflict on the provider’s behalf. For the buyer, the issue is concrete: ask how this provider handles such a request, whether it challenges it, and whether it informs the customer when the law allows.

The basis for transfers outside Mauritius

A service from a US software vendor generally involves transfers outside Mauritius: storage in a region located outside the country, support access, escalations. Each must rest on one of the bases in section 36: demonstrated appropriate safeguards, the explicit consent of the individual, or a necessity provided for by law. The Act also requires appropriate security measures, including pseudonymisation and encryption (section 31), and notification of a breach to the Commissioner without undue delay, no later than 72 hours after becoming aware of it (section 25).

These rules govern transfers within the meaning of Mauritian law. They do not take a US provider out of the scope of the CLOUD Act. A prudent business documents this legal basis and plans what to do if it falls. This monitoring belongs in the documentation of processing activities, not in a slogan.

What actually reduces exposure

Choose the operator. If the company that bills, backs up and administers the service is European, and does not depend on a US group for possession of the data, a CLOUD Act order is not addressed to it. This is the main lever.

Read the list of subcontractors. A European operator that sends emails, backups or support to a US subcontractor reintroduces a provider subject to US law. The list of subcontractors is part of the protection. The common mistake: checking the main hosting provider and forgetting the ticketing tool or the backup.

Distinguish the software vendor from the operator. Using software whose vendor is American is not the same as entrusting the data to that vendor. Zimbra is published by Synacor, in the United States. When it is installed and backed up by a European hosting provider, in that provider’s facilities, the operational holder of the mailboxes is the hosting provider. The contract must prohibit the vendor from accessing content, and state who applies the patches.

Treat support as access. A technician who opens a mailbox or a backup is processing data. Where that technician is located, the record of the access and its reason matter as much as the location of the disk.

Encrypt with a key you hold, where the service allows it. Encryption at rest with a key held by the provider protects against disk theft. It does not prevent the provider from reading the data to deliver the service, nor from producing them if compelled to. Encryption with a key that only you hold changes the picture for content. On a full suite, it does not always cover every stage: some stages require the service to process the content, and encryption there is then in the hands of the software vendor or the operator (filtering and quarantine, indexing for search, document processing in a CRM). The right questions are therefore: at which stages does the provider manage the key, how long do the data remain there, and who can access them? The scope has to be read.

Keep an exit. Regular exports, open formats, and a restore test. Legal protection without a recoverable copy is incomplete.

What is not enough

  • Announcing “Europe-hosted” or “Mauritius-hosted” without naming the operator. The criteria that matter are detailed on the page definition, criteria and limits.
  • Signing a DPA and considering the matter closed. The DPA organises data protection obligations between the customer and the provider. It does not take a US software vendor out of US law.
  • Believing that a Microsoft or Google data region cancels out the CLOUD Act. These regions describe where certain data are stored and processed. The vendor remains American.
  • Requiring SecNumCloud for an SME’s email service when the real need is a European operator. SecNumCloud is a qualification of an offering, useful when the tender or the nature of the data requires it. The ANSSI catalogue states which offerings hold it. Klytic does not hold it. Nor should OVHcloud’s Zimbra email offering be confused with the OVHcloud infrastructure offerings that are qualified for named scopes.

Nor is the CLOUD Act the only criterion. A business with data of low sensitivity, which depends on advanced Microsoft 365 or Google Workspace features and documents the basis for its transfers, can reasonably stay. The choice becomes questionable when it has not been made: no one has named the holder of the data or planned an exit. The pages European cloud or American cloud and Microsoft 365 or a sovereign solution explore this trade-off.

A step-by-step approach

  1. List the processing activities: email, files, CRM, telephony, backups, support.
  2. For each one, name the company that holds the data.
  3. Exclude or regulate those that are US providers with control of the content.
  4. Write down the list of subcontractors and review it every year.
  5. Test an export.

Example: a 25-person accounting firm that goes through this exercise often finds that the email service is clearly identified, but that the e-signature tool, file sharing with clients or the backup were added without checking the operator. These are the lines to regulate first.

Microsoft 365, Google Workspace and Klytic are compared on the page Microsoft 365, Google Workspace or Klytic; the general criteria, in what is a sovereign cloud.

Frequently asked questions

Is a datacenter in France enough to rule out the CLOUD Act?

No. The law targets the provider subject to US law that has possession or control of the data, wherever they are stored. The location of the disk remains useful, but it does not answer the question of the operator.

Can the provider challenge an order?

§ 2703(h) provides for a motion to quash or modify, within 14 days of service. This remedy presupposes an executive agreement in force with the country concerned. The US Department of Justice page mentions no agreement with France, and none is in force with the European Union.

Does the Data Protection Act 2017 protect my data?

It sets a Mauritian rule: a transfer outside Mauritius requires appropriate safeguards, the explicit consent of the individual or a necessity provided for by law (section 36). It places the US provider in a conflict of laws, without resolving it on the provider’s behalf.

Where Klytic stands

Dedicace Software, a French company, operates Klytic. Hosting is provided in any geographical area corresponding to the applicable jurisdiction, subject to the availability of the required services, for example in Europe or Mauritius, or on the customer’s servers. The email software is Zimbra, published in the United States: protection comes from the operator and the operating contract, not from the vendor’s nationality. The software vendor has no access to the data and cannot compel Klytic to hand them over.

The data are held entirely by the customer, or by Klytic on the customer’s behalf, in a geographical area that falls under the applicable jurisdiction. They are encrypted natively, or according to the customer’s choice. The key is held by the customer, or kept in the customer’s account, and Klytic has no access to it.

Some stages rely on encryption managed by Klytic, because the service has to process the content: emails and documents processed in the CRM, and emails placed in quarantine by the filtering, which are encrypted in the database. The exception is the email service: if the customer has not enabled encryption with its own key, its emails are stored encrypted with a key managed by Klytic. Conversely, emails encrypted by the customer can be indexed for search if the customer has given its key to its email client.

In transit, emails are encrypted from the moment they pass through Klytic MTA filtering, then between the platform’s servers, and on every access to the mailbox: webmail, email client or mobile, from the company network as well as from outside. Only one stage does not depend on Klytic: sending to another domain. Encryption is maintained there when the recipient’s server supports it, which is often the case; otherwise, the message makes this last journey in clear text, as with any email provider. To guarantee confidentiality all the way to the recipient in every case, the message itself must be encrypted (S/MIME or PGP).

Access to files is tightly restricted through limited access rights, and a connection audit raises an alert in the event of a fraudulent attempt. As with any provider, the contract must describe this possession, this encryption and their scope. See also the page hosting and sovereignty.

Klytic does not hold the SecNumCloud qualification. None of these statements constitutes general immunity: a French operator remains subject to French law.

This page describes a general framework. It does not constitute legal advice.

Sources

Accessed in October 2026.

  • 18 U.S.C. § 2713, text introduced by the CLOUD Act: disclosure of data in the provider’s possession or control, including outside the United States. govinfo
  • 18 U.S.C. § 2703, including subsection (h): the provider’s motion to quash or modify, 14-day time limit, concept of a qualifying foreign government. govinfo
  • U.S. Department of Justice, CLOUD Act Resources: agreements with the United Kingdom and Australia, negotiations with the European Union. justice.gov
  • Data Protection Office, “The Data Protection Act 2017” (Act No. 20 of 2017). dataprotection.govmu.org Sections 3(5), 4, 14, 25, 31 and 36: scope, authority, registration, breach notification, security, transfers outside Mauritius.
  • French Senate, commission of inquiry on public procurement, record of the week of 9 June 2025 (hearing of 10 June 2025). senat.fr
  • ANSSI, SecNumCloud FAQ. cyber.gouv.fr
  • Zimbra, FAQ (software vendor: Synacor). zimbra.com/faqs

A French operator for your data

Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.

Talk to an advisor →

Klytic hosting

Welcome offer

30-day free trial, assisted migration

No-commitment trial offer. An advisor will call you back to understand your needs and prepare your Klytic space.