CLOUD Act
The Clarifying Lawful Overseas Use of Data Act, signed in March 2018, added Section 2713 to Title 18 of the US Code. It grants US law-enforcement authorities the right to compel any US-controlled cloud provider to surrender customer data regardless of where in the world that data physically sits.
The mechanism
18 USC §2713 reads: "A provider of electronic communication service or remote computing service shall comply with the obligations of this chapter to preserve, backup, or disclose the contents of a wire or electronic communication and any record or other information pertaining to a customer or subscriber within such provider's possession, custody, or control, regardless of whether such communication, record, or other information is located within or outside of the United States."
The operative phrases — "possession, custody, or control" and "regardless of whether…located within or outside" — make the extraterritorial reach explicit.
Who can be served
Any US-incorporated provider. Any US subsidiary of a foreign provider where the subsidiary has operational control. Any non-US provider with sufficient US presence (the "purposeful availment" test). In practice this includes every major cloud platform: AWS, Azure, GCP, Cloudflare, Akamai, Backblaze, Dropbox, OneDrive, GitHub.
Why hyperscaler regional storage doesn't solve it
A bucket in Frankfurt operated by AWS EMEA is still reachable by a US National Security Letter served on AWS Inc. The corporate group, not the regional subsidiary, holds "possession, custody, or control" in the §2713 sense. EU residency clauses don't change this.
What customer-managed keys do and don't do
Keys in the provider's KMS — even "customer-managed" — are operationally reachable by the provider's compute plane during reads. A court can compel that plane to perform the unwrap. CMK reduces but does not eliminate CLOUD Act exposure.
The architectural answer
For sovereignty against the CLOUD Act to be architectural rather than contractual, three things must hold: keys derived only on the customer device; data spread across multiple providers in multiple jurisdictions; no server-side API path returning plaintext. SkyeConnex enforces all three. Read the full mechanic →
Related laws
UK Investigatory Powers Act, China National Intelligence Law (2017), France Loi sur le renseignement, Russia data-localisation laws — each provides similar compelled-disclosure authority for providers under its jurisdiction.
Related terms
See also
Posts that mention CLOUD Act
Schrems II two years on: what actually changed for EU-US data transfers
The 2020 CJEU ruling invalidated Privacy Shield. Five years and one EU-US Data Privacy Framework later, the underlying problem remains. Here…
Read → Regulation · 8 min readThe CLOUD Act and why data residency isn't enough
The CLOUD Act extends US legal reach to data held by US-controlled cloud providers anywhere in the world. Choosing a Frankfurt or Toronto re…
Read → Regulation · 8 min readWhat a CLOUD Act subpoena actually looks like in practice
Most board conversations about the CLOUD Act stay abstract. Here's a concrete walkthrough of how the mechanism works — and why architectural…
Read →