What the CLOUD Act means for UK businesses using US software
Your data might sit in Dublin, but if the provider is American, a US law can compel its release wherever it's stored. The CLOUD Act is a control question most founders have never heard of, and it's worth an hour of your attention.
Your customer data sits in a data centre in the countryside, on a well-known cloud platform, covered by UK and EU law. Reassuring. It's also not the whole story. If the company running that data centre is American, there's a US law that can compel it to hand your data to US authorities, wherever in the world the servers happen to be. It's called the CLOUD Act, and most business owners have never heard of it.
This isn't a story about spies or mass surveillance. It's a plainer, more useful point: you probably control your business data less than you assume, and the CLOUD Act is the clearest example of the gap.
What the law actually does
The CLOUD Act, passed in the US in 2018, says that an American technology provider must produce data it holds when properly ordered to by US authorities, even if that data is stored on servers in another country. So the physical location of the data centre, the thing vendors love to reassure you about, isn't the deciding factor. What matters is who ultimately controls the company holding your data. If that's a US business, US legal reach can follow the data across the border.
What that means in practice is worth sitting with. Your customers' data, and your own legal obligations under UK law, are quietly exposed to a foreign jurisdiction you never actively chose to enter. Your information ends up governed by another country's legal, democratic, and cultural norms, and those may not be ones you'd have signed up to. You didn't decide that; the choice of supplier decided it for you.
For most UK businesses this is a low-impact risk, and that's fine. The point isn't to panic; it's to know. A risk you've assessed and accepted is a decision. A risk you've never heard of is a blind spot, and blind spots are what turn into nasty surprises during due diligence, a security review, or a contract with a client who does care.
What to actually do
Start by knowing which of your suppliers are US-controlled. For the everyday tools, that's usually most of them, and that's a reasonable trade for the quality on offer. The exercise worth doing is matching your most sensitive data (customer records, legal files, anything covered by a client's confidentiality terms) against where it actually lives and who ultimately controls that supplier.
Then read the data terms for those few sensitive systems, not all of them; you're looking for who the provider is and what they commit to. Where the sensitivity justifies it, UK and EU-based alternatives exist and are worth weighing, though they're not automatically better and often less mature. This is a judgement, made system by system, not a reason to rip everything out and start again.
Then follow the chain one step further, to your suppliers' suppliers. The company you pay almost certainly hands your data to its own sub-processors, and their jurisdiction counts just as much as your supplier's. Most vendors list these somewhere in their terms; run the same check on them. That's often where the real exposure sits, one layer down from where anyone thinks to look.
The goal isn't sovereignty for its own sake. It's to be able to answer, when a serious client or investor asks, exactly where your important data and your metadata sits and who can reach it. Most businesses can't. Being one that can is quietly worth a great deal.
Not sure where your most sensitive data actually lives, or who controls it? Book a call and we'll map it with you before someone else asks the question.
Robin Carswell
More on
Where does your data actually live?
When you sign up to a SaaS tool, your data goes somewhere. Most UK businesses haven't decided where — and clients in legal, healthcare, and financial services will ask.