Hosting your data in the EU is an important part of data protection, but it does not automatically tell you which laws may apply to the provider handling it. Under the US CLOUD Act, certain service providers subject to US jurisdiction can be required to produce data they control, even when that data is stored outside the United States.
For European businesses, that makes data residency only one part of the picture. To understand your actual data sovereignty, you also need to look at provider jurisdiction, cloud infrastructure, subprocessors and the safeguards surrounding access to your data. This article explains what the CLOUD Act means in practice, how it differs from GDPR and what to consider when choosing a cloud or SaaS provider.
TL;DR – Article summary
- The CLOUD Act can require certain providers subject to US jurisdiction to produce data they control, even when that data is stored outside the United States.
- EU data hosting is important, but it does not automatically mean your data is outside the reach of foreign legal obligations.
- GDPR and the CLOUD Act regulate different things, and one does not simply override the other.
- European businesses should assess data residency, provider jurisdiction, cloud infrastructure, subprocessors and security safeguards together.
- Customer feedback data can contain personal information, so feedback platforms should be included in the same data-governance and vendor due-diligence processes as other SaaS tools.
- Data sovereignty goes beyond server location: the key questions are where is the data, who controls it, and which laws and safeguards apply?
In this article, we’ll cover:
- What is the CLOUD Act?
- Does EU data hosting protect you from the CLOUD Act?
- GDPR vs the CLOUD Act: How do they differ?
- Why the CLOUD Act matters when choosing SaaS providers
- What does the CLOUD Act mean for customer feedback data?
- Data residency vs data sovereignty: Why European businesses are looking beyond hosting
- What should you ask your cloud or SaaS provider?
- How Mopinion approaches European data hosting
- EU hosting is only one part of data sovereignty
- Frequently asked questions
What is the CLOUD Act?
The CLOUD Act (Clarifying Lawful Overseas Use of Data Act) is a US law that governs access to electronic data held by certain service providers in the context of criminal investigations. Adopted in March 2018, it clarified that providers subject to US jurisdiction may be required to disclose data within their possession, custody or control in response to valid US legal process, even when that data is stored outside the United States.
This distinction matters for European businesses. A company might store its data entirely within an EU data centre, but the physical location of that data does not necessarily determine whether the provider operating the service is subject to US legal obligations. In other words, where your data is hosted and which jurisdiction your provider falls under are two separate questions.
The CLOUD Act also introduced a framework that allows the US to establish bilateral agreements with qualifying foreign governments for cross-border access to electronic evidence. As
Eurojust explains in its overview of the CLOUD Act, the legislation was designed to improve how US and foreign authorities obtain data held by service providers during criminal investigations.
This does not mean US authorities have unrestricted access to data stored in Europe. Requests still involve legal processes and applicable safeguards. But for European organisations assessing their cloud and SaaS providers, the CLOUD Act highlights why looking only at the location of a data centre does not provide the full picture. Provider jurisdiction matters too.

Does EU data hosting protect you from the CLOUD Act?
Not necessarily. Hosting your data in the EU can offer important advantages for data residency, privacy and compliance, but the physical location of a server alone does not determine whether the CLOUD Act may apply to the provider handling that data.
The CLOUD Act focuses in part on whether a service provider subject to US jurisdiction has possession, custody or control of the requested data. As the
US Department of Justice explains, this obligation can apply regardless of whether the data itself is stored inside or outside the United States.
Consider a European business that chooses to have its customer data stored in a data centre in Frankfurt. If the service is operated by a provider subject to US jurisdiction, storing the data in Germany does not by itself remove every potential US legal obligation affecting that provider.
This is why it helps to distinguish between three related concepts:
- Data residency describes where your data is physically stored.
- Provider jurisdiction concerns which laws and legal obligations may apply to the company processing or controlling that data.
- Data sovereignty looks more broadly at who ultimately controls the data and infrastructure, which jurisdictions apply and what safeguards are in place.
Importantly, this does not mean that US authorities have unrestricted access to EU-hosted data. The CLOUD Act concerns disclosure through applicable legal processes, not open or automatic access to data held by US providers. And when personal data protected by the GDPR is involved, European data protection requirements do not simply disappear.
The European Data Protection Board (EDPB), for example, has clarified that a request from a third-country authority does not automatically provide a lawful basis for transferring personal data from the EU. Organisations must assess whether the disclosure and resulting transfer comply with the GDPR, including the requirements of Article 48 and Chapter V. For businesses evaluating their technology stack, this is also why choosing GDPR-compliant customer feedback tools involves looking beyond a simple EU-hosting claim.
So, EU data hosting is important, but it is only one part of the picture. European businesses evaluating cloud and SaaS providers should consider not only where their data is stored, but also who controls it, which jurisdictions those providers fall under and what legal and technical safeguards surround access to it. Mopinion’s own data and security overview is an example of the kind of information buyers should review when assessing how a provider handles data residency, infrastructure and security.
GDPR vs the CLOUD Act: How do they differ?
GDPR and the CLOUD Act regulate different things. GDPR is a European data protection law that governs how personal data is collected, processed, stored and transferred. The CLOUD Act concerns circumstances in which certain service providers subject to US jurisdiction can be required to produce electronic data in response to valid US legal process.
Put simply, GDPR is primarily about protecting personal data, while the CLOUD Act is about lawful access to electronic evidence.
GDPR and the CLOUD Act have different purposes
The GDPR sets rules for how organisations handle personal data. It covers areas such as lawful processing, transparency, data minimisation, security, individual rights and international data transfers.
The CLOUD Act has a different purpose. It concerns access to electronic evidence for law-enforcement investigations and clarifies when certain providers subject to US jurisdiction may be required to produce data they control.
The two laws therefore address different questions, even though they can sometimes apply to the same data.
They also apply to different organisations
GDPR applies to organisations processing personal data where the Regulation falls within its territorial scope. This can include organisations both inside and outside the EU.
The relevant CLOUD Act provisions concern electronic communication and remote computing service providers that are subject to US jurisdiction.
This distinction matters because simply using a data centre in Europe does not necessarily tell you which legal obligations apply to the company operating the service.
Data location is treated differently
GDPR places specific conditions on transferring personal data outside the EU and EEA. Organisations need an appropriate legal basis and, where applicable, safeguards for international transfers.
Under the CLOUD Act, however, a provider subject to US jurisdiction may be required to produce data within its possession, custody or control even when that data is physically stored outside the United States.
That is why data residency and provider jurisdiction should not be treated as the same thing.
What happens when a foreign authority requests EU personal data?
This is where the interaction between GDPR and the CLOUD Act becomes particularly important.
According to the European Data Protection Board’s guidance on Article 48 GDPR, a request from a third-country authority does not, by itself, provide a legal basis for processing personal data or automatically justify transferring that data outside the EU.
Where GDPR applies, organisations still need to consider the appropriate legal basis for disclosure and the rules governing international data transfers.
Article 48 also addresses decisions from foreign courts or administrative authorities requiring personal data to be disclosed. Such decisions are not automatically recognised or enforceable in the EU simply because they were issued by a foreign authority. Applicable international agreements and GDPR requirements still have to be considered.
Does GDPR override the CLOUD Act?
Not quite. It is misleading to think of the relationship as a simple contest in which one law automatically overrides the other.
A provider subject to US jurisdiction may face obligations under valid US legal process, while European data protection requirements may simultaneously govern whether and how personal data can be disclosed or transferred.
The important takeaway is:
A CLOUD Act request does not make GDPR disappear, and GDPR does not make the CLOUD Act irrelevant.
For European organisations, this is another reason to look beyond data-centre location when assessing a SaaS provider. Understanding which entities process your data, which jurisdictions they may fall under and how they handle government access requests gives you a clearer picture of the legal environment surrounding your data.
Why the CLOUD Act matters when choosing SaaS providers
The CLOUD Act adds another consideration to SaaS procurement: where your data is hosted is important, but so is who provides the service and which jurisdictions may apply to them.
For European businesses, this means a vendor assessment should go beyond a simple promise of “EU hosting”. A provider may store customer data entirely within Europe while still being subject to legal obligations arising outside the EU.

Look beyond the location of the data centre
When evaluating a SaaS provider, it helps to look at the entire chain of companies involved in processing your data.
For example, the SaaS company you contract with may use a separate cloud infrastructure provider, which may in turn rely on other subprocessors. These relationships can affect where data is processed, who may have access to it and which jurisdictions need to be considered.
This does not mean that using a US provider automatically makes a service non-compliant with GDPR. Nor does choosing a European provider automatically guarantee compliance. Instead, organisations need to understand the actual setup and safeguards of each service they use.
The European Data Protection Board has also highlighted that the possibility of third-country law affecting a processor’s ability to comply with GDPR should be considered before entering into contracts with processors or subprocessors.
What should you check before choosing a SaaS provider?
When assessing a cloud or SaaS solution, consider questions such as:
- Where is the provider headquartered? This can help you understand which jurisdictions may be relevant.
- Where is your data stored and processed? Look beyond the provider’s headquarters to the actual infrastructure used.
- Which cloud providers and subprocessors are involved? Check who else can process or access your data and where those companies operate.
- How does the provider handle government data requests? Look for policies explaining how requests are assessed, challenged where appropriate and disclosed to customers.
- What security measures protect your data? This can include encryption, authentication, access controls, logging and data deletion processes.
- What contractual protections are available? Review the Data Processing Agreement (DPA), subprocessor documentation and mechanisms for international data transfers.
- Can you choose your hosting or infrastructure setup? Some providers offer European organisations greater control over where and how their data is hosted.
These questions form part of a wider vendor assessment. As we explain in our guide to choosing feedback software, the right platform should fit not only your functional requirements but also your organisation’s security and data-protection needs.
Ultimately, the CLOUD Act does not mean European businesses should automatically rule out every SaaS provider with links to the US. It does mean that provider jurisdiction deserves a place alongside data residency, security and GDPR compliance when assessing your technology stack.
The more clearly a provider can explain where your data goes, which companies are involved and how access is governed, the better equipped you are to assess the actual risks around your data.
What does the CLOUD Act mean for customer feedback data?
The CLOUD Act does not create special rules specifically for customer feedback. However, feedback stored or controlled by a service provider subject to US jurisdiction could potentially fall within the scope of a valid legal demand in the same way as other electronic data held by that provider. The CLOUD Act applies based on factors such as provider jurisdiction and possession, custody or control of the data, rather than whether the information happens to come from a survey or feedback form.
For European CX teams, this matters because customer feedback is part of your wider customer-data ecosystem. It deserves the same attention to data residency, access and provider jurisdiction as other customer information.
Customer feedback can contain personal data
A feedback response might look simple at first glance. A user gives a rating, selects an answer and leaves a comment.
But depending on how the feedback form is configured, the data collected could also include:
- Names and email addresses
- Customer or account identifiers
- Information connected to an identifiable user
- URLs or other contextual information
- Technical or online identifiers
- Open-text comments containing personal information
- Screenshots or other visual feedback containing user data
Under GDPR, personal data is broadly defined as information relating to an identified or identifiable living person. Separate pieces of information can also become personal data when combined in a way that makes someone identifiable. The European Commission’s explanation of personal data provides examples of how broad this definition can be.
Open-text feedback deserves particular attention because users control what they write. Even if you do not explicitly ask for personal information, someone might include their name, order details, contact information or other identifying information in their response.
This is one reason privacy should be considered when designing and managing digital feedback programmes. As we have discussed previously in our guide to GDPR and digital feedback collection, organisations should understand what feedback data they collect, where it is stored and who can access it.
Your feedback platform is part of your data infrastructure
The CLOUD Act therefore gives CX and procurement teams another reason to look beyond the feedback form itself.
Your feedback platform may rely on cloud infrastructure providers and subprocessors to store or process the responses you collect. Those relationships can influence where the data resides, which companies can access it and which jurisdictions may be relevant.
Again, this does not mean customer feedback held by a provider with US ties is automatically accessible to US authorities. A CLOUD Act disclosure requires applicable legal process, and the US Department of Justice states that the Act does not authorise indiscriminate or bulk collection.
The practical question for a European organisation is instead: Do you know who ultimately stores, processes and controls your feedback data?
What should CX teams pay attention to?
You do not need to treat every customer comment as highly sensitive information. But you should understand the data flowing through your feedback programme.
That means considering:
- Which personal data your feedback forms actually collect
- Whether you can minimise unnecessary personal data collection
- Where feedback data is stored and processed
- Which cloud providers and subprocessors are involved
- Who can access the collected data
- How long feedback is retained
- How your provider handles government access requests
- Whether masking, anonymisation or other privacy controls are available
GDPR’s data-protection-by-design principle also encourages organisations to limit personal-data processing to what is necessary and to build safeguards into processing from the outset. You can read more in the European Commission’s guidance on data protection by design and by default.
Ultimately, feedback data should not sit outside your organisation’s wider data-governance strategy. If you are already asking where customer, CRM or analytics data is hosted and which providers have access to it, those same questions should extend to the platform collecting the voice of your customer.
Data residency vs data sovereignty: Why European businesses are looking beyond hosting
Data residency tells you where your data is stored. Data sovereignty looks at the bigger picture: who controls that data, which laws may apply to it and how much control your organisation has over the underlying infrastructure.
For European businesses, this distinction is becoming increasingly important. Choosing an EU data centre can help meet residency requirements, but it does not necessarily answer questions about provider ownership, jurisdiction, subprocessors or potential access under foreign laws such as the CLOUD Act.
This broader focus is also reflected at EU level. The European Commission’s Cloud Sovereignty Framework assesses cloud sovereignty across areas including legal, operational, technological and supply-chain considerations rather than focusing on data location alone.
For businesses choosing SaaS platforms, the takeaway is simple: EU hosting remains important, but true data sovereignty requires looking beyond the server location. Provider jurisdiction, infrastructure dependencies, data access and the safeguards surrounding that access should all form part of the assessment.
What should you ask your cloud or SaaS provider?
When evaluating a cloud or SaaS provider, it helps to go beyond a general claim of “EU hosting” and ask questions that reveal where your data is stored, who can access it and which legal frameworks may apply.
A practical due-diligence checklist could include:
1. Where is our data stored?
Ask whether your data is stored in the EU, EEA or another region, and whether that location can change depending on the service or infrastructure used.
Data residency is an important starting point, but it should not be the end of the assessment.
2. Which company actually controls and processes it?
Find out which legal entity provides the service and which organisations are involved in processing your data.
A European data-centre location does not necessarily tell you which company ultimately controls the infrastructure or which jurisdictions may apply to it.
3. Which cloud infrastructure providers do you use?
Many SaaS platforms rely on third-party infrastructure providers for hosting and processing.
Ask which cloud providers are involved and whether customers can choose between different hosting or infrastructure options. This can give your organisation greater visibility and control over where its data is processed.
4. Which subprocessors have access?
Review the provider’s subprocessor list to understand which third parties may process your data, what services they provide and where they operate.
Pay particular attention to subprocessors located outside the EU or subject to additional jurisdictions.
5. How do you handle government data requests?
Ask whether the provider has a clear process for assessing requests from law-enforcement or government authorities.
Useful questions include whether requests are reviewed for legal validity, challenged where appropriate and disclosed to affected customers when legally permitted.
6. How is data protected?
Jurisdiction is only one part of data protection. You should also understand the technical and organisational safeguards surrounding your information.
Look for measures such as:
- Encryption in transit and at rest
- Role-based access controls
- Strong authentication
- Audit logging
- Data masking or anonymisation
- Retention and deletion controls
- Regular security testing and monitoring
These protections can help reduce unnecessary access and limit exposure even when data is stored within approved regions.
7. What contractual documentation is available?
Finally, review the documentation supporting the provider’s security and privacy claims.
This can include:
- A Data Processing Agreement (DPA)
- An up-to-date subprocessor list
- Security and compliance documentation
- International data-transfer mechanisms
- Data-retention and deletion policies
- Incident-response procedures
The aim is not to find a provider that can promise zero legal risk. Instead, look for one that can clearly explain where your data is, who is responsible for it, which parties may access it and what safeguards are in place.
For European businesses, that level of transparency is increasingly becoming an important part of choosing a cloud or SaaS provider.
How Mopinion approaches European data hosting

For European organisations, having visibility into where feedback data is stored and who provides the underlying infrastructure is increasingly part of vendor due diligence. Mopinion approaches this through EU data residency, a multi-cloud infrastructure strategy and documented security and data-processing controls.
European data residency and cloud choice
Mopinion stores customer data within the European Union by default. Its multi-cloud strategy currently includes both Amazon Web Services (AWS) and Scaleway, giving organisations different infrastructure options while keeping customer data hosted in Europe.
AWS data is stored in European data centres by default. For organisations that specifically prioritise European cloud infrastructure and digital sovereignty, Mopinion also partners with Scaleway, a French cloud provider, to offer an option hosted in Europe by a European company.
This gives customers another factor to consider alongside functionality when choosing their feedback setup: not only where the data is stored, but also who provides the underlying cloud infrastructure.
Security and access controls
European hosting is only one part of Mopinion’s approach to protecting customer data. Mopinion maintains ISO 27001 certification and operates an Information Security Management System (ISMS) covering its security processes and controls.
Its documented access-management measures include strong authentication for privileged users, access logging and reviews, automated user provisioning and separate development, testing, acceptance and production environments. Customers can also use security options such as SSO and MFA for their accounts.
Mopinion also provides privacy-focused features including data masking for visual feedback and automated data anonymisation, helping organisations reduce unnecessary exposure of personal information within their feedback programmes.
Transparency around subprocessors
Understanding which third parties are involved is equally important. Mopinion publishes a subprocessor overview identifying providers involved in processing customer data, their functions and the locations in which data is processed.
The current subprocessor documentation states that written DPAs are in place with external subprocessors and that current operations maintain data processing within the EU/EEA. It also outlines the transfer mechanisms used where third-country transfers may apply.
For organisations reviewing Mopinion from a data-sovereignty perspective, the broader takeaway is that European data residency is supported by visibility into cloud infrastructure, subprocessors, access controls and security practices. You can find the full details in Mopinion’s Data and Security overview.
EU hosting is only one part of data sovereignty
Knowing that your data is hosted in Europe is important. But it does not tell you everything about who may control it, which jurisdictions may apply or what safeguards surround it.
For European businesses, a stronger assessment looks at three questions together:
Where is the data? → Who controls it? → Which laws and safeguards apply?
That means considering data residency alongside provider jurisdiction, cloud infrastructure, subprocessors, access controls and the legal processes that may affect the organisations handling your data.
For customer feedback data in particular, this broader view matters because feedback can form part of your wider customer-data ecosystem and may contain personal information. Looking at hosting location alone therefore gives only a partial picture.
By evaluating data residency, provider jurisdiction, infrastructure and security together, European organisations can develop a much clearer understanding of their actual data sovereignty and make more informed decisions when choosing cloud and SaaS providers.
Ready to see Mopinion in action?
Want to learn more about Mopinion’s all-in-1 user feedback platform? Don’t be shy and take our software for a spin! Do you prefer it a bit more personal? Just book a demo. One of our feedback pro’s will guide you through the software and answer any questions you may have.
Frequently Asked Questions
The CLOUD Act is a US law that governs access to electronic data held by certain service providers for law-enforcement purposes. It clarified that providers subject to US jurisdiction may be required to produce data within their possession, custody or control, even when that data is stored outside the United States.
Not necessarily. Hosting data in the EU determines where that data is stored, but it does not automatically determine which laws may apply to the provider controlling or processing it. Provider jurisdiction, cloud infrastructure and subprocessors should also be considered.
No. GDPR and the CLOUD Act regulate different things, and one does not simply override the other. GDPR governs the processing and transfer of personal data, while the CLOUD Act concerns lawful access to electronic evidence. Where both may be relevant, organisations need to consider their obligations under each framework.
No. The CLOUD Act does not provide unrestricted or automatic access to EU-hosted data. Disclosure requires applicable US legal process. Where GDPR applies, European rules governing personal-data disclosure and international transfers may also need to be considered.
Data residency describes where data is physically stored. Data sovereignty is broader and considers who controls the data, which jurisdictions and laws may apply, which infrastructure providers are involved and what safeguards surround access to it.
Businesses should ask where their data is stored and processed, which legal entity provides the service, which cloud providers and subprocessors are involved, how government data requests are handled, what security measures are in place and which contractual protections support GDPR compliance.
Potentially. Customer feedback is electronic data and may contain personal information such as names, email addresses, account identifiers or identifying details in open-text comments. If that data is controlled by a provider subject to relevant US jurisdiction, the same CLOUD Act considerations can apply as with other customer data.
No. Choosing European infrastructure can reduce certain dependencies and provide greater control over data location, but data sovereignty also depends on factors such as provider ownership, jurisdiction, subprocessors, access controls, security measures and contractual arrangements.
