Skip to content

Caught Between Two Legal Orders: Digital Sovereignty and the Law

Why a Data Processing Agreement with an American cloud provider offers less protection than you thin. And what organisations must do about it.

Roel
May 28, 202614 min read

A False Sense of Legal Security

cross European organisations, a quietly dangerous assumption has taken hold: that compliance with the General Data Protection Regulation (GDPR) confers a comprehensive legal shield for personal data. It does not. The contractual architecture that European companies erect around their data — Data Processing Agreements, Standard Contractual Clauses, transfer impact assessments — is real, carefully constructed, and genuinely meaningful within the European legal order. But it exists in a fundamentally different legal universe from the one in which many of their cloud and software vendors operate.

When a European marketing team uploads audience segments to an American advertising platform, or when a procurement department stores tender evaluations in a US-headquartered SaaS tool, or when a human resources function processes employee data through a cloud infrastructure provider headquartered in Seattle, they are not simply making a technology choice. They are placing data into a dual jurisdiction — one governed by EU law, and one governed by the legal compulsions of the United States of America. These two legal orders do not communicate with each other. In several critical respects, they are structurally incompatible.

"A Data Processing Agreement tells you how a vendor will treat your data in normal operations. It says nothing about what happens when a classified government order arrives at the vendor's headquarters."

This article maps the legal tensions that European organisations must understand in the age of digital sovereignty. It begins with the relevant statutory landscape — the CLOUD Act, FISA Section 702, Schrems II, and the EU–US Data Privacy Framework — and works through their practical interactions. It concludes with a concrete guide for marketers: which internal colleagues to involve, which questions to ask, and what foundational steps will allow an organisation to describe its data governance position with genuine rigour.


The Laws That Shape the Tension

Understanding digital sovereignty requires understanding the instruments that create the problem. These are not obscure regulatory footnotes. They are foundational statutes that shape what is legally possible when European data is processed by non-European entities.

  • US Federal Law | CLOUD Act (2018) The Clarifying Lawful Overseas Use of Data Act requires American providers to produce data in response to lawful US government orders — regardless of where the data is physically stored. A warrant served on a US-headquartered company can compel disclosure of data held on servers in Frankfurt, Dublin, or Amsterdam. Critically, this process requires no judicial review at the European level, and providers are frequently prohibited from notifying the data subject or the organisation whose data is being accessed. The Act also contains a framework for bilateral executive agreements between the US and other governments, but the EU as a whole has not entered into such an agreement.
  • US Intelligence Law | FISA Section 702 Section 702 of the Foreign Intelligence Surveillance Act authorises the US government to conduct broad surveillance of non-US persons who are outside the United States — even when their data is stored on infrastructure operated by a US company inside the European Union. Unlike a criminal warrant, FISA 702 orders operate through a specialised court (the FISA Court) whose proceedings are classified. The breadth of the authority, the lack of transparency, and the absence of equivalent rights for non-US persons were central to the European Court of Justice's reasoning in its Schrems II judgment.
  • EU Court of Justice | Schrems II (2020) In Data Protection Commissioner v. Facebook Ireland and Maximillian Schrems (Case C-311/18), the Court of Justice of the European Union invalidated the EU–US Privacy Shield framework. The Court found that US surveillance law — principally FISA 702 and Executive Order 12333 — did not provide a level of protection essentially equivalent to that guaranteed in the EU by the Charter of Fundamental Rights. Standard Contractual Clauses remain valid as a transfer mechanism, but must be supplemented by a Transfer Impact Assessment demonstrating that the receiving legal environment provides adequate protection in practice. Schrems II exposed a structural gap that no cotract can fully close.
  • International Agreement | EU-US Data Privacy Framework (2023) Adopted by the European Commission in July 2023, the EU–US Data Privacy Framework (DPF) is the third attempt to establish a legal basis for transatlantic data flows following the invalidation of Safe Harbour (2015) and Privacy Shield (2020). The DPF introduces new commitments from the US side: limitations on data collection under Executive Order 14086, the creation of an independent Data Protection Review Court for EU individuals, and enhanced oversight of US intelligence activities. These represent genuine improvements. However, the DPF remains politically fragile. Privacy advocacy groups have signalled their intention to challenge it before the Court of Justice, and a third invalidation cannot be excluded.

Why Contracts Cannot Close the Distance

The prevailing compliance reflex in European organisations is to require a Data Processing Agreement from every supplier handling personal data. This is necessary, appropriate, and mandated by Article 28 of the GDPR. But it addresses a different problem from the one that digital sovereignty concerns are actually about.

A DPA governs the contractual relationship between a data controller (typically the European organisation) and a data processor (the vendor). It specifies purpose limitations, security obligations, sub-processing restrictions, audit rights, and breach notification timelines. Standard Contractual Clauses — the standard template clauses issued by the European Commission — govern the transfer of data from the EU to a third country, and place binding obligations on the data importer.

What neither instrument governs is the relationship between the vendor and the sovereign authority of its home country. When the US Department of Justice issues a production order under the CLOUD Act, or when the National Security Agency invokes Section 702, the vendor is subject to that compulsion as a matter of US federal law. The DPA and the SCCs do not alter that legal exposure, because they are private contracts between private parties. They cannot override statute.

⚠ Critical asymmetry: Standard Contractual Clauses define how a vendor processes your data within the GDPR framework. They say nothing about what happens when a classified government order arrives at that vendor's registered office in the United States. The data processor may be in technical breach of your DPA if they comply — and in criminal breach of US federal law if they do not. The GDPR and the CLOUD Act cannot both be fully satisfied simultaneously.

The Transfer Impact Assessment as a Diagnostic Tool

The obligation to conduct a Transfer Impact Assessment (TIA) before transferring personal data to a third country on the basis of SCCs was clarified by the European Data Protection Board in its Recommendations 01/2020. A TIA requires the data exporter to assess whether the law and practice of the destination country would, in practice, prevent the data importer from complying with its contractual obligations. For transfers to the United States, an honest TIA must grapple with the existence of the CLOUD Act and FISA 702. Many organisations conduct these assessments in a cursory fashion, effectively rubber-stamping the transfer rather than genuinely evaluating the risk.

The Schrems II Legacy: Structural Incompatibility Persists

The structural tension identified by the Court of Justice in Schrems II has not been resolved by the Data Privacy Framework, even if the DPF provides an arguable basis for transfers in the present. The underlying incompatibility — between an EU legal order that treats data protection as a fundamental right, and a US intelligence architecture that treats foreign persons' data as a legitimate surveillance target — remains. What the DPF has done is create an improved institutional mechanism for managing that incompatibility, not eliminate it.

How Europe Is Responding

The European Union's regulatory response to the vulnerabilities exposed by Schrems II and the CLOUD Act has been substantial, though uneven in implementation. Several legislative and policy initiatives are shaping the landscape in which organisations must now make technology decisions.

The European Data Governance Act and Data Act

The Data Governance Act (DGA), applicable since September 2023, establishes a framework for data sharing and data intermediation services within the EU. One of its provisions explicitly addresses unlawful international government access, requiring cloud service providers to take "reasonable technical, legal and organisational measures" to prevent access to EU data that is prohibited under EU law.

The NIS2 Directive

The Network and Information Security Directive 2 (NIS2), which EU Member States were required to transpose into national law by October 2024, significantly expands the scope of cybersecurity obligations compared to its predecessor. It extends mandatory security and incident reporting requirements to a wide range of "essential" and "important" entities, including digital infrastructure providers, managed services, and public administration. Its emphasis on supply chain security and third-party risk management implicitly pushes organisations towards a more rigorous evaluation of where critical data processing occurs.

EUCS and Cloud Certification

The European Union Agency for Cybersecurity (ENISA) has been developing the European Cybersecurity Certification Scheme for Cloud Services (EUCS). The scheme has been subject to considerable political debate, notably around whether a "High+" assurance level should require cloud providers to be free of non-EU legal jurisdiction. As of 2025, the scheme is not yet finalised, but its development signals a direction of travel: European regulators are moving towards formal recognition that legal jurisdiction over a vendor is itself a material risk dimension.

"The question is no longer simply 'where is the data stored?' The question that regulators, auditors, and sophisticated clients are now asking is: 'Who has legal authority over the entity that processes the data?'"

Emerging European Alternatives

The market for European-headquartered alternatives to dominant US cloud and SaaS platforms has matured considerably in recent years. In analytics, providers such as Piwik PRO (Poland) offer GDPR-native implementations without the jurisdictional exposure of Google Analytics 4. In cloud infrastructure, providers such as IONOS (Germany), OVHcloud (France), and Hetzner (Germany) operate under EU law. In productivity software, Nextcloud and Collabora Online provide open-source alternatives to the Microsoft 365 and Google Workspace ecosystems. The gap is narrowing, and the policy tailwinds are significant.


What This Means for Data Governance

The legal tensions described above are not primarily a concern for lawyers and compliance officers. They are operational realities that affect technology procurement, vendor selection, data architecture, and client-facing representations. Organisations that treat these questions as a tick-box compliance exercise are taking on risk they have not properly characterised.

[ table ]

None of the scenarios above represent catastrophic, imminent risks in the ordinary course of operations. For most organisations, the probability of an actual government access event in any given year is low. But probability is not the only relevant measure of risk. Regulatory risk, reputational risk, and contractual risk are all real and growing — particularly as public sector and enterprise clients become more demanding in their data governance requirements.


What You Need to Know, Who to Involve, and Where to Start

If you have read this far as a marketer, you may be wondering where your responsibility begins and ends in this legal landscape. The answer is: closer to the beginning than most marketers assume. Marketing functions are, in many organisations, among the heaviest users of third-party data infrastructure — analytics platforms, CRM systems, advertising technology, email service providers, marketing automation tools. You are not a lawyer. But you are a data user, and data users carry a share of the responsibility for how data is handled.

What You Must Understand as a Marketer

  1. Your vendor list is a legal risk map. Every US-headquartered SaaS product you use to process personal data — analytics platforms, marketing automation, advertising audiences, CRM — carries CLOUD Act and FISA 702 exposure. This does not necessarily mean you must stop using these tools. It means you must know which ones you use and why.
  2. A DPA is not a complete solution. When a supplier provides a Data Processing Agreement, you are entitled to treat it as a necessary condition for working with them — not a sufficient one. The DPA governs contractual behaviour; it does not govern government compulsion.
  3. The Data Privacy Framework is fragile. The legal basis under which many US-to-EU data transfers currently occur has been legally challenged before and may be challenged again. Organisations whose entire transfer compliance strategy rests on DPF certification are exposed to significant disruption if it is invalidated.
  4. Sectoral and client obligations may exceed GDPR. If your organisation works with public sector clients, healthcare organisations, financial institutions, or any entity that has imposed data localisation or jurisdiction requirements in contractual terms, your standard marketing technology stack may already be non-compliant with those obligations.
  5. You can and should articulate your position. Digital sovereignty is becoming a competitive differentiator, particularly in B2B markets. Organisations that can credibly explain their data governance choices are increasingly advantaged in sales and procurement processes, especially in the public sector.

Which Internal Colleagues to Involve

Building a credible legal basis for your organisation's data governance position is not a marketing task alone. You will need input from several disciplines.

  • Legal & Compliance | Privacy Counsel / Data Protection Officer Your DPO or privacy counsel owns the formal legal analysis. They should be conducting Transfer Impact Assessments, reviewing DPA adequacy, and maintaining the Record of Processing Activities. Engage them early to understand which transfers are currently documented and which have not been assessed rigorously.
  • IT & Infrastructure | CISO / IT Security The Chief Information Security Officer maps the technical infrastructure. They know where data actually resides, which vendors have system access, and what encryption architecture exists. You need their view to understand whether contractual commitments match technical reality.
  • Procurement | Vendor Management / Legal Procurement Vendor selection and contract management often sit outside the marketing function. Your procurement colleagues hold DPAs, SCC schedules, and vendor certifications. They are also best placed to introduce data sovereignty requirements into future procurement processes.
  • Executive | CFO / COO / Board Sponsor Digital sovereignty decisions frequently involve cost implications, strategic positioning questions, and reputational risk. Senior executive sponsorship is essential if you want to move from assessment to action rather than filing the analysis and taking no steps.
  • Sales & Client relations | Account Management / Bid Team If your organisation bids for public sector or enterprise contracts, data governance requirements will increasingly appear in tender specifications. Your bid and account management teams can tell you whether data sovereignty is already being raised by clients or evaluators.
  • Communications | Corporate Communications Once your organisation has a credible governance position, communicating it clearly — in privacy policies, in client materials, in sector-specific documentation — becomes a communications task. Involve your communications function early so that the eventual narrative is accurate and consistent.

Logical Steps to Build a Valid Legal Foundation

The following sequence provides a practical path from awareness to a documented, defensible organisational position on digital sovereignty. These steps are cumulative; each one builds on the last.

  1. Conduct a complete vendor inventory. Begin with your marketing technology stack. List every tool or platform that processes personal data — analytics, advertising, email, CRM, marketing automation, form handling, A/B testing. For each, record: vendor name, headquarters jurisdiction, data storage location, transfer mechanism, and what categories of personal data are processed. This is your risk surface.
  2. Identify which transfers have documented Transfer Impact Assessments. Work with your DPO to understand which of your US-headquartered vendor relationships have a completed TIA on file. Where TIAs are absent or outdated (pre-2021 assessments should be reviewed against current guidance), flag these as a priority for remediation.
  3. Classify your vendors by jurisdictional exposure. Create a tiered classification. Tier 1: European-headquartered, no US parent or secondary jurisdiction exposure. Tier 2: US-headquartered or US-parented, with a completed TIA and valid transfer mechanism. Tier 3: US-headquartered, transfer basis unclear or TIA incomplete. Tier 3 requires action.
  4. Evaluate European-jurisdiction alternatives for high-risk tools. For the tools that carry the highest data sensitivity or the greatest volume of personal data, evaluate whether European-jurisdiction alternatives exist that are functionally adequate for your needs. This is not a commitment to switch — it is a documented consideration that demonstrates genuine engagement with the risk.
  5. Develop a written data sovereignty policy. Work with legal, IT, and procurement to produce an internal policy document that describes your organisation's approach to vendor jurisdiction, transfer safeguards, and acceptable residual risk. This document becomes the internal reference point for future procurement decisions and the basis for client-facing representations.
  6. Incorporate sovereignty criteria into procurement processes. Work with your procurement function to embed data jurisdiction questions into vendor selection templates. For any new vendor that will process personal data, the standard evaluation should include: jurisdiction of the vendor's ultimate parent, applicable government access laws, transfer mechanism and TIA requirement, and availability of EU-domiciled alternatives.
  7. Document your position, and keep it current. A written, dated, version-controlled record of your organisation's data governance analysis — including your assessment of key vendors, the legal frameworks applied, and the risk determinations made — demonstrates to supervisory authorities, clients, and auditors that your organisation is engaging in good faith with a genuinely complex area of law.

This article is intended for informational purposes only and does not constitute legal advice. Organisations should seek qualified legal counsel in their jurisdiction when making data governance decisions. Laws and regulatory guidance referenced reflect the position as of 2025.

Did you enjoy this article?

Recommend it — Standard Reader surfaces well-loved writing to more readers across the network.

Across the AtmosphereDiscussions