Why "No US Cloud" Is More Than a Marketing Promise
A server location in Frankfurt sounds reassuring — but what matters is whose law the operator is subject to. A sober look at the CLOUD Act, Schrems II, and the services running along in the background.
Whether it is a law firm's case files, a cultural association's membership lists, or a practice's appointment requests: as soon as a US cloud service is involved, a question arises that data-centre locations alone cannot answer — whose law is the operator subject to?
The CLOUD Act: access follows the company, not the server
The US CLOUD Act of 2018 obliges US providers to hand over data upon a government order — regardless of where the servers are located. A US corporation with a data centre in Frankfurt remains a US corporation; a "German location" changes nothing about this legal reality. On top of that come surveillance powers such as FISA Section 702, which are aimed specifically at non-US persons.
Schrems II: why this matters for the GDPR
It was these powers that brought down the "Privacy Shield" agreement in 2020: the Court of Justice of the European Union struck it down in its "Schrems II" judgment (C-311/18), because US law does not guarantee an equivalent level of protection. The successor, the "Data Privacy Framework", stands on the same shaky foundation and is already under challenge. Anyone processing specially protected data under Art. 9 GDPR is reluctant to build on that.
"Not in the background either" — the overlooked part
Many offerings look European and still pull in US services: Google Fonts, scripts from US CDNs, analytics tools, captchas, maps. Each of these requests transmits at least the visitor's IP address to the USA — the Regional Court of Munich awarded damages for exactly that in 2022. "No US cloud" is only a robust promise if it also covers sub-processors and dynamically loaded resources. A note on my own products: they load nothing from third-party servers – local fonts, no CDNs, no trackers; I verify this page by page.
The alternatives are unspectacular — and that is a good thing
The vast majority of organisations do not need a hyperscaler: German and European hosts offer web hosting, servers, and email under EU law, at ordinary prices. Software that gets by without pulling in US services simply renders the third-country question moot.
In short
The US cloud question is a matter of legal systems: access follows the company, not the server location — and the promise has to include the services in the background. Where data is well placed instead is shown in Your Server, Your Data.
Frequently asked questions
Isn't AWS with a data centre in Frankfurt "Germany"?
Physically yes, legally no: the CLOUD Act binds US companies regardless of server location.
What about Microsoft 365 and Google Workspace?
The same legal situation. For specially protected data (health, religion, legal mandates), the assessment is considerably stricter than for everyday communication.
How do I spot hidden US services on a website?
The browser developer tools (the "Network" tab) show every request to third-party servers; more convenient are checking tools such as webbkoll.dataskydd.net.
Last updated: August 2026 · This article provides general information and is not legal advice.
Ask a question — I always reply personally.
Sounds like your topic?
Let’s find out – with no obligation – where your biggest lever is.






