GDPR + CLOUD Act in 3 sentences

GDPR is the EU data privacy law. The CLOUD Act lets US authorities seize data from US providers anywhere in the world. Together they create a sovereignty gap for EU organisations using US cloud or AI services.

Note: This is a simplified checklist. Refer to the official GDPR (EU) 2016/679 and CLOUD Act for full requirements. Consult legal counsel for compliance advice.

GDPR + CLOUD Act sovereignty checklist

Check each item that applies to your data handling. GDPR and the CLOUD Act create a sovereignty gap for EU organisations using US cloud or AI services.

Assessment progress
Not Started
0 of 8 answered
GDPR + CLOUD Act sovereignty requirements
Do you process special category data (health biometric genetic) with AI?GDPR Article 9
Article 9 makes your management body personally liable for special category data. If you process health data for insurance underwriting, biometric authentication for banking, or genetic data for HR, you are carrying Article 9 exposure. Regulators have fined organisations up to 4% of global turnover. Your board signed the contract. Your board takes the fine.
Do you have a signed Data Processing Agreement with every AI or cloud provider?GDPR Article 28
Every AI and cloud provider must sign a Data Processing Agreement. Most providers use standard terms they will not change. You cannot get audit rights or exit clauses. Your DORA third party risk register shows a gap you cannot close.
Do you conduct Transfer Impact Assessments for every cross-border data flow?Schrems II + GDPR Art. 28
Schrems II requires you to assess whether third country law undermines EU data protection. The US CLOUD Act reach means US providers cannot offer adequate protection. Your TIA will conclude the same thing every time. You still have no alternative.
Do you control sub-processors and require prior written authorisation?GDPR Article 28
Your AI provider uses sub-processors you did not approve. GDPR Article 28 requires prior written authorisation for every sub-processor. You cannot audit a provider's entire supply chain. Your DPA is already breached.
Do you know whether your data is stored in a jurisdiction with an adequacy decision?GDPR Article 48
Article 48 restricts transfers to jurisdictions without an adequacy decision. The US does not have one. Your EU data centre does not help when the provider is US headquartered. Your data is leaving the EU legal framework.
Can you prove your data is not in the possession custody or control of a US provider?CLOUD Act reach
The CLOUD Act lets US authorities seize data from US providers anywhere in the world. Your EU data centre does not protect you. Your US listed provider will comply without telling you. Your data is not private.
Do you have a documented breach notification procedure that meets GDPR Article 33 requirements?GDPR Article 33 + NIS2
GDPR requires breach notification within 72 hours. NIS2 requires 24 hour early warning for essential entities. If your AI provider suffers a breach, you may not find out in time. Your management body is liable for late notification. Fines apply.
Do you run AI and data workloads on infrastructure you own and control?Sovereignty requirement
You depend on external providers for AI and data workloads. DORA requires exit strategies. NIS2 requires supply chain control. The EU AI Act requires documented governance. You cannot demonstrate any of these when the capability is rented.
Why your board needs to see this
Article 9 special category data

GDPR Article 9 bans processing of health, biometric, and genetic data without explicit consent or a specific legal basis. If your AI touches this data and runs on US providers, you cannot show compliance.

CLOUD Act overrides GDPR

The US CLOUD Act lets US authorities compel US providers to hand over data regardless of where it is stored. Your EU data centre with a US provider does not give you data sovereignty. Schrems II confirmed this.

Fine: EUR 20M or 4%

GDPR fines reach EUR 20 million or 4% of global revenue. Your management body is liable. If your provider suffers a breach and you cannot notify within 72 hours, you carry the fine.

GDPR Article 9 intersects with the AI Act for high risk AI systems processing special category data. Check your AI Act exposure.

Worried about NIS2, DORA, AI Act or GDPR?

These regulations ask the same question. Who controls the systems you depend on. Our sovereign platform gives you the answer. You.

NIS2 Checklist Your DORA Register AI Act Checklist

No sales pressure. A clear look at your numbers, your dependencies, and your options.