r/dataprotection Data Subject 5d ago

General Discussion Data localisation ≠ Data jurisdiction

Just because your data is stored outside the US does not mean US authorities cannot reach it.

Under the US CLOUD Act, a US cloud provider can be compelled to hand over data in its control, even when that data sits on servers outside the US.

So a foreign company storing customer data on domestic servers run by a US provider may still find that data reachable through US legal process.

Where your data is stored matters less than who controls it.

2 Upvotes

2 comments sorted by

1

u/erparucca Data Subject 4d ago

FISA 702 passed in 2008. It is publicly known since 2013 that US Gov/agencies leverage that to spy over. Safe harbour (EU/US data transfer scheme) has consequently (thanks Scherms) been invalidated in sep 2015 (judgement formalized in oct 2015 by EU cour of Justice).

Then we had Scherms II ruling in July 2020, and yet here we are.

What's the point of your post?

PS "foreign company": foreign compared to which country? Rhetorical question: you may want to phrase your posts non giving for granted that every reader is based in the US.

PPS_ problem is not "US legal process" but even more "whoever has access to the data, legally or illegally" because in current ecosystems we have no way of knowing with certainty who access our data (or unknown copies of it) unless it's self-hosted.

1

u/achakez Data Subject 4d ago

Encryption changes the picture too. If the provider has no practical access to the keys a legal order for the stored data is a very different situation from one where the provider can decrypt and hand it over.