What does the CLOUD Act do?
The CLOUD Act, enacted in 2018, amends U.S. law to clarify how law enforcement accesses data stored by U.S. tech companies, regardless of server location.
It compels providers to disclose customer data on U.S. servers or abroad via warrants, while allowing challenges if foreign privacy laws conflict, and enables bilateral agreements with other nations for reciprocal access to combat serious crimes.
Data access: U.S. authorities can demand stored communications globally from American firms, addressing pre-cloud era gaps in the Stored Communications Act.
Provider safeguards: Companies may contest orders through "comity" analysis weighing U.S. interests against foreign laws.
International deals: Authorizes executive agreements with qualifying countries, bypassing some mutual legal assistance delays for crimes like terrorism or cybercrime.
Implications for Cloud services: In contexts like Atlassian Government Cloud, it reinforces U.S. jurisdiction over data of U.S.-based providers, even with U.S.-only residency, heightening compliance focus for global users.
Related content
What is the difference between Jira Server vs Jira Cloud?
Jira Server and Jira Cloud differ primarily in hosting, management, and feature delivery, with Server being an on-premises solution now end-of-life and Cloud as Atlassian's hosted SaaS offering.
What is the difference between GDPR and Cloud Act?
GDPR is an EU-wide privacy statute that limits what organisations may do with individuals’ personal data and how that data can be transferred outside the bloc.
The CLOUD Act is a U.S. criminal-procedure law that expands when U.S. authorities may compel cloud providers to hand over data—even if the bits sit in Europe.
One protects data subjects; the other empowers investigators. Because both reach across borders, they can collide, forcing companies to balance EU obligations to withhold data against U.S. orders to disclose it.
GDPR and the CLOUD Act pursue opposite goals—one to shield personal data, the other to expose it for legitimate policing—yet both claim global reach. Companies operating trans-Atlantically must design governance that can survive being pulled in both directions at once.
