· AI · 7 min read
Residency Is Not Jurisdiction
Data "stored in the EU" sounds like protection from US access. It is not, automatically. What the CLOUD Act and FISA 702 mean, and when it matters for your company.

Residency is not jurisdiction.
Where a server sits does not decide who can legally demand access to its data. Microsoft’s EU Data Boundary governs location. The CLOUD Act and FISA Section 702 govern access, and both attach to the company, not the server’s location. For most mid-market workloads, that is an insurance question. For critical infrastructure, public sector clients, and heavily regulated industries, it is a real criterion.
At the former Checkpoint Charlie in Berlin, a replica of the old sign still stands: “You are entering the American sector.” Back then, American law visibly ended at a line on the street.
With cloud data, that line no longer exists, even though many IT departments plan as if it still does. The setting in the admin center reads reassuringly: “EU Data Boundary, active.” All Copilot data, it says, sits in Frankfurt and Amsterdam. One follow-up question stays open anyway: what happens to the data in Frankfurt if a US authority asks for it?
The honest answer does not fit on a marketing slide.
What the EU Data Boundary Actually Governs
The EU Data Boundary is real. Microsoft keeps M365 and Copilot customer data within the EU and EFTA for storage and most processing steps. That is a contractual and technical commitment, not a marketing claim, and it satisfies most data protection questions.
It answers one question: where does the data sit? It does not answer a second, often more important one: who can demand its release?
The Question Residency Does Not Answer
Access rights do not follow the server. They follow the company. Microsoft, Google, and AWS are US companies. Two US laws require them to hand over data, regardless of where that data sits:
The CLOUD Act of 2018 requires US providers to hand over data in their possession or control. Server location plays no role. FISA Section 702 lets US authorities monitor communications of people outside the US when a US provider is involved. Again: company status decides, not server location.
One provider admitted this publicly. Anton Carniaux, general counsel of Microsoft France, testified under oath before the French Senate on June 10, 2025. Microsoft could not guarantee the protection of French citizens’ data from US access, not without local consent. He added that Microsoft resists unfounded requests. Such a compelled disclosure has not happened yet. He could not rule it out structurally, though.
How the CLOUD Act and FISA 702 Apply in Detail
Both laws work through the company, not the location:
- CLOUD Act: applies once data is in the “possession, custody, or control” of a US company. An EU subsidiary changes nothing as long as the US parent has legal access.
- FISA 702: targets non-US persons outside the US, but covers any “electronic communication service provider” subject to US law. Again: company status, not server location.
- GDPR Article 48: a foreign court order alone is not valid legal grounds to transfer personal data out of the EU. A US provider that complies with a CLOUD Act order risks conflicting with GDPR. That is an unresolved legal conflict, not a closed loophole.
The three frameworks contradict each other, and courts have not resolved that contradiction yet. That alone is why providers choose their words carefully on this question.
Where the Picture Lies
The obvious analogy: your files sit in a safe deposit box at a US bank’s Frankfurt branch. The bank is headquartered in the US, so a US authority could theoretically reach the box.
Here the picture lies, and not in your favor. A real safe deposit box requires physical access, often a legal assistance order recognized in Germany, and usually the bank or even the customer finds out. A CLOUD Act request needs none of that. It is an electronic request to US headquarters. It can come with a gag order. Neither you nor a German authority has to find out. The safe-deposit-box image suggests friction that often does not exist in practice.
The old Checkpoint Charlie sign was more honest about this than today’s legal reality: at least it marked the boundary.
What This Means For Your Company
For most mid-market workloads, this is not a purchasing decision. Internal collaboration, standard emails, meeting notes: if a hypothetical US access poses no real risk here, the EU Data Boundary is enough. It is insurance, not a reason to switch providers.
The question gets concrete on two criteria, and you should answer both yourself:
- Do you process data whose disclosure to a foreign authority would be regulatorily prohibited or existential for your business? This typically applies to critical infrastructure operators, public sector clients, and industries with strict confidentiality obligations.
- Would a silent disclosure to a foreign authority, one you are never notified about, cause real regulatory or contractual damage?
Two no’s, and your current setup is probably fine. One yes, and it is worth looking at EU-operated providers (IONOS, StackIT, or OVH, for example) or your own cloud account with model hosting under your own control.
One clarification often misstated in this context: Microsoft’s enterprise contracts exclude training its models on customer data. That is a separate question from jurisdiction, and the two should not get mixed up.
What You Can Do Now
You can now tell the difference between what a provider means when it advertises “your data stays in the EU,” and what that claim leaves open. The one line worth keeping: residency says where the data sits. Jurisdiction says who can demand it.
The more common data leak in daily business is a different one anyway. Employees use personal ChatGPT or Gemini accounts because no approved tool is available. They paste company data into consumer products that train on input by default. That is a bigger and more everyday risk than the CLOUD Act, and it is fixable without touching the jurisdiction question at all.
One more gap stays open here: how many of the AI licenses a company already pays for actually get used. More on that in one of the next posts in this series.
Frequently Asked Questions
What does data residency mean for AI services like Microsoft 365 Copilot? Data residency describes where data is physically stored and processed. Microsoft’s EU Data Boundary keeps customer data within the EU and EFTA for most processing steps. That is a real, contractually guaranteed boundary, but it only answers where the data sits, not who can compel its release.
Why does the EU Data Boundary not protect against US government access? The CLOUD Act and FISA Section 702 do not attach to where a server sits. They attach to the company that runs it. If the provider is a US company, a US authority can demand data regardless of whether it sits in Frankfurt or Virginia. Microsoft France confirmed this under oath before the French Senate on June 10, 2025.
When does the jurisdiction question actually matter for mid-sized companies? For most workloads at a typical mid-sized company, it is an insurance question, not a purchase criterion. It becomes concrete for critical infrastructure operators, public sector clients, and heavily regulated industries. There, EU-operated providers or your own cloud account are worth a look.
Related: Hosting or Renting Your Own AI Models and Why ChatGPT Does Not Know Your Company Knowledge.



