Compare & price
HomeGuidesMade in US

Made in US hosting: what the CLOUD Act means for your data

Hosting in the United States, or with a US provider, places your data under US law wherever it physically sits. Here is what that implies, and when it still makes sense.

Sovereignty: where the data sits, crossed with the provider's governing lawSovereignty requires two conditions at oncePartialSovereigndata and law alignedExposedExposede.g. US provider: CLOUD Actlocal / EU lawnon-EU lawdata outside the countrydata inside the country
Sovereignty rests on two conditions met together: data on the territory and a provider subject to local law. One without the other leaves exposure.
Estimate my cost →

The US has no single federal privacy law, but a sectoral patchwork (health, finance) and state laws such as California's CCPA/CPRA. What matters for sovereignty lies elsewhere: government access powers.

The CLOUD Act, the real issue #

The CLOUD Act (2018) lets US authorities compel a provider subject to US law to hand over data, including data stored outside the United States. In other words, a US provider stays exposed even with servers in Europe. Location alone is not enough.

Transfers from Europe #

To move EU personal data to the US, you rely on the Data Privacy Framework (DPF) or standard contractual clauses. These frameworks regulate the transfer but do not neutralize the risk of US government access.

For whom, and for whom not #

Made in US fits services whose users and obligations are American, or that value proximity to the US market. For sensitive European data or a sovereignty requirement, it is the most exposed profile: a European provider and law are preferable.

FAQ #

Servers in Europe with a US provider, is that sovereign?

No. The CLOUD Act follows the provider, not just the server. A provider subject to US law can be compelled to hand over data hosted in Europe.

Does the GDPR apply to data hosted in the US?

If it concerns EU individuals, the GDPR follows the data and requires the transfer to be framed (DPF, standard clauses). But it does not override US access powers exercised on site.

Written on 1 September 2026.

From reading to comparing: relevant data centers

Equinix DC1-DC15,DC21-DC22 - Ashburn
Ashburn · 509 networks on site · certified HIPAA, ISO 22301
View the listing →
Equinix CH1/CH2/CH4 - Chicago
Chicago · 329 networks on site · certified HIPAA, ISO 22301
View the listing →
Equinix MI1 - Miami, NOTA
Miami · 328 networks on site · certified HIPAA, ISO 22301
View the listing →
Hurricane Electric Fremont 2
Fremont · 305 networks on site
View the listing →

Estimate my cost →   Compare data centers

Other guides

Guides · Expert answers →

Advertisement