Souveränität

Do US authorities access EU data? The report from the University of Cologne, and how they are adjusting their cloud strategy.

Do US authorities access EU data? The report from the University of Cologne, and how they are adjusting their cloud strategy.

Karl Heinz Land

Karl Heinz Land

·

2

Min. Lesezeit

Greifen US-Behördenzugriff auf EU-Daten? Das Gutachten der Universität zu Köln, und wie sie ihre Cloud-Strategie anpassen

aufsatz

Bild: KI generiert mit neuland.ai HUB

The federal government investigates: what data access do US authorities have on cloud services worldwide?

The question of how secure corporate data in the cloud really is is more relevant than ever. A recent expert opinion from the Faculty of Law at the University of Cologne (March 2025, legal-opinion-on-us-legal-situation_redacted - FragDenStaat) shows: US authorities have extensive access rights to data, even if it is stored in European data centers.

The key findings of the expert opinion: US law prevails over server location

  •  US laws such as FISA, SCA, and CLOUD Act allow US authorities access to data regardless of the server location.

  • The “control” of the US company over the data is crucial, not the physical location of storage.

  • European subsidiaries of US companies are subject to disclosure obligations.

  • Section 702 FISA explicitly addresses cloud service providers and data centers. Disclosure without a judicial order is possible.

  • Executive Order 12.333 allows access to data abroad without the cooperation of cloud providers, e.g., by exploiting vulnerabilities in the infrastructure.

  • Objections to disclosure orders are hardly possible. Legal protection for European companies is not guaranteed.

  • If the provider has access to the keys, encryption does not protect.

  • “Cloud data is located in the EU” does not offer sovereign protection as long as US companies maintain control.


How does neuland.ai respond to the US cloud strategy?

For companies, a massive compliance risk arises: The extraterritorial application of US law collides with the GDPR. Even encryption is no panacea as long as the provider has control over the keys. The Cologne expert opinion emphasizes: “Cloud data is located in the EU” is not a sovereign shield. Those who rely on US hyperscalers must conduct data protection impact assessments, document technical and organizational measures, and critically review contractual clauses.

neuland.ai is well aware of these challenges from practice: We support companies in developing and operating sovereign AI applications – from architecture to implementation. Our HUB provides a stable, GDPR-compliant platform that relies on confidential computing, attestation, and key sovereignty. This way, you maintain control over your data – regardless of location and provider.

Your next step: Test sovereignty – with neuland.ai

Do you want to know how to make your cloud and AI strategy future-proof and compliant? Test our demo version or speak directly with our sales team. We will show you how to align technical sovereignty and data protection with the neuland.ai HUB – and secure your innovative strength.

Conclusion


US access rights to EU data are not a theoretical risk, but a reality. Those who rely on sustainable AI architectures need more than standard solutions. With neuland.ai, you orchestrate your data and applications sovereignly – Made in Germany, for the European medium-sized businesses.

The federal government investigates: what data access do US authorities have on cloud services worldwide?

The question of how secure corporate data in the cloud really is is more relevant than ever. A recent expert opinion from the Faculty of Law at the University of Cologne (March 2025, legal-opinion-on-us-legal-situation_redacted - FragDenStaat) shows: US authorities have extensive access rights to data, even if it is stored in European data centers.

The key findings of the expert opinion: US law prevails over server location

  •  US laws such as FISA, SCA, and CLOUD Act allow US authorities access to data regardless of the server location.

  • The “control” of the US company over the data is crucial, not the physical location of storage.

  • European subsidiaries of US companies are subject to disclosure obligations.

  • Section 702 FISA explicitly addresses cloud service providers and data centers. Disclosure without a judicial order is possible.

  • Executive Order 12.333 allows access to data abroad without the cooperation of cloud providers, e.g., by exploiting vulnerabilities in the infrastructure.

  • Objections to disclosure orders are hardly possible. Legal protection for European companies is not guaranteed.

  • If the provider has access to the keys, encryption does not protect.

  • “Cloud data is located in the EU” does not offer sovereign protection as long as US companies maintain control.


How does neuland.ai respond to the US cloud strategy?

For companies, a massive compliance risk arises: The extraterritorial application of US law collides with the GDPR. Even encryption is no panacea as long as the provider has control over the keys. The Cologne expert opinion emphasizes: “Cloud data is located in the EU” is not a sovereign shield. Those who rely on US hyperscalers must conduct data protection impact assessments, document technical and organizational measures, and critically review contractual clauses.

neuland.ai is well aware of these challenges from practice: We support companies in developing and operating sovereign AI applications – from architecture to implementation. Our HUB provides a stable, GDPR-compliant platform that relies on confidential computing, attestation, and key sovereignty. This way, you maintain control over your data – regardless of location and provider.

Your next step: Test sovereignty – with neuland.ai

Do you want to know how to make your cloud and AI strategy future-proof and compliant? Test our demo version or speak directly with our sales team. We will show you how to align technical sovereignty and data protection with the neuland.ai HUB – and secure your innovative strength.

Conclusion


US access rights to EU data are not a theoretical risk, but a reality. Those who rely on sustainable AI architectures need more than standard solutions. With neuland.ai, you orchestrate your data and applications sovereignly – Made in Germany, for the European medium-sized businesses.