Deskpro Blog

What Is the US CLOUD Act? A Guide for Help Desk Buyers

Written by Madeline Jacobson | July 31, 2026

Summary:

  • The US CLOUD Act lets the US government compel any vendor under US jurisdiction to hand over data it controls, even data stored in EU or other overseas data centers.
  • Data residency isn't data sovereignty: choosing an in-region data center doesn't protect your ticket data if the vendor (or its sub-processors, including AI providers) is US-based.
  • Help desks are high-risk because tickets accumulate PII, attachments, and sensitive customer context.
  • The most reliable way to eliminate exposure is custody: self-hosted, private cloud, or sovereign cloud deployment means the vendor can't turn over data it can't access.

If you’re evaluating help desk software and your security team tells you that your help desk needs to be hosted in your organization’s region, you should ask a follow-up question: Is it just the data center that needs to be in-region, or is it the vendor’s headquarters too?

The reason this matters is because of the US CLOUD Act, a federal law that makes data stored by US-based companies subject to US jurisdiction, no matter where that data is physically stored. In other words, a help desk vendor who is subject to US jurisdiction could be legally compelled to turn over data it holds on your behalf, even if every byte sits in a Frankfurt data center. That means you risk losing control of your customer’s personally identifiable information (PII), file attachments, and other sensitive support ticket data.

If you’re unsure how (or if) the CLOUD Act impacts your help desk buying decision, this guide is for you. We’re covering what the law does, where it conflicts with GDPR, why data residency alone won’t protect you from it, and what questions you should ask any help desk vendor before you sign.

What is the US CLOUD Act?

The Clarifying Lawful Overseas Use of Data (CLOUD) Act is a US federal law signed in March 2018. The full text of the law is a 32-page read, but the point that matters to help desk buyers is this: technology companies under US jurisdiction can be compelled by the US government to turn over electronic communications and data stored on the companies’ servers and data centers overseas.

The law grew out of a real dispute. In the Microsoft Ireland case, the US government sought emails that Microsoft stored in a Dublin data center, and Microsoft argued a US warrant couldn't reach data held abroad. The case went all the way to the Supreme Court before Congress resolved the question by passing the CLOUD Act, which made clear that storage location is no shield when the provider itself is subject to US jurisdiction.

The CLOUD Act applies broadly to cloud infrastructure providers, email platforms, AI companies, and SaaS vendors. If a company is incorporated in the US, operates a US subsidiary, or otherwise does enough business to be subject to US jurisdiction, the CLOUD Act applies.

Data residency vs. data sovereignty: Why choice of data center location isn’t enough

If you’ve already spent some time researching help desk vendors, you’ve probably seen that some of the major players offer a choice of data center location (often for an add-on fee or locked behind a higher-tier plan). But when those vendors are based in the US, letting you choose a data center in your region isn’t enough to get around the CLOUD Act. That’s because what really matters is data sovereignty, not just residency.

What data residency actually means

Data residency is a geographic commitment: your data will be stored and processed in a specific physical location, such as a data center in the EU or United Arab Emirates. Residency matters for latency, for certain regulatory requirements, and for keeping data within a preferred legal region under normal operations. What residency does not address is which government can compel access to that data. A server's postal address says nothing about the legal obligations of the company operating it.

What data sovereignty means and how it determines CLOUD Act exposure

Data sovereignty is all about whose laws govern the data. Under the CLOUD Act, the answer follows the provider. A US-headquartered vendor, or the US subsidiary of a foreign vendor, can be ordered to produce data it controls anywhere in the world. Your ticket data can live in Dublin on EU-owned infrastructure and still be reachable by a US warrant, because the warrant targets the company, and the company can access the data.

The tension between the CLOUD Act and GDPR

The fact that we’ve included multiple EU examples above isn’t an accident. While there are data privacy laws all over the world, the General Data Protection Regulation (GDPR) is a big one that’s relevant to organizations in the European Union and European Economic Area along with businesses outside those regions that handle EU data. There’s also significant tension between GDPR and the CLOUD Act that’s worth understanding.

Article 48 of the GDPR essentially says a company can’t hand over EU personal data to a non-EU court or authority just because that authority demands it. For that demand to be enforceable, it has to be based on an international agreement, such as a mutual legal assistance treaty (MLAT).

The CLOUD Act is not one of these international agreements. It's a domestic US statute, and it explicitly requires US providers to comply with valid orders even when compliance conflicts with foreign law.

This puts a technology provider that receives a CLOUD Act order for EU personal data in a difficult position. If it complies, it risks violating GDPR. If it doesn’t, it risks contempt proceedings in the US.

There is one set of exceptions. The CLOUD Act's executive agreements create recognized legal channels between the US and partner countries (currently just the UK and Australia). For data covered by those agreements, the cross-border conflict is reduced because a formal international framework exists. For EU data, no such agreement is in force, and the tension remains.

Why all this matters for help desk buyers

Support leaders should understand the basics of the CLOUD Act because, in many parts of the world, it will impact their software buying decision. A help desk is one of the most data-dense platforms in your stack, and if you’re subject to data privacy laws like GDPR, you have to make sure you’re taking the steps necessary to protect your data. If you don’t, you risk your compliance and security team vetoing your help desk before you make the purchase.

The data at risk in a help desk

Think about what accumulates in a help desk over five years of operation. Every support ticket is a conversation between your organization and a customer or employee, and those conversations contain names, email addresses, account details, screenshots, contracts, medical or financial context, attachments, and internal notes your agents never expected anyone outside the team to read. A single legal demand against your vendor could, in principle, reach all of it.

Who’s most exposed

The organizations with the most at stake are the ones already operating under strict data rules: healthcare providers handling patient information, banks and financial services firms bound by confidentiality obligations, law firms holding privileged material, government agencies with sovereignty mandates, and EU-based organizations subject to GDPR.

In a Deskpro survey of over 220 support and IT leaders, 81% of respondents said security is "very important" or "critical" when selecting support technology, and 78% involve their IT or security teams in the final decision. For teams in regulated industries, data sovereignty is often a big part of what their security teams look at because of the CLOUD Act.

Is your help desk vendor subject to the CLOUD Act?

If you determine that data sovereignty is one of the security and compliance requirements for your help desk, you should ask your prospective vendors the following five questions:

  1. Where is the vendor legally headquartered? A US company, or the US subsidiary of a foreign company, is subject to US jurisdiction, and your data will be too if it’s stored in the vendor’s cloud.
  2. Where are its sub-processors and infrastructure partners incorporated? A European vendor running entirely on US hyperscaler infrastructure has not removed US jurisdiction from the picture. If its AI features are powered by an AI provider based in the US, it’s the same story. Request the list of sub-processors (i.e., any third parties that would touch your data).
  3. Does the vendor publish a transparency report? Disclosure of government data requests, even if the number is zero, signals that the vendor has thought about how it would respond.
  4. What deployment models are available? A cloud-only vendor holds your data by definition. A vendor offering on-premise or private cloud deployment can put the data in your custody instead.
  5. What contractual protections exist? Look for a data processing agreement (DPA), standard contractual clauses (SCCs), and a commitment to notify you of government requests and challenge overbroad ones where legally possible.

How to reduce CLOUD Act exposure when choosing a help desk

Knowing that data sovereignty is a requirement will shorten your list of help desk providers to review. As you build your shortlist, you’ll want to focus on three key areas: deployment flexibility, vendor transparency, and contractual safeguards.

Deployment flexibility: Sovereign cloud, private cloud, and on-premise

The CLOUD Act reaches data in a US provider's possession, custody, or control. But if the provider lets you deploy your help desk in your own sovereign environment–whether that’s in a sovereign cloud, a regional private cloud, or on-premise–you avoid CLOUD Act exposure. The vendor can’t turn over your data to the US government when they don’t have access to it. Your data stays in your security perimeter, and you meet your organization’s data sovereignty requirements.

Vendor transparency and sub-processor disclosure

Your exposure is the sum of every company that touches your data, so map the full chain. A credible vendor will tell you which sub-processors handle customer data, where each is incorporated, and what happens when one changes. If you intend to use the AI features in the help desk, pay particularly close attention to your AI model options. Does the vendor lock you into a model operated by a US-based company, or are you able to connect your model of choice? If you can use a sovereign or private AI model, you can use the help desk’s AI features without your data leaving your security perimeter.

Contractual safeguards: DPAs, SCCs, and notification clauses

Contracts can't override the law, but they shape how a vendor behaves under legal pressure. A strong DPA with SCCs establishes your data protection terms. A notification clause commits the vendor to telling you about government demands unless a gag order prevents it, and a challenge clause commits it to contesting requests that are overbroad or improperly served. Ask to see these terms during procurement, while they're still negotiable.

How Deskpro approaches data sovereignty and security

Deskpro is a US-headquartered company, so we'll be direct: our cloud service operates under the same US legal framework as every other American software vendor. What we offer instead is deployment flexibility, which lets you choose who holds your data.

Organizations that need to keep data out of vendor custody can deploy Deskpro on-premise, in a regional private cloud, or in a sovereign cloud, where the full platform, including workflow automation and AI features powered by the model of your choice, runs inside your own security perimeter. We also provide the security architecture teams in regulated industries need: ISO 27001 and SOC 2 Type II certification, encryption at rest and in transit, role-based access controls, and comprehensive audit logging. Support teams in government, healthcare, and financial services choose Deskpro because our platform lets them keep their data under their control.

Choosing a help desk platform with data sovereignty in mind

The CLOUD Act doesn’t take US technology off the table altogether. But it does require you to ask sharper questions during procurement: where a vendor is incorporated, who its sub-processors are, what its contracts commit it to when a government comes calling, and whether you can take custody of your own data if your compliance requirements demand it. Regulated organizations that ask those questions early avoid expensive migrations later.

If data sovereignty is part of your help desk criteria, explore how Deskpro handles security across cloud and self-hosted deployments, or talk to our team about your specific compliance requirements.

FAQs

What is the CLOUD Act in simple terms?

The CLOUD Act is a 2018 US law that lets American law enforcement, with a valid warrant or court order, compel US companies to hand over data they control, even when that data is stored in another country. It also created a framework for the US to sign agreements with allied governments so their investigators can request data directly from US providers. The key principle: legal access follows the company that controls the data, not the location of the server.

Does the CLOUD Act apply to companies based outside the US?

It can. The law applies to any provider subject to US jurisdiction, which includes foreign companies with US subsidiaries, offices, or substantial US business operations. A European vendor with a significant American presence may be within reach of a CLOUD Act order. That's why vendor due diligence should cover corporate structure and sub-processors, and why "we're a European company" is the beginning of the conversation rather than the end of it.

Is the CLOUD Act the same as the Patriot Act?

No, though they're often conflated. The Patriot Act, passed in 2001, expanded US surveillance and investigative powers broadly in the wake of 9/11. The CLOUD Act, passed in 2018, is narrower: it amended the Stored Communications Act to clarify that US legal process reaches data stored abroad and to enable cross-border data agreements with partner countries. Both concern government access to data, but they are separate laws with different scopes and mechanisms.

Does hosting data in the EU protect it from the CLOUD Act?

Not by itself. EU hosting determines where your data physically lives, while the CLOUD Act follows who controls it. If your help desk vendor is a US company or is otherwise subject to US jurisdiction, its EU-hosted data remains reachable by US legal process. EU hosting still has value for latency, regulatory alignment, and day-to-day data handling. For protection from US jurisdiction specifically, custody matters more than geography, which is where self-hosted deployment comes in.

Does GDPR override the CLOUD Act?

Neither law overrides the other; they're laws from different governments that can point in opposite directions. GDPR Article 48 says demands for EU personal data from outside the EU only count if they come through an official agreement between governments, while the CLOUD Act tells US providers to comply with valid US orders regardless. A provider caught between them faces legal risk on both sides. For buyers, the practical lesson is to structure deployments so the conflict never lands on your data.