EU bans American cloud for sensitive data: what this means for your organisation
By Cyso Cloud on
Last updated on
The European Commission is drawing a hard line: sensitive government and healthcare data will soon no longer be allowed to be stored on servers belonging to Microsoft, Google or Amazon. Although a concrete deadline has yet to be set, the direction is irreversible. For municipalities, healthcare institutions and financial organisations, now is the moment to take action.
In this article, we explain what the new EU cloud legislation involves, what risks the American Cloud Act brings with it, and how your organisation can make a controlled switch to GDPR-compliant cloud hosting within the EU.

A turning point in European cloud policy
On 13 May 2026, Dutch IT Leaders reported on plans by the European Commission that will fundamentally change the cloud market. Part of the so-called Tech Sovereignty Package, due to be presented on 27 May, are rules restricting the use of American cloud platforms for processing sensitive government data. Sectors such as the judiciary, healthcare and financial services will be required to house their most critical data on European cloud infrastructure.
The reason is clear: growing European dependence on foreign technology, and the American Cloud Act. Under certain conditions, that law gives the American government access to data held by American companies, regardless of where that data is physically stored. In other words, even data in a European data centre belonging to an American company falls within the scope of American legislation.
What this means in practice: a hospital storing patient data via Microsoft Azure, or a municipality working with Google Workspace, will need to review these arrangements. Not as an option, but as a legal obligation.
Why the Cloud Act is a real risk, even with European data centres
A common misconception: "our data is already in Europe, so we're safe." This isn't true. The American Cloud Act (Clarifying Lawful Overseas Use of Data Act) applies on the basis of company location, not data location. Microsoft, Google and Amazon are American companies. That makes their entire infrastructure, including European data centres, legally subject to American legislation.
The NIS2 Directive, in force since October 2024, and the GDPR impose additional requirements on the processing of personal data. Government organisations are also subject to the BIO (Baseline Information Security for Government), which directly affects cloud choices. Data sovereignty is therefore no longer an abstract ambition, but an enforceable obligation.
What we see every day: the urgency is now
At Cyso, we've been guiding organisations through secure cloud migrations for years. In recent months, we've noticed a clear shift. Municipalities, healthcare institutions and government bodies are increasingly getting in touch with the same three questions:
Where does our current SaaS provider store our data?
Do we comply with the GDPR, NIS2 and the upcoming EU cloud rules?
How do we migrate to an EU-hosted solution in a controlled way?
What used to be a technical conversation is now a governance issue. Privacy officers, legal counsel and directors are raising the alarm. They don't want to be caught off guard by legislation that is already well underway.
Cyso: fully European, fully governed by EU law
Cyso's cloud infrastructure is housed entirely in Dutch and German data centres. There's no American parent company, no Cloud Act risk and no legal grey area. Your data falls exclusively under EU law and is processed in line with the GDPR and the NIS2 Directive.
Our solutions are suited to organisations working with privacy-sensitive or confidential data, including personal data, medical records and government information.
We offer:
Cloud hosting in Europe
GDPR-compliant and NIS2-ready infrastructure
Guided cloud migration, from inventory to go-live
No vendor lock-in with American hyperscalers
Cyso's cloud platform and infrastructure are housed entirely in the Netherlands and Germany. No American parent company, no Cloud Act risk, no legal grey areas. Your data stays where you want it to stay: within the EU, under EU law.
Frequently asked questions about the EU cloud legislation
Does my organisation need to migrate immediately?
No hard deadline has been set yet, but the regulation is unavoidable. Organisations that start now avoid time pressure and operational risks later on.
Does Microsoft Azure or Google Cloud in Europe also fall under the Cloud Act?
Yes. The Cloud Act applies on the basis of the company's nationality, not the server's location. Data held by American companies always falls within the scope of American legislation, even if that data sits in a European data centre.
What's the difference between GDPR compliance and EU cloud compliance?
The GDPR governs how personal data is processed. The new EU cloud rules additionally restrict which cloud providers may store sensitive data at all. Both apply cumulatively.
How long does a cloud migration typically take?
This depends on the complexity of the current environment. An average migration for a medium-sized municipality or healthcare institution takes 3 to 6 months with a well-prepared approach.
No reason left to wait
The question isn't whether your organisation needs to migrate to European cloud infrastructure. The question is when, and whether you do so in a controlled way or under pressure. A timely switch to GDPR-compliant, EU-hosted cloud hosting isn't just a compliance measure. It's an investment in digital sovereignty, operational continuity and organisational peace of mind.
Ready to take the next step?
We'll guide you from the first inventory through to a full, working cloud migration. Get in touch with us for a no-obligation conversation about your specific situation.



