Home / Blog

Can you store personal data in an American cloud?

August 5, 2025 · International transfers

Can you store personal data in an American cloud?

Cloud storage has become an indispensable part of our digital landscape. Many organisations store data using tools from American providers such as Microsoft, Google or Amazon. But is that simply allowed when personal data is involved?

Since the Privacy Shield was struck down (2020) and stricter EU rules were drawn up, the answer is: not without safeguards. As an organisation, you have to be able to justify why you place personal data in an American cloud and which measures you have taken to do so in a legally sound way.

1️⃣ The basis: personal data may only leave the EU under conditions

Under the GDPR, personal data may only be transferred to countries outside the European Economic Area (EEA) if that country:

  • Has an adequacy decision from the EU (such as Japan or Switzerland)
  • Or if you take additional measures yourself that ensure an equivalent level of protection

Since the Court of Justice struck down the Privacy Shield, the US has no general adequacy decision, but since July 2023 there is the EU–US Data Privacy Framework. That means: transfers to certified parties are possible under conditions, but it is not a free pass.

2️⃣ Is it a transfer or just storage?

The term “transfer” is broader than you might think. According to the European supervisory authorities, there is already a transfer if:

  • The data is physically stored on servers outside the EU
  • Or if staff in the US can access data stored within the EU (for example for support)

So it does not matter where the data is, but who can access it. That is why you should always take a critical look at your cloud provider’s contracts and infrastructure.

3️⃣ Which extra measures should you take?

  • Standard Contractual Clauses (SCCs) between you and the provider
  • Encryption of data at rest and in transit
  • Functionally separated access: European customers are served by an EU team
  • A clear record of processing activities documenting where data is stored and who can access it
  • Check whether your supplier participates in the EU–US Data Privacy Framework (here is how to check the DPF register)

Please note: you do not only have to show that you have taken measures, but also that they are effective.

If you work with an American cloud supplier, you have to be able to demonstrate that the personal data is protected just as well as within the EU.

4️⃣ What do the supervisory authorities say?

The European supervisory authorities are critical. The Dutch Data Protection Authority states that transfers to the US still carry risks, even under the new framework. The bar is higher still for sensitive data or government bodies.

So make sure that you:

  • Have properly mapped the risks (DPIA)
  • Can legally justify the cloud provider you have chosen
  • Have an alternative ready in case legislation changes

✅ Conclusion: is it allowed?

Yes, under conditions. You may process personal data via an American cloud provider if:

  • The supplier complies with the EU–US Data Privacy Framework
  • You have taken the right contractual and technical measures
  • You can demonstrably record this in your processing policy

No guarantees, then, but with the right preparation responsible use is possible.

🔐 RealCob helps you keep the overview

RealCob shows exactly which personal data you store where, with which supplier and under which conditions. That way you can see in one dashboard whether you comply with the rules for international transfers, including alerts when legislation changes.

👉Try RealCob free for 30 days

👉Book a quick demo

← All articles

From reading to fixing.

RealCob checks every GDPR and NIS2 obligation and makes it demonstrable. Try it free for 30 days or book a 20-minute demo.

No credit card required · Prefer to see where you stand first? Take the free GDPR check

Try free for 30 days