back

by _tk_·7d ago·view on hn ↗
Unfortunately, even if all data lives in the European Union, as long as a company is conducting business in the US, the Cloud Act makes it possible to compel them to hand over any information. This can include making administrative personnel sign NDAs or face heavy repercussions. Conducting business in the US includes advertising to US citizens e.g through maintaining a website in English.

At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.

1 comments
I am pretty sure that European states are already storing data that is out of reach for the US government, and I don't understand how Congress could legislate against this, short of an act of war.
There are certainly exceptions, but a lot of European Governments use Azure or Google for their office applications, including different law enforcement agencies and militaries.
Indeed. My point, however, is that Congress cannot pass legislation to compel European governments to share data with the US if/when they decide not to. OP is making a weird claim about the practical impossibility of escaping US data collection.