Collective

We’re a worker-owned agency that designs, builds and supports websites for organisations we believe in.

The Cloud Act, tech sovereignty and why communications leaders should care

Most heads of communications do not spend much time thinking about where their organisation’s data is stored. They are more likely to be dealing with a website launch, a campaign deadline or a media enquiry.

But the technology behind those activities can create communications, governance and reputational risks. The US Cloud Act helps explain why tech sovereignty should be part of the conversation.

What is the Cloud Act?

The Clarifying Lawful Overseas Use of Data Act (Cloud Act) is a US law that came into force in 2018.

In simple terms, it confirms that US law enforcement agencies can require US technology companies to provide data in their possession, custody or control, even when that data is stored outside the United States.

In practice, storing data in a European data centre does not necessarily put it beyond the reach of US law. An organisation in the UK might store information in London, Frankfurt or Dublin. If its service provider is a US company, however, that information may still fall within the scope of a US legal request.

For many organisations, particularly charities, NGOs and public sector bodies, this can come as a surprise.

This does not mean that US authorities can freely access data or that privacy protections disappear. Requests must follow legal processes and can be challenged in some circumstances.

The important point is that the organisation storing the data may not have complete control over who can access it or which country’s laws apply. That raises questions about trust, governance and accountability.

The French Experience

This is not just a theoretical concern.

France’s Health Data Hub, which provides access to health data for research and innovation, has used Microsoft Azure. Its data was physically hosted in Microsoft data centres in France.

In June 2025, Microsoft France appeared before a French Senate inquiry into public procurement and digital sovereignty. When asked whether it could guarantee that French public-sector data would never be transferred to the US government, the company said that it could not provide an absolute guarantee.

There was no suggestion that the Health Data Hub’s data had been accessed. Legal, contractual and technical safeguards were also in place. The concern was that access remained legally possible.

The French government subsequently began work to move the platform to French cloud provider Scaleway. The migration forms part of a wider effort to give France greater control over its sensitive public data.

The case attracted political attention because public trust depends on more than where data is physically stored. It also depends on who controls the technology and which laws apply to it.

The wider sovereignty question

The Cloud Act highlights a broader issue: how much control does your organisation really have over the technology it depends on?

Many organisations rely on a small number of global technology providers for hosting, analytics, productivity tools, artificial intelligence services and communications platforms.

Each decision may make sense on its own. Together, they can create significant dependency.

Tech sovereignty offers a practical way to think about that dependency. It means maintaining meaningful control over the systems, platforms and data your organisation relies on. It also means understanding critical dependencies and making deliberate choices about them.

It does not mean that every organisation must build and host all its own technology. Nor does it mean automatically rejecting every large or US-based provider.

It means knowing where risks sit, deciding which risks are acceptable and keeping your options open.

Why this matters to communications leaders

Supporters, residents and service users may never ask where your organisation’s data is hosted. But they may ask difficult questions after a data breach, supplier failure, legal dispute or sudden change in regulation.

Communications teams can then find themselves explaining technology decisions made years earlier, often without having been involved in them.

Those questions may come from journalists, regulators, funders, supporters or elected representatives. The reputational problem may not be the original incident alone. It may also be the organisation’s inability to explain why it chose a supplier, what risks it considered and what safeguards it put in place.

Organisations that understand their digital dependencies are better placed to communicate openly, demonstrate good judgement and respond confidently when something goes wrong.

Communications leaders do not need to become cloud infrastructure specialists. But they should be involved in conversations about technology risk, particularly when decisions could affect trust and reputation.

Where to start

You do not need to replace every platform overnight. Start by asking:

  • Which technology providers are critical to our operations?
  • Where is our data stored, processed and backed up?
  • Which legal jurisdictions apply to our suppliers and data?
  • What would happen if a critical provider became unavailable?
  • How easily could we move our data and services elsewhere?
  • Could open-source, UK-based or European alternatives reduce our dependency?

The goal is not perfection. It is greater visibility and better-informed decisions.

Technology choices are communications choices

The Cloud Act is not a reason to panic or replace every US technology provider. It is a reminder that technology choices are rarely only technical.

They are also choices about control, accountability and trust.

Communications leaders should have a voice in those decisions before they become communications problems.

Book Your Free Consultation with Simon

We'd love to chat with you about tech sovereignty and how we can help your organisations prepare for an uncertain future.

Meet the Authors
Back to blog