There is a document you signed when you started using AWS, Azure, or Google Cloud.
You did not read it. Nobody reads it. It runs to forty, sometimes sixty pages of dense legal prose, and somewhere in the middle — usually around page 23, in a section titled something like "Use of Customer Data for Service Improvement" — there is a clause.
The clause says, in careful legal language, that your cloud provider may access your data to operate and improve their services.
You clicked Accept.
AWS's Customer Agreement states that AWS may access Customer Content as necessary to provide the AWS Services, prevent or address technical or service problems, or as required by law.
As necessary. That phrase is doing a lot of work.
It means that a support engineer investigating a service incident may access the storage bucket where you keep your customers' medical records. It means that an automated system scanning for malware may process the encrypted database where you store payment information. It means that a government with a valid legal order can compel AWS to produce your data — and AWS's data centres are, in most cases, subject to US jurisdiction regardless of which region you selected.
This is not a conspiracy theory. This is the contract.
When European companies choose eu-west-1 or europe-north1, they believe they have solved the data residency problem. The data is in Europe. GDPR is satisfied.
It is not that simple.
The legal entity operating that European data centre is an American corporation subject to US law. The CLOUD Act — passed in 2018 — gives US law enforcement the authority to compel American companies to produce data stored anywhere in the world, including European data centres, without notifying the data subject or the host country.
In 2023, the EU-US Data Privacy Framework attempted to address this. Legal scholars are divided on whether it does. The Schrems III challenge is already in preparation.
What is not in dispute: your cloud provider's employees can access your data. The technical capability exists. The legal permission exists. The audit trail showing when and why they did so is not yours to inspect.
Two years ago, ISO 27001 auditors would accept "data is in an EU region" as sufficient evidence of data residency controls. That is changing.
Auditors are now asking: Can any party outside your organisation access this data without your knowledge or consent?
For data stored in a cloud vault managed by a third party, the honest answer is yes.
This matters beyond compliance theatre. GDPR Article 32 requires that you implement measures ensuring ongoing confidentiality of processing systems. A system where the operator has a technical and legal right of access is not, by any reasonable reading, a confidential processing system.
The fine for getting this wrong is up to €20 million, or 4% of global annual turnover, whichever is higher.
Companies choose cloud vaults because they are convenient and because the alternative — running your own key management infrastructure — sounds expensive and complicated.
The calculation usually goes: Cloud vault costs €200/month. Running our own costs a senior engineer's time. Cloud wins.
This calculation omits several things.
It omits the cost of the legal opinion you will need when a large customer asks for evidence that their data is truly private. It omits the time your security team will spend answering questionnaires about cloud provider access policies. It omits the conversation you will have with your board when a competitor is fined €4 million and the question is asked: Are we exposed to the same risk?
And it omits the scenario nobody prices in until it happens: your cloud provider receives a legal order. They comply. Your customer data is accessed. You are the last to know — because the order came with a gag clause.
Before your next renewal with your cloud provider, find the clause. It will be there. Read it carefully.
Then ask yourself: if a customer asked you to prove — technically, not just contractually — that no third party has the ability to access their personal data, what would you show them?
If you do not have a good answer, you are not alone. Most companies do not.
The question is whether you want to be in that position when someone important asks it.