eSeal beta

Guide

The US CLOUD Act and Your E-Signature Contracts

If your business uses a US-based e-signature platform — DocuSign, Adobe Sign, Dropbox Sign, PandaDoc — every contract you've ever signed through it is potentially reachable by US federal agencies via the CLOUD Act, regardless of where the data centre physically sits. For most SMBs this is theoretical. For anyone handling sensitive commercial data, IP, M&A documents, or regulated personal data, it's a live compliance and confidentiality issue.

What is the CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act was signed into US law in March 2018. It gives US federal law enforcement the authority to compel any US-based technology provider to produce data in that provider's possession, custody, or control — regardless of where the data is physically stored.

Before the CLOUD Act, the law was unclear: a 2013 warrant against Microsoft demanding emails stored in Ireland went to the Supreme Court and was mooted when the CLOUD Act passed. Congress deliberately settled the question in favour of extra-territorial reach.

The mechanism is a warrant, subpoena, or court order under existing US legal process (usually the Stored Communications Act). The company receiving it can challenge on the grounds that compliance would violate foreign law — but the default is production. And there's a gag provision: the company usually cannot tell the customer their data was requested.

How it affects e-signature platforms

E-signature platforms hold a lot: the signed contract itself, all metadata (signer names, emails, IP addresses, timestamps), any negotiation history, audit trails, and often uploaded ID documents. A CLOUD Act warrant against DocuSign can reach all of that. The gag order means the customer doesn't necessarily find out.

What's exposed:

"But it's encrypted at rest" doesn't help: the platform holds the keys. "But it's in the EU data centre" doesn't help: the CLOUD Act reaches the parent company, not the physical drives.

The GDPR conflict

Here's where it gets legally messy. GDPR Article 48 says that transfers of personal data in response to a foreign court or authority order are lawful only if based on an international agreement (like a mutual legal assistance treaty). A CLOUD Act warrant is not that — it's a unilateral US instrument. So a US provider complying with a CLOUD Act request that includes EU personal data is, strictly, breaching GDPR.

The European Data Protection Board has been clear about this since 2019: US law that permits access without EU-equivalent protections creates a "fundamental problem" for GDPR compliance. The Schrems II ruling (July 2020) invalidated Privacy Shield on essentially these grounds.

The current stopgap is the EU-US Data Privacy Framework (adequacy decision July 2023), which is already under legal challenge. If it falls — and Max Schrems has said he'll challenge it — every EU company using a US e-signature platform for personal data has an overnight compliance problem.

What "EU-sovereign" actually protects

An EU-sovereign platform — incorporated in the EU, hosted on EU infrastructure with no US ownership in the stack — is outside the CLOUD Act's reach. US law enforcement can only reach it via a Mutual Legal Assistance Treaty (MLAT) request routed through the relevant EU member state's judicial system, which applies EU due-process standards, notifies the data subject where possible, and can be refused.

The key phrase in the CLOUD Act is "possession, custody, or control." An EU company with no US presence has no US person to serve a warrant on. It's not that the US chooses not to reach in — it legally can't, at least not without going through the MLAT process, which gives the EU jurisdiction the opportunity to refuse.

How to check where your signed contracts really live

Three questions for any e-signature provider:

An honest answer to all three from a US provider will confirm the exposure. It doesn't mean you must stop using them — it means the risk is real and needs a documented decision.

When it doesn't matter

Being blunt: for signing a mundane consulting agreement or vendor NDA between two businesses with no state-secret implications, CLOUD Act exposure is theoretical risk. The US Department of Justice isn't reading everyone's contracts. The real cases that get invoked are typically FCPA investigations, sanctions enforcement, and organised crime. If your signed contracts genuinely don't touch any of that, the CLOUD Act is a compliance and legal-hygiene issue rather than a hot risk.

But it changes the moment you handle: M&A documents, government contracts, competitively sensitive IP, EU sanctions-related counterparties, or personal data of European regulated categories (health, financial). At that point, EU-sovereign isn't paranoia — it's the correct architecture.

Where eSeal sits

eSeal is incorporated in the EU (Italy), runs on Hostinger's EU infrastructure (Lithuania), uses Mistral (French AI) for analysis, and delivers email via Resend (EU-compliant). No US company anywhere in the stack, so no CLOUD Act reach. Signed PDFs are also deleted immediately after signing — there's no long-term contract archive for anyone to subpoena.

For related reading: our DocuSign alternative guide covers the broader vendor picture, and the eIDAS guide explains the EU signature framework.

Try CLOUD Act-free signing

eSeal runs entirely on EU infrastructure — incorporation, hosting, AI, email. Free. PAdES B-T. eIDAS SES-tier.

Sign a PDF free →