If your business uses a US-based e-signature platform — DocuSign, Adobe Sign, Dropbox Sign, PandaDoc — every contract you've ever signed through it is potentially reachable by US federal agencies via the CLOUD Act, regardless of where the data centre physically sits. For most SMBs this is theoretical. For anyone handling sensitive commercial data, IP, M&A documents, or regulated personal data, it's a live compliance and confidentiality issue.
What is the CLOUD Act?
The Clarifying Lawful Overseas Use of Data Act was signed into US law in March 2018. It gives US federal law enforcement the authority to compel any US-based technology provider to produce data in that provider's possession, custody, or control — regardless of where the data is physically stored.
Before the CLOUD Act, the law was unclear: a 2013 warrant against Microsoft demanding emails stored in Ireland went to the Supreme Court and was mooted when the CLOUD Act passed. Congress deliberately settled the question in favour of extra-territorial reach.
The mechanism is a warrant, subpoena, or court order under existing US legal process (usually the Stored Communications Act). The company receiving it can challenge on the grounds that compliance would violate foreign law — but the default is production. And there's a gag provision: the company usually cannot tell the customer their data was requested.
How it affects e-signature platforms
E-signature platforms hold a lot: the signed contract itself, all metadata (signer names, emails, IP addresses, timestamps), any negotiation history, audit trails, and often uploaded ID documents. A CLOUD Act warrant against DocuSign can reach all of that. The gag order means the customer doesn't necessarily find out.
What's exposed:
- Full text of every signed contract (NDAs, M&A term sheets, employment contracts, partnership agreements)
- Identities and contact details of everyone who's signed
- IP addresses and access logs, potentially revealing corporate locations and travel patterns
- Uploaded identity documents where AES/QES-tier signing was used
- Metadata about which contracts were signed when, revealing deal flow and business relationships
"But it's encrypted at rest" doesn't help: the platform holds the keys. "But it's in the EU data centre" doesn't help: the CLOUD Act reaches the parent company, not the physical drives.
The GDPR conflict
Here's where it gets legally messy. GDPR Article 48 says that transfers of personal data in response to a foreign court or authority order are lawful only if based on an international agreement (like a mutual legal assistance treaty). A CLOUD Act warrant is not that — it's a unilateral US instrument. So a US provider complying with a CLOUD Act request that includes EU personal data is, strictly, breaching GDPR.
The European Data Protection Board has been clear about this since 2019: US law that permits access without EU-equivalent protections creates a "fundamental problem" for GDPR compliance. The Schrems II ruling (July 2020) invalidated Privacy Shield on essentially these grounds.
The current stopgap is the EU-US Data Privacy Framework (adequacy decision July 2023), which is already under legal challenge. If it falls — and Max Schrems has said he'll challenge it — every EU company using a US e-signature platform for personal data has an overnight compliance problem.
What "EU-sovereign" actually protects
An EU-sovereign platform — incorporated in the EU, hosted on EU infrastructure with no US ownership in the stack — is outside the CLOUD Act's reach. US law enforcement can only reach it via a Mutual Legal Assistance Treaty (MLAT) request routed through the relevant EU member state's judicial system, which applies EU due-process standards, notifies the data subject where possible, and can be refused.
The key phrase in the CLOUD Act is "possession, custody, or control." An EU company with no US presence has no US person to serve a warrant on. It's not that the US chooses not to reach in — it legally can't, at least not without going through the MLAT process, which gives the EU jurisdiction the opportunity to refuse.
How to check where your signed contracts really live
Three questions for any e-signature provider:
- Where is the operating company incorporated? Not where their EU sales office is — the actual parent company. Check their Terms of Service; the "governing law" clause usually reveals it
- Who owns the cloud infrastructure they run on? AWS, Google Cloud, Azure — all US-owned, all CLOUD Act-reachable, even in EU regions. Even a French provider on AWS Paris is still exposed via Amazon
- Where is their support and engineering staff? If the people with production access are in the US, they can be compelled under US law regardless of where the servers are
An honest answer to all three from a US provider will confirm the exposure. It doesn't mean you must stop using them — it means the risk is real and needs a documented decision.
When it doesn't matter
Being blunt: for signing a mundane consulting agreement or vendor NDA between two businesses with no state-secret implications, CLOUD Act exposure is theoretical risk. The US Department of Justice isn't reading everyone's contracts. The real cases that get invoked are typically FCPA investigations, sanctions enforcement, and organised crime. If your signed contracts genuinely don't touch any of that, the CLOUD Act is a compliance and legal-hygiene issue rather than a hot risk.
But it changes the moment you handle: M&A documents, government contracts, competitively sensitive IP, EU sanctions-related counterparties, or personal data of European regulated categories (health, financial). At that point, EU-sovereign isn't paranoia — it's the correct architecture.
Where eSeal sits
eSeal is incorporated in the EU (Italy), runs on Hostinger's EU infrastructure (Lithuania), uses Mistral (French AI) for analysis, and delivers email via Resend (EU-compliant). No US company anywhere in the stack, so no CLOUD Act reach. Signed PDFs are also deleted immediately after signing — there's no long-term contract archive for anyone to subpoena.
For related reading: our DocuSign alternative guide covers the broader vendor picture, and the eIDAS guide explains the EU signature framework.
Try CLOUD Act-free signing
eSeal runs entirely on EU infrastructure — incorporation, hosting, AI, email. Free. PAdES B-T. eIDAS SES-tier.
Sign a PDF free →