These matters of complicated jurisdiction and sovereignty law require the advice of an experienced international data lawyer. These lawyers need the advice of experienced international technologists, and that is the bit I do. Each has to know quite a bit about what the other is doing, so I study the relevant statutes and speak to the people drafting the next versions of the regulations.
The EU Court of Justice has twice ↗ decided ↗ that US spying means EU data cannot be managed by US companies, because it violates the privacy of EU citizens. This was very awkward because US companies captured a large part of the EU data market and used their money and influence to spin this issue and in 2026 the court will decide the appeal on a third decision ↗. The facts have materially changed and many observers feel there is potential the court will strike down the 2023 EU-US Data Privacy Framework (DPF) ↗ currently in force. Throughout this period the various laws and regulatory schemes keep getting changed to provide a way for the practically unlimited US spying to be presented as limited by US government promises. Even if these companies promise to hold data within the EU, and even if they are otherwise highly compliant, the US government still insists on access to all data at all times. That is why these cases keep getting brought and in 2026 the mood in Europe is very different. Perhaps this time there will be a definitive “no” from the court given that many EU governments and companies are turning away from US cloud as a matter of sovereign policy. The UK situation depends in many ways on whatever it is that the EU court decides.
Background
Privacy Shield was a 2016 self-certification scheme for US companies to hold themselves to the strict EU privacy rules. In 2020 Privacy Shield was struck down by the EU Court of Justice. In non-technical terms, the Court said: There is no way Privacy Shield can work. So don’t use US-controlled cloud companies such as Google or Amazon.
In late 2021 this decision started rippling out across Europe, as one place and then another tried to take steps away from these giant US companies, starting with government users. We all like familiarity and wish to avoid change, so this direction seemed astonishing to many people. Responses by the US companies were creative, investing billions in positive-sounding changes such as regional data localisation and “Sovereign Cloud” offerings. The EU Commission (which is distinct from the EU Parliament, the EU courts, and the EU Council) has been consistently in favour of US companies, and responded to the court judgements with a scheme called Standard Contractual Clauses which the US companies adopted enthusiastically. None of these change the fact that US courts, governments and sometimes companies can reach into any data stored by any US company worldwide. The US companies also used their immense power in coercive political, economic and legal methods including a new IP tool called paracopyright.
I have been researching, advising, consulting and teaching on the collapse of Privacy Shield since 2016, including this substantial Privacy Shield paper whose extensive references set the scene for the story in 2026.
On 16th July 2020, the EU Court of Justice decision striking the EU-US Privacy Shield ↗ was the culmination of years of effort by many people to highlight human rights abuses. Privacy Shield demonstrates how closely privacy and human rights are connected.

Now we await the next stage in this saga, expected before the end of 2026.
The details
The details are complicated, but in summary, factors include:
- the Digital Single Market
- the six or so EU security and privacy laws are based on international Human Rights (derived from the Universal Declaration of Human Rights)
- various US Presidential Executive Orders stripping privacy protections from non-US citizens, which almost-but-don’t-quite apply to EU citizens, depending on legal arguments either way
- conflicting privacy defaults in EU and US laws
- bulk collection by the US under FISA Section 702 ↗ (50 U.S.C. section 1881a) and Executive Order 12333 ↗ (4 December 1981, 46 FR 59941)
- dependence on goodwill of the US president to respect EU privacy, rather than relying on US statute. The current US president appears to dislike cooperation with Europe generally, and has enacted several Executive Orders bearing on EU data privacy
- The US CLOUD Act ↗ which claims Universal Jurisdiction ↗ in data matters and compels US companies to comply
FAQ
Is This Just About Pure Human Rights?
No. The EU decided in 2014 to create a Digital Single Market to mirror the physical Single Market. The EU calculated that the only way to do this was to foster trust in consumers, and the only way to do that was to emphasise privacy as a basic Human Right. The thinking of the EU is that economic prosperity will follow if Human Rights are respected. But yes, it is also about pure Human Rights too.
What Does This Mean for Cloud Companies?
US Cloud companies such as Google, Amazon, eBay etc from 2021 are slowly becoming either deprecated or illegal to use within Europe. Multiple countries have already banned these companies for government use, and the restrictions keep tightening. These cloud companies are fighting hard, but this is not the first time the same court has passed the same judgement. There is no legal change for EU-based cloud companies, which are unaffected.
What Does This Mean for EU Tech Companies?
Opportunity. Facebook, Gmail and Amazon AWS (for example) are far from unique and their technical features have already been replicated elsewhere, although they have large amounts of cash to help them fight and evolve. EU tech companies who have standardised on Google or Amazon APIs for example already know they are committed to regular refreshes and upgrades so change is not unthinkable. For EU Cloud suppliers, competition is already fierce but the barrier to entry is still quite low. In 2026 there are now many case studies at scale of how to move off US cloud.
What Does This Mean for EU (or UK) Organisations?
This process can feel a little like consumers seeking more ecologically-friendly alternatives to common items. The nature of lockin is that there are many pieces involved, and this is not necessarily easy. For example, email replacement for Outlook may seem straightforward, but many organisations have dependencies on Microsoft authentication systems or integration with document management systems that makes it harder to unpick.
Isn’t EU Cloud Immature?
Not any more. If you are insisting on hyperscale cloud, there are few EU companies. But cloud at scale 5 million or so is doable without being a Baidu or an Amazon, and many quite sbstantial organisations are finding that maybe cloud isn’t entirely the answer they thought it was anyway.
Is the US Government Really That Bad?
Yes. Even if some others want to behave just as badly, only the US has a majority of the cloud services used by EU citizens and residents. The US explicitly removes all protections from everyone in the world. The US Presidential Order Enhancing Public Safety states:
Sec. 14. Privacy Act. Agencies shall, to the extent consistent with applicable law, ensure that their privacy policies exclude persons who are not United States citizens or lawful permanent residents from the protections of the Privacy Act regarding personally identifiable information. US Presidential Order Enhancing Public Safety
To be legally and politically precise, there was some protection in an agreement called the EU-US Umbrella Agreement, and the US Congress passed the Judicial Redress Act to make the Umbrella Agreement effective. But in July 2020 the EU Court of Justice said none of that is any use. The US still spies on all data all the time, and that is against EU law, therefore US cloud is not permitted to hold EU personal data. These details are in the paper referenced above.
What About the UK?
The UK is no longer in the EU. The UK has backed the US repeatedly in its data protection laws, but the EU still certifies the UK as acceptable for storing EU citizen’s data. However it is beginning to look like Data Mobility Post-Brexit is going in one direction only, which is away from the UK. This is not yet settled case law, but changes are happening fast in this area. The UK has very little input to decisions around the EU Data Privacy Framework, and must just deal with what is decided within the EU.
Why is Privacy Described as a Race to the Top?
“Race to the Top” describes the entire problem of the EU-US Privacy Shield. The EU has much higher standards in privacy than the US. An EU company can easily detune from EU standards to US standards if required to do business in the US, within certain limitations. It is definitely easy from a technical point of view if systems have been designed with this in mind. Unfortunately for US companies, doing things the other way around is not possible. Even if the US company complies perfectly with every law, the decisions of the US mean that they still have to make EU data available to the US Government.