On 10 June 2025, the head of public and legal affairs at Microsoft France sat before a French Senate inquiry committee and answered questions under oath. One of them: could he guarantee that French citizens' data entrusted to Microsoft would never be handed to the US authorities without the French authorities' consent? His answer took one sentence: “No, I cannot guarantee it” (translated from French). He added that it had never happened, and that if a US court ordered it, Microsoft would have to comply (Usine Digitale, Techniques de l'Ingénieur).
That isn't a confession peculiar to Microsoft. It's an accurate description of a law every one of its American competitors is bound by: the CLOUD Act. And it applies directly to the file you're about to drop on a PDF converter.
What the law says, in three sentences
The Clarifying Lawful Overseas Use of Data Act passed the US Congress in 2018, after years of wrangling between the FBI and Microsoft over emails stored in Ireland (Techniques de l'Ingénieur, US Department of Justice resources). It lets the US authorities compel any service provider under US jurisdiction to hand over data in its “possession, custody or control”, wherever that data physically sits (IT for Business). The test isn't where the server is. It's the nationality of the company that controls it.
In practice, a file on an AWS server in Paris, Azure in Marseille or Google Cloud in Saint-Ghislain can be reached by a US request just as if it were sitting in Virginia. “Servers in Europe” is a statement about geography. The CLOUD Act is a question of law.
Who's caught
Any company “subject to the jurisdiction of the United States”: American companies and their subsidiaries, wherever they operate. That takes in the three hyperscalers (Amazon Web Services, Microsoft Azure, Google Cloud) and, more broadly, any American software or online-service vendor.
For PDF tools, that means two circles:
Services that are American themselves. Adobe (Acrobat online) and Foxit are US companies. A file you drop with them is, for as long as they keep it, held by an entity the law targets directly.
European services hosted with an American provider. This is the most common case, and the hardest to see. iLovePDF (Barcelona) describes on its Security page an infrastructure built on “cloud partnerships” and a storage provider it doesn't name. Smallpdf (Switzerland) says it processes files “in the cloud”. If that cloud is one of the three hyperscalers — and for the vast majority of services that size, it is — your file is held by a provider subject to the CLOUD Act, whatever the nationality of the brand on your screen. Only PDF24 states “servers located in Germany”, and it doesn't say whose either.
So the question to put to any service isn't “where are your servers?” but “who owns them?”. None of the five big converters answers it on the page where you drop your file. We went through their pages one by one.
“It has never happened”
That's the second half of Microsoft's answer, and as far as the company knows, it's true. Three things to bear in mind:
- A CLOUD Act request can come with a ban on telling the customer. “Never happened” means “never happened that we know of, or never disclosed”.
- The risk isn't statistical; it's structural. The law exists, the procedure exists, and a file sitting with an affected provider is exposed for every minute it sits there.
- The French state has drawn its own conclusions. The 2024 SREN law requires the administration's sensitive data to be hosted on SecNumCloud-qualified infrastructure (the French security qualification issued by ANSSI, the national cybersecurity agency). Version 3.2 of that standard requires that neither the provider nor its subsidiaries be exposed — through their head office, their shareholders or the law they operate under — to access orders from foreign authorities (donneespersonnelles.fr). The Health Data Hub, hosted on Microsoft Azure since 2020 and criticised for it, announced on 23 April 2026 that it was moving to Scaleway, a qualified provider (Tech Insider, ActuIA). When the state walks away from a provider over its health data, it's worth asking the same question about yours.
The hyperscalers' answer: three strategies, one problem
The American providers have worked out that “servers in Europe” no longer cuts it. Each has built a response, and how they built it tells you a lot about what the law actually demands.
AWS: a separate structure, but still Amazon. On 15 January 2026, AWS opened the AWS European Sovereign Cloud in Brandenburg: infrastructure physically and logically cut off from the rest of AWS, €7.8 billion of investment, operations restricted to staff living in the EU, a new parent company and three German-law subsidiaries run by European citizens, a European managing director, and an advisory board made up solely of EU citizens (About Amazon, aws.eu, Developpez.com). It's a real, expensive effort. But those entities are still owned by Amazon, and the CLOUD Act reaches whatever is under a US provider's “control”. As the specialist press has pointed out, no structure, however compartmentalised, can offer an absolute guarantee while the parent company remains subject to US law (IT for Business). The offering isn't SecNumCloud-qualified.
Google: handing control to a European third party. Google took a different route: S3NS, a French-law joint venture set up in 2022, majority-owned and operated by Thales, which delivers Google Cloud services from French data centres. Its PREMI3NS offering gained SecNumCloud 3.2 qualification in December 2025 — the first pairing of American technology with French operation to pass ANSSI's test of immunity from extraterritorial law (Business Wire, PAC).
Microsoft: the same route, not there yet. Bleu, a French company owned by Orange and Capgemini, distributes Azure and Microsoft 365 from infrastructure isolated from Microsoft's global systems. It cleared the first milestones of SecNumCloud qualification in 2025 and is aiming for full qualification in 2026; as of mid-year it hadn't got there (Usine Digitale, Synapsys). Microsoft also offers the EU Data Boundary, a commitment to process data within the EU — which does nothing to change the company's nationality.
What the three strategies share is more telling than what sets them apart: to escape the law, the company holding the data has to stop being American. A subsidiary isn't enough (AWS); it takes a majority European shareholder and independent operations (S3NS, Bleu). That's exactly what SecNumCloud 3.2 requires, and it's what the hyperscalers themselves ended up conceding by building these structures. Critics call it “sovereignty as a façade”, since the code and the updates still belong to the American vendor (Parlons Cloud); supporters see it as the only way to get feature-rich services without legal exposure. It's a legitimate debate. It's also one the user of a PDF converter never gets to have.
Because here's the part that concerns you: none of the big online PDF converters says it uses any of these offerings. They don't name their host at all. So you're not with S3NS, not with Bleu, not with a SecNumCloud-qualified provider. You are, in all likelihood, in a standard region of an American hyperscaler — the very thing the state decided to leave behind for its health data.
What that means for a PDF
An online converter keeps your file for an hour, two hours, sometimes for an unspecified period. During that window, the file is in the clear (the server has to read it to process it) and held by the hosting provider. If that provider is subject to the CLOUD Act, so is your file, for as long as the window lasts.
For a CV or a brochure, the question doesn't arise. For anything covered by professional secrecy, legal proceedings, a medical record, a negotiation or third-party data you're responsible for under the GDPR, it arises in exactly the same way it did for the state and its health data.
And there's a point the sovereignty debate tends to forget: under the GDPR, you are the data controller for the data inside the files you upload. The converters' privacy policies say as much. If a file holding your customers' or employees' data is handed to a foreign authority from the servers of a processor you chose, it's your processing chain that's on the line.
The only data out of reach is the data that never leaves
The CLOUD Act applies to data held by a provider. Data that has never been sent to any provider is held by no one but you. That's an exemption by design, not by contract.
That's the principle behind PDFKami: merging, compressing, splitting and converting all run in your browser, on your machine. The file isn't uploaded. There's no cloud, American or European, because there's no processing server. The site itself is served from European infrastructure, but that only concerns the page, not your files: they don't go anywhere. And you don't have to take that on trust: the page's security policy (CSP) technically blocks every outgoing connection, and you can check it yourself in 60 seconds.
What this approach doesn't cover: heavy OCR, PDF-to-Word conversion, qualified signatures. Those need a server — and for those operations alone, “who owns the server?” becomes the first question to ask. Since 2 August 2026, it sits alongside the questions raised by the AI Act whenever an “AI” tool reads your documents.