PDF Kami EU-Hosted

Blog

CLOUD Act: why “hosted in Europe” won't protect your PDF

A 2018 US law lets American authorities demand data hosted in Europe, and Microsoft has admitted as much under oath to the French Senate. What that means for every file you upload to an online PDF converter, and how to stay out of reach.

On 10 June 2025, the head of public and legal affairs at Microsoft France sat before a French Senate inquiry committee and answered questions under oath. One of them: could he guarantee that French citizens' data entrusted to Microsoft would never be handed to the US authorities without the French authorities' consent? His answer took one sentence: “No, I cannot guarantee it” (translated from French). He added that it had never happened, and that if a US court ordered it, Microsoft would have to comply (Usine Digitale, Techniques de l'Ingénieur).

That isn't a confession peculiar to Microsoft. It's an accurate description of a law every one of its American competitors is bound by: the CLOUD Act. And it applies directly to the file you're about to drop on a PDF converter.

What the law says, in three sentences

The Clarifying Lawful Overseas Use of Data Act passed the US Congress in 2018, after years of wrangling between the FBI and Microsoft over emails stored in Ireland (Techniques de l'Ingénieur, US Department of Justice resources). It lets the US authorities compel any service provider under US jurisdiction to hand over data in its “possession, custody or control”, wherever that data physically sits (IT for Business). The test isn't where the server is. It's the nationality of the company that controls it.

In practice, a file on an AWS server in Paris, Azure in Marseille or Google Cloud in Saint-Ghislain can be reached by a US request just as if it were sitting in Virginia. “Servers in Europe” is a statement about geography. The CLOUD Act is a question of law.

The CLOUD Act follows the company, not the server: a file hosted in a US provider's European data centre stays within reach of a request from the US authorities; a file that never leaves your computer sits outside any third-country jurisdiction

Who's caught

Any company “subject to the jurisdiction of the United States”: American companies and their subsidiaries, wherever they operate. That takes in the three hyperscalers (Amazon Web Services, Microsoft Azure, Google Cloud) and, more broadly, any American software or online-service vendor.

For PDF tools, that means two circles:

Services that are American themselves. Adobe (Acrobat online) and Foxit are US companies. A file you drop with them is, for as long as they keep it, held by an entity the law targets directly.

European services hosted with an American provider. This is the most common case, and the hardest to see. iLovePDF (Barcelona) describes on its Security page an infrastructure built on “cloud partnerships” and a storage provider it doesn't name. Smallpdf (Switzerland) says it processes files “in the cloud”. If that cloud is one of the three hyperscalers — and for the vast majority of services that size, it is — your file is held by a provider subject to the CLOUD Act, whatever the nationality of the brand on your screen. Only PDF24 states “servers located in Germany”, and it doesn't say whose either.

So the question to put to any service isn't “where are your servers?” but “who owns them?”. None of the five big converters answers it on the page where you drop your file. We went through their pages one by one.

“It has never happened”

That's the second half of Microsoft's answer, and as far as the company knows, it's true. Three things to bear in mind:

The hyperscalers' answer: three strategies, one problem

The American providers have worked out that “servers in Europe” no longer cuts it. Each has built a response, and how they built it tells you a lot about what the law actually demands.

Three hyperscaler responses to the CLOUD Act: AWS's separate subsidiary (still owned by Amazon), the majority-European joint ventures S3NS (Thales-Google) and Bleu (Orange-Capgemini-Microsoft), and local processing, which does away with the host altogether

AWS: a separate structure, but still Amazon. On 15 January 2026, AWS opened the AWS European Sovereign Cloud in Brandenburg: infrastructure physically and logically cut off from the rest of AWS, €7.8 billion of investment, operations restricted to staff living in the EU, a new parent company and three German-law subsidiaries run by European citizens, a European managing director, and an advisory board made up solely of EU citizens (About Amazon, aws.eu, Developpez.com). It's a real, expensive effort. But those entities are still owned by Amazon, and the CLOUD Act reaches whatever is under a US provider's “control”. As the specialist press has pointed out, no structure, however compartmentalised, can offer an absolute guarantee while the parent company remains subject to US law (IT for Business). The offering isn't SecNumCloud-qualified.

Google: handing control to a European third party. Google took a different route: S3NS, a French-law joint venture set up in 2022, majority-owned and operated by Thales, which delivers Google Cloud services from French data centres. Its PREMI3NS offering gained SecNumCloud 3.2 qualification in December 2025 — the first pairing of American technology with French operation to pass ANSSI's test of immunity from extraterritorial law (Business Wire, PAC).

Microsoft: the same route, not there yet. Bleu, a French company owned by Orange and Capgemini, distributes Azure and Microsoft 365 from infrastructure isolated from Microsoft's global systems. It cleared the first milestones of SecNumCloud qualification in 2025 and is aiming for full qualification in 2026; as of mid-year it hadn't got there (Usine Digitale, Synapsys). Microsoft also offers the EU Data Boundary, a commitment to process data within the EU — which does nothing to change the company's nationality.

What the three strategies share is more telling than what sets them apart: to escape the law, the company holding the data has to stop being American. A subsidiary isn't enough (AWS); it takes a majority European shareholder and independent operations (S3NS, Bleu). That's exactly what SecNumCloud 3.2 requires, and it's what the hyperscalers themselves ended up conceding by building these structures. Critics call it “sovereignty as a façade”, since the code and the updates still belong to the American vendor (Parlons Cloud); supporters see it as the only way to get feature-rich services without legal exposure. It's a legitimate debate. It's also one the user of a PDF converter never gets to have.

Because here's the part that concerns you: none of the big online PDF converters says it uses any of these offerings. They don't name their host at all. So you're not with S3NS, not with Bleu, not with a SecNumCloud-qualified provider. You are, in all likelihood, in a standard region of an American hyperscaler — the very thing the state decided to leave behind for its health data.

What that means for a PDF

An online converter keeps your file for an hour, two hours, sometimes for an unspecified period. During that window, the file is in the clear (the server has to read it to process it) and held by the hosting provider. If that provider is subject to the CLOUD Act, so is your file, for as long as the window lasts.

For a CV or a brochure, the question doesn't arise. For anything covered by professional secrecy, legal proceedings, a medical record, a negotiation or third-party data you're responsible for under the GDPR, it arises in exactly the same way it did for the state and its health data.

And there's a point the sovereignty debate tends to forget: under the GDPR, you are the data controller for the data inside the files you upload. The converters' privacy policies say as much. If a file holding your customers' or employees' data is handed to a foreign authority from the servers of a processor you chose, it's your processing chain that's on the line.

The only data out of reach is the data that never leaves

The CLOUD Act applies to data held by a provider. Data that has never been sent to any provider is held by no one but you. That's an exemption by design, not by contract.

That's the principle behind PDFKami: merging, compressing, splitting and converting all run in your browser, on your machine. The file isn't uploaded. There's no cloud, American or European, because there's no processing server. The site itself is served from European infrastructure, but that only concerns the page, not your files: they don't go anywhere. And you don't have to take that on trust: the page's security policy (CSP) technically blocks every outgoing connection, and you can check it yourself in 60 seconds.

What this approach doesn't cover: heavy OCR, PDF-to-Word conversion, qualified signatures. Those need a server — and for those operations alone, “who owns the server?” becomes the first question to ask. Since 2 August 2026, it sits alongside the questions raised by the AI Act whenever an “AI” tool reads your documents.

FAQ

Does the CLOUD Act apply to data stored in Europe?

Yes, as soon as the company holding it is subject to US jurisdiction. Where the server sits isn't the test.

Is a European service hosted on AWS, Azure or Google Cloud affected?

The data is held by the cloud provider, which is American, so it's exposed to a CLOUD Act request whatever the nationality of the service out front.

Doesn't the GDPR protect against this?

The GDPR regulates transfers and imposes safeguards; it doesn't make a US request void. The clash between the two texts is precisely what Microsoft's answer to the French Senate laid bare.

Have there been documented cases involving PDF files?

None that we know of publicly. Requests can come with a gag obligation, which makes the absence of public cases tell you very little.

How do I process a sensitive PDF without exposing myself?

Don't upload it. Browser-based tools like PDFKami send the file to no provider at all. For operations that need a server, pick a provider whose host isn't subject to a third-country jurisdiction (SecNumCloud-qualified, for example).

Read next

← All articles