Can you put customer data in US clouds?
Placing personal data in cloud services outside the EU is allowed but regulated. Since 2023, transfers to the US have rested on an adequacy decision providing a legal basis, though the situation could change. Encryption and EU regions reduce the risk, and for especially sensitive data, a European option can be justified despite the cost. Assess sensitivity before you choose.
The question of where data may be stored has plagued Swedish decision-makers for years. The large, convenient, and cheap cloud services are often American, while personal data under the GDPR can’t simply be moved out of the EU. The result is a squeeze between the practical and the legal. Here’s a nuanced picture of what actually applies in 2026 and how to make a well-grounded decision instead of either ignoring the issue or banning everything.
The current state of transfers to the US
The basic rule is that personal data can be processed freely within the EU, but a transfer to a country outside it – a so-called third country – requires a specific legal basis. The US has been the difficult case, since earlier legal bases were struck down by the EU Court of Justice with reference to US surveillance legislation.
Since 2023, an adequacy decision has again provided a legal basis for transfers to US providers that have joined the underlying framework. In practice, that means US clouds can be used legally again, provided the provider is covered.
But history calls for caution. Earlier equivalents have been struck down in court, and it can’t be ruled out that the current decision will also be challenged and fall. Wise planning therefore means not just relying on today’s basis, but thinking through what you would do if it disappeared.
Technical safeguards
Regardless of the legal basis, the right technology significantly reduces the risk. The point of safeguards is to make any access as useless as possible.
| Safeguard | What it provides |
|---|---|
| Strong encryption | Data is unreadable without the key – especially if you hold the keys yourselves |
| EU region | Data is stored physically in the EU, which reduces but doesn't remove the risk |
| Data minimization | Fewer personal data points in the cloud means less to protect |
| Pseudonymization | Data can't be linked to a person without a separate key |
Encryption is the single most important measure, and it’s strongest when you hold the keys yourselves – then the provider can’t read the data in plaintext even if compelled to hand it over. Placing data in a European region helps too, but with a caveat: if the provider is American, the data can still fall under US law that gives authorities access. An EU region removes part of the risk, then, but not the question of who can ultimately be compelled to hand over the data.
When European alternatives are justified
There’s no rule that everything has to sit in the same cloud. A reasonable approach is to tier your data by sensitivity and let the level of protection follow from that.
- Non-sensitive data – such as anonymous statistics or content with no link to a person – can usually stay in a large US cloud with normal safeguards without raising concerns.
- Everyday personal data can stay there with tightened safeguards: encryption with your own keys, an EU region, and data minimization.
- Especially sensitive data – health data, data about children, or data in public-sector operations – weighs heavily toward a European alternative, where the question of foreign access doesn’t arise in the same way.
A European cloud often costs more and sometimes has a smaller ecosystem, and that extra cost is real. But for the most sensitive data, it can be well justified, both legally and in terms of trust.
A scenario: the decision that held up
A healthcare-adjacent service faced a choice between a cheap US cloud and a pricier European one. Instead of picking one for everything, they split it up: the health data went to a European provider, while operations and anonymous statistics stayed in the large US cloud with encryption. The extra cost was limited to the small, sensitive part.
The decision wasn’t based on a feeling that “everything foreign is dangerous,” but on an assessment of what each dataset could actually tolerate. It’s that trade-off – the data’s sensitivity against cost and requirements – that should drive the choice, rather than a blanket rule for the whole organization.
If you want to work out where your data should live without getting stuck in either excessive caution or unnecessary risk, we at Weapp are glad to help with that trade-off – get in touch with a description of the data involved.
Frequently asked questions
Is it legal to use US cloud services in 2026?
Yes, with the right basis. Since 2023, an adequacy decision has provided a legal basis for transfers to the US for providers that have joined the underlying framework. That makes US clouds usable again after years of uncertainty. But decisions of this kind have been struck down before, so build in a plan for what you'd do if the legal situation changes again.
Is choosing a European data center region enough?
It helps but doesn't solve everything. Storing data physically in the EU reduces the risk, but if the provider is American, the data can still fall under US legislation that gives authorities access. An EU region is a good safeguard, but it doesn't remove the question of who can ultimately be compelled to hand over the data.
Which technical safeguards reduce the risk?
Strong encryption is the most important one – especially if you hold the keys yourselves, so the provider can't read the data in plaintext. Minimizing which personal data ends up in the cloud at all helps too, as does pseudonymizing where possible. These safeguards mean that any access gives away far less usable information.
When should we choose a European alternative despite the higher cost?
When the data is especially sensitive or the organization especially exposed. Health data, data about children, or public-sector data weigh heavily toward a European choice. Weigh the extra cost against the risk and the requirements in your industry. For non-sensitive data, a US cloud with safeguards is often enough, while the most sensitive data can justify an EU-based alternative.