On March 23, 2018, a short US statute is passed in Washington, without a separate parliamentary debate, slipped inside a 2,200-page federal budget. Nobody in Europe pays attention. Eight years later, that law — the CLOUD Act — legally frames US access to tens of billions of European emails hosted by providers under US jurisdiction. It has never been suspended. No European mechanism has neutralised it to date.
In the meantime, the professional inbox has become the living archive of everything sensitive a company owns: client correspondence, contracts, health data, HR notes, commercial strategies, trade secrets. The average law firm holds — from our field experience — more than a decade of exchanges covered by attorney-client privilege, sometimes two when the mailbox follows the partner throughout their career. A chartered accountant handles accounting export files and tax returns every single day. An HR director keeps, as an email attachment, appraisal forms that, in another jurisdiction, would require a physical safe.
This article is not an advocacy piece. It is a legal and operational analysis of the CLOUD Act applied to professional email in 2026 — what the law really allows, what it does not, and the three concrete levers to protect your inbox. It is written for regulated professions, DPOs, CFOs and executives who have to answer a question that has become hard to avoid: can we still, in 2026, entrust our professional correspondence to a provider subject to US law without running a specific impact assessment?
🛡️ Quick answer: The CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) authorises US authorities to compel a provider subject to US law to disclose data it holds, regardless of where the servers are located. It creates an unresolved conflict with the GDPR, acknowledged by the CJEU in Schrems II (2020). For a professional inbox, three protection levers apply: choose a provider not subject to US law, reinforce contractual clauses, and use encryption plus organisational compartmentalisation.
💡 Key figures — March 23, 2018: date the CLOUD Act was adopted (Division V of the Consolidated Appropriations Act, 2018, Pub. L. 115-141). 0: number of mechanisms that currently suspend the application of the CLOUD Act for companies subject to US law. 3: concrete protection levers (technical, contractual, organisational) available to a European company.
🎯 Key takeaways
- The CLOUD Act allows extraterritorial access to data held by any provider subject to US law, wherever it is hosted
- Physical location in Europe does not change the applicable jurisdiction — what matters is the legal entity
- The GDPR does not neutralise the CLOUD Act — the Schrems II ruling (2020) acknowledged the unresolved conflict
- Regulated professions (lawyers, accountants, health) face additional risk linked to professional secrecy
- 3 protection levers: technical (EU publisher / EU infrastructure / EU AI models), contractual (solid DPAs), organisational (encryption + compartmentalisation)
- The major US hyperscalers fall under the CLOUD Act — a legal fact to factor into your impact assessment, with no value judgment on the quality of their services
- The Data Privacy Framework (2023) reduces political risk without removing the underlying legal contradiction
- A documented impact assessment is now expected by the CNIL for sensitive processing hosted outside the EU
📖 Table of contents
- What the CLOUD Act is, in plain terms
- Who is concerned by the CLOUD Act?
- The GDPR / CLOUD Act conflict: CJEU and CNIL positions
- What a professional email really contains — and why that matters
- Use case 1 — Law firms
- Use case 2 — Chartered accounting firms
- Use case 3 — Health and sensitive HR
- Use case 4 — Professions with specific obligations
- The 3 levers to protect against the CLOUD Act
- The Neston approach
- Frequently asked questions (FAQ)
1. What the CLOUD Act is, in plain terms
The origin: Microsoft v. United States (2013-2018)
The CLOUD Act was born out of a famous case. In 2013, the FBI was investigating a drug trafficking ring and asked Microsoft to hand over the emails of an account hosted in one of the company's Irish datacentres. Microsoft refused, arguing that US jurisdiction did not physically extend to Ireland. The case went all the way to the Supreme Court. The trial became a symbol: could US law reach data stored outside the US territory?
Before the Supreme Court could rule, the US Congress passed the CLOUD Act on March 23, 2018, tucked inside the Consolidated Appropriations Act — an omnibus federal budget. Technically, the text sits in Division V of the Consolidated Appropriations Act, 2018 (Pub. L. 115-141), structured in sections 101 to 106. The pending litigation became moot: the new text explicitly resolved the question in favour of access. The CLOUD Act does not create a new power; it clarifies and confirms a power the US administration was already invoking — the extraterritorial reach of US law over data held by US operators.
What the text really allows
The CLOUD Act amends two existing statutes — the Stored Communications Act (SCA) and the Electronic Communications Privacy Act (ECPA) — to clarify two points. First: a provider of electronic communications subject to US jurisdiction must preserve, back up or disclose the content of a communication at the request of a competent authority, regardless of the physical location of the data. Second: the text provides for a mechanism of bilateral agreements (Executive Agreements) enabling qualified foreign governments to send access requests directly to US providers.
What the text does not allow
It is essential to understand the limits. The CLOUD Act does not authorise generalised economic espionage. It does not apply to any data, in any context. It requires a procedural framework: a formal request from a competent authority, in the context of a criminal or intelligence investigation, with documented grounds. Providers may challenge a requisition that would manifestly violate the law of a third country. Finally, the text does not replace international judicial cooperation: existing mutual criminal assistance treaties remain in force.
The real risk, in practice, is not a wave of public requisitions. It is structural: the mere legal existence of this access door creates a sovereignty asymmetry. A European DPO can no longer consider that data hosted at a US operator is beyond the reach of a third-party authority.
2. Who is concerned by the CLOUD Act?
The legal definition of a covered provider
The CLOUD Act targets "providers of electronic communication service" and "providers of remote computing service" — that is, very broadly, providers of email, cloud storage, collaborative platforms and cloud AI. The attachment criterion is dual: either the company is incorporated in the United States, or it is substantially present on US territory — operational subsidiary, office, employees, significant contracts.
Foreign subsidiaries of US companies
This is the most counter-intuitive point for a European reader. A French, German or Irish subsidiary of a US group remains legally attachable to its parent company. A CLOUD Act request addressed to the parent may relate to data held by the subsidiary. Concretely: the major US hyperscalers on the market fall under the CLOUD Act through their European subsidiaries. This is a legal fact to factor into an impact assessment, without any value judgment on the quality of their services.
How a requisition actually unfolds
A CLOUD Act requisition follows a specific circuit that is often little known in Europe. The US authority (typically a federal prosecutor or a civilian intelligence agency) obtains a warrant from a judge — the famous "probable cause" of the 4th Amendment. The warrant is then addressed to the provider's US headquarters. The provider must preserve the data, then hand it over within a set deadline (usually a few days to a few weeks). A "gag order" may prohibit informing the person concerned, sometimes for extended periods.
Two operational points matter for a European DPO. First: the actual pace of requisitions is documented by the transparency reports published semi-annually by the major hyperscalers; these reports do not detail CLOUD Act cases precisely but give orders of magnitude (tens of thousands of requests per year, an increasing share of which is extraterritorial). Second: the provider may challenge a requisition that would manifestly violate the law of a third country, via a "comity" procedure — legally available, but rarely documented publicly in transparency reports.
Joint ventures and the "trust cloud"
Since 2021, several French initiatives have structured joint ventures to offer a cloud service operated in Europe on US-licensed technology. Bleu (co-founded by Orange and Capgemini, based on Microsoft Azure technology) and S3ns (co-founded by Thales and Google Cloud) are the most visible examples. The idea: structure operational governance to place the service outside the direct scope of the CLOUD Act, while still benefiting from the features of major hyperscalers.
Definitive qualification depends on the SecNumCloud certification issued by ANSSI, which specifically requires immunity from extra-European laws. In 2026, several offerings are under qualification. The legal debate focuses on software updates, support channels and the role of US development teams: as many points where a technical or contractual back door may remain.
💡 Point of vigilance — A provider advertising "data hosted in France" says nothing about its jurisdiction. The right question to ask: "is your company incorporated in France, without a majority capital link to a US group, and are your underlying AI models operated by entities not subject to the CLOUD Act?". Three yeses: outside the CLOUD Act. One no: within scope.
3. The GDPR / CLOUD Act conflict: CJEU and CNIL positions
Schrems II: the ruling that changed everything
On July 16, 2020, the Court of Justice of the European Union handed down the Schrems II ruling (case C-311/18). The decision invalidated the Privacy Shield, the agreement that until then had framed EU-US transfers. The main reason: US intelligence laws (including FISA 702 and Executive Order 12333) allow US authorities to access the data of European citizens without the latter having a legal remedy equivalent to that provided by European law. In other words: the level of personal data protection in the United States is not deemed equivalent to the European level.
This ruling does not explicitly cite the CLOUD Act, but it draws its context. The CLOUD Act is one of the legal building blocks of the US data access ecosystem. It concretely enables what Schrems II considers structurally problematic.
The Data Privacy Framework (2023-2024)
Following the invalidation of the Privacy Shield, the US administration and the European Commission negotiated a new agreement, adopted in July 2023 under the name Data Privacy Framework (DPF). It rests on commitments made by the US administration, notably the creation of a Data Protection Review Court (DPRC) to enable European citizens to challenge certain processing operations. It allows "DPF-certified" US companies to receive European personal data without additional standard contractual clauses.
The DPF is legally fragile. Several appeals are pending before the CJEU. Max Schrems, the activist behind the previous rulings, has announced a near-inevitable "Schrems III". The CLOUD Act remains in force and continues to allow extraterritorial requisitions. The DPF frames "normal" transfers; it does not suspend exceptional access mechanisms.
The CNIL position in 2026
For several years now, the CNIL has been inviting data controllers to conduct their own impact assessment rather than treat the DPF as an automatic guarantee. For sensitive data (health, professional secrecy, minors' data), the authority recommends vigilance in choosing providers subject to extra-European jurisdictions. A documented impact assessment is now expected for sensitive processing hosted outside the EU.
To dive deeper into the full GDPR framework applied to AI email, see our complete GDPR guide which details the DPO checklist and the handling of CLOUD Act transfers on the controller side.
4. What a professional email really contains and why that matters
The content of professional email in 2026
Professional email contains far more than the text of messages. It constitutes an extraordinarily rich database: identity of correspondents, timelines of communication, attachments, organisation structures, positions held on cases, personal preferences, incidental medical or family information. For a mid-level manager, ten years of email archives amount to tens or hundreds of thousands of messages (order of magnitude observed on the inboxes of users who share their history with us during onboarding) — a volume that, cross-referenced, allows a fine-grained map of the organisation, its relationships and its vulnerabilities to be reconstructed.
Personal data under the GDPR
The GDPR (article 4) defines personal data as "any information relating to an identified or identifiable natural person". A professional email addressed to John Smith, CFO at Client X, with the subject "your dismissal for gross misconduct", is personal data processing under the GDPR. Article 9 governs special categories: health, political opinions, trade union membership, sexual orientation. An HR attachment containing an appraisal form assessing an employee potentially falls under the scope of article 9.
Sector-specific professional secrecy
Beyond the GDPR, several professions are subject to specific secrecy obligations:
| Profession | Legal basis of secrecy | Potential sanction |
|---|---|---|
| Lawyer | Article 66-5, law of 31 December 1971 | Disciplinary + criminal sanction (art. 226-13 Criminal Code) |
| Chartered accountant | Article 21, ordinance of 19 September 1945 | Disciplinary + criminal sanction |
| Doctor | Article R.4127-4, Public Health Code | Ordinal + criminal sanction |
| Notary | Article 23, law of 25 Ventôse year XI | Disciplinary + criminal sanction |
| Banker | Article L.511-33, Monetary and Financial Code | Civil + criminal sanction |
Each of these obligations requires the professional to guarantee the confidentiality of information received in the course of their mission. The choice of digital tools used to process this information engages the professional liability of the practitioner. A firm that uses a provider subject to the CLOUD Act without a prior impact assessment exposes its disciplinary liability — and, in some cases, its criminal liability.
5. Use case 1 — Law firms
Lawyer-client privilege
Article 66-5 of the law of 31 December 1971 protects correspondence between a lawyer and their client. This privilege is absolute, general and unlimited in time. It covers written exchanges, including emails. Unauthorised access to this correspondence violates professional secrecy — and deprives the client of the protection they are entitled to in any subsequent proceedings.
Position of the French Bar Council (CNB)
The CNB has for several years communicated on the vigilance required in choosing digital tools. Recommendations invite firms to document their risk analysis, to favour solutions whose infrastructure and governance remain in Europe, and to assess exposure to extra-European laws specifically. A lawyer entrusting their inbox to a provider subject to the CLOUD Act must be able to justify that choice and the compensatory measures in place.
Disciplinary risk and bar solutions
Disciplinary risk is not hypothetical. A characterised violation of professional secrecy can lead to proceedings before the bar's disciplinary council — regardless of whether an actual access has taken place. It is the deliberate jeopardising of the secret that constitutes the breach. The bars have developed e-Mail avocat services to offer a sovereign alternative, framed by the profession. These services offer an encrypted mailbox, hosted in France, with governance operated by French bodies.
One specific case deserves attention: Anglo-Saxon e-discovery procedures. When international litigation involves a US party, the procedure provides for the forced production of relevant emails. If the correspondence of a European lawyer falls within scope and is hosted at a provider subject to US law, disclosure may be ordered by the US judge — without the European judge intervening. The French Court of cassation has repeatedly recalled that French law does not have extraterritorial effect to protect a French secret outside the national territory. This is a strategic vigilance point for firms involved in international contentious matters.
❌ Risky configuration
Law firm — email service subject to a non-European jurisdiction with no documented CLOUD Act impact assessment, AI plugin subject to US law, client correspondence stored without any sensitivity distinction.
✅ Defensible configuration
A provider with a documented impact assessment AND a French-publisher AI plugin, compartmentalisation of the most sensitive files, encryption of litigation attachments, sovereign alternative (e-Mail avocat, SecNumCloud-qualified offering) for the most sensitive matters.
6. Use case 2 — Chartered accounting firms
The chartered accountant's professional secrecy
Article 21 of the ordinance of 19 September 1945 imposes on chartered accountants a professional secrecy equivalent to that of a lawyer. It covers information received in the course of the mission: tax returns, accounting export files (FEC), exchanges on cash flow, executive compensation, clients' strategic decisions. Breach of this obligation combines a disciplinary sanction (Regional Council of the Order) and a criminal sanction (article 226-13 of the Criminal Code, one year of imprisonment and a €15,000 fine).
FECs, tax returns and sensitive attachments
The particularity of the profession: exchanges with clients go through attachments. A FEC sent by email at year-end is a flat file containing all the accounting entries of the year — a document of absolute sensitivity. A tax return attached to a closing email reveals a company's financial health, its tax positions, possibly its disputes. Multiplied by a firm's active client portfolio (a common estimate: a few hundred active files, with a seasonal peak at closing time), the volume of sensitive data hosted in the mailbox becomes considerable.
CSOEC position and recommended practices
The Conseil Supérieur de l'Ordre des Experts-Comptables (CSOEC) has since 2018 restated the professional's responsibility in choosing digital tools. Practical recommendations include: documenting the firm's data governance, running a prior impact assessment before any change of communication tool, informing clients about the providers used, and favouring — where possible — sovereign solutions for the most sensitive data. A firm using an email service subject to a non-European jurisdiction without a documented impact assessment is not acting illegally — but it must be able to justify its choice in the face of any ordinal challenge.
7. Use case 3 — Health and sensitive HR
Health data and the HDS obligation
Health data is subject to a reinforced regime: article 9 of the GDPR (special category), article L.1111-8 of the French Public Health Code and its regulatory part (articles R.1111-9 to R.1111-15-1 CSP, obligation to host with an operator certified HDS — Health Data Host). A mailbox used to exchange medical letters, prescriptions or examination reports must, in theory, be operated by a certified HDS host. Yet few mainstream mailboxes are directly certified — and the CLOUD Act question overlays the HDS question when the certified host is a subsidiary of a US group.
The HDS framework distinguishes six certifiable activities (provision and maintenance in operational condition of the physical infrastructure, provision of the operating system, provision and administration of software platforms, infrastructure management, outsourced backup, administration and operation of the information system). A professional mailbox that receives a medical report falls, depending on the configuration, into several of these activities: the provider must then cover the entire scope processed. The up-to-date list of certified hosts is published by the Agence du Numérique en Santé (esante.gouv.fr); this is the first document to consult before any tool choice.
Crucial point: HDS certification says nothing about CLOUD Act exposure. A host may be HDS-certified and still fall under US law via its parent company or its infrastructure subcontractors. The two criteria — HDS compliance and immunity from extra-European laws — must be verified separately. A practitioner who regularly receives specialist reports by email has every interest in documenting this dual verification, especially when operating in a regulated sector (medical biology, imaging, telemedicine).
Sensitive HR documents as attachments
The HR department of a mid-sized company handles, every week, documents that — taken out of context — expose the organisation to significant risks: annual appraisal forms, disciplinary procedures, employment contracts with compensation clauses, mutual termination memos, sick leave notices. These documents almost always travel by email, often as attachments. Confidentiality relies on trust in the mailbox used. Unauthorised access to these attachments creates a direct legal risk for the company (GDPR, labour law, trade secrets) and a human risk for the people concerned.
HRIS and specific certifications
Large companies often outsource HR management to HRIS (Human Resources Information Systems). Some HRIS publishers are certified against sector-specific frameworks or offer dedicated European hosting. But as soon as an HR director receives an attachment via standard email, the HRIS protection no longer applies to the email flow. The consistency of the full chain — HRIS + mailbox + attachments — becomes an audit point in its own right.
8. Use case 4 — Professions with specific obligations
Notaries: drafting of deeds and originals
The notary is a public officer. They receive and keep authentic deeds that stand as proof until challenged for forgery. Preparatory exchanges with clients (draft deeds, wealth information, family details) are covered by article 23 of the law of 25 Ventôse year XI. The Conseil Supérieur du Notariat has developed dedicated business tools (Real, Adsn) offering a secure and sovereign communication framework. Using a standard mailbox for preparatory exchanges exposes the notary to the same problem as the lawyer.
Doctors and liberal health professionals
Beyond HDS, liberal doctors have since 2018 had access to a national secure health messaging system (MSSanté) operated by the Agence du Numérique en Santé. This system offers a sovereign framework for exchanges covered by medical secrecy. In practice, a significant portion of medical exchanges still goes through mainstream mailboxes — a tolerated practice whose legal security is limited.
Defence, OIV and state sovereignty
Operators of Vital Importance (OIV, defined by articles L.1332-1 et seq. of the French Defence Code), defence industry actors and organisations subject to the NIS 2 directive are subject to reinforced rules. For these entities, the use of mailboxes subject to the CLOUD Act for classified or strategic data is explicitly framed, and even prohibited. The SecNumCloud framework issued by ANSSI plays the role of reference certification for these uses.
The NIS 2 directive (EU directive 2022/2555), transposed into French law by law no. 2025-391 of 30 April 2025, extends the scope of Operators of Essential Services and introduces the Important Entities: health, financial services, transport, energy, public administration. Many SMEs and mid-sized companies that were not concerned by NIS 1 become so under NIS 2. For these entities, the question of the choice of mail tools becomes a mandatory audit object — national supervisory authorities (ANSSI in France) may demand accounts on the full chain.
The link with the CLOUD Act is direct: a NIS 2 entity that hosts its mailbox with a provider subject to US law must be able to demonstrate that this exposure has been analysed and knowingly accepted, with proportionate compensatory measures. The absence of a documented analysis becomes, in 2026, a recurring audit point.
9. The 3 levers to protect against the CLOUD Act
Faced with this legal architecture, three levers are available. None solves the question on its own; combined, they significantly reduce exposure. They are detailed below, in order of effectiveness.
Lever 1 — Technical: choose a provider not subject to US law
This is the most radical lever, and the only one that addresses the problem at its source. Select a provider whose publisher, infrastructure AND underlying AI models are operated by European entities, outside US capital control. The check must cover the full chain: publishing company, host, subcontractors, AI models used for generation and analysis.
Concretely, for a professional inbox: favour a French or European provider that has obtained the SecNumCloud certification (ANSSI) or an equivalent certification. For the AI layer: favour models operated by a European publisher (Mistral, LightOn, Aleph Alpha), with inference hosting in the EU.
For an in-depth comparative analysis, our guide to the 4 hosting configurations of an AI email assistant details the possible combinations, from 100% France to hybrid under standard contractual clauses.
Impact: outside CLOUD Act if the chain is completeLever 2 — Contractual: solid DPAs and notification clauses
The contractual lever has a real but limited usefulness against an extra-European law. A private contract cannot neutralise a legal obligation imposed on a party by its own jurisdiction. What the contract can do, however: oblige the provider to notify any foreign requisition as soon as possible (subject to US gag orders), precisely document subcontractors and their location, commit to technical measures (encryption, compartmentalisation), and provide for penalties in case of breach.
The European Commission's standard Data Processing Agreement (SCC 2021) is a starting point. It should be supplemented by a specific CLOUD Act addendum for sensitive data. The legal value of these clauses is still debated — but they create a valuable audit trail in the event of litigation.
Impact: traceability + audit, not neutralisationLever 3 — Organisational: encryption and compartmentalisation
Three concrete practices. First: end-to-end encryption of the most sensitive exchanges, via dedicated tools (S/MIME, PGP, or encrypted messaging like Tuta, ProtonMail, Olvid for ministerial communication). Second: compartmentalisation of data by sensitivity level — the most sensitive files do not transit through the main mailbox, but through a dedicated channel (secure client portal, digital vault). Third: training of employees to identify content that must not transit through mainstream cloud tools.
Compartmentalisation is particularly effective: it reduces the volume of exposed data without requiring a full infrastructure change. A law firm can keep its main mailbox for day-to-day operations and use a sovereign tool only for the 5 to 10% most sensitive files.
Impact: significant reduction in exposed volumeComparative synthesis of the 3 levers
The three levers are not mutually exclusive — they combine. The table below positions each one against four operational criteria: legal effectiveness, switching cost, reversibility (ease of walking back if the analysis needs to be revised) and adoption effort for end users.
| Criterion | Lever 1 — Technical | Lever 2 — Contractual | Lever 3 — Organisational |
|---|---|---|---|
| Legal effectiveness | High — addresses the question at source | Low in law — audit trail + notification | Medium — depends on compartmented scope |
| Switching cost | High if full migration, moderate if AI layer only | Low — contract negotiation only | Moderate — dedicated tool + training |
| Reversibility | Medium — two-way migration possible | High — a contract is renegotiated | High — the sensitivity matrix can evolve |
| User effort | Low if ergonomics are equivalent | Zero — invisible for users | High — colleagues change habits |
| When to prefer | Recent set-ups, professions with absolute secrecy | Historical context, gradual migration | Firms with heterogeneous file sensitivity |
The combination recommended in practice: lever 1 on the AI layer (choice of a sovereign publisher), lever 3 on the most sensitive files (compartmentalisation + end-to-end encryption), lever 2 everywhere as a traceability safety net. This three-tier approach produces an impact assessment that is defensible before a professional order, a DPO regulator or a client concerned with compliance.
Understand our privacy policy in detail.
The dedicated page details the full processing chain, the subcontractors used, and the guarantees provided on data sovereignty.
Read the privacy policy →10. The Neston approach
Neston is a French publisher, headquartered in France, not owned by a US group — a structure that places the publisher directly outside the scope of the CLOUD Act, with an optional Mistral EU setting to route the AI layer to a model hosted in the European Union. Important transparency point: the underlying mailbox (Outlook, Gmail) remains under the jurisdiction of its provider. Our tool adds a sovereign AI layer on top of your existing mailbox; it does not replace the strategic choice of the mail provider itself. A full chain outside the CLOUD Act therefore requires combining this sovereign AI layer with a sovereign mailbox (e-Mail avocat, SecNumCloud-qualified offering, or an equivalent European solution).
To understand the broader criteria for choosing an AI email assistant, see our dedicated article on criteria for choosing an AI email assistant. For our product position on sovereignty, see our position on sovereignty.
Estimate the ROI of a sovereign AI email assistant for your firm.
Our simulator calculates the annual savings based on your profession, your email volume and your loaded hourly cost. Result in euros and in hours recovered per year.
Launch the simulator →11. Frequently asked questions (FAQ)
In summary: the key points to remember
- The CLOUD Act, adopted on March 23, 2018, authorises extraterritorial access to data held by any provider subject to US law, regardless of the hosting country
- Physical location does not change the applicable jurisdiction — what matters is the legal entity of the provider
- The GDPR does not neutralise the CLOUD Act — the Schrems II ruling (2020) acknowledged the unresolved conflict
- Regulated professions (lawyers, chartered accountants, doctors, notaries) carry a reinforced responsibility in choosing tools
- 3 protection levers: technical (EU publisher / EU infrastructure / EU AI models), contractual (solid DPAs), organisational (encryption + compartmentalisation)
- The major US hyperscalers fall under the CLOUD Act — a legal fact to factor into your impact assessment, with no value judgment on the quality of their services
- A documented impact assessment is now expected by the CNIL for sensitive processing hosted outside the EU
- The SecNumCloud certification from ANSSI remains the best indicator of immunity from extra-European laws
The CLOUD Act is not a reason to panic — it is a legal parameter to factor into the tooling decision. In 2026, no organisation handling sensitive data can skip a specific impact assessment. The right question is no longer "can I use this provider" — it is "what level of exposure am I willing to assume, for what type of data, with what documented compensatory measures".
📚 Further reading
- AI and email in 2026: the complete GDPR guide
- Hosting an AI email assistant in France: the 4 configurations
- Neston manifesto: our position on sovereignty
- Writing professional emails with AI — Complete guide
- Generative AI for the inbox — 2026 overview
- Simulator: how much can you save per year?
An AI email assistant published by a French company, outside the CLOUD Act.
Neston installs into Outlook in a few minutes, learns your style, and offers a Mistral EU option for the most sensitive processing. Neston is available with a 14-day free trial, no credit card required.
Join the beta waitlist →Windows 10/11 · Outlook · Mistral EU option (GDPR)
🔬 Sources & methodology
- Congress.gov — CLOUD Act (Division V of the Consolidated Appropriations Act, 2018, Pub. L. 115-141) — official text amending the Stored Communications Act and the Electronic Communications Privacy Act, sections 101 to 106
- CJEU — Schrems II ruling (C-311/18, 16 July 2020) — invalidation of the Privacy Shield and framework applicable to EU-US transfers
- CNIL — "Data transfers outside the EU" file — GDPR framework applicable to transfers and impact assessment
- Conseil National des Barreaux — communications on digital tools and lawyer-client privilege
- ANSSI — SecNumCloud framework — French certification of immunity from extra-European laws for cloud service providers
- Law no. 71-1130 of 31 December 1971, article 66-5 — lawyer-client privilege
- Ordinance no. 45-2138 of 19 September 1945, article 21 — chartered accountant's professional secrecy
Article published on August 24, 2026 · Updated on August 25, 2026 · Reading time: 18 minutes · ≈ 4,900 words