CLOUD Act vs GDPR data sovereignty: the risk of U.S. providers for EU body-worn video

Many organisations assume that storing data in the EU means the data stays under EU control. For body-worn video, that assumption can be dangerously incomplete.

If your provider falls under U.S. jurisdiction, a U.S. legal order may still reach data stored in Europe. For public-sector organisations and legal teams, that is not a technical footnote. It is a governance risk.

Storing data in Europe is not the same as controlling it

Data sovereignty is often treated as a question of geography. In practice, it is just as much about legal reach and operational control.

Eurojust, the EU agency that supports judicial cooperation in criminal matters, has explained that the U.S. CLOUD Act made explicit that U.S. service providers can be required to preserve and produce data they control, regardless of where that data is stored.

In plain language: EU hosting does not automatically remove U.S. legal exposure when the provider remains subject to U.S. jurisdiction.

For organisations handling body-worn video, that distinction matters. These systems often process sensitive footage, involve public-facing incidents, and sit in environments where accountability and chain of custody matter.

The risk becomes more serious when:

  • the provider is subject to U.S. jurisdiction through ownership, control, or operational nexus
  • support or administration can access data from outside the EEA (European Economic Area)
  • sub-processors sit in third countries, or key services rely on non-EEA entities

The CJEU’s Schrems II ruling underlined why this matters. EU law requires essentially equivalent protection when personal data is exposed to third-country public authority access.

Where the tension starts: U.S. legal access versus EU data protection rules

GDPR is not the source of the problem. The real issue is that U.S. law may compel certain providers to disclose data under their control, while EU data protection law sets strict limits on when personal data may be disclosed or transferred.

That creates a direct tension for organisations handling sensitive body-worn video. Even if the data is stored in the EU, exposure to a provider under U.S. jurisdiction can still raise sovereignty and compliance questions.

The European Data Protection Board has clarified that a foreign government order does not automatically create a lawful basis under GDPR for disclosure or transfer. In other words, receiving an order is not the same as being allowed to comply with it under EU law.

For legal teams and procurement leads, that means vendor assessment should go beyond storage location alone.

A checklist for Legal Affairs and procurement

When assessing a provider, the key questions are straightforward:

  • Who is the legal counterparty, and which jurisdiction governs it?
  • Who can technically access the data, including support and incident response?
  • What is the documented process for third-country requests, including challenge, notification, and transparency reporting?
  • Who controls the encryption keys, and can the provider access them?

EDPB Recommendations 01/2020 also explain why supplementary measures, including strong encryption and organisational controls, may be necessary when transfer tools alone do not provide EU-equivalent protection.

What this means in practice

For many organisations, the practical lesson is simple: EU data storage on its own is not enough. If sensitive video data may still be reached through U.S. jurisdiction, then the real assessment has to include provider structure, operational access, subprocessors, and governance.

That is especially relevant for police, enforcement, inspection, and other public-sector contexts where recorded footage can contain personal data, evidence, or legally sensitive material.

Where ZEPCAM fits

For organisations that want to reduce potential exposure to U.S. jurisdiction, a more structural mitigation is to choose a body-worn video provider whose ownership, hosting model, and operational setup are designed to minimise that exposure as far as possible.

ZEPCAM is a European body-worn video provider headquartered in the Netherlands, with a Dutch legal and operational base. It offers deployment options that can support stronger local control over sensitive video data, including ZEPCAM-managed hosting in selected jurisdictions and customer-controlled infrastructure where applicable and on-premise installation.

ZEPCAM also highlights recognised certifications for information security, cloud security, and privacy controls, including ISO 27001, ISO 27017 and ISO 27018, where applicable within its service model.

This does not remove every compliance obligation, but it can help organisations reduce legal and operational exposure compared with provider models that remain more closely tied to non-EU jurisdiction.

Final thought

If body-worn video is part of your operational or legal workflow, the right question is not only where your data is stored. The more important question is who can ultimately be compelled to access it.

That is where the difference between storage and sovereignty becomes very real.

Share This