Get a free audit

Field Notes / Data Sovereignty

The UK Is Not Just Exposed to the CLOUD Act. It Signed the Agreement That Runs Both Ways.

The US-UK Data Access Agreement has been in force since October 2022. A section 253 notice can compel a provider to change its service and forbid it from telling you, which is how Apple came to withdraw Advanced Data Protection for new UK users. Neither is a control you can test. Here is the part of your cloud estate that is, and what we find when we look.

Author
Red Team Partners
Read
12 MIN READ
Filed
07 Sep 2026
London at night, above a cloud estate whose jurisdiction is decided by company law rather than by where the racks sit.

01 Two doors, and the UK holds a key to both

he CLOUD Act was passed on 23 March 2018 to end a long fight between the United States and Microsoft over emails held in an Irish data centre. It settled the fight by making location irrelevant. A provider under US jurisdiction produces what it owns, holds or controls, wherever it sits. Six months of debate about where to put the racks was answered by company law instead of geography.

Microsoft, Google and Amazon Web Services all run UK regions. Those regions are real and they solve real problems: latency, procurement rules, public sector policy, GDPR transfer mechanics. What a region does not change is where the parent company is incorporated. Asked directly by the French Senate in June 2025 whether it could guarantee under oath that European data would never reach US authorities, Microsoft France answered that it could not The Register 2025 . That answer applies with equal force to a London region.

The Data Access Agreement adds the second door. Its safeguards are genuine: requests must concern serious crime, and a request sent to the UK must not target people located in the UK. Read that safeguard carefully, though, because it protects UK residents from US requests. It does not protect the non-UK people in your customer database, your international staff, or the subsidiary you acquired in Frankfurt last year.

02 The order your provider cannot tell you about

A technical capability notice compels a company to build or retain a capability that assists UK investigatory powers. The recipient cannot disclose the notice. The Investigatory Powers (Amendment) Act 2024 tightened the regime further, including obligations around notifying the Home Office before making certain changes to a service IPA 2016 s.253 .

The Apple sequence is the only public case study you have. A notice in January 2025 reportedly sought access to encrypted iCloud data. Apple removed Advanced Data Protection for new UK users in February rather than build the capability. In October 2025 the Financial Times reported that the first notice had been withdrawn and a second issued, narrowed to British users. Privacy International and Liberty are challenging the power at the Investigatory Powers Tribunal, with a case management hearing this month and a substantive hearing listed for December 2026 Privacy International .

Set aside the politics. For your threat model the structural fact is this: a provider in your supply chain can be ordered to alter its service and prohibited from telling you. Your vendor questionnaire cannot detect that. Your SOC 2 report cannot detect it. The assurance industry runs on attestations, and an attestation is a statement by someone who may be legally barred from making a different one.

There is one signal available, and Apple gave it. Watch for capability withdrawal. A provider that quietly drops end-to-end encryption, removes a key-custody option, changes its jurisdictional wording, or restricts a security feature in one country only is telling you something it cannot say in a sentence. Put that on a monitoring list. It is cheap and almost nobody does it.

THE SILENT CHANGE An abstract data estate, where the boundary that matters is drawn by company law rather than by network topology.
A withdrawn feature is sometimes the only public evidence that a secret notice exists. Monitor your providers' capability changes, not just their status pages.

03 Residency is a claim. Here is what testing finds.

Almost everything written about the CLOUD Act is legal analysis, and the legal analysis has been settled for years. What is missing is the measurement. You cannot test jurisdiction. You can test everything underneath it, and when we test an estate carrying a "your data stays in the UK" promise, we look for five things. We rarely find none of them.

What is promisedWhat measurement usually shows
Data stays in the UK regionProduction data does. Backups and disaster recovery copies replicate to a second region outside it
Encryption with your own keysKeys held in the provider's HSM, inside the provider's trust boundary, operated by the provider. The label says customer-managed, the custody says otherwise
No provider access without approvalSupport and administration paths that engage during incidents, logged to a place nobody has ever read
Only payload data needs protectingTelemetry, diagnostics, logs and metadata leave the boundary as routine. Metadata answers who, with whom, when and how often
The subprocessor is UK-basedTier three and tier four of the chain are not, and tier four does not appear in the contract at all

The fourth row deserves particular attention. Sovereignty debates focus on content because content is what people picture. Investigators have always valued connection data at least as highly. Who spoke to whom, how often, from which device, at what hour. That data is rarely encrypted, because operations need to read it, and it is rarely covered by a residency promise, because it never comes up in a sales conversation.

None of this is an accusation against the hyperscalers. These gaps come from operational necessity, from defaults nobody changed, and from migrations where somebody set an exception and never took it back. We find the same patterns in estates hosted by British providers. The point is not who you trust. The point is that a promise nobody has measured is an expectation rather than a control.

04 What the contract says against what the packets do

UK GDPR and the Data Protection Act 2018 make you the controller. That status does not move because you bought a managed service. Article 28 obliges you to use processors that provide sufficient guarantees, and Article 5(2) makes you accountable for demonstrating compliance rather than asserting it. The ICO has been consistent that due diligence on a processor is an ongoing obligation, not a procurement event.

Here is the practical translation. If your data protection impact assessment says data remains in the UK, and your backups replicate to Dublin, you do not have a legal problem with the CLOUD Act. You have a factual error in a document you signed. The second is easier to fix and considerably more embarrassing to discover during an incident.

For firms under FCA supervision, operational resilience adds a second lens. SYSC 8 outsourcing obligations and the resilience regime both assume you know what your important business services depend on, all the way down. A dependency you cannot name is a dependency you cannot recover from. The CLOUD Act question and the resilience question have the same first step, and it is an accurate map.

05 What to fix this quarter

The job is not to defeat the CLOUD Act. It is to shrink the amount of useful material an order reaches, and to carry the remainder knowingly and on the record. A demonstrated measurement of your provider's promises is worth more in front of the ICO or the FCA than any certificate, because it is evidence rather than assertion.

Remediation Log
  • A data flow map that separates production, backups, logs, telemetry and support access, each labelled with its actual region rather than its promised one
  • Key custody verified: are your keys genuinely outside the provider trust boundary, and what happens to your data when you revoke them
  • The datasets whose disclosure would actually hurt identified first, and those encrypted under keys you hold
  • Provider administration and support access inventoried, logged, and the logs read by a named person on a schedule
  • Subprocessor chain mapped to tier three and four, with the governing jurisdiction recorded at each tier rather than only at the contracting party
  • A watch list for capability withdrawal: removed encryption options, changed jurisdiction wording, security features restricted in one country only
  • Legal position on the Data Access Agreement and section 253 exposure documented with counsel and filed with the DPIA, with an owner and a review date

Apple told you a notice existed by removing a feature. Microsoft told the French Senate where the guarantee ends. Both are honest answers to questions your vendor questionnaire never asked. What happens inside your own estate, below the line those answers draw, is knowable, and nobody knows it until somebody measures it. We measure it: where your data goes, what your keys really protect, what your provider's admin plane reaches, and where the contract and the packets disagree. You get the gaps and a fix order. Enterprise-grade. Not enterprise-priced. Start with your Threat Map.

References

Sources

  1. US Department of Justice. Landmark U.S.-UK Data Access Agreement Enters into Force. 3 October 2022. justice.gov
  2. Investigatory Powers Act 2016, section 253 (technical capability notices), as amended by the Investigatory Powers (Amendment) Act 2024. legislation.gov.uk
  3. Apple Support. Apple can no longer offer Advanced Data Protection in the United Kingdom to new users. 21 February 2025. support.apple.com
  4. Privacy International. Our challenge against the UK’s secret TCN powers. privacyinternational.org
  5. The Register. Microsoft exec admits it cannot guarantee data sovereignty. 25 July 2025. theregister.com
  6. CMS. Demystifying the debate on the US CLOUD Act vs European and UK data sovereignty in cloud services. cms.law