Risks of Transferring Personal Data to the United States
Last updated: 13 September 2026
Risks of using US cloud platforms, direct or indirect, even when the servers and the data are in the EU.
They own the data about your audience
We warn organisations not to use US-owned cloud services, even when the servers and the data are located in the EU. One key reason is simple and almost always overlooked: every US cloud service automatically generates crucial metadata: access logs, session data, IP addresses, device and location information, timestamps, and which webpage, object, video, livestream or document was opened, when, and for how long. That metadata contains personal data of your viewers, the provider generates it, stores it unencrypted on systems under US oversight, and automatically becomes the owner of it, not you.
That is a serious risk, because the provider can access the personal data of your audienceand watch along with what your viewers are watching. And it can profile them. What if someone watches politically sensitive content through your video platform? What if the provider combines ITS data about YOUR viewers with other datasets and profiles and targets your viewers individually? What if it runs YOUR audience data through AI and gains deep insight into your reach figures, your audience and your business, and then competes with you using your own data, which is legally theirs? You might think people and organisations would not go that far. Look at how few scruples the industry has shown when it comes to hoovering up personal data around advertising.
Encryption does not help here. You can encrypt the content you store, with your own keys. You cannot encrypt, see or take with you the metadata the provider creates about your users. EU data residency does not help either: the logs are generated on the provider’s systems and belong to the provider, regardless of where the servers stand.
The better-known risks: forced disclosure and going dark
On top of that you run the more familiar risks. A US provider can be forced under US law (the CLOUD Act, FISA) to hand over these data, wherever the servers are and with no real legal recourse for Europeans. And your service can be switched off. US providers are bound by US executive orders, sanctions and export controls and will follow them, whatever your contract says. In 2025 US sanctions led to a US provider disabling the e-mail of the International Criminal Court’s chief prosecutor. Technical infrastructure has been politically weaponised more than once.
If video and streaming are core business for you, this hits you hard: in your revenue, your reputation, and possibly the survival of your company. You do not even have to be the target. If you are completely innocent but sit on a platform that also hosts someone who is, rightly or wrongly, designated as an unwelcome person or organisation, you can still become a victim when that service goes dark. There is no notice period and no plan B unless you built one in advance.
Fines, reputational damage and washing
Separately, you risk fines and reputational damage because you are not complying with the law, or because your supplier engages in sovereignty-washing or privacy-washing and you did not do your homework. “Sovereign”, “EU-hosted” and “privacy by design” are marketing labels until verified: check ownership and ultimate jurisdiction, the actual technology stack and sub-processor chain, where usage and support data go, who holds the keys, and the compliance evidence itself (processing agreement, transfer impact assessment, certifications, audit reports). Under the GDPR the accountability stays with you as the customer. Their shortcoming and their deception suddenly become your problem. The Dutch regulator fined Uber 290 million euro in 2024 for unsafe transfers to the US.
What the law says: two blogs by Sjoera Nas
Sjoera Nas, privacy expert and adviser at Privacy Company, published two blogs on this subject, recently, in September 2026. Her analysis underpins the above:
- The permission to transfer data to the US is formally still valid, but hollow. The EU allows transfers because the European Commission decided in 2023 that the US offered “adequate” protection (the EU-US Data Privacy Framework). Note that this adequacy decision only covers US companies that have voluntarily certified under the EU-US DPF; for any other US provider it never applied and transfers already require other safeguards. The Dutch State Secretary for Justice confirmed on 27 August 2026 that the decision is still in force. But the safeguards it rests on have been dismantled: the US oversight board (PCLOB) has lost its members and cannot function; the executive order the deal rests on may have been revoked by a secret presidential order; and on 29 June 2026 the US Supreme Court ruled that the President may dismiss independent regulators at will. European regulators formally raised the alarm with the Commission on 31 July 2026. The Court of Justice already struck down two earlier EU-US agreements; a third case (Latombe) is pending, and an annulment takes effect immediately, without a transition period. The Dutch government already warns against providers under non-European law for core tasks.
- Contracts (SCCs) are not a fallback. Standard Contractual Clauses are a written promise by the provider to follow EU rules. They cover only the content you store; for account, diagnostic, support and website data, the very metadata described above, the provider acts as independent controller, outside the contract. The provider must assess the transfer risks but need not share that assessment with you; large providers invoke legal privilege. Privacy Company has never seen a provider warn customers about changed laws or government orders. And the Court ruled in Schrems II that SCC transfers must stop when the destination country’s law prevents adequate protection, which an annulment would establish for the US. Even while SCCs are formally still considered valid, the risks are far too great to rely on them.
- Encryption only covers stored content. Customer-managed encryption is necessary for sensitive data if you stay on US platforms, but you risk losing everything if key management fails, and it does nothing for the metadata the provider generates itself.
- EU data residency covers content only. Usage and account data still flow to the US and to subcontractors in third countries such as India, the Philippines, Kenya or Ghana.
What to do now
- Inventory and exit strategy. Map every dependency on non-European providers, including the usage data behind “EU-only” storage. Draft an exit plan per service before a court ruling or a political decision forces it on you.
- Renegotiate. Review all processing agreements. Ask providers to commit in writing to moving to an exclusively European provider if the adequacy decision falls. Do not stop asking when a provider says “content stays in the EU”.
- Choose European. From highest to lowest protection: a 100% European-owned provider with the required sovereignty level (for example SEAL-3); a European provider on European or US technology; a US provider’s “sovereign cloud” (US authorities can still reach usage data); customer-managed encryption on US platforms as a last resort. For the metadata layer, only the first option truly solves the problem.
- Vet every supplier. Verify technically and through compliance documentation, to avoid sovereignty-washing and privacy-washing. A supplier that will not show its documentation is asking you to carry its risk.
- Invest in people. Retrain system administrators for European alternatives. Mature options exist; see european-alternatives.eu and eualternative.eu.
Sources: Sjoera Nas, Privacy Company: Mag je nog persoonsgegevens doorgeven naar de VS? (3 September 2026), https://www.privacycompany.eu/nl/blog/mag-je-nog-persoonsgegevens-doorgeven-naar-de-vs; Mag je nog persoonsgegevens doorgeven op basis van SCC’s als de VS niet meer adequaat zijn? (10 September 2026), https://www.privacycompany.eu/nl/blog/mag-je-persoonsgegevens-doorgeven-obv-sccs-als-vs-niet-adequaat-zijn.