If you are a law firm, accounting practice, financial adviser or recruiting consultant holding sensitive personal data on behalf of clients and candidates, the location of that data has quietly become a question you will be asked — and "it's in the cloud" is no longer an answer. The reason is not a single breach. It is ambiguity: a US legal regime that can compel American providers to hand over data regardless of where the servers sit, and a US administration whose posture makes that power feel unpredictable. This article explains what your clients are actually worried about and how to give them an answer that holds.
The fear is not hypothetical, and it reached the Swedish front pages this week. When a national agency the size of Trafikverket cannot settle internally whether moving to a US cloud is safe, a five-person firm holding client identity documents in the same ecosystem is exposed to exactly the same question — with none of the legal department.
On 24 June 2026, Sweden's public broadcaster revealed that the Swedish Transport Administration (Trafikverket) is moving parts of its operations onto US cloud services from Microsoft. Internal IT staff at the Borlänge head office had filed formal warnings: the decision basis was unclear, sensitive information could be exposed, and costs could rise several-fold. The IT director dismissed the criticism as the normal range of opinion inside a large agency and said only non-sensitive, public information would be involved.
Microsoft's written response is the part worth dwelling on. The company said it has legal, technical and contractual protections, and that it would contest any request from US authorities that conflicts with European law. Read that carefully: the assurance is not "this cannot happen." It is "if it happens, we will fight it." That gap — between cannot and will-try-to — is the entire problem.
It is rarely a specific hacker. In sales conversations the worry that comes up again and again is the ambiguity itself: a US administration that appears willing to disregard established norms, combined with laws that reach across the Atlantic. Two US legal instruments sit underneath it.
| Instrument | What it permits | Why it reaches EU-stored data |
|---|---|---|
| Cloud Act | US courts can compel a US-headquartered provider to produce data under a warrant. | Applies regardless of where the servers physically are — including a datacentre inside the EU. |
| FISA 702 | Targeted signals collection against non-US persons. | Requests are made to the provider via selectors; the customer has no visibility or control over what is handed over. |
This is not a fringe reading. In late May 2026 the Swedish Armed Forces' own cloud strategy rejected the tech giants' reassurances as "false security," citing both the Cloud Act and FISA as far-reaching obligations to hand over data — a decision we looked at in more detail in Försvaret nobbar amerikanskt moln. In the same period the Swedish government published a national cloud policy conceding that one-sided dependence on foreign providers subject to problematic extraterritorial legislation carries significant risk — while critics noted the policy is only guidance, not a binding requirement. The direction of travel is unmistakable.
Here is the insider point. A great many e-signature platforms, client portals and verification tools are built on top of US hyperscale cloud, even when they market an "EU data residency" option. Residency means the bytes sit on a server in Europe. It does not, on its own, remove the provider from the reach of the Cloud Act if that provider — or its parent — is US-headquartered. Firms discover this distinction late, usually when a client or their general counsel asks the question directly and the honest answer turns out to be "we're not actually sure."
The realisation usually arrives in one of two ways. The first is a client questionnaire: a corporate client, a bank, or a public-sector body sends a vendor-security form asking, in writing, where personal data is processed and whether any non-EU party can access it. The firm forwards the question to its signing or portal provider and gets back a paragraph that carefully says "data is stored in the EU" while never quite answering who can be compelled to hand it over. The second is an incident in the news — a Trafikverket, an armed-forces strategy, a government policy — that prompts a managing partner to ask the question internally for the first time and find that nobody knows the answer.
Either way, the discovery is the same: "EU data residency" was treated as the end of the analysis when it was only the beginning. Residency answers where the bytes rest. It does not answer who has legal reach over the company holding them. For a firm whose entire value rests on client confidence, learning that distinction in front of a client is the expensive way to learn it.
The defensible answer is structural, not contractual. It means the data sits with a provider that is not subject to US extraterritorial reach in the first place, operating under EU law and audited against it. For identity and signing specifically, that aligns with the eIDAS framework and the GDPR security-of-processing duty under Article 32 — obligations you already carry as the controller of your clients' personal data.
A firm that can answer the data-location question well has three things:
This is where ZealiD's position differs by design. As a Swedish Qualified Trust Service Provider on the EU Trusted List, all account content in Trust Circle is hosted and operated within the EEA under sole EU operational control, with no third party holding independent access to unencrypted content — which means that when a client asks where their data sits and who can reach it, the answer is short, specific and does not end with "but we'd contest it."