Menu
← All articles

US cloud risks: what Dutch coaches need to know

US cloud risks: what Dutch coaches need to know

A pair of hands locks the door of a secure server cabinet in the cloud.

Yes, US cloud services carry a legal risk for Dutch organisations. The decisive factor is not where the servers are located, but who owns the company behind the service. Under the US CLOUD Act, US authorities can demand data from a US company, even if that data is stored in Frankfurt or Amsterdam.

For coaches and small practices, this means one concrete thing: start a brief risk assessment today.

  • Map out which client data is sensitive (case files, health information, notes about personal problems).
  • Carry out a data protection impact assessment (DPIA), or make a simple risk assessment before choosing new software.
  • Consider EU-hosted alternatives or ask your existing providers about customer-managed encryption keys.

The Dutch Data Protection Authority (AP), the NCSC and the EU–US Data Privacy Framework all play a role in this consideration. Below you'll read exactly what they advise and how to translate that into your own practice.

Key takeaways

The legal risk of US cloud services lies in ownership and jurisdiction, not in the physical location of servers, and can only be mitigated with a combination of technical, contractual and documentation steps.

Point Details
Ownership determines the risk The CLOUD Act applies to US companies, even when data is stored in Europe.
Check DPF participation Verify whether your provider is actively enrolled in the Data Privacy Framework, not just whether they claim to be.
A sovereign cloud is no silver bullet AWS, Microsoft and Google offer additional European configurations, but the parent company's US jurisdiction remains.
Document your reasoning Record why you do or do not choose a US cloud solution and review this annually.
Deliberately choose EU hosting Exantur offers coaches EU hosting in Frankfurt as an alternative to US cloud solutions.

Table of contents

What does the CLOUD Act govern and why does it affect Dutch organisations?

The CLOUD Act is US legislation that gives US law enforcement agencies the right to demand data from US companies, regardless of where that data is physically located. A US parent company remains subject to this law, even if its European subsidiary neatly hosts everything in Frankfurt.

For a Dutch organisation, this means the promise that "your data stays in Europe" does not automatically protect against a US request. It's about ownership, not location.

Suppose you are a coach and use a US SaaS tool for client files. Those files might be stored on a server in Ireland, but if the parent company is based in California, a US court order can still demand access to those files. The location of the server changes nothing about that.

This is precisely why Cloud.nl emphasises that the 2018 law grants extraterritorial authority: US jurisdiction follows the company, not the cable.

What does the Data Privacy Framework mean for your practice?

The EU–US Data Privacy Framework (DPF) is an approval by the European Commission that permits the transfer of personal data to participating US companies without additional contractual constructions. In short: if a US provider is enrolled in the DPF, you may in principle share data without extra paperwork.

Without DPF participation, or in case of doubt, additional measures are needed, such as Standard Contractual Clauses (SCCs) and your own risk assessment.

  • Always check whether your provider is actively on the DPF list, not just whether they claim to be on their website.
  • If in doubt, ask for the provider's latest transparency report.
  • Record which additional measures you have taken when a provider does not participate.

The DPF replaces the earlier Privacy Shield, which was declared invalid by the European Court of Justice. That precedent is precisely why SURF warns that the current adequacy decision, too, could be reconsidered through court proceedings or geopolitical tensions. Anyone who now relies solely on the DPF, without SCCs as a safety net, is building on ground that has already subsided once before.

Which technical and contractual measures really help?

No single measure reduces the risk to zero, but a few concrete steps significantly lower it. Technology and contracts work best together.

On the technical side, it helps to manage the encryption key yourself instead of leaving it to the provider. That way, a provider may hand over data upon request, but without the key that data is unreadable. Strong login security with multi-factor authentication (MFA, where in addition to a password you also use a code or app to log in) is a standard part of this.

On the contractual side, it comes down to SCCs, Binding Corporate Rules (BCR) and a clear data processing agreement setting out who is responsible for what. Also ask questions further down the chain: which subcontractors does your provider use, and where are they located?

  • Manage your own encryption key where possible, instead of fully trusting the provider.
  • Enable MFA for everyone who has access to client data.
  • Ask for an up-to-date data processing agreement and check the subcontractor list.
  • Reassess providers periodically, not just at the initial choice.

Pro tip: Pseudonymise client names before uploading sensitive notes to a cloud tool. Use initials or a client number instead of the full name, so that a file on its own is not directly traceable.

As Perrit points out: encryption helps, but if the provider manages the key itself, a court order can still compel that provider to unlock it.

Does a 'sovereign' cloud solve the problem?

Amazon, Microsoft and Google now offer variants that present themselves as "sovereign": AWS European Sovereign Cloud, Microsoft EU Data Boundary and Google Sovereign Controls. These products add genuine technical options, such as additional European data centres, separate key management options and restrictions on where administrative staff are located.

What they don't solve: the parent company remains American and therefore remains subject to US legislation. A technical configuration changes nothing about that legal reality.

  • These products can reduce the risk of unauthorised access by third parties.
  • They change nothing about the authority of US authorities to demand data via the parent company.
  • For healthcare and government, where regulators are especially cautious, this distinction is often decisive.

For a coaching practice with everyday administration, this kind of configuration may offer sufficient comfort. For those working with medical data or government files, the situation is different.

What do the AP, the NCSC and the Dutch government advise?

What do the AP, the NCSC and the Dutch government advise? — overview diagram

The Dutch Data Protection Authority advises organisations to preferably use cloud services that are not subject to the legislation of countries outside the European Economic Area, certainly for health-sensitive data.

The NCSC observes that in practice it is often difficult to determine exactly whether extraterritorial legislation actually grants access to European data, and therefore advises a thorough risk analysis of both the provider and the entire chain behind it.

The controller always remains ultimately responsible. You cannot fully outsource that risk to a provider, however well the contracts are drafted.

This tension also comes up in the answers to parliamentary questions: the government-wide cloud policy has to deal with providers that are subject to foreign legislation. For the healthcare sector, the AP specifically warned executives against the use of US cloud services for health data.

Practical checklist: which steps should you take?

A structured approach prevents you from overlooking risks or making isolated decisions without any basis.

  1. Inventory and classify your data. Which client data is sensitive (health, personal problems, financial information) and which is neutral?
  2. Map out your provider chain. Who owns each tool you use, and is it subject to US legislation? Is the provider on the DPF list?
  3. Carry out a risk assessment where needed. In case of doubt, deploy SCCs and additional technical measures such as your own key management.
  4. Document your decision. Record why you do or do not choose a US cloud solution, and review that choice periodically.

These four steps take an afternoon, not a month. The result is a decision document with which, during an audit or when a client asks, you can simply show that you have thought about it.

How does a coach tackle this in practice?

A coaching practice that had client files stored in a US tool decided to migrate to an EU-hosted system with its own key management. Prior to the migration, the practice recorded in a short document which data was sensitive and why EU hosting was preferred.

  • The coach first carried out a simple risk assessment on the existing tool.
  • A decision document was produced setting out which consideration had been made and why.
  • After migration, that document was retained as evidence of due diligence.

This kind of documentation is precisely what regulators expect: not perfection, but a demonstrable, well-considered choice. Anyone who takes such steps shows that responsibility for personal data is taken seriously. Background on this, including the warning that a data processing agreement alone is not sufficient against a US court order, is woven into the AP's advice above.

When is a risk acceptable and when is it not?

Risk is not by definition a problem. The problem arises when you take the risk without recognising it. For general administration, a US cloud tool with good security is an acceptable choice for many practices. For sensitive client files, health information or work involving minors, the bar is higher, and EU-hosted storage deserves preference.

What matters is not which choice you make, but whether you can justify that choice. Record the reasoning, review it every year, and switch providers as soon as the risks outweigh the convenience.

An EU-hosted option for coaches who want certainty

As a coach, what you mainly want is to be able to get to work without worrying about where your client data ultimately ends up. Exantur is built as EU-hosted coaching software: the data is stored in Frankfurt, not with a US parent company. That immediately changes the legal picture you have read about above.

Exterior of a modern and well-secured European data centre

Exantur combines client management, session notes, goals and accountability between sessions in one workspace, with security that takes MFA and a clear data processing agreement into account. That makes it easier to demonstrate that you have deliberately chosen a processor within the European Economic Area, exactly as regulators recommend.

Want to see whether this fits your practice? Take a look at the practice management software for coaches and start the free 14-day trial.

Sources

This article contains general information and does not replace the advice of a qualified lawyer. Consult a qualified legal professional about your own situation before acting on the basis of this content.

Frequently asked questions

Which cloud service is safe for client data?

There is no absolutely safe cloud service, but an EU-hosted service from a non-US company, combined with your own key management and MFA, gives you the most control. For sensitive data, the AP recommends favouring processors within the European Economic Area.

Which companies active in the Netherlands are American?

Many major cloud service providers used in the Netherlands, such as providers of Microsoft, Google Workspace and Amazon Web Services, have a US parent company. That is the case even when their European data centres are located in the Netherlands or Germany.

What is the biggest downside of a cloud backup?

The biggest legal downside is that a US provider can be compelled to hand over data to US authorities, even if the backup is stored in Europe. Technically, dependence on your internet connection and on the provider also remains a point of attention.

Is the Data Privacy Framework sufficient protection?

The DPF makes transfers to participating US companies easier, but it offers no guarantee against future legal or political changes. Many organisations therefore prepare by using SCCs as an additional safeguard.

Does EU hosting for coaching software really help?

Yes, EU hosting by a non-US company removes the CLOUD Act risk, because there is no US parent company from which data can be requested. Exantur, for example, uses EU hosting in Frankfurt for coaches who deliberately choose this.

Recommendation