The US CLOUD Act and VPN Jurisdiction Claims: What the Department of Justice Says the Act Requires of Providers, What It Does Not Do and Why a Head Office Country Is Not the Whole Story

VPN marketing often leans on the country where a company is registered, and the US CLOUD Act is sometimes mentioned as a reason to prefer a provider based elsewhere. The Act is a US federal law of March 2018 (the Clarifying Lawful Overseas Use of Data Act), and the US Department of Justice (DOJ) has published both the text and a set of Frequently Asked Questions about it. This article summarises what those DOJ documents say the Act does and does not do, and what that means for reading a provider’s jurisdiction claims. It reflects the DOJ’s own account of the law, not an independent legal analysis, and it is general information rather than legal advice.

What the Act changed

The Act has two main parts, according to the DOJ. The first amended the US Stored Communications Act by adding section 2713 to title 18 of the US Code. The text requires a provider of electronic communication service or remote computing service to comply with US obligations to preserve, back up or disclose the contents of a communication and any record or information about a customer or subscriber “within such provider’s possession, custody, or control”, regardless of whether it is located inside or outside the United States. The second part allows the US to enter executive agreements with foreign governments that meet privacy and rule-of-law standards, so that each side’s authorities can serve their own domestic legal process directly on providers.

The DOJ FAQ says the first change did not create new authority for US law enforcement to obtain information. It describes it as a clarification of obligations of providers that are already subject to US jurisdiction.

Who is covered, and what “jurisdiction” means

The FAQ says the definitions of these providers include email providers, cell phone companies, social media platforms and cloud storage services, and do not include a company just because it has some interaction with the internet, such as certain e-commerce sites. It gives no example that names a VPN service.

On jurisdiction, the DOJ says US jurisdiction is not limited to US corporations, US-headquartered companies or companies owned by US persons, but is not unlimited either. Whether a company providing services in US territory is subject to US jurisdiction is, in its words, a highly fact-dependent question of whether it has sufficient contacts with the United States. The more a company has purposefully conducted activities in, or directed its conduct into, the US, the more likely a US court is to find it subject to US jurisdiction. The FAQ adds that the analysis is the same regardless of corporate structure: a US court must have jurisdiction over an entity that has possession or control of the data, and whether a company controls data held by a subsidiary is a fact-dependent inquiry.

For a reader comparing providers, that wording means a registered address alone is not the whole story about which country’s legal process can reach a company. It also sits alongside the site’s explainer on VPN jurisdiction and the Five and Fourteen Eyes alliances.

What the Act does not do

  • It does not compel decryption. The FAQ says the Act is “encryption neutral”: it creates no new authority to force providers to decrypt communications, and does not stop providers from assisting or countries from addressing decryption in their own laws.
  • It does not cover civil or commercial inquiries. The DOJ says agreements are used only for the prevention, detection, investigation or prosecution of serious crime, and only in response to legal process.
  • It does not require a provider to obey a foreign order. The FAQ says US law contains no such requirement, and that enforcement is under the law of the requesting country. It adds that agreements remove legal barriers on the provider’s side, not create obligations.
  • It does not let foreign orders target US persons. Foreign orders under an agreement may not intentionally target US persons or people in the United States.

Agreements in force

The DOJ’s CLOUD Act resources page (updated October 2023) lists agreements with the United Kingdom (signed October 2019) and Australia (December 2021), and describes negotiations with Canada and the European Union. The FAQ explains that under an agreement a country can use its own legal authority, for example a UK order rather than a US warrant, to obtain data from a US-based provider, assuming it has jurisdiction over that provider. These agreements apply to orders about serious crime, not to ordinary consumer disputes.

What this means for a VPN customer

None of the DOJ’s statements says anything about VPN logging practices. What they do establish is that the reach of legal process depends on what data a company holds and where a court has jurisdiction, not only where it is registered. That is why the site’s articles on no-logs claims and audits and warrant canaries and transparency reports treat what a provider stores as the more direct question: a company cannot disclose records it does not hold, though this depends on the provider’s own claims being accurate.

Common questions

Does the CLOUD Act mean US authorities can read VPN traffic?

The DOJ says the Act does not compel decryption and does not create new authority for US law enforcement to obtain data. It clarifies the duties of providers already subject to US jurisdiction.

Does being based outside the US avoid the Act?

The DOJ says jurisdiction turns on a company’s contacts with the US and its possession or control of data, not just on where it is headquartered.

The bottom line

According to the DOJ, the CLOUD Act confirms that providers subject to US jurisdiction must disclose data in their possession, custody or control wherever it is stored, and it creates a framework for agreements such as those with the UK and Australia. It does not force decryption or expand US jurisdiction. For VPN buyers, a headquarters country is only one input; what the provider actually keeps, and whether its claims stand up to audit, matter as much.

Sources