EU companies on AWS... how are you actually handling the CLOUD Act exposure? Our legal team just flagged this and I'm trying to understand what others are doing

Posted by Proud_Boot6703@reddit | sysadmin | View on Reddit | 145 comments

So we've been running on AWS Frankfurt for a couple of years assuming that covered our GDPR obligations. Last month our legal team came back with something I hadn't really thought through properly.

The issue...AWS is a US company. Under the CLOUD Act (2018), US authorities can request access to data regardless of where it's physically stored. So "data in Frankfurt" doesn't mean "outside US jurisdiction." That's a separate question from GDPR and our lawyers are now treating it as a real exposure.

I'm curious what other EU companies are actually doing about this:

Also curious about the practical cost difference, we've seen claims of 40-70% savings moving to EU providers but that seems high. What are people actually seeing?

Not looking to sell anything, genuinely trying to figure out what the right move is here.