← Secure Shore Cloud Secure Shore Cloud — Data Protection, Nassau, The Bahamas

Jurisdiction · plain English

The CLOUD Act does not care where your data sits.
It cares who holds it.

Most people assume that if their files are stored on a server in Frankfurt, they are governed by German law. For the purposes of US law enforcement access, that assumption is the wrong way round — and the distinction decides whether an offshore strategy actually works.

What the CLOUD Act is

The Clarifying Lawful Overseas Use of Data Act, passed in the United States in 2018, requires a covered provider to hand over data in its possession, custody or control when served with valid US legal process — regardless of whether that data is stored inside or outside the United States.

It was passed to settle a specific argument. Microsoft had refused a US warrant for email stored in its Dublin datacentre, on the grounds that a US warrant stops at the US border. The case reached the Supreme Court. Congress resolved it by legislating that the border of the disk is not the relevant border.

The Act applies to "providers of electronic communication service or remote computing service" — deliberately broad definitions that cover essentially every cloud storage, email and hosting company.

The test is jurisdiction over the company, not the location of the disk

US authorities can compel disclosure only from entities over which US courts have personal and subject-matter jurisdiction. What matters is whether the provider is reachable by a US court — not which country the hard drive is in.

This is the part that is routinely misread, and it cuts both ways.

A US-incorporated provider storing your data in Frankfurt is still a US company. It remains subject to US process, and the data is in its custody and control. Selecting a European region changes the physical location of the bytes. It does not change who can be ordered to produce them.

Conversely, a provider that operates exclusively outside the United States, with no US presence, is generally not within the personal jurisdiction of a US court and cannot be compelled under the CLOUD Act. The Cross-Border Data Forum puts it plainly: if a company operates exclusively outside the United States, "the United States does not have personal jurisdiction over that company."

What this means when you are choosing a provider

If jurisdictional exposure is genuinely on your risk register — because you handle regulated client data, privileged material, or commercially sensitive records — then the question to ask a prospective provider is not "which regions do you offer?"

It is these:

A caveat worth stating. No jurisdiction is a legal force field. Every country has lawful-access powers of its own, mutual legal assistance treaties exist, and a provider anywhere can be served under its own local law. The honest framing is not immunity — it is choosing which legal system you are exposed to, deliberately, instead of inheriting one by default.

Where Secure Shore sits

Secure Shore operates from its own facility in Nassau, The Bahamas — a purpose-built, privately owned, carrier-neutral data center the company has run since 2015. Storage, virtual servers and dedicated servers are all provisioned there.

The infrastructure detail that matters for this question: servers are addressed with Bahamian-domiciled IP space, BGP-announced across four independent local carriers. Traffic does not need to transit the United States to reach the service, and the data does not leave the country as part of normal operation.

If your requirement is that a specific set of records lives under one clearly identified legal system, that is the shape of the answer — and it is checkable, which matters more than a marketing claim. See how the Bahamian framework works, or the facility itself.

Common questions

Does storing data in an EU region of a US cloud protect it from the CLOUD Act?

Not on its own. The Act reaches data in the possession, custody or control of a provider subject to US jurisdiction, wherever that data is stored. Choosing an EU region changes where the bytes physically sit; it does not change which courts can order the provider to produce them.

Can a non-US provider be forced to comply with a US warrant?

Generally not, if it operates exclusively outside the United States and has no US presence giving a US court personal jurisdiction over it. Providers with US subsidiaries, branches or substantial US business may be in a different position. It is a question about the corporate entity, not the server rack.

Does end-to-end encryption solve the problem instead?

It helps significantly, but only if the provider genuinely cannot decrypt. If the provider holds or can derive the keys, those keys sit in its custody and control like any other data. Encryption and jurisdiction are complementary controls, not substitutes.

Is data in The Bahamas unregulated?

No — and that is the point. The Bahamas has its own data protection statute and a Data Protection Commissioner. The proposition is not the absence of law; it is a single, identifiable legal system rather than overlapping foreign ones.

Store it where you chose to store it

Cloud storage, virtual servers and dedicated servers, provisioned from our own facility in Nassau. Free tier to start, no card required.

Create a free accountSee pricing