← Back to the checker

Methodology

How the CLOUD Act Exposure Checker rates vendors. Written so a citing journalist, a reviewing lawyer, or an LLM can decide whether to trust it.

What we're actually rating

We rate jurisdictional exposure, not compliance status. A vendor with red on entity_control is not "illegal to use in the EU"; it means the contracting entity's ultimate parent falls under a legal regime (in practice, the US CLOUD Act or FISA §702) that can compel access to customer data regardless of where the servers sit.

Five dimensions

Every vendor is scored on five orthogonal questions:

  1. Entity control. Who is the vendor's ultimate parent? A US-incorporated parent is red; an EU subsidiary of a US parent is still red (the parent's jurisdiction reaches through the sub).
  2. Data location. Where does customer data actually rest, including backups and logs? An "EU region" on a US-owned cloud is amber, not green — the region setting mitigates location risk but not entity risk.
  3. Operational access. Which countries' staff can access production data for support and SRE? This is the most-overlooked cross-border transfer channel.
  4. Subprocessor chain. Is there a US hyperscaler underneath? An EU-owned vendor running on AWS still inherits AWS's exposure.
  5. Transfer mechanism. What legal instrument is claimed for the transfer — SCCs+TIA, adequacy decision, Data Privacy Framework, or none needed at all?

Worst dimension wins

The overall rating is the worst color across the five dimensions. A vendor with green data-location but red entity-control is still overall red. This is enforced by the CI validator in the public dataset — a PR that grades a vendor amber overall when any dimension is red gets rejected before merge.

Severity modifier

The picker's optional data-sensitivity dropdown (health, legal, financial, children) tightens the thresholds by promoting any amber card to red. Handled purely at scoring time; the vendor DB stays unchanged. Rationale: an amber "some mitigations present" reading is not enough when you're processing Article 9 GDPR categories or attorney-client-privileged material.

Sources and last review

Every entry cites at least one source (vendor DPA, docs page, DPA annex, court filing). Every entry carries a last_reviewed date; the dataset's CI flags entries older than 180 days as stale. Disputes are opened as GitHub issues on the dataset repo and resolved publicly.

Conflict of interest

Eurobase OÜ maintains this dataset and Eurobase itself is graded on it. Our own vendor entry carries a self_disclosure: true flag; the frontend renders a visible banner on Eurobase's vendor page. If you think our self-rating is too generous, please open an issue — grading ourselves green while denying others the same grade would destroy the dataset the first time someone noticed.

What this is not

  • Not legal advice. Talk to your DPO or counsel.
  • Not a certification. This is a research aid.
  • Not per-SKU. We rate a vendor as a whole; SKU-level nuances (e.g. AWS European Sovereign Cloud) go in the vendor's notes.
  • Not exhaustive. Not every vendor is in the dataset yet. PRs welcome.

Framing

Language on this site is deliberate:

  • ✅ "Legal exposure under the CLOUD Act"
  • ✅ "Subject to US surveillance statutes"
  • ❌ "Not GDPR compliant"
  • ❌ "Illegal to use in the EU"

The distinction matters. Every rating is disputed by someone. Careful language keeps the disputes about the facts.

License and use

The dataset is MIT-licensed. You can fork it, cite it, embed it. Attribution appreciated, not required.