When you upload a photo to a cloud storage service, most people think of it as disappearing into “the cloud” — a vague, borderless space that holds files until you want them back. The cloud is not borderless. Your files sit on physical servers, in physical data centers, in specific countries. And the country where your data lives — along with the country where the company providing the service is headquartered — determines which governments have legal tools to access it.
This is not hypothetical. Governments around the world routinely request data from cloud providers. Major providers publish transparency reports documenting thousands of requests per year. Understanding which legal frameworks apply to your data is part of understanding what privacy a cloud storage subscription actually provides.
The Two Layers of Jurisdiction
Two jurisdictional questions apply to any cloud storage arrangement:
Where is the company incorporated? This determines which country’s laws govern the company’s legal obligations. A company incorporated in the United States must comply with US law, including US government requests, regardless of where it physically stores your data.
Where is the data physically stored? This determines which countries’ laws may apply to the physical infrastructure holding your data, which can matter for local search warrants and local law enforcement requests.
The interaction between these two questions is where most of the complexity lives.
The CLOUD Act: How US Law Reaches Data Stored Anywhere
The US Clarifying Lawful Overseas Use of Data Act, commonly called the CLOUD Act, requires US companies to produce data in response to valid legal orders — regardless of where the data is physically stored. A US company storing data in European data centers must still comply with a US federal subpoena or court order for that data.
This has a significant practical implication: “data stored in the EU” on a US-headquartered cloud service is not protected by EU data residency from US government requests. The GDPR and a company’s “EU data center” claims describe where the bits physically sit and which privacy framework governs commercial data use. They do not override the company’s legal obligation to comply with US court orders.
This is one reason privacy-conscious users have sought cloud services headquartered outside the US. A company based in Switzerland, Germany, or Iceland is not subject to CLOUD Act demands, though it remains subject to its own country’s laws and to EU law if it operates in the EU.
GDPR and What It Actually Covers
The EU’s General Data Protection Regulation governs how personal data must be handled for EU residents, regardless of where the processing company is based. GDPR includes requirements about cross-border data transfers — if a company transfers data about EU residents to a country without adequate privacy protections, it must use specific legal mechanisms to justify the transfer.
GDPR does not prevent legal access by authorities. Member state law enforcement can still seek data through their own legal channels. What GDPR primarily governs is commercial data use: how companies can collect, process, and share personal data for business purposes.
For cloud storage users in the EU, GDPR means companies must:
- Be clear about what data they collect and why
- Honor requests to access, correct, or delete personal data
- Report certain data breaches within 72 hours
- Not use personal data for purposes beyond what they disclosed at the time of collection
These are meaningful protections for commercial privacy — they constrain what a company can do with your data. They do not constrain what a government with a valid legal order can compel the company to hand over.
How Data Requests Actually Work
Cloud providers receive requests through several legal mechanisms, each with different requirements:
Search warrants require judicial approval and probable cause. They are the standard mechanism for law enforcement requesting specific account content in criminal investigations.
Subpoenas require less judicial scrutiny than warrants, typically used to compel production of account metadata — who you are, when you accessed the account, IP addresses used — rather than file contents. In the US, content often requires a warrant; metadata may require only a subpoena.
National Security Letters are administrative subpoenas issued without judicial approval, typically for national security investigations. They often come with gag orders preventing the recipient from disclosing that one was received. Recipients have challenged these in court, with limited success.
International requests through mutual legal assistance treaties allow governments to request data from foreign companies by routing the request through a formal government-to-government channel. This process is slower and has more procedural safeguards than a domestic legal order, but it is the mechanism through which cross-border legal access typically occurs.
Most legitimate government requests fall into the first two categories and apply to specific accounts in specific investigations — not bulk surveillance of ordinary users’ personal files.
What Transparency Reports Tell You
Major cloud providers publish transparency reports disclosing aggregate statistics about government requests: how many they received, from which countries, how many they complied with fully or partially, and how many they rejected.
These reports do not disclose which accounts were targeted — that information is often legally restricted — but they provide a signal about the volume and origin of requests. A provider that publishes detailed transparency reports, distinguishes between content requests and metadata requests, and documents instances where it challenged overbroad requests presents different risk than one that does not publish any transparency information.
For personal file and photo storage, a few things worth checking in a provider’s transparency report:
- Does one exist? Providers that do not publish one give you less information.
- Do they distinguish between content requests and metadata requests?
- Do they challenge requests they believe are overbroad?
- Do they notify users when legally permitted to do so?
The absence of a transparency report is itself informative.
The Jurisdiction Question for Personal Use
Some cloud storage providers explicitly market on the basis of jurisdiction — emphasizing that they are headquartered in countries with strong privacy laws and no obligation to comply with US or other government requests.
Switzerland has historically been a favored location for privacy-conscious services, due to its strong data protection laws and political neutrality. Iceland has been marketed similarly. Companies based in Germany are subject to EU law but outside the direct reach of US government demands.
Whether this matters for your personal files depends on your threat model. For most people storing personal photos and documents, the practical risk from government surveillance is low compared to the risk of commercial data misuse — companies selling data to advertisers, using it to train AI, or suffering breaches that expose it to criminals.
GDPR and CCPA compliance, strong encryption, and a business model that does not monetize user data are more relevant protections for everyday use cases. For activists, journalists, lawyers handling sensitive cases, and others with specific reason to be concerned about government access, jurisdiction matters more directly.
CCPA and US Data Rights
California’s Consumer Privacy Act and its expansion give California residents specific rights over personal data held by covered companies: the right to know what data is collected, the right to delete it, and the right to opt out of its sale to third parties.
Like GDPR, CCPA governs commercial data use rather than government access. But its existence, and similar laws being enacted across other US states, reflects a broader trend of legislating data rights that previously did not exist in US federal law.
For cloud storage users, CCPA compliance means a company cannot sell your data to data brokers, must honor deletion requests, and must disclose what it collects. These protections are meaningful even if they do not address the government access question.
What Actually Protects Your Data
Across all jurisdictions, the most consistent protection for personal file and photo storage is encryption. Data encrypted at rest means that even if a government entity compels a provider to produce data, what they receive is encrypted ciphertext. The practical security of this depends on who holds the encryption keys — the provider or you.
Server-side encryption (where the provider holds keys) protects against unauthorized third parties and against most breaches, but means the provider can technically decrypt and produce plaintext to comply with legal orders. This is the standard model for most consumer cloud storage services.
Client-side zero-knowledge encryption (where you hold keys) means the provider can produce only ciphertext they cannot decrypt. It provides the strongest protection against legal access, but typically comes with trade-offs: no server-side search, no web-based preview, and you are responsible for not losing the key.
For the government access question specifically, understanding this distinction is what determines what a legal order can actually compel a provider to produce.
daftei uses AES-256 encryption at rest and TLS 1.3 in transit — server-side encryption, with Anthropic holding the keys. This is the honest representation of what the service provides. daftei is GDPR- and CCPA-compliant, does not sell data, and does not show ads. When you delete your account, data is permanently and irreversibly erased after a 30-day grace window. For most personal use cases — where the practical concern is commercial misuse rather than government access — this model covers what matters.
Making an Informed Choice
The takeaway is not that cloud storage is untrustworthy. It is that “cloud storage” covers a wide range of services with different legal obligations, different business models, and different approaches to government requests.
When choosing a provider for personal files, the questions that matter for jurisdiction:
- Where is the company incorporated, and what legal demands is it obligated to comply with?
- Does it publish a transparency report?
- Does it encrypt data at rest, and who holds the keys?
- Does it have a stated policy on notifying users about legal requests when permitted?
- What privacy regulations does it comply with, and what does compliance actually require in practice?
Answers to these questions tell you more about actual data privacy than any marketing claim about security or privacy positioning.
Start with daftei’s free tier to see how storage without data monetization actually works.