privacy

Where Are Your Files When You Cross a Border?

Accessing cloud storage abroad exposes your personal files to different legal jurisdictions. Here's what digital nomads and frequent travelers need to know.

Your cloud storage provider has a home country. So does each server in their infrastructure. And when you cross a border — as a traveler, remote worker, or digital nomad — the legal landscape governing your personal photos, documents, and files changes in ways that are invisible but real.

The common understanding of cloud privacy is file-level: is my data encrypted? Who has the encryption keys? The questions that matter for people moving across jurisdictions are different: who has the legal authority to demand access? What counts as “lawful access” in this country? And how does my activity pattern — where I access files from, when, on what device — create a record that extends beyond the contents of the files themselves?

None of these questions have alarming answers for most people in most situations. But understanding them matters if you’re making a deliberate choice about where to store personal files, and it matters differently depending on where you’re going.

The Server Location Question

“My data is in the cloud” understates how physical cloud infrastructure is. Your files sit on servers in specific countries, managed by specific companies, subject to specific national laws. A company’s global presence doesn’t merge all those locations into a single jurisdiction. A file stored on a server in Germany is subject to German law and EU law. The same file stored on a server in the United States is subject to US law — including the CLOUD Act, which we’ll discuss shortly.

The practical significance varies by provider and by country, but the basic principle is important: the legal framework that governs access to your data depends primarily on where the data is physically stored and where the company is incorporated, not on where you are when you access it.

This means the jurisdiction governing your files is largely settled when you choose a provider, not when you travel. A US-based provider storing data on US servers carries US legal jurisdiction regardless of whether you’re in Oslo, Nairobi, or São Paulo when you open the app.

What Governments Can Legally Request

Most cloud providers receive government access requests as a matter of routine. Major providers publish transparency reports disclosing the volume of these requests annually — the numbers are in the tens of thousands for large services.

The most significant legal framework for cross-border access is the US CLOUD Act (Clarifying Lawful Overseas Use of Data Act). It allows US law enforcement to request data from US-based providers regardless of where the data is physically stored — including data stored in servers in Europe, Asia, or anywhere else. EU privacy law, including GDPR, explicitly conflicts with this in some cases, creating a legal tension that courts in multiple jurisdictions have not fully resolved.

For EU-based providers storing data in EU servers, EU law requires legal process that complies with European standards. Mutual Legal Assistance Treaties (MLATs) govern cross-border requests between countries — these are typically slower and subject to more procedural requirements than domestic requests.

The practical takeaway: if your cloud provider is incorporated in the US and stores data on US servers, US law governs access requests, regardless of your nationality or location. If your provider is incorporated in the EU and stores data on EU servers, EU law governs — including stronger procedural requirements for government access.

Border Device Searches and Cloud Data

A distinct but related risk applies when you’re physically crossing a border with a device that’s logged into cloud storage.

Border agents in many countries — including the United States — have authority to inspect devices presented at the border, with fewer procedural requirements than a domestic search warrant. US Customs and Border Protection can request that you unlock your device and may image its contents. This is true for US citizens as well as travelers.

If your device is logged into cloud storage, a border agent inspecting your device may be able to access not just what’s locally stored but what’s accessible through your logged-in sessions. This is different from the government accessing cloud storage through a formal legal request to the provider — this is access through your physical device, in person.

Practical steps for frequent border crossers:

  • Log out of cloud storage accounts before crossing a border. A stored session token on a device is an access credential. Remove it before crossing, log back in after.
  • Be aware that some cloud apps cache or download content locally as a performance optimization. Files you “opened” in a cloud app may be stored in the app’s local cache even if you’ve logged out.
  • Consider using a travel device — a phone or laptop with minimal cloud credentials and a fresh browser profile — for crossing borders, leaving your primary device at home for sensitive work.
  • Know your rights in the specific country you’re entering. US border practices differ from those in the EU, UK, Canada, and other jurisdictions. Knowing whether you’re legally required to unlock a device, or can decline, is situation-specific.

Data Jurisdiction When Accessing Files Abroad

Accessing your cloud storage from another country creates a second, distinct jurisdiction question: what can the country you’re in do with the fact that you’re accessing a foreign service?

In practice, for most countries and most personal file types, the answer is: very little, unless you’re of investigative interest for other reasons. The data flow between your device and a foreign cloud provider over HTTPS is encrypted in transit, and most countries don’t have practical mechanisms to intercept and decrypt modern TLS traffic at scale.

But there are specific situations where this changes:

High-risk countries. Some countries use deep packet inspection infrastructure to analyze, block, or intercept internet traffic more aggressively. Travelers to countries with extensive internet surveillance infrastructure — a list that varies by source but typically includes countries with documented state surveillance programs — face a meaningfully different environment than travelers to countries without such infrastructure.

VPN usage. VPNs encrypt your traffic beyond the TLS layer and prevent local network observers — including ISPs in the country you’re visiting — from seeing what services you’re connecting to. They don’t change the jurisdiction analysis for the cloud provider’s servers, but they reduce local surveillance exposure while traveling. Note that VPN services themselves are banned or restricted in some countries.

Enterprise travel. If you’re accessing personal files through a work-managed device or a work network while traveling, your employer’s network monitoring may apply to your personal cloud access in ways that don’t apply when you’re on your own device and network. Keep personal and work access separated on different devices where possible.

The Fourteen Eyes and Data Sharing

The intelligence-sharing arrangement known as the Five Eyes (US, UK, Canada, Australia, New Zealand) and its extensions to Nine and Fourteen Eyes countries means that a lawful access request from one member country can effectively be shared with others. This isn’t widely understood as a cloud storage risk, but it’s relevant for people who might be of investigative interest across multiple jurisdictions.

For most personal users storing photos and documents, this is not a realistic threat model. For journalists, activists, lawyers, or anyone whose work makes them a potential surveillance target across jurisdictions, the fact that a US provider complying with a domestic lawful access request can result in data becoming accessible to allied intelligence services is worth factoring into storage decisions.

How GDPR Travels with You — and Where It Doesn’t

The GDPR follows EU residents to some extent, but not completely. GDPR’s key data protection rights — access, erasure, portability — are rights you can exercise against the data controller (your cloud provider) from anywhere in the world, because the obligation belongs to the controller, not to your location.

However, GDPR doesn’t protect you from the legal authorities of non-EU countries where you’re physically present. A Brazilian government request to a Brazilian-incorporated subsidiary of your EU cloud provider is governed by Brazilian law, not GDPR. The jurisdiction of data processing and the jurisdiction of your physical location are separate questions.

India’s Digital Personal Data Protection Act, California’s privacy laws, and the privacy frameworks of other major jurisdictions each create their own rights and obligations — and those frameworks interact (or conflict) with GDPR in ways that the companies storing your data are responsible for navigating, often without clear resolution.

Choosing a Provider with Jurisdiction in Mind

For travelers and nomads who are deliberate about where their personal files live, a few practical criteria:

Where is the provider incorporated? The country of incorporation determines which country’s legal process has primary jurisdiction over the company itself and its obligations to respond to government requests.

Where are the servers? Many providers let you choose or display your storage region. EU-based storage under EU jurisdiction has different access requirements than US-based storage under US jurisdiction. Some providers replicate data across regions, which can complicate the jurisdiction analysis.

What does the provider’s transparency report say? The volume, type, and response rate of government access requests in the provider’s most recent transparency report gives a real-world picture of how often lawful access is exercised and how the provider responds.

What is the provider’s deletion policy? If you delete data and leave a service, does deletion eliminate the data from all servers — or does it remain in backups, subject to access requests for an undisclosed period? A provider with a specific, time-bounded deletion policy (as opposed to a vague reference to “routine deletion”) gives you more confidence about what’s actually gone.

The questions raised by cross-border jurisdiction are genuinely complex, and no cloud storage solution resolves all of them. But they’re different questions from the ones typically covered in privacy marketing — and understanding them separately from the “is my data encrypted?” question gives a more accurate picture of what privacy choices actually affect.

Most digital nomads and regular travelers are not surveillance targets, and routine personal file storage carries routine risk. The point isn’t to alarm — it’s to give you an accurate model so that if your situation changes, or if you’re storing something more sensitive than usual, you know which knobs actually matter.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts