On June 3, 2026, the European Commission proposed a piece of legislation that received relatively little consumer press coverage — largely because it reads like infrastructure policy rather than personal privacy news. The Cloud and AI Development Act, known by its acronym CADA, sets up a formal sovereignty framework for cloud services operating in the European Union.
The proposal is worth understanding even if you are not a policy analyst, and even if you don’t live in the EU, because it crystallizes a question that applies to anyone who stores personal files in the cloud: where exactly is your data, and whose laws govern what happens to it?
CADA is a proposal — it has not yet been enacted, and the legislative process in the EU involves negotiation between the Commission, the Parliament, and the Council before anything becomes law. But the framework it describes reflects a direction of travel that is relevant to how personal cloud storage will be structured over the next decade.
Why Cloud Sovereignty Became a Priority
The European Commission’s motivation for CADA is stated plainly in the proposal’s preamble: the EU has a structural dependence on a small number of non-European cloud providers, and that dependence creates strategic and legal vulnerabilities.
The major providers of cloud infrastructure — data centers, storage platforms, AI compute — are primarily American companies operating under U.S. law. This means that personal data stored in European data centers by European users, if stored through an American company, is technically subject to U.S. law as well as European law.
The relevant U.S. statute is the CLOUD Act (Clarifying Lawful Overseas Use of Data Act), enacted in 2018. Under the CLOUD Act, U.S. law enforcement can compel U.S.-headquartered companies to produce data stored on their servers anywhere in the world — including servers physically located in EU member states. The data being in Frankfurt, Dublin, or Amsterdam doesn’t change the legal exposure if the company holding it is subject to U.S. jurisdiction.
This is not a hypothetical. CLOUD Act requests have been used to access data stored in European data centers. The Schrems II ruling from the Court of Justice of the European Union addressed this incompatibility between U.S. surveillance law and GDPR’s protections, leading to years of legal uncertainty about transatlantic data transfers that is still not fully resolved.
CADA is one response to this: building a formal framework for classifying cloud services by how well they can protect data from non-EU legal demands.
The Four-Level Sovereignty Framework
The heart of CADA’s autonomy pillar is a tiered classification system for cloud services. Each level specifies a set of requirements; higher levels provide stronger sovereignty assurances.
Level 1 (EU-based processing). The basic tier requires only that data processing occur within the EU and that providers comply with EU law. Many existing cloud services already meet this standard. It does not address the question of non-EU legal demands — a U.S. company with EU data centers can be Level 1 while still technically subject to CLOUD Act requests.
Level 2 (EU-controlled processing). This tier requires that the cloud provider be incorporated and headquartered in an EU member state, not merely operating EU infrastructure. This is designed to eliminate the CLOUD Act exposure by removing the U.S. nexus. Providers at Level 2 would need to be companies where EU law is the governing law with no meaningful U.S. corporate relationship.
Level 3 (EU-sovereign processing). This tier adds requirements around supply chain transparency, personnel clearances, and independent auditing. The goal is providing assurance not only that the company is EU-based but that the infrastructure it uses — hardware, software, network, support — is sufficiently within EU control to be resistant to foreign legal demands or covert access.
Level 4 (Maximum sovereignty). The highest tier adds requirements around ownership structure, operational control, and verified independence from any non-EU entity that might be subject to a foreign government’s legal demands. This tier is designed for the most sensitive public-sector workloads where even indirect foreign exposure is unacceptable.
The Three Pillars of CADA
Sovereignty is only one of three pillars in the CADA proposal. The other two address different structural issues.
Research and innovation. CADA includes provisions directing investment toward European AI and cloud research. The EU has identified AI compute — the raw processing power needed to train and run large AI models — as a strategic resource that the continent needs more of. CADA creates mechanisms to direct public and private investment toward building European capacity.
Data center capacity. The proposal addresses the physical infrastructure gap. Europe has fewer large-scale data centers than the United States or China, which limits the amount of computation and storage that can happen on European soil under European control. CADA aims to stimulate data center construction within EU member states.
The Distinction From Earlier EU Digital Legislation
CADA is often discussed alongside GDPR, the EU AI Act, and the EU Data Act, but they serve different purposes.
GDPR is about how personal data is processed: consent, rights, breach notifications, data minimization. It applies to organizations processing EU residents’ data, regardless of where the organization is based.
The EU AI Act is about how AI systems are developed and deployed: risk categorization, transparency, prohibited uses. It applies to AI systems placed on the EU market.
The EU Data Act (effective September 2025) is about data access and portability: who can access data generated by connected devices, portability requirements for cloud storage switching, elimination of egress fees.
CADA is about where data is and who controls it: the physical and legal infrastructure in which data processing happens, and whether that infrastructure is sufficiently European to be protected from non-EU legal demands.
These frameworks layer on top of each other. GDPR sets the processing rules; the EU Data Act sets the portability rules; CADA, if enacted, will set the sovereignty classification rules. Compliance with one does not automatically address the concerns of another.
What This Means for Personal Cloud Storage
CADA’s immediate scope is primarily public-sector workloads — government data, critical infrastructure, health systems. The four-level framework tells public bodies what cloud providers they can use for which types of data.
For consumer personal cloud storage, the direct application is more indirect, but the effects will be real over a multi-year timeline.
Provider choices will shift. If CADA passes and higher sovereignty tiers become requirements for significant public contracts, EU-based cloud providers who build to those standards will have competitive advantages in the European market. This could reshape which providers grow in Europe and what infrastructure they build.
The framework may extend to more contexts. CADA’s public-sector focus now doesn’t mean it stays there. Regulations that start with government data often extend to regulated industries (healthcare, finance) and then to consumer services handling sensitive personal data.
The CLOUD Act question becomes more legible. One practical consequence of CADA’s framework is that it forces clarity about something many users don’t think to ask: is the company holding my cloud files subject to U.S. law? The sovereignty tiers make that question concrete and give it a classification system.
The Underlying Question for Personal Files
Wherever you store personal files — photos, documents, journals, recordings — the sovereignty question is real even outside the EU regulatory framework.
Where are the servers? Physical location determines which country’s laws can compel access to data stored on those servers, independent of any encryption or contractual protections.
Where is the company incorporated? Legal jurisdiction for the company matters as much as physical server location. A company incorporated in the United States and subject to U.S. law can be compelled to produce data from servers anywhere in the world under the CLOUD Act.
What legal demands could reach your data? Government access to personal data — through legal process, national security letters, intelligence agency demands — is a real-world risk that most privacy discussions underweight relative to commercial data misuse.
CADA doesn’t answer these questions for personal cloud storage users globally. What it does is make the EU’s answer clear and enforceable within EU regulatory space. That clarity is useful as a reference point even for people who aren’t EU residents thinking about analogous questions in their own context.
The Timeline
CADA is a proposal. The EU legislative process runs through multiple stages: Commission proposal, Parliamentary committee review, Council negotiation, trilogue between the three bodies, final votes, and then a transition period before the law takes full effect.
Based on the pace of similar legislation, full implementation of CADA — if enacted without major revision — is likely two to four years from the June 2026 proposal date. The final form of the law may differ from the current proposal.
The proposal signals a direction, and that direction is increasingly clear: data sovereignty is becoming a formal regulatory category, not just a vague aspiration. Organizations that store personal data will need to know where their cloud infrastructure stands relative to that category.
Why This Matters Now
You don’t have to wait for CADA to become law to benefit from asking the questions it raises.
When you evaluate where to store personal files — photos, medical documents, financial records, personal journals — it is worth knowing whether the company holding them is subject to legal demands that could compel disclosure without your knowledge or consent. It is worth knowing where the servers are. It is worth reading how the company describes its relationship to government legal process in its terms of service.
CADA is the EU trying to turn those questions into a certification framework. The underlying questions exist regardless of what the framework says.
The companies that take data sovereignty seriously as a principle — not just as a marketing point — tend to be explicit about their infrastructure, their legal relationships, and the limits of what they can and can’t protect. That transparency is the starting point for making an informed choice about where your most personal files live.