In June 2024, Anton Carniaux, Director of Public and Legal Affairs at Microsoft France, was heard by the French Senate during an inquiry into public procurement and European digital sovereignty. The question asked under oath was direct: could Microsoft guarantee that French citizens' data would never be handed over to US authorities without French government authorization? The answer was no. If a court order based on the Cloud Act—the Clarifying Lawful Overseas Use of Data Act, a 2018 American law requiring US-based companies to provide data under their custody to any American judicial authority, regardless of where that data is stored—were presented, Microsoft would have to comply, even if it violated European data protection laws. It was not a confession of misconduct. It was a description of the system’s normal functioning. And Brazil, unlike the European Union, has not yet built the legal equivalent that supports such a refusal.

The hearing that exposed the system's normal functioning

Carniaux's statement in the French Senate was not a technical novelty for those following the debate on digital sovereignty. It was, however, a rare moment of public transparency regarding a reality that usually remains behind the scenes of corporate contracts: the reach of the Cloud Act surpasses any data localization agreement.

American law establishes that companies with a presence in the United States, whether in information technology or remote computing, are subject to American court orders to supply data in their possession, custody, or control, regardless of where that data is physically stored. This means that a data center installed in Paris, São Paulo, or Tokyo does not alter the obligation of the operating company if it is American. The server's address changes. The law applicable to the company does not.

This distinction is the core of the digital sovereignty problem that the French Senate episode made visible. Governments and organizations that contract services from American companies, regardless of where the servers are physically located, remain subject to the reach of the Cloud Act as long as there are no legal safeguards to support the refusal of data delivery. Infrastructure location is a necessary condition, but not sufficient, to guarantee sovereignty over the data circulating within it.

The cross-border principle: jurisdiction follows the operator

The model of corporate submission to the laws of the home country is neither an American invention nor a peculiarity of the current context. It is a principle repeated in different legal systems around the world, with variations in scope and purpose.

China's 2017 National Intelligence Law obliges any Chinese company, regardless of where it operates in the world, to cooperate with state intelligence agencies. The UK's Investigatory Powers Act 2016 authorizes interception warrants outside UK territory, extending British intelligence surveillance capabilities beyond its borders. Australia’s 2018 TOLA (Telecommunications and Other Legislation Amendment) can force global tech companies to build access capabilities for encrypted communications, including those operating outside Australia.

It is important to recognize, as the analysis points out, that the stated purpose of most of these laws is to support international cooperation against organized crime, terrorism, and national security threats. The issue is not that these laws are illegitimate in their original purpose. It is that the mechanism they create, by subordinating global private companies to the laws of their country of origin, turns the data of citizens from other countries into an object of dispute between sovereignties, without those citizens having any participation in the process.

Cross-surveillance architecture and the dilution of individual protections

Beyond national laws, there is a structural arrangement that goes beyond any individual legal text: the Five Eyes, an intelligence alliance comprising the United States, the United Kingdom, Canada, Australia, and New Zealand. This alliance creates a cross-surveillance architecture that, in practice, bypasses the constitutional protections of each individual member.

The mechanism works because each country in the alliance has legal restrictions on monitoring its own citizens. However, it does not have the same restrictions on sharing information about citizens of other countries with its partners. The result is that intelligence from one country regarding citizens of another can circulate among members without triggering the domestic protections each would apply if monitoring their own nationals. The architecture transforms the individual limitation of each legal system into a systemic opening for shared access.

Trump did not invent this mechanism, as Consuelo Rodrigues points out. He accelerated something that already existed, transforming private companies into tension points between sovereign states and converting citizen data into geopolitical leverage. What changed with the recent context was not the structure, but the willingness to use it more explicitly and less mediated by the multilateral commitments that previously moderated the exercise of this power.

The European experience: from Schrems I to Schrems II and Article 48 of the GDPR

The European Union did not arrive at the current debate without having traveled a long and costly path. The Schrems I (2015) and Schrems II (2020) rulings by the Court of Justice of the European Union were the milestones that forced the recognition that voluntary data protection agreements do not withstand confrontation with American surveillance legislation.

In the Schrems I case, the Court invalidated Safe Harbor, the agreement that since 2000 regulated the transfer of personal data of European citizens to American companies that adhered to its principles. The central reason was that Safe Harbor was not enforceable against the US government, which allowed participating companies to be forced to set aside its application for reasons of public safety or national defense. Privacy Shield, created to replace it in 2016, was likewise invalidated in the Schrems II case in July 2020 on the same grounds: American surveillance legislation does not offer European citizens' data a level of protection equivalent to that guaranteed by the GDPR (General Data Protection Regulation).

The European normative response is codified in Article 48 of the GDPR, which prohibits companies operating in Europe from handing over data based on orders from third countries, except when this occurs under a mutual legal assistance treaty in force between the requesting country and a European Union member state. This is the so-called blocking statute: a legal barrier that provides legal support for refusing data delivery in the face of a foreign court order that does not pass through agreed multilateral mechanisms. Brazil's LGPD (General Personal Data Protection Law) has no equivalent.

What the LGPD has and what it lacks

The LGPD represents a real advancement in personal data protection in Brazil. It establishes a robust set of rights for data subjects, obligations for controllers and processors, and oversight mechanisms by the ANPD (National Data Protection Authority). The Brazilian legal framework also has extraterritorial reach: it applies to the processing of data of persons located in Brazil, regardless of where the processing is carried out or where the agent is headquartered.

The problem lies at another level. Brazil has legislation with extraterritorial reach but faces the real challenge of exercising it when the operator is outside national jurisdiction. Specifically, it lacks an explicit blocking statute—a norm that legally authorizes a company to refuse compliance with a foreign judicial surveillance order that has not passed through multilateral legal assistance channels.

Without this normative support, the position of companies operating in Brazil is fragile when faced with an order based on the Cloud Act or equivalents from other jurisdictions. They do not have, under Brazilian law, an explicit legal basis that allows them to refuse compliance with such an order, in the way Article 48 of the GDPR offers companies operating in Europe. Building data sovereignty requires going beyond internal protection, with safeguards that prevent the rights of Brazilian citizens from being arbitrated by the laws of another state.

Frequently Asked Questions about data sovereignty and extraterritorial jurisdiction

Q: What is the Cloud Act and why does it affect data outside the United States?

The Cloud Act (Clarifying Lawful Overseas Use of Data Act) is an American law enacted in 2018 that obliges US-based technology companies to provide, by court order, data under their custody wherever it is stored. The Cloud Act affects data outside the United States because the criterion for application is the operator's nationality, not the server's physical location. Data stored on a server in Brazil, if under the operation of an American company, can be requested by American authorities without the server's physical address offering any protection.

Q: What was the Schrems I case and what is its relevance to data protection?

The Schrems I case was a ruling by the Court of Justice of the European Union, decided in October 2015, which declared Safe Harbor—the agreement that regulated the transfer of European citizens' personal data to American companies since 2000—invalid. The Schrems I case demonstrated that voluntary data protection agreements do not withstand confrontation with American surveillance legislation, as Safe Harbor was not enforceable against the US government in matters of national security, leaving European citizens' data vulnerable to access by American intelligence.

Q: What is a blocking statute and why doesn't the LGPD have one?

A blocking statute is a legal norm that legally authorizes a company to refuse compliance with a foreign judicial order for data access that has not passed through recognized multilateral legal assistance channels between the countries involved. Article 48 of the European Union's GDPR is the most consolidated example of this mechanism. Brazil's LGPD does not have an equivalent to this article, meaning that companies operating in Brazil have no explicit legal support under Brazilian law to refuse foreign judicial surveillance orders.

Q: What is the Five Eyes and how does it relate to data sovereignty?

The Five Eyes is an intelligence alliance between the United States, United Kingdom, Canada, Australia, and New Zealand that creates a cross-surveillance architecture among its members. It relates to data sovereignty because each country in the alliance has legal restrictions on monitoring its own citizens, but not necessarily the same restrictions on sharing information about citizens of other countries with its partners. The result is a shared access capability that, in practice, bypasses the individual constitutional protections of each member when applied to foreign citizens.

Q: Why is server location not sufficient to guarantee data sovereignty?

Server location is not sufficient because the relevant criterion for applying extraterritorial surveillance laws is not the physical address of the equipment, but the nationality of the operating company. An American Big Tech company installing data centers in Brazil remains subordinate to US laws, including the Cloud Act. The hard drive's address changes. The law applicable to the company does not. Data sovereignty requires, beyond physical infrastructure location, control over who operates that infrastructure and under which law that operation is held accountable.

Q: What was Microsoft's statement in the French Senate and what does it reveal?

In June 2024, Anton Carniaux confirmed to the French Senate, under oath, that Microsoft cannot guarantee that French citizens' data will not be handed over to the US government without French government authorization. The statement reveals that the normal operation of the current legal system, specifically the Cloud Act, places American companies in a position to comply with US court orders even when they conflict with the data protection laws of the countries where they operate. The episode illustrates that corporate subordination to the laws of the home country is not a theoretical hypothesis: it is a description of the mechanism in operation.


A country that delegates the custody of its citizens' data to companies subject to foreign jurisdictions does not, in fact, control the fate of those citizens. This sentence summarizes the legal and political consequences of the current model. The absence of a blocking statute in the LGPD is not a minor technical gap: it is the expression of a choice not yet made regarding the level of protection Brazil decides to offer data subjects when the threat comes from outside its territorial limits. Personal data protection is, at its essence, the protection of fundamental rights. And fundamental rights only respect borders when there are legal mechanisms to ensure they are respected. Building data sovereignty means building these mechanisms, one by one, with the clarity that no server installed in Brazil automatically guarantees that the data stored therein is governed by Brazilian law.