> The data protection authority justified this with the fact that US authorities could access personal data (probably primarily the IP address) for criminal purposes on the basis of the CLOUD Act, among other things. This occurs regardless of whether data is stored on servers in the USA or Europe.
I have to imagine the particular bureaucrats the author was dealing with are somehow wrong here? Otherwise this implies that a European business cannot use basically any American software (directly or even indirectly, like this case), even if that software fully conforms with processing and storing all data in Europe. The fact that American authorities could coerce any American company into turning data over, even if it’s stored in Europe, is enough?