International access to data is often approached primarily as a GDPR issue.
The EU Data Act adds another dimension.
Article 32 specifically addresses international governmental access to non-personal data held in the European Union by providers of data processing services.
For international SaaS and cloud providers — particularly those headquartered outside the EU or relying on non-EU infrastructure providers — this creates a separate compliance issue that needs to be considered alongside, but distinguished from, GDPR international transfer requirements.
Providers of data processing services must take adequate technical, organisational and legal measures to prevent international or third-country governmental access to, or transfer of, non-personal data held in the EU where such access or transfer would conflict with EU law or the law of the relevant Member State.
This obligation can therefore affect providers established outside the European Union when they provide data processing services to EU customers.
For international providers, the analysis should not stop at the location of their servers.
The legal framework applicable to the provider, its corporate group and relevant subcontractors may also need to be considered.
For a broader overview of the Data Act requirements applicable to SaaS and cloud providers, see EU Data Act & SaaS: What International Providers Need to Know.
This distinction is fundamental.
The GDPR already provides a detailed framework governing international transfers of personal data.
Article 32 of the Data Act addresses a different issue: certain governmental access to non-personal data held in the EU.
Depending on the service, this may include commercially sensitive information, business data, technical information or other data that does not qualify as personal data.
A provider should therefore not assume that its international data-access analysis is complete merely because its GDPR transfer mechanisms are in place.
The two regimes need to be assessed separately.
The Data Act distinguishes between requests supported by an applicable international agreement and other third-country decisions or orders.
Where a decision or judgment requiring access or transfer is based on an applicable international agreement — such as a mutual legal assistance treaty — the Data Act expressly recognises that framework.
Where no such agreement applies and complying with the request would risk creating a conflict with EU or relevant Member State law, access or transfer is subject to specific conditions.
These include requirements concerning the specificity and proportionality of the decision, the availability of judicial review and the ability of the relevant court or tribunal to take account of legal interests protected under EU or national law.
The provider may therefore need to carry out a genuine legal assessment before responding to the request.
Compliance cannot be dealt with only when a request arrives.
International providers should have an internal process capable of identifying and escalating governmental access requests involving EU-held non-personal data.
This may include:
The process may need to interact with existing procedures for law-enforcement requests, GDPR matters and cybersecurity incidents without treating them as legally identical.
A SaaS provider may not control every layer of the infrastructure on which customer data is stored or processed.
Cloud infrastructure providers and other subcontractors may themselves be subject to third-country laws or receive governmental access requests.
The provider should therefore understand how relevant suppliers address these requests.
Contractual arrangements may need to cover matters such as:
The objective is not simply to obtain contractual assurances, but to ensure that the provider can actually meet its own obligations under the Data Act.
Article 32 does not impose only a contractual obligation.
The Data Act expressly refers to technical, organisational and legal measures.
Depending on the circumstances, relevant measures may include access controls, encryption, key-management arrangements, internal governance, audit mechanisms and appropriate security assurance.
The appropriate measures will depend on the service architecture, the sensitivity of the data and the legal exposure of the provider and its suppliers.
A contractual clause stating that data is “hosted in the EU” is therefore not, by itself, a complete response to the issue.
Governmental access and digital sovereignty are increasingly raised during technology contract negotiations in France, particularly by regulated organisations and public-sector customers.
International providers may encounter:
Not all such customer requirements derive directly from Article 32 of the Data Act.
Some may arise from other regulatory frameworks, public-sector policies or the customer's own risk-management requirements.
The provider therefore needs to distinguish between the underlying legal requirement and the additional contractual position sought by the customer.
For public-sector projects, see also Selling SaaS and Cloud Services to the French Public Sector: What International Providers Need to Know.
For international providers, one practical lesson is particularly important:
EU hosting and EU legal sovereignty are not necessarily the same thing.
Locating data in an EU data centre may address an important part of the customer's requirements, but it does not automatically resolve every issue concerning third-country governmental access.
The analysis may also need to consider corporate structure, applicable foreign laws, infrastructure providers, contractual safeguards and technical measures.
Conversely, the existence of a non-EU parent company does not mean that every service is automatically incompatible with EU requirements.
The relevant legal and technical circumstances need to be assessed rather than reduced to a simple provider-nationality test.
Withlaw assists international SaaS and cloud providers in addressing EU requirements relating to third-country governmental access, including:
The objective is to identify the provider's actual legal exposure and implement proportionate contractual, organisational and technical safeguards without reducing a complex issue to data location alone.