IT Contracts, Data & Cybersecurity Lawyer | Withlaw
  • Our firm
  • About us
  • Our areas of expertise
  • What our clients say
  • Insights
  • Contact us
  • FR

Third-Country Government Access under the EU Data Act: What International SaaS and Cloud Providers Need to Know

International access to data is often approached primarily as a GDPR issue.

The EU Data Act adds another dimension.

Article 32 specifically addresses international governmental access to non-personal data held in the European Union by providers of data processing services.

For international SaaS and cloud providers — particularly those headquartered outside the EU or relying on non-EU infrastructure providers — this creates a separate compliance issue that needs to be considered alongside, but distinguished from, GDPR international transfer requirements.

What does Article 32 require?

Providers of data processing services must take adequate technical, organisational and legal measures to prevent international or third-country governmental access to, or transfer of, non-personal data held in the EU where such access or transfer would conflict with EU law or the law of the relevant Member State.

This obligation can therefore affect providers established outside the European Union when they provide data processing services to EU customers.

For international providers, the analysis should not stop at the location of their servers.

The legal framework applicable to the provider, its corporate group and relevant subcontractors may also need to be considered.

For a broader overview of the Data Act requirements applicable to SaaS and cloud providers, see EU Data Act & SaaS: What International Providers Need to Know.

The issue is not limited to personal data

This distinction is fundamental.

The GDPR already provides a detailed framework governing international transfers of personal data.

Article 32 of the Data Act addresses a different issue: certain governmental access to non-personal data held in the EU.

Depending on the service, this may include commercially sensitive information, business data, technical information or other data that does not qualify as personal data.

A provider should therefore not assume that its international data-access analysis is complete merely because its GDPR transfer mechanisms are in place.

The two regimes need to be assessed separately.

What happens when a third-country authority requests access?

The Data Act distinguishes between requests supported by an applicable international agreement and other third-country decisions or orders.

Where a decision or judgment requiring access or transfer is based on an applicable international agreement — such as a mutual legal assistance treaty — the Data Act expressly recognises that framework.

Where no such agreement applies and complying with the request would risk creating a conflict with EU or relevant Member State law, access or transfer is subject to specific conditions.

These include requirements concerning the specificity and proportionality of the decision, the availability of judicial review and the ability of the relevant court or tribunal to take account of legal interests protected under EU or national law.

The provider may therefore need to carry out a genuine legal assessment before responding to the request.

Providers need an internal response process

Compliance cannot be dealt with only when a request arrives.

International providers should have an internal process capable of identifying and escalating governmental access requests involving EU-held non-personal data.

This may include:

  • identifying the requesting authority and legal basis;
  • determining the categories and location of the data concerned;
  • identifying any applicable international agreement;
  • assessing potential conflicts with EU or Member State law;
  • involving appropriate legal, security and compliance teams;
  • documenting the assessment and response;
  • considering whether the relevant customer can or should be informed.

The process may need to interact with existing procedures for law-enforcement requests, GDPR matters and cybersecurity incidents without treating them as legally identical.

Infrastructure providers and subcontractors matter

A SaaS provider may not control every layer of the infrastructure on which customer data is stored or processed.

Cloud infrastructure providers and other subcontractors may themselves be subject to third-country laws or receive governmental access requests.

The provider should therefore understand how relevant suppliers address these requests.

Contractual arrangements may need to cover matters such as:

  • notification of governmental requests where legally permitted;
  • challenge procedures;
  • disclosure limitations;
  • security measures;
  • cooperation and documentation;
  • data location;
  • subcontracting arrangements.

The objective is not simply to obtain contractual assurances, but to ensure that the provider can actually meet its own obligations under the Data Act.

Technical and organisational measures also matter

Article 32 does not impose only a contractual obligation.

The Data Act expressly refers to technical, organisational and legal measures.

Depending on the circumstances, relevant measures may include access controls, encryption, key-management arrangements, internal governance, audit mechanisms and appropriate security assurance.

The appropriate measures will depend on the service architecture, the sensitivity of the data and the legal exposure of the provider and its suppliers.

A contractual clause stating that data is “hosted in the EU” is therefore not, by itself, a complete response to the issue.

Why this matters when contracting with French customers

Governmental access and digital sovereignty are increasingly raised during technology contract negotiations in France, particularly by regulated organisations and public-sector customers.

International providers may encounter:

  • customer questionnaires concerning exposure to third-country laws;
  • contractual commitments concerning governmental access requests;
  • requirements relating to data location;
  • restrictions on subcontractors;
  • specific security or encryption requirements;
  • requests for notification or challenge mechanisms.

Not all such customer requirements derive directly from Article 32 of the Data Act.

Some may arise from other regulatory frameworks, public-sector policies or the customer's own risk-management requirements.

The provider therefore needs to distinguish between the underlying legal requirement and the additional contractual position sought by the customer.

See Negotiating SaaS Agreements with French Enterprise Customers: What International Providers Should Expect.

For public-sector projects, see also Selling SaaS and Cloud Services to the French Public Sector: What International Providers Need to Know.

Data sovereignty requires a broader analysis than server location

For international providers, one practical lesson is particularly important:

EU hosting and EU legal sovereignty are not necessarily the same thing.

Locating data in an EU data centre may address an important part of the customer's requirements, but it does not automatically resolve every issue concerning third-country governmental access.

The analysis may also need to consider corporate structure, applicable foreign laws, infrastructure providers, contractual safeguards and technical measures.

Conversely, the existence of a non-EU parent company does not mean that every service is automatically incompatible with EU requirements.

The relevant legal and technical circumstances need to be assessed rather than reduced to a simple provider-nationality test.

How Withlaw can help

Withlaw assists international SaaS and cloud providers in addressing EU requirements relating to third-country governmental access, including:

  • assessing the application of Article 32 of the EU Data Act;
  • reviewing contractual arrangements with infrastructure providers and other subcontractors;
  • reviewing governmental-access procedures and escalation processes;
  • addressing contractual requirements relating to data location, governmental access and digital sovereignty;
  • supporting responses to French customer security and compliance questionnaires;
  • negotiating these issues with French enterprise and public-sector customers;
  • coordinating Data Act requirements with GDPR, cybersecurity and other applicable EU or French regulatory frameworks.

The objective is to identify the provider's actual legal exposure and implement proportionate contractual, organisational and technical safeguards without reducing a complex issue to data location alone.

© Withlaw 2015 – 2026 – All rights reserved

Legal information / Privacy Policy / Credits / Contact us / Share / Follow us on LinkedIn