The magazine of innovation in Africa
CLOUD Act, FISA 702: what African data hosted with a US cloud provider is really exposed to
Published today
For CEOs, CIOs and DPOs of African companies that host, or are thinking of hosting, with AWS, Azure, Google Cloud or Oracle. This explainer covers two US laws and what they mean for you. It doesn't compare prices, and it isn't legal advice.
The short answer (as of October 9, 2026)
The 2018 CLOUD Act requires US providers to hand over to US authorities any data they control, wherever in the world it is stored. A server in Johannesburg or Lagos doesn't change that.
Section 702 of FISA allows targeted surveillance of non-US persons outside the United States, with providers' assistance. It lapsed on June 12, 2026. But collection already authorized continues until the current certifications expire in March 2027.
The risk is real, but it isn't automatic. It depends on who controls your provider, what kind of data you hold, and what your own national law requires for transfers.
No African country has signed a CLOUD Act agreement with the United States. What applies is US law, not a negotiated framework.
The legal texts
| Text | What it says | Status |
| ---------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| CLOUD Act (Public Law 115-141, Division V, March 23, 2018) | The law that created the two sections below | In force |
| 18 U.S.C. § 2713 | Providers must preserve or disclose data "within such provider's possession, custody, or control," whether it is located "within or outside of the United States" | In force |
| 18 U.S.C. § 2523 | Agreements allowing a foreign government to request data directly from a US provider | Signed with the UK (Oct. 3, 2019) and Australia (Dec. 15, 2021); negotiations under way with Canada and the EU; none with any African country |
| FISA Section 702 (50 U.S.C. § 1881a) | Targeted surveillance of non-US persons outside the United States; the government can compel an "electronic communication service provider" to assist, in secret | Lapsed on June 12, 2026, after two short extensions. Certifications approved in March 2026 remain valid until March 2027 |
The CLOUD Act comes down to one line in § 2713: providers must disclose data they control, "regardless of whether such communication, record, or other information is located within or outside of the United States." That line is why the server's location makes no difference.
On FISA 702, keep in mind that the lapse doesn't end surveillance overnight. And Congress can pass a new law at any time.
Who it applies to
What counts is whether the provider controls the data, not where the server sits. A provider subject to US law can receive a request for data stored in Africa.
And today, the major US clouds have only a handful of regions on the continent:
| Provider | Regions open in Africa | Announced |
| --------------- | ---------------------------------------------------------------------- | ----------------------------------------------------------------- |
| AWS | Cape Town (since April 2020); Local Zone in Lagos (since January 2023) | Local Zones in Johannesburg and Nairobi |
| Microsoft Azure | Johannesburg and Cape Town (since March 2019) | Kenya region (announced May 2024) |
| Google Cloud | Johannesburg (since January 31, 2024) | None |
| Oracle | Johannesburg (January 2022), Casablanca (April 7, 2026) | Nairobi (announced January 2024), second Moroccan region (Settat) |
In practice, a Senegalese, Ivorian or Cameroonian company that picks one of these clouds sends its data out of the country, usually to South Africa or Europe. And it stays within reach of the CLOUD Act.
Providers publish their own figures. AWS says that since it started reporting the statistic in 2020, it has not disclosed any enterprise or government customer content stored outside the US to the US government. Microsoft and Oracle publish twice-yearly reports on law enforcement requests. These are useful, but they are company commitments, not legal protections.
What this means for an African company
There are two separate risks, and they shouldn't be confused:
- The CLOUD Act is a criminal investigation tool. It requires US legal process (a warrant or court order) targeting specific data. The provider can challenge it.
- FISA 702 is an intelligence tool. It targets non-US persons outside the United States, and the provider must keep it secret. This second risk matters most for sensitive data: strategy, health, government data.
This is where your own law comes in. Several African laws already regulate data leaving the country:
| Country | What the law says | Provision |
| ------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------- |
| Côte d'Ivoire | Transfers outside ECOWAS only to a country with equivalent protection, and with prior authorization from the regulator (ARTCI) | Law 2013-450, art. 26 |
| Senegal | Transfers only to a country with adequate protection; otherwise, exceptions or authorization from the CDP | Law 2008-12, arts. 49–51 |
| Nigeria | Adequacy of the destination country is assessed taking into account, among other things, "access of a public authority to personal data" | NDPA 2023, s. 42(2)(c) |
| Kenya | Transfers only with proof of appropriate safeguards to the Data Commissioner; consent also required for sensitive data | Data Protection Act 2019, ss. 48–49 |
| Rwanda | Personal data must be stored in Rwanda unless the authority issues a certificate | Law 058/2021, art. 50 |
Nigeria is the clearest case. The law explicitly asks whether foreign public authorities can access the data. A Nigerian DPO who chooses a US cloud must therefore be able to explain why the CLOUD Act and FISA don't make the transfer inadequate.
So the real question isn't "US cloud: yes or no?" It's "which data, with whom, under what safeguards, and have I done what my law requires?"
What remains uncertain
- The future of FISA 702. The section has lapsed, but authorized collection continues until March 2027, and Congress can restore it at any time.
- Conflicts of law. If a US authority requests data that your national law forbids transferring without authorization, the provider is caught between two legal systems. To our knowledge, no African court has ruled on this.
- Provider commitments. Promises to challenge requests are real, but they remain company policy.
What about a European provider like Hodi?
Let's be clear: a European provider is still subject to European courts. No operator is outside the law. The difference is that European law protects against foreign requests:
- the GDPR (Art. 48) only recognizes a third country's order to hand over personal data if it is based on an international agreement, such as a mutual legal assistance treaty;
- the Data Act (Art. 32) requires cloud providers to take measures against foreign government access to non-personal data held in the EU.
One honest caveat: both texts primarily protect data located or processed in the EU. And a European group with a US subsidiary can be exposed through that subsidiary. OVHcloud US acknowledges in its FAQ that CLOUD Act requests could cover data stored outside the United States; the group, for its part, states that its European entities are not subject to it. So always ask your provider where its companies are, not just its servers.
Your data and your backups can stay in Africa, depending on the zone you choose. What is European is, first and foremost, the operator's legal accountability. These are two separate links in the chain.
So what does this mean for your hosting?
Five questions to ask any provider, whoever they are:
- Where is my data, and where are my backups? Both matter, and they aren't always in the same place.
- Which company controls the service, and where does it have subsidiaries? That's what the CLOUD Act looks at.
- What happens if a foreign authority requests my data? Is it written into the contract or the data processing agreement (DPA)?
- Does my transfer comply with my national law? Prior authorization, safeguards, local storage: see the table above.
- Can I get my data back and leave? Reversibility is the best insurance against lock-in.
Hodi is a French company with no US subsidiary, and customer data is not stored on US public cloud platforms. It stays in the location chosen at order, which we don't change without your consent (DPA, Art. 6.1). Backups are stored in the zone of your choice: Europe, South Africa or the ECOWAS region. That isn't total sovereignty, because total sovereignty doesn't exist. It's a way to strengthen it: you choose where your data goes and which law applies to your provider.
Let's talk: hello\@hodi.host.
Sources
Last checked: October 9, 2026.
- 18 U.S.C. § 2713 and 50 U.S.C. § 1881a (govinfo)
- CLOUD Act resources and agreements (US Department of Justice)
- Section 702 lapse and current certifications (EPIC, June 11, 2026)
- AWS and the CLOUD Act
- Microsoft law enforcement requests report
- Oracle law enforcement requests report
- OVHcloud US CLOUD Act FAQ
- Cloud regions: Google Johannesburg (ITWeb) · Oracle Casablanca (Médias24) · Oracle Nairobi (Oracle press release) · AWS Lagos (ITWeb Africa)
- Legal texts: GDPR, Art. 48; Data Act (Regulation (EU) 2023/2854), Art. 32; Nigeria Data Protection Act 2023, s. 42; Côte d'Ivoire, Law 2013-450 (Official Gazette), arts. 1 and 26; Senegal, Law 2008-12, arts. 49–51; Kenya, Data Protection Act 2019, ss. 48–49; Rwanda, Law 058/2021, art. 50
- Hodi DPA