Two legal developments explain why “where is my data” became a serious question for ordinary WordPress owners: the Schrems II ruling and the US CLOUD Act. Neither is as complicated as the acronyms suggest. Together they say something plain: if a US-controlled company holds your data, that data can be reachable under US law, and moving personal data to the US now needs a real justification rather than a checkbox. Here is what each one actually decided, and what it means for a site running WordPress in the EU.
What Schrems II actually decided
Schrems II is the common name for a judgment of the Court of Justice of the European Union, handed down on 16 July 2020 in case C-311/18. The court was asked whether the legal mechanisms used to send personal data from the EU to the United States gave Europeans enough protection. It reached two conclusions that still shape the landscape.
First, it invalidated the EU-US Privacy Shield, the framework thousands of companies had relied on to legitimise transfers to the US. Overnight, “we are Privacy Shield certified” stopped being a valid basis. Second, it kept Standard Contractual Clauses alive but attached a condition: a company relying on them cannot just sign the clauses and move on. It has to assess whether the destination country actually offers protection essentially equivalent to EU law, and add supplementary measures where it does not. The court’s concern with the US was specifically its government surveillance powers, which a private contract between two companies cannot switch off.
The practical takeaway is that transfers to the US are no longer automatic. They are allowed where a valid mechanism and a genuine assessment support them, and they are a problem where a mechanism is cited but the underlying protection is not really there.
What the CLOUD Act changes
The US Clarifying Lawful Overseas Use of Data Act, passed in 2018, addresses the other side of the same coin. It confirms that US authorities can compel US-based providers to hand over data in their possession, custody or control, regardless of where in the world that data is physically stored. In other words, a US company operating a data centre in Sweden can still be ordered, under US law, to produce data held on that Swedish hardware.
This is the point that surprises people. You can store data in the EU and still not be free of foreign legal reach, because reach follows corporate control, not just the location of the disk. It is why the sovereignty question has two parts: where the data sits, and who controls the company holding it. Checking the second part in practice means auditing your host’s sub-processors and ownership chain. The CLOUD Act is the reason the second part cannot be waved away.
Schrems II tightened how data may leave the EU. The CLOUD Act shows how a foreign law can still reach data that never left. Together they make corporate control the thing to check.
Where the Data Privacy Framework fits
After Privacy Shield fell, the EU and US negotiated a replacement. In 2023 the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework, which once again allows personal data to flow to US companies that self-certify under it. If you use a US service today and it relies on a lawful basis, this is often the mechanism it points to, alongside Standard Contractual Clauses.
It is worth being honest about the status of this framework. It is the current, valid mechanism, and it is reasonable to rely on it. It is also the third attempt at an EU-US arrangement of this kind, and the previous two were struck down by the same court. Privacy advocates, including Max Schrems, have signalled that this one may be challenged as well. That does not make it unsafe to use now. It does mean that building your foundation on the assumption that US transfers will always be frictionless is a bet on a mechanism with a history of being overturned.
Chapter V, without the jargon
All of this sits inside Chapter V of the GDPR, the part that governs transfers of personal data outside the EU. You do not need to memorise article numbers to understand the shape of it. Chapter V says a transfer to a country outside the EU needs a lawful route, and it lists the main ones:
- An adequacy decision, where the Commission has judged a country’s protection good enough. The EU-US Data Privacy Framework works this way for certified US firms.
- Appropriate safeguards, most commonly Standard Contractual Clauses, now paired with the Schrems II assessment.
- Specific, narrow derogations for particular situations, which are not meant to be a routine basis for ongoing transfers.
The cleanest way to stay comfortably inside Chapter V is to have less to transfer in the first place. If the personal data your site collects is processed and stored inside the EU, by companies controlled inside the EU, most of Chapter V simply does not apply to your hosting. You are not managing a transfer, because there is no transfer. That is the quiet advantage of keeping the hosting path European: it turns a compliance question into a non-question.
What this means for your WordPress site
You do not have to remove every US service from your life to respond sensibly to Schrems II and the CLOUD Act. The proportionate move is to look at where your visitors’ personal data concentrates, which is the hosting path, and make sure that path is under EU control. Then handle the front-end and peripheral tools with the same logic: prefer EU-based or self-hosted options for anything that touches visitor data, and keep good records of the rest. That is a defensible posture, and it is one you can explain to a client or a regulator without hand-waving.
This is the reasoning Celestio is built on. By keeping the hosting path on Swedish infrastructure with no US cloud in it, we take the hardest transfer question off the table for the data that matters most. Our sovereignty page explains how that is set up, and our legal and GDPR hub holds the actual policies and processing terms if you want to read the fine print.
This is practical guidance, not legal advice. Schrems II and transfer law are nuanced, so consult your DPO or legal counsel for your specific situation.
