Do cross-border data rules apply to a cloud provider?
Short answer
Yes, this is the core case. Region choice, support access and subprocessors decide the route before any contract clause does.
Read against the registers 2026-08-26.
Who the role is
Whoever runs infrastructure, hosting or a platform for someone else's data and traffic.
What the topic covers
Moving records across a border is where the three regimes separate most. The EU relies on adequacy and contractual safeguards. China runs an assessment and filing route with volume thresholds. The United States has no single federal transfer rule.
Duties the EU acts name for this role
- GDPR — Regulation (EU) 2016/679, Article 28: Process personal data only on documented instructions, under a written processor agreement.
The rows behind the answer
European Union
- GDPR — Regulation (EU) 2016/679: Chapter V allows a transfer on adequacy, standard contractual clauses or another named safeguard.
United States
- California Consumer Privacy Act, as amended by the CPRA: No general export restriction. Service provider contracts carry the duty instead of a transfer mechanism.
China
- Measures for the Security Assessment of Outbound Data Transfers: A security assessment by the regulator is required above the stated volume and category thresholds.
- Measures on the Standard Contract for Outbound Transfer of Personal Information: A filed standard contract is the route below the assessment thresholds, with an impact assessment attached.
- Provisions on Facilitating and Regulating Cross-border Data Flows: Names exemptions where neither the assessment nor the standard contract route is required.
Where companies usually start
- Draw the actual route of the records, including subprocessors and support access.
- Count the Chinese volume thresholds before choosing between the assessment and the contract route.
- Attach the transfer assessment to the contract, not to a separate slide deck.
This page reads published registers and describes common practice. It is not legal advice and it is not a compliance verdict.
Other questions for cloud service provider
- Do ai governance rules apply to a cloud provider?
- Do personal data rules apply to a cloud provider?
- Do cybersecurity rules apply to a cloud provider?
- Do health data rules apply to a cloud provider?
- Do online platforms rules apply to a cloud provider?
- Do consumer rights rules apply to a cloud provider?
- Do product safety rules apply to a cloud provider?
- Do climate disclosure rules apply to a cloud provider?
- Do export controls rules apply to a cloud provider?
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.