“We have SCCs and a DPA”
Contracts and standard clauses are in place
Your contract binds your supplier. It does not bind an American court.
Standard contractual clauses and a data processing agreement set out what a supplier is allowed to do with a customer's data. They are agreements between two private companies. They do not limit what a court can order one of those companies to do, and an order does not stop being valid because the company signed a contract promising otherwise. This is why the Court of Justice of the European Union struck down the previous EU-US data arrangement in 2020 rather than simply asking for stronger contracts: a contract cannot bind a government that never signed it.
18 U.S.C. §2713 · checked 2026-09-04 · Commission Implementing Decision (EU) 2023/1795 · checked 2026-09-04
What to ask instead
Which part of the agreement covers an order from a court outside Europe?
A data agreement covers what your supplier chooses to do. The question is what your supplier can be forced to do, and most agreements never mention it at all.
If the answer is a European company you can name, that settles it.
The other six
- “It's hosted in Europe”
- “Enterprise tier — they don't train on our data”
- “They're certified under the Data Privacy Framework”
- “We're on a sovereign cloud with a European operating entity”
- “It's encrypted, in transit and at rest”
- “Nothing sensitive goes in there”
Or run the whole test on your own company — about four minutes, nothing kept.