What Washington’s Section 301 investigation means for European digital sovereignty
On 23 July 2026 the European Commission fined Google €890 million. Within 48 hours, a competition decision had turned into a transatlantic trade dispute, with the US president announcing a trade investigation and predicting tariffs on the European Union.
This analysis sets out what happened, what changed and what did not, and why we read the dispute as an argument for European digital independence rather than against it.
What happened between Brussels and Washington
The European Commission fined Google €890 million for breaching the Digital Markets Act, the company’s first penalty under that law and the largest the DMA has produced so far. The Commission issued two separate decisions: €460 million for giving its own shopping, hotel, transport and sports services preferential ranking in Google Search, and €430 million for restricting how app developers steer users toward cheaper purchase channels outside Google Play. Google must now bring its practices into compliance or face periodic penalty payments.
Google rejected the decision, arguing that compliance forces it to remove real-time search features and dismantle protections on Google Play, and framing the outcome as product degradation rather than fair competition.
Washington responded within hours. US Trade Representative Jamieson Greer said the EU’s enforcement actions are creating substantial uncertainty for American exports and warned that they threaten transatlantic trade stability. The following day, President Trump announced that the United States would open an investigation under Section 301 of the Trade Act of 1974 into the fines the EU has levied on American technology companies. He said he anticipated a substantial tariff on the EU and predicted that the EU would reverse the penalties. European officials pushed back, stating that they answer to their own laws rather than to outside pressure.
Three details determine how seriously to read this.
Section 301 is currently Washington’s primary tariff instrument. After the US Supreme Court invalidated the administration’s tariffs under the International Emergency Economic Powers Act in February 2026, USTR has been rebuilding its tariff programmes on a Section 301 footing, including tariffs of 10 to 12.5 percent on imports from 60 trading partners, which the administration ordered on 23 July with effect from the following day. A Section 301 case against the EU’s digital rulebook is not an unusual escalation. It applies a mechanism already in active use.
The step also follows sustained political groundwork. Twenty-five members of the US House had written to the White House urging exactly this action, arguing that DMA and DSA enforcement functions as a de facto tax on American companies. Washington policy institutes welcomed the announcement as putting Brussels on notice.
Most importantly, Washington has announced the investigation but has not opened it. Under the statute, a Section 301 case formally begins when USTR publishes a notice in the Federal Register setting out the scope and timetable and requests consultations with the foreign government. That notice has not appeared, and the EU digital case does not yet feature on USTR’s list of active Section 301 investigations. The next substantive development will be that document rather than another statement.
Precedent offers one further caution. In 2020 the first Trump administration opened Section 301 investigations into national digital services taxes across Europe. Washington announced tariffs, then suspended them in 2021 as part of the OECD tax agreement. Whether that pattern repeats remains unknown.
How a trade dispute reaches your cloud infrastructure
Washington’s objective is not the €890 million. The objective is to make the European Union enforce its digital rules less aggressively, and the administration has stated as much directly. Brussels has refused.
If the United States now applies tariffs, the EU has to respond, and its strongest levers are not steel or bourbon. They are digital: the rules it applies to American platforms, and the arrangements that permit personal data to move across the Atlantic.
That second lever is the one that reaches ordinary businesses, because it is what makes using an American cloud provider lawful in the first place.
Routine transfers of personal data to US providers rest on the EU-US Data Privacy Framework, an adequacy decision the European Commission adopted in 2023. That framework is not a treaty. It is a Commission decision built on US executive commitments, and the Commission can suspend, amend or repeal it if the underlying American legal framework changes. The General Court confirmed exactly that continuing obligation when it dismissed a challenge to the framework on 3 September 2025, upholding its validity as it stood when the Commission adopted it. French MP Philippe Latombe has since appealed to the Court of Justice, so the question remains open. The CJEU annulled the two predecessor arrangements, Safe Harbour and Privacy Shield, in 2015 and 2020.
The chain therefore runs as follows. Trade pressure produces European counter-pressure. The transatlantic data arrangement becomes a bargaining chip. The legal basis of an American cloud contract turns uncertain. Not next month, and not necessarily at all. But that is the mechanism, and it has moved twice before.
The US CLOUD Act: why jurisdiction matters more than location
Everything above concerns the political durability of these arrangements. Beneath them sits a legal fact that most organisations find when a dispute of this kind finally prompts them to look.
The US CLOUD Act of 2018 allows American authorities to compel American companies to produce data regardless of where in the world that data sits. Article 48 of the GDPR provides that an order from a non-EU court or authority carries force only where an international agreement, such as a mutual legal assistance treaty, underpins it. Both statements hold true simultaneously, and no amount of data centre placement resolves the contradiction.
The European Data Protection Board and the European Data Protection Supervisor examined this directly in a joint legal assessment for the European Parliament in July 2019. They concluded that a foreign authority’s request does not in itself make a transfer lawful, and that providers subject to US jurisdiction have very limited options for complying with CLOUD Act orders without breaching the GDPR. No EU-US agreement has resolved that conflict since.
The providers themselves have confirmed the position on the record. In sworn testimony before a French Senate inquiry into public procurement and digital sovereignty in June 2025, senators asked Microsoft France’s director of public and legal affairs whether he could guarantee that American authorities would never receive French citizens’ data without French authorisation. His answer, as reported by The Register, was that he could not guarantee it. He added that it had never happened. Forbes covered the same testimony. Both halves of that answer deserve credence, and neither of them amounts to a guarantee.
The point is jurisdictional rather than geographic. A server in Frankfurt that a US incorporated company owns falls under American law. A German or Dutch subsidiary does not alter the control relationship. This is why sovereign cloud offerings from American hyperscalers still draw scepticism. They can genuinely improve data residency, encryption and operational separation, all of which carry real value, but they cannot change who ultimately controls the corporate entity.
So the trade dispute and the CLOUD Act operate on different timescales. The dispute is what makes organisations look. Jurisdiction is what they find when they do.
The nature of the dependency risk
Put together, the exposure these two things describe is neither a fine nor a sudden loss of access. It is dependency, and dependency behaves differently from the operational risks most IT functions already manage competently.
Three characteristics make it difficult to price. The probability of disruption in any given quarter is low, which makes deferral easy to justify. The potential impact is severe, because the systems in question are the ones an organisation cannot suspend while a dispute runs its course. And the remediation time is long, since migrating file storage, mail and identity infrastructure takes quarters rather than weeks, which means the decision must precede the disruption rather than respond to it. Risks with that profile receive too little weight, not through carelessness, but because nothing in the ordinary course of business ever triggers the review.
The concentration compounds it. American providers account for the majority of the European cloud market, which means the dependency is not spread across many jurisdictions but concentrated in one: the same jurisdiction currently threatening tariffs over the rules that govern it. Dependency on many countries is diversification. Dependency on one is exposure.
For an individual organisation, then, the question is not whether this trade dispute resolves favourably. It is how much business critical function sits under a jurisdiction it has no part in, and what relocating that function would realistically cost. Regulated sectors such as public administration, healthcare and financial services encounter the question earlier, because supervisory authorities ask it directly. Everyone else encounters it during due diligence, an audit, or an incident.
The conclusion this supports is deliberateness rather than urgency. An organisation should be able to state, without commissioning a research project, which of its critical systems fall under non-EU jurisdiction, what its contracts actually guarantee about third country access, and how long an exit would take. Most cannot answer all three. That gap, rather than any particular tariff, is what makes the current dispute worth attention.
Our position on European digital independence
Rules only attract this level of pressure when they work.
Nobody opens a trade investigation over regulation that has no effect. Washington is contesting the Digital Markets Act precisely because it changes behaviour. That is an argument for keeping data under European rules, not for treating those rules as a liability.
We would draw a sharper conclusion as well. If a trade negotiation can move an organisation’s compliance position, that position is not sovereign. It is contingent. The reasonable response is not to wait and see how this dispute resolves, but to reduce the number of things in the infrastructure that depend on it resolving favourably.
Commentators usually frame European digital sovereignty as a political project. For an individual business it is something far more ordinary: knowing which legal system its data sits in, and choosing one whose rules it is willing to live under. That is a procurement decision, and it is available today.
The market has already moved on this. Gartner forecasts worldwide sovereign cloud infrastructure spending of 80 billion dollars in 2026, up 35.6 percent, with European growth of 83 percent taking the region from 6.9 billion dollars in 2025 to 12.6 billion in 2026 and past North America in 2027. Gartner also expects 20 percent of existing workloads to shift from global to local cloud providers.
Four questions for your own stack
1. Who owns your provider, rather than where do the servers sit? Data residency and jurisdiction answer different questions. What matters is corporate control: which country’s courts can compel your provider to act.
2. What does your contract guarantee, and what does it merely describe? “Data stored in the EU” describes current practice. A contractual commitment on jurisdiction and third country access creates an enforceable obligation. Establish which one you hold.
3. Where does your unstructured data actually live? Most organisations have mapped their CRM and ERP. Files, shared drives, mail attachments and backups usually hold the real exposure, because nobody ever made a deliberate decision about them.
4. Could you leave? Sovereignty without portability is a preference rather than a capability. Check the exit: export formats, notice periods, and how long a migration would realistically take.
Where vBoxx stands
vBoxx is an independent Dutch company. Since 2012 we have run our own hardware in data centres in the Netherlands and Germany, we hold ISO 27001 certification, and the US CLOUD Act does not reach us.
vBoxxCloud is our storage and file sharing platform for teams. Your files stay in Europe, under European law.
Questions about where your own data currently sits? Get in touch.
Frequently asked questions
Does the Section 301 investigation cancel the EU’s fine on Google? No. Section 301 is a domestic US trade procedure with no power over European Commission decisions. Washington has announced the investigation but has not formally opened it, because USTR has not yet published the required Federal Register notice.
Is my data safe if my US provider stores it in an EU data centre? Storage location and legal jurisdiction answer different questions. Under the US CLOUD Act, American authorities can compel American companies to produce data wherever it sits. Microsoft confirmed under oath before a French Senate inquiry in June 2025 that it could not guarantee otherwise.
What is the difference between data residency and digital sovereignty? Residency means your data physically sits in a given country. Sovereignty means only that country’s legal system can compel access to it. Residency without sovereignty leaves the underlying exposure intact.
Is the EU-US Data Privacy Framework still valid? Yes. The General Court upheld it in September 2025 in Case T-553/23. Latombe has appealed that ruling to the Court of Justice, and the CJEU annulled two predecessor arrangements in 2015 and 2020.
Should European businesses migrate away from US cloud providers? That depends on risk profile, sector and regulatory obligations. The reasonable first step is assessment rather than migration: establish which systems fall under non-EU jurisdiction, then decide which of those you are comfortable leaving that way.
Sources
- European Commission, press release on the Google DMA fines, 23 July 2026
- European Commission, Digital Markets Act decision summary
- The White House, Section 301 tariff action on 60 economies
- Office of the US Trade Representative, active Section 301 investigations
- Congressional Research Service, Section 301 of the Trade Act of 1974
- EDPB and EDPS, joint legal assessment of the US CLOUD Act, July 2019
- Gartner, sovereign cloud IaaS spending forecast, February 2026



