The most controversial president of the United States, Donald Trump, signed an executive order shortly before his departure that requires American cloud companies to keep records on their foreign customers, in an effort to help American authorities track down individuals committing cybercrimes.

US cloud providers will be required to archive names, physical and email addresses, national identification numbers, means and sources of payment, such as credit card or bank account information, phone numbers, and IP addresses used to access services.
“Foreign actors are using IaaS for a variety of tasks while carrying out malicious activities, making it extremely difficult for United States officials to identify and obtain information through legal process before these foreign actors move to replacement infrastructure and destroy evidence of their past activities,” Trump wrote in a letter to House Speaker Nancy Pelosi and Vice President Mike Pence.
“The term [IaaS] means any product or service offered to a consumer, including free or ‘trial’ offerings, that provides processing, storage, networks or other essential computing resources and with which the consumer can develop and run software , including operating systems and applications,” it states.

“The consumer typically does not manage or control most of the underlying hardware, but does have control over the operating systems, storage, and any applications that are deployed. The term includes “managed” products or services, in which the provider is responsible for some aspects of system , and “unmanaged” products or services, in which the provider is responsible only for ensuring that the product is available to the consumer.”
The order gives the Minister of Commerce the ability to restrict access to US cloud services if a country is deemed to have “any significant number of foreign persons offering United States IaaS products that are used for malicious activities”. This section and the record-keeping obligations will commence after 180 days.
