Your Data Lives in Europe. Your Provider Lives Under US Law.
There’s a phrase you can’t escape in cloud marketing right now: EU data region. Microsoft has one. AWS has one. Google has one. Now Fastmail, an email provider, has joined the list. The pitch is always the same — your data stays in Europe. The question nobody in the marketing copy wants to answer: does moving bits to a Frankfurt data center actually put them out of reach of a US warrant?
It doesn’t. And the reason why is worth understanding, because it’s the difference between a real compliance win and a false sense of security.
Why every cloud vendor suddenly has a European address
This started with regulation, not customer demand. Since GDPR, European companies and public agencies have needed a legal basis every time personal data crosses the EU border. Then in 2020, the Court of Justice of the EU handed down Schrems II, striking down the Privacy Shield framework that had made US data transfers routine. Overnight, “our data sits on American servers” went from a footnote to a procurement liability.
Vendors responded the obvious way. Build a data center in Europe. Let customers pick a region. Put a line on the pricing page that reads your data never leaves the EU.
That line is true. The data really does stay there. The problem is the question it quietly leaves unanswered.
The CLOUD Act closed the door on location-based arguments
The Clarifying Lawful Overseas Use of Data Act, passed in 2018, comes down to one principle: a company subject to US jurisdiction must comply with US legal process regardless of where in the world the data is stored.
The backstory is almost too on-the-nose. Microsoft refused to hand over emails held on Irish servers, fought the DOJ through the courts, and took the case to the Supreme Court. Before the justices could rule, Congress passed a law that mooted the whole dispute. The verdict, delivered legislatively: location is irrelevant. Control is what matters.
So the real test isn’t a map coordinate. It’s this: is the legal entity capable of retrieving your data within reach of US law? If a US parent company can direct its European subsidiary to produce records, the physical location of the disk is a rounding error.
France, Germany, and the Netherlands have all published government assessments reaching roughly this conclusion. It’s not a fringe reading.
That doesn’t make EU regions worthless
This is where the conversation usually swings to the opposite extreme — sovereignty theater, all of it marketing. That’s also wrong. The honest answer requires separating two different threat models.
What an EU region genuinely fixes: your GDPR cross-border transfer analysis gets dramatically simpler. Compliance overhead drops. Public-sector procurement checkboxes get checked. Latency improves because physics. And exposure to bulk collection by third countries, or interception along transatlantic network paths, goes down. For a European business, that’s a real, practical set of benefits.
What it does not fix: a US legal demand served on a US-controlled company. That’s not an engineering problem. You can’t solve a question of corporate nationality by pouring more concrete in Dublin.
The framing that works: regulatory compliance improves, state-access exposure stays flat. The failure is marketing that bundles both into one reassurance. The feature itself is fine.
Email is uniquely bad at resisting this
There’s a reason this lands harder on Fastmail than on, say, a file-sync service. Email is architecturally a system where the server has to read your content for the product to work.
Messaging apps can go end-to-end encrypted and mean it. Signal responds to subpoenas with a registration timestamp because that’s genuinely all it holds. Email can’t get there. Server-side search needs plaintext. Spam filtering needs plaintext. And the killer: most of your inbox arrives from outside, unencrypted, because the sender’s provider had no idea you cared. If your correspondent is on Gmail, Google has a copy of that thread no matter what you do.
Encryption at rest, tight access logging, transparency reports — all worth doing, all meaningfully better than nothing. But none of them let an email provider say we can’t see it. And if they can see it, they can be compelled to produce it. Proton and Tuta work around parts of this with client-side encryption and search index tricks, at real cost to functionality, and even they can’t encrypt mail that arrives in the clear.
What to actually check before you switch
Skip the marketing page. Four things matter.
Corporate jurisdiction. Where is the company incorporated? Does it have a US parent, a US subsidiary, or meaningful US operations? This determines legal exposure. Server location does not.
What “encrypted” means. At rest, or end to end? How does search work if it’s end to end? When a provider uses the word encryption without qualifying it, assume at rest — that means they hold the keys.
Transparency reporting. How many government requests came in, how many were complied with, is there a warrant canary? A provider that publishes nothing has told you how seriously it takes the question.
Your actual threat model. For most people the realistic risk isn’t a national security letter. It’s credential stuffing, phishing, and the provider getting breached. A hardware security key will protect you far more than agonizing over the CLOUD Act. If you are a journalist, an activist, or handling privileged legal material, the calculus changes — and so should your tooling.
The takeaway
EU data regions are a useful feature sold with an oversized promise. The gap between the comfort they market and the threats they block is where the problem lives.
Your data’s real location isn’t a point on a map. It’s the answer to a different question: whose courts can compel the person holding the keys? Worth asking about the mail, the docs, and the backups you’re using right now — most people have never checked, and the answer is rarely the country they’d guess.
Comments
Loading comments...