Background

Why European data sovereignty matters

Not scare stories β€” just the legal facts, with sources. Five minutes of reading that changes how you choose a host.

1. A server in Europe can still answer to Washington

In 2018 the United States passed the CLOUD Act. It obliges American providers to hand over data that is in their “possession, custody, or control” β€” wherever in the world it is stored [1]. A US company’s datacenter in Frankfurt or Amsterdam is still within reach of a US warrant. That includes the European subsidiaries of American clouds.

To be precise β€” because precision matters here: the CLOUD Act is not mass surveillance. It requires legal process, typically a court-approved warrant in a criminal investigation. The separate FISA Section 702 regime covers foreign-intelligence collection targeting non-US persons [2]. Two different laws, one common feature: your data’s location in Europe does not protect it if your provider is American.

2. Microsoft confirmed it β€” under oath

On 10 June 2025, before an inquiry committee of the French Senate, the legal director of Microsoft France was asked whether he could guarantee that French citizens’ data would never be transmitted to US authorities without France’s agreement. His answer:

“Non, je ne peux pas le garantir.”
β€” “No, I cannot guarantee it.”

Anton Carniaux, Director of Public and Legal Affairs, Microsoft France, French Senate hearing, 10 June 2025 [3]

He added that it had never happened to date, and that Microsoft resists unfounded requests. Both true β€” and beside the point. The point is that no US-headquartered provider can promise you otherwise, because their own law forbids them to.

3. The legal bridge keeps collapsing

EU-US data transfers rest on adequacy agreements β€” and they keep getting struck down. Safe Harbour fell in 2015 (Schrems I). Privacy Shield fell in 2020 (Schrems II), when the EU Court of Justice found US surveillance law incompatible with European fundamental rights [4]. Its successor, the Data Privacy Framework, survived a first challenge in September 2025 β€” but the appeal is now before the EU’s highest court (case C-703/25 P) [5], while the US oversight board meant to safeguard the deal has lost its quorum [6].

If your hosting depends on a US provider, your GDPR compliance depends on that framework surviving. Ours doesn’t β€” because no transfer to the US takes place in the first place.

4. What we do differently

  • Your sites run exclusively on EU-owned infrastructure providers in EU datacenters β€” never on the EU regions of American clouds.
  • Backups stay in the EU, on EU-owned storage.
  • We are an independent European company β€” no US parent, no private-equity roll-up.
  • A Data Processing Agreement and a complete, public sub-processor list come with every plan.
  • This website itself sets no third-party requests β€” no US fonts, no US analytics, nothing.

One honest caveat, because honesty is the product: “sovereignty” is about structural legal exposure, not about magic immunity. European providers answer to European courts and European law β€” as they should. What you remove by choosing an EU-owned chain is the foreign legal reach over your data, and your dependency on EU-US deals that keep failing in court.

Sources

  1. US Congressional Research Service, The CLOUD Act, report R45173 β€” congress.gov/crs-product/R45173
  2. Congressional Research Service on FISA Section 702 and the 2024 RISAA reauthorization β€” congress.gov/crs-product/R48592
  3. French Senate, commission d’enquΓͺte hearing of 10 June 2025 (senat.fr); reported by The Register (25 July 2025) and heise online
  4. Court of Justice of the EU, C-311/18 (Schrems II), 16 July 2020
  5. EU General Court, T-553/23 (Latombe), 3 September 2025; appeal C-703/25 P pending before the Court of Justice
  6. Reporting on the US Privacy and Civil Liberties Oversight Board losing its quorum, January 2025 onwards