| ▲ | jacquesm 6 hours ago |
| EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities. |
|
| ▲ | ffsm8 5 hours ago | parent | next [-] |
| > your data can still be forcibly pulled and often without you being aware that this happened as a german i feel the urge to point out that this technically also applies to european companies...
With more hurdles for the US, but still technically applicable |
| |
| ▲ | jacquesm 4 hours ago | parent | next [-] | | That's true but the EU still has a - mostly - functioning legal system. See 'Schrems' and other lawsuits that came out as they should have. | | |
| ▲ | perks_12 3 hours ago | parent [-] | | Take a look at how they play with regards to chat control. The EU is just the same corrupt BS like D.C., only with a lot more virtue signaling. | | |
| ▲ | jacquesm 3 hours ago | parent | next [-] | | Sorry, I don't agree with that. The amount of corruption in the USA right now is simply off the scale. | | |
| ▲ | sneak an hour ago | parent [-] | | Nah, it’s just more visible. It’s not that much of a sea change. And it’s ridiculously naive to pretend that the major countries in Europe don’t have their own mechanisms to regularly and effectively bypass any democratic inconveniences when necessary. They regularly push through things that no constituent would ever want or vote for. | | |
| |
| ▲ | sscaryterry 2 hours ago | parent | prev [-] | | Not nearly the same thing. Trump and his family have made billions. I cannot say the same of von der Leyen. |
|
| |
| ▲ | usernomdeguerre 5 hours ago | parent | prev | next [-] | | True, I think the calculus is more about who you think is more trustworthy than what tools they have to damage you. | |
| ▲ | throwawayffffas 3 hours ago | parent | prev | next [-] | | I am almost positive things are not the way they were and requests for data access especially if the subjects background is "suspect" are more highly scrutinized. And as the Americans are choosing to interfere in European domestic politics and trample their own laws and constitution the more scrutiny their requests will get. | |
| ▲ | slow_typist 4 hours ago | parent | prev [-] | | Especially if European companies have an office and significant share of customers in the US. |
|
|
| ▲ | V__ 6 hours ago | parent | prev | next [-] |
| For anyone curious, it's the CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil. [1] https://en.wikipedia.org/wiki/CLOUD_Act |
| |
| ▲ | tzs 12 minutes ago | parent | next [-] | | It's weird how everyone focuses on that part of the CLOUD Act. The CLOUD Act actually did two things: (1) that, and (2) provided an expedited way for the US to enter into Mutual Legal Assistance Treaties (MLATs) with other countries. It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part. The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting. One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications. There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction). So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant. The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US. With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes. There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were. The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing then across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them. For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada. With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them. And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant. The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification. The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block. There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so. Civil rights groups and many others were not impressed with those safeguards. | |
| ▲ | samudrijan 5 hours ago | parent | prev | next [-] | | The point of control is Congress, until we stop electing corpratist politicians, we will continue to get bad legislation. | | |
| ▲ | redserk 2 hours ago | parent [-] | | It doesn't matter if it's Congress. At the end of the day America's internal governance systems are America's problem. The rest of the world should not care if a certain branch is causing issues, and frankly, is starting to come to that conclusion. It's unfortunate for us, but we very rarely isolate individual government systems for other nations. |
| |
| ▲ | braiamp 6 hours ago | parent | prev [-] | | Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based. | | |
| ▲ | kid64 6 hours ago | parent [-] | | They're Australian | | |
| ▲ | petcat 5 hours ago | parent | next [-] | | Australian companies are also subject to the USA Cloud Act. As is the UK, with Canada coming on board soon too. Even the entire EU is in the process of negotiating the same agreement. https://www.justice.gov/archives/opa/pr/united-states-and-ca... https://www.justice.gov/archives/opa/pr/justice-department-a... | | |
| ▲ | jorvi 3 hours ago | parent | next [-] | | That is plain wrong, and on top of that, the CLOUD act doesn't really solve anything because if the order to obtain data is legal for the US arm but illegal for the EU arm, releasing the data from say Ireland to the US would immediately lead to steep monetary and legal penalties for the EU arm. | | | |
| ▲ | yborg 5 hours ago | parent | prev [-] | | Your linked information doesn't indicate anywhere that Australia or any other foreign government is subject to US law. The latter states that negotiation with the EU on this topic was suspended in 2019. Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty. | | |
| ▲ | petcat 5 hours ago | parent [-] | | https://www.justice.gov/criminal/criminal-oia/cloud-act-agre... > The latter states that negotiation with the EU on this topic was suspended in 2019. Dated 2023: > Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations The negotiations are still ongoing. Canada is further along than the EU. |
|
| |
| ▲ | perpetuallunch 3 hours ago | parent | prev | next [-] | | That’s not going to help anyone. The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence. https://en.wikipedia.org/wiki/Five_Eyes | | |
| ▲ | JAlexoid 3 hours ago | parent [-] | | Even being stored in EU doesn't preclude your data from being targeted by signals intelligence. Which is different than requiring US based companies to provide non-US data to American government. Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction. |
| |
| ▲ | wolfi1 5 hours ago | parent | prev [-] | | isn't there this five eyes thingy? |
|
|
|
|
| ▲ | thisislife2 an hour ago | parent | prev | next [-] |
| True. Australia is part of the Five Eyes alliance. Fastmail is an Australian company. Australia also has the Assistance and Access Act - https://havenmessenger.com/blog/posts/australia-assistance-a... - which just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them. (When the law passed, Fastmail lost many clients - https://www.itnews.com.au/news/fastmail-loses-customers-face... ). |
|
| ▲ | microtonal 5 hours ago | parent | prev | next [-] |
| Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail: - The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act. - The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar. Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication. |
| |
| ▲ | 1over137 an hour ago | parent [-] | | Something like 99% of email is now done over TLS. | | |
| ▲ | SoftTalker 15 minutes ago | parent [-] | | Yes but it will almost always work with self signed or expired certificates, or downgrades to clear text if that's what it takes to deliver the message. |
|
|
|
| ▲ | DarrenDev 4 hours ago | parent | prev | next [-] |
| EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US. AWS, Azure, GCP, Oracle, Schwarz Digits, SAP |
| |
| ▲ | easton 4 hours ago | parent | next [-] | | Requiring that you believe those companies that they won’t hand the keys over to the US at the first ask. Like, the critical problem with the AWS sovereign pitch is that you must believe that they won’t give the keys to the US, and they also won’t give the source code that’s hosted in the US to the government either for them to find vulnerabilities in. I don’t know if that’s good enough unless you just need the data to stay in the EU and you don’t care if another country sees it. I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I don’t know if they explained how they’re safe to the public. | | |
| ▲ | jacquesm 4 hours ago | parent [-] | | The harder problem here is that any real EU sovereign platform would have to come with ironclad guarantees that it isn't going to be directly or indirectly sold to a US party. And when enough customers move that marketshare is affected the bags with money tempting shareholders will get larger and larger. |
| |
| ▲ | jacquesm 4 hours ago | parent | prev | next [-] | | You can strike at least four of those. | |
| ▲ | martin_a 3 hours ago | parent | prev [-] | | > AWS, Azure, GCP, Oracle What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies. | | |
| ▲ | everfrustrated 37 minutes ago | parent [-] | | > Only Schwarz and SAP are free from that by being German companies. Not true. You also have to be sure that the company directors will never travel to the US even for a holiday or any third party country that would uphold an extradition request from the US. It's just email. Nobody is going to jail to protect your email. If you care that much run your own email server. |
|
|
|
| ▲ | rufasterisco 5 hours ago | parent | prev | next [-] |
| Can you point me towards some resources that show EU customers moving? Not that I don’t trust the statement, I just would like to know more. |
| |
| ▲ | jacquesm 4 hours ago | parent | next [-] | | I hope Airbus is large enough for you? https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cl... And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right. | | | |
| ▲ | toomuchtodo 4 hours ago | parent | prev [-] | | HN Search: airbus critical apps scaleway - https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments) Netherlands reaches deal with European cloud company to decrease U.S. tech reliance - https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ... - April 24th, 2026 Wary of US Big Tech, the EU looks to build its “EuroStack” - https://sherwood.news/world/wary-of-us-big-tech-the-eu-looks... - March 18th, 2026 Why European Companies Are Leaving US Cloud Providers in 2026 — And Where They're Going - https://massivegrid.com/blog/european-companies-leaving-us-c... - March 12th, 2026 Europe gets serious about cutting digital umbilical cord with Uncle Sam's big tech - https://www.theregister.com/off-prem/2025/12/22/europe-gets-... - December 22nd, 2025 Schleswig-Holstein waves auf Wiedersehen to Microsoft stack - https://www.theregister.com/software/2025/10/15/schleswig-ho... - October 15th, 2025 EU Banks Launch Wero Payments to Dislodge Visa, Mastercard - https://news.ycombinator.com/item?id=41666833 - September 2024 (88 comments) https://european-alternatives.eu/ https://euro-stack.com/ | | |
|
|
| ▲ | kisamoto 4 hours ago | parent | prev | next [-] |
| Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act? |
| |
| ▲ | kvemkon 2 hours ago | parent | next [-] | | > Take Hetzner as an example. Similar happened already with OVH Canada vs France. > In an affidavit, Xavier Barriere, corporate counsel at OVH in Paris, describes the dramatic situation: If the important proponent of European data sovereignty were to comply with the Canadian order, those responsible in France would be committing a criminal offense. They face up to six months in prison and fines of up to 90,000 euros per violation. However, if OVH ignores the Canadian court, it faces contempt of court proceedings in Ontario, which can also lead to severe sanctions. https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-Fr... And one comment here: https://news.ycombinator.com/item?id=46060903 | |
| ▲ | jacquesm 4 hours ago | parent | prev [-] | | Well, for sure they can pressure them but I highly doubt Hetzner would break the law in Europe to satisfy the US government, they are a lot more to lose here than there. I realize that that is not proof. |
|
|
| ▲ | mrtesthah 6 hours ago | parent | prev | next [-] |
| Ok, but Fastmail is an Australian company based in Melbourne. |
| |
| ▲ | petcat 6 hours ago | parent | next [-] | | Australia and the US entered into a bilateral agreement in 2024 which made Australian companies subject to the US CLOUD Act. https://www.justice.gov/criminal/criminal-oia/cloud-act-agre... | |
| ▲ | toomuchtodo 6 hours ago | parent | prev | next [-] | | As a FastMail customer who spends a portion of the year in the US, I am happy to pay to move my data to the EU region, even if they cannot yet fully guarantee all my data will remain outside of US access at this time. Defense and mitigations in depth, over time. We must always start somewhere, and perfect is never the target (as it does not exist). | | | |
| ▲ | OJFord 6 hours ago | parent | prev [-] | | But whose cloud infrastructure do they use? (I don't know, but it might likely be AWS, GCP, or Azure.) | | |
| ▲ | microtonal 5 hours ago | parent | next [-] | | That it described in the linked post: We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. | |
| ▲ | calvinmorrison 5 hours ago | parent | prev [-] | | None. It's racked and stacked old school |
|
|
|
| ▲ | BrandoElFollito 3 hours ago | parent | prev | next [-] |
| The French head of Microsoft ctor not, under oath, say that Microsoft can guarantee sovereignty. This is the evidence that until you have a EU company, under EU rules and not present in the US at all, you cannot have sovereignty. |
|
| ▲ | realo 3 hours ago | parent | prev | next [-] |
| pCloud is an example. Swiss corporation with data centers in Luxembourg. |
|
| ▲ | amelius 5 hours ago | parent | prev | next [-] |
| How does Apple handle it? |
| |
| ▲ | xnickb 5 hours ago | parent [-] | | Why would apple care? Eu is what a quarter of their business? And where exactly will those people move? They're locked into the Apple infra. |
|
|
| ▲ | calvinmorrison 5 hours ago | parent | prev | next [-] |
| Fastmail is an Australian company |
| |
| ▲ | gib444 4 hours ago | parent [-] | | And hosted on US infrastructure, satisfying the "or" clause in their post | | |
| ▲ | sodapopcan 3 hours ago | parent [-] | | The article says they installed their own servers, though. What am I missing here? |
|
|
|
| ▲ | selectively 6 hours ago | parent | prev | next [-] |
| [dead] |
|
| ▲ | atmosx 5 hours ago | parent | prev [-] |
| That’s true and Fastmail runs on AWS. But it’s a start and a “feature” many have requested for years. It’s funny because the HQ and I believe their workforce is located in Australia. |
| |
| ▲ | jph00 3 hours ago | parent | next [-] | | Not only is that not true, but in fact FastMail predates AWS by some years. Source: I founded FastMail. | | |
| ▲ | jph 2 hours ago | parent [-] | | Great username :-) I'm a happy longtime Fastmail customer and I'm migrating to the new EU area. |
| |
| ▲ | chrismorgan 5 hours ago | parent | prev | next [-] | | Fastmail has never used AWS, and this article is pretty clear about how they have always used their own hardware and traditional colocation. Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now. | | |
| ▲ | atmosx 5 hours ago | parent [-] | | That’s interesting, I thought they were hosted on AWS. Thanks for sharing. |
| |
| ▲ | preisschild 4 hours ago | parent | prev | next [-] | | But how is it actually "a start" or improves anything at all? It doesnt matter where the "physical location" of the data is. It matters who has access to it. | |
| ▲ | calvinmorrison 5 hours ago | parent | prev [-] | | Fastmail runs on its own infra. |
|