EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.
> just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them
It stops just short of saying that you must do thispreemptively, but is pretty clear that you must do it if they ask you to.
> your data can still be forcibly pulled and often without you being aware that this happened
as a german i feel the urge to point out that this technically also applies to european companies...
With more hurdles for the US, but still technically applicable
I am almost positive things are not the way they were and requests for data access especially if the subjects background is "suspect" are more highly scrutinized.
And as the Americans are choosing to interfere in European domestic politics and trample their own laws and constitution the more scrutiny their requests will get.
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
It's weird how everyone focuses on that part of the CLOUD Act. The CLOUD Act actually did two things: (1) that, and (2) provided an expedited way for the US to enter into Mutual Legal Assistance Treaties (MLATs) with other countries.
It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.
The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.
One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.
There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).
So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.
The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.
With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.
There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.
The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing them across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.
For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.
With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.
And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.
The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.
The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.
There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.
Civil rights groups and many others were not impressed with those safeguards.
Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US.
Requiring that you believe those companies that they wonât hand the keys over to the US at the first ask.
Like, the critical problem with the AWS sovereign pitch is that you must believe that they wonât give the keys to the US, and they also wonât give the source code thatâs hosted in the US to the government either for them to find vulnerabilities in. I donât know if thatâs good enough unless you just need the data to stay in the EU and you donât care if another country sees it.
I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I donât know if they explained how theyâre safe to the public.
What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.
Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?
Similar happened already with OVH Canada vs France.
> In an affidavit, Xavier Barriere, corporate counsel at OVH in Paris, describes the dramatic situation: If the important proponent of European data sovereignty were to comply with the Canadian order, those responsible in France would be committing a criminal offense. They face up to six months in prison and fines of up to 90,000 euros per violation. However, if OVH ignores the Canadian court, it faces contempt of court proceedings in Ontario, which can also lead to severe sanctions.
Well, for sure they can pressure them but I highly doubt Hetzner would break the law in Europe to satisfy the US government, they are a lot more to lose here than there. I realize that that is not proof.
And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right.
As a FastMail customer who spends a portion of the year in the US, I am happy to pay to move my data to the EU region, even if they cannot yet fully guarantee all my data will remain outside of US access at this time. Defense and mitigations in depth, over time. We must always start somewhere, and perfect is never the target (as it does not exist).
The French head of Microsoft ctor not, under oath, say that Microsoft can guarantee sovereignty. This is the evidence that until you have a EU company, under EU rules and not present in the US at all, you cannot have sovereignty.
Thatâs true and Fastmail runs on AWS. But itâs a start and a âfeatureâ many have requested for years. Itâs funny because the HQ and I believe their workforce is located in Australia.
Fastmail has never used AWS, and this article is pretty clear about how they have always used their own hardware and traditional colocation.
Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now.
But how is it actually "a start" or improves anything at all? It doesnt matter where the "physical location" of the data is. It matters who has access to it.
EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret âEU data regionâ to mean âfor privacyâ here until reading the article is completely understandable; I empathize, having done the same.
I think it's not unreasonable to see this as a first, positive, step.
It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.
Posted on the previous submission for this: itâs a good start, but from the article:
If what you need is a guarantee that your data remains only in the EU, we donât have that, and weâd rather tell you directly than let you assume otherwise.
For me this is already a better value proposition, as less value add happens in the US. With the US being a perpetrator in trade war against the EU, even this matters. Everything counts, in large amounts...
I started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their apps
Tuta is always encrypted I don't know where you got the impression that it was optional or that they could somehow magically make it work over IMAP without a bridge like proton.
Love them, but I wish they had a way to upload new sieve rules via an API. I'm probably going to try them with my own domain at some point since I think they have an option to just deliver all mail bound for that domain, which makes setting up random emails for dodgy sites really easy.
Actually thrilled that I can choose US data residency. Apparently, it was always that way? Happy that I can choose it though as I would prefer my data not be stored somewhere else.
Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though itâs protected by cryptography.
If firms donât have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their usersâ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
The Assistance and Access Act is completely irrelevant to Fastmail, because Fastmail doesnât offer end-to-end encryption. Fastmail was always subject to the Telecommunications Act, which allows Australian police access with warrants, and Fastmail has always made it clear that it complies with legal warrants.
The article you're quoting [1] concerns itself with the creation of systemic "encryption-breaking" capabilities and exploits which said law bends over backwards to expressly prohibit [2].
Australian company so: lol. Snowden triggered a few narrow real wins but the broader surveillance apparatus adapted, survived, and in some ways grew. Things were just legalised.
The local government cannot get access to the servers in Amsterdam?
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
Your reply is dishonest. I obviously couldn't replicate the entire article, but I'm assuming everyone that reads my comment also has read the article. And so you know very well what I meant.
If you advertise foolproof safes, but they end up not in fact being exactly that very thing you advertised then I'm sure you will have a great reason as to why actually your 'foolproof' safe can not be foolproof and you never guaranteed such a thing in your tos.
But at the end of the day, you promised foolproof safes, and you did not deliver.
Your argument is "well if you leave the lock open then...". And the reply to that argument is that "yes, we all know". The fact that I the user can make a mistake, does not excuse the company from saying "well, anyway, he would have made a mistake anyway so why bother"
At the moment all your data is still replicated in the US (they say it will change in the future, sure) and all the logs are also stored there, with no plans to change it or more details into what they contain.
As of now there's no guarantee of... anything, really.
Obviously if you decide to send an email to the US you're choosing to send your data there, that's a strawman.
Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
As long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Actâand non-U.S. citizens have absolutely no legal recourse when it comes to U.S. services
If what you need is a guarantee that your data remains only in the EU, we donât have that, and weâd rather tell you directly than let you assume otherwise.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
Among these runbox is quite good and my friend has used migadu for a few years and likes it even though he says the "soft" limits still make him uncomfortable even though so far he has never hit them; so I guess that should be fine. Posteo doesn't support custom domains (I've used them and otherwise they are good). I wouldn't go with Proton ever. Mailo seems new - never heard of them. Would love to get a review.
mailbox.org can be avoided if you need to send and receive emails from domains where the mail admins might not be email admin savants and/or privacy activists (sometimes that's not a choice in case of Govt services etc and you may not live in a country when you can get those changes done). Also, if you ever face an issue and send them an email, expect the reply to come in weeks (if you are lucky) and that too a flippant (sometimes even terse) nothing-mail and then if you respond the cycle repeats until you give up.
Depends on the definition and your threat model but to make a very large story short; itâs email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and thatâs the highest level of security you can realistically achieve.
If that works fine if not, use another method of comm. Email wasnât designed to be secure.
Thank you. Sure. In Europe the "euro stack" approach becomes more and more relevant. So, the issue is more a compliance topic in the way of making use of service provides, who are best-case "eu-headquartered", but at least with a guarantee that processing on my side stays within the european realm. Doesn't mean very little in a technical understanding of security, I agree.
Proton is leaving Switzerland because of surveillance and privacy issues.
> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance â proposals that have been outlawed in the EU â Proton is moving most of its physical infrastructure out of Switzerland.
They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.
Can't wait to verify my age before reading emails!
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
No one would know that other than Fastmail and regulators. But what I can say is keeping different emails for different purposes might be the way. Unless your domain also has none of your PII attached to you, neither is any of your email interactions. It's not ideal but I finally stopped fighting it and use few emails that offers both privacy and anonymity if I ever need that.
I have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
Even at cloud prices, 50GB of storage is ~$1/month. Offering an additional tier with pathetic storage to save $0.80 or whatever is muddling the offering.
I guess they could offer a 0GB storage option that only operated as a relay?
The flagged/dead comment contains a copy of the entire page, but the relevant part is:
> Built by us, not rented from someone else
> Weâve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software â specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We donât rent computing or management services from a big cloud provider and pass on their assurances. Thatâs how weâve approached privacy, reliability, and performance for more than 25 years.
> Weâve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software â specified right down to the exact model of disks in each machine.
Does it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.
The US data replicas will be resilient, and when the FBI asks your data to reveal things about itself, your data will refuse to reveal anything about itself in the characteristic resilient manner. That's why the mention of "resilient".
To me, jurisdiction matters more than physical location. I'd rather be with a EU-operated service that stores data on a non-EU server, than a non-EU operator with a German/french datacenter.
Data is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.
EU data regions are based on the insanely flawed idea that data is:
* a physical thing that can only live in one place
* not copyable
* can be 'contained'.
The whole thing reeks of bureaucratic 'best practices' that just aren't.
Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.
Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.
Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.
Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.
This is not an EU law anyways, this is snakeoil companies acting like having their data located in the EU will change who has access to it and will make it "GDPR compliant" (it wont since the CLOUD ACT still applies)
> The CLOUD Act authorizes bilateral agreements between the United States and trusted foreign partners that will make both nationsâ citizens safer, while at the same time ensuring a high level of protection of those citizensâ rights.
I think the keywords are "trusted" and "citizens' rights". US burned a lot of trust in the last few years, and what's happening with ICE doesn't really scream "citizens' rights" either. I can see why many "trusted foreign partners" would now think twice rather than help out the US compared to just 5 years ago.
As a EU person, I'd really like to not have ties with US when possible, and I'd really like to foster the economy of non-US alternatives.
EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.
True. Australia is part of the Five Eyes alliance. Fastmail is an Australian company. Australia also has the Assistance and Access Act - https://havenmessenger.com/blog/posts/australia-assistance-a... - which just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them. (When the law passed, Fastmail lost many clients - https://www.itnews.com.au/news/fastmail-loses-customers-face... ).
> just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them
It stops just short of saying that you must do thispreemptively, but is pretty clear that you must do it if they ask you to.
> your data can still be forcibly pulled and often without you being aware that this happened
as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
That's true but the EU still has a - mostly - functioning legal system. See 'Schrems' and other lawsuits that came out as they should have.
True, I think the calculus is more about who you think is more trustworthy than what tools they have to damage you.
I am almost positive things are not the way they were and requests for data access especially if the subjects background is "suspect" are more highly scrutinized.
And as the Americans are choosing to interfere in European domestic politics and trample their own laws and constitution the more scrutiny their requests will get.
europeans like it more when just european governments are doing it
Especially if European companies have an office and significant share of customers in the US.
For anyone curious, it's the CLOUD act:
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
[1] https://en.wikipedia.org/wiki/CLOUD_Act
The point of control is Congress, until we stop electing corpratist politicians, we will continue to get bad legislation.
It's weird how everyone focuses on that part of the CLOUD Act. The CLOUD Act actually did two things: (1) that, and (2) provided an expedited way for the US to enter into Mutual Legal Assistance Treaties (MLATs) with other countries.
It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.
The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.
One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.
There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).
So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.
The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.
With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.
There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.
The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing them across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.
For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.
With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.
And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.
The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.
The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.
There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.
Civil rights groups and many others were not impressed with those safeguards.
Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
Something like 99% of email is now done over TLS.
EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US.
AWS, Azure, GCP, Oracle, Schwarz Digits, SAP
Requiring that you believe those companies that they wonât hand the keys over to the US at the first ask.
Like, the critical problem with the AWS sovereign pitch is that you must believe that they wonât give the keys to the US, and they also wonât give the source code thatâs hosted in the US to the government either for them to find vulnerabilities in. I donât know if thatâs good enough unless you just need the data to stay in the EU and you donât care if another country sees it.
I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I donât know if they explained how theyâre safe to the public.
You can strike at least four of those.
> AWS, Azure, GCP, Oracle
What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.
Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?
> Take Hetzner as an example.
Similar happened already with OVH Canada vs France.
> In an affidavit, Xavier Barriere, corporate counsel at OVH in Paris, describes the dramatic situation: If the important proponent of European data sovereignty were to comply with the Canadian order, those responsible in France would be committing a criminal offense. They face up to six months in prison and fines of up to 90,000 euros per violation. However, if OVH ignores the Canadian court, it faces contempt of court proceedings in Ontario, which can also lead to severe sanctions.
https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-Fr...
And one comment here: https://news.ycombinator.com/item?id=46060903
Well, for sure they can pressure them but I highly doubt Hetzner would break the law in Europe to satisfy the US government, they are a lot more to lose here than there. I realize that that is not proof.
The relevant fact about Hetzner is that it's an EU company with US branch, not a US company with an EU branch.
Can you point me towards some resources that show EU customers moving?
Not that I donât trust the statement, I just would like to know more.
I hope Airbus is large enough for you?
https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cl...
And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right.
HN Search: airbus critical apps scaleway - https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments)
Netherlands reaches deal with European cloud company to decrease U.S. tech reliance - https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ... - April 24th, 2026
Wary of US Big Tech, the EU looks to build its âEuroStackâ - https://sherwood.news/world/wary-of-us-big-tech-the-eu-looks... - March 18th, 2026
Why European Companies Are Leaving US Cloud Providers in 2026 â And Where They're Going - https://massivegrid.com/blog/european-companies-leaving-us-c... - March 12th, 2026
Europe gets serious about cutting digital umbilical cord with Uncle Sam's big tech - https://www.theregister.com/off-prem/2025/12/22/europe-gets-... - December 22nd, 2025
Schleswig-Holstein waves auf Wiedersehen to Microsoft stack - https://www.theregister.com/software/2025/10/15/schleswig-ho... - October 15th, 2025
EU Banks Launch Wero Payments to Dislodge Visa, Mastercard - https://news.ycombinator.com/item?id=41666833 - September 2024 (88 comments)
https://european-alternatives.eu/
https://euro-stack.com/
Ok, but Fastmail is an Australian company based in Melbourne.
Australia and the US entered into a bilateral agreement in 2024 which made Australian companies subject to the US CLOUD Act.
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
As a FastMail customer who spends a portion of the year in the US, I am happy to pay to move my data to the EU region, even if they cannot yet fully guarantee all my data will remain outside of US access at this time. Defense and mitigations in depth, over time. We must always start somewhere, and perfect is never the target (as it does not exist).
But whose cloud infrastructure do they use? (I don't know, but it might likely be AWS, GCP, or Azure.)
The French head of Microsoft ctor not, under oath, say that Microsoft can guarantee sovereignty. This is the evidence that until you have a EU company, under EU rules and not present in the US at all, you cannot have sovereignty.
pCloud is an example.
Swiss corporation with data centers in Luxembourg.
How does Apple handle it?
Why would apple care? Eu is what a quarter of their business? And where exactly will those people move? They're locked into the Apple infra.
Fastmail is an Australian company
And hosted on US infrastructure, satisfying the "or" clause in their post
Thatâs true and Fastmail runs on AWS. But itâs a start and a âfeatureâ many have requested for years. Itâs funny because the HQ and I believe their workforce is located in Australia.
Not only is that not true, but in fact FastMail predates AWS by some years.
Source: I founded FastMail.
Fastmail has never used AWS, and this article is pretty clear about how they have always used their own hardware and traditional colocation.
Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now.
But how is it actually "a start" or improves anything at all? It doesnt matter where the "physical location" of the data is. It matters who has access to it.
Fastmail runs on its own infra.
EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret âEU data regionâ to mean âfor privacyâ here until reading the article is completely understandable; I empathize, having done the same.
I think it's not unreasonable to see this as a first, positive, step.
It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.
Indeed; see also the top thread discussing that, as I donât have anything to add to the ground already covered: https://news.ycombinator.com/item?id=49223931
Posted on the previous submission for this: itâs a good start, but from the article:
If what you need is a guarantee that your data remains only in the EU, we donât have that, and weâd rather tell you directly than let you assume otherwise.
Wow they completely missed the ball on why people want reassurances that their data stays in the EU
For me this is already a better value proposition, as less value add happens in the US. With the US being a perpetrator in trade war against the EU, even this matters. Everything counts, in large amounts...
I think they just know what they can and can't guarantee.
they also said in the article it is dependent on them standing up a second EU region. this is simply an announcement of their first.
One needs multiple data centers in europe for backup and DR, sounds like they have one
Or you can just use any of the actual European companies (Iâm using Tuta).
https://european-alternatives.eu/category/email-providers
I started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their apps
IMAP can do TLS though (IMAPS).
Did they say what's stopping them from using that (and requiring the encryption!)?
Tuta is always encrypted I don't know where you got the impression that it was optional or that they could somehow magically make it work over IMAP without a bridge like proton.
Infomaniak is another one https://www.infomaniak.com/en/ksuite
Nice, as a European customer, I appreciate this.
Side note, I moved to Fastmail a couple years ago, and so far Iâve been very happy with it! The Gmail migrator works great, too.
Love them, but I wish they had a way to upload new sieve rules via an API. I'm probably going to try them with my own domain at some point since I think they have an option to just deliver all mail bound for that domain, which makes setting up random emails for dodgy sites really easy.
I assume they support this part of JMAP https://jmap.io/spec/rfc9661/
Actually thrilled that I can choose US data residency. Apparently, it was always that way? Happy that I can choose it though as I would prefer my data not be stored somewhere else.
Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though itâs protected by cryptography.
If firms donât have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their usersâ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
The Assistance and Access Act is completely irrelevant to Fastmail, because Fastmail doesnât offer end-to-end encryption. Fastmail was always subject to the Telecommunications Act, which allows Australian police access with warrants, and Fastmail has always made it clear that it complies with legal warrants.
The article you're quoting [1] concerns itself with the creation of systemic "encryption-breaking" capabilities and exploits which said law bends over backwards to expressly prohibit [2].
[1] https://fee.org/articles/australia-s-unprecedented-encryptio...
[2] https://classic.austlii.edu.au/au/legis/cth/consol_act/ta199...
Australian company so: lol. Snowden triggered a few narrow real wins but the broader surveillance apparatus adapted, survived, and in some ways grew. Things were just legalised.
The local government cannot get access to the servers in Amsterdam?
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
The article states that they do not offer any guarantee that my data will stay in the EU!
I feel that that's the whole point. And the whole point of them making this article/advertisement.
How could they possibly guarantee such a thing?
Do you only send and receive emails with people in the EU?
Your reply is dishonest. I obviously couldn't replicate the entire article, but I'm assuming everyone that reads my comment also has read the article. And so you know very well what I meant.
If you advertise foolproof safes, but they end up not in fact being exactly that very thing you advertised then I'm sure you will have a great reason as to why actually your 'foolproof' safe can not be foolproof and you never guaranteed such a thing in your tos.
But at the end of the day, you promised foolproof safes, and you did not deliver.
Your argument is "well if you leave the lock open then...". And the reply to that argument is that "yes, we all know". The fact that I the user can make a mistake, does not excuse the company from saying "well, anyway, he would have made a mistake anyway so why bother"
At the moment all your data is still replicated in the US (they say it will change in the future, sure) and all the logs are also stored there, with no plans to change it or more details into what they contain.
As of now there's no guarantee of... anything, really.
Obviously if you decide to send an email to the US you're choosing to send your data there, that's a strawman.
Its not about the people you send emails to, its about who has access to your entire mailbox.
In the moment that would be the Trump Administration for example.
Useless. US companies have to get EU citizen's data on request. They can and must do so. Only non-US companies can ignore US data requests.
Fastmail is an Australian company.
Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
There are no Five Eyes country in the EU.
the company is based in Australia, which is part of FVEY
Is fastmail not australian?
No, but there are nine eyes and fourteen eyes with EU countries.
they offer services in the EU
Not sure Five Eyes will outlast Trump, the UK has reportedly stopped sharing some intelligence with the US:
https://www.courthousenews.com/uk-faces-questions-on-complic...
This may not have much practical consequence, but still there's some symbolic value which is welcomed in today's geopolitical climate.
As long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Actâand non-U.S. citizens have absolutely no legal recourse when it comes to U.S. services
their HQ is supposed to be in Melbourne, Australia
They mention it only briefly in their publication. Their about page is clearer about that.
If what you need is a guarantee that your data remains only in the EU, we donât have that, and weâd rather tell you directly than let you assume otherwise.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
https://mailbox.org/ Germany https://posteo.de/ Germany https://runbox.com/ Norway https://www.migadu.com/ Switzerland
more: https://european-alternatives.eu/category/email-providers
Among these runbox is quite good and my friend has used migadu for a few years and likes it even though he says the "soft" limits still make him uncomfortable even though so far he has never hit them; so I guess that should be fine. Posteo doesn't support custom domains (I've used them and otherwise they are good). I wouldn't go with Proton ever. Mailo seems new - never heard of them. Would love to get a review.
mailbox.org can be avoided if you need to send and receive emails from domains where the mail admins might not be email admin savants and/or privacy activists (sometimes that's not a choice in case of Govt services etc and you may not live in a country when you can get those changes done). Also, if you ever face an issue and send them an email, expect the reply to come in weeks (if you are lucky) and that too a flippant (sometimes even terse) nothing-mail and then if you respond the cycle repeats until you give up.
Splendid, thank you. the european-alternatives.eu is exactly what helped! Appreciate it!
Depends on the definition and your threat model but to make a very large story short; itâs email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and thatâs the highest level of security you can realistically achieve.
If that works fine if not, use another method of comm. Email wasnât designed to be secure.
Thank you. Sure. In Europe the "euro stack" approach becomes more and more relevant. So, the issue is more a compliance topic in the way of making use of service provides, who are best-case "eu-headquartered", but at least with a guarantee that processing on my side stays within the european realm. Doesn't mean very little in a technical understanding of security, I agree.
I do not know any EU-only, but ProtonMail is in Switzerland.
Proton is leaving Switzerland because of surveillance and privacy issues.
> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance â proposals that have been outlawed in the EU â Proton is moving most of its physical infrastructure out of Switzerland.
https://proton.me/blog/lumo-ai
They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.
https://www.justice.gov/archives/opa/pr/justice-department-a...
Can't wait to verify my age before reading emails!
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
PS: Am a paying customer for like a decade
No one would know that other than Fastmail and regulators. But what I can say is keeping different emails for different purposes might be the way. Unless your domain also has none of your PII attached to you, neither is any of your email interactions. It's not ideal but I finally stopped fighting it and use few emails that offers both privacy and anonymity if I ever need that.
Jurisdiction is an outdated way of looking at things. End-to-end encryption is what actually matters. Of course, people are stupid, so it continues.
I have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
You mean why isnât there a cheaper tier than $5/mo? Not much to be gained by offering it, I would think.
Even at cloud prices, 50GB of storage is ~$1/month. Offering an additional tier with pathetic storage to save $0.80 or whatever is muddling the offering.
I guess they could offer a 0GB storage option that only operated as a relay?
As a customer, thank you, Fastmail. I recall reading a few months back that this was rumored to be in the works, glad it panned out.
As a European and Fastmail user, this is great news.
Finally! I have been asking for this since the US started to lose its mind. Great they are listening.
But this is completely worthless, they still fall under the cloud act. Trump Admin still has access to your mailbox.
Secondary copy not in EU. So how exactly does that help with compliance?
It sounded like a temporary situation until they get a second EU datacenter.
And which company hosts the data? An American company like Aws, Azure, Google or a European company like OVH, Stackit?
The flagged/dead comment contains a copy of the entire page, but the relevant part is:
> Built by us, not rented from someone else
> Weâve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software â specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We donât rent computing or management services from a big cloud provider and pass on their assurances. Thatâs how weâve approached privacy, reliability, and performance for more than 25 years.
> Weâve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software â specified right down to the exact model of disks in each machine.
Not more safe. Only safe way is to use a company not under US regulation.
Does it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.
Okay, that solves two problems for me. Great news.
We offer EU data centers for customers that want their emails to stay in the EU but
"Resilient replicas of your data will live in the US"
?
The US data replicas will be resilient, and when the FBI asks your data to reveal things about itself, your data will refuse to reveal anything about itself in the characteristic resilient manner. That's why the mention of "resilient".
How is that possible if the OS/drive/vault is backdoored? Could you elaborate?
I think "resilient" just means "backup copy" and I do think (IANAL) it is illegal to destroy emails when asked for them in the US.
Or was your comment ironic? Sorry, German, irony impaired.
To me, jurisdiction matters more than physical location. I'd rather be with a EU-operated service that stores data on a non-EU server, than a non-EU operator with a German/french datacenter.
Data is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.
Totally irrelevant because of the CLOUD Act.
Aussie law might be even worse than US; I would never use Fastmail.
using cirrux.me and very happy with an actual EU hosted option (Team is Dutch)
EU data regions are based on the insanely flawed idea that data is:
* a physical thing that can only live in one place
* not copyable
* can be 'contained'.
The whole thing reeks of bureaucratic 'best practices' that just aren't.
Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.
Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.
Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.
Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.
This is not an EU law anyways, this is snakeoil companies acting like having their data located in the EU will change who has access to it and will make it "GDPR compliant" (it wont since the CLOUD ACT still applies)
> The CLOUD Act authorizes bilateral agreements between the United States and trusted foreign partners that will make both nationsâ citizens safer, while at the same time ensuring a high level of protection of those citizensâ rights.
I think the keywords are "trusted" and "citizens' rights". US burned a lot of trust in the last few years, and what's happening with ICE doesn't really scream "citizens' rights" either. I can see why many "trusted foreign partners" would now think twice rather than help out the US compared to just 5 years ago.
As a EU person, I'd really like to not have ties with US when possible, and I'd really like to foster the economy of non-US alternatives.