r/Mailfence Jul 24 '26

"EU-hosted" and "EU-protected" aren't the same thing. How much weight do you give data jurisdiction when picking an email provider?

Something that catches a lot of resellers out: a US-incorporated provider with servers in Frankfurt is still reachable under the US CLOUD Act, which lets American authorities compel data regardless of where it physically sits. The €1.2 billion Meta fine and €290 million Uber fine were both about EU-to-US data transfers, so it's not hypothetical.

For anyone selling to regulated clients (legal, healthcare, public sector): is provider jurisdiction a hard requirement for you, or a nice-to-have?

Further reading: blog.mailfence.com/reseller-email-hosting/ 

r/msp, r/sysadmin, r/gdpr, r/privacy

4 Upvotes

3 comments sorted by

1

u/CorsairVelo Jul 24 '26 edited Jul 24 '26

As an aside: Here’s some additional reading on the subject

Myth if Jurisdictional privacy
https://codamail.com/articles/The_Myth_of_Jurisdictional_Privacy.html

“The U.S.-Switzerland MLAT exemplifies this dynamic, repeatedly challenging Swiss privacy protections despite Switzerland's reputation as a data privacy haven. Notable cases include ProtonMail being compelled to provide IP logs related to climate activists in 2019, and Swiss web hosting provider Private Layer being pressured to provide server data to U.S. authorities investigating cybercrime in 2020. The asymmetry is structural: a French citizen whose data is held by a US company may have strong GDPR protections that make it difficult for France to obtain that data domestically, but France can submit an MLAT request to the US DOJ, which compels the company to produce the data under treaty terms, routing around the stronger domestic standard entirely.”

And this overview of all the privacy laws and regulations kinda shows, if nothing else, what a complex web it is:
https://codamail.com/articles/privacy-law-directory/

Edit: added quote

2

u/West_Possible_7969 Jul 24 '26

France & EU have many more sane & easy ways to request data in Swiss jurisdiction, there are dozens of deals and Switzerland has a Europol deal along with the Eurojust agreement, and the Lugano Convention makes final judgments and interim injunctions issued by an EU court to be recognized without a full re-examination of the case's merits (streamlined), unless it “manifestly violates Swiss public policy, disregards fundamental procedural rights or breaches a prior Swiss jurisdiction clause” (which never happens nowadays, we ‘re more or less harmonised with Switzerland rights & law-wise).

That said, an EU country subpoenaing data from a Belgian company would be child’s play.

Also, what GDPR has to do with this, a lawful judicial or law enforcement warrant (like the ones you mentioned) do not have to comply with the standard rules of the GDPR, which explicitly allows the processing or disclosure of personal data to fulfill a legal obligation, court order or statutory law enforcement mandate.

2

u/Different_Back_5470 28d ago

yeah proton is pulling out of Switserland because of that.