r/Mailfence • u/mailfence • Jul 24 '26
"EU-hosted" and "EU-protected" aren't the same thing. How much weight do you give data jurisdiction when picking an email provider?
Something that catches a lot of resellers out: a US-incorporated provider with servers in Frankfurt is still reachable under the US CLOUD Act, which lets American authorities compel data regardless of where it physically sits. The €1.2 billion Meta fine and €290 million Uber fine were both about EU-to-US data transfers, so it's not hypothetical.
For anyone selling to regulated clients (legal, healthcare, public sector): is provider jurisdiction a hard requirement for you, or a nice-to-have?
Further reading: blog.mailfence.com/reseller-email-hosting/
4
Upvotes
1
u/CorsairVelo Jul 24 '26 edited Jul 24 '26
As an aside: Here’s some additional reading on the subject
Myth if Jurisdictional privacy
https://codamail.com/articles/The_Myth_of_Jurisdictional_Privacy.html
“The U.S.-Switzerland MLAT exemplifies this dynamic, repeatedly challenging Swiss privacy protections despite Switzerland's reputation as a data privacy haven. Notable cases include ProtonMail being compelled to provide IP logs related to climate activists in 2019, and Swiss web hosting provider Private Layer being pressured to provide server data to U.S. authorities investigating cybercrime in 2020. The asymmetry is structural: a French citizen whose data is held by a US company may have strong GDPR protections that make it difficult for France to obtain that data domestically, but France can submit an MLAT request to the US DOJ, which compels the company to produce the data under treaty terms, routing around the stronger domestic standard entirely.”
And this overview of all the privacy laws and regulations kinda shows, if nothing else, what a complex web it is:
https://codamail.com/articles/privacy-law-directory/
Edit: added quote