Keeping Your Data in Europe — Why and How
Lees dit in het Nederlands →$ trace --where-is-it --and-under-which-law
Keeping Your Data in Europe — why and how
Our servers are in Germany and Finland and our data doesn't leave there. Except where it does — and that's the interesting part of this post. There are seven vendors that something passes through, and one of them is American. Below we name them, plus the difference between "our servers are in the EU" and "we fall under European law." Those two are not the same.
The question "is my data in Europe" almost always gets an answer that's too short. Usually: "yes, we host in the EU." That's true, and it's not the whole story.
This post answers it for ourselves, with names attached. We're not lawyers and this isn't legal advice — it's how we've set it up and why.
01 / the question behind the questionWhy do you actually want to know this?
Rarely for the geography. Almost always for one of these three:
- Your clients ask about it. Healthcare, education, financial services: it's in the procurement conditions and you just need to be able to answer it.
- You need a data processing agreement and it has to state which parties process your customer data. Then you need a list, not reassurance.
- You want to know who can access your data. That's the real question, and the answer to that isn't "Germany."
That third one is the important one. Where the disk sits is a technical fact. Who's allowed access is a legal fact. They don't automatically line up.
02 / where it sitsWhich server, which country?
Two servers, two countries, one vendor.
The vendor is Hetzner: a German company, with German and Finnish data centers. That's why we can say "in Europe" without an asterisk after it — not only do the servers sit there, the company itself falls under it.
That distinction is the entire point of this post, and it comes back in block 4.
03 / what does cross the borderWhere is it not true?
With seven vendors, and one of them is American. Here they are.
We once tried to write "one subprocessor" on our own site. That wasn't true and it got pulled before it went live. There are eight of them, and a list with names is more useful than a number that a lawyer can knock down with a single question.
A vendor who tells you they have one subprocessor hasn't counted them.
What you can take from this: ask for the list, not for the reassurance. Anyone who processes customer data should have that list on hand.
04 / the difference with "EU region"What are you actually buying when a vendor promises that?
A location. Not necessarily a jurisdiction.
Large providers let you choose to put your data in a European data center. That's real and it helps: it improves speed, and it's often exactly what's asked for in a procurement condition.
But it doesn't answer the third question from block 1. Where the disk sits says nothing about which law applies to the company managing that disk. An American parent company remains an American company, even if the server is in Frankfurt.
We're not lawyers and won't make claims here about how that plays out in a specific case. What we can say: these are two different questions, and a vendor who lumps them together rarely does that by accident.
To be clear: we ourselves use two American services for things that matter. So we're not saying it's not allowed. We're saying you should know what you have.
05 / what you can askFour questions for every vendor — including us
These four separate a real answer from reassurance.
- Give me the list of subprocessors, with name and country. If you get a number instead of a list, it hasn't been counted.
- Under which law does the company itself fall, regardless of where the server sits? This is the question "EU region" doesn't answer.
- In whose name are the accounts you build in? If the answer is "ours," you know enough — then you don't own the data, you just have access to it.
- What can I export tomorrow, and in what format? An answer without a format isn't an answer.
For us, the answer to the third one is: the accounts are in your name. We build inside them, not next to them. There's no environment of ours that your customer data moves into and that we hold the key to. If you stop working with us, the maintenance stops, not your access.
Where are your servers?+
So does nothing cross the border?+
What does "EU region" mean with a large provider? +
How do I check this with my own vendors?+
Is this legal advice?+
Want to know where your customer data actually sits right now?
Book a call
We'll look at where your time is leaking and tell you honestly whether we can do something about it. Often the answer is: you can do this yourself. Then we'll say so, and you'll have spent thirty minutes on a clear answer.
This text was produced with AI assistance and reviewed and approved for publication by a human.