• Compliance
  • Pricing
  • Features
LoginSignup
  • Compliance
  • Pricing
  • Features
  • GitHub
LoginSignup

Open-source platform for security, compliance, and operations — run on any cloud with no vendor lock-in.

Products

  • Services
  • Features
  • Pricing
  • Compliance
  • Scope of Service

Company

  • About
  • Solutions Brief
  • Careers
  • Blog
  • Why Obmondo
  • Logos

Contact

  • info@obmondo.com
  • sales@obmondo.com
  • Talk to us
  • Contact Us

© 2026 Obmondo. All rights reserved.

Terms & ConditionsUnsubscribeCookie Policy
All Posts
GDPRData SovereigntyCloud StrategyCLOUD ActDigital SovereigntyKubeAid

Why 'Hosted in the EU' Doesn't Mean GDPR Compliant

MW

Mohammad Warid

08 Aug 2026 · 7 min read

Read on

If you've ever had a vendor tell you "don't worry, our EU customers' data is hosted in an EU data center, so you're GDPR compliant," you've heard the most common, most confidently stated, and most wrong sentence in cloud procurement.

It's wrong for a specific, boring, and very well-documented legal reason, and it's about to become relevant again. So let's actually walk through it.


The short version

GDPR compliance for data transfers isn't about where the server sits. It's about who controls the company operating that server, and which government can legally lean on that company. The data on a server in Frankfurt owned or operated by a US corporation legally still falls under US jurisdiction. Twice now, the EU's top court has torn up the paperwork that let US companies handle that data anyway. A third round is already brewing, and this time the EU might not even need a courtroom to pull the plug.


Round one and round two: Safe Harbor and Privacy Shield

This isn't new. It's happened before, twice, and both times for the same underlying reason.

In 2015, the EU's Court of Justice struck down a framework called Safe Harbor — the agreement that had let US companies self-certify they'd protect EU personal data adequately. The court said: not good enough, US surveillance law lets your government access this data in ways EU law wouldn't allow.

The EU and US patched together a replacement called Privacy Shield. In 2020, the court struck that down too, for essentially the same reason. This is the ruling most people mean when they say "Schrems II." It's named after Max Schrems, the Austrian privacy activist and lawyer whose complaints triggered both cases.

The current replacement is called the EU-US Data Privacy Framework (DPF), in force since July 2023. If you're keeping score, this is patch number three on a problem the court has now identified twice.


Why "Schrems III" is not really a joke

The DPF has already been challenged once, by a French member of parliament, and it survived — technically. A French court dismissed the case in September 2025, but the ruling only confirmed the framework was valid based on the facts as they stood back in 2023. That ruling is now under appeal.

Meanwhile, Schrems' organization, noyb, has been circling with a broader challenge of its own — one that goes after the structural foundations of the DPF rather than a narrow technicality. Their argument leans on the same US surveillance law (FISA Section 702) that sank Privacy Shield, plus a new wrinkle: a 2026 US Supreme Court ruling that weakened the independence of the Federal Trade Commission, which happens to be one of the two US bodies the DPF's entire oversight and redress mechanism depends on.

Here's the part that should genuinely worry anyone relying on the DPF: Schrems has said publicly that he might not even need to file that third case. If US oversight independence keeps eroding, the European Commission may end up pausing or killing the deal on its own, without waiting for a court to force its hand.

So the pattern so far is: agreement gets signed, agreement gets challenged, agreement gets torn up, repeat. Betting your compliance posture on "the current agreement is still valid" has a two-for-two track record of aging badly.


The part everyone gets wrong: it was never about the server

Here's the misconception that causes all the confusion. People assume the fix is simple: just make the US cloud provider promise to keep your data on EU soil, in an EU region, maybe even run by "EU staff." Problem solved, right?

No. And this is the actual important detail.

Think of it like a bank vault. It doesn't matter which country the physical vault sits in. What matters is which bank operates it, and which country that bank is chartered in. If the bank is a US bank, a US court can order that bank to open the vault, wherever the vault physically is, because the order isn't directed at the building. It's directed at the bank.

That's exactly how the US CLOUD Act works. The law says a US company must hand over data in its "possession, custody, or control," and it explicitly doesn't matter whether that data is stored inside or outside the United States. Jurisdiction follows the company, not the server rack.

For this not to apply to you, an EU subsidiary would need to be genuinely independent of its US parent: no shared infrastructure, no parent-company access, no contractual control. In practice, that's not how any of the big three hyperscalers structure their EU operations. Their "EU region" entities remain wholly owned and controlled subsidiaries of a US parent company, which means the CLOUD Act reaches them regardless of which country the data center sits in.

This isn't theoretical. In June 2025, Microsoft's own legal counsel in France was asked under oath, in front of the French Senate, whether he could guarantee that French citizens' data would never be handed to US authorities without French approval. His answer: "No, I cannot guarantee that." Not because Microsoft is being difficult. Because legally, he can't promise something the CLOUD Act doesn't let him promise.


Where this leaves "using a US consultancy" too

The same logic applies even if the infrastructure itself isn't the issue. If a US-based consultancy or contractor is given access to EU personal data — even data physically hosted in the EU — that access can itself be enough to bring the CLOUD Act into play. The law reaches whoever has "possession, custody, or control," and control has been read broadly enough to include the practical ability to retrieve or act on the data, not just literal physical storage. Hand a US entity the keys, and you've potentially handed US authorities a legal path to the data too, no matter where the servers physically sit.


So what actually works

Right now, today, a company can technically still rely on the DPF, or on Standard Contractual Clauses with extra safeguards, and be nominally compliant. That's true. But "nominally compliant under an agreement with a track record of getting invalidated" is not the same thing as "durably compliant."

The version of this that doesn't depend on the next court ruling, the next US administration, or the next noyb filing, is straightforward: use a provider that is actually EU-owned and EU-operated, with no US parent company anywhere in the ownership chain, and no US entity holding access to the data. That's the only setup where the company signing your data processing agreement can actually stand behind it, because no foreign law gives a foreign government a back door into the promise.

That's not a workaround or a loophole. It's just removing the one variable — US corporate control — that both Schrems rulings and the CLOUD Act keep coming back to.

This is part of why we built KubeAid, Obmondo's open source GitOps platform for running production Kubernetes, around EU-owned bare-metal providers like Hetzner, OVHcloud, and Scaleway rather than the usual hyperscaler defaults. We started making that case on cost: a self-managed cluster on EU bare metal runs at roughly a tenth of the equivalent managed offering from a major cloud provider. The compliance case turns out to be just as strong — arguably stronger — since these are EU-incorporated companies that can sign a data processing agreement without a US framework's next court date hanging over it.


The takeaway

GDPR compliance for cross-border data was never really a geography question. It's a control question: who owns the company operating your infrastructure, and which government can compel that company to act. Servers in the EU, run by a company that answers to Washington, solve none of that. It took two Court of Justice rulings and one French Senate hearing to make that painfully explicit. A third invalidation — or a Commission-initiated retreat — looks increasingly like a matter of when, not if.


This is a general explainer, not legal advice. If you're making a specific compliance decision, talk to a lawyer who specialises in EU data protection law.


Written by

MW
Mohammad Warid

Continue reading

All posts
Open Source AI: Are You Calling a Cab, Leasing a Car, or Building One in Your Garage?
aiopensourcearchitecture

Open Source AI: Are You Calling a Cab, Leasing a Car, or Building One in Your Garage?

Mohammad Warid·31 Jul 2026·5 min
etcd Disk Latency: The Silent Killer of Control-Plane Stability
kubernetesetcd

etcd Disk Latency: The Silent Killer of Control-Plane Stability

Mohammad Warid·28 Jul 2026·3 min
Kubernetes assumes an infinite datacenter
kubernetescluster apibare metal

Kubernetes assumes an infinite datacenter

Shivam Kumar·28 Jul 2026·13 min
Open Source · Digital Sovereignty

Want us running it instead?

Obmondo manages Linux and Kubernetes for teams anywhere — monitoring, upgrades and compliance on a shared open-source platform, so you collaborate on ISO 27001 and CIS18 instead of doing it alone.