A genuine European alternative is EU or EEA headquartered, majority European-owned, and running on infrastructure it controls in that territory. That combination is what puts a provider outside the reach of US extraterritorial law.
The common substitute — EU data residency from a US-owned provider — does not achieve this. The US CLOUD Act reaches data held by US companies regardless of where it is stored, so a Frankfurt data centre operated by a US parent is a latency improvement, not a jurisdictional one.
None of this means you are currently breaking the law. It means you are relying on an adequacy decision whose two predecessors were both annulled.
Why this became a live question
For a decade, "where is the data hosted" was a procurement checkbox. Three things turned it into a board-level topic.
The legal ground kept moving. Safe Harbour was struck down in 2015. Privacy Shield was struck down in 2020. The EU-US Data Privacy Framework replaced it in 2023 and is now itself under appeal. Anyone who built on the first two and had to rebuild twice has learned to discount the third.
The hyperscalers responded with residency, not sovereignty. Microsoft completed its EU Data Boundary in February 2025. AWS launched its European Sovereign Cloud with a first region in Brandenburg, generally available in January 2026, backed by a stated €7.8 billion investment. These are serious engineering efforts. They do not change who owns the parent company.
European procurement started voting with money. Scaleway took part of a €180 million EU sovereign cloud tender in April 2026. Germany's federal government built openDesk, an open-source workplace suite, on Nextcloud, OnlyOffice, Jitsi and Matrix rather than licensing an American one.
The three tiers of "European"
Almost every argument about EU alternatives is really a disagreement about which of these three a product belongs to.
| Tier | What it means | US legal exposure | Transfer mechanism needed |
|---|---|---|---|
| 1. EU sovereign | EU/EEA headquartered, European-owned, EU infrastructure | None | None — not a transfer |
| 2. Adequate third country | Swiss or UK provider under an adequacy decision | None directly | None — adequacy covers it |
| 3. EU residency, US parent | US-owned provider storing data in the EU | CLOUD Act applies | DPF certification or SCCs |
Tier 2 deserves a note, because vendor marketing blurs it constantly. Switzerland and the UK are not in the EU. They hold adequacy decisions, which means personal data can flow to them without standard contractual clauses — genuinely convenient. But they are separate legal regimes with their own regulators, and adequacy is reviewed and can lapse. The UK's decisions were renewed on 19 December 2025 and carry a sunset clause running to 27 December 2031.
So Proton and Infomaniak (both Swiss) are excellent privacy-respecting products, and they are not EU providers. That distinction rarely changes a small business's decision, but stating it wrongly in a data protection impact assessment is the kind of error a regulator notices.
The CLOUD Act problem
The Clarifying Lawful Overseas Use of Data Act, passed in 2018, allows US authorities to compel a US-based provider to hand over data in its possession, custody or control — wherever in the world that data physically sits.
That single phrase is the whole argument. It means:
- A US company's German data centre is still reachable by a US warrant served in America
- Contractual promises about data location do not override a statutory obligation on the parent
- "EU Data Boundary" and "sovereign cloud" branding addresses residency and operational control, not corporate jurisdiction
Where the Data Privacy Framework stands
As of September 2026, the EU-US Data Privacy Framework is valid and in force. Transfers to DPF-certified US companies are lawful and need no additional mechanism.
The history is why people hedge anyway:
In September 2025 the EU General Court dismissed French MP Philippe Latombe's action to annul the adequacy decision, finding the US Data Protection Review Court sufficiently independent and US bulk collection limits adequate. He appealed to the Court of Justice in October 2025. That appeal has not been decided.
Two things are worth noting about the first-instance judgment. It assessed the situation as it stood when the Commission adopted the decision in 2023, not as it stands now. And the court that will hear the appeal is the same one that annulled both predecessors.
Category map: what to replace with what
Ordered by how easy the switch is, not by how much noise the category gets.
| Category | Typical US incumbent | European options | Switching difficulty |
|---|---|---|---|
| Web analytics | Google Analytics | Plausible (EE), Matomo (DE/NZ), Fathom | Very low |
| Consent management | OneTrust | iubenda (IT), Usercentrics (DE), Cookiebot (DK) | Very low |
| Email marketing | Mailchimp | Brevo (FR), MailerLite (LT), CleverReach (DE) | Low |
| Business VPN / access | Cisco, Zscaler | NordLayer (LT) | Low |
| Email & office suite | Google Workspace, Microsoft 365 | Nextcloud (DE), Infomaniak (CH), openDesk (DE) | Medium to high |
| Cloud infrastructure | AWS, Azure, GCP | Hetzner (DE), OVHcloud (FR), Scaleway (FR) | High |
Each of these has its own guide:
Which switches are actually worth making
The honest ranking, by compliance gain divided by effort.
1. Analytics — the clearest win
Moving from Google Analytics to a cookie-free European analytics tool removes a US transfer, removes a consent category, and can remove the need for a cookie banner altogether if it is your only non-essential tracker. An afternoon's work for a structural improvement. We cover the options in Google Analytics alternatives.
2. Consent management — often already done
This is the category nobody realises is already European. iubenda is Italian, Usercentrics is German, Cookiebot is Danish, Complianz is Dutch. If you are running one of these you have already made the switch without framing it that way.
3. Email marketing — low friction, real data
Your mailing list is a genuine pile of personal data, and the platforms are close substitutes. Brevo, MailerLite and CleverReach are all mature EU products. Exporting and importing a list is an afternoon; the hard part is rebuilding automations.
4. Everything else — think harder
Cloud infrastructure and office suites are where the sovereignty argument is strongest in principle and weakest in practice for a small company. The migration is measured in weeks or months, the feature gaps are real, and you will spend the savings on engineering time. Worth doing when you are already changing providers, rarely worth doing purely for compliance.
When not to switch
Cases where staying put is the correct answer:
- You process no personal data in that system. Sovereignty arguments apply to personal data. Your CI runner does not need to be European because it compiles code.
- The European option is materially worse at the job. A compliance improvement that costs you customers is a bad trade. Be honest about feature gaps rather than talking yourself into them.
- You would be swapping one dependency for a less stable one. A small European vendor that might not exist in three years carries its own risk, including to data availability.
- The migration would consume the budget for fixes that matter more. A working consent banner and an accurate privacy policy prevent far more enforcement risk than your hosting provider's flag. See what actually gets fined.
- You are mid-migration on something else. Sequence matters. Two simultaneous platform moves is how outages happen.
A sensible order of operations
- Inventory before you migrate List every system holding personal data, its provider, the provider's headquarters, and where the data sits. Most businesses find a surprise or two. This doubles as your Article 30 record.
- Sort by tier, not by vibe Mark each vendor as tier 1, 2 or 3 using the table above. Tier 3 entries are your actual transfer exposure — everything else is noise.
- Fix the cheap ones first Analytics, consent, email marketing. Days of work, immediate reduction in transfer surface, no dependency on a legal outcome.
- Write down the contingency for the rest For each remaining tier 3 vendor, note what you would do if the DPF fell. Often the answer is "sign SCCs and run a transfer impact assessment" — which is fine, as long as it is written down before you need it.
- Revisit when something changes A CJEU ruling, a vendor acquisition, or a new processing activity. Not on a calendar reminder nobody honours.
Cookie-free analytics
It is the one switch that removes a US transfer, deletes a consent category and can retire your cookie banner entirely — in an afternoon. Plausible is Estonian and EU-hosted. We use it on this site and earn nothing from recommending it.
Frequently asked questions
What counts as a European tech alternative?
In the strictest sense, a provider that is headquartered and majority-owned in the EU or EEA and processes data on infrastructure it controls in that territory. A weaker version — EU data residency from a US-owned provider — still leaves the provider subject to US law such as the CLOUD Act. Swiss and UK providers sit in a third category: outside the EU, but covered by adequacy decisions, so transfers to them need no extra mechanism.
Is using a US cloud provider a GDPR violation?
No. Transfers to US companies certified under the EU-US Data Privacy Framework are lawful, and the framework remains in force. The risk is not that you are breaking the law today — it is that the adequacy decision could be struck down, as its two predecessors were, leaving you to find a new legal basis at short notice.
Does the CLOUD Act apply if my data is stored in Europe?
Yes. The US CLOUD Act reaches data in the possession, custody or control of a US-based provider regardless of where that data is physically stored. This is why EU data residency from a US-owned company is not the same as sovereignty — the German data centre does not put the data beyond the reach of a US warrant served on the parent.
Is the EU-US Data Privacy Framework still valid in 2026?
Yes. The EU General Court dismissed a challenge to it in September 2025, upholding the European Commission's adequacy decision. An appeal is pending before the Court of Justice and has not been decided. Both previous transatlantic frameworks, Safe Harbour and Privacy Shield, were ultimately annulled by that same court.
Are Swiss and UK providers European for GDPR purposes?
For transfer purposes, effectively yes. Both Switzerland and the United Kingdom hold European Commission adequacy decisions, so personal data can flow to them without standard contractual clauses. They are not EU member states, they have their own regulators and legal regimes, and their adequacy is periodically reviewed — the UK's decisions were renewed in December 2025 with a sunset clause running to December 2031.
Should a small business switch to European providers?
Selectively. Switching analytics and email marketing is usually cheap, quick and removes real compliance work. Migrating cloud infrastructure or a whole office suite is expensive and disruptive, and for most small businesses the compliance benefit does not justify it on its own. Change the things where the switching cost is low and the compliance gain is concrete.
Does switching to European providers remove my cookie banner?
Only if it removes the non-essential cookies. A banner is required because of what you store on the visitor's device, not because of where the vendor is incorporated. A European analytics tool that sets no cookies removes the requirement; a European ad platform that sets tracking cookies does not. See do I need a cookie banner?