as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
AWS, Azure, GCP, Oracle, Schwarz Digits, SAP
Not that I don’t trust the statement, I just would like to know more.
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
Anyone who falls for this is a fool wanting to be fooled.
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
Wow, it's nothing. How about writing your PR after the data is not going to the US at all?
At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
I feel that that's the whole point. And the whole point of them making this article/advertisement.
So all of this is pointless.
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
PS: Am a paying customer for like a decade
In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation.
I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US DoJ says “now” or… > Fastmail refuses
Then what?
Aussie law might be even worse than US; I would never use Fastmail.
"Resilient replicas of your data will live in the US"
?