back
295 comments
EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.
True. Australia is part of the Five Eyes alliance. Fastmail is an Australian company. Australia also has the Assistance and Access Act - https://havenmessenger.com/blog/posts/australia-assistance-a... - which just stops shy of asking Australian tech companies, like Fastmail, to build backdoors into their products so that the government can "legally access" data from them. (When the law passed, Fastmail lost many clients - https://www.itnews.com.au/news/fastmail-loses-customers-face... ).
> your data can still be forcibly pulled and often without you being aware that this happened

as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable

For anyone curious, it's the CLOUD act:

> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.

[1] https://en.wikipedia.org/wiki/CLOUD_Act

Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:

- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.

- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.

Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.

EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US.

AWS, Azure, GCP, Oracle, Schwarz Digits, SAP

The French head of Microsoft ctor not, under oath, say that Microsoft can guarantee sovereignty. This is the evidence that until you have a EU company, under EU rules and not present in the US at all, you cannot have sovereignty.
Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?
Can you point me towards some resources that show EU customers moving?

Not that I don’t trust the statement, I just would like to know more.

Ok, but Fastmail is an Australian company based in Melbourne.
EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data region” to mean “for privacy” here until reading the article is completely understandable; I empathize, having done the same.
Posted on the previous submission for this: it’s a good start, but from the article:

If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.

Or you can just use any of the actual European companies (I’m using Tuta).

https://european-alternatives.eu/category/email-providers

Nice, as a European customer, I appreciate this.

Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.

I call this "sovereignty washing": American companies pretending they can magically free themselves from the U.S. CLOUD Act by setting up a paper European presence.

Anyone who falls for this is a fool wanting to be fooled.

Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.

The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which

"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.

If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."

As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.

Does it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.
> Resilient replicas of your data will live in the US (for now). As we only have one location in Europe so far, the geographically separate copy will remain on servers in one of our US locations.

Wow, it's nothing. How about writing your PR after the data is not going to the US at all?

Unfortunately, even if all data lives in the European Union, as long as a company is conducting business in the US, the Cloud Act makes it possible to compel them to hand over any information. This can include making administrative personnel sign NDAs or face heavy repercussions. Conducting business in the US includes advertising to US citizens e.g through maintaining a website in English.

At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.

The local government cannot get access to the servers in Amsterdam?

I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.

As long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Act—and non-U.S. citizens have absolutely no legal recourse when it comes to U.S. services
Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.

Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)

Actually thrilled that I can choose US data residency. Apparently, it was always that way? Happy that I can choose it though as I would prefer my data not be stored somewhere else.
Australian company so: lol. Snowden triggered a few narrow real wins but the broader surveillance apparatus adapted, survived, and in some ways grew. Things were just legalised.
The article states that they do not offer any guarantee that my data will stay in the EU!

I feel that that's the whole point. And the whole point of them making this article/advertisement.

As a customer, thank you, Fastmail. I recall reading a few months back that this was rumored to be in the works, glad it panned out.
> Emergency backups for everybody are stored in our Philadelphia location. As well as the live replicas of your data, we also keep a separate set of encrypted backups taken every few hours for every account. These are in Philadelphia for all users at the moment.

So all of this is pointless.

Finally! I have been asking for this since the US started to lose its mind. Great they are listening.
Can't wait to verify my age before reading emails!

In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.

PS: Am a paying customer for like a decade

Its not only a question of five eyes access. There is also the concern of being subject to the whims of a regime that might decide you shouldn't have access to services hosted in their country.
To me, jurisdiction matters more than physical location. I'd rather be with a EU-operated service that stores data on a non-EU server, than a non-EU operator with a German/french datacenter.
I have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
Data is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.
Jurisdiction is an outdated way of looking at things. End-to-end encryption is what actually matters. Of course, people are stupid, so it continues.
This may not have much practical consequence, but still there's some symbolic value which is welcomed in today's geopolitical climate.
As a European and Fastmail user, this is great news.
And which company hosts the data? An American company like Aws, Azure, Google or a European company like OVH, Stackit?
using cirrux.me and very happy with an actual EU hosted option (Team is Dutch)
Not more safe. Only safe way is to use a company not under US regulation.
Secondary copy not in EU. So how exactly does that help with compliance?
Okay, that solves two problems for me. Great news.
Useless. US companies have to get EU citizen's data on request. They can and must do so. Only non-US companies can ignore US data requests.
Maybe it’s a silly question, but how much of those “EU Region” makeups that were seeing are enforceable in reality?

In extreme cases the US DoJ can reach, let’s say the CEO/CTO arrest them or pick up family members in case of some sort of non-compliance in some criminal investigation.

I can imagine something like > US DoJ has some PoI with some account in Fastmail “EU region” > Fastmail says “sorry we’re GDPR” > US DoJ says “now” or… > Fastmail refuses

Then what?

Totally irrelevant because of the CLOUD Act.

Aussie law might be even worse than US; I would never use Fastmail.

We offer EU data centers for customers that want their emails to stay in the EU but

"Resilient replicas of your data will live in the US"

?