Home›Guides›Sovereignty

Sovereignty

What does “data hosted in Europe” really mean?

“Data hosted in Europe” means that the provider states it stores certain data in datacenters located in Europe. The phrase is true or false depending on the list of data it covers. It does not say which law applies to the company that holds the data.

Updated October 20268 min readOfficial sources cited

Why the phrase deserves a close reading

The statement appears on almost every email and storage offering. It reassures, and that is its commercial purpose. For a senior executive, an IT director or a DPO, it is only a starting point: the record of processing activities, a customer questionnaire or a tender will ask where the data are, but also who accesses them and from where.

An overly broad phrase creates two risks. The first is wrongly declaring that no data leave Europe. The second is believing a question has been settled when it has not: the question of the operator and the law that applies to it. The page protect a business from the CLOUD Act addresses this second point.

Europe, European Union, EFTA, Switzerland

Brochures mix up four scopes.

  • European Union. Twenty-seven states. The GDPR applies there directly.
  • European Economic Area. The Union, plus Iceland, Liechtenstein and Norway.
  • EFTA. Iceland, Liechtenstein, Norway and Switzerland. Microsoft describes its EU Data Boundary as covering the EU and EFTA.
  • Switzerland. A European country outside the European Union. The European Commission has adopted an adequacy decision for Switzerland. The law applicable to a Swiss hosting provider is Swiss law, supplemented by the GDPR when it processes data of individuals located in the Union for a customer established there. Infomaniak hosts in Switzerland. Presenting it as a French or German datacenter would be inaccurate. Presenting it as subject to the CLOUD Act as a US company would be inaccurate too.

These distinctions are not lawyers’ details. A tender that requires hosting “in the European Union” is not necessarily satisfied by an offering that announces “Europe” and includes Switzerland or another EFTA country. Conversely, Swiss hosting may suit a business that has checked the applicable framework. The common mistake is to treat the word “Europe” as an answer, when it calls for a list.

When you read “Europe”, ask for the list of countries.

Which data the phrase covers

An email service produces at least six families of data.

  1. Messages and attachments.
  2. Calendars, contacts and files.
  3. Backups.
  4. Technical logs (who logged in, from where, at what time).
  5. Support data (tickets, copies requested for a diagnosis).
  6. Billing and tenant administration metadata.

Many offerings “hosted in Europe” refer to family 1, sometimes to family 2. Families 3 to 5 are the ones that most often go elsewhere: follow-the-sun support (your requests pass from one team to another around the world according to the time zone), a US ticketing tool, backups with a subcontractor, antivirus software whose signatures or samples leave the area.

These families are not secondary. Logs show who works with whom and at what time. A copy of a mailbox sent to support for a diagnosis contains as much as the mailbox itself. A backup is a second complete copy.

For the services included in the EU Data Boundary, Microsoft documents storage and processing in the EU and EFTA of customer data and pseudonymised personal data, as well as storage at rest of professional services data, with transfers that continue: remote access by staff outside the area for certain incidents, storage outside the area of certain elements of escalated tickets, optional features enabled by the administrator, Multi-Geo customers outside the scope. Google documents data regions for covered content (email, calendar, files, documents, depending on the edition). Google’s documentation specifies that unlisted data, such as certain logs, are not covered by this data region policy.

These two software vendors have one merit: they publish what is covered and what is not. A provider, whatever its nationality, that writes nothing about its backups, logs and support offers no greater guarantees; it simply offers fewer to check.

Reading the list of what is covered takes an hour. That hour is what gives the phrase its meaning.

Example

A 40-person services SME with two branches compares two email offerings. Both announce “data hosted in Europe”. On reading the documentation, the IT director finds that the first covers mailboxes and files, but that the support ticketing tool is hosted outside Europe and that technicians may connect from several continents. The second specifies the country of the mailboxes, backups and logs, and states that support works from the same scope, with a record of every access.

Both phrases were true. Only the second makes it possible to complete the record without approximation. The final choice may still be made on other criteria, such as features or price, but it is made with full knowledge of the facts.

What the phrase does not prove

It does not prove that the operator is European. A US software vendor can host in Ireland.

It does not prove that there are no transfers. An email sent to a correspondent outside Europe leaves Europe because the sender intended it to. An attachment opened in a third-party tool leaves the scope. Finally, if the customer requests a backup copy to its own vault, the location and storage conditions of that copy depend on the location and characteristics of the vault chosen by the customer.

It does not prove who can read. Transport encryption (TLS) protects the journey. Encryption at rest protects a stolen disk. As long as the operator holds the key in order to deliver the service, it can technically access the content. This is the usual framework for an email service, with a US provider as with a European one. What matters then is the access rule, the record, and the law that applies to the operator.

The framework changes when the key is held by the customer, or kept in the customer’s account behind a password the operator does not have: the operator can no longer read the content without an action the customer would notice. This is the choice Klytic has made, described below.

It does not prove reversibility. Data hosted in Marseille that you cannot export remain difficult to leave.

Common mistakes

  • Reading the brochure instead of the documentation. The brochure summarises; the software vendor’s documentation and the contract describe the exact scope.
  • Forgetting optional features. An option enabled by an administrator, such as video conferencing or an external antivirus, can take data outside the announced scope.
  • Confusing location and operator. A datacenter in Frankfurt operated by a company subject to foreign law remains exposed to that law. See European cloud or American cloud.
  • Asking nothing about the exit. The storage location does not help if the export is incomplete or slow.

The questions to ask in writing

These questions should be asked in writing for a simple reason: the answer can be carried over into the contract or the record.

  • Which countries, for messages, files, backups and logs?
  • Can support connect from outside this scope? In which cases?
  • Which subcontractors receive a copy or access?
  • What happens if we enable an optional feature (instant messaging, video conferencing, external antivirus, audience measurement)?
  • Within what time frame and in what format do we recover everything?

The pages GDPR and Microsoft 365 and GDPR and Google Workspace apply these questions to the two most widespread suites. For email alone, see choosing a European business email service.

Frequently asked questions

Does hosting in Switzerland count as hosting in Europe?

Geographically, yes. Legally, Switzerland is not in the European Union, but the Commission has adopted an adequacy decision in its respect. If your contract or a tender requires the European Union, this must be checked before signing.

If my data are in Europe, can I say that none of them leave?

Not without checking. Backups, logs, support tickets and optional features often follow different rules from the mailboxes. Microsoft itself lists transfers that continue despite its EU Data Boundary.

Is a US software vendor that hosts in Europe compliant with the GDPR?

The question is poorly framed. The storage location is only one element; the legal basis for transfers, the subcontractors and support access also matter. Moreover, the location says nothing about the law that applies to the software vendor.

Does encryption settle the question?

It protects the journey and the disk. It does not make the data unreadable to the operator that holds the key. What matters, therefore, is who holds the key, what the contract says about it, and which features the encryption applies to.

Where Klytic stands

When the service is hosted by Klytic for a European customer, the data are hosted in Europe. For a customer in the Mauritius area, the announced hosting is Mauritius or Europe. For other customers, hosting is provided in a geographical area that complies with the applicable jurisdiction, subject to the availability of the required services. The customer can also have the service hosted on its own premises. For telephony, the dedicated server is hosted in a European cloud, in Mauritius or in a geographical area that complies with the applicable jurisdiction, depending on the customer’s request or needs. Backups follow the same operator: every hour for email, documents and CRM, every day for telephony, with 30-day retention.

At Klytic, the encryption key is held by the customer, or kept in the customer’s account. Klytic has no access to it: to obtain it, Klytic would have to destroy or change the account password, which it does not have, and the customer would notice. The stages where encryption is managed by Klytic (filtering quarantine, processing in the CRM, emails when the customer has not enabled its own key) are detailed on the page protect a business from the CLOUD Act. The contract must describe this possession and this encryption. The published details are on the pages hosting and sovereignty and frequently asked questions.

This page describes a general framework. It does not replace an analysis of your contract.

Sources

Accessed in October 2026.

  • Microsoft, definition of the EU Data Boundary and tenant eligibility conditions, including the exclusion of Multi-Geo. Microsoft Learn
  • Microsoft, announced completion of this boundary in February 2025 for customer data, pseudonymised data and technical support data at rest. Microsoft, On the Issues, 26 February 2025
  • Microsoft, transfers that remain: remote access, escalation of certain tickets, optional features. Microsoft Learn
  • Google, data covered by data regions, and exclusion of unlisted types (logs, cache). Google Help
  • Google, choice of United States, Europe or no preference, depending on the edition. Google Help
  • European Commission, adequacy recognised for Switzerland. List of adequacy decisions
  • Klytic, published backup schedule: email, documents and CRM every hour, telephony every day, 30-day retention. Frequently asked questions

A French operator for your data

Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.

Talk to an advisor →

Klytic hosting

Welcome offer

30 days free trial, migration support included

No-commitment trial. An advisor calls you back to understand your needs and prepare your Klytic workspace.