Hacker News new | past | comments | ask | show | jobs | submit

Fastmail offers EU data region

https://www.fastmail.com/blog/fastmail-offers-eu-data-region/
EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.
loading story #49226525
> your data can still be forcibly pulled and often without you being aware that this happened

as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable

That's true but the EU still has a - mostly - functioning legal system. See 'Schrems' and other lawsuits that came out as they should have.
Take a look at how they play with regards to chat control. The EU is just the same corrupt BS like D.C., only with a lot more virtue signaling.
Sorry, I don't agree with that. The amount of corruption in the USA right now is simply off the scale.
loading story #49227832
Not nearly the same thing. Trump and his family have made billions. I cannot say the same of von der Leyen.
loading story #49227131
True, I think the calculus is more about who you think is more trustworthy than what tools they have to damage you.
I am almost positive things are not the way they were and requests for data access especially if the subjects background is "suspect" are more highly scrutinized.

And as the Americans are choosing to interfere in European domestic politics and trample their own laws and constitution the more scrutiny their requests will get.

Especially if European companies have an office and significant share of customers in the US.
For anyone curious, it's the CLOUD act:

> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.

[1] https://en.wikipedia.org/wiki/CLOUD_Act

The point of control is Congress, until we stop electing corpratist politicians, we will continue to get bad legislation.
It doesn't matter if it's Congress. At the end of the day America's internal governance systems are America's problem. The rest of the world should not care if a certain branch is causing issues, and frankly, is starting to come to that conclusion.

It's unfortunate for us, but we very rarely isolate individual government systems for other nations.

Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
They're Australian
Australian companies are also subject to the USA Cloud Act. As is the UK, with Canada coming on board soon too.

Even the entire EU is in the process of negotiating the same agreement.

https://www.justice.gov/archives/opa/pr/united-states-and-ca...

https://www.justice.gov/archives/opa/pr/justice-department-a...

That is plain wrong, and on top of that, the CLOUD act doesn't really solve anything because if the order to obtain data is legal for the US arm but illegal for the EU arm, releasing the data from say Ireland to the US would immediately lead to steep monetary and legal penalties for the EU arm.
It is not wrong...

You can read the text right here:

https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...

The same agreement is in place with the UK. Canada and EU are currently in the process of negotiating it.

Your linked information doesn't indicate anywhere that Australia or any other foreign government is subject to US law. The latter states that negotiation with the EU on this topic was suspended in 2019.

Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty.

https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...

> The latter states that negotiation with the EU on this topic was suspended in 2019.

Dated 2023:

> Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations

The negotiations are still ongoing. Canada is further along than the EU.

That’s not going to help anyone.

The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence.

https://en.wikipedia.org/wiki/Five_Eyes

Even being stored in EU doesn't preclude your data from being targeted by signals intelligence. Which is different than requiring US based companies to provide non-US data to American government.

Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.

isn't there this five eyes thingy?
Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:

- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.

- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.

Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.

EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US.

AWS, Azure, GCP, Oracle, Schwarz Digits, SAP

Requiring that you believe those companies that they won’t hand the keys over to the US at the first ask.

Like, the critical problem with the AWS sovereign pitch is that you must believe that they won’t give the keys to the US, and they also won’t give the source code that’s hosted in the US to the government either for them to find vulnerabilities in. I don’t know if that’s good enough unless you just need the data to stay in the EU and you don’t care if another country sees it.

I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I don’t know if they explained how they’re safe to the public.

The harder problem here is that any real EU sovereign platform would have to come with ironclad guarantees that it isn't going to be directly or indirectly sold to a US party. And when enough customers move that marketshare is affected the bags with money tempting shareholders will get larger and larger.
You can strike at least four of those.
> AWS, Azure, GCP, Oracle

What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.

Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?
> Take Hetzner as an example.

Similar happened already with OVH Canada vs France.

> In an affidavit, Xavier Barriere, corporate counsel at OVH in Paris, describes the dramatic situation: If the important proponent of European data sovereignty were to comply with the Canadian order, those responsible in France would be committing a criminal offense. They face up to six months in prison and fines of up to 90,000 euros per violation. However, if OVH ignores the Canadian court, it faces contempt of court proceedings in Ontario, which can also lead to severe sanctions.

https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-Fr...

And one comment here: https://news.ycombinator.com/item?id=46060903

Well, for sure they can pressure them but I highly doubt Hetzner would break the law in Europe to satisfy the US government, they are a lot more to lose here than there. I realize that that is not proof.
Can you point me towards some resources that show EU customers moving?

Not that I don’t trust the statement, I just would like to know more.

I hope Airbus is large enough for you?

https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cl...

And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right.

HN Search: airbus critical apps scaleway - https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments)

Netherlands reaches deal with European cloud company to decrease U.S. tech reliance - https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ... - April 24th, 2026

Wary of US Big Tech, the EU looks to build its “EuroStack” - https://sherwood.news/world/wary-of-us-big-tech-the-eu-looks... - March 18th, 2026

Why European Companies Are Leaving US Cloud Providers in 2026 — And Where They're Going - https://massivegrid.com/blog/european-companies-leaving-us-c... - March 12th, 2026

Europe gets serious about cutting digital umbilical cord with Uncle Sam's big tech - https://www.theregister.com/off-prem/2025/12/22/europe-gets-... - December 22nd, 2025

Schleswig-Holstein waves auf Wiedersehen to Microsoft stack - https://www.theregister.com/software/2025/10/15/schleswig-ho... - October 15th, 2025

EU Banks Launch Wero Payments to Dislodge Visa, Mastercard - https://news.ycombinator.com/item?id=41666833 - September 2024 (88 comments)

https://european-alternatives.eu/

https://euro-stack.com/

US Cloud soon illegal? Trump punches first hole in EU-US Data Deal - https://noyb.eu/en/us-cloud-soon-illegal-trump-punches-first... (2025-01)

EU-US Data Transfers: First Reaction on "Latombe" Case - https://noyb.eu/en/eu-us-data-transfers-first-reaction-latom... (2025-09)

EU-US Data Transfers: Time to prepare for more trouble to come - https://noyb.eu/en/eu-us-data-transfers-time-prepare-more-tr... (2025-12)

US Supreme Court just blew up EU-US Data Transfers - https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-tra... (2026-06)

Ok, but Fastmail is an Australian company based in Melbourne.
Australia and the US entered into a bilateral agreement in 2024 which made Australian companies subject to the US CLOUD Act.

https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...

As a FastMail customer who spends a portion of the year in the US, I am happy to pay to move my data to the EU region, even if they cannot yet fully guarantee all my data will remain outside of US access at this time. Defense and mitigations in depth, over time. We must always start somewhere, and perfect is never the target (as it does not exist).
Agree - small steps always positive here
But whose cloud infrastructure do they use? (I don't know, but it might likely be AWS, GCP, or Azure.)
That it described in the linked post:

We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers.

None. It's racked and stacked old school
The French head of Microsoft ctor not, under oath, say that Microsoft can guarantee sovereignty. This is the evidence that until you have a EU company, under EU rules and not present in the US at all, you cannot have sovereignty.
pCloud is an example.

Swiss corporation with data centers in Luxembourg.

How does Apple handle it?
Why would apple care? Eu is what a quarter of their business? And where exactly will those people move? They're locked into the Apple infra.
Fastmail is an Australian company
And hosted on US infrastructure, satisfying the "or" clause in their post
The article says they installed their own servers, though. What am I missing here?
That’s true and Fastmail runs on AWS. But it’s a start and a “feature” many have requested for years. It’s funny because the HQ and I believe their workforce is located in Australia.
Not only is that not true, but in fact FastMail predates AWS by some years.

Source: I founded FastMail.

Great username :-) I'm a happy longtime Fastmail customer and I'm migrating to the new EU area.
Fastmail has never used AWS, and this article is pretty clear about how they have always used their own hardware and traditional colocation.

Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now.

That’s interesting, I thought they were hosted on AWS. Thanks for sharing.
But how is it actually "a start" or improves anything at all? It doesnt matter where the "physical location" of the data is. It matters who has access to it.
Fastmail runs on its own infra.
EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data region” to mean “for privacy” here until reading the article is completely understandable; I empathize, having done the same.
loading story #49228035
Posted on the previous submission for this: it’s a good start, but from the article:

If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.

loading story #49224045
loading story #49224788
Or you can just use any of the actual European companies (I’m using Tuta).

https://european-alternatives.eu/category/email-providers

loading story #49226144
Nice, as a European customer, I appreciate this.

Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.

loading story #49228207
Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.

The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which

"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.

If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."

As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.

loading story #49224729
loading story #49227136
loading story #49226830
The article states that they do not offer any guarantee that my data will stay in the EU!

I feel that that's the whole point. And the whole point of them making this article/advertisement.

loading story #49224625
Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
loading story #49224042
loading story #49224247
loading story #49226955
loading story #49227827
As long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Act—and non-U.S. citizens have absolutely no legal recourse when it comes to U.S. services
loading story #49226065
{"deleted":true,"id":49223950,"parent":49223082,"time":1786210631,"type":"comment"}
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.

Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)

Depends on the definition and your threat model but to make a very large story short; it’s email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and that’s the highest level of security you can realistically achieve.

If that works fine if not, use another method of comm. Email wasn’t designed to be secure.

Thank you. Sure. In Europe the "euro stack" approach becomes more and more relevant. So, the issue is more a compliance topic in the way of making use of service provides, who are best-case "eu-headquartered", but at least with a guarantee that processing on my side stays within the european realm. Doesn't mean very little in a technical understanding of security, I agree.
{"deleted":true,"id":49224407,"parent":49224342,"time":1786213296,"type":"comment"}
I do not know any EU-only, but ProtonMail is in Switzerland.
Proton is leaving Switzerland because of surveillance and privacy issues.

> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland.

https://proton.me/blog/lumo-ai

They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.

https://www.justice.gov/archives/opa/pr/justice-department-a...

That was 2023 before the 2nd Trump Admin and before the Privacy and Civil Liberties Oversight Board that was supposed to be independent and protect against abuse has resigned.
Can't wait to verify my age before reading emails!

In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.

PS: Am a paying customer for like a decade

Jurisdiction is an outdated way of looking at things. End-to-end encryption is what actually matters. Of course, people are stupid, so it continues.
I have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
loading story #49224489
As a customer, thank you, Fastmail. I recall reading a few months back that this was rumored to be in the works, glad it panned out.
As a European and Fastmail user, this is great news.
Finally! I have been asking for this since the US started to lose its mind. Great they are listening.
loading story #49225269
Secondary copy not in EU. So how exactly does that help with compliance?
loading story #49225871
And which company hosts the data? An American company like Aws, Azure, Google or a European company like OVH, Stackit?
loading story #49223958
loading story #49223930
Not more safe. Only safe way is to use a company not under US regulation.
Does it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.
Okay, that solves two problems for me. Great news.
We offer EU data centers for customers that want their emails to stay in the EU but

"Resilient replicas of your data will live in the US"

?

loading story #49224338
To me, jurisdiction matters more than physical location. I'd rather be with a EU-operated service that stores data on a non-EU server, than a non-EU operator with a German/french datacenter.
Data is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.
Totally irrelevant because of the CLOUD Act.

Aussie law might be even worse than US; I would never use Fastmail.

using cirrux.me and very happy with an actual EU hosted option (Team is Dutch)
[flagged]
loading story #49224369
loading story #49224347
EU data regions are based on the insanely flawed idea that data is:

* a physical thing that can only live in one place

* not copyable

* can be 'contained'.

The whole thing reeks of bureaucratic 'best practices' that just aren't.

Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.

Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.

Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.

Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.

loading story #49224971