NL EN

Hosting and data

Where does your organisation's data live, and why does it matter?

Mans Ziesel ·

Short answer

It comes down to two things: where your data physically sits, and which law applies to the company that manages it. An American supplier can store your data in a European data centre and still fall under the American CLOUD Act, which can require it to hand data over. To rule that out, choose a supplier that is itself under European law and manages its own hardware.

What do people mean by “where is my data”?

Usually two things at once. The first is the physical place: which country, which data centre, which machine. The second is the law: which company manages that machine, and which laws that company is subject to.

The two do not always line up. A server in Amsterdam can be managed by a company from Seattle. Your data is then in the Netherlands, but an American company controls it.

What does the CLOUD Act do?

The CLOUD Act is an American law from 2018. It requires American providers of online services to hand over data to American law enforcement that has a valid warrant. It makes no difference whether that data is in the United States or elsewhere. The American Department of Justice says so itself: it concerns data the provider has in its possession, custody or control, wherever that data is.

That does not mean American authorities look in your mailbox every day. It means the possibility exists, and your supplier does not get to decide on it.

And the GDPR?

The GDPR (in the Netherlands: AVG) sets the rules for having personal data processed outside the EU. For the United States, the EU-US Data Privacy Framework has applied since 10 July 2023. It is a decision of the European Commission: personal data may go to American companies that have signed up to the framework.

It is the third attempt. The two earlier arrangements, Safe Harbor and Privacy Shield, were struck down by the Court of Justice of the EU. The current framework is valid, but anyone looking further ahead allows for the chance that it will be challenged again.

What about Microsoft 365?

Microsoft has put real work into this. With the EU Data Boundary, completed in February 2025, the data of European customers of Microsoft 365, among others, is stored and processed within the EU and EFTA. Support data has stayed within that boundary since then too.

That solves the first part: the physical place. The second part remains. Microsoft is an American company, and the CLOUD Act is about control, not location. For many organisations that is an acceptable risk. For a law firm, a healthcare provider or a business whose clients ask about it explicitly, sometimes not.

Which questions do you ask your supplier?

These six get you clarity quickly:

  • Which data centre, in which country, is my data in?
  • Who owns the hardware: you, or is it rented from a larger cloud company?
  • Which law applies to the company that manages the data, and to its parent company?
  • Who has access to my data, and how is that recorded?
  • Where are the backups?
  • How do I take my data and configuration with me if I want to leave?

If an American parent company turns up at the third question, you know what the CLOUD Act means for you.

Look at the chain as well. A Dutch hosting company that rents its servers from an American cloud company is in effect putting your data with that American company after all. The name on the invoice then says little about who manages the hardware.

Where is the data with us?

On hardware we own, in a data centre in Hengelo. We rent no capacity from an American cloud company. We are a Dutch company, so there is no parent company outside Europe that could get access to anything.

That is where your servers and websites run under hosting and cloud, and your files, mail and calendar in JevanaHub. Want to know first what makes sense for your organisation? We work that out together under advice. Sometimes the answer is simply Microsoft 365. We set out the difference in Nextcloud or Microsoft 365.

Questions

What is the CLOUD Act?

The CLOUD Act is an American law from 2018. It requires American providers of online services to hand over data to American law enforcement that asks for it with a valid warrant, regardless of whether that data is stored in the United States or elsewhere. It covers data the provider has in its possession, custody or control.

Is data in a European Microsoft data centre safe from the CLOUD Act?

Not entirely. Microsoft stores and processes the data of European Microsoft 365 customers inside the EU, and that is a real commitment. Microsoft is still an American company, though, and the CLOUD Act looks at who controls the data, not at where it sits. How much that risk weighs for your organisation depends on what you store.

Can I store personal data with an American cloud supplier?

Usually, yes. Since July 2023 the EU-US Data Privacy Framework applies, a decision of the European Commission that allows transfers to American companies that have signed up to it. You do need to record it in your record of processing and your data processing agreement. Earlier arrangements of this kind were struck down twice by the European court, so keep an eye on it.

Which questions should I ask my IT supplier about my data?

Ask which data centre your data is in, who owns the hardware, and which law applies to the company that manages it. Ask too who has access to it, where the backups are, and how you take your data and configuration with you if you leave. A good supplier answers those questions without turning it into a meeting with a lawyer.

Where is your data when Jevana hosts it?

On hardware we own, in a data centre in Hengelo. We rent no space from an American cloud company, and there is no foreign supplier between your data and us. We are a Dutch company and fall under Dutch and European law. You can always take your data and configuration with you to another provider.

Tell us what you run.

An introduction costs nothing. You talk straight away to one of the two people who will actually do the work.