Hosting and data
Where does your organisation's data live, and why does it matter?
Short answer
It comes down to two things: where your data physically sits, and which law applies to the company that manages it. An American supplier can store your data in a European data centre and still fall under the American CLOUD Act, which can require it to hand data over. To rule that out, choose a supplier that is itself under European law and manages its own hardware.
What do people mean by “where is my data”?
Usually two things at once. The first is the physical place: which country, which data centre, which machine. The second is the law: which company manages that machine, and which laws that company is subject to.
The two do not always line up. A server in Amsterdam can be managed by a company from Seattle. Your data is then in the Netherlands, but an American company controls it.
What does the CLOUD Act do?
The CLOUD Act is an American law from 2018. It requires American providers of online services to hand over data to American law enforcement that has a valid warrant. It makes no difference whether that data is in the United States or elsewhere. The American Department of Justice says so itself: it concerns data the provider has in its possession, custody or control, wherever that data is.
That does not mean American authorities look in your mailbox every day. It means the possibility exists, and your supplier does not get to decide on it.
And the GDPR?
The GDPR (in the Netherlands: AVG) sets the rules for having personal data processed outside the EU. For the United States, the EU-US Data Privacy Framework has applied since 10 July 2023. It is a decision of the European Commission: personal data may go to American companies that have signed up to the framework.
It is the third attempt. The two earlier arrangements, Safe Harbor and Privacy Shield, were struck down by the Court of Justice of the EU. The current framework is valid, but anyone looking further ahead allows for the chance that it will be challenged again.
What about Microsoft 365?
Microsoft has put real work into this. With the EU Data Boundary, completed in February 2025, the data of European customers of Microsoft 365, among others, is stored and processed within the EU and EFTA. Support data has stayed within that boundary since then too.
That solves the first part: the physical place. The second part remains. Microsoft is an American company, and the CLOUD Act is about control, not location. For many organisations that is an acceptable risk. For a law firm, a healthcare provider or a business whose clients ask about it explicitly, sometimes not.
Which questions do you ask your supplier?
These six get you clarity quickly:
- Which data centre, in which country, is my data in?
- Who owns the hardware: you, or is it rented from a larger cloud company?
- Which law applies to the company that manages the data, and to its parent company?
- Who has access to my data, and how is that recorded?
- Where are the backups?
- How do I take my data and configuration with me if I want to leave?
If an American parent company turns up at the third question, you know what the CLOUD Act means for you.
Look at the chain as well. A Dutch hosting company that rents its servers from an American cloud company is in effect putting your data with that American company after all. The name on the invoice then says little about who manages the hardware.
Where is the data with us?
On hardware we own, in a data centre in Hengelo. We rent no capacity from an American cloud company. We are a Dutch company, so there is no parent company outside Europe that could get access to anything.
That is where your servers and websites run under hosting and cloud, and your files, mail and calendar in JevanaHub. Want to know first what makes sense for your organisation? We work that out together under advice. Sometimes the answer is simply Microsoft 365. We set out the difference in Nextcloud or Microsoft 365.