EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.
> your data can still be forcibly pulled and often without you being aware that this happened
as a german i feel the urge to point out that this technically also applies to european companies...
With more hurdles for the US, but still technically applicable
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
Which wouldn't matter where the data is located, so I don't think that this is the reason Fastmail is doing it, because a savvy enough company would know that the problem is that the company is US based.
Yeah, this does absolutely not solve the CLOUD Act issues. However, it is good to look at what the ramifications of the CLOUD Act is for e-mail:
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
That’s true and Fastmail runs on AWS. But it’s a start and a “feature” many have requested for years. It’s funny because the HQ and I believe their workforce is located in Australia.
And as a FastMail customer who spends a portion of the year in the US, I am happy to pay to move my data to the EU region, even if they cannot yet fully guarantee all my data will remain outside of US access at this time. Defense and mitigations in depth, over time. We must always start somewhere, and perfect is never the target (as it does not exist).
Can't wait to verify my age before reading emails!
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
Posted on the previous submission for this: it’s a good start, but from the article:
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data region” to mean “for privacy” here until reading the article is completely understandable; I empathize, having done the same.
I have never understood their 50+10 GB storage as the starting plan. Anyone storing a lot of emails, please don't come at me screaming, but know that not everyone keeps every email and every attachment ever received right there in that email account (especially the attachments). For me, email is just communication i.e timed information, not data storage, except for very personal emails, and very very rare, some non-personal important emails. So some people do like to simply delete the emails they no longer need. Also their pricing almost feels like "unlimited storage" backup solutions mass pricing strategy.
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
Depends on the definition and your threat model but to make a very large story short; it’s email, others have copies (your gmail friends?). Metadata is public by default the body can be encrypted and encrypted at rest (comes with many limitations) and that’s the highest level of security you can realistically achieve.
If that works fine if not, use another method of comm. Email wasn’t designed to be secure.
Thank you. Sure. In Europe the "euro stack" approach becomes more and more relevant. So, the issue is more a compliance topic in the way of making use of service provides, who are best-case "eu-headquartered", but at least with a guarantee that processing on my side stays within the european realm. Doesn't mean very little in a technical understanding of security, I agree.
Proton is leaving Switzerland because of surveillance and privacy issues.
> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland.
They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.
Five Eyes country are subject to local data disclosure orders and gag clauses, forcing them to hand over user data that may then enter the shared intelligence pool
The flagged/dead comment contains a copy of the entire page, but the relevant part is:
> Built by us, not rented from someone else
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We don’t rent computing or management services from a big cloud provider and pass on their assurances. That’s how we’ve approached privacy, reliability, and performance for more than 25 years.
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
The US data replicas will be resilient, and when the FBI asks your data to reveal things about itself, your data will refuse to reveal anything about itself in the characteristic resilient manner. That's why the mention of "resilient".
Data is still compellable through US Cloud Act (and other provisions). If you want true EU data region, you should buy from a company without presence in the US.
You mean Chat Control 1.0 that was already in place from 2021 to April 2026 and allows for voluntary scanning for CSAM in unecrypted data through hash-matching for existing and indexed CSAM material?
Chat Control 1.0 is a permanent extension of a temporary law that already existed a year ago, allowing the companies to scan your messages if they want to. Nothing changed since then.
as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
[1] https://en.wikipedia.org/wiki/CLOUD_Act
Even the entire EU is in the process of negotiating the agreement.
https://www.justice.gov/archives/opa/pr/united-states-and-ca...
https://www.justice.gov/archives/opa/pr/justice-department-a...
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
Not that I don’t trust the statement, I just would like to know more.
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers.
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
PS: Am a paying customer for like a decade
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
I feel that that's the whole point. And the whole point of them making this article/advertisement.
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
If that works fine if not, use another method of comm. Email wasn’t designed to be secure.
> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland.
https://proton.me/blog/lumo-ai
They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.
https://www.justice.gov/archives/opa/pr/justice-department-a...
https://www.courthousenews.com/uk-faces-questions-on-complic...
> Built by us, not rented from someone else
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We don’t rent computing or management services from a big cloud provider and pass on their assurances. That’s how we’ve approached privacy, reliability, and performance for more than 25 years.
"Resilient replicas of your data will live in the US"
?
I think "resilient" just means "backup copy" and I do think (IANAL) it is illegal to destroy emails when asked for them in the US.
Or was your comment ironic? Sorry, German, irony impaired.