https://www.courthousenews.com/uk-faces-questions-on-complic...
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
Even the entire EU is in the process of negotiating the agreement as well.
https://www.justice.gov/archives/opa/pr/united-states-and-ca...
https://www.justice.gov/archives/opa/pr/justice-department-a...
"Resilient replicas of your data will live in the US"
?
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers.
as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
Not that I don’t trust the statement, I just would like to know more.
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
I_am_tiberius•48m ago
techpression•47m ago
fhdkweig•45m ago
> Built by us, not rented from someone else
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We don’t rent computing or management services from a big cloud provider and pass on their assurances. That’s how we’ve approached privacy, reliability, and performance for more than 25 years.