Live data from Hacker News

Fastmail offers EU data region

fastmail.com

131–140 of 302 posts

Re: Fastmail offers EU data region

#131

Earlier quoted context omitted.

Take a look at how they play with regards to chat control. The EU is just the same corrupt BS like D.C., only with a lot more virtue signaling.

Sorry, I don't agree with that. The amount of corruption in the USA right now is simply off the scale.

Nah, it’s just more visible. It’s not that much of a sea change. And it’s ridiculously naive to pretend that the major countries in Europe don’t have their own mechanisms to regularly and effectively bypass any democratic inconveniences when necessary. They regularly push through things that no constituent would ever want or vote for.

Re: Fastmail offers EU data region

#132

Earlier quoted context omitted.

Can you point me towards some resources that show EU customers moving? Not that I don’t trust the statement, I just would like to know more.

I hope Airbus is large enough for you? https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cl... And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put…

Tnx!

Re: Fastmail offers EU data region

#133

Earlier quoted context omitted.

Can you point me towards some resources that show EU customers moving? Not that I don’t trust the statement, I just would like to know more.

HN Search: airbus critical apps scaleway - https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments) Netherlands reaches deal with European cloud company to decrease U.S. tech reliance - https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ... - April 24th, 2026 Wary of US Big T…

Thank you su much, wow

Re: Fastmail offers EU data region

#134
post #124

Or you can just use any of the actual European companies (I’m using Tuta). https://european-alternatives.eu/category/email-providers

I started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their apps

Tuta is always encrypted I don't know where you got the impression that it was optional or that they could somehow magically make it work over IMAP without a bridge like proton.

Re: Fastmail offers EU data region

#135
post #118

Earlier quoted context omitted.

HN Search: airbus critical apps scaleway - https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments) Netherlands reaches deal with European cloud company to decrease U.S. tech reliance - https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ... - April 24th, 2026 Wary of US Big T…

US Cloud soon illegal? Trump punches first hole in EU-US Data Deal - https://noyb.eu/en/us-cloud-soon-illegal-trump-punches-first... (2025-01) EU-US Data Transfers: First Reaction on "Latombe" Case - https://noyb.eu/en/eu-us-data-transfers-first-reaction-latom... (2025-09) EU-US Data Transfers: Time to prepare for more trouble to come - https://noyb.eu/en/eu-us-data-transfers-time-prepare-more-tr... (2025-12) US Supr…

Tnx!

I was up to date on noyb, but not aware that actually companies are moving at this speed and size.

Thanks all for some great resources

Re: Fastmail offers EU data region

#136

Earlier quoted context omitted.

EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US. AWS, Azure, GCP, Oracle, Schwarz Digits, SAP

> AWS, Azure, GCP, Oracle What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.

> Only Schwarz and SAP are free from that by being German companies.

Not true. You also have to be sure that the company directors will never travel to the US even for a holiday or any third party country that would uphold an extradition request from the US.

It's just email. Nobody is going to jail to protect your email.

If you care that much run your own email server.

Re: Fastmail offers EU data region

#137
post #131

Earlier quoted context omitted.

Sorry, I don't agree with that. The amount of corruption in the USA right now is simply off the scale.

Nah, it’s just more visible. It’s not that much of a sea change. And it’s ridiculously naive to pretend that the major countries in Europe don’t have their own mechanisms to regularly and effectively bypass any democratic inconveniences when necessary. They regularly push through things that no constituent would ever want or vote for.

Nah, it’s worse now than ever.

Re: Fastmail offers EU data region

#138

Earlier quoted context omitted.

Yeah, this does absolutely not solve the CLOUD Act issues. However , it is good to look at what the ramifications of the CLOUD Act is for e-mail: - The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of do…

Something like 99% of email is now done over TLS.

Yes but it will almost always work with self signed or expired certificates, or downgrades to clear text if that's what it takes to deliver the message.

Re: Fastmail offers EU data region

#139
post #13
post #9

EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happen…

For anyone curious, it's the CLOUD act: > The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil. [1] https://en.wikipedia.org/wiki/CLOUD_Act

It's weird how everyone focuses on that part of the CLOUD Act. The CLOUD Act actually did two things: (1) that, and (2) provided an expedited way for the US to enter into Mutual Legal Assistance Treaties (MLATs) with other countries.

It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.

The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.

One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.

There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).

So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.

The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.

With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.

There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.

The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing them across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.

For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.

With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.

And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.

The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.

The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.

There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.

Civil rights groups and many others were not impressed with those safeguards.

Re: Fastmail offers EU data region

#140
The local government cannot get access to the servers in Amsterdam?

I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.

Post reply on HN