Sovereignty
“Data hosted in Europe” means that the provider states it stores certain data in datacenters located in Europe. The phrase is true or false depending on the list of data it covers. It does not say which law applies to the company that holds the data.
Updated October 20268 min readOfficial sources cited
The statement appears on almost every email and storage offering. It reassures, and that is its commercial purpose. For a senior executive, an IT director or a DPO, it is only a starting point: the record of processing activities, a customer questionnaire or a tender will ask where the data are, but also who accesses them and from where.
An overly broad phrase creates two risks. The first is wrongly declaring that no data leave Europe. The second is believing a question has been settled when it has not: the question of the operator and the law that applies to it. The page protect a business from the CLOUD Act addresses this second point.
Brochures mix up four scopes.
These distinctions are not lawyers’ details. A tender that requires hosting “in the European Union” is not necessarily satisfied by an offering that announces “Europe” and includes Switzerland or another EFTA country. Conversely, Swiss hosting may suit a business that has checked the applicable framework. The common mistake is to treat the word “Europe” as an answer, when it calls for a list.
When you read “Europe”, ask for the list of countries.
An email service produces at least six families of data.
Many offerings “hosted in Europe” refer to family 1, sometimes to family 2. Families 3 to 5 are the ones that most often go elsewhere: follow-the-sun support (your requests pass from one team to another around the world according to the time zone), a US ticketing tool, backups with a subcontractor, antivirus software whose signatures or samples leave the area.
These families are not secondary. Logs show who works with whom and at what time. A copy of a mailbox sent to support for a diagnosis contains as much as the mailbox itself. A backup is a second complete copy.
For the services included in the EU Data Boundary, Microsoft documents storage and processing in the EU and EFTA of customer data and pseudonymised personal data, as well as storage at rest of professional services data, with transfers that continue: remote access by staff outside the area for certain incidents, storage outside the area of certain elements of escalated tickets, optional features enabled by the administrator, Multi-Geo customers outside the scope. Google documents data regions for covered content (email, calendar, files, documents, depending on the edition). Google’s documentation specifies that unlisted data, such as certain logs, are not covered by this data region policy.
These two software vendors have one merit: they publish what is covered and what is not. A provider, whatever its nationality, that writes nothing about its backups, logs and support offers no greater guarantees; it simply offers fewer to check.
Reading the list of what is covered takes an hour. That hour is what gives the phrase its meaning.
A 40-person services SME with two branches compares two email offerings. Both announce “data hosted in Europe”. On reading the documentation, the IT director finds that the first covers mailboxes and files, but that the support ticketing tool is hosted outside Europe and that technicians may connect from several continents. The second specifies the country of the mailboxes, backups and logs, and states that support works from the same scope, with a record of every access.
Both phrases were true. Only the second makes it possible to complete the record without approximation. The final choice may still be made on other criteria, such as features or price, but it is made with full knowledge of the facts.
It does not prove that the operator is European. A US software vendor can host in Ireland.
It does not prove that there are no transfers. An email sent to a correspondent outside Europe leaves Europe because the sender intended it to. An attachment opened in a third-party tool leaves the scope. Finally, if the customer requests a backup copy to its own vault, the location and storage conditions of that copy depend on the location and characteristics of the vault chosen by the customer.
It does not prove who can read. Transport encryption (TLS) protects the journey. Encryption at rest protects a stolen disk. As long as the operator holds the key in order to deliver the service, it can technically access the content. This is the usual framework for an email service, with a US provider as with a European one. What matters then is the access rule, the record, and the law that applies to the operator.
The framework changes when the key is held by the customer, or kept in the customer’s account behind a password the operator does not have: the operator can no longer read the content without an action the customer would notice. This is the choice Klytic has made, described below.
It does not prove reversibility. Data hosted in Marseille that you cannot export remain difficult to leave.
These questions should be asked in writing for a simple reason: the answer can be carried over into the contract or the record.
The pages GDPR and Microsoft 365 and GDPR and Google Workspace apply these questions to the two most widespread suites. For email alone, see choosing a European business email service.
Geographically, yes. Legally, Switzerland is not in the European Union, but the Commission has adopted an adequacy decision in its respect. If your contract or a tender requires the European Union, this must be checked before signing.
Not without checking. Backups, logs, support tickets and optional features often follow different rules from the mailboxes. Microsoft itself lists transfers that continue despite its EU Data Boundary.
The question is poorly framed. The storage location is only one element; the legal basis for transfers, the subcontractors and support access also matter. Moreover, the location says nothing about the law that applies to the software vendor.
It protects the journey and the disk. It does not make the data unreadable to the operator that holds the key. What matters, therefore, is who holds the key, what the contract says about it, and which features the encryption applies to.
When the service is hosted by Klytic for a European customer, the data are hosted in Europe. For a customer in the Mauritius area, the announced hosting is Mauritius or Europe. For other customers, hosting is provided in a geographical area that complies with the applicable jurisdiction, subject to the availability of the required services. The customer can also have the service hosted on its own premises. For telephony, the dedicated server is hosted in a European cloud, in Mauritius or in a geographical area that complies with the applicable jurisdiction, depending on the customer’s request or needs. Backups follow the same operator: every hour for email, documents and CRM, every day for telephony, with 30-day retention.
At Klytic, the encryption key is held by the customer, or kept in the customer’s account. Klytic has no access to it: to obtain it, Klytic would have to destroy or change the account password, which it does not have, and the customer would notice. The stages where encryption is managed by Klytic (filtering quarantine, processing in the CRM, emails when the customer has not enabled its own key) are detailed on the page protect a business from the CLOUD Act. The contract must describe this possession and this encryption. The published details are on the pages hosting and sovereignty and frequently asked questions.
This page describes a general framework. It does not replace an analysis of your contract.
Legal status as of 5 October 2026. This text does not replace a contract review. The EU–US adequacy decision (EU) 2023/1795 is in force. It is being challenged. The ANSSI catalogue is authoritative for SecNumCloud.
Accessed in October 2026.
Email, documents, video conferencing, CRM and telephony, hosted in the zone that matches your jurisdiction, for example in Europe or Mauritius, or on your premises.
Welcome offer
No-commitment trial offer. An advisor will call you back to understand your needs and prepare your Klytic space.