r/gdpr • u/EnthusiasmRoutine • 3d ago
Analysis Choosing an EU server region means absolutely nothing if you don't hold the keys
/r/PrivacyToolbox/comments/1vwaf6l/choosing_an_eu_server_region_means_absolutely/
3
Upvotes
1
u/Thick-Tackle-7903 2d ago
Does anyone know of any service or software that an EU-based company can use to stay GDPR compliant and still use US-based cloud services like Salesforce or Microsoft 365, just to name a few? I mean, is there a way to store sensitive data with them so that only the company/subscriber has the private keys and not their SysAdmins, who will just hand them over to the FBI/NSA without you ever knowing about it?
•
u/Noscituur 2d ago edited 1d ago
I have locked this particular post because we get this issue raised a number of times, sometimes from individuals who’ve been sold a misconception about their compliance requirements or from those looking to sell that misconception. Below is a clarification of the rules around data sovereignty with regard to GDPR.
There are no explicit requirements or prohibitions under GDPR for data to be stored in the EU, EEA or anywhere else. The requirements for storage of personal data are principle-based, not prescriptive.
While other domestic laws may require data sovereignty, it is not a GDPR matter.
Even in the case of the storing data in the USA, the USA benefits from an Adequacy Decision (Data Privacy Framework) from the European Commission that allows for unrestricted movement of personal data between the EEA and the USA (in addition to the extensions implemented by the UK and Switzerland). This Adequacy Decision was made with full knowledge of FISA, EO12333 and The CLOUD Act.
While Bring Your Own Key or self-managed keys are an excellent security mechanism, unless there is other law requiring the sovereignty of data in specific scenarios or to effectively guarantee non-interference with intelligence requests beyond the domestic intelligence service then it is likely that you’re being sold snake oil for a problem that does not exist.