EU infrastructure and the GDPR: requirements and real cost
Complying with the GDPR when you host a digital product depends above all on which law binds the company that runs the servers. Where the servers are comes second. A US provider with a data center in Frankfurt is still subject to US law. Since June 29, 2026, that distinction is no longer just a debate for lawyers.
What happened in June and why it affects you
A quick recap of the last three years, because the decision makes no sense without it.
In July 2023 the European Commission adopted the EU-US Data Privacy Framework, the adequacy decision that allows personal data to be sent to certified US companies without standard contractual clauses or a transfer impact assessment. In September 2025 the EU General Court dismissed the action seeking to annul it (case T-553/23, Latombe, Spanish Data Protection Agency press release, in Spanish), and the agency welcomed the ruling as a source of stability and legal certainty. One of the key arguments the Court rejected was that the US review court lacked independence.
On June 29, 2026, the US Supreme Court ruled 6–3 that the legal limits on removing Federal Trade Commission commissioners violate the US Constitution (Trump v. Slaughter).
That ruling says nothing about data protection. What it addresses is how independent a US oversight body is from the executive branch. And the independence of oversight is exactly the ground on which the Court of Justice of the EU struck down the two previous agreements, Safe Harbor and Privacy Shield.
The framework is still in force today. Nothing you’ve built became illegal this morning. But this is the third bridge built over the same ground, and the first two collapsed.
Start with who operates the servers
This is where most people go wrong from the start.
The US CLOUD Act of 2018 establishes that US authorities can require data from a provider subject to their jurisdiction regardless of where it’s physically stored. Choosing the Frankfurt or Ireland region in a US provider’s console solves latency. Jurisdiction stays exactly where it was.
Which leaves two questions to ask, in this order:
- Who owns the company that runs the service, and under which law does it answer?
- Only then: where is the data?
Most audits ask them the other way around, which is why they come out reassuring and prove nothing.
What you can run today without leaving Europe
The practical answer: far more than most people think, and that’s been true for years.
| Need | European options | Note |
|---|---|---|
| Compute and containers | Scaleway (FR), OVHcloud (FR), Hetzner (DE), Exoscale (CH), IONOS (DE) | The first four comfortably cover a vertical SaaS |
| Managed database | Scaleway, OVHcloud, Exoscale | Managed Postgres with backups and replicas |
| Object storage | Scaleway, OVHcloud, Infomaniak | S3-compatible APIs, so the code doesn’t change |
| Transactional email | Scaleway, Brevo (FR), Infomaniak (CH) | Where most people give up and go back to a US provider |
| CDN and protection | OVHcloud, Bunny (SI), Scaleway | Less mature than the US alternative, but good enough |
| Payment provider | Mollie (NL), Adyen (NL), Redsys (ES) | See the next section: this is where it pays to be honest |
A caveat about “Europe”
It’s worth being precise, because the table above mixes two things.
The territory where the GDPR applies directly is the European Economic Area: the twenty-seven EU countries plus Iceland, Liechtenstein and Norway. Moving personal data within it doesn’t count as an international transfer and requires no extra mechanism. Moving it outside does.
Switzerland isn’t in the European Economic Area. What it has is an adequacy decision from the European Commission, reviewed and confirmed in January 2024, which has a similar effect: data can flow without standard contractual clauses or binding corporate rules. Today there are seventeen adequacy decisions in force, including the UK’s (renewed until December 2031) and the one for the United States, which only covers organizations certified under the framework.
In practice, the two differ in risk: an adequacy decision is reviewed periodically and can be withdrawn, while membership of the European Economic Area can’t be. That’s why Exoscale and Infomaniak, both Swiss, sit one step behind Scaleway or OVHcloud if what you want is never to have this conversation again.
Vecinly is built on Scaleway, in France, and was designed that way from day one. It wasn’t a migration or a reaction to regulatory news. The decision was made at the start, and it cost nothing.
That’s the takeaway. Setting up the infrastructure in Europe while the product is being built costs the same as setting it up anywhere else. It’s a choice of provider, and the architecture doesn’t change: Postgres is Postgres, containers are containers, and the storage API is identical. What’s expensive is moving it later, with data in it and customers using it.
What you can’t run in Europe, and it has to be said
An article that presented this as a clean decision would be lying.
The payment provider is the clear case. Stripe is American. It can be replaced with Mollie or Adyen, both Dutch and perfectly solid, but with a thinner feature set for complex subscriptions. If your model has proration, usage-based tiered plans and billing in several countries, the comparison is less flattering than this article would like.
Other pieces where a European alternative exists but is weaker: product analytics, support and chat tools, marketing email, and nearly everything related to language models.
How to handle what stays outside, which is the useful part:
- Minimize what you send. A payment provider doesn’t need your user’s activity history. Send an identifier and an amount.
- Keep it apart from the core. The data that defines your product, your customers and their activity, stays inside. Whatever leaves does so in a limited, documented way.
- Write it into the record of processing activities. Every provider outside the European Economic Area, with its purpose, its legal basis and its transfer mechanism.
- Have the data processing agreement signed with each one and keep it somewhere you can find it.
- Check what each provider relies on: certification under the framework, standard contractual clauses, or both.
Perfect purity isn’t achievable. Traceability is, and it’s what an auditor will ask you for.
What it costs and why the surprise runs the other way
The common belief is that sovereignty comes at a price. For basic infrastructure, the opposite is true.
The line item that skews the comparison most is data egress. A terabyte of outbound traffic costs around $83 a month on AWS, and nothing at all with several European providers (2026 comparison). For a SaaS that serves documents, images or reports, that one line can decide the bill.
In return, you do give up some real things, and it’s worth knowing them up front:
- Fewer managed services. You have to build by hand things that come ready-made on the big clouds.
- Less around it. Fewer third-party integrations, fewer templates, fewer forum answers at three in the morning.
- Fewer people who already know it. Hiring someone with OVHcloud experience is harder than finding someone with AWS experience.
For a vertical SaaS with tens or hundreds of customers, none of these three is a deal-breaker. For a platform with global-scale requirements, they can be.
What’s coming and why it’s not worth waiting for it
Two things in motion, neither settled.
On June 3, 2026 the European Commission presented a proposal for a Cloud and AI Development Act with a common sovereignty framework built on four assurance levels. It isn’t in force: it has to be negotiated with Parliament and the Council, and its final wording may change considerably.
The EU Data Act, already applicable, requires providers to guarantee portability, interoperability and fairer contract terms. That lowers the cost of switching providers, which is exactly what keeps a lot of people stuck today.
Neither will make this week’s decision for you. And that’s the underlying argument: regulation moves much more slowly than a product. If you build on the premise that any piece might have to change provider, what gets approved matters far less.
The playbook, if you’re starting out
In order, and each one takes a day to decide:
- Choose a European provider for the core: compute, database and storage. There’s no technical trade-off here worth arguing about.
- Use standard pieces. Postgres, containers, an S3-compatible API. The more standard your stack, the less it costs to switch providers later.
- Isolate whatever leaves Europe behind a module of its own, instead of spreading it through the code.
- Write your record of processing activities in the first month, without waiting for the first audit.
- Sign the data processing agreements as you sign up with each provider.
- Write down what you’d do if the transfer framework fell tomorrow. Even half a page. With that document, the framework falling is a bad week. Without it, three months.
If you’re already on a US cloud
Don’t rush to migrate. Migrating infrastructure with customers on it is a serious project, with real risk and no immediate benefit for anyone using your product.
What’s worth doing this week:
- Inventory which personal data leaves the European Economic Area, to whom and why. Most companies don’t know, and that blind spot is the real exposure.
- Check whether your providers would still be covered if the framework fell. Many have also signed standard contractual clauses, in which case losing the framework would give you a scare while business carried on as usual.
- Work out what it would cost to move the core. With a figure on the table, the decision stops being ideological.
And a recommendation that runs against Nimboo’s own interest: if your product already works well and you don’t handle sensitive data, the most reasonable thing is probably to leave it alone and simply document things and keep the plan in writing. Rebuilding infrastructure that works over a regulatory risk that may take two years to materialize rarely pays off. It’s different if you’re starting out, or if you sell to the public sector, healthcare or regulated industries: there, your customer has already made the decision.
Building the product now? It’s the only moment this decision is free. Nimboo builds custom SaaS with the infrastructure in the client’s name from day one, and with the provider chosen on judgment rather than habit. The price of each phase is on the pricing page.