DEV Community

Cover image for How to Host a Website Without US Cloud Providers (And What Actually Counts as 'EU')
Martin
Martin

Posted on Originally published at neleto.io

How to Host a Website Without US Cloud Providers (And What Actually Counts as 'EU')

Someone has asked whether the website can move "off American infrastructure." The honest answer starts with a correction: where the servers physically stand matters less than who legally controls the company running them. A rack in Frankfurt owned by a US corporation is still reachable by US law.

Does hosting in an EU data centre put you outside US legal reach?

No. Physical location is one factor among several, and on its own it decides very little.

The US CLOUD Act (2018) lets US authorities compel a provider under US jurisdiction to hand over data in its "possession, custody, or control," regardless of where the data sits. That reach extends to US parent companies and, in practice, their European subsidiaries.

This isn't theoretical. On 10 June 2025, Microsoft France's legal counsel Anton Carniaux was asked under oath in a French Senate hearing whether he could guarantee French citizens' data would never reach US authorities. His answer: "Non, je ne peux pas le garantir." The limits are real: a warrant or court order is required, and the act is encryption-neutral. But a limit you have to litigate isn't a control you can cite in an assessment.

What actually counts as "EU"?

"EU" is used for four different things, and mixing them up is where most bad decisions start.

Level What it means Does US law reach it?
EU region A US provider's data centre located in the EU Yes, the provider is still US-controlled
EU data residency contract Contractual promise that data stays in the EU Yes, a contract does not override a US court order
US-branded "sovereign cloud" A US hyperscaler's EU-operated, sometimes locally-partnered offering Contested. Depends on the ownership and operational chain, which varies per product
EU-controlled provider Incorporated and controlled in the EU/EEA, no US parent, no material US operations Not directly. This is the only level where the answer changes

The fourth row does the work. Everything above it is a mitigation, not a change of jurisdiction. Sovereign-cloud branding from US hyperscalers is a contested claim rather than a settled fact, which is why the EU's Tech Sovereignty Package of 3 June 2026 proposes formal "assurance levels". The label alone told nobody anything.

Is the EU-US Data Privacy Framework still valid in 2026?

Yes. As of writing it's still in force, and noticeably less stable than a year ago. Don't plan on it being permanent, and don't plan on it collapsing tomorrow either.

On 3 September 2025 the EU General Court dismissed Philippe Latombe's annulment challenge (T-553/23), though on the facts as they stood at the 2023 adequacy decision. In October 2025 Latombe appealed to the CJEU, the court that struck down Safe Harbor and Privacy Shield.

Then on 29 June 2026, in Trump v. Slaughter, the US Supreme Court held 6 to 3 that statutory removal protections for FTC Commissioners are unconstitutional. On 31 July 2026 the EDPB asked the Commission to assess the consequences, noting that the adequacy decision expressly relies on FTC independence.

There are also reports of the PCLOB losing quorum and instability around FISA Section 702 renewals. Practically: keep Standard Contractual Clauses and transfer impact assessments in place rather than leaning on the DPF alone.

Legal risk or political preference? They lead to different answers

Both are legitimate, and conflating them produces incoherent decisions.

Legal risk is about specific personal data, specific processing, documented transfer mechanisms. It's proportionate (a marketing site logging IP addresses isn't a health portal), and the response is a data map, a transfer impact assessment, and changes to the layers that actually carry personal data.

Strategic preference is about supply-chain dependency, geopolitical exposure, and where your money goes. It isn't proportionate to risk, and it can justify moving things that pose no legal problem at all.

If your motivation is the second, say so. Dressed up as a compliance requirement, it becomes a project that fails its own stated test.

Which layers of your website actually touch US services?

More than most people expect. The host is the layer everyone focuses on and usually the least interesting. Each row below is a separate contract, data flow and decision.

Layer Common default European option If you can't switch
Server / host AWS, Azure, GCP Hetzner (DE), IONOS (DE), OVHcloud (FR), Scaleway (FR), UpCloud (FI) SCCs plus encryption whose keys you hold
CDN Cloudflare, CloudFront, Fastly Bunny.net (SI), Myra (DE), KeyCDN (CH, non-EU but an adequacy country) Or drop the CDN; many sites don't need one
DNS Cloudflare, Route 53 deSEC (DE), Hetzner DNS, INWX (DE), Bunny DNS Query data is low-sensitivity, but not nothing
Web fonts Google Fonts CDN Self-host the font files Nothing, just self-host
Analytics Google Analytics Matomo (self-hosted or EU cloud), Plausible (EE), Piwik PRO (PL), etracker (DE) Consent, IP truncation, DPA
Embedded video YouTube, Vimeo Bunny Stream, Dailymotion (FR), self-hosted PeerTube Click-to-load facade so nothing loads pre-consent
Forms + transactional email SendGrid, Mailgun, Postmark Brevo (FR), Mailjet (FR), Rapidmail (DE), CleverReach (DE), Scaleway TEM Your own SMTP on EU infrastructure
Error tracking Sentry, Datadog, LogRocket Self-hosted Sentry, GlitchTip Scrub PII in the browser before it leaves
AI in the content pipeline OpenAI, Anthropic, Google Mistral (FR), Aleph Alpha (DE), IONOS AI Model Hub, OVHcloud AI Endpoints Don't paste personal data into any of them

Fonts are the cheapest win. In January 2022 the Landgericht München I awarded a visitor €100 in damages because a site loaded Google Fonts from Google's CDN, sending the visitor's IP address to the US without consent. Self-hosting the files takes an afternoon.

What you actually give up by going EU-only

Real costs, not token ones. Anyone who tells you the switch is free hasn't done it.

You get fewer managed services. Europe has excellent infrastructure and a much thinner layer of managed services on top, so you'll self-manage things a hyperscaler would have run for you. Ecosystems are smaller too: fewer Terraform modules, fewer integrations, fewer answers at 2am.

Some gaps are genuine. Error tracking and video hosting are the weakest rows above, where the self-hosted options work but trail Sentry and YouTube in polish. Edge performance outside Europe trails Cloudflare and CloudFront, so if your traffic is in São Paulo or Singapore, a European-only CDN costs real milliseconds. And in the AI layer, European providers have closed a lot of ground, but for some tasks frontier US models are still ahead, so re-check rather than assume.

None of that is a dealbreaker for a content website. Several of them are, for a global consumer product.

Where Neleto fits in this

Neleto is a complete CMS with managed EU hosting on Hetzner in Falkenstein and Nuremberg (Germany) and Helsinki (Finland). Triple-A Soft, the company behind it, is German, and there's no US parent in the chain. That puts the hosting layer in the fourth row of the table above rather than the first, and you pick the region when you start a project, on every plan including the free tier.

The more useful argument isn't the flag, it's the count of moving parts. Rendering is built in, so there's no second frontend stack deployed elsewhere. Image scaling is built in, so images never travel to an external transformation service. Fewer third-party services touching the page means fewer data-transfer questions in the first place, and every row you delete from that table is a DPA you don't sign and a subprocessor you don't re-check when its ownership changes.

Neleto doesn't make anyone automatically GDPR-compliant. That depends on what you collect and what you bolt on. Embed YouTube and load Google Analytics on a Neleto site and you have the same problems as anywhere else.

One caveat on our own stack: Neleto ships a native MCP server, and the AI clients people use it with (Claude Code, Cursor, Windsurf) are US products. If your policy is EU-only end to end, that's a layer like any other, and we aren't exempt from it.

When this is not worth doing

Skip the migration if any of these describe you.

You process no personal data beyond server logs, with no analytics, no forms and no embeds. Exposure is already near zero and the project would be theatre.

Your organisation is US-based or US-owned. A German host doesn't change your own jurisdiction. Fix the data map first.

You need global edge performance more than jurisdictional clarity. Worldwide e-commerce traffic will feel a European-only CDN.

You depend on a US-only managed service with no European equivalent. Name it, then decide whether the rest is worth moving anyway. Partial migration is a legitimate outcome.

Nobody has actually asked the question. Budget spent on a problem you can't articulate is budget not spent on one you can.

The middle path is usually right: move the layers that carry personal data and are cheap to move (fonts, analytics, DNS, transactional email), keep what's load-bearing, and document why for each. "Everything is in the EU" is rarely true once someone reads the subprocessor list.


Try it yourself: Open your site with the browser network tab recording, load a page in a private window, and list every domain it contacts. That list is your real answer, and it's usually longer than the one in your privacy policy.

Top comments (0)