All posts

Data Sovereignty Isn't a Map Pin: Why "EU Region" Is Not "EU Jurisdiction"

Servers in Frankfurt aren't sovereignty. Residency is geography; jurisdiction is power. The US CLOUD Act binds the company, not the disk — which is why Microsoft's own lawyer told the French Senate he "cannot guarantee" EU data stays in the EU.

A green pin over Germany is not sovereignty

A cloud provider can store every byte of your data in Frankfurt, paint a green pin over Germany, and still be legally forced to hand your files to a foreign government. Data residency is geography: where the disks physically sit. Data sovereignty is power: who can compel disclosure. They are not the same word, and only the second one protects you. The fastest way to see the gap is to read the law that the map pin pretends doesn't exist.

What an "EU region" actually promises

When a provider tells you the data is stored in the EU, the promise is narrow and specific: the bytes rest on disks inside the EU. That is residency, and it is worth something. It shortens the legal distance for an EU regulator and keeps latency low.

But residency is a fact about hardware, not about who can reach it. The disk doesn't know who owns the company operating it. And the law doesn't care where the disk is. It cares who controls the company.

Three questions hide inside "is my data safe in Europe?"

Untangle the marketing and there are three separate questions, usually collapsed into one.

  1. Where the data physically sits. The data-center location: Falkenstein, Frankfurt, Dublin, us-east-1. This is residency.
  2. Who legally controls the operating company. Is the entity running the service incorporated in the EU with EU directors, or is it the European subsidiary of a US corporation? This is corporate jurisdiction.
  3. Who can compel disclosure. Which government's courts can issue a binding order the company must obey, on pain of contempt? This is the question that decides everything, and the map pin says nothing about it.

A provider can score perfectly on the first and fail completely on the third. That gap is where "sovereign washing" lives: selling residency as if it were sovereignty.

The CLOUD Act binds the company, not the disk

The US CLOUD Act, signed in March 2018, amended the Stored Communications Act so that American law enforcement can compel any US-incorporated company, by warrant or subpoena, to produce data it controls — no matter where on Earth that data lives. The law attaches to the company, not the server. If the entity holding your decryption keys is American, or has an American parent that can direct it, a US court order reaches your data whether it sits in Virginia or in a Frankfurt data center with a German flag on the brochure.

This isn't a theoretical edge case; it's the entire point of the law. The CLOUD Act exists to close the loophole that Microsoft Corp. v. United States opened, when Microsoft refused a 2013 warrant for emails stored in Dublin and argued a US warrant couldn't reach foreign servers. Congress wrote the CLOUD Act to make sure it could, and in April 2018 the Supreme Court sent the case back as moot. The location defense is dead in US law.

"I cannot guarantee that"

The cleanest statement of the problem didn't come from a privacy activist. It came from the vendor's own lawyer, under oath.

On 18 June 2025, before a French Senate inquiry into digital sovereignty in public procurement, Microsoft France's director of public and legal affairs, Anton Carniaux, was asked whether he could guarantee that data on French citizens would never be transmitted to the US government without the explicit agreement of the French authorities.

His answer: "No, I cannot guarantee that."

He added that it had never happened, and that Microsoft contests requests it considers unfounded. Both caveats are fair and worth stating. But "we will resist" is not "we cannot be compelled." A lawful, founded order is one the company must obey, and the most senior legal voice in the room knew it. A French data center, a US-owned operator, people who genuinely intend to protect you — and still no guarantee the data stays in Europe. Residency didn't save it. Corporate ownership sank it.

Two levers that actually move the answer

There are exactly two postures that change the outcome, and a serious provider pulls both.

The first is corporate jurisdiction. The company that holds the contracts, runs the servers, and could be served an order should be incorporated in the EU with no US parent in the chain. Beebeeb is operated by Initlabs B.V., a Dutch company (KvK 95157565), with data stored on dedicated servers in Falkenstein, Germany. There is no US entity to compel. We lay out exactly how that infrastructure is set up on our security page.

The second lever makes the first one almost academic: never hold the keys at all. If the servers only ever store ciphertext, then "compel disclosure" produces nothing readable, regardless of which government asks. This is the difference between trusting a jurisdiction and not having to. With zero-knowledge, client-side encryption, your files are encrypted on your device — keys derived from your passphrase before anything leaves it. The server stores AES-256-GCM ciphertext and nothing that decrypts it. Our features page spells out what that protects in practice.

Sovereignty you can verify

Jurisdiction is a promise you have to trust. Architecture is a property you can check. The strongest posture combines both: EU incorporation so there is no foreign order to obey, and zero-knowledge encryption so even a valid domestic order yields ciphertext. That is the bar we hold on every tier, the free one included.

It's also why "encrypted, US-owned, EU region" is weaker than it looks, and why it's worth asking any provider — including the one your iPhone defaults to — who holds the keys and who owns the company. Our honest Beebeeb-versus-iCloud comparison walks through exactly that.

If you'd rather test the architecture than take our word for it, Upload a file and ask the only question that matters: who, other than you, could ever decrypt it.

Files only you can read

Beebeeb is end-to-end encrypted, zero-knowledge cloud storage — stored in Falkenstein, Germany, open source, with a 14-day free trial on every plan. Encryption happens on your device; we only ever hold ciphertext we can’t read.

Join the waitlist See pricing How the encryption works