The OneDrive problem isn't OneDrive
OneDrive is good software. The sync client is mature, the Office integration is genuinely useful, and 1 TB per user covers most teams without a second thought. The problem sits one layer down: Microsoft is a US company, and that single fact decides who can ultimately be compelled to reach your files. For an EU team holding client records or anything special-category under GDPR, that isn't a footnote — it's the whole question. This is for teams already on Microsoft 365 who want an EU-jurisdiction home for the confidential files OneDrive holds. Not a Microsoft teardown; Microsoft has real strengths, and we'll name them.
What Microsoft charges, and what it actually protects
OneDrive for Business rides inside Microsoft 365. As of mid-2026, Business Basic is $6/user/month and Business Standard is $12.50/user/month, each with 1 TB of OneDrive storage per user. On July 1, 2026 both rise: Basic to $7, Standard to $14.
On data protection, Microsoft has done real engineering. The EU Data Boundary commits to storing and processing EU/EFTA customer data inside Europe, and for residency alone it largely delivers. But residency is not jurisdiction. Microsoft is incorporated in the US, which puts it under the US CLOUD Act — a law that compels US companies to produce data on a valid US order no matter where the servers physically sit.
You don't need a critic's framing for this. In June 2025, Microsoft France's legal-affairs director Anton Carniaux was asked under oath before the French Senate whether he could guarantee French citizens' data would never reach US authorities without French approval. His answer: "Non, je ne peux pas le garantir." No, I cannot guarantee that. He noted Microsoft contractually resists unfounded requests — which concedes the point, because a valid order isn't an unfounded one. The European Data Protection Board agrees: a CLOUD Act demand is not a lawful basis for a third-country transfer, and GDPR Chapter V requires technically effective measures — encryption with keys held outside the provider's reach.
The EU Data Boundary moves where your bytes rest. It does not move who can be served an order to produce them.
And the perimeter is a setting, not a wall. In 2026 Microsoft introduced Copilot Flex Routing, which lets model inference on tenant data run outside the EU Data Boundary — in the US, Canada, or Australia — during peak demand, on by default for many tenants. You can switch it off in the admin center, which is the issue exactly: the boundary holds because Microsoft configured it that way, and the configuration is theirs to change.
The lock-in nobody prices in
List price is the cheap part. OneDrive is one tile in a suite — identity in Entra ID, mail in Exchange, collaboration in SharePoint and Teams — and storage is the tile most tangled into the rest. Leaving means unpicking sync clients, known-folder redirection, and permissions that were never built to be portable. Microsoft will export your bytes; it won't make the exit feel like anything but a project. That's why teams stay long after deciding the jurisdiction is wrong for them. The honest goal isn't ripping out Microsoft 365 overnight — it's moving the data that actually matters somewhere the legal question has a clean answer. That somewhere has to clear a short bar: the server holds only ciphertext you alone can decrypt, the company is an EU legal entity and not a US subsidiary, an engineer can read the encryption code, and the exit is a plain file export.
How Beebeeb measures up — and where it doesn't yet
Beebeeb is built to that bar. Every tier is zero-knowledge by default, no exceptions: your passphrase derives your keys with Argon2id on your device, files are sealed with AES-256-GCM, per-recipient sharing uses X25519, and login runs over OPAQUE so your password never reaches our servers. We hold ciphertext and nothing else, and we could not hand a court your file contents if it ordered us to, because we never have the keys.
The company is Initlabs B.V., incorporated in the Netherlands (KvK 95157565). Data sits on dedicated servers in Falkenstein, Germany, under an infrastructure provider with no US parent. The product clients — web app, CLI, mobile, desktop, and the core crypto library — are open source, so the encryption is code you can read, not a promise you take on faith. Pricing is flat and per-terabyte, never per-seat: Starter €1.99/mo for 100 GB, Basic €3.99/mo for 200 GB, Pro €10.99/mo for 1 TB, scaling to 99 TB self-serve at +€10.99 per extra TB and a custom quote beyond — every plan opens with a 14-day free trial rather than a permanent free tier. The full breakdown is on the pricing page.
Now the honest part. Beebeeb does not replace Microsoft 365: no Word, no Excel, no Teams, no shared mailbox. It replaces the storage layer for files you need kept private. Native mobile and desktop apps are coming soon; today the web app and CLI are live, with WebDAV through the CLI. Direct Google Drive and Dropbox import is coming soon, not shipped. Our independent security audit is planned and its findings will be published — we haven't been audited yet, and won't pretend otherwise. On polish and ecosystem depth, Microsoft wins. On who can be compelled to read your files, it isn't close. We don't out-encrypt the EU incumbents either: Proton Drive and Tresorit are zero-knowledge and open-source too, so we match them on the crypto and compete on price and jurisdiction.
How teams actually make the move
The realistic pattern isn't a big-bang cutover. You move the sensitive subset first — HR records, client deliverables, anything you'd dread seeing in a disclosure log — while routine Office collaboration stays where the tooling is strong. Encrypted sharing with link expiry, max-opens, passphrase protection, and one-click revocation covers most of what teams used SharePoint links for, and accountless file requests let clients send you documents even we can't read.
If you want the wider field first, our honest rundown of EU storage alternatives concedes where each one beats us. OneDrive isn't broken — it's owned by a company that told a parliament, under oath, that it can't promise your data stays out of US hands. If that changes how you feel about where your confidential files live, you already know the first question to put to your next provider.