· via dev.to (home feed)
EU hosting guide separates legal control from server location across nine stack layers
A dev.to guide argues US legal reach follows provider control rather than server location, sorts four meanings of 'EU hosting', and maps European alternatives across the whole stack.

A guide published on dev.to addresses the question of moving a website off US infrastructure, and opens by correcting a common assumption: where servers physically stand matters far less than who legally controls the company operating them. A rack in Frankfurt owned by a US corporation is still reachable by US law.
US legal reach follows control, not geography
According to the guide, the US CLOUD Act of 2018 lets US authorities compel a provider under US jurisdiction to hand over data in its possession, custody or control, wherever that data physically sits — a reach extending to US parent companies and, in practice, their European subsidiaries. The guide cites a 10 June 2025 French Senate hearing at which Microsoft France's legal counsel Anton Carniaux, asked under oath whether he could guarantee French citizens' data would never reach US authorities, answered that he could not. The act still requires a warrant or court order and is encryption-neutral, but a limit you have to litigate is not a control you can cite in a data-protection assessment.
Four meanings of "EU", and only one changes the answer
The guide separates four things people call EU hosting. An EU region — a US provider's data centre inside the bloc — stays within US legal reach because the provider is US-controlled. An EU data-residency contract is a promise, and a contract does not override a US court order. A US hyperscaler's sovereign-cloud offering is contested: whether US law reaches it depends on ownership and the operational chain, which varies per product. Only the fourth level, a provider incorporated and controlled in the EU or EEA with no US parent and no material US operations, changes the jurisdictional answer. The EU's Tech Sovereignty Package of 3 June 2026 proposes formal assurance levels, the guide notes, precisely because the sovereign-cloud label alone communicates nothing.
The EU-US Data Privacy Framework is intact but strained
The framework remains in force, the guide says, though less stable than a year ago. On 3 September 2025 the EU General Court dismissed Philippe Latombe's annulment challenge (T-553/23), judged on the facts of the 2023 adequacy decision; he appealed to the CJEU in October 2025 — the court that struck down Safe Harbor and Privacy Shield. On 29 June 2026, in Trump v. Slaughter, the US Supreme Court held 6-3 that statutory removal protections for FTC Commissioners are unconstitutional, and on 31 July 2026 the EDPB asked the Commission to assess the consequences, since the adequacy decision expressly relies on FTC independence. The practical upshot: keep Standard Contractual Clauses and transfer impact assessments in place rather than leaning on the framework alone.
Legal risk and strategic preference are different projects
Legal risk concerns specific personal data and processing, scales with sensitivity — a marketing site logging IP addresses is not a health portal — and calls for a data map, a transfer impact assessment and changes to the layers that actually carry personal data. Strategic preference concerns supply-chain dependency, geopolitical exposure and where money goes; it is not proportionate to risk and can justify moving things that pose no legal problem at all. A preference dressed up as a compliance requirement, the guide warns, becomes a project that fails its own stated test.
Most US exposure hides in layers beyond hosting
The host is the layer everyone focuses on and usually the least interesting, the guide argues. Each layer is a separate contract and data flow. European options include Hetzner, IONOS, OVHcloud, Scaleway and UpCloud for servers; Bunny.net, Myra and KeyCDN (Swiss, an adequacy country) for CDN; deSEC, Hetzner DNS and INWX for DNS; self-hosted font files; Matomo, Plausible and etracker for analytics; Bunny Stream, Dailymotion or self-hosted PeerTube behind click-to-load facades for video; Brevo and Mailjet for forms and transactional email; self-hosted Sentry or GlitchTip with browser-side PII scrubbing for error tracking; and Mistral, Aleph Alpha and OVHcloud AI Endpoints for the AI layer.
Fonts are the cheapest win: in January 2022 the Landgericht München I awarded a visitor €100 in damages after a site pulled Google Fonts from Google's CDN, sending the visitor's IP address to the US without consent.
What going EU-only actually costs
The guide is blunt that the switch is not free. Europe offers strong infrastructure with a thinner managed-service layer and smaller ecosystems; error tracking and video hosting are the weakest alternatives; audiences outside Europe pay real milliseconds; and frontier US AI models still lead on some tasks. None of that is a dealbreaker for a content website, and several gaps can be for a global consumer product. The guide also discloses its origin: it comes from the team behind Neleto, a CMS with managed EU hosting on Hetzner, and the authors concede the product alone does not make a site GDPR-compliant.
Why it matters
The legal-versus-physical distinction is the one most teams get wrong, and it changes procurement: an EU region or residency add-on from a US provider buys mitigation, not a change of jurisdiction. With the Data Privacy Framework under active legal strain, transfers need redundant mechanisms rather than a single point of failure. And because most US exposure hides in unaudited layers — fonts, DNS, analytics, error tracking — a genuine move requires an inventory across the whole stack, not just a new hosting contract.
- #cloud
- #hosting
- #data-residency
- #gdpr
- #eu-sovereignty