Posted by groomlake 16 hours ago
It stops just short of saying that you must do thispreemptively, but is pretty clear that you must do it if they ask you to.
I admit it is a concern, as a Fastmail user, but this discussion only seems to happen on the Fastmail threads, yet no one bats an eye if one is suggested to open a gmail account like everybody else.
as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
(At least that's what people keep telling me, im not a lawyer)
Which I may add: you could've easily found out yourself too if you looked up what I wrote.
The Trump regime a way more corrupt than anything currently seen in Europe.
He currently attempting to steal Greenland so he can strip it of mineral assets for fucks sack.
No politician in Europe is starting wars for personal gain.
Only Trump and Putin.
Just because you disagree with a law, that doesn't make it "corruption" - it does make you an authoritarian that attacks democracy as soon as other people don't vote like you want.
If the law is initiated by the parliament and not by some company through lobby. Lobby is corruption.
Please stop spreading fabrications - even when you dislike the result. That's fascist behaviour.
- Elections are so rare (every 5 years) and encompass so many huge life-altering choices (VDL being one of the criteria only) that it's not democratic. The Swiss vote every important law, like "Should we buy fighter jets".
- De facto, party health is part of democracy (look at the Rwanda: It is absolutely possible to have a genocide made by democracies, and it is in fact more frequent than dictatorships) and network effects have made that European parties don't represent the people's will,
- Europe dispatches money to countries that need convincing, like Scottland, while wearing the mature members' citizen to the bone. We can't even have decent roads or internet here, while newcomers are super-happy to join ("I'm happy because Europe brought wealth and economic development!!!" - yeah look in 20 years). Money flushing around Europe trying to bribe citizens groups into staying, which makes opposition impossible. The EU is too chicken to let citizen vote every 20 years on whether we should stay in Europe, because then answer would be a big NO.
- The kill switch didn't even work, countries can't leave, or there is retaliation. Not only UK but France voted against the new treaties in 2005, the president still signed them.
The EU is the most lazy level of democracy. It's a knee-jerk reaction to say that VDL can be removed from office by the citizen.
Rwanda has never been a democracy. Habyarimana was "elected" with 99% of the votes ffs.
> and it is in fact more frequent than dictatorships
It is trivially easy to verify that this is not true.
I suggest you show up for next EU election if you don't like the option.
It is worth remembering at this point how von der Leyen first became Commission President. She was controversially nominated by the European Council - who are not directly elected representatives within the EU system - deviating from the spitzenkandidat convention in a way that surprised and angered many MEPs - who are. Her own national government (Germany) did not support her in the Council voting because one of the parties in the governing coalition opposed her. She was eventually confirmed by a narrow majority in a secret ballot of the European Parliament from which little can therefore be determined about who did or didn't vote for her except that quite a lot of MEPs who were expected to support her candidacy based on public statements did not in fact do so in the secret vote.
So she was essentially proposed by a group of people who aren't directly elected at EU level and in some cases aren't even directly elected by the nations they represent - in violation of the normal convention expected by the only people who are directly elected at EU level - and was then narrowly confirmed by that directly elected group only in a secret ballot from which the vote of each individual representative was not recorded and there is therefore no possibility for their own electorates to hold those representatives to account personally for how they voted. Given that we are talking about the most influential political post in the EU this is not exactly a powerful demonstration of democratic legitimacy and a clear popular mandate no matter how you look at it.
Everything else she does needs to be confirmed by representatives of your own member state.
Just like EVERY OTHER democracy.
The next election is in 2029. I suggest you show up instead of spreading fabrications online.
And as the Americans are choosing to interfere in European domestic politics and trample their own laws and constitution the more scrutiny their requests will get.
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
It's unfortunate for us, but we very rarely isolate individual government systems for other nations.
It was the MLAT thing that the various civil liberties groups object to (I'll cover the problems with those down below). There was very little objection to the first part.
The first part was not controversial because pretty much every country has something equivalent (for reasons I'll cover below), as did the US except specifically in the case of data covered by the SCA due to poor drafting.
One of the big reasons for the SCA was created was the emerging "third party doctrine" meant that instead of having to get a warrant or subpoena against you to get your data they could simply subpoena it from any of your service providers that had it. The SCA made it so the third party doctrine subpoenas would not apply to stored communications.
There were still cases where the government would need to compel the service provider to turn over the data. They wanted something with the probable cause requirements of a warrant but the delivery method of a subpoena. (A subpoena asks someone who controls the data to turn a copy over. A warrant is for when the government wants to raid the data center and seize the data. Since that involves the government directly acting where the data is located it only applies to someplace where they have jurisdiction).
So they created a new thing, the SCA warrant. The called it a "warrant" because it had the probable cause requirements of a warrant, but neglected to add something saying that in other respects it functions like a subpoena. I'll call this a pseudo-warrant.
The SCA was not the first pseudo-warrant. That would be the warrants under the Wiretap Act of 1968. Territoriality questions did not arise under that because by its nature the data it sought copies of was always in the US.
With the SCA the data might not necessarily be in the US. Years later Microsoft argued that because it is a "warrant" it should have the territorial restrictions that normal warrants have. The CLOUD Act clarified that it was indeed supposed to be like a subpoena as far as territoriality goes.
There have been some more pseudo-warrants created since then, but their drafters learned from the SCA and made sure the original legislation was clear on just what they were.
The reason pretty much every country has something like that, going back well before online documents, is because not having such a thing leads to big problems. If anyone in the country could shield documents from subpoenas (or whatever the equivalent is called in that country) by merely storing them across a border every company with documents that it needs to keep but that might be incriminating later would get sent to a storage facility across a border as soon as they were no longer actively using them.
For example as soon as a car company in Detroit releases a new car all the documents where during development engineers brought up safety concerns which management decided to not address would be sent across the bridge to a storage facility in Canada.
With electronic documents it is even easier. You would not have to wait until you aren't actively using the documents to stick them outside the country. Just stick your file server across a border and make sure you only have copies in country when someone is actively reading or editing them.
And so pretty much everywhere subpoenas compel someone in the country who controls the documents to fetch them (or copies) and turn them over. The actual location of the documents is completely irrelevant.
The thing that was worrying about the CLOUD Act was the MLAT provisions. MLATs are treaties where the participating countries agree on law enforcement. They include things like sharing information and cooperating on investigations. Normally these are enacted just like any other treaty. The executive branch negotiates them and then the Senate votes on ratification.
The CLOUD Act adds an expedited process where the Attorney General and the Secretary of State can sign an MLAT. Congress is not involved. These agreements allow foreign law enforcement to make requests directly to US service providers instead of going through the diplomatic channels normal MLAT requests go through, and they allow them access to stored communications that the SCA would normally block.
There are some safeguards. The foreign government is not supposed to intentionally target US people who are in the US and are not not supposed to use the data they get to infringe freedom of expression. There's also a 180 day window before these executive MLATs take effect during which Congress can block them by passing a joint resolution to do so.
Civil rights groups and many others were not impressed with those safeguards.
Even the entire EU is in the process of negotiating the same agreement.
https://www.justice.gov/archives/opa/pr/united-states-and-ca...
https://www.justice.gov/archives/opa/pr/justice-department-a...
You can read the text right here:
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
The same agreement is in place with the UK. Canada and EU are currently in the process of negotiating it.
Things have changed. With Chinese law in regards to data within Chinese jurisdiction a long-standing thing and an unfriendly American government potentially in power for an extended period, other countries are realizing the importance of data sovereignty.
> The latter states that negotiation with the EU on this topic was suspended in 2019.
Dated 2023:
> Justice Department and European Commission Announces Resumption of U.S. and EU Negotiations on Electronic Evidence in Criminal Investigations
The negotiations are still ongoing. Canada is further along than the EU.
The Five Eyes is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperation in signals intelligence.
Does fastmail have a US presence? If no - then they're not bound at all by US jurisdiction.
See: https://roncobb.net/img/cartoons/aus/k5092-on-Tucker_Box-cuu...
The question is: do they office services to residents of said country / state.
If so they may well be subject to certain laws that, if broken, could result in penalties up to an including extradition of the responsible officers.
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
AWS, Azure, GCP, Oracle, Schwarz Digits, SAP
Like, the critical problem with the AWS sovereign pitch is that you must believe that they won’t give the keys to the US, and they also won’t give the source code that’s hosted in the US to the government either for them to find vulnerabilities in. I don’t know if that’s good enough unless you just need the data to stay in the EU and you don’t care if another country sees it.
I know they probably did some work on it (what if primary AWS goes rogue and the EU entity must work without it) but I don’t know if they explained how they’re safe to the public.
I am assuming the reason companies switch to them is not price or tech. US cloud providers have the advantage on both.
Selling EU companies data would mean destroying trust over their main selling point, not to mention incur on EU wrath.
Feels like living one whistleblower away from doom.
I refer to fully EU clouds, parent list includes US clouds that do not need bags of money, Clouds Act in enough.
What? Those are US companies, they will have to give out your data under the Cloud Act. Only Schwarz and SAP are free from that by being German companies.
Not true. You also have to be sure that the company directors will never travel to the US even for a holiday or any third party country that would uphold an extradition request from the US.
It's just email. Nobody is going to jail to protect your email.
If you care that much run your own email server.
All the added eyes are European (Denmark, France, the Netherlands, Norway; Germany, Belgium, Italy, Spain, and Sweden)
Not that I don’t trust the statement, I just would like to know more.
https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cl...
And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right.
Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments)
Netherlands reaches deal with European cloud company to decrease U.S. tech reliance - https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ... - April 24th, 2026
Wary of US Big Tech, the EU looks to build its “EuroStack” - https://sherwood.news/world/wary-of-us-big-tech-the-eu-looks... - March 18th, 2026
Why European Companies Are Leaving US Cloud Providers in 2026 — And Where They're Going - https://massivegrid.com/blog/european-companies-leaving-us-c... - March 12th, 2026
Europe gets serious about cutting digital umbilical cord with Uncle Sam's big tech - https://www.theregister.com/off-prem/2025/12/22/europe-gets-... - December 22nd, 2025
Schleswig-Holstein waves auf Wiedersehen to Microsoft stack - https://www.theregister.com/software/2025/10/15/schleswig-ho... - October 15th, 2025
EU Banks Launch Wero Payments to Dislodge Visa, Mastercard - https://news.ycombinator.com/item?id=41666833 - September 2024 (88 comments)
EU-US Data Transfers: First Reaction on "Latombe" Case - https://noyb.eu/en/eu-us-data-transfers-first-reaction-latom... (2025-09)
EU-US Data Transfers: Time to prepare for more trouble to come - https://noyb.eu/en/eu-us-data-transfers-time-prepare-more-tr... (2025-12)
US Supreme Court just blew up EU-US Data Transfers - https://noyb.eu/en/us-supreme-court-just-blew-eu-us-data-tra... (2026-06)
I was up to date on noyb, but not aware that actually companies are moving at this speed and size.
Thanks all for some great resources
Similar happened already with OVH Canada vs France.
> In an affidavit, Xavier Barriere, corporate counsel at OVH in Paris, describes the dramatic situation: If the important proponent of European data sovereignty were to comply with the Canadian order, those responsible in France would be committing a criminal offense. They face up to six months in prison and fines of up to 90,000 euros per violation. However, if OVH ignores the Canadian court, it faces contempt of court proceedings in Ontario, which can also lead to severe sanctions.
https://www.heise.de/en/news/Canadian-Court-OVHcloud-from-Fr...
And one comment here: https://news.ycombinator.com/item?id=46060903
A difference could be that Germany might not have such blocking law as France. At least I have never heard of it.
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers.
Swiss corporation with data centers in Luxembourg.
Source: I founded FastMail.
Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now.
It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
Did they say what's stopping them from using that (and requiring the encryption!)?
So it "breaks end to end encryption" even with smtps and imaps apparently. The few emails I received weren't from tutamail users so presumably came over SMTP.
It's confusing to know what they mean because they confuse terms. They say emails are "stored end to end encrypted".
They don't pass my smell test
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
[1] https://fee.org/articles/australia-s-unprecedented-encryptio...
[2] https://classic.austlii.edu.au/au/legis/cth/consol_act/ta199...
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
https://www.courthousenews.com/uk-faces-questions-on-complic...