A Website Without US Cloud: EU Hosting and Digital Sovereignty
“Where does our data actually live?” has moved from compliance footnote to board-level question. Between the CLOUD Act, shifting privacy frameworks, and the debate about digital dependence, more and more companies are asking whether their website really has to run on US infrastructure. The short answer: it doesn’t – and the switch is easier than the debate sounds. This article sorts the legal landscape into plain language and shows what a website entirely on EU services looks like.
The usual boundary up front: we are developers, not lawyers – this article explains the technical and practical side. The legal assessment of your case belongs to your data protection officer.
What this is really about: three different questions
The location debate likes to mix three things that belong apart:
- The legal question. Transfers of personal data to third countries need a basis under the GDPR. For the US, one exists – via the data privacy framework and standard contractual clauses – but it has history: two predecessor agreements were struck down by the European Court of Justice. Building on US services means building on a basis that can change.
- The access question. The CLOUD Act obliges US providers to hand data to US authorities on order – even when it sits on EU servers. That is why “EU region at a US hyperscaler” only half solves the problem: server location changes latency, not the provider’s jurisdiction.
- The dependence question. Sovereignty also means: how easily do you get out again? Pricing changes, discontinued products, account suspensions – anyone bundling website, mail, and backups with a single large provider negotiates from the weaker position in the future.
For most business websites, the pragmatic consequence: choose EU providers where they are equivalent – and for hosting, they practically always are.
The good news: a website needs no US cloud
A business website consists of a handful of services – and each has an equivalent EU option:
- Hosting: Hetzner, Mittwald, IONOS, All-Inkl – German data centres, German contracts, DPA included. What matters in hosting generally is covered separately; we recommend without commission.
- Fonts: self-host Google Fonts instead of loading them from Google’s servers – standard since the 2022 Munich ruling anyway. Costs nothing, removes one data flow per page view.
- Analytics: Matomo (self-hosted or EU cloud) instead of US services – or the honest question of whether server logs and Search Console haven’t long been enough.
- Backups: on German storage servers, separate from the hosting – exactly how we do it in our WordPress maintenance with a storage box in a German data centre.
- The website’s outgoing email: via your own hosting or European SMTP services instead of US mail APIs.
- CDN & external scripts: often entirely dispensable with static sites – our own website loads no external services at all. Where a CDN is needed, European options exist.
The pattern behind it: the fewer dynamic third-party services a website needs, the easier sovereignty becomes. A static architecture (with Astro, for instance) has a structural advantage here – no reason for US SaaS when the site consists of pre-built files on a German server.
Where it gets harder – named honestly
Three places where the pure doctrine rubs against practice:
- Cloud headless CMS: many SaaS CMS host in US regions by default; EU hosting often only comes in higher tiers. Self-hosted open source (Strapi, Directus) or Git-based content solves it – the trade-off is covered in the GDPR headless article.
- Mailboxes and office suites: moving away from US office suites is its own, larger project – and doesn’t belong in a website budget. For now it suffices that the website itself can be sovereign, even if the office package isn’t (yet).
- Reach services: embedding YouTube videos or using US marketing tools brings the third-country question back – then with a consent solution that genuinely blocks before consent.
The pragmatic roadmap
- Take inventory: which external services does your website load today? (Browser dev tools, network tab – or our privacy tech check does it for you.)
- The easy switches first: fonts local, backups to Germany, analytics to Matomo or dropped.
- Move hosting at the next natural moment: a hosting migration rarely pays off as an end in itself, but during a relaunch or provider trouble it is a side step instead of a project.
- Document: a current register of services and DPAs turns the next privacy inquiry into routine instead of research.
An honest conclusion
Digital sovereignty is no ideology project for a business website – it is a series of unspectacular decisions: German host instead of hyperscaler, local fonts instead of Google’s servers, Matomo instead of US analytics, backups in a German data centre. None of it costs noticeable comfort, and in sum the third-country questions disappear from your privacy policy instead of having to be defended there. Our own website runs exactly this way – not out of dogma, but because it is the simpler position.
Want to know which services your website actually loads today – and what a switch would cost? We check it honestly and provider-independently: drop us a line.
Frequently Asked Questions
Is hosting with US providers possible in a GDPR-compliant way?
Formally it can be – via the current data privacy framework and standard contractual clauses. Practically, a structural tension remains: US providers are subject to the CLOUD Act, which can give US authorities access to data even when it sits on EU servers. Anyone who wants to avoid that residual uncertainty and the documentation effort chooses providers with both seat and servers in the EU – then the question never arises.
What does digital sovereignty mean for a business website?
Control over where your data lives, which law it is subject to, and how easily you can switch providers. Concretely: hosting, email, backups, fonts, analytics, and consent services with European providers or self-operated – plus the ability to move with your data at any time. Sovereignty is not an anti-US statement; it is risk management.
Which EU hosts are suitable for business websites?
For the typical business website: German providers like Hetzner (strong hardware, fair prices), Mittwald (managed WordPress, German processing), IONOS, or All-Inkl. All offer servers in Germany, German contracts, and DPAs. We recommend without commission – which one fits depends on the use case, not the name.
Is an EU server at a US provider enough?
Only half. The server location solves the latency and data-path question, not the legal one: a US company remains subject to the CLOUD Act no matter where its data centres stand. Anyone taking location seriously therefore looks at two things – where the servers are AND where the provider is incorporated.
Related Services
Founder & Full-Stack Developer
20+ years of web development experience. Specialised in Laravel, WordPress and custom software for mid-sized businesses.