

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- As long as the company's legal headquarters are in the U.S., U.S. agencies have access to the data under the Cloud Act—and non-U.S. citizens have absolutely no legal recourse when it comes to U.S. servicesby doener
- their HQ is supposed to be in Melbourne, Australia
They mention it only briefly in their publication. Their about page is clearer about that.
by hinata08 - The local government cannot get access to the servers in Amsterdam?
I use Fastmail but just consider it safe from third party advertisers. If I wanted safety from governments I would use something else, or at least encrypt my email contents.
by user00005 - Unfortunately, even if all data lives in the European Union, as long as a company is conducting business in the US, the Cloud Act makes it possible to compel them to hand over any information. This can include making administrative personnel sign NDAs or face heavy repercussions. Conducting business in the US includes advertising to US citizens e.g through maintaining a website in English.
At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.
by _tk_ - I am pretty sure that European states are already storing data that is out of reach for the US government, and I don't understand how Congress could legislate against this, short of an act of war.by telmo
- > Resilient replicas of your data will live in the US (for now). As we only have one location in Europe so far, the geographically separate copy will remain on servers in one of our US locations.
Wow, it's nothing. How about writing your PR after the data is not going to the US at all?
by zecg - Isn't it a step in that direction? The first data centre in Europe shows a commitment and it will likely be easier to do the next data centre(s).by tikkabhuna
- Does it matter much? From one side, you are still in the 14 eyes countries (in fact, I would trust a Chinese server if i am living in the west and vice versa), on another side, emails as a protocol was never meant to be secure or private, so deal with it as that, if you are after private or secure communication, choose a protocol that provides that, adding more stuff to emails will only complicate it further plus giving false sense of privacy/security, gpg will leak meta data, receiver email server/client might expose you too, among many gaps, so just avoid it. Still, make sure your email spf dkim dmarc etc are set properly and carry on.by tamimio
- Seeing a lot of detail in the comments about the CLOUD act which applies as they(fastmail) themselves have an equivalent that was signed between USgov and Australia.
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
by rzerowan - The article you're quoting [1] concerns itself with the creation of systemic "encryption-breaking" capabilities and exploits which said law bends over backwards to expressly prohibit [2].
[1] https://fee.org/articles/australia-s-unprecedented-encryptio...
[2] https://classic.austlii.edu.au/au/legis/cth/consol_act/ta199...
by denismi - The Assistance and Access Act is completely irrelevant to Fastmail, because Fastmail doesn’t offer end-to-end encryption. Fastmail was always subject to the Telecommunications Act, which allows Australian police access with warrants, and Fastmail has always made it clear that it complies with legal warrants.by chrismorgan
- I call this "sovereignty washing": American companies pretending they can magically free themselves from the U.S. CLOUD Act by setting up a paper European presence.
Anyone who falls for this is a fool wanting to be fooled.
by hn_submit - Fastmail is Australian though.by jnrk
- Interesting take considering Fastmail is very clearly not an American company.by pigbearpig
- Nice, as a European customer, I appreciate this.
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
by cube2222 - Love them, but I wish they had a way to upload new sieve rules via an API. I'm probably going to try them with my own domain at some point since I think they have an option to just deliver all mail bound for that domain, which makes setting up random emails for dodgy sites really easy.by EPWN3D
- Or you can just use any of the actual European companies (I’m using Tuta).by tumdum_
- Infomaniak is another one https://www.infomaniak.com/en/ksuiteby nicolas_
- I started using tuta until I realised they don't support IMAP. Something to do with not guaranteeing encryption (which isn't even enabled by default) but has the convenient effect of locking you into their appsby dwedge
- Any providers that don't provide SMTP/IMAP/JMAP are just a boring way of giving away control over your mail and the client software you use.
I don't know about Tuta specifically, but Protonmail is practically intentionally hostile against anyone using their own keys. Which is the biggest sign that their marketing and actual intent do not align.
by Avamander - Posted on the previous submission for this: it’s a good start, but from the article:
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
by robin_reala - One needs multiple data centers in europe for backup and DR, sounds like they have one
- Wow they completely missed the ball on why people want reassurances that their data stays in the EUby intothemild
- EU folks, note the warnings threaded throughout this post: this is not currently any sort of panacea against US or AU data hosting risks, but it will make your data noticeably closer to home. Fastmail (Australia) merged with Pobox (Philadelphia) resulting in a complex tri-national law/risk surface when the EU is involved, so go in eyes wide open having read this in full. That everyone will overinterpret “EU data region” to mean “for privacy” here until reading the article is completely understandable; I empathize, having done the same.by altairprime
- I think it's not unreasonable to see this as a first, positive, step.
It's certainly giving them some benefit of the doubt, but it doesn't seem unreasonable that, say, the EU server and the US backup will in some time be an EU server and an EU backup.
- EU data regions are a reflexive action by companies that try to hold on to their EU customers (and more and more are leaving, surprisingly the larger ones seem to be leading here). Realize that as long as you are still hosted on US owned infrastructure or that if there are US (or: five-eyes) owned companies anywhere in the stack your data can still be forcibly pulled and often without you being aware that this happened. There are only very few such stacks that are 100% owned by EU entities.by jacquesm
- Can you point me towards some resources that show EU customers moving?
Not that I don’t trust the statement, I just would like to know more.
by rufasterisco - Does this still apply if there are separate legal entities for US & EU operations? Take Hetzner as an example. They have a separate US company to deal with their US data center. Would their EU servers be vulnerable to the CLOUD Act?by kisamoto
- The French head of Microsoft ctor not, under oath, say that Microsoft can guarantee sovereignty. This is the evidence that until you have a EU company, under EU rules and not present in the US at all, you cannot have sovereignty.
- EU sovereign clouds are taking off right now - especially when it comes to sensitive data (government, healthcare, etc.). Lots of players moving into the space. The common denominator - nothing touches the US.
AWS, Azure, GCP, Oracle, Schwarz Digits, SAP
by DarrenDev