ES version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
73% Positive
Analyzed from 2482 words in the discussion.
Trending Topics
#data#fastmail#act#more#cloud#still#own#email#https#company

Discussion (80 Comments)Read Original on HackerNews
as a german i feel the urge to point out that this technically also applies to european companies... With more hurdles for the US, but still technically applicable
> The CLOUD Act primarily amends the Stored Communications Act (SCA) of 1986 to allow federal law enforcement to compel U.S.-based technology companies via warrant or subpoena to provide requested data stored on servers regardless of whether the data are stored in the U.S. or on foreign soil.
[1] https://en.wikipedia.org/wiki/CLOUD_Act
- The US could request your data. You probably shouldn't use e-mail for anything sensitive anyway for many reasons. E-Mail was traditionally not encrypted and I think that many servers still allow plain-text communication. The protocols are old and there are all kinds of downgrade attacks. Aside from that, even if your service does not fall under the CLOUD Act, you are probably f*cked anyway, because most people you communicate with are using services that fall under the CLOUD Act.
- The US can force the provider to block your account. The workarounds are: regularly backup your e-mail (easy for services that offer IMAP) and, most importantly, use a domain with an extension that is not under the control of a US (or probably five eyes) registrar.
Use an E2E-encrypted messenger with perfect forward secrecy, etc. for most personal communication.
Fastmail used to be based in Melbourne only, but after the Pobox merger it ended up with an office in Philadelphia too. No idea how the balance of things is between the offices now.
Not that I don’t trust the statement, I just would like to know more.
https://thenextweb.com/news/airbus-scaleway-aws-sovereign-cl...
And many others besides, pretty much every company I've looked at in the last year is either acutely aware of the problem or they are already executing on it. With Trump and his merry band of criminals repeatedly stating they're going to take Greenland by force you can't blame them either, that would effectively put the EU on a war footing with the United States (I still can't believe I'm writing this sort of thing and it is not entirely fiction), the end result of that would be that there would be an absolute run on EU hosted capacity. They're just trying to beat the rush and hope they'll never be proven to be right.
Dutch Government moves cloud services to EU provider from US tech firms:
https://brusselssignal.eu/2026/04/dutch-government-moves-clo...
https://nltimes.nl/2026/04/24/netherlands-reaches-deal-europ...
Gov.uk has replaced Stripe with Dutch provider Adyen - https://news.ycombinator.com/item?id=48415217 - June 2026 (235 comments)
EU Banks Launch Wero Payments to Dislodge Visa, Mastercard - https://news.ycombinator.com/item?id=41666833 - September 2024 (88 comments)
https://www.justice.gov/criminal/criminal-oia/cloud-act-agre...
We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers.
If what you need is a guarantee that your data remains only in the EU, we don’t have that, and we’d rather tell you directly than let you assume otherwise.
* a physical thing that can only live in one place
* not copyable
* can be 'contained'.
The whole thing reeks of bureaucratic 'best practices' that just aren't.
Even worse than that, trying to keep email restricted to the EU (or anywhere else) means that you effectively wouldn't be able to communicate with anyone in a different region, which is kinda the whole point.
Why not just make your own internet next? and then you can disconnect from everyone else who is trying to hack you. Just pull your network plug.
Email itself is hopelessly insecure by design anyway. Not just metadata when you are E2EE everything inside the envelope, but even basic vulns like downgrade attacks are simple because it's literally a violation of the RFCs (so you're not spec-compliant) to require TLS or any other encryption.. Why? because requiring modern crypto might interfere with deliverability and backwards compatibility. The real, deeper reason is that email is from a kinder, simpler time (well, at least simpler) and the design goals were never updated to keep up with the times.
Email is what we have. Just understand its flaws and then use other tools where you can. And who cares where your email lives - it's too easy to break anyway.
In all seriousness though, what are the chances Fastmail won't require KYC at some point? I have sent them a support request with that question and got a non-answer.
PS: Am a paying customer for like a decade
The more concerning issue as far as Australian based tech is The Assistance and Access Act 2018 which
"...permits government enforcement agencies to force businesses to hand over user info and data even though it’s protected by cryptography.
If firms don’t have the power to intercept encrypted data for authorities, they will be forced to create tools to allow law enforcement or government to have access to their users’ data."
As far as i know this has not been challenged or walked back and with the rise of ChatControl like laws doesnt seem it will.
Side note, I moved to Fastmail a couple years ago, and so far I’ve been very happy with it! The Gmail migrator works great, too.
I feel that that's the whole point. And the whole point of them making this article/advertisement.
Do you only send and receive emails with people in the EU?
As of now there's no guarantee of... anything, really.
Obviously if you decide to send an email to the US you're choosing to send your data there, that's a strawman.
https://www.courthousenews.com/uk-faces-questions-on-complic...
Is there an alternative that really keeps data in the EU? (And not only in the sense it serves a sales promotion)
If that works fine if not, use another method of comm. Email wasn’t designed to be secure.
> Because of legal uncertainty around Swiss government proposals to introduce mass surveillance — proposals that have been outlawed in the EU — Proton is moving most of its physical infrastructure out of Switzerland.
https://proton.me/blog/lumo-ai
They are moving to Germany, but will quickly find that they are going to face the same surveillance and privacy issues since the EU is in the process of negotiating a data sharing agreement under the US Cloud Act.
https://www.justice.gov/archives/opa/pr/justice-department-a...
> Built by us, not rented from someone else
> We’ve installed our own servers, co-located in a secure facility in Amsterdam, set up by our own engineers. This new location is built to the same high standards as our existing infrastructure in Philadelphia and St Louis, with our own hardware and our own software — specified right down to the exact model of disks in each machine.
> In all our locations, data is stored encrypted at rest inside locked racks, and managed by our in-house team. We don’t rent computing or management services from a big cloud provider and pass on their assurances. That’s how we’ve approached privacy, reliability, and performance for more than 25 years.
"Resilient replicas of your data will live in the US"
?
I think "resilient" just means "backup copy" and I do think (IANAL) it is illegal to destroy emails when asked for them in the US.
Or was your comment ironic? Sorry, German, irony impaired.