Cloud Act Alternative: EU-Sovereign Cloud Hosting

Updated on August 4, 2026

A datacenter in Frankfurt or Paris does not put your data beyond the reach of US law. What decides that is who operates the service. Bunker is operated by a European entity with no US parent, subsidiary or presence, hosted in France under EU law, so it sits outside the scope of US production orders under the Cloud Act.

What if a US executive order cut off access to your cloud or your AI?

If a US order cuts your access, here is how to take back control: the Bunker stack is open-source, you export your data in open formats with no egress fees, you redeploy the same platform on European infrastructure or on your own servers, then you resume operations without depending on the original operator.

The US Cloud Act, passed in 2018, lets US authorities order any provider under US jurisdiction to produce the data it holds, regardless of where the servers physically sit. An AWS region in Frankfurt, an Azure region in Amsterdam, a Google Cloud zone in Paris: all three are operated by US companies, so all three fall under that order. FISA Section 702 adds electronic surveillance of non-US targets, and Schrems II (CJEU, 2020) struck down the Privacy Shield precisely over this conflict.

If you handle health records, financial data or public-sector files in Germany, Austria, the Netherlands or Switzerland, the question your DPO and legal team keep coming back to is simple: can a foreign authority compel access to this data? With a US-operated cloud, the honest answer is yes. Bunker changes that answer.

“No, I cannot guarantee it.”

Anton Carniaux, Director of Public and Legal Affairs, Microsoft France

Under oath before the French Senate inquiry committee, 10 June 2025, when asked to guarantee that French citizens' data would never be handed to US authorities.

Record of the French Senate inquiry committee (10 June 2025)

Why Bunker sits outside US jurisdiction

European operator, no US ties

Bunker is run by a European entity with no US parent company, subsidiary, branch or staff. There is no legal person for US authorities to serve a Cloud Act production order on. Jurisdiction follows the operator, not the flag on the building.

Hosted in France under EU law

Servers, storage and backups stay on French soil, governed by GDPR and French law. No transatlantic transfer sits in the data path, which removes the Schrems II problem at the root instead of papering over it with Standard Contractual Clauses.

Open-source and auditable

The stack is open source end to end: Kubernetes, PostgreSQL, Ceph S3 storage, private LLMs. Your security team can read the code, inspect the deployment and verify what actually runs. No black box, no proprietary control plane you have to take on trust.

Flat pricing, no egress fees

Pricing is flat and published. Pulling your data back out costs nothing, because there are no egress fees. That keeps exit cheap and reversibility real, instead of a clause you can never afford to use.

Bunker compared to the US hyperscalers

Criterion Bunker AWS Azure Google Cloud
Operator jurisdiction EU only (France) United States United States United States
Subject to US Cloud Act No Yes Yes Yes
FISA 702 exposure None Yes Yes Yes
Data location guarantee France, by operator Region setting only Region setting only Region setting only
Open-source and auditable Yes, full stack No No No
GDPR Art. 28 DPA Standard, no US transfer With SCCs With SCCs With SCCs
Reversibility No egress fees, self-hostable Egress fees apply Egress fees apply Egress fees apply

Why an EU region at a US provider does not protect you

AWS, AzureUS operatorEU datacenterEU operatorUS legal reachEU law only

This is the point most procurement checklists get wrong. Choosing eu-central-1 on AWS, or a Frankfurt region on Azure, controls where the bytes are stored. It does nothing about who can be ordered to produce them. AWS, Microsoft and Google are US companies, so a US court can issue a Cloud Act order against the parent, and the parent has the legal obligation to comply with data its European subsidiary holds. The datacenter being in the EU is irrelevant to that order. Microsoft has acknowledged in public hearings that it cannot guarantee EU data will never leave the EU under such a request. The physical address is a comfort, not a legal shield.

What actually moves the line is the jurisdiction of the operator. Bunker is operated by a European entity with no US parent, subsidiary or presence, so there is no US-reachable company that can be compelled to hand over your data. A foreign authority would have to go through European mutual legal assistance channels, before a European judge, under EU law. That is a different legal regime, not a contractual promise bolted onto a US service. Combined with hosting in France and an open-source stack you can audit, it gives your DPO and RSSI something they can document for a regulator rather than hope holds up under Schrems II scrutiny.

Microsoft 365 and Copilot are the worked example

The clearest case is Microsoft. In June 2025, before the French Senate inquiry committee, Microsoft France's director of public and legal affairs admitted under oath that he could not guarantee French citizens' data would never be handed to US authorities. His technical colleague added that keeping EU customer data in the EU since January 2025 is a contractual commitment, not a legal shield. In March 2024, the European Data Protection Supervisor had already ruled that the European Commission's use of Microsoft 365 infringed EU data-protection rules.

Copilot raises the stakes rather than lowering them. It processes your content in clear text, emails, documents and conversations, to generate its answers, so encryption at rest does not help once the data is decrypted for the model. According to several technical analyses, routing can send Copilot requests outside the EU data boundary, to datacenters in the US, Canada or Australia, when EU servers are saturated. Microsoft's own sovereign-cloud announcements move servers, not the operator's jurisdiction. A private AI hosted in France, on open models you control, removes the problem instead of relocating it.

Frequently asked questions

The Cloud Act: what is the concrete risk for a European company?

The risk is twofold. Legal first: a US authority can order a provider under US jurisdiction to produce your data, including data hosted in Europe, which puts you in tension with the GDPR (the Schrems II ruling). Operational next: a political decision or a sanction can suspend your access to a US service overnight. For healthcare, finance or the public sector, both risks now block entire projects.

What do I do if my US cloud provider cuts off my access?

Plan reversibility before the incident. In practice: keep a recent export of your data in open formats, choose an open-source stack you can redeploy elsewhere, and check that no proprietary component holds you back. With Bunker, the switch is built in. You retrieve your data with no egress fees and relaunch the same platform on European infrastructure or on your own servers, without starting over.

Does hosting in an EU AWS region protect me from the Cloud Act?

No. Selecting an EU region controls where your data is stored, not who can be ordered to produce it. AWS is a US company, so a US court can issue a Cloud Act order against it for data its European entity holds, wherever that data physically sits. The same applies to Azure and Google Cloud. To be outside that reach, the operator itself has to be outside US jurisdiction, which is the case for Bunker.

What makes Bunker outside the reach of US extraterritorial law?

Bunker is operated by a European entity with no US parent company, subsidiary, branch or presence, and it is hosted in France under EU law. There is no US-reachable legal person for authorities to serve a Cloud Act or FISA 702 order on. A request would have to go through European mutual legal assistance, before a European judge. We state this as a matter of legal structure, not as a claim of absolute immunity.

How does this relate to Schrems II and GDPR compliance?

Schrems II struck down the Privacy Shield in 2020 because US surveillance law, including FISA 702, conflicts with the protection GDPR requires. With a US-operated cloud, you carry that conflict and try to manage it with Standard Contractual Clauses and transfer impact assessments. With Bunker, your data stays under EU law with no transatlantic transfer in the path, so the conflict does not arise. A DPA aligned to Article 28 of the GDPR is available.

Can I run Bunker on my own servers instead of the managed offer?

Yes. The stack is open source: Kubernetes, PostgreSQL, Ceph S3 storage and private LLMs. You can take the managed service or install the same stack on hardware you control, including on-premise in your own datacenter. Because the components are open source and there are no egress fees, moving between managed and self-hosted, or out entirely, stays a practical option rather than a theoretical one.

Are Microsoft 365 and Copilot subject to the Cloud Act, even hosted in Europe?

Yes. Microsoft is a US company, so a Cloud Act order can reach data its European entity holds, wherever it is stored. Microsoft France admitted this under oath before the French Senate in June 2025, and the European Data Protection Supervisor ruled in March 2024 that the European Commission's use of Microsoft 365 infringed EU data-protection rules. Copilot adds exposure because it processes your content in clear text, and routing can push requests outside the EU data boundary. A sovereign collaborative suite and a private AI hosted in France remove that exposure.

Move your data out of US jurisdiction

Talk to our team about a sovereign cloud operated in France, with a GDPR Article 28 DPA and no transatlantic transfer.