Danish hosting or US cloud? Schrems II explained for business owners
What Schrems II, the CLOUD Act and the Data Privacy Framework mean for where your website's data lives, explained for business owners rather than lawyers.
This article was translated from Danish. Read the original.
If your website, webshop or app stores customer data with a US-controlled cloud provider, you are relying on a legal arrangement that has been struck down twice and is being challenged a third time. Hosting in Denmark or elsewhere in the EU, with a European provider, sidesteps that entire problem: no transfer mechanism to defend, no adequacy decision to keep an eye on, no CLOUD Act exposure through a US parent company.
That is the short version. The longer version involves two court rulings, one US law and one fragile political agreement. It is worth understanding, because “where is our data hosted?” is a question your customers, your larger clients’ procurement departments and possibly Datatilsynet will ask at some point.
I look after security and GDPR at NBS. This is the walkthrough I give clients who ask what the fuss is about. We are developers, not lawyers; treat this as background for a business decision, and get a data protection lawyer involved for anything binding.
What the law actually says
GDPR does not require your data to stay in the EU. It requires that personal data transferred outside the EU/EEA keeps an “essentially equivalent” level of protection. Transfers to the US are only lawful through an approved mechanism, and the history of those mechanisms is the whole story.
Safe Harbor (2000–2015). The first EU–US transfer framework. The Court of Justice of the EU (CJEU) invalidated it in 2015 in Schrems I, after Max Schrems challenged Facebook’s transfers in light of the Snowden disclosures about US surveillance.
Privacy Shield (2016–2020). The replacement. In July 2020 the CJEU invalidated that too, in the ruling known as Schrems II. The court’s reasoning: US surveillance law (notably FISA Section 702 and Executive Order 12333) lets intelligence agencies access data held by US providers in ways that are not limited to what is strictly necessary, and EU residents have no effective legal remedy against it. Data in US hands therefore did not enjoy essentially equivalent protection.
Standard Contractual Clauses (SCCs), after 2020. Schrems II left SCCs, contract templates between you and the provider, technically valid, with a catch: you must assess, case by case, whether the destination country’s laws undermine them, and add supplementary measures if they do. For US providers subject to surveillance law that assessment is genuinely hard, because no contract clause binds the NSA.
EU–US Data Privacy Framework (2023 onwards). In July 2023 the European Commission adopted an adequacy decision for the DPF, restoring a general legal basis for transfers to certified US companies after the US introduced new safeguards (Executive Order 14086 and a redress mechanism). That is the current position: transfers to DPF-certified US providers are lawful today. But the DPF is contested. Challenges are under way, privacy groups including Schrems’ organisation noyb argue it does not fix what the CJEU objected to, and the US safeguards rest on an executive order that any US administration can weaken or revoke. Many European privacy professionals treat a third strike-down as a realistic scenario rather than a hypothetical one.
The pattern matters more than any single ruling. Every framework so far has been an attempt to paper over a real conflict between EU fundamental-rights law and US surveillance law, and that conflict has not gone away.
Two Danish cases that show it is not theory
Datatilsynet is not known for being trigger-happy, but it has taken the transfer question seriously twice in ways that matter for ordinary businesses.
The Chromebook case (Helsingør Municipality, 2022). Datatilsynet banned Helsingør Municipality from using Google Chromebooks and Google Workspace for Education in its schools, because the municipality could not document that pupils’ personal data was protected against transfer to the US without a lawful basis. The case dragged on for years, and the ban was later lifted after Google and the municipalities changed the setup. But the message stood: “we use a big, reputable US provider” is not in itself a risk assessment.
The Google Analytics statement (September 2022). Following the Austrian, French and Italian authorities, Datatilsynet concluded that Google Analytics, as configured at the time, could not be used lawfully without supplementary measures, and that Danish organisations should either stop using it or implement measures such as a reverse proxy that strips identifying data before it reaches Google. We cover the analytics side in web analytics without cookies.
Both cases predate the DPF, and both were about the transfer, not about the tool being bad. That is exactly the point: the legal footing of the transfer is what keeps shifting.
The CLOUD Act: why server location alone does not save you
Here is the part that surprises most business owners. The US CLOUD Act (2018) allows US law enforcement, with appropriate legal process, to compel US-based providers to hand over data in their possession, custody or control, regardless of where the data is physically stored. A US hyperscaler’s data centre in Frankfurt or Copenhagen is still within reach of a US warrant served on the parent company.
So “we chose the EU region” on a US cloud platform addresses latency and, partly, the optics of data residency, but it does not remove US jurisdiction. The provider is still a US company; the CLOUD Act follows the company, not the server. The big US clouds have introduced “sovereign cloud” offerings and EU entity structures to mitigate this. How well those constructions hold up is exactly the sort of question that is legally unsettled and worth a lawyer’s opinion if it is load-bearing for your business.
To be fair about scope: CLOUD Act requests target criminal investigations, not mass surveillance, and the average Danish webshop’s order data is unlikely to interest US authorities. The problem is legal and commercial rather than practical. It complicates your transfer assessment, it is an awkward line in a procurement questionnaire, and it puts your compliance position at the mercy of litigation you do not control.
A practical comparison
| Question | European provider, EU jurisdiction | US provider, EU region | US provider, US region |
|---|---|---|---|
| Transfer mechanism needed | No | Contested, because of CLOUD Act reach | Yes (DPF, or SCCs plus assessment) |
| Survives a DPF invalidation | Unaffected | Partly exposed | Directly exposed |
| CLOUD Act exposure | No (no US parent) | Yes, via the parent company | Yes |
| Procurement friction | Low | Medium | High |
| Latency for Danish visitors | Good | Good | Worse |
| Typical cost for small workloads | Comparable | Comparable | Comparable, plus transfer risk |
The last row deserves emphasis. For websites, webshops and typical web apps, European hosting is price-competitive with US hyperscalers and often cheaper. There is no shortage of options: Danish providers such as Simply.com and DanDomain, European ones such as Hetzner, OVHcloud and Scaleway, or your own server at a European provider running an open-source deployment platform like Coolify. Which one fits depends on what you run; none of them requires you to argue about US law. The trade-off used to be a thinner catalogue of managed services, which is real if you need an exotic managed database and irrelevant for the workloads most businesses actually run.
What it means for different businesses
A local business website collects modest personal data: contact forms, perhaps visitor statistics. Your legal risk is low either way, but EU hosting makes your privacy policy one paragraph shorter and one hedge weaker, and self-hosted fonts plus cookieless analytics remove the most commonly criticised issues entirely.
A webshop processes customer identities, addresses and order histories at scale. Transfer questions apply to every processor in the stack, not just hosting: payment, shipping, e-mail, analytics. We cover the full stack in the GDPR checklist for webshops.
A SaaS company has it hardest. Your customers’ data processing agreements pass their obligations through to you, and “where do you host?” appears in every serious procurement process. EU hosting turns a recurring negotiation into a tick box, and data residency clauses in customer contracts increasingly demand EU processing outright.
The honest argument for just using EU infrastructure
You can build a defensible legal position on US cloud today: rely on the DPF, sign SCCs as a fallback, document a transfer impact assessment, monitor the litigation. Plenty of competent companies do exactly this.
Our view, as three developers who have to stand behind what we ship: that is a lot of ongoing legal machinery to defend a choice that, for most Danish businesses, buys nothing. European providers deliver equivalent performance and price for standard workloads. Choosing them collapses the whole question. No adequacy decision to monitor, no supplementary measures to document, no exposure if a Schrems III lands. Compliance by architecture is cheaper than compliance by paperwork, and it does not expire when a court rules.
That is why everything we build runs on hosting in the EU under EU jurisdiction by default. It is not an add-on. A five-page website costs DKK 3,995 one-time (Start), and operations, hosting and security cost from DKK 375 a month (Basis), all excluding VAT; see prices. The same default applies to websites, webshops and web apps.
If you already have a site on a US platform, moving it is usually a day or two of work, not a project. We look at what you run, pick a European provider that fits, move the site and the domain, and hand you the keys. You can read about why owning your own setup matters in do you own your website?.
Frequently asked questions
Is it illegal to use AWS, Google Cloud or Azure in Denmark? No. Under the current Data Privacy Framework and with proper contracts it is lawful. The concern is robustness, with ongoing challenges to the DPF and CLOUD Act jurisdiction, not present-day illegality.
Does an EU region on a US cloud make me GDPR-compliant? It helps with data residency and latency, but it does not remove US jurisdiction over the provider. Whether that constitutes a transfer requiring safeguards is one of the actively debated questions, and regulators, Datatilsynet included, have leaned towards caution.
What happened in Schrems II, in one sentence? In July 2020 the CJEU invalidated the EU–US Privacy Shield because US surveillance law prevented US providers from guaranteeing EU-equivalent data protection, while leaving SCCs valid only with case-by-case assessments.
Could the Data Privacy Framework be struck down? It is being contested in court, and both of its predecessors were invalidated. Nobody can promise an outcome; prudent architecture does not depend on one.
Do I need a lawyer? For a small site on European infrastructure, the standard compliance basics generally suffice. If you transfer personal data to US providers at scale, sign enterprise data processing agreements or process sensitive data, yes: get a data protection lawyer’s assessment. This article is technical background, not legal advice.
Why us
Cheaper than most, and not worse for it
We are three developers. No project managers, no salespeople, no open-plan office downtown. That overhead is what you would otherwise be paying on top of the work itself, and it is why we can keep the price down on websites, webshops, web apps and mobile apps alike. Every price is published and fixed in writing before we start — from DKK 375 a month or DKK 3,995 one-time. See prices.
Cheaper does not mean less. We build and run our own products: NBS Booking, NBS Food and the KalorieTracker app, which is live in the App Store and Google Play. So we have already paid for the mistakes we advise you about. You talk to the person writing the code, and you own the code afterwards. If you want to move on without us, you can.
