How to Host a Website Without US Cloud Providers (And What Actually Counts as 'EU')
An EU data centre is not the same thing as being outside US legal reach. Here is the difference, layer by layer.
Someone has asked whether the website can move "off American infrastructure." The honest answer starts with a correction: where the servers physically stand matters less than who legally controls the company running them. A rack in Frankfurt owned by a US corporation is still reachable by US law.
Does hosting in an EU data centre put you outside US legal reach?
No. Physical location is one factor among several, and on its own it decides very little.
The US CLOUD Act (2018) lets US authorities compel a provider under US jurisdiction to hand over data in its "possession, custody, or control," regardless of where the data sits. That reach extends to US parent companies and, in practice, their European subsidiaries.
This isn't theoretical. On 10 June 2025, Microsoft France's legal counsel Anton Carniaux was asked under oath in a French Senate hearing whether he could guarantee French citizens' data would never reach US authorities. His answer: "Non, je ne peux pas le garantir." The limits are real: a warrant or court order is required, and the act is encryption-neutral. But a limit you have to litigate isn't a control you can cite in an assessment.
What actually counts as "EU"?
"EU" is used for four different things, and mixing them up is where most bad decisions start.
| Level | What it means | Does US law reach it? |
|---|---|---|
| EU region | A US provider's data centre located in the EU | Yes, the provider is still US-controlled |
| EU data residency contract | Contractual promise that data stays in the EU | Yes, a contract does not override a US court order |
| US-branded "sovereign cloud" | A US hyperscaler's EU-operated, sometimes locally-partnered offering | Contested. Depends on the ownership and operational chain, which varies per product |
| EU-controlled provider | Incorporated and controlled in the EU/EEA, no US parent, no material US operations | Not directly. This is the only level where the answer changes |
The fourth row does the work. Everything above it is a mitigation, not a change of jurisdiction. Sovereign-cloud branding from US hyperscalers is a contested claim rather than a settled fact, which is why the EU's Tech Sovereignty Package of 3 June 2026 proposes formal "assurance levels". The label alone told nobody anything.
Is the EU-US Data Privacy Framework still valid in 2026?
Yes. As of writing it's still in force, and noticeably less stable than a year ago. Don't plan on it being permanent, and don't plan on it collapsing tomorrow either.
On 3 September 2025 the EU General Court dismissed Philippe Latombe's annulment challenge (T-553/23), though on the facts as they stood at the 2023 adequacy decision. In October 2025 Latombe appealed to the CJEU, the court that struck down Safe Harbor and Privacy Shield.
Then on 29 June 2026, in Trump v. Slaughter, the US Supreme Court held 6 to 3 that statutory removal protections for FTC Commissioners are unconstitutional. On 31 July 2026 the EDPB asked the Commission to assess the consequences, noting that the adequacy decision expressly relies on FTC independence.
There are also reports of the PCLOB losing quorum and instability around FISA Section 702 renewals. Practically: keep Standard Contractual Clauses and transfer impact assessments in place rather than leaning on the DPF alone.
Legal risk or political preference? They lead to different answers
Both are legitimate, and conflating them produces incoherent decisions.
Legal risk is about specific personal data, specific processing, documented transfer mechanisms. It's proportionate (a marketing site logging IP addresses isn't a health portal), and the response is a data map, a transfer impact assessment, and changes to the layers that actually carry personal data.
Strategic preference is about supply-chain dependency, geopolitical exposure, and where your money goes. It isn't proportionate to risk, and it can justify moving things that pose no legal problem at all.
If your motivation is the second, say so. Dressed up as a compliance requirement, it becomes a project that fails its own stated test.
Which layers of your website actually touch US services?
More than most people expect. The host is the layer everyone focuses on and usually the least interesting. Each row below is a separate contract, data flow and decision.
| Layer | Common default | European option | If you can't switch |
|---|---|---|---|
| Server / host | AWS, Azure, GCP | Hetzner (DE), IONOS (DE), OVHcloud (FR), Scaleway (FR), UpCloud (FI) | SCCs plus encryption whose keys you hold |
| CDN | Cloudflare, CloudFront, Fastly | Bunny.net (SI), Myra (DE), KeyCDN (CH, non-EU but an adequacy country) | Or drop the CDN; many sites don't need one |
| DNS | Cloudflare, Route 53 | deSEC (DE), Hetzner DNS, INWX (DE), Bunny DNS | Query data is low-sensitivity, but not nothing |
| Web fonts | Google Fonts CDN | Self-host the font files | Nothing, just self-host |
| Analytics | Google Analytics | Matomo (self-hosted or EU cloud), Plausible (EE), Piwik PRO (PL), etracker (DE) | Consent, IP truncation, DPA |
| Embedded video | YouTube, Vimeo | Bunny Stream, Dailymotion (FR), self-hosted PeerTube | Click-to-load facade so nothing loads pre-consent |
| Forms + transactional email | SendGrid, Mailgun, Postmark | Brevo (FR), Mailjet (FR), Rapidmail (DE), CleverReach (DE), Scaleway TEM | Your own SMTP on EU infrastructure |
| Error tracking | Sentry, Datadog, LogRocket | Self-hosted Sentry, GlitchTip | Scrub PII in the browser before it leaves |
| AI in the content pipeline | OpenAI, Anthropic, Google | Mistral (FR), Aleph Alpha (DE), IONOS AI Model Hub, OVHcloud AI Endpoints | Don't paste personal data into any of them |
Fonts are the cheapest win. In January 2022 the Landgericht München I awarded a visitor €100 in damages because a site loaded Google Fonts from Google's CDN, sending the visitor's IP address to the US without consent. Self-hosting the files takes an afternoon.
What you actually give up by going EU-only
Real costs, not token ones. Anyone who tells you the switch is free hasn't done it.
You get fewer managed services. Europe has excellent infrastructure and a much thinner layer of managed services on top, so you'll self-manage things a hyperscaler would have run for you. Ecosystems are smaller too: fewer Terraform modules, fewer integrations, fewer answers at 2am.
Some gaps are genuine. Error tracking and video hosting are the weakest rows above, where the self-hosted options work but trail Sentry and YouTube in polish. Edge performance outside Europe trails Cloudflare and CloudFront, so if your traffic is in São Paulo or Singapore, a European-only CDN costs real milliseconds. And in the AI layer, European providers have closed a lot of ground, but for some tasks frontier US models are still ahead, so re-check rather than assume.
None of that is a dealbreaker for a content website. Several of them are, for a global consumer product.
Where Neleto fits in this
Neleto is a complete CMS with managed EU hosting on Hetzner in Nuremberg and Falkenstein, Germany. Triple-A Soft, the company behind it, is German, and there's no US parent in the chain. That puts the hosting layer in the fourth row of the table above rather than the first, on every plan including the free tier. Regions in the USA and Asia are coming, and you'll pick the region when you create an instance.
The more useful argument isn't the flag, it's the count of moving parts. Rendering is built in, so there's no second frontend stack deployed elsewhere. Image scaling is built in, so images never travel to an external transformation service. Fewer third-party services touching the page means fewer data-transfer questions in the first place, and every row you delete from that table is a DPA you don't sign and a subprocessor you don't re-check when its ownership changes.
Neleto doesn't make anyone automatically GDPR-compliant. That depends on what you collect and what you bolt on. Embed YouTube and load Google Analytics on a Neleto site and you have the same problems as anywhere else.
One caveat on our own stack: Neleto ships a native MCP server, and the AI clients people use it with (Claude Code, Cursor, Windsurf) are US products. If your policy is EU-only end to end, that's a layer like any other, and we aren't exempt from it.
When this is not worth doing
Skip the migration if any of these describe you.
You process no personal data beyond server logs, with no analytics, no forms and no embeds. Exposure is already near zero and the project would be theatre.
Your organisation is US-based or US-owned. A German host doesn't change your own jurisdiction. Fix the data map first.
You need global edge performance more than jurisdictional clarity. Worldwide e-commerce traffic will feel a European-only CDN.
You depend on a US-only managed service with no European equivalent. Name it, then decide whether the rest is worth moving anyway. Partial migration is a legitimate outcome.
Nobody has actually asked the question. Budget spent on a problem you can't articulate is budget not spent on one you can.
The middle path is usually right: move the layers that carry personal data and are cheap to move (fonts, analytics, DNS, transactional email), keep what's load-bearing, and document why for each. "Everything is in the EU" is rarely true once someone reads the subprocessor list.
Try it yourself: Open your site with the browser network tab recording, load a page in a private window, and list every domain it contacts. That list is your real answer, and it's usually longer than the one in your privacy policy.
Read next
Why EU Hosting Compliance Matters for Your Website
Data sovereignty, GDPR, and choosing the right infrastructure in 2026
40-Page WordPress Migration: Honest Walkthrough
The content migration took under an hour. The full cutover (domain, DNS, redirects, forms, QA) took most of a day. Every step, every gotcha.
Full CMS vs Headless: Why All-in-One Wins for Most of the Web
Headless earned its reputation for real reasons. Here's the honest trade-off — and why, for most sites, a complete CMS is the better deal.