Website Hosting in Europe: What Switching Away from U.S. Providers Really Means, and in What Order

85 percent of German companies believe they are too dependent on U.S. cloud services, yet 71 percent use them anyway. We’ll explain the CLOUD Act and the Data Privacy Framework without causing a panic, show you where your website’s data is actually stored today, and tell you what you should migrate and in what order.

Date

/

Category

Technology & Systems

Technology & Systems

/

Author

Dustin Tatarowicz

Dustin Tatarowicz

Featured image for the post

“Our tax advisor says we should move away from American providers. Does that apply to our website, too?” The question came from a mechanical engineer in the Bergisch region, and it exemplifies an issue that, by 2026, had migrated from the IT departments of large corporations to small and medium-sized businesses: digital sovereignty. Eighty-five percent of the companies surveyed by Bitkom believe Germany is too dependent on U.S. cloud providers, and 91 percent would prefer to use German providers. In fact, 71 percent currently run on U.S. infrastructure.

This article explains the legal aspects behind the discussion, what actually changed in 2026, where your website’s data is really stored today, and which steps make sense for a small or medium-sized business—and which are just for show. First off: We’re web designers, not lawyers. For a binding assessment of your case, you’ll need a law firm that specializes in IT law.

What the CLOUD Act Is About

The U.S. CLOUD Act of March 2018 requires U.S. companies to hand over data to U.S. authorities upon request, regardless—according to the text of the law—of whether the data is stored “inside or outside the United States.” What matters is not the location of the server, but who has control over the data. A data center in Frankfurt owned by a U.S. corporation is just as subject to this requirement as one in Virginia.

Microsoft France confirmed just how real this is in June 2025 before a committee of the French Senate. When asked for a guarantee that data would not be shared with U.S. authorities without the consent of the French authorities, the legal counsel replied verbatim: “No, I cannot guarantee that, but it has never happened before.” Both parts of the statement are important. Legally, such access cannot be ruled out. In practice, Microsoft reported 190 government requests worldwide regarding corporate customers in the second half of 2025; data was disclosed in 94 of these cases, and content was disclosed in 45 of them. For a small business’s website, the statistical risk is therefore minuscule. The legal problem remains nonetheless, because it cannot be negotiated away in a contract.

Why this topic is getting so much attention in 2026

The legal framework between the EU and the U.S. is called the Data Privacy Framework (DPF), and it suffered several setbacks in 2026. In September 2025, the General Court of the European Union dismissed a lawsuit challenging the agreement, but the appeal before the European Court of Justice is still pending. The U.S. oversight body PCLOB, which is designated as the supervisory authority under the agreement, has not had a quorum since early 2025. And on June 29, 2026, the Supreme Court ruled that the President may dismiss members of the Federal Trade Commission (FTC) at any time. The FTC is the agency responsible for enforcing the agreement on the U.S. side. On July 31, 2026, the European Data Protection Board therefore sent a written request to the European Commission asking it to assess whether the agreement is still viable.

The DPF is still in effect. But anyone who has been following data protection since 2015 is familiar with the pattern: Safe Harbor was struck down in 2015, and the Privacy Shield in 2020—each time by a single ruling. Many companies don’t want to have to revamp their contracts overnight a third time.

Timeline of Data Protection Agreements Between the EU and the U.S., from Safe Harbor in 2015 to the Ban on Exit Fees in 2027

Safe Harbor and Privacy Shield have been ruled invalid; the Data Privacy Framework is currently under appeal and review.

At the same time, the EU has opened the door to switching providers: The Data Act has been in effect since September 12, 2025, and requires cloud providers to make switching technically possible. Since then, fees for data extraction may only cover costs; as of January 12, 2027, they will be completely prohibited. For those who want to switch, January will be the best time to do so.

What the Numbers Say About Aspirations and Reality

The June 2026 Bitkom Cloud Report, a telephone survey of 603 companies with 20 or more employees, clearly illustrates this divide. 91 percent would prefer to use German providers, and 53 percent do so. 8 percent prefer U.S. providers, and 71 percent use them. 64 percent say U.S. policy is forcing them to rethink their cloud strategy. 37 percent would accept higher costs or fewer features for a purely German cloud; last year, that figure was 27 percent. And 59 percent cite dependence on their existing provider—the “lock-in”—as the biggest hurdle.

Bar chart: Preferred and actually used cloud providers among German companies, according to Bitkom; 91 percent prefer German providers, 71 percent use U.S. providers

Expectations and Reality in the Bitkom Cloud Report 2026.

The market is moving more slowly than sentiment. According to figures from Synergy Research, the three major U.S. providers hold about 70 percent of the European cloud market, while European providers collectively hold about 15 percent—down from 29 percent in 2017. Gartner expects spending on sovereign cloud infrastructure in Europe to nearly double to $12.6 billion by 2026. The money is flowing, but from a very small base.

What's new in 2026—and what just sounds new

In January 2026, Amazon launched its “European Sovereign Cloud” in Brandenburg, operated by a German GmbH with a European workforce, at a cost of 7.8 billion euros. In February, Telekom launched an Industrial AI Cloud in Munich featuring approximately 10,000 Nvidia chips, operated on German soil. Microsoft completed its EU Data Boundary as early as 2025 and, since April 2026, has pledged to challenge in court any order to shut down European services. The BSI published criteria for cloud sovereignty in April, and the European Commission proposed a Cloud and AI Development Act in June, which aims to triple data center capacity in Europe within five to seven years.

The catch that analysts point out with nearly all of these offerings: The European subsidiary remains a subsidiary. Even the Amazon Sovereign Cloud is 100 percent owned by Amazon.com, and the CLOUD Act is tied to precisely this level of control. Microsoft’s promise concerns the shutdown of services, not the handover of data. An “EU region” offered by a U.S. provider changes latency and paperwork, but not the legal scope. Legal independence from the CLOUD Act exists only for providers with European ownership and their own infrastructure, such as STACKIT, IONOS, Hetzner, OVHcloud, or Mittwald.

Where Your Website's Data Is Stored Today

This is where things get specific—and, for many, surprising. We've reviewed the information provided by the providers themselves.

Framer, our preferred platform, is a Dutch company based in Amsterdam. However, its security documentation states unequivocally: All services are operated in Amazon data centers in the U.S. Form submissions and CMS content are therefore stored in the U.S., and the legal basis is the DPF or, alternatively, standard contractual clauses. There is no purely EU-based option. According to its own statements, Webflow stores customer and visitor data in the U.S. Squarespace does the same, while Wix stores data in the U.S. and Ireland. Shopify stores the shop, order, and customer data of new European merchants in Europe by default, but continues to process this data internationally.

And then there’s the layer that hardly anyone thinks about: the Content Delivery Network—the intermediary network that delivers the site worldwide. If you use Cloudflare’s free plan, your encrypted connections are decrypted at every Cloudflare location worldwide. There is an option to limit this to EU locations, but it costs extra.

Also, a “German provider” doesn’t necessarily mean “German infrastructure.” Raidboxes, a popular German WordPress hosting provider, runs on Amazon servers in Frankfurt, according to its own privacy policy. Mittwald operates its own data center in Espelkamp, and Hetzner operates its own in Falkenstein and Nuremberg. If you want to verify whether a server is “located in Germany,” you need to ask three questions: Who owns the provider? Who owns the hardware? And where is the connection decrypted?

Table: Data Center Locations for Framer, Webflow, Squarespace, Wix, Shopify, Raidboxes, Mittwald, and Hetzner

Where website builders and web hosting providers say they store their data.

The Lesson from the Google Fonts Ruling

In January 2022, the Munich Regional Court demonstrated just how quickly a theoretical question can turn into a letter from a lawyer. A website had dynamically loaded fonts from Google servers, thereby transferring a visitor’s IP address to the U.S. without consent. The court awarded 100 euros in damages. What followed was a wave of cease-and-desist letters—thousands of them—and the Berlin Office of the Attorney General launched investigations into the senders themselves in at least 2,418 cases. The technical solution—loading fonts from your own server—takes just one hour. The same principle applies to Google Maps, YouTube embeds, and reCAPTCHA: either embed them in a way that requires consent or host them yourself.

Analytics and Email: The Actual Data Flows

On a typical company website without an online store or login, personal data flows through three channels: the contact form, visitor statistics, and the inbox where inquiries are received. That’s exactly where you should focus your attention—not on the website builder itself.

Google Analytics requires consent, and the data protection authorities in Austria and France had already declared its use unlawful in 2022 before the DPF established a new legal basis. If the DPF is overturned, the issue will immediately be up for debate again. Plausible, a European provider, is hosted by Hetzner in Falkenstein and promises that website data never leaves the EU. Matomo Cloud runs in Frankfurt and, in its configured form, is included on the French regulator’s list of consent-free tools. For the past two years, we have been using almost exclusively such tools for our clients, partly because they do not require cookie banners.

The situation with Microsoft 365 is mixed: In 2022, the Data Protection Conference determined that Microsoft was unable to demonstrate compliance with data protection regulations. In November 2025, following its own negotiations with Microsoft, the Hessian Data Protection Commissioner concluded that compliant use was possible under certain conditions. This applies to Hesse; other states have not adopted this position. If you want to play it safe, use a German provider for your company email.

Sovereignty is not the same as security

One point that BSI Director Claudia Plattner made clear in the summer of 2025—and which drew criticism—was: “Sovereignty is not the same as self-sufficiency.” The point is to have options, not to be able to do everything on one’s own. The BSI criteria from April 2026 therefore require that a provider first meet the security requirements of the C5 catalog before sovereignty is even evaluated.

Translated for the website: A neglected WordPress site with outdated plugins on a Hetzner server is unstable and insecure. A well-maintained Framer site on U.S. servers is secure but subject to legal constraints. One does not solve the other. Anyone who switches without addressing updates, backups, and access rights has simply traded one problem for another.

Here’s what we recommend to small and medium-sized businesses, in this order:

1. Switch analytics providers—one day. Replace Google Analytics with Plausible or Matomo. Side effect: The cookie banner can be removed entirely from many pages, which, in our experience, leads to more inquiries.

2. Move forms—it takes one to two days. Form data is the most sensitive data on a typical website. It can be sent to an EU endpoint—such as your own WordPress site, a European form tool, or a small service on a German server—without leaving the website builder.

3. Check email over the weekend. Email accounts with a German provider, with a clean DNS migration. This is the step that offers the most value per euro, because that's where the inquiries, quotes, and contracts are located.

4. Clean up external embeds—one afternoon. Host fonts yourself; load maps and videos only with consent.

5. Website hosting last. Once a website has been set up following steps 1 through 4, the website builder itself processes almost no personal data. Switching is worthwhile if a relaunch is planned anyway, or if bookings, customer accounts, or health data are involved. For these cases, we now rely on systems hosted in Europe, and starting in January 2027, the Data Act will make it possible to switch without termination fees.

Five steps in order: Statistics, Forms, Email, Embeddings, and finally Hosting

The order we recommend for small and medium-sized businesses.

Conclusion: Less panic, more order

The risk is real, but asymmetrical. If the agreement with the U.S. falls through, a business that uses European statistics, European forms, and the German postal service won’t have to do anything that day. Everyone else will have to go through the same contract battle as in 2020. The first four steps together take one workweek, don’t change the look of the website, and take the fear out of the issue. Whether the website builder itself needs to migrate is then a question of business model, not fear.

Related: WordPress 7.0 Is Here: What Really Matters for Your Website and Framer, Webflow, WordPress: Why There’s No Single “Best System” · Services: Web Design for Small Businesses and Trades

Do you want to know where your website is sending data right now?

We’ll take a look at which services your site loads, where forms, analytics, and fonts are hosted, and let you know which of the five steps will be effective for you and which won’t. Send us a quick message via the contact form. We’ll respond within 24 hours—personally and without any sales pitch.