Opens in a new tab

The legal framework protecting your data in the US is at risk.

The US Supreme Court has ended the independence of the FTC, the pillar of the EU-US data agreement, and "Schrems III" is already being prepared in court. Anyone with data at American providers faces new uncertainty. Anyone who keeps it in Europe, with a European provider, does not.

  • Servers in Europe
  • 100% European jurisdiction
  • Zero transfers to the US
Hands removing a server from a rack in a data centre, with the EU flag

Why this matters

Three agreements. Three collapses foretold.

Since 2000, the EU and the US have signed three legal frameworks to legitimise the transfer of personal data. The first two were struck down in court. The third has just lost its foundation.

2015

Safe Harbour struck down

The Court of Justice of the EU strikes down the first agreement (Schrems I case). Thousands of European companies have to rebuild their legal basis overnight.

2020

Privacy Shield struck down

History repeats itself: the CJEU strikes down the second agreement (Schrems II). US surveillance and the lack of effective redress for European citizens are, once again, the reason.

2026

Data Privacy Framework at risk

The US Supreme Court (Trump v. Slaughter, 29 June) declares the FTC's independence unconstitutional: the authority mentioned 259 times in the European Commission's adequacy decision. noyb calls for an orderly revocation of the agreement and is preparing what is already being called "Schrems III".

What now?

The question that remains

The adequacy decision formally remains in force until the Commission revokes it or the court strikes it down. But the question for any European business is simple: do you want to build your GDPR compliance on an agreement that is at risk for the third time in ten years?

The real impact

If your data is with a US provider, this concerns you.

You don't need to wait for a court ruling to feel the cost of uncertainty.

Compliance forever under construction

Transfer impact assessments (TIAs) that rely on the FTC's independence may have to be rewritten. Every collapsed agreement forces you to redo contracts, clauses and assessments.

Risk in tenders and audits

Clients, partners and regulators increasingly ask where data is stored. "In the US, under an agreement being challenged in court" is an answer that is increasingly hard to defend.

Dependence on other people's decisions

The fate of your data is decided between Washington, Brussels and Luxembourg, in proceedings that last years and that your company does not control.

The alternative

Data in Europe. Problem solved at source.

Sooma does not depend on adequacy decisions, standard contractual clauses or transatlantic agreements, because the data never leaves European jurisdiction.

CriterionNon-EU servicesSooma
Data locationUS (or undefined)Portugal
Legal basis for transferContested adequacy decision / SCCsNot applicable: there is no transfer
Exposure to "Schrems III"TotalNone
Applicable lawUS CLOUD Act + GDPRPortuguese and European law only
When the next agreement fallsRedo compliance all over againNothing changes
SupportInternational ticketTeam in Europe

Sovereignty in practice

Europe has already understood. So have businesses.

Several Member States have announced digital sovereignty strategies and plans to reduce dependence on American providers, and the European Commission itself has included the topic in its technological sovereignty package. Choosing a European provider is no longer a political statement: it is risk management. For the more than 100,000 mailboxes managed by Sooma, including those of the Portuguese Bar Association (Ordem dos Advogados), that decision has already been made.

Talk to the team

Frequently asked questions

Digital sovereignty and data transfers

Straight answers to the questions this topic raises in businesses.

No. The EU-US adequacy decision formally remains in force until the European Commission revokes it or the Court of Justice of the EU strikes it down. What has changed is the risk: the authority the agreement rests on has lost the independence European law requires, and the agreement now faces legal and political challenge, just like the two previous agreements, which ended up being struck down.

There is no immediate legal obligation. But if your business relies heavily on the GDPR (health, finance, legal, public sector), it is worth assessing how much it costs your organisation to rebuild its compliance basis every time a transatlantic agreement collapses, and comparing that with the cost of simply keeping your data in Europe.

No. Storage and processing take place in Europe, under European jurisdiction. There are no transfers of personal data to the US, so the validity (or collapse) of transatlantic agreements does not affect Sooma customers.

Sending an email to a recipient in the US is not the same as storing your data with an American provider. What digital sovereignty solves is the location and jurisdiction of your data at rest: your mailboxes, archives and contacts.

For Sooma customers: nothing. For those using US providers: it will depend on what the Commission and the courts decide, but the experience of 2015 and 2020 suggests a period of uncertainty, contract renegotiation and updated impact assessments.

Put your data out of reach of the next collapse.

Assisted migration included. 60-day guarantee, no-questions-asked refund.

See pricing

Leave us a message

Privacy policy