The legal framework protecting your data in the US is at risk.
The US Supreme Court has ended the independence of the FTC, the pillar of the EU-US data agreement, and "Schrems III" is already being prepared in court. Anyone with data at American providers faces new uncertainty. Anyone who keeps it in Europe, with a European provider, does not.
- Servers in Europe
- 100% European jurisdiction
- Zero transfers to the US

Why this matters
Three agreements. Three collapses foretold.
Since 2000, the EU and the US have signed three legal frameworks to legitimise the transfer of personal data. The first two were struck down in court. The third has just lost its foundation.
2015
Safe Harbour struck down
The Court of Justice of the EU strikes down the first agreement (Schrems I case). Thousands of European companies have to rebuild their legal basis overnight.
2020
Privacy Shield struck down
History repeats itself: the CJEU strikes down the second agreement (Schrems II). US surveillance and the lack of effective redress for European citizens are, once again, the reason.
2026
Data Privacy Framework at risk
The US Supreme Court (Trump v. Slaughter, 29 June) declares the FTC's independence unconstitutional: the authority mentioned 259 times in the European Commission's adequacy decision. noyb calls for an orderly revocation of the agreement and is preparing what is already being called "Schrems III".
What now?
The question that remains
The adequacy decision formally remains in force until the Commission revokes it or the court strikes it down. But the question for any European business is simple: do you want to build your GDPR compliance on an agreement that is at risk for the third time in ten years?
The real impact
If your data is with a US provider, this concerns you.
You don't need to wait for a court ruling to feel the cost of uncertainty.
Compliance forever under construction
Transfer impact assessments (TIAs) that rely on the FTC's independence may have to be rewritten. Every collapsed agreement forces you to redo contracts, clauses and assessments.
Risk in tenders and audits
Clients, partners and regulators increasingly ask where data is stored. "In the US, under an agreement being challenged in court" is an answer that is increasingly hard to defend.
Dependence on other people's decisions
The fate of your data is decided between Washington, Brussels and Luxembourg, in proceedings that last years and that your company does not control.
The alternative
Data in Europe. Problem solved at source.
Sooma does not depend on adequacy decisions, standard contractual clauses or transatlantic agreements, because the data never leaves European jurisdiction.
| Criterion | Non-EU services | Sooma |
|---|---|---|
| Data location | US (or undefined) | Portugal |
| Legal basis for transfer | Contested adequacy decision / SCCs | Not applicable: there is no transfer |
| Exposure to "Schrems III" | Total | None |
| Applicable law | US CLOUD Act + GDPR | Portuguese and European law only |
| When the next agreement falls | Redo compliance all over again | Nothing changes |
| Support | International ticket | Team in Europe |
Sovereignty in practice
Europe has already understood. So have businesses.
Several Member States have announced digital sovereignty strategies and plans to reduce dependence on American providers, and the European Commission itself has included the topic in its technological sovereignty package. Choosing a European provider is no longer a political statement: it is risk management. For the more than 100,000 mailboxes managed by Sooma, including those of the Portuguese Bar Association (Ordem dos Advogados), that decision has already been made.
Talk to the teamFrequently asked questions
Digital sovereignty and data transfers
Straight answers to the questions this topic raises in businesses.
Has the Trump v. Slaughter ruling made it illegal to use American providers?
No. The EU-US adequacy decision formally remains in force until the European Commission revokes it or the Court of Justice of the EU strikes it down. What has changed is the risk: the authority the agreement rests on has lost the independence European law requires, and the agreement now faces legal and political challenge, just like the two previous agreements, which ended up being struck down.
My company uses Microsoft 365 / Google Workspace. Do I have to switch right away?
There is no immediate legal obligation. But if your business relies heavily on the GDPR (health, finance, legal, public sector), it is worth assessing how much it costs your organisation to rebuild its compliance basis every time a transatlantic agreement collapses, and comparing that with the cost of simply keeping your data in Europe.
With Sooma, does my data pass through servers outside the EU?
No. Storage and processing take place in Europe, under European jurisdiction. There are no transfers of personal data to the US, so the validity (or collapse) of transatlantic agreements does not affect Sooma customers.
What if I need to communicate with customers or suppliers in the US?
Sending an email to a recipient in the US is not the same as storing your data with an American provider. What digital sovereignty solves is the location and jurisdiction of your data at rest: your mailboxes, archives and contacts.
What happens if the Data Privacy Framework is actually struck down?
For Sooma customers: nothing. For those using US providers: it will depend on what the Commission and the courts decide, but the experience of 2015 and 2020 suggests a period of uncertainty, contract renegotiation and updated impact assessments.
Put your data out of reach of the next collapse.
Assisted migration included. 60-day guarantee, no-questions-asked refund.
