Opens in a new tab

Public sector · 6 min read · Published by Sooma

Eight questions a public body should ask its email provider

A digital sovereignty checklist, to use before the next procurement procedure.

Article published on 24 September 2026

In June 2026, the United States Supreme Court decision in Trump v. Slaughter ended the independence of the Federal Trade Commission. For most people, it was news about American politics. For anyone managing information systems at a Portuguese public body, it was something else: the removal of one of the pieces underpinning the agreement that allows Europeans' data to be transferred to the United States.

It is the third shock in ten years. Safe Harbor fell in 2015, Privacy Shield fell in 2020, and the agreement that replaced them is now being challenged. None of these episodes resulted from bad faith by the negotiators. They resulted from a fundamental incompatibility between two ways of understanding sovereignty, which no political agreement can resolve.

Meanwhile, our European peers have been acting. In France, the cloud doctrine reserves State systems with sensitive data for qualified infrastructure immune to non-European legislation. In Italy, public data has been classified by criticality and the most sensitive concentrated in qualified national infrastructure. In Germany, one Land migrated email across its entire administration, more than forty thousand mailboxes, to open solutions. In the Netherlands, parliament approved motions to halt unnecessary migrations of the administration to American cloud providers.

Portugal has approved its national sovereign cloud plan, to be implemented over the coming years. It is official recognition that the current dependency is a risk. But a specific body, with a procurement procedure to launch this half-year, cannot wait until the end of the decade.

These are the eight questions to ask before that procedure. They do not require technical knowledge. They require clear answers.

1. Which law is the entity operating the service subject to, and who controls it?

It is the question that covers all the others, and it is almost never asked. Do not confuse it with the location of the servers. A company incorporated in the United States, or controlled by an American company, remains subject to American law wherever it installs its equipment.

The case that proved it was not theoretical. In 2013, the American courts demanded that a technology company hand over the contents of an email account stored in a data centre in Dublin. The company refused and won in court. In 2018, Congress passed legislation requiring the handover of data in the possession, custody or control of these companies, regardless of the country where it is stored. The case ended with the handover.

Answer to require: identification of the contracting entity, its registered office, its ownership and control structure, and the law it is subject to.

2. Where is the data physically located, and who has access to the premises?

Location does not settle the question of jurisdiction, but it is still relevant. You need to know which country the equipment is in, who operates the physical space, and whether that operator has logical access to the systems.

Answer to require: location of the data centres, identification of the physical hosting provider, and an express statement on whether or not that provider has access to the data.

3. Are there transfers to third countries, even occasional ones?

The question should cover everything, not just the main service. Website traffic analytics, customer support tools, payment processing, fonts loaded from external servers. Each of these may constitute a transfer.

Answer to require: a complete list of sub-processors and recipients, with their location, and a statement on transfers to third countries.

4. How long are traffic logs kept, and on what grounds?

Many providers keep communication metadata for months or years, out of technical inertia. It is worth recalling the current framework: the Portuguese Constitutional Court declared unconstitutional, with generally binding force, the rules that required general retention of traffic data for one year, and again declared unconstitutional a later attempt at indiscriminate retention for three months.

In other words, prolonged retention of metadata without a specific purpose is no longer an obligation today. It is a risk.

Answer to require: specific retention periods by type of log, and the purpose that justifies them.

5. How are requests from authorities handled, including foreign ones?

A public body has a particular interest in knowing what happens if someone requests access to its data, and above all if that someone is an authority from another country.

Answer to require: a description of the internal procedure for reviewing requests, and a statement on how direct requests from third-country authorities are handled, which should follow judicial cooperation mechanisms involving the Portuguese authorities. Also ask whether the provider publishes a transparency report.

6. How is administrative and professional secrecy protected?

Disciplinary proceedings, health data, classified information, communications with lawyers. If these matters travel over infrastructure subject to a third-country jurisdiction, the duty of secrecy no longer depends on the body alone.

Answer to require: a statement on the provider's access to the content of communications, and on the circumstances in which such access may occur.

7. Does the provider take on the role of processor, and does it provide a data

processing agreement?

For the data stored in the mailboxes, the public body is the controller and the provider is the processor. This requires a written contract with the content set out in Article 28 of the General Data Protection Regulation. A provider that does not offer one is not in a position to contract with a public body.

Answer to require: a draft data processing agreement, with annexes on sub-processors and security measures.

8. What happens at the end of the contract?

Reversibility is often forgotten when contracting and painful when terminating.

Answer to require: data export formats and protocols, retention period after termination, deadline and method of deletion, and whether support is provided for the transition to another provider.

A final note on what is at stake

None of these questions is about technology. They are all about responsibility.

Whoever decides on the communications infrastructure of a public body is not just choosing a service. They are determining under which legal order the communications between the State and the citizens it serves will fall. It is a sovereignty decision, taken in a set of tender specifications.

 

The good news is that none of this requires waiting for national plans. It requires asking eight questions, and choosing based on the answers.

Share this article

Keep reading

Related articles

More on sovereignty, legal proof and business communications.

Your company email. In Europe. Protected by European law.

60 days to try it, no commitment. Assisted migration included.

Leave us a message

Privacy policy