For years, the question of whether storing personal data in US-based cloud services complies with European privacy laws has been a legal and political minefield. While the EU and US have repeatedly attempted to establish frameworks to enable transatlantic data flows, these agreements have consistently failed to withstand legal scrutiny.
The latest iteration of those attempts, the EU-US Data Privacy Framework (DPF), is now facing the same fate as its predecessors — rendered practically defunct due to structural issues and alarming developments in US oversight mechanisms.
If the deal is revoked, this could turn disastrous for companies. Judges in the EU could make the use of US clouds illegal at any moment. Read on to understand what the current situation around the agreement could mean for businesses handling data across the continents.
Oversight’s board chair and members laid off
A key provision in the DPF is the oversight function provided by the US Privacy and Civil Liberties Oversight Board (PCLOB). However, on January 27, the chairman of the board and two other members were dismissed, leaving only one active board member and a skeleton legal team of four staff members. Judge found the dismissal of the two members of the board unlawful.
With such a weakened oversight body, the fundamental concerns that led the Court of Justice of the European Union (CJEU) to strike down previous agreements remain unaddressed. The current DPF is unlikely to survive the inevitable legal challenges ahead, much like its predecessors, Privacy Shield and Safe Harbor.
The legal reality: data transfers to the US remain risky
From a legal perspective, the CJEU’s rulings on transatlantic data transfers have been clear: unless the US implements substantial legal reforms, no framework will provide sufficient protection under EU law. The General Data Protection Regulation (GDPR) requires that personal data be protected with a level of security equivalent to what is granted within the EU. However, under US law, foreign citizens lack the same privacy rights as US residents, and intelligence agencies retain broad access to data stored by US-based companies.
This means that, despite the existence of the DPF, organizations handling EU personal data must assess whether their transfers to US-based cloud providers comply with GDPR. In practice, this is difficult, if not impossible, without additional safeguards such as encryption, data localization, or alternative hosting solutions.
EU-US Data Privacy Framework at risk: what this means for businesses
Companies relying on US cloud providers to store or process EU customer data are left in an uncertain position. Even if they adhere to the DPF, they may still be violating GDPR due to the unresolved structural issues. Legal challenges are inevitable, and it is only a matter of time before the CJEU is asked to review the framework once again.
For businesses, this could mean several things:
DPF is not a long-term solution — Organizations should not assume that compliance with the framework guarantees GDPR adherence.
Risk of enforcement actions — European data protection authorities could take action against companies transferring data under the DPF if it is deemed non-compliant.
Time to look for alternatives — EU-based or self-hosted cloud solutions offer a legally safer approach for organizations handling sensitive data.
Nextcloud’s approach: a future-proof alternative
Given the ongoing legal uncertainties, businesses and government entities need solutions that ensure compliance with GDPR without depending on fragile political agreements. Nextcloud offers a fully self-hosted, Europe-based cloud collaboration platform that keeps data under the direct control of organizations. With on-premises hosting and strong encryption features, Nextcloud allows businesses to maintain compliance with EU privacy laws while avoiding the risks associated with US-based services.
Webinar on Nextcloud Hub vs Microsoft 365: Choosing digital sovereignty for your organization
Discover in this on-demand webinar how Nextcloud Hub stacks up against Microsoft 365, offering greater flexibility, privacy and full compliance. Includes a features demo and a Q&A session.
As history has shown, legal frameworks like Safe Harbor and Privacy Shield, and now the DPF, do not offer the stability or protection that businesses need. By choosing self-hosted solutions, organizations can future-proof their operations and guarantee compliance with the highest standards of data protection.
Is it high time we moved away from US cloud providers?
The EU-US Data Privacy Framework is already on shaky ground, and the recent turmoil at the PCLOB only further weakens its credibility. Companies that continue to rely on US cloud providers for handling EU personal data do so at their own legal and business risk. Now is the time to explore alternatives that prioritize data sovereignty and long-term compliance.
Nextcloud provides a reliable, secure, and GDPR-compliant solution that empowers businesses to take control of their data. As regulatory scrutiny increases, organizations must act proactively to protect their users and their operations from future legal challenges.
Take Nextcloud Hub 10 for a test drive!
Regain control over your data. Try Nextcloud Hub 10 now without installation, or download the latest version.
Nous vous présentons Nextcloud Talk « Munich » - une plateforme de communication open source numériquement souveraine pour les équipes hybrides qui offre une réponse solide aux nuages des Big Tech. Maintenant encore plus résiliente, puissante et facile à démarrer. En savoir plus pour plus de détails.
Bienvenue à Nextcloud Hub 10. Notre dernière version offre des performances accrues dans chaque application, une intégration plus poussée sur l'ensemble de la plateforme et des dizaines de nouvelles fonctionnalités qui vous faciliteront la vie.
Les organisations, petites et grandes, ont besoin d'un moyen d'assurer la résilience et la souveraineté numérique de leurs opérations - une alternative à Teams, open-source et respectueuse de la vie privée. Aujourd'hui, nous vous présentons cette solution - Nextcloud Talk.
Nous vous présentons une mise à jour majeure de l'assistant Nextcloud IA, ainsi que de nouvelles informations sur notre collaboration avec plusieurs grands fournisseurs d'hébergement tels que IONOS et OVHcloud pour vous proposer des options d'IA en tant que service !
Bechtle et Nextcloud ont annoncé aujourd'hui une plateforme de collaboration entièrement administrée pour le secteur public, qui ne nécessite pas d'appel d'offres et peut être déployée immédiatement.
Découvrez comment passer de ownCloud à Nextcloud. Notre outil d'aide à la migration fournit des informations sur le processus de migration et vous aide à effectuer la transition en douceur.
Au cours de la dernière année, l'IA est devenue un sujet à la mode. Il y a de l'engouement, mais aussi du fondement. Il y a du positif et du négatif. Nous voulons vous offrir le positif, pas le négatif, et ignorer le battage médiatique ! […]
Au début de l'année 2025, les hyperscalers américains ont commencé à promouvoir leurs nouvelles offres de « cloud souverain » dans le cadre d'une grande campagne de relations publiques en Europe. Au cours des dernières semaines, leur discours s'est effondré. Ce ne sont pas les critiques ou les organismes de surveillance qui ont mis en évidence les contradictions, mais les entreprises technologiques elles-mêmes qui ont admis que leurs promesses de « souveraineté » étaient vides de sens.
Passionate about data privacy and Nextcloud? We invite you speak at the Nextcloud Community Conference to share your experience, knowledge and news with the community!
Nextcloud announces new partnership with Thinkfree Office, a self-hosted office suite developed in South Korea, which is known for its ease of use. This collaboration is all about giving you more options, greater control, and a better user experience.
Nous enregistrons certains cookies pour compter les visiteurs et faciliter l'utilisation du site. Ces données ne quittent pas notre serveur et ne sont pas destinées à vous suivre personnellement ! Consultez notre politique de confidentialité pour plus d'informations Personnaliser
Les cookies utilisés pour enregistrer les données saisies dans les formulaires, telles que le nom, l'adresse électronique, le numéro de téléphone et la langue préférée.
Nom du cookie :nc_form_fields
Description du cookie :Mémorise les données saisies dans les formulaires pour une prochaine visite (nom, adresse électronique, numéro de téléphone et langue préférée).
Les cookies statistiques collectent des informations de manière anonyme et nous aident à comprendre comment nos visiteurs utilisent notre site web. Nous utilisons la solution open source de mesure de statistiques web Matomo
Service:Matomo
Description du cookie :
_pk_ses*: Compte la première visite de l'utilisateur
_pk_id*: Aide à ne pas compter deux fois les visites.
mtm_cookie_consent: Se souvient que l'utilisateur a donné son accord pour le stockage et l'utilisation de cookies.
Expiration du cookie :_pk_ses*: 30 minutes
_pk_id*: 28 jours
mtm_cookie_consent: 30 jours