All articlesGDPR & Data Protection

    EU hosting vs. US cloud

    13 April 20268 min read

    Where your data is stored determines who can access it. For Austrian small businesses using AI tools, the difference between EU hosting and US cloud is not just technical, it is legally relevant. This article explains what matters.

    What does “server location” mean for your business?

    If you use an AI chatbot or phone assistant, customer data gets processed: names, phone numbers, email addresses, conversation content. That data sits on a server. And where that server is located determines which law applies.

    EU servers (e.g. Germany, Austria, Ireland): the GDPR applies. Authorities can only access data with a judicial order. There are clear rules for data protection, consent and deletion.

    US servers (or a US provider with an EU data centre): here it gets more complicated. The US CLOUD Act of 2018 allows American authorities to access data held by US companies, even when that data sits on a server in Frankfurt or Vienna.

    The problem: CLOUD Act vs. GDPR

    The heart of the conflict:

    • The GDPR (Art. 44-49) prohibits transferring personal data to third countries without an adequate level of protection.
    • The US CLOUD Act obliges US companies to hand over data on request from authorities, regardless of where the server is located.

    That means: if you use an AI chatbot from an American provider, and that provider relies on US servers (or is subject to the CLOUD Act), your customer data could in theory be accessed by US authorities without any European court being involved.

    Schrems II, the Data Privacy Framework and “Schrems III”

    The topic of EU-US data transfer has a chequered history:

    1. Safe Harbor (2000-2015): the first agreement between the EU and the US. Declared invalid by the CJEU (“Schrems I”).
    2. Privacy Shield (2016-2020): the successor agreement. Also struck down by the CJEU (“Schrems II”), because US surveillance laws do not offer equivalent protection.
    3. Data Privacy Framework (since 2023): the current agreement. Based on a US executive order, not on a statute. Austrian privacy activist Max Schrems has announced he will challenge this agreement too.

    As of April 2026: the Data Privacy Framework still applies, but a “Schrems III” case is in preparation. Structural changes at the US privacy oversight bodies (PCLOB, FTC) raise further questions. The legal situation is uncertain.

    What does this mean for small businesses in practice?

    As a small business owner, you don't need to be a lawyer. But you should know these three things:

    1. EU hosting alone is not enough. If the provider is a US company (e.g. Google, Microsoft, Amazon), it is subject to the CLOUD Act, even with a data centre in Frankfurt.
    2. Pay attention to the provider's registered office. A provider based in the EU that hosts on EU servers offers the strongest protection. No US law can reach the data.
    3. Check the data processing agreement (DPA). Every reputable provider offers one. It states where data is processed, who has access and how long data is retained. More on this in our article GDPR and AI: what SMEs must know.

    The comparison: EU hosting vs. US cloud

    CriterionEU provider + EU serverUS provider + EU serverUS provider + US server
    GDPR-compliantYesLimited (CLOUD Act)Problematic
    EU authority accessOnly with a judicial orderOnly with a judicial orderOnly with a judicial order
    US authority accessNo access possiblePossible (CLOUD Act)Possible (CLOUD Act + FISA 702)
    Legal certaintyHighUncertain (DPF could be struck down)Low
    Suitable for sensitive dataYesConditionallyNo
    Recommendation for small businessesBest choiceAcceptable with DPFAvoid

    What to watch for in AI tools

    If you want to use an AI chatbot or AI phone assistant for your business, check the following points:

    • Where is the provider's registered office? EU is ideal, US is critical.
    • Where are the servers located? An EU data centre is a must.
    • Is there a data processing agreement? Nothing works without one.
    • Is conversation data used for AI training? With many US providers, your customer data feeds into model training. A dealbreaker.
    • How long is data retained? The shorter, the better (data minimisation, Art. 5 GDPR).

    The EU AI Act: what additionally applies from August 2026

    The EU AI Act brings additional obligations for AI providers and users from August 2026. For small businesses using chatbots or phone assistants, two points matter most:

    • Transparency obligation: customers must know they are talking to an AI, not a human.
    • Provider obligation: the provider of your AI system must document how the system works and implement technical measures for labelling AI-generated content.

    A reputable provider takes on these obligations for you. Ask about it.

    How ServasBot solves this

    At ServasBot, we consistently rely on EU hosting:

    • All chatbot data sits on servers in Germany
    • The AI phone assistant is run by fonio.ai, a European provider with EU servers
    • We provide a data processing agreement and ensure GDPR compliance
    • Customer data is not used for AI training
    • ServasBot is based in Austria (Villach)

    Frequently asked questions

    Is it illegal to use a US cloud service?

    No, not as such. Under the current Data Privacy Framework, transferring data to the US is generally allowed. However, the legal situation is uncertain: the framework could be struck down by a “Schrems III” ruling, as has already happened twice with its predecessors.

    Is an EU data centre enough with a US provider?

    Only partly. The server location reduces the risk, but the US CLOUD Act allows US authorities to access data held by US companies regardless of server location. For maximum certainty, the provider itself should be based in the EU.

    What happens if the Data Privacy Framework is struck down?

    Then transferring data to US providers would again be unlawful, unless you use additional safeguards (standard contractual clauses, encryption). If you already rely on an EU provider, you are on the safe side.

    What data does an AI chatbot actually process?

    That depends on how it is used. Typically: IP addresses, conversation content, optionally name and email address. With an AI phone assistant, phone numbers and voice recordings are added. All of this is personal data within the meaning of the GDPR.

    Conclusion

    The server location is not a technical detail. It determines the legal certainty of your AI solution. For Austrian small businesses, the safest choice is a provider with an EU registered office and EU hosting. That protects your customer data from access by US authorities and makes you independent of international agreements that could be struck down at any time.

    More on data protection: GDPR and AI: what SMEs must know. Or try our AI readiness checklist to find out whether an AI chatbot or phone assistant suits your business.

    Sounds interesting?

    Build your own AI chatbot and try it free for 30 days.

    Start 30-day free trial

    Questions? We're happy to help.

    Send us a message and we'll get back to you within 24 hours on business days.

    +43 677 61163934

    If we don't pick up, our AI assistant takes the call.

    Write to us

    By submitting, you agree to the processing of your data in accordance with our Privacy Policy.