Founder price · 100 spots leftReserve

[ Guide ]

GDPR-compliant email hosting in the EU: what it takes

What GDPR asks of your email provider: a DPA, lawful transfers after Schrems II, the EU-US Data Privacy Framework in 2026, and where data residency matters.

· 6 min read

[ In short ]

  • GDPR does not require email to be hosted in the EU; it requires a data processing agreement and lawful safeguards for any transfer outside it.
  • Transfers to US providers rely on the EU-US Data Privacy Framework or standard contractual clauses; the Framework stands, but its appeal is pending at the EU Court of Justice.
  • EU hosting by an EU company removes the transfer question for the mailboxes; check where backups, support and AI features run too.
  • Ask every provider for its DPA, sub-processor list, data location, breach process and how to export everything when you leave.

01Does GDPR require email to be hosted in the EU?

No. GDPR lets you host email anywhere, as long as your provider signs a data processing agreement (Article 28) and any transfer of personal data outside the European Economic Area has a legal basis under Chapter V: an adequacy decision, standard contractual clauses or another safeguard. EU hosting is a way to make that simpler, not a legal requirement.

Email is personal data almost by definition: names, addresses, the content of conversations with customers and staff, sometimes health or financial details in attachments. For that data your company is the controller, and the email provider is your processor. The duty to choose a provider that offers sufficient guarantees is yours (Article 28(1)).

This guide explains the rules and the 2026 state of play. It is not legal advice; for a specific decision, ask your data protection officer or counsel.

02The data processing agreement (DPA)

Article 28(3) lists what the contract with any processor must say. With an email provider, check that the DPA covers at least the following:

  • Instructions only. The provider processes your mail only to run the service you asked for, never for its own purposes such as training AI models or advertising.
  • Confidentiality. Staff who can access data are bound to keep it confidential.
  • Security. The measures of Article 32: encryption in transit and at rest, access control, backups, testing.
  • Sub-processors. A list of them (hosting, support, AI providers), with notice of changes and a right to object.
  • Help with rights requests. Access, deletion and export requests from the people in your mail.
  • Breaches. The provider tells you without undue delay, so you can notify your supervisory authority within 72 hours where Article 33 requires it.
  • Deletion or return. At the end of the contract, all mail is returned or deleted, at your choice.
  • Audits. You can verify compliance, usually through reports and certifications.

Large providers publish a standard DPA you accept online. Small ones sometimes have none, which is a reason to walk away before price or features come into it.

03Transfers outside the EU: Schrems II and the Data Privacy Framework

In July 2020 the Court of Justice of the EU struck down the Privacy Shield in the case known as Schrems II (C-311/18), because US surveillance law did not offer protection essentially equivalent to EU law. It kept standard contractual clauses valid, but required exporters to check, case by case, whether the destination country’s law undermines them and to add measures where it does.

The European Commission adopted a new adequacy decision for the EU-US Data Privacy Framework (DPF) in July 2023. US companies that certify under it can receive EU personal data without further safeguards. Where things stand in October 2026:

DateWhat happened
July 2023Commission adopts the DPF adequacy decision
3 Sept 2025EU General Court dismisses the Latombe challenge and upholds the DPF
31 Oct 2025Appeal lodged at the Court of Justice (C-703/25 P); pending, no hearing date announced
29 June 2026US Supreme Court rules in Trump v. Slaughter that FTC commissioners can be removed by the President without cause
31 July 2026The EDPB asks the Commission to assess whether that ruling affects the DPF

The DPF is valid today, and a US provider certified under it can lawfully host your mail. The risk is that it falls the way its two predecessors did. Many companies therefore keep standard contractual clauses in their contracts as a fallback, or prefer providers that do not transfer the data at all.

04Data residency: EU hosting versus an EU provider

“EU hosting” can mean two different things, and the difference matters for email.

Set-upWhere mail sitsWho could be compelled to hand it over
EU company, EU data centresEUEU authorities, under EU and national law
US company, EU data regionEU, by contract and configurationAlso US authorities: the US CLOUD Act (2018) lets them order US providers to produce data they control, wherever it is stored
US company, no region choiceAnywhere the provider runsUS and other authorities; transfers rely on the DPF or SCCs

The big suites offer EU storage, with conditions. Google Workspace lets admins set data regions on editions such as Business Standard, Business Plus and the Enterprise editions, but not Business Starter. Microsoft completed its EU Data Boundary for Microsoft 365 in February 2025, keeping customer data, pseudonymized data and support data for EU customers inside the EU and EFTA.

Neither change makes those companies European. If what you want is to keep your mail out of reach of non-EU law, choose a provider established in the EU that stores and processes in the EU. Options are reviewed in European email providers.

05AI features that read your mail

Assistants that summarize, draft or follow up read the content of your mail, so the same questions apply to them, often with a second provider involved.

  • Which model provider processes the text, and in which region? Is it listed as a sub-processor?
  • Is your mail used to train or improve models? The answer in the DPA should be no.
  • How long are prompts and outputs kept, and can staff of the AI provider read them?
  • Can each person turn the assistant on or off for their own mailbox?

Skein keeps mail and its agent on servers in Frankfurt, in the EU, never uses your mail to train AI models, and includes the data processing agreement in its terms. Pricing and what is included: pricing.

06Checklist for choosing a GDPR-compliant email host

  • A DPA that meets Article 28(3), signed or accepted before any real mail flows.
  • A public sub-processor list with locations, and notice of changes.
  • Where mailboxes, backups, logs and support access sit, in writing.
  • For any transfer outside the EEA: the DPF certification or SCCs, and the provider’s transfer assessment.
  • Encryption in transit (TLS, ideally MTA-STS) and at rest.
  • Breach notification terms that let you meet the 72-hour deadline.
  • Export of every mailbox in a standard format (IMAP, mbox), and deletion when you leave.
  • Admin access to employees’ mail that is limited, logged and covered by your own internal policy.

Spain and employee mail

In Spain, the LOPDGDD adds rules on employers’ access to digital devices, including work email (Article 87): the company must set the criteria for use and inform staff before any access. Whatever host you choose, write that policy.

Moving providers to get there is mostly DNS work; see how to migrate from Google Workspace.

Questions

Is Gmail GDPR compliant?
Google Workspace (not free Gmail) offers a data processing addendum that incorporates standard contractual clauses for transfers, and lets some editions store data in the EU. Whether that is enough is your assessment as controller. Free consumer Gmail is not designed for business data.
Is the EU-US Data Privacy Framework still valid in 2026?
Yes. The EU General Court upheld it in September 2025. An appeal is pending at the Court of Justice, and in July 2026 the EDPB asked the Commission to assess a US Supreme Court ruling on FTC independence. Until a court or the Commission acts, it remains in force.
Do I need a DPA with my email provider?
Yes. Your provider processes personal data on your behalf, so Article 28 GDPR requires a contract with the content it lists. Most providers include it in their terms or offer it online; if one has none, choose another.
Is EU data residency enough for GDPR?
It removes most transfer questions for the stored mail, but GDPR also needs a DPA, security and lawful processing. And with a US-owned provider, EU storage does not take the data out of the reach of US law such as the CLOUD Act.

See Skein follow up for you

Business email on your own domain with an agent that follows up on every conversation. Hosted in the EU. Try the demo with sample mail, nothing to install.

[ Sources ]

  1. 01GDPR, Regulation (EU) 2016/679 (EUR-Lex)
  2. 02Court of Justice, C-311/18 (Schrems II)
  3. 03EDPB Recommendations 01/2020 on supplementary measures
  4. 04European Commission: Standard contractual clauses
  5. 05IAPP: General Court dismisses Latombe challenge, upholds the DPF
  6. 06WilmerHale: Court of Justice to review challenge to the DPF
  7. 07EDPB letter on Trump v. Slaughter and the DPF (31 July 2026)
  8. 08Google Workspace: choose a geographic location for your data
  9. 09Microsoft: EU Data Boundary completed (February 2025)
  10. 10Google Workspace: Privacy compliance and records (Cloud Data Processing Addendum)
  11. 11US Department of Justice: CLOUD Act resources
  12. 12Spain, LOPDGDD (Ley Orgánica 3/2018), BOE

Facts about other products were checked on 5 Oct 2026; prices and plans change.

[ Read next ]