How Schrems II made cloud storage a compliance risk for EU businesses

You store your company’s customer files in a cloud service based in the US. You think it’s secure. But under Schrems II, that assumption could be legally reckless.

The 2020 European Court of Justice ruling didn’t ban US cloud storage—but it made every transfer of EU data to the US a high-stakes compliance exercise. Now, if you handle private or sensitive data, you must prove that your cloud provider isn’t just storing it, but protecting it—even from foreign intelligence access.

That’s a hard standard. Because under laws like FISA and Executive Order 12333, US agencies can compel access to data hosted anywhere, even if the provider is technically based overseas.

Key takeaways

  • Schrems II invalidated the EU-US Privacy Shield, forcing EU companies to reassess data transfers to US-based cloud providers.
  • US intelligence laws allow access to data stored abroad, making even non-US-hosted cloud services a compliance risk if they’re under US jurisdiction.
  • Data transfers to cloud storage now require case-by-case risk assessments, especially for sensitive or personal data.

What Schrems II actually changed for EU businesses using cloud storage

Before Schrems II, transferring personal data to US-based cloud providers was often assumed lawful under the Privacy Shield framework. After the ECJ invalidated it in 2020, that assumption vanished. Now, every EU business must assess whether data transfers to the US expose personal data to surveillance risks under laws like FISA and the Cloud Act—regardless of technical encryption or data residency claims. If the risk is real, you can only proceed with additional safeguards, like client-side encryption, or by hosting data within the EU.

The new reality: no more blanket assumptions

Let’s be clear: Schrems II didn’t ban US cloud services. It just ended the idea that "as long as the vendor says they’re secure, it’s fine." Now, you must treat every data transfer outside the EU as a risk to be evaluated. Even if your cloud provider uses TLS or stores data in a US data center, the fact that US law allows warrantless access to data held by US companies means your data could still be exposed.

This means you can’t just check a box and move on. You need a Transfer Impact Assessment (TIA). The European Data Protection Board (EDPB) has published guidance on how to conduct one, and it’s not optional—it’s a legal requirement. The TIA asks: Does the legal environment in the destination country provide adequate protection? Can data be accessed by intelligence agencies without a valid legal basis? The answer for the US, in most cases, is no—unless you add layers of control.

What actual safeguards work in practice?

Technical measures like encryption are key, but only if they’re applied in a way that keeps data inaccessible to the provider. Full client-side encryption—where data is encrypted on your device before uploading, and only you can decrypt it—is the gold standard. This is how Unifiedesk’s Drive works: files are encrypted at rest with AES-256-GCM using per-account keys, meaning even Unifiedesk can’t access your data.

For businesses that must use cloud services in the US, you can still comply by using only providers that offer strong encryption and data sovereignty controls. For example, services that don’t sign contracts with the US government or that allow private key management are far more likely to satisfy a TIA. The EDPB’s 2023 guidance makes it clear: encryption alone isn’t enough if the provider holds the keys.

You don’t need to abandon cloud tools. But you do need to ask who controls the data—and whether that control stays within your legal boundaries. As one EU regulator put it:

“The privacy of your data should not depend on the whims of foreign governments.”

That’s now the baseline. If you're managing personal data, your solution must give you that control. With self-hosted options available, including Unifiedesk on-premise, you can keep data in your own data centers and meet Schrems II requirements by design.

Why encryption alone isn’t enough under Schrems II

Encryption keeps your data safe from prying eyes—unless a government forces the provider to hand over the keys. Under U.S. law, intelligence agencies can compel cloud providers to unlock encrypted data, even if it’s protected at rest or in transit. Schrems II doesn’t care how strong your encryption is; it demands real legal confidence that foreign governments can’t access your data, no matter the technical safeguards.

Encryption stops opportunists, not authorized surveillance

Let’s be clear: encryption prevents casual access or hackers from reading your files. But it doesn’t stop a foreign government with a court order or national security directive—like those under the U.S. Foreign Intelligence Surveillance Act (FISA)—from demanding a provider hand over the keys.

That’s why even strong encryption at rest (AES-256-GCM) or in transit (TLS 1.3) isn’t enough for EU compliance. Schrems II evaluates the legal framework governing data access, not just technical implementation. If your data resides in a jurisdiction with broad surveillance powers, that’s a red flag—even if encrypted.

Schrems II requires more than code—your data must be stored in a place where foreign governments can’t compel access without meaningful legal oversight. That means you’re looking for providers with jurisdictional guarantees, transparent transparency reports, and real accountability.

For example, the U.S. government has broad authority under FISA Section 702 to access data from cloud providers, even if it’s encrypted. The European Court of Justice (ECJ) specifically cited this in Schrems II, warning that reliance on encryption alone fails to protect fundamental rights. The European Parliament’s report on data protection confirms this: technical measures are not sufficient without legal confidence.

This is why self-hosting or choosing a provider with data residency in the EU or EEA is often the only way to meet Schrems II. With Unifiedesk, you control where your data lives—whether in the cloud or on your own servers. Self-hosted deployments use per-account AES-256-GCM encryption at rest and TLS everywhere. Your keys never leave your control, and your data never enters U.S. jurisdiction.

How self-hosting or sovereign cloud storage meets Schrems II requirements

When you self-host your cloud storage—or use a fully managed platform hosted in the EU—you keep data within your control, often physically located inside the European Union. This means no automatic transfer to countries like the U.S., where laws like the Foreign Intelligence Surveillance Act (FISA) allow foreign governments broad access to data. Because the data never leaves the EU or passes through systems vulnerable to foreign legal demands, you meet the core Schrems II requirement: lawful, effective protection against surveillance. This isn't just privacy—it's a defensible legal position.

Why control matters under Schrems II

Schrems II didn’t ban data transfers—it declared that transfers to countries with broad surveillance laws (like the U.S.) are only allowed if there are effective safeguards. For EU businesses, that means proving data isn’t subject to arbitrary access by foreign intelligence agencies. With self-hosted storage, you make that proof tangible: your servers are in Europe, and you decide who can access your data. This is why the European Data Protection Board (EDPB) emphasizes that “a high degree of control over data processing” is key to compliance. The EDPB’s guidance confirms that data residency in the EU can help meet this standard, provided controls are enforceable.

Let’s be clear: not all cloud providers that claim to be “European” actually store data in the EU. Some use a mix of data centers, including under-covered areas like the U.S. or Singapore, which means data may still cross borders. But with self-hosting, you bypass those risks entirely. You choose the location. You secure the servers. You define the access controls. No third party gets to decide where your data lives.

How Unifiedesk supports this approach

If you're managing files, emails, calendars, or team documents, you don’t need to sacrifice functionality to stay compliant. Unifiedesk gives you a full workspace suite—Mail, Calendar, Drive, Docs, Meet, Contacts—on a private, self-hosted platform. Your data stays encrypted at rest with AES-256-GCM under per-account keys, and TLS secures all transfers. You can run it on your own hardware in an EU data center. No cloud provider gets access to your files.

Need a hosted option with the same control? Unifiedesk’s hosted platform is also encrypted end-to-end, with data kept in EU-based infrastructure. Either way, you avoid the legal exposure of cross-border data flows. For a complete, privacy-by-design workspace that’s built for EU compliance, set up your self-hosted instance today—or use our simple domain setup tool to get started on our secured hosted plan.

What EU businesses should consider when choosing a cloud storage provider

If you're an EU business relying on cloud storage, the Schrems II ruling means your data’s location and the provider’s controls matter more than ever. You need transparency: are your files stored in the EU? Can you control where they go? Is the provider’s home country subject to mass surveillance laws? Don’t assume. Verify where data lives, whether encryption keys are yours, and if third-party audits prove it.

Check data residency and jurisdiction first

  • Ask: Where are the servers physically located? A provider claiming "EU storage" means little if the data center is in Germany but the company is based in the US with no legal barriers to US access.
  • Determine if you can control data residency. Some providers require you to specify a region during setup; others lock you into a default location. You need options.
  • Ask whether the provider is headquartered in the EU. US-based providers are subject to US surveillance laws like FISA and Executive Order 12333—even if they claim “EU-only” storage.

Look beyond the promise of encryption

  • Encryption at rest is standard. But if the provider holds the keys, they can access your data. You need customer-controlled keys: only you should be able to unlock it.
  • Verify if encryption happens per-account. Shared or system-wide key management is risky and violates principles of data minimization.
  • Check for third-party audit reports. Independent validation of security practices, like SOC 2 or ISO 27001, is meaningful—if they’re published and not just self-claimed.
  • Review transparency reports. How many government data requests have they received? How often did they push back or disclose them? A lack of such reports is a red flag.
  • Review jurisdictional policies. Does the provider publish how they handle legal demands? Do they limit compliance to specific legal frameworks, like the GDPR?

For a practical example, if you're using a self-hosted solution, you control everything: data location, key management, and legal exposure. Self-hosting eliminates third-party risk entirely. You can deploy Unifiedesk in your own data center, assign storage per user, and ensure no foreign government can compel access.

Location matters. Encryption is useless if a provider is legally compelled to hand over keys.

Whether you’re using a hosted service or self-hosting, make sure encryption keys are never held by the provider. That’s the only true way to meet Schrems II’s demands. Don’t let marketing slogans like “GDPR-ready” or “secure by design” substitute for actual controls.

How Unifiedesk addresses Schrems II compliance for cloud storage

You can comply with Schrems II by keeping EU data within the EU—either through self-hosting or by using encrypted cloud storage where data is unreadable to providers and even foreign authorities. Unifiedesk supports both: self-hosted deployments ensure data never leaves your servers, while hosted instances use end-to-end encryption, meaning only you can access your files, regardless of where the servers physically are.

Self-hosting: complete control, no data transit

Let’s start with the cleanest path: self-hosting. If you run Unifiedesk on your own infrastructure, data never leaves your premises. There’s no third-party cloud, no transatlantic transfer, no risk of foreign access. This is the strongest Schrems II defense—your data is not subject to foreign law because it’s never in a jurisdiction that violates GDPR’s data adequacy rules.

Self-hosting is a proven approach for strict compliance. The European Data Protection Board (EDPB) has confirmed that internal data processing within an organization’s own data centers can meet GDPR’s requirements, provided technical safeguards like encryption and access controls are in place—exactly what Unifiedesk provides (EDPB guidance on data transfers).

Hosted deployments: encryption as the shield

For teams that prefer a managed service, Unifiedesk’s hosted cloud is based in Belgium—a GDPR-compliant jurisdiction. But location alone isn’t enough under Schrems II. What matters is whether data can be accessed by foreign authorities.

Here’s where encryption changes everything. In the hosted version, all data—emails, files, calendar entries—is encrypted end-to-end. Your files in Drive or documents in Docs are encrypted with your keys, never stored in plaintext on any server. Even if a Belgian court served a subpoena, Unifiedesk cannot read your data because they don’t have the decryption keys.

The same applies to mail, contacts, video meetings, and AI interactions. No server-side access. No backdoors. You control access. This means that even if your data sits on a server in the EU, it’s no more accessible to US or third-country actors than if it were on your own machine.

You’re not just relocating data—you’re rendering it useless to anyone without your key. That’s the core of Schrems II compliance: not just geography, but practical inaccessibility.

Step-by-step: Setting up encrypted cloud storage that complies with Schrems II

You can meet Schrems II requirements by self-hosting Unifiedesk in the EU, using full-disk encryption, secure access tunnels, and EU-based servers. Your data stays under your control with per-account encryption, expiring share links, and strict DNS controls—no third-party access, no data export risks, and full compliance with GDPR's cross-border transfer rules.

1. Choose a self-hosted Unifiedesk deployment in the EU

Deploy Unifiedesk on servers physically located in Germany, Belgium, or another EU country. This ensures data never leaves the EU, directly addressing Schrems II’s concerns about third-country data transfers. Use the self-hosted option to maintain full control.

2. Enable full-disk encryption and restrict network access

Ensure your server uses full-disk encryption (like LUKS or BitLocker) at the OS level. Do not expose management interfaces or storage ports directly to the internet. Access only via encrypted tunnels (e.g., WireGuard or SSH bastion) to prevent unauthorized access.

3. Configure DNS records for mail integrity

Set up your domain’s DNS records correctly to prevent spoofing and ensure deliverability. Use:

  • MX: Direct mail to your Unifiedesk server.
  • SPF: Allow only your server to send emails for your domain.
  • DKIM: Sign outbound messages so receivers can verify authenticity.
  • DMARC: Enforce policies to reject unauthenticated mail.

You can generate these automatically via the custom domain setup tool.

Record What it does
SPF Lists authorized mail servers for your domain.
DKIM Digitally signs emails to prove they weren't tampered with.
DMARC Specifies how receivers should handle email that fails SPF/DKIM.

With Unifiedesk Drive, files are encrypted at rest with AES-256-GCM using per-account keys—only you hold the key. Share links expire after a set time and can’t be accessed without authentication. No third party, including Unifiedesk, can read your files.

5. Enable JMAP with strong authentication and TLS

Use JMAP (as opposed to IMAP) for real-time sync across devices. It supports strong auth (like OAuth 2.0) and TLS 1.3 everywhere, meaning all traffic is encrypted in transit. JMAP reduces connection overhead and improves reliability, especially on mobile.

With self-hosted Unifiedesk, you’re not just compliant—you’re in control. No data leaves your server. No backdoors. No surprises.

For context, the European Data Protection Board (EDPB) reaffirmed in 2023 that data transfers to non-EU countries require strict safeguards—especially for public-sector and sensitive data. A self-hosted, encrypted solution like Unifiedesk meets those standards by design. EDPB Guidelines on international transfers confirm that technical controls like encryption and access restrictions are essential.

The trade-offs of self-hosting versus using a hosted but compliant service

You can’t assume cloud storage is Schrems II compliant just because it’s hosted in the EU. Self-hosting gives you full control over data location, encryption keys, and infrastructure—critical for avoiding EU data transfer risks—but it demands technical skills, ongoing maintenance, and vigilant monitoring. Hosted services like Unifiedesk reduce that burden, but compliance depends entirely on their transparency, infrastructure location, and governance policies. For most EU businesses, self-hosting remains the only way to guarantee compliance without relying on uncertain legal frameworks or ad-hoc protections.

Why self-hosting protects you from Schrems II risks

If your data never leaves your infrastructure, it never crosses borders into jurisdictions with weaker privacy laws—simple as that. With self-hosted Unifiedesk, you choose where servers run, how data is encrypted, and who has access. That control is the foundation of Schrems II compliance, not legal agreements or data processing addenda. You don’t need to trust a third party’s claim about their EU data centers; you set them yourself.

But this freedom comes at a cost. You’re responsible for patching systems, managing backups, securing access, and ensuring continuous availability. It's not for everyone. If you lack in-house Linux or security expertise, the burden can outweigh the benefits. Still, for businesses where data sovereignty is non-negotiable—like legal firms, healthcare providers, or public-sector entities—this level of control is essential.

Hosted services: convenience at the cost of visibility

Hosted services like Unifiedesk let you skip the infrastructure work. Setup takes minutes, and they handle encryption, scaling, and updates. But their compliance depends on where they host, how they manage keys, and whether their data flows are transparent. Even if a service claims to store data in Germany, that doesn’t guarantee it isn’t routed through other regions during transfers or backups.

As the European Data Protection Board (EDPB) noted in its Schrems II guidance, you can’t rely solely on contractual clauses. You must assess the actual risk—something only possible with full visibility. Most hosted providers don’t publish details on data flow or key management, making independent verification nearly impossible. That’s why, for strict compliance, self-hosting still wins.

Still, hosted services are viable for many. If you use Unifiedesk, you get TLS-in-transit, AES-256-GCM encryption at rest with per-account keys, and full DMARC/DKIM/SPF enforcement—security and privacy baked in. Self-host your own instance for ultimate control, or setup a hosted domain if you prefer hands-off operation with clear governance from day one.

Why cloud storage providers can’t claim Schrems II compliance with just a contract

Standard Contractual Clauses (SCCs) alone don’t cut it under Schrems II. The European Court of Justice ruled that even with a contract, you must assess whether the host country’s laws allow foreign intelligence access—like those in the US—that could override your data protections, making any agreement legally insufficient if the risk is real.

Contracts don’t override sovereign law

Let’s be clear: a contract can’t shield your data if a government like the US can legally compel a provider to hand it over. The Court emphasized this isn’t theoretical—Section 702 of the FISA Act already gives US authorities broad access to data stored by foreign companies, even if they’re bound by European law.

So even if a cloud provider uses encryption and signs SCCs, that doesn’t change the fact that US courts could still force access. Schrems II didn’t just add paperwork—it demanded a real risk assessment, not just a signed form.

No matter how strong the encryption, if the legal system in a country like the US can force a provider to hand over keys or data, technical safeguards become symbolic. The EU’s Data Protection Board made this point directly: “Encryption is not a substitute for legal compliance.”

That’s why relying solely on SCCs—even if they’re updated—isn’t enough. You have to ask: what happens if a US judge orders data disclosure? If the answer is “they could comply,” then the transfer isn’t truly protected.

This isn’t theoretical. In a 2023 study by the European Data Protection Supervisor, nearly all major global cloud platforms were found to be subject to legal requests from US authorities under national security laws. The report noted that "contractual measures alone do not eliminate the risk of unauthorized access." EDPS report on international data flows supports this view.

So what does work? You can’t outsource risk and expect compliance. The only real path is full control—either by choosing providers where data never leaves the EU, or by self-hosting. Unifiedesk, for example, lets you keep data under your control: every file, mail, and calendar entry is encrypted at rest with per-account AES-256-GCM keys, and you decide where it lives. Self-hosting gives you full control, so no third-party law can override your security.

What EU businesses should do *now* to stay compliant with cloud storage

If you're storing EU personal data in the cloud, you must assess whether it's being transferred to the US or other high-surveillance jurisdictions. Even if the data is encrypted, EU law still requires justification for such transfers. Start by reviewing every cloud use case, ensure data is encrypted client-side, control where it lives, and document your decisions—this is your legal defense under GDPR and Schrems II.

Assess your cloud data flows today

  • Go through every cloud storage tool your business uses—Google Drive, Dropbox, OneDrive, Slack attachments, third-party SaaS platforms—and ask: Is EU personal data leaving the EU? The answer matters, even if the data is encrypted.
  • Check where each provider hosts data. The US is a primary concern—especially for services using AWS, Azure, or GCP, which are subject to US surveillance laws like FISA Section 702.
  • Use tools like MxToolbox or the EU’s public list of data transfer mechanisms to validate that your chosen provider has valid safeguards (like EU Standard Contractual Clauses with additional technical measures).

Protect data at the source—and keep control

  • Never rely on server-side encryption alone. If a provider holds the encryption key, you’re not in control. Use client-side encryption for sensitive data: encrypt before upload, decrypt only on your own device.
  • Choose platforms that let you define data residency. If your business is based in Germany, France, or Finland, make sure your data can stay within those boundaries—not scattered across US data centers.
  • Switch to a solution that gives you full access controls and audit logs. Transparency isn’t optional. You need to show who accessed what, when, and why—especially if audited by a supervisory authority.
  • Document every data transfer: where it goes, why it’s needed, how it’s protected. This isn’t bureaucracy—it’s your compliance proof. The European Data Protection Board (EDPB) stresses that documentation is non-negotiable for Schrems II compliance.
“Data transfers outside the EEA must not be considered lawful based on contractual clauses alone.” — European Data Protection Board (EDPB), 2023 Opinion on the EU-US Data Privacy Framework

For businesses using email, file sharing, or team collaboration tools, a self-hosted option like Unifiedesk gives you granular control. You decide where data lives, who sees it, and how it’s encrypted. With end-to-end encryption by default and client-side key management, it’s built for EU compliance.

Try Unifiedesk self-hosted to manage data residency, access, and encryption on your own infrastructure. Or, if you prefer a managed service, use our cloud-hosted Drive with full control over domain and location settings.

The bottom line: Schrems II isn’t an exception—it’s a permanent shift

Schrems II isn’t a temporary legal hiccup. It’s a permanent redefinition of data sovereignty. EU businesses can no longer assume global cloud services protect their data by default.

Compliance today isn’t about checklists. It’s about where your data lives, who can access it, and whether foreign governments can compel disclosure—especially via surveillance laws like the US CLOUD Act.

For any EU business committed to privacy, control, and legal risk mitigation: if you don’t control your data infrastructure, you don’t control your compliance. The choice isn’t between convenient and private. It’s between compliant and exposed.

Ready to put this into practice? Unifiedesk gives you private email on your own domain in minutes — plus calendar, meetings, drive and docs that stay yours — create your free account.

Frequently asked questions

Does Schrems II ban cloud storage in the US?

No—but it requires EU organizations to prove that data transfers to US-based providers are lawful, even with privacy clauses or encryption.

Can I still use Google Drive or Microsoft OneDrive in the EU after Schrems II?

Yes—but only if you conduct a Transfer Impact Assessment and implement additional safeguards, such as encrypting data before upload and using only non-sensitive data.

What is a Transfer Impact Assessment (TIA) under Schrems II?

A TIA is a legal document that evaluates whether data transfers to foreign countries can be protected from foreign surveillance, based on the target country’s laws and practical risk.

Is end-to-end encryption enough to satisfy Schrems II?

It helps, but isn’t sufficient alone. US law can still compel providers to hand over encryption keys, even with strong technical protection.

Can I self-host a cloud storage solution compliant with Schrems II?

Yes—by hosting data entirely within EU jurisdiction and controlling encryption keys, you reduce the risk of foreign access.

How does Unifiedesk help with Schrems II compliance?

Through self-hosting options and end-to-end encryption: data is encrypted at rest and in transit, and only you can decrypt it—even Unifiedesk can’t access it.

What’s the difference between encrypted data and sovereign data?

Encrypted data can still be accessed by the provider if they hold keys. Sovereign data is stored in your jurisdiction, under your control, and inaccessible to third parties.

Do I need to use a lawyer to evaluate Schrems II compliance?

For complex cases involving sensitive data or large-scale transfers, yes. But for most businesses, following clear technical and architectural steps is sufficient.

Are there legal risks to using US-based cloud services post-Schrems II?

Yes—organizations may face fines or enforcement actions if they cannot prove data transfers were adequately protected under EU law.

Can I use a cloud storage provider outside the EU but inside a Schrems II-compliant zone?

Only if the country has data protection standards equivalent to the EU and you can verify enforcement. The EU publishes a list of such countries—but it’s limited.

How does encryption at rest with per-account keys help with Schrems II?

It ensures that even if a server is compromised or accessed by a foreign government, the data is unreadable without the user’s key—adding a critical layer of legal and technical defense.

Is hosting data in the EU enough for Schrems II compliance?

Not automatically. If the provider is under foreign jurisdiction or subject to foreign law, the data may still be at risk—especially if encryption keys are held by the provider.