HN Debrief

Fastmail offers EU data region

  • Privacy
  • Infrastructure
  • Regulation
  • Europe
  • Security

Fastmail’s post says European customers can now choose to store their primary mailbox data in an Amsterdam region that Fastmail runs itself on owned hardware in a colocation facility. The company stresses that this is not an EU-only guarantee. Replicas still exist in the US for resilience, logs and some other data are not fully moved, and full EU-only operation would require a second EU site for disaster recovery. That honesty landed better than the feature itself. People liked that Fastmail finally shipped something many customers wanted, but the main reaction was that the announcement is easy to overread as a privacy or sovereignty win when it is really a narrower infrastructure change.

Treat this as a partial compliance and latency improvement, not a sovereignty solution. If your requirement is to keep mailbox access out of US or Five Eyes legal reach, you still need to evaluate provider jurisdiction, corporate structure, backup location, and whether email is even the right tool.

Discussion mood

Cautiously positive about Fastmail shipping an EU option, but mostly skeptical that it solves the problem people actually care about. The strongest mood was that jurisdiction and provider ownership matter more than server location, especially for an Australian company with US backups and for email as an inherently weak privacy medium.

Key insights

  1. 01

    CLOUD Act is often oversimplified

    The most useful legal clarification was that the famous "data stored abroad" piece was mostly a fix for the Stored Communications Act, which had treated a subpoena-like order as if it had the territorial limits of a warrant. The more consequential part was the mechanism for faster bilateral access agreements, because that opens a cleaner path for foreign governments to request data directly from service providers with weaker democratic checks than a full treaty process.

    Do not reduce cross-border data risk to a slogan about where disks sit. Ask counsel which legal instruments apply to your provider, including executive data-sharing agreements and local conflicts-of-law exposure.

      Attribution:
    • tzs #1
  2. 02

    Fastmail is not renting AWS

    A lot of people assumed this was another regional checkbox built on Amazon or Microsoft. It is not. Fastmail’s founder and other informed commenters said the service runs on its own hardware in colocation facilities, and the post itself says the Amsterdam region was installed and operated by Fastmail engineers. That does not solve jurisdiction, but it removes one whole layer of dependence on a US cloud vendor.

    If you care about sovereignty, separate "who owns the company" from "who owns the infrastructure." Both matter, and Fastmail looks stronger on the infrastructure side than many larger vendors.

      Attribution:
    • jph00 #1
    • chrismorgan #1
    • microtonal #1
    • calvinmorrison #1
  3. 03

    Australia law matters differently for Fastmail

    The scary Australian law in this context is not the one many people reached for. Because Fastmail does not offer end-to-end encrypted mail, the Assistance and Access Act is less relevant than ordinary lawful access under Australia’s Telecommunications Act. In plain terms, Fastmail has always been able to comply with warrants for mailbox contents, so the incremental risk here is not about forcing decryption backdoors into an end-to-end system that does not exist.

    Map legal risk to the actual product architecture. If a provider can already read stored content, debates about anti-encryption laws may be a distraction from the more direct disclosure powers it already faces.

      Attribution:
    • chrismorgan #1
    • rzerowan #1
  4. 04

    Cross-border orders create law conflicts

    The more realistic failure mode is not a single government cleanly reaching every server. It is a provider getting trapped between incompatible obligations in different countries. The OVH Canada example showed how handing over data to satisfy one jurisdiction can expose the parent or sibling entity elsewhere to criminal or financial penalties. That makes multinational structures less of a magic shield and more of a legal minefield.

    If you run or buy from a multinational provider, ask where the decision-making entity sits and what happens when legal orders conflict across affiliates. Corporate separation helps only if it is matched by real operational separation and a credible willingness to absorb local penalties.

      Attribution:
    • kvemkon #1
    • jorvi #1
    • petcat #1
  5. 05

    European buyers are actually moving

    What stood out was not abstract anti-US sentiment but concrete examples of switching behavior. People pointed to Airbus moving critical apps to Scaleway, Dutch efforts to cut reliance on US cloud vendors, payment and public sector procurement shifts, and repeated warnings from noyb about the fragility of EU-US data transfer arrangements. That makes Fastmail’s move look less like a niche feature and more like a response to a real buying trend.

    If you sell infrastructure or SaaS into Europe, assume sovereignty questions are now part of enterprise procurement. You need a crisp answer on jurisdiction, subcontractors, backups, and exit paths before a customer asks.

      Attribution:
    • jacquesm #1
    • toomuchtodo #1
    • j0057 #1

Against the grain

  1. 01

    Email is the wrong privacy battleground

    The sharpest pushback was that trying to make email sovereign or private at the storage layer overstates what email can ever deliver. Mail routing leaks metadata, transport security still has downgrade and interoperability issues, and recipients usually store copies on other systems anyway. On that view, focusing on EU residency for mailboxes risks selling a feeling of safety that the protocol cannot cash.

    Use email for ordinary communication and records, not for secrets that depend on storage location. Move sensitive conversations to end-to-end encrypted messaging and treat mail retention as a resilience and compliance question.

      Attribution:
    • superq #1
    • microtonal #1
    • ln809 #1
  2. 02

    Partial steps still have value

    A smaller but credible view was that this launch does not need to be perfect to be worth doing. Even without airtight sovereignty, reducing routine data handling in the US and giving European customers a closer region is a meaningful directional improvement. The symbolism also matters because buyers are actively looking for ways to unwind US dependence over time.

    Do not dismiss incremental architecture changes just because they fall short of an absolute guarantee. For some customers, a staged path with clear limits is enough to justify migration or renewal.

      Attribution:
    • toomuchtodo #1
    • tmgldn #1
    • trocado #1

In plain english

CLOUD Act
A United States law that governs when service providers can be compelled to provide data and how the US can make data-access agreements with other countries.
colocation
A hosting model where a company installs and manages its own servers inside a third-party data center facility.
disaster recovery
Infrastructure and processes used to restore systems and data after outages, failures, or site loss.
EU
European Union, a political and economic bloc of European countries with shared laws and institutions.
EuroStack
A push for Europe to build and buy more of its own digital infrastructure instead of relying on foreign technology providers.
noyb
A European digital rights group known for legal challenges around privacy and international data transfers.
Pobox
An email forwarding and mailbox service company that Fastmail merged with, adding a US business presence.
Stored Communications Act
A United States law covering government access to stored electronic communications such as email held by service providers.

Reference links

Legal and policy references

Examples of European sovereignty shifts

Privacy advocacy and transfer-risk analysis

Provider alternatives