Background

US CLOUD Act, European DNS and why jurisdiction beats data residency

Many European organisations assume that hosting or DNS in an EU data centre automatically keeps them clear of US law. Jurisdiction of the provider often matters more than where the server sits.

This guide is general information for operators and buyers, not legal advice. For compliance decisions, use your own counsel and your supervisory authority guidance.

What the US CLOUD Act is

The Clarifying Lawful Overseas Use of Data (CLOUD) Act (2018) can require US providers to disclose data under their control to US law enforcement, even when that data is stored outside the United States. If your DNS, mail or portal runs on a US parent company (or a European subsidiary of one), the legal reach can follow corporate control, not only the rack location in Amsterdam or Frankfurt.

Tension with GDPR Article 48

GDPR Article 48 addresses transfers and disclosures based on judgments or decisions from third countries. Orders from outside the EU are not automatically valid in the EU without an international agreement (such as an MLAT) or another lawful basis. A US-regulated provider can face conflicting duties: comply with a US order, or risk breaching European rules. Buyers should treat “EU region” marketing as residency, not as a full answer on jurisdiction.

Why DNS is part of this discussion

DNS is the internet’s address book. Queries and resolver paths create metadata about who looks up which names and when. Authoritative DNS and related control planes sit on the critical path for websites and mail. Putting those controls under a non-EU parent can widen who can compel access to operational data, even when content storage looks “European”.

“EU data regions” are not the same as EU jurisdiction

US vendors often offer European regions and sovereignty tooling. That can help with where bits are stored. It does not by itself remove US corporate jurisdiction over the provider. For many European buyers, the practical question is: who owns and operates the company that runs your domain, DNS, mail and customer portal?

What a realistic EU stack looks like on NovaMX

NovaMX B.V. is a Dutch company. The customer journey for domains and DNS (including DNSSEC), web hosting, European CDN for hosted sites, business email, MailControl (DMARC, SPF flattening, BIMI, MTA-STS) and website monitoring stays under one My NovaMX account. Public TLS for NovaMX hosts uses Actalis. That design reduces US CLOUD Act exposure on the registrar-to-mail path compared with stitching US hyperscaler tools into the same journey.

NovaMX is not a global Cloudflare-style anycast WAF or volumetric DDoS scrubbing network. If you need that class of edge product, use a specialist. See our European platform guide for scope.

Practical checks before you buy

  1. Ask who the contracting entity is, and whether a US parent can compel the operator.
  2. Separate data residency promises from jurisdiction and subprocessors on DNS, mail and identity.
  3. Prefer one account for domain, DNS, MX and authentication so changes stay auditable.
  4. Verify public baselines (for example Internet.nl and Hardenize on novamx.eu) and read Trust & security for company facts.

Next steps

Read the European platform guide for product scope, then Domains, Mail security or Contact. During soft launch, new customer enquiries go to Contact rather than open self-registration.