Servers in de EU, eigen (dubbele) sleutels: helpt het? - Bert Hubert's writings
a day ago
- EU server location does not protect data from US surveillance due to the CLOUD Act.
- US companies may share data for AI, advertising, or with partners despite contracts.
- US intelligence can access data under laws like FISA Section 702 and EO 12333, without notification.
- Double Key Encryption (DKE) by Microsoft is complex, limited to 5% most sensitive data, and impractical for common use.
- Bring your own key or double encryption cannot fully protect against US government access or sanctions.
- US sanctions can disable cloud services for European entities, as seen with Amsterdam Trade Bank.
- Server location in the EU may inadvertently make data easier to surveil under US law.
- Practical solutions require acknowledging risks and limiting sensitive data in US clouds.