Data sovereignty

GDPR and email hosting: what the regulation actually requires

Choosing where mail holding personal data rests, and who operates that storage Which transfer are you making? Your mail EU disks, EU firm Outside the EEA EU disks, US firm Chapter V turns on control, not only location

Under GDPR your email host is a processor and you are the controller. That single allocation, from Article 4(7) and 4(8), determines nearly everything else: the host owes you a contract and security measures, and you owe the regulator an account of why those mailboxes exist, how long they persist, and what happens when someone asks for a copy of their data.

“GDPR-compliant email hosting” is therefore a category error as usually advertised. A provider can be a compliant processor. Compliance itself is a property of your processing, not of your vendor.

What does GDPR actually require from email hosting?

Four things, concretely: a processor contract with the terms Article 28(3) enumerates, security appropriate to the risk under Article 32, a lawful basis for transfers under Chapter V if any data leaves the EEA, and a breach chain that meets Article 33.

Article 28(3) is a checklist, and it is worth reading rather than trusting. The contract must be in writing and must bind the processor to: act only on your documented instructions; impose confidentiality on anyone handling the data; apply Article 32 measures; engage no sub-processor without your authorisation and inform you of intended changes; assist you with data subject rights; assist with your Articles 32 to 36 obligations; delete or return the data at the end of the engagement; and make available the information needed to demonstrate all of it, including submitting to audits.

Article 32 asks for measures appropriate to the risk and names encryption and pseudonymisation as examples. Article 30 requires you, not your host, to keep records of processing — and mailboxes are processing.

Then the parts controllers forget. Storage limitation, Article 5(1)(e): mail kept forever by default is the most common unlawful retention I encounter, because nobody ever decided to keep it, the system simply never deleted anything. And subject access, Article 15: mailbox search is where most access requests are actually answered, which makes your host’s search and export capabilities a compliance dependency whether or not anyone wrote that down.

What does a “GDPR-compliant” claim usually mean?

In practice it means four things, all real and none sufficient: a data processing agreement you can sign online, storage in an EU region, an ISO 27001 certificate, and encryption in transit and at rest.

That is a reasonable processor package. Here is what it does not cover, and what stays with you no matter which vendor you pick.

Your lawful basis for the processing, and your privacy notice describing it. Retention periods per mailbox category and the deletion mechanism that enforces them. The workflow that answers access, rectification and erasure requests inside a month. Your Article 30 records. Your transfer impact assessment where the processor or its sub-processors sit in third countries. Employee monitoring rules — reading a departed colleague’s mailbox has its own national law layered on top of GDPR, and in Germany or France that layer is not decorative. And a DPIA under Article 35 where the processing is high risk, which mailboxes for special category data usually are.

A vendor cannot do any of that for you. Anyone implying otherwise is selling reassurance.

Why are US providers still a transfer problem?

Because control, not location, triggers Chapter V, and a US-controlled provider carries US legal reach into the EU with it.

The chain is short. Schrems II (Case C-311/18, 16 July 2020) annulled the Privacy Shield adequacy decision and held that standard contractual clauses remain valid only where the exporter verifies, case by case, that the destination country’s law does not undermine them. The CLOUD Act, in force since 2018, obliges a provider subject to US jurisdiction to produce data in its possession, custody or control regardless of where the data is stored. GDPR Article 48 recognises a third-country authority’s order to transfer personal data only where it rests on an international agreement such as a mutual legal assistance treaty. A warrant served directly on a provider is not one.

The EU–US Data Privacy Framework, adopted in July 2023, gives an adequacy route again for certified US recipients, and it makes the paperwork considerably easier. It is also the third such bridge; the two before it were annulled in 2015 and 2020. Planning for the possibility that a supervisory authority or a court revisits it is prudence, not paranoia.

Nothing here forbids using a US provider. It means the transfer analysis is yours to document, to keep current, and to defend — and that a European public body will often decline the exercise entirely rather than perform it.

What should you verify before signing?

Nine things. I would ask them in this order, and I would want the answers in writing.

Where is the entity that holds the stored bytes incorporated, and does it have a US parent or subsidiary? This determines the transfer analysis, and it is the question vendors answer least directly.

Who can decrypt the mail, technically? If the provider can render your mailbox in a browser, it holds the key. That is a legitimate design, but it is not the same as encryption you control, and Article 32 documentation should say which one you bought.

Is there an Article 28(3) contract with a complete sub-processor list, locations, and a notice period for changes? A DPA without the list is half a DPA.

From which countries can support staff access mailbox contents, and is that access logged in a way you can see?

What is the breach notification commitment, in hours, from the processor to you? Your own 72-hour clock under Article 33 starts when you become aware, so a vague “without undue delay” leaves you carrying the vendor’s latency.

How do you execute retention and erasure? Not whether a delete button exists — whether it reaches backups, and on what schedule.

What is the export format, and can you read it without the provider’s software? Mail in a documented, standard layout is portable. Mail in a proprietary store is a dependency dressed as an archive.

What happens to the data on termination, and how is deletion evidenced?

And, if it matters in your sector: which attestations cover this specific service, not the parent company. C5, HDS, SecNumCloud and ISO 27001 all have scopes, and the scope is where the interesting details live.

I am a founder rather than a lawyer, and none of this is legal advice. It is the regulation and the reported judgments — cite them, not me.

Frequently asked questions

What does GDPR require from an email host?

That it act as your processor under a contract meeting Article 28(3): processing only on your documented instructions, confidentiality obligations on staff, security measures under Article 32, no new sub-processor without authorisation, assistance with data subject requests and breach duties, and deletion or return of the data when the contract ends. The host owes you those terms; the lawfulness of what you do with the mailboxes stays yours.

Does a GDPR-compliant email provider make my email use compliant?

No. A provider can only supply its half: a processor contract, security measures, breach notification and a defensible transfer position. Your half stays with you — lawful basis, retention limits under Article 5(1)(e), records of processing under Article 30, answering access and erasure requests, employee monitoring rules, and a DPIA where the processing warrants one.

Is Gmail or Microsoft 365 GDPR compliant for business email?

Both offer processor terms and EU storage options, so they can be used lawfully. The difficulty is Chapter V: both are US-controlled, so a transfer analysis is required even for data stored in Europe, and several European supervisory authorities have criticised or restricted public-sector deployments over exactly that. It is a documentation burden rather than an automatic prohibition.

How fast must an email breach be reported under GDPR?

A controller must notify the competent supervisory authority within 72 hours of becoming aware of a personal data breach under Article 33, unless the breach is unlikely to result in risk. A processor must notify its controller without undue delay. Affected individuals must be told under Article 34 where the risk to them is high, though Article 34(3)(a) excuses that notice where measures such as encryption render the data unintelligible.

Does encryption at rest satisfy GDPR for email?

It is evidence of appropriate security, not a compliance certificate. Article 32(1)(a) names encryption as an example measure and Article 34(3)(a) treats it as a reason to skip notifying individuals. Neither provision cares where the key is, so ask who holds it: encryption a provider can reverse is a control against outsiders, not against the provider.