Skip to content
Independently verified · Quarterly re-audit
EU VETTED
Curated collection

Cloud storage without US sub-processors

European cloud-storage services verified to run with no US sub-processors, compared on ownership, hosting region, CLOUD Act exposure and sub-processor chain.

In short

The cloud-storage services listed here operate with no US sub-processors in the data path: an EU/EEA/Switzerland operator with no US parent and no US-incorporated processor handling file data. kDrive by Infomaniak (Switzerland, Geneva, own Swiss data centres, ISO 27001) and luckycloud (Germany, Berlin, zero-knowledge encryption on its own German hardware) are the strongest fully-managed options; Nextcloud (Germany, Stuttgart) is the open-source standard, clean as a managed EU service or self-hosted. In cloud storage the exposure usually re-enters through a US CDN in front of the service, an S3-compatible object layer or the operator's US parent, which is why each listing records the full chain, not just where the servers sit.

EU Vetted Editorial
Verified June 2026 How we verify

Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

Why it matters

At a glance

Key facts per option, checked against each vendor's own documents.

  • Proton Drive

    hosted in Switzerland, zero-knowledge end-to-end encryption, no CLOUD Act exposure, from €4/mo.

    Best for: Encrypted cloud storage for individuals and teams who want the strongest sovereignty story with a full Swiss privacy ecosystem (Mail, VPN, Pass).

  • hosted in Switzerland, encrypted at rest, no CLOUD Act exposure, from €4/mo.

    Best for: Encrypted cloud storage for teams wanting a low-friction Google-Workspace-style switch on Infomaniak's own Swiss data centres.

  • Nextcloud

    hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €6/mo.

    Best for: organisations that want to self-host or use managed EU hosting with full control over their data, encryption keys, and sub-processors

  • luckycloud

    hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure.

    Best for: German and DACH SMBs that want zero-knowledge storage on a small founder-led provider's own German data centres

  • Koofr

    hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €1/mo.

    Best for: privacy-conscious individuals and small teams who want German-hosted storage from an independent vendor, with optional client-side encryption via Koofr Vault for sensitive files

  • hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €6/mo.

    Best for: German SMBs and individuals who want an established large vendor with in-country data centres and an optional zero-knowledge encryption layer

  • leitzcloud

    hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €8.8/mo.

    Best for: German and DACH SMBs and public-sector adjacencies that want German-only data residency on the operator's own infrastructure with a multilingual UI

  • Jottacloud

    hosted in Norway, encrypted at rest, no CLOUD Act exposure, from €7/mo.

    Best for: Encrypted cloud storage and backup for users who want Norway-hosted storage on renewable power with generous capacity.

  • hosted in Germany, encrypted at rest, no CLOUD Act exposure, from €4.29/mo.

    Best for: Buyers who want a cheap, no-frills managed Nextcloud instance hosted exclusively in Germany by the same certified operator as Hetzner's cloud and dedicated servers, and don't need default zero-knowledge encryption.

  • Leviia

    hosted in France, encrypted at rest, no CLOUD Act exposure, from €2.4/mo.

    Best for: French individuals, families, and SMBs who want a sovereign France-hosted Nextcloud-based drive plus S3-compatible object storage

  • Oodrive

    hosted in France, encrypted at rest, no CLOUD Act exposure.

    Best for: regulated French organisations in public sector, finance, healthcare, and defence that need SecNumCloud-qualified file sharing and e-signature

  • Wimi

    hosted in France, encrypted at rest, no CLOUD Act exposure, from €3/mo.

    Best for: French teams who want a sovereign collaboration suite where file storage sits alongside project workspaces, messaging, and calendars

How to choose
FAQ

Frequently asked questions

Where do US sub-processors usually hide in a cloud-storage stack?
In the layers around the file store rather than the file store itself: a US CDN terminating TLS in front of the service, an S3-compatible object-storage layer operated by a US-incorporated provider, the transactional email relay for sharing notifications, mobile push delivered through US app-platform channels, and product analytics. An EU-hosted storage front-end can still route file or usage data through one of those, which is why we record each sub-processor separately.
What counts as 'no US sub-processors' on this page?
The operating company is EU/EEA/Swiss, has no US parent, and uses no US-incorporated sub-processor in the data path: the directory's 'CLOUD Act exposure: none' bar, verified against each vendor's public sub-processor list and ownership records.
Is EU hosting alone enough to escape the CLOUD Act?
No. EU hosting addresses where data sits, not which jurisdiction can compel the operator. A US parent company or a US-incorporated processor in the chain keeps the data reachable under the CLOUD Act even with servers in Frankfurt or Paris. Location and jurisdiction are recorded as separate signals on every listing.
Do Swiss and Norwegian providers count as 'European' here?
Yes, with the distinction kept visible. The bar is an EU/EEA/Switzerland operator outside US jurisdiction: Norway is in the EEA and fully under the GDPR; Switzerland holds an EU adequacy decision and its own strong data-protection law. Each listing names the operator's actual country so buyers who need EU-member-state incorporation specifically can filter for it.
Can I migrate from Dropbox, Google Drive or OneDrive without losing structure?
Generally yes. Most services here support WebDAV and tools like rclone, and several offer native importers that preserve folder structure; what rarely transfers is share links and granular permissions, which need re-creating. Each profile notes the import paths the vendor documents.
Methodology

How we verified every listing here.

For each product we read the public DPA, sub-processors document, hosting region declaration, certifications, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology →