Jottacloud
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based This listing EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Norwegian cloud storage & backup (Jotta Group AS, est. 2008), 100% Norway-hosted on renewable power, server-side AES-256, public DPA, files stay in Norway.
Jottacloud is a European service hosted in Norway, with at most minor, transient US exposure under the CLOUD Act. It is listed under File sharing.
Assessment notes
Jottacloud is operated by Jotta Group AS (Øvre Slottsgate 5, Oslo, Norway; org. no. 992 603 615), founded 2008 by Roland Rabben, a Norwegian company that stores all customer files in Norway, in the ISO/IEC 27001-certified Green Mountain SVG1 facility at Rennesøy, powered by renewable hydropower, with a publicly linked pre-signed DPA and an explicit statement that the US CLOUD Act does not reach a Norwegian operator; the sub-processor list published on the vendor's own GDPR page (re-read 2026-08-26, page updated 28 May 2026) is the reason the score moved down from 4 to 3, because it names seven processors of which six are US-owned — Stripe (payments), Intercom (support), Microsoft (Office Online document editing), Google Firebase and Crashlytics (analytics), Mailchimp (customer communication) and Slack/Salesforce (internal) — which crosses the rubric's ≥3-US-sub-processors threshold; storage itself never leaves Norway, so CLOUD Act exposure is minor rather than material, but the Microsoft Office Online path means file content can reach a US-owned processor on demand, and the remaining gaps are unchanged: server-side (not zero-knowledge) encryption with company-held keys, and no vendor-level ISO 27001.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 7 · 7 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Not assessed
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: No
Jump to
About Jottacloud
Jottacloud is a Norwegian cloud storage and online-backup service operated by Jotta Group AS, headquartered at Øvre Slottsgate 5, Oslo (organisation number 992 603 615). It was founded in 2008 by Roland Rabben (reportedly motivated by wanting to keep his family's photos safe) and the name is a deliberate misspelling of "Yottabyte." Over more than fifteen years it has grown into one of the larger independent European storage providers, with reported double-digit average annual revenue growth.
The core sovereignty story is strong and simple: all of Jottacloud's server infrastructure is physically in Norway, powered by renewable hydropower and seawater-cooled, and the company explicitly markets that as a Norwegian operator it is outside the reach of the US CLOUD Act. Data is protected under Norwegian and EEA privacy law, a Data Processing Agreement is publicly linked (not gated behind enterprise sales), and the company maintains a transparency page. The main caveat for an encryption-focused buyer: Jottacloud uses server-side AES-256 encryption with company-managed keys, not zero-knowledge / client-side encryption: Jotta can technically access stored data, unlike Proton Drive, Internxt or Tresorit. Jotta holds no ISO 27001 certificate of its own: the ISO/IEC 27001 certification it cites belongs to the Green Mountain SVG1 facility at Rennesøy where the storage sits. A sub-processor list is published, on the vendor's GDPR documentation page rather than its legal pages, and it is the reason this listing is not rated clear of the CLOUD Act. Seven processors are named and six are US-owned, among them Microsoft Office Online, which can see document content when a user opens a file for editing. Files at rest still never leave Norway, so exposure is recorded as Minor rather than higher.
The ownership change announced in March 2025 has taken shape as a 50/50 joint venture between Hawk Infinity, the Norwegian technology investor that owns Jotta, and Telenor Amp, combining Jottacloud with Telenor's Min Sky. Founder Roland Rabben leads the combined company, which reports more than 2 million active customers on roughly NOK 200M of 2025 revenue at an enterprise value of about NOK 1.5bn. Telenor is a large, partly Norwegian-state-owned telco, so no US capital enters the structure and the ownership signal is unchanged, but completion was subject to Norwegian Competition Authority approval and could not be confirmed as formally closed from a primary source; the about page still names only Jotta Group AS.
Pricing is freemium and rose in mid-2026: 5 GB free; Home 1 TB at €7.90 per month or €79 a year; Personal Unlimited at €12.90 per month or €129 a year; Home 5 TB at €15.90 or €159; Pro 10 TB at €29.90 per month or €299 a year. Monthly and yearly prices are published side by side, so the entry figure recorded here is the true pay-monthly one. Best fit: Norwegian and EEA individuals and SMBs who want straightforward backup-and-sync with genuine in-country hosting and a clean CLOUD Act story, and who do not require zero-knowledge encryption. Buyers who need client-side encryption should prefer Proton Drive, Internxt, Filen or Tresorit.
Sub-processor map · 7
-
Google Firebase and Crashlytics USUnited States
Application analytics and crash reporting; ancillary telemetry
-
Intercom, Inc. USUnited States
Customer support and communication; ancillary — no access to stored files
-
Mailchimp USUnited States
Customer communication and email campaigns; ancillary
-
Microsoft Corporation USUnited States
Office Online document editing — the only listed processor that can see file content, and only for a document the user opens in it
-
PostHog USUnited States
User-behaviour analysis; ancillary telemetry. Jurisdiction is not stated on the vendor's page — PostHog, Inc. is US-incorporated and an EU-cloud option exists, so this is recorded conservatively as US and needs confirmation
-
Slack (Salesforce) USUnited States
Internal team communication; ancillary
-
Stripe, Inc. USUnited States
Payment processing; ancillary — no access to stored files
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Google Firebase and Crashlytics | United States | Application analytics and crash reporting; ancillary telemetry | US |
| Intercom, Inc. | United States | Customer support and communication; ancillary — no access to stored files | US |
| Mailchimp | United States | Customer communication and email campaigns; ancillary | US |
| Microsoft Corporation | United States | Office Online document editing — the only listed processor that can see file content, and only for a document the user opens in it | US |
| PostHog | United States | User-behaviour analysis; ancillary telemetry. Jurisdiction is not stated on the vendor's page — PostHog, Inc. is US-incorporated and an EU-cloud option exists, so this is recorded conservatively as US and needs confirmation | US |
| Slack (Salesforce) | United States | Internal team communication; ancillary | US |
| Stripe, Inc. | United States | Payment processing; ancillary — no access to stored files | US |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications · none listed
Capability matrix
Table 2Capabilities of Jottacloud
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Switzerland · €4/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €10/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Switzerland · €4/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: No Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€4/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€10/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: No
Open source: No
|
€4/mo |