These matters of complicated jurisdiction and sovereignty law require the advice of an experienced international lawyer. These lawyers need the advice of experienced international technologists, and that is the bit I do. Each has to know quite a bit about what the other is doing, so I study the relevant statutes and speak to the people who are drafting the next versions of the regulations.
The EU-US Data Privacy Framework (DPF) ↗ is intended to put limits on US surveillance of EU citizens (with UK citizens covered in a bolt-on called the “bridge”). It always was a kludge designed to allow US companies to continue holding vast amounts of EU/UK data regardless of US government spying, and now it is on is on life support. The US Privacy and Civil Liberties Oversight Board (PCLOB) was a mandatory requirement for the deal but it has only one term-expired member, and the equally essential FISA Section 702 ↗ expired in June 2026. The expiry does not stop the surveillance, just the oversight that was negotiated. EU/UK businesses want to store their data within US control, and so these laws and frameworks are designed to make it legal for them to do so. In practical terms there is no protection for EU/UK citizens, so the legalities are a kind of compliance dance, and a very expensive one too.
For UK CEOs and boards of management there is an additional layer, because the data they store on their customers (no matter what underlying company actually has it, for example Amazon Web Services) is not allowed to be fully under their control if they have EU customers. Unless a UK company is willing to change their corporate structure - which they usually are not - then they need to give up ultimate access to any data they hold on EU citizens. In short:
A UK company with no EU establishment that deliberately offers goods or services to people in the EU, or monitors their behaviour there, will usually need to appoint an EU representative under GDPR Article 27 ↗ (there is a narrow exemption for occasional, low-risk processing.)
The representative is a real live person or organisation available locally in the EU to individuals and regulators, where “available” means “we can physically raid them if we choose to do so”. Appointing a representative doesn’t reduce corporate liability, but is just an essential requirement. Often the representative will be required to have ultimate root keys to the UK company’s corporate data.
For UK companies there is more uncertainty than for EU companies, because if the EU decides to acknowledge the reality of the DPF and drop it, according to court cases now in progress, then the UK’s bridge arrangement remains in place and thus automatically UK companies are no longer adequete for storing EU citizen data unless they choose one of the other, older mechanisms. The UK could choose to drop the bridge legislation too, but in any case it would have to decide between the EU and US. There are protections that can be put in place against these events but for any substantial company they need to be worked out well ahead of time. It is risky and expensive to move data jurisdictions in a hurry.
As a technical note, “EU citizens” is not quite right, it is “people in the EU”, a more expansive and generous definition, but “citizens” gives the idea.
What’s up in 2026
If you are a UK or EU company with data exposure, you need to be working on your plans B and C. The top three unpredictable pressures are:
When will the DPF finally die? When it does, and if a giant firewall is then raised between the US and EU data, this could do what EU citizens have repeatedly been unable to do: stop US companies and spies infinitely using their data without knowledge or consent. Executive Order 14086 ↗ is subject to a “secret review”, and any EU legislators who believe this EO offers any protection are in fantasyland. On the other hand, US cloud companies have established a firm monopoly grip over a large proportion of EU data.
The FISA 702 Renewal Cliff is in April 2026. FISA is how US spy agencies illegally collect EU data in bulk, and if it is expanded (or possibly even just renewed) then the EU data deal would likely be further endangered. FISA is already based on “America First” with no practical limitations, but it does have a few fig leaves to preserve some degree of European dignity.
Data Adequacy seems a retaliatory instrument in the US-EU trade war. The US has already threatened tariffs specifically because of the EU Digital Services Act and the AI Act. The EU has discussed striking down the DPF, which would, it is said, stop US companies being able to access any EU data. I am sceptical, because the companies have weapons the EU legislators seem only dimly aware of, especially paracopyright.
GDPR Article 48 says that a foreign court or administrative order (eg a US court order) requiring disclosure of personal data has no legal effect in the EU unless it comes through an international agreement such as a mutually binding treaty. There is no such treaty in place, so a US parent company such as Amazon is therefore caught Article 48 (which says it has no right to disclose EU data) and US law (which says it must obey a court or be in contempt.) Evidently, Amazon obeys US law not EU law.
Background
The UK has historically been a trusted destination for international data storage, and UK companies have regarded themselves as having a natural advantage from this point of view. Various political and legal decisions have chipped away at that, including interpretations of the two UK Investigatory Powers Acts, and Brexit. A view expressed in technical circles since 2014 or so is that master encryption keys should not be kept in the UK, and since Brexit took effect in 2020 many additional questions arise about privacy and security. This has progressed from being a technical curiosity to an urgent matter affecting core business operations.
In 2019, the UK signed a bilateral agreement under the US CLOUD Act ↗, a law that lets US law enforcement compel American tech companies to hand over data stored anywhere in the world, regardless of local privacy laws. The UK was at liberty to do so ↗ due to Brexit. This put the UK out of step with the EU, who continues to develop data sovereignty initiatives ↗, the first of which comes into effect in 2025. 2025 is also when the UK’s adequacy for handling EU data expires (see below.)
Also in 2020, the Five Eyes ↗ countries, joined by India and Japan, signed a statement ↗ calling on tech companies to build backdoor access into encrypted communications for law enforcement, undermining the mathematical guarantees that make end-to-end encryption trustworthy. The EU does not agree with this position. EU security services are also unhappy about mathematically correct end-to-end security, but there is no move to ban it, so this also increases distance between default EU and UK positions.
The 2025 cliff came and went
The European Commission’s two 2021 UK adequacy decisions originally expired in June 2025. The Commission extended them briefly while it assessed the UK’s new legislation, then renewed both decisions on 19 December 2025 ↗ until 27 December 2031.
This gives companies breathing space. EU personal data can continue moving to the UK under the adequacy decisions, but the settlement is neither permanent nor unconditional. The Commission will conduct its first review within four years, with European Data Protection Board involvement, and can intervene if UK protections diverge materially.
Adequacy makes transfers easier. It does not make the UK part of the EU, and it does not remove the Article 27 representative requirement.
Data protection facts as of 2026
The EU has good reason to be suspicious of UK intentions regarding data protection:
The renewal followed the Data (Use and Access) Act 2025 ↗, which received Royal Assent in June 2025. Most of its data-protection and privacy provisions took effect on 5 February 2026. The Act retained the UK GDPR while changing how it operates, including legitimate interests, research, automated decisions and UK transfers to other countries. A company can therefore receive EU data under adequacy while operating under rules that are gradually becoming different.
- The UK shows little sustained interest in restraining or replacing US cloud companies or insisting that non-compliant behaviour stop (“non-compliance” as defined by the GDPR and/or court decisions, in all of the EU, UK and US.) The opposite is true in many EU countries and in the EU institutions.
- Successive UK governments seem strongly inclined to derogate from or withdraw from the European Convention on Human Rights, even though its membership and history is not related to the EU, and even though it had substantial UK input in its design and operation. This is not a new idea - withdrawal from the ECHR was in the 2012 UK Conservative Manifesto. In 2024 the UK government felt a need to state that proposed DPDI was consistent with the ECHR, which indicates the level of concern (and stating this does not make it true; everything is still unclear.) This is not something any organisation can be sure about.
- A 2021 English High Court case (Harry Miller v The College of Policing [2021] EWCA Civ 1926 ↗) challenged police recording of lawful speech as “hate incidents.” The court ruled in Miller’s favour, but did so on Common Law grounds, freedom of expression as a long-standing English legal principle, instead of relying on the European Convention on Human Rights as was increasingly the case since it was adopted into UK law. The conclusion was probably broadly similar, but the legal reasoning stepped away from internationally-recognised rights standards. The situation is different in Scotland, where the legal system and the common law is different, but the UK has jurisdiction and can impose the English will as it pleases. It is thus reasonable to conclude this was in fact a UK decision, as supported by Privacy International v Investigatory Powers Tribunal [2021] EWHC 27 (Admin) ↗, where the question was whether the IPT (the UK’s secret court for hearing complaints about GCHQ and MI5 surveillance) could itself be held accountable by ordinary courts. The High Court said yes, but the case illustrates how much UK surveillance law operates behind closed doors.
- The UK is one of the Five Eyes ↗ countries, whose behaviour led to US Cloud companies being banned in some circumstances in Europe as I analysed here. The UK has repeatedly been identified as conducting spying on US citizens that is illegal in the US, and since Brexit the UK has the same “third country” relationship to the EU as it does to the US.
- The National Security Act 2023 was passed in part to respond to the ECtHR ruling in Big Brother Watch v UK (2021) that aspects of GCHQ’s bulk interception programme violated the right to privacy. The Act attempts to put mass surveillance on a firmer legal footing, but the general issue is not settled.
The reasons US cloud services are inappropriate relate to legal facts (where US Acts and Presidents claim global access to all data), and espionage facts as revealed by many including Edward Snowden ↗.
Even these facts can be somewhat arguable, and of course many US companies operating in the EU/UK do so, awaiting further decisions by the highest EU courts. However there is little uncertainty about technical and mathematical facts such as:
- Fibre optic connectivity to the EU from the UK is excellent, meaning that a datacentre in France or Germany is practically as close as London or Glasgow for most companies in the UK.
- It is mathematically possible to store data from the UK such that only someone with keys based in the EU can read it. This is conceptually a kind of drop box.
- It is mathematically possible to detect whether (a) any individual or (b) a specific authorised individual has (c) accessed or (d) changed data. This means that EU and UK-specific audit trails can be implemented with a level of assurance that the EU is likely to accept.
- It is not mathematically possible to be sure that nobody has accessed information if master keys for that information are held by someone in an untrusted jurisdiction (i.e. one that is judged inadequate by the EU)
- It is inconvenient and technically difficult to store master encryption keys in the UK in a way that is legally secure from the UK government. This is related to the UK Regulation of Investigatory Powers Act, and the UK Terrorism Act, and UK interpretations of self-incrimination (ie the circumstances of handing over passwords and the like.) Unfortunately, many ordinary businesses are caught up in these matters of personal liberty and state powers of compulsion. While there can be similar situations in the EU, the EU Human Rights-based approach reduces that risk.
- Connectivity across the Atlantic often goes via Europe in any case, with no or little difference in transit time
These technical and mathematical facts show that it is possible, and sometimes preferable, for UK companies to handle personal data in the EU rather than in the UK. That does not mean it is easy, just easier than the alternatives.
What Are the Options?
The question “should I keep personal data in the UK?” is not theoretical. Data storage decisions can involve a lot of money and need to be stable for as long as possible, and UK companies often have global or European customers with specific requirements.
It is not a simple fix to host data in the EU. Even though the differences may be just milliseconds and users will never notice a change in the application, hosting in the EU means that ultimate passwords must be held on EU soil, not UK soil. It also means that ultimate decision making must be in the EU, not in the UK. There are financial and organisation implications. These are factual statements rather than opinions about what might be possible. The implications can be confronting for UK companies, and many companies have still not considered them.
Splitting Database Hosting Between EU and UK customers
It can be possible to split the UK and EU customers of a company.
Analysis will show case-by-case whether, for a particular organisation:
- whether UK customers gain or lose by this arrangement;
- whether UK customers should be given the choice of jurisdiction;
- whether it is possible for any UK company to know accurately whether one of their customers is an EU citizen or not (almost certainly no, it is typically not technically possible at all. That may sound odd, but there are so many exceptions that this is a generally true statement);
- whether there is a definitive answer for customers who are both EU and UK
In other words, in many cases, accurately dividing customers by perceived jurisdiction is not possible. It would often be very difficult to defend the decision in court, or to a privacy enforcement body, or to a customer who has made a subject access request.
Hosting all data in the EU
This might sound simple, but it has implications for UK company structure and decisionmaking. If you’re hosting in the EU, then ultimate password authority must be managed by an independent EU contractor (perhaps a law firm.) There are many data storage companies in the EU with equivalent technical capabilities to UK and US companies, so the question concerns corporate constraints, not technical constraints.
Splitting the IT data management functions of the company
This means establishing a new data storage company that is 100% based in Europe, in the eyes of EU law. This will meet the independence requirements and tests, so long as the company is not a subsidiary of the UK company. It may also open up business opportunities. This is not compatible with traditional monolithic IT department organisation.
It helps to remember that European regulators and courts increasingly restrict particular uses of US cloud companies. The UK is now a third country whose adequacy decisions make transfers easier without restoring EU membership.
Other Options
- View the data storage requirements as a form of outsourcing, and then engage a third-party EU storage company.
- Take advantage of the special situation of Northern Ireland. This is looking less useful. There would still be business uncertainty even in the humorous hypothetical case of a datacentre with movable data racks sited precisely on the Irish border between the EU and the UK.
Local people, not just local servers
The obligation also runs in the other direction. An EU company which targets or monitors people in the UK may need a UK representative under the UK GDPR. Similar representative requirements apply to some cross-border intermediary services under the Digital Services Act and to specified infrastructure and managed-service providers under NIS2.
Cross-border business is therefore accumulating obligations to have local people who can answer to regulators and customers. Buying another cloud region does not satisfy that need. Decisions about data location, encryption keys and corporate authority have to be made together.
2026 and beyond
From time to time I am engaged to help organisations in the UK and in the EU make decisions about where their data is stored, how it is accessed, and how to keep things as stable as possible over the next few years. This was a dizzying mess until 2025, some clarity arrived in the first part of 2026 but it remains complicated and easy to get wrong. Organisations need as much certainty as they can get for making decisions which are expensive to change in the future.