Your email is GDPR-compliant today. Will it still be next year?

Google Workspace and Microsoft 365 are GDPR-compliant today because of one adequacy decision, and that decision is before the same court that struck down the previous two. What your provider has admitted under oath, and...

Binadit Tech Team 20 September 2026 12 min पढ़ें
Your email is GDPR-compliant today. Will it still be next year?

If your company runs on Google Workspace or Microsoft 365, your email, calendar and files live with an American provider. Ask your IT partner whether that is allowed under the GDPR and you will hear: yes, both are certified under the EU-US Data Privacy Framework, so you are fine.

That answer is correct. It is also incomplete. This article explains why the legal basis for your email is far shakier than it looks, what your provider has already admitted under oath, and what a European alternative costs. Spoiler: less than you pay now.

The short version

  • Email in Google Workspace or Microsoft 365 is a transfer of personal data to a US company. It is lawful today because of one instrument: the EU-US Data Privacy Framework of July 2023.
  • The two frameworks before it, Safe Harbor and Privacy Shield, were both struck down by the Court of Justice of the EU. The current one is before that same court now.
  • An EU data centre does not change this. Under the US CLOUD Act a US provider must hand over data it controls, wherever the servers are. Asked under oath in June 2025, Microsoft France could not guarantee otherwise.
  • Email, calendar and files hosted by a Dutch company in the Netherlands involve no transfer at all, and start at €1.99 per mailbox per month.

The rule: personal data does not leave Europe without a legal basis

Chapter V of the GDPR, Articles 44 to 50, is clear. Personal data may only be transferred to a country outside the European Economic Area if that country offers an adequate level of protection (Article 45), or if you as the controller put safeguards in place yourself, such as the EU standard contractual clauses (Article 46). Article 48 adds that a foreign court order or government demand does not by itself make a transfer lawful.

Email is personal data. Every message, every calendar invite, every shared file contains names, addresses, contracts, HR matters, medical notes from an employee, complaints from customers. If that data sits in a US company's infrastructure, this chapter of the GDPR applies to you.

Three attempts, two collapses, one pending verdict

The EU and the US have tried three times to create a legal bridge for this data:

  • Safe Harbor (2000). Struck down by the Court of Justice of the EU in 2015 (Schrems I).
  • Privacy Shield (2016). Struck down in 2020 (Schrems II). The Court found that US surveillance law, in particular FISA Section 702, gives EU citizens no effective protection or remedy.
  • The EU-US Data Privacy Framework (July 2023). This is the basis your Google or Microsoft contract relies on today.

Every one of these frameworks was presented as the definitive solution. Two of them are gone. Companies that had built their compliance on Privacy Shield woke up in July 2020 with no legal basis for their email, overnight.

Where the current framework stands in September 2026

The DPF is still in force. But look at what has happened around it:

  1. It is before the Court of Justice. A challenge by French MP Philippe Latombe was dismissed by the General Court on 3 September 2025 (Case T-553/23), but the court restricted itself to the facts as they stood when the framework was adopted in July 2023. Nothing that has happened in the US since then was weighed. Latombe appealed (Case C-703/25 P), and that appeal is pending before the Court of Justice, the body that struck down the previous two frameworks. In June 2026 the Court granted Microsoft leave to intervene in support of the Commission, on the ground that Microsoft has a direct interest in the outcome. That tells you how much is at stake for them.
  2. The US safeguards it rests on are being dismantled. The adequacy decision leaned on independent US oversight bodies. The Privacy and Civil Liberties Oversight Board has had no quorum since 27 January 2025 and is down to a single member. On 29 June 2026 the US Supreme Court held in Trump v. Slaughter that the protection of FTC commissioners against dismissal is unconstitutional, so the President may remove them at will. The FTC is the body that enforces the framework on the US side. The same day, privacy organisation noyb called on the European Commission to "orderly withdraw" the adequacy decision and announced a court challenge of its own. The Commission has said only that it will assess the ruling.
  3. FISA 702 has not been reformed. The surveillance law at the heart of Schrems II was due to expire on 20 April 2026, was kept alive by two short-term extensions, and lapsed on 12 June 2026 when the House rejected a third. Collection continues regardless, under court certifications that run until around March 2027. Through all of it, nothing in the law has changed in the direction the Court demanded.

You do not need to predict the outcome. You only need to notice that your company's email compliance depends on a decision that a court may annul on a date you do not control, and that the last time this happened it took three years to replace.

"But our data is stored in an EU data centre"

This is the most common reassurance, and it does not solve the problem. Under the US CLOUD Act, a US company must hand over data under its control when a US authority demands it, regardless of where the servers are. A Dutch, Irish or German data centre owned by a US parent company is still within reach.

You do not have to take our word for it. On 10 June 2025, Anton Carniaux, director of public and legal affairs at Microsoft France, testified under oath before a French Senate inquiry into public procurement. Its rapporteur, Senator Dany Wattebled, asked him whether he could guarantee that data of French citizens entrusted to Microsoft through the state purchasing body would never be transmitted on the order of the US government without the explicit agreement of the French authorities. His answer: "Non, je ne peux pas le garantir." No, I cannot guarantee that. He added that it had never happened so far. That is the point: it depends on whether it happens, not on whether it can.

The full exchange is in the official Senate transcript (in French) and was reported in English by The Register. This is the provider itself, on the record, under oath.

An EU region in a US cloud is a location choice. It is not a jurisdiction choice.

Not sure where your own mail goes? It is in public DNS. Our US exposure scanner looks up who handles the email for your domain, and which legal system that company falls under.

The AI layer makes it worse

Both Google and Microsoft are now building AI assistants directly into your mailbox and your files. That adds a second set of obligations:

  • Purpose limitation and data minimisation. Your customers' data was collected to answer their request, not to train or improve a model. Consumer and many "free" AI tiers use input for exactly that. Only business contracts explicitly exclude it, and you need to verify that yours does.
  • Accuracy. AI models produce confident errors. If an assistant writes incorrect information about a real person into a summary or a draft, that violates the accuracy principle of the GDPR, and once something is inside a trained model it cannot be deleted for a single individual.
  • The EU AI Act. Its transparency duties have applied since 2 August 2026. The heavier documentation and oversight duties for AI used in areas such as HR, credit or access to essential services were postponed in July 2026 and now apply from 2 December 2027. That is a delay, not a reprieve: if you cannot tell which model processed which data, in which jurisdiction, you will not be able to meet them when they land.

Every AI feature switched on inside a US productivity suite is another data flow you are accountable for under Article 24 of the GDPR, and another one you have to explain to a customer or a regulator.

What your accountability actually requires

Article 24 GDPR makes you, the controller, responsible for demonstrating compliance with appropriate technical and organisational measures. After Schrems II that includes assessing, for each transfer, whether the destination offers equivalent protection and adding measures if it does not. In practice this means that with a US provider you are expected to keep a transfer impact assessment up to date, monitor a court case in Luxembourg, follow US executive orders and be ready to switch if the framework falls.

Or you remove the transfer.

The alternative: email, calendar and files that never leave the Netherlands

Binadit hosts business email, shared calendars and file storage from our own data centre in the Netherlands, on hardware we own, operated by a Dutch company with no foreign parent. There is no transfer to a third country, so Chapter V of the GDPR does not apply to your mailbox at all. No adequacy decision to watch, no CLOUD Act exposure, no transfer impact assessment to maintain.

What you get:

  • Email with your own domain, spam and virus filtering, and full support for Outlook, Apple Mail, Thunderbird and mobile clients through standard protocols. Your people keep the mail client they already use.
  • Calendar and contacts shared across your organisation, working in the same clients.
  • File storage and sharing as a replacement for OneDrive and Google Drive, with sharing links, versioning and desktop sync.
  • Self-service management of mailboxes, aliases and users through the Binadit portal.
  • A Dutch data processing agreement under Dutch law, with a Dutch supervisory authority, and support in your own language from a fixed contact who knows your setup.
  • No AI training on your data. Ever. Your data is yours; we host it, we do not learn from it.

What that looks like for the suite you use now is worked out per product: the alternative to Microsoft 365, including Exchange itself hosted in the Netherlands, the alternative to Google Workspace, and Binadit Drive as the alternative to Google Drive, to OneDrive and to Dropbox.

And it costs less than what you pay today

The entry tiers of Google Workspace and Microsoft 365 cost roughly €6 to €8 per user per month depending on the commitment you sign, and the plans most companies actually end up on cost well over €10 (list prices excluding VAT, September 2026). Here is what the same thing costs in a Dutch data centre:

Price Best for
Mailbox on our shared platform from €1.99 per mailbox per month Teams that want email, calendar and files without running anything themselves
Exchange mailbox, hosted in the Netherlands from €4.95 per mailbox per month Companies that want to keep Outlook, Exchange ActiveSync and shared mailboxes exactly as they are. Same software, but hosted and controlled by a Dutch company on Dutch hardware, so the CLOUD Act does not reach it.
Managed dedicated mail server from €149 per month, unlimited mailboxes Organisations from roughly 25 mailboxes upward, or anyone who wants a fully isolated environment. Your only limit is disk space, not the number of users. You create mailboxes and domains yourself in the Binadit portal; we manage the server, updates, backups and monitoring.
Managed dedicated Exchange server from €299 per month, unlimited mailboxes Larger Exchange environments that want their own isolated server with full Outlook compatibility, managed by us, with mailboxes and domains under your own control in the Binadit portal.

Run the numbers for a 30-person company. On a Google or Microsoft entry plan you pay around €2,500 a year. The same 30 people cost €716 a year on our shared platform, €1,782 a year on hosted Exchange, or a flat €1,788 a year on a dedicated server that will still be the same price at 60 or 100 mailboxes. You get the compliance fix and the savings in the same move.

We migrate your existing mailboxes, calendars and files from Google or Microsoft, including historic mail, and we run both environments side by side until you switch DNS. No downtime, no lost mail.

What to do this week

  1. Check which of your services currently rely on the EU-US Data Privacy Framework. For most companies the answer starts with email.
  2. Ask your provider, in writing, whether it can guarantee that your data will not be handed to a non-EU authority. Keep the answer. Microsoft has already given theirs.
  3. Talk to us about what a move would look like for your organisation. We will map your current setup, give you a fixed migration price and a date.

You can stay compliant by monitoring a court case, or you can stay compliant by not having the problem. Get in touch with Binadit for a migration assessment.

Frequently asked questions

Is Google Workspace GDPR-compliant?

Today, yes. Google is certified under the EU-US Data Privacy Framework, which the European Commission adopted in July 2023, and that makes the transfer of your email to Google lawful. The compliance is as durable as that framework. Its two predecessors were struck down by the Court of Justice of the EU, and an appeal against the current one is pending there.

Is Microsoft 365 GDPR-compliant if we choose an EU data region?

The EU region decides where the data is stored. It does not decide which law the provider answers to. Microsoft is a US company, and under the CLOUD Act it must produce data under its control when a US authority orders it to, wherever that data is stored. Microsoft France stated under oath in June 2025 that it cannot guarantee otherwise.

What happens to our email if the Data Privacy Framework is annulled?

The same as in July 2020, when Privacy Shield fell. The transfer loses its legal basis on the day of the judgment, without a transition period. You would have to rely on standard contractual clauses and a transfer impact assessment that concludes US law offers equivalent protection, which is the conclusion the Court would just have rejected.

Does the CLOUD Act apply to a Dutch hosting company?

The CLOUD Act binds providers that fall under US jurisdiction. A Dutch company with no US parent, hosting on its own hardware in the Netherlands, is outside it. A demand for data would have to go through a Dutch court under Dutch law.

Can we keep using Outlook if we leave Microsoft 365?

Yes. Outlook is a mail client and works with any mailbox that speaks the standard protocols. With a hosted Exchange mailbox in the Netherlands you also keep Exchange ActiveSync, shared mailboxes and shared calendars exactly as they are.