Čeština
Přihlásit se Vyžádat ukázku

All articles

A European server is not enough: how data leaks out unnoticed

Your mail and files are in Europe, yet your website, phones and tools still send data to US companies. Where it leaks, and how to close the gaps.

Published · 2 min read · Binadit

These articles are available in English, Dutch, German, French and Spanish.

“Our data is stored in Europe” is a reassuring sentence, but it says less than it seems. Even a company that has neatly moved its mail and files to a European provider often sends data to US companies every day, without anyone having decided to.

Where data goes without you noticing

A selection of the channels almost every company has:

  • Operating system and office software. Windows and Microsoft 365 send diagnostic data to Microsoft. Microsoft itself documents that part of this cannot be fully switched off.
  • The browser. Sync with a Google or Microsoft account, search engines and extensions that read along.
  • The website. Analytics, fonts from Google Fonts, CAPTCHAs, embedded videos and maps, and CDNs. With every visit, your visitor’s IP address goes to those parties.
  • Security and management. Antivirus and EDR, crash reporting, monitoring, cloud logging and remote support.
  • Identity. Signing in with Microsoft Entra or Google ties every account to a US service.
  • AI integrations and plug-ins. An AI feature in a tool you already had often sends your text to an external model.
  • Phones. Almost every business phone runs in the Apple or Google ecosystem, with backups and notifications going through their servers.

The server location of your mail tells you nothing about any of these flows.

The difference between hoping and enforcing

The usual approach is policy: staff may not put sensitive data into certain services, and we choose suppliers with a good privacy policy. But that still means hoping every application behaves.

A stronger approach is to restrict outbound traffic technically. All outgoing connections then pass through a firewall or proxy, and by default nothing is allowed except the destinations you explicitly permit. New or unknown connections stand out immediately, and a program cannot decide on its own to send data to a new party. This is called default deny, and it changes the question from “we hope it goes well” to “technically, it cannot do otherwise”.

Start with what you control

  1. Make an inventory of all software, SaaS services, apps and browser extensions, and find out for each supplier who the ultimate owner is.
  2. Look at the whole chain: not only where the server is, but also where backups, support, logging and management sit, and which subcontractors have access.
  3. Clean up your website. Host fonts yourself, use European or self-hosted analytics, and load nothing from third parties without a reason.
  4. Choose a workplace where the basics are already right, so you do not have to work out for each service separately where the data goes.
  5. Restrict outbound traffic on the network, with a list of permitted destinations.

How Binadit does it

This website loads nothing from third parties. Fonts, scripts and images come from binadit.work itself, and there is no tracking and no Google Analytics. Binadit Workspace runs on servers that Binadit manages itself in Dutch data centres, with sign-in through our own mail server rather than a US identity service. Mail, calendar, files, documents, meetings and chat therefore stay within one European environment, and the list of outbound destinations you need to allow stays short.

See Binadit Workspace or read why a US data centre in Europe is not a solution.

Vyžádat ukázku Ceník