GDPR-Compliant VPN 2026: Why US Cloud VPNs Are a Compliance Risk
GDPR-Compliant VPN 2026: Why US Cloud VPNs Are a Compliance Risk
US cloud VPNs are subject to the CLOUD Act – a direct conflict with the GDPR. Why Schrems II also affects Tailscale and Cloudflare WARP. Compliance-ready hosting in Germany.
Content notice: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, pricing, versions, licensing models and external content are subject to change. Please verify the information independently, especially before making business-critical or security-relevant decisions. This article does not constitute individual professional, legal or tax advice.
US cloud VPNs are a structural GDPR risk in 2026 – even when you choose the EU region of a US provider. The reason: the US CLOUD Act forces US companies to hand over data globally upon US authority request. The CJEU ruling Schrems II explicitly determined in 2020 that US surveillance laws (CLOUD Act, FISA Section 702) don't provide adequate data protection for EU data. The EU-US Data Privacy Framework of 2023 doesn't change this – it only regulates transfer mechanisms, not authority access rights. To be GDPR-compliant, you need a VPN provider with EU headquarters, EU data centers, and no US parent company.
Also worth reading: NIS2 and Network Security for VPN · VPN for Healthcare and Legal Professionals · Site-to-Site VPN Without MPLS
Quick Comparison: VPN Providers and CLOUD Act Risk
| Provider | HQ | Infrastructure | CLOUD Act | GDPR Risk |
|---|---|---|---|---|
| Cloudflare WARP / Zero Trust | USA (San Francisco) | Own edge worldwide, US parent | ✓ Yes | 🔴 High |
| Zscaler ZTNA | USA (San Jose) | Own edge worldwide, US parent | ✓ Yes | 🔴 High |
| Tailscale | Canada (Toronto) | AWS (US cloud) | ✓ Indirect (AWS) | 🟡 Medium |
| NordLayer | Lithuania (Vilnius), complex holding (Panama/NL/US) | Own infra, EU HQ | ✗ Not directly | 🟡 Medium |
| Twingate | USA (Redwood City) | Own cloud, US parent | ✓ Yes | 🔴 High |
| Check Point SASE / Harmony SASE (formerly Perimeter 81) | Tel Aviv, NASDAQ-listed (CHKP) | Own cloud, US business presence | ✓ Yes | 🔴 High |
| NetBird via birdhost | Germany (merkaio) | German DCs (ISO 27001, BSI C5) | ✗ No | 🟢 None |
Table of Contents
- The Core Problem: CLOUD Act vs. GDPR
- The EU-US Data Privacy Framework (DPF): Not a Real Solution
- Provider Check: Where Each VPN Service Stands
- Three Compliance Layers for GDPR VPN
- NIS2 Tightens the Situation
- Practical Example: Hidden CLOUD Act Risks
- What Defines GDPR-Compliant VPN Hosting
- birdhost: Managed NetBird Hosting for GDPR Compliance
- Decision Guide: Which Provider for Which Use Case?
- Conclusion
- Sources
The Core Problem: CLOUD Act vs. GDPR
What the CLOUD Act Mandates
The Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 2018) requires US companies to hand over data upon request from US authorities – regardless of where the data is stored. This applies to every cloud provider, every SaaS platform, and every VPN service owned by a US company.
In concrete terms: when the FBI or NSA demands data from a US company, the company must comply – even if the data sits in an AWS data center in Frankfurt. A contractual commitment to challenge such a request in court is subordinate to the legal obligation under the CLOUD Act.
What the GDPR Requires
Article 48 GDPR is unambiguous: orders from foreign authorities to transmit personal data are only recognized if based on an international agreement like a Mutual Legal Assistance Treaty (MLAT). The CLOUD Act is not such an agreement.
The CJEU ruling Schrems II (July 2020) invalidated the Privacy Shield between the EU and USA – because US surveillance laws (Section 702 FISA, Executive Order 12,333) don't provide protection comparable to the GDPR. The court established: as long as a cloud provider has technical access to data (e.g., to decrypt it), Standard Contractual Clauses (SCCs) are insufficient.
The Direct Conflict
A US cloud provider that complies with a CLOUD Act order and transmits European customer data to US authorities inevitably violates the GDPR. The company is caught between two mutually exclusive legal regimes:
- US law: data disclosure is mandatory
- EU law: data disclosure without an MLAT basis is prohibited
Practically, this means: every US provider is structurally not GDPR-compliant – regardless of how many additional contracts they offer.
The EU-US Data Privacy Framework (DPF): Not a Real Solution
The EU-US Data Privacy Framework, in force since July 2023, was meant to be the Privacy Shield successor. But it only regulates transfer mechanisms for certified US companies – it doesn't prevent US authorities from continuing to access EU data.
What the DPF does:
- Provides a certification mechanism for US companies
- Formally facilitates data transfer to the USA
- Mandates a complaint authority (Data Protection Review Court)
What the DPF does not do:
- Doesn't change the CLOUD Act
- Doesn't prevent access via FISA Section 702
- Doesn't provide effective legal recourse for EU citizens
Schrems III: The Next Wave of Litigation?
The first lawsuit against the DPF came from French MP Philippe Latombe – and failed: on September 3, 2025, the European General Court (Latombe case, T-553/23) dismissed the lawsuit and confirmed the adequacy decision. Max Schrems, who already brought down Privacy Shield (Schrems II) and Safe Harbor (Schrems I), has been critical of the Latombe ruling and is considering his own, broader-scoped lawsuit – as of May 2026, this has not been filed.
Additionally, political developments in the USA – such as the dismissal of Democratic members of the Privacy and Civil Liberties Oversight Board (PCLOB) by the Trump administration – are, according to data protection experts, structurally weakening the foundation of the DPF. Companies relying today on a US provider's DPF certification risk losing their compliance foundation again.
Provider Check: Where Each VPN Service Stands
Cloudflare WARP / Cloudflare Zero Trust
- HQ: Cloudflare, Inc., San Francisco, California
- Infrastructure: Own global edge network in over 330 cities across more than 125 countries
- CLOUD Act: Directly applicable
- EU options: "Data Localization Suite" for additional fee – doesn't structurally prevent US authority access
- TLS termination: At Cloudflare edge (plaintext access by Cloudflare)
Cloudflare's Customer Metadata Boundary promises that logs and metadata stay in the EU. But that doesn't change the fact that Cloudflare Inc. is a US company – and thus subject to the CLOUD Act. Which building blocks of Cloudflare One an EU-hosted overlay can replace, and which it cannot, is separated category by category in Cloudflare Zero Trust alternative.
Zscaler ZTNA / Zscaler Internet Access
- HQ: Zscaler, Inc., San Jose, California
- Infrastructure: Own Zero Trust Exchange platform with global data centers
- CLOUD Act: Directly applicable
- EU data residency: Available at extra cost – doesn't change the US group risk
- Market position: Leader in enterprise ZTNA segment, but structurally a US provider
Tailscale
- HQ: Tailscale Inc., Toronto, Canada (Canadian company)
- Infrastructure: Control plane on AWS (US cloud) in AWS Virtual Private Clouds
- DERP relay servers: Multiple providers, multiple regions
- CLOUD Act: Indirectly applicable via AWS – when US authorities demand data from AWS, this also affects Tailscale configurations
- Data locations per privacy policy: "Canada, Germany, USA, UK, and possibly other jurisdictions"
Tailscale encrypts user traffic end-to-end with WireGuard – Tailscale itself doesn't see the content. But control plane metadata (devices, users, keys) sits on AWS servers subject to the CLOUD Act. With Aperture and the Border0 acquisition, Tailscale is also turning this AWS control plane into a central control point for AI agents and privileged access, which further increases the CLOUD Act exposure, as we show in Tailscale Aperture and the Border0 acquisition: the sovereign NetBird alternative.
Twingate
- HQ: Twingate Inc., Redwood City, California
- Infrastructure: Own cloud control plane, connector architecture
- CLOUD Act: Directly applicable
- Self-hosting: Not possible – control plane is proprietary and cloud-only
- Vendor lock-in: High (proprietary platform)
Check Point SASE / Harmony SASE (formerly Perimeter 81)
- HQ: Tel Aviv (Israel) – Check Point Software Technologies, NASDAQ-listed (CHKP) with significant US business presence (US office Redwood City)
- Product status: Perimeter 81 was acquired by Check Point in 2023 (closing September 2023, $490M) and progressively integrated into the Check Point portfolio since 2024 (official product name: Check Point SASE / Harmony SASE)
- CLOUD Act: Applicable via US business presence and NASDAQ listing (personal jurisdiction)
- EU data residency: On request – doesn't change the US legal framework
NordLayer
- Operational HQ: Vilnius, Lithuania (Nord Security)
- Group structure: Complex – the historical parent Tefincom S.A. is based in Panama, Nord Security is incorporated in Amsterdam (Netherlands), and NordLayer (formerly NordVPN Teams) relocated its operational headquarters to the USA in 2020
- Infrastructure: Own global servers, EU main base
- CLOUD Act: Not directly applicable to the EU operational HQ – but due to US operational presence and partial US group affiliation, the risk should be classified as 🟡 Medium rather than 🟢 Low
- GDPR: Fundamentally EU-compatible, but more nuanced in practice
- Limitation: Proprietary cloud SaaS model, no self-hosting option
NetBird via birdhost
- HQ Software: NetBird GmbH, Berlin
- HQ Hosting: merkaio Brands GmbH, Germany (Ruhr region)
- Infrastructure: German ISO 27001 and BSI C5 certified data centers
- CLOUD Act: Not applicable
- Open source: ✓ Hybrid license (BSD-3-Clause for most components, AGPLv3 for server components Management, Signal, Relay – since August 2025)
- Self-hosting: ✓ Fully possible (all control plane components)
Three Compliance Layers for GDPR VPN
Layer 1: Provider Jurisdiction (Jurisdictional Layer)
The provider must have its headquarters in the EU and have no US parent company. Otherwise, the CLOUD Act applies via the corporate connection. This excludes:
- US companies directly (Cloudflare, Zscaler, Twingate)
- US subsidiaries of European groups (if data control lies with the US subsidiary)
- EU companies with a US parent (e.g., Microsoft Germany → Microsoft Corp.)
Layer 2: Infrastructure (Technical Layer)
The entire infrastructure – control plane, signal server, relay, database – must be in the EU. Important: not via AWS or Azure EU regions, because these hyperscalers are subject to the CLOUD Act. Dedicated German hosters (Hetzner, IONOS Cloud, plusserver, OVH-DE) are safer.
Layer 3: Encryption (Cryptographic Layer)
Even with an EU provider and EU infrastructure, user traffic should be end-to-end encrypted – so that not even the hoster has plaintext access. WireGuard fulfills this natively. For key management, an own key manager under EU control is recommended.
Only when all three layers are fulfilled is a VPN setup legally GDPR-compliant.
NIS2 Tightens the Situation
Since December 6, 2025, the NIS2 Implementation Act has been in force in Germany. § 30 BSIG requires for around 29,500 companies in Germany:
- State-of-the-art cryptography and encryption (No. 8)
- Access control and identity management (No. 9)
- Multi-factor authentication (No. 10)
- Supply chain security (No. 4)
- Effectiveness assessment of measures (No. 6)
Especially supply chain security (No. 4) makes US cloud VPNs problematic: a provider legally obligated to hand over EU data to US authorities cannot be reliably integrated into a secure supply chain. NIS2 violations carry fines up to €10M or 2% of revenue for essential entities, or €7M or 1.4% of revenue for important entities – plus personal management liability under § 38 BSIG.
Practical Example: Hidden CLOUD Act Risks
Scenario: SMB Uses Tailscale Business
A German machinery company with 80 employees deploys Tailscale Business – $18/user/month, cloud SaaS, quickly set up. Management thinks: "Tailscale is Canadian, we're safe."
What management overlooked:
- Tailscale control plane runs on AWS (US cloud). AWS thus has technical access to all Tailscale metadata.
- AWS is subject to the CLOUD Act. An FBI request to AWS reaches Tailscale data – without Tailscale being informed (gag order possible).
- Tailscale's privacy policy explicitly names "Canada, Germany, USA, UK" as data locations. The US risk is named directly.
This will surface in a GDPR audit. In the worst case: fine plus reputation damage.
Scenario: SMB Uses NetBird via birdhost
Same company, same requirement – but NetBird via birdhost:
- NetBird is open source (hybrid license: BSD-3 / AGPLv3 for server components) – code fully auditable, no hidden data leakage.
- birdhost hosts the control plane in a German data center (Hetzner Falkenstein) – ISO 27001 and BSI C5 certified.
- Operating company: merkaio Brands GmbH, German company, no US group, no CLOUD Act.
- Data Processing Agreement (DPA) directly available in the portal.
GDPR audit: all requirements met. NIS2 § 30 No. 4 (supply chain security): met.
What Defines GDPR-Compliant VPN Hosting
| Criterion | Requirement |
|---|---|
| Provider HQ | EU, no US parent company |
| Server location | EU data centers with clear data residency |
| Infrastructure provider | EU hoster (no AWS/Azure/GCP EU region) |
| Data processing | Entirely in the EU |
| Encryption | End-to-end, modern protocols (WireGuard, ChaCha20) |
| DPA | Standardized, immediately available |
| Open source | Desirable for auditability |
| Certifications | ISO 27001 (DC operator), BSI C5 for particularly sensitive data |
birdhost: Managed NetBird Hosting for GDPR Compliance
Our managed NetBird hosting in Germany fulfills all three layers:
- Jurisdictional Layer: merkaio Brands GmbH, Germany. No US group. No CLOUD Act risk.
- Technical Layer: German ISO 27001 and BSI C5 certified data centers. With Germany region selected, no data packet leaves the EU.
- Cryptographic Layer: NetBird with WireGuard – end-to-end encryption. Not even birdhost itself can decrypt the traffic.
Additionally:
- DPA immediately available in the merkaio portal
- 8 regions worldwide – available for global companies, with clear data residency per region
- Open Source: NetBird is hybrid licensed (BSD-3-Clause for most components, AGPLv3 for management, signal, and relay servers since August 2025) – every line of code auditable
- Flat-rate pricing: from €99.90/month, no per-user fees
Decision Guide: Which Provider for Which Use Case?
US Cloud VPN (Cloudflare, Zscaler, Twingate, Check Point Harmony SASE)
Acceptable when:
- You have no personal data in the VPN
- You are not a NIS2 or KRITIS operator
- You don't process special categories of data (Art. 9 GDPR)
- US data access is acceptable for your business model
Tailscale (Canada / AWS)
Acceptable when:
- You accept the indirect CLOUD Act risk via AWS
- Tailscale convenience matters more than 100% EU data residency
- You operate a DPF-certified setup
NetBird via birdhost (Germany)
Recommended when:
- You need GDPR compliance without compromise
- You are NIS2-relevant (KRITIS, regulated industries)
- You have personal data in the VPN (employees, customers, patients, clients)
- You must structurally ensure data sovereignty
- You factor in Schrems III as a real risk
Conclusion
The GDPR question for VPNs is no longer a theoretical discussion in 2026. With NIS2 fines up to €10M (essential entities) or €7M (important entities), personal management liability, and over €7.1B in GDPR fines since 2018 – with the highest top-10 fines hitting US groups such as Meta (€1.2B), Amazon (€746M), and TikTok – the compliance question is existential.
US cloud VPNs – no matter how technically sophisticated – remain structurally a risk. The CLOUD Act forces US providers to disclose data, the CJEU has rated US surveillance laws as inadequate, and the EU-US Data Privacy Framework doesn't solve the core problem. Even Tailscale is indirectly affected via AWS infrastructure.
birdhost positions itself clearly: German provider, German data centers, open-source code, no US group risk. For companies with real GDPR requirements, this is the only legally secure choice.
Try it now: merkaio self-service portal – 7 days free.
Recommended reading: NIS2 and VPN Network Security · VPN for Healthcare and Legal Professionals
Sources
- docurex: CLOUD Act, EU GDPR, Schrems II – What Companies Need to Know
- Kiteworks: Prevent US Government Access to European Data
- heise: US Data Transfer, GDPR and CLOUD Act – Legal Risks
- netfiles: CLOUD Act – Risk and Solution for EU Companies
- Novalnet: The End of Cloud Illusion – Why US Providers Pose an Unacceptable Compliance Risk Under GDPR and DORA
- Tailscale Privacy Policy – Official Data Locations
- Tailscale Data Processing Addendum (DPA)
- Cloudflare GDPR Trust Hub – Schrems II Response
- Cloudflare: Customer Metadata Boundary
- IAPP: Schrems Addresses Emerging Questions Around EU-US Data Privacy Framework
- BSI: NIS-2 Directive and BSI Act
- secjur: NIS2 Requirements – All 10 Mandatory Measures Under § 30 BSIG
- Looming Tech: Why Your AWS EU Region Is Not GDPR-Safe
- Adequacy: EU-US Data Privacy Framework – Compliance Risks and Impact
- NetBird GitHub Repository
- birdhost.de – Managed NetBird Hosting
Frequently Asked Questions
Are US cloud VPNs GDPR-compliant?▼
Is an EU data center of a US provider sufficient?▼
What about Tailscale? They're Canadian.▼
How does a GDPR-compliant VPN work?▼
What happens with GDPR violations using US VPNs?▼
Is EU location enough for compliance?▼
What does the BSI say about US cloud VPNs?▼
How is NetBird with birdhost GDPR-compliant?▼
Written by
Timo Wevelsiep
Founder, merkaio
Founder of merkaio. Managed NetBird VPN hosting. Focused on network security, zero-trust architecture and scalable VPN infrastructure.
LinkedIn