Back to Blog|VPN Guides

GDPR-Compliant VPN 2026: Why US Cloud VPNs Are a Compliance Risk

May 7, 2026
Timo WevelsiepTimo Wevelsiep
birdhost

GDPR-Compliant VPN 2026: Why US Cloud VPNs Are a Compliance Risk

US cloud VPNs are subject to the CLOUD Act – a direct conflict with the GDPR. Why Schrems II also affects Tailscale and Cloudflare WARP. Compliance-ready hosting in Germany.

birdhost.de Blog

Content notice: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, pricing, versions, licensing models and external content are subject to change. Please verify the information independently, especially before making business-critical or security-relevant decisions. This article does not constitute individual professional, legal or tax advice.

US cloud VPNs are a structural GDPR risk in 2026 – even when you choose the EU region of a US provider. The reason: the US CLOUD Act forces US companies to hand over data globally upon US authority request. The CJEU ruling Schrems II explicitly determined in 2020 that US surveillance laws (CLOUD Act, FISA Section 702) don't provide adequate data protection for EU data. The EU-US Data Privacy Framework of 2023 doesn't change this – it only regulates transfer mechanisms, not authority access rights. To be GDPR-compliant, you need a VPN provider with EU headquarters, EU data centers, and no US parent company.

Also worth reading: NIS2 and Network Security for VPN · VPN for Healthcare and Legal Professionals · Site-to-Site VPN Without MPLS


Quick Comparison: VPN Providers and CLOUD Act Risk

Provider HQ Infrastructure CLOUD Act GDPR Risk
Cloudflare WARP / Zero Trust USA (San Francisco) Own edge worldwide, US parent ✓ Yes 🔴 High
Zscaler ZTNA USA (San Jose) Own edge worldwide, US parent ✓ Yes 🔴 High
Tailscale Canada (Toronto) AWS (US cloud) ✓ Indirect (AWS) 🟡 Medium
NordLayer Lithuania (Vilnius), complex holding (Panama/NL/US) Own infra, EU HQ ✗ Not directly 🟡 Medium
Twingate USA (Redwood City) Own cloud, US parent ✓ Yes 🔴 High
Check Point SASE / Harmony SASE (formerly Perimeter 81) Tel Aviv, NASDAQ-listed (CHKP) Own cloud, US business presence ✓ Yes 🔴 High
NetBird via birdhost Germany (merkaio) German DCs (ISO 27001, BSI C5) ✗ No 🟢 None

Table of Contents

The Core Problem: CLOUD Act vs. GDPR

What the CLOUD Act Mandates

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 2018) requires US companies to hand over data upon request from US authorities – regardless of where the data is stored. This applies to every cloud provider, every SaaS platform, and every VPN service owned by a US company.

In concrete terms: when the FBI or NSA demands data from a US company, the company must comply – even if the data sits in an AWS data center in Frankfurt. A contractual commitment to challenge such a request in court is subordinate to the legal obligation under the CLOUD Act.

What the GDPR Requires

Article 48 GDPR is unambiguous: orders from foreign authorities to transmit personal data are only recognized if based on an international agreement like a Mutual Legal Assistance Treaty (MLAT). The CLOUD Act is not such an agreement.

The CJEU ruling Schrems II (July 2020) invalidated the Privacy Shield between the EU and USA – because US surveillance laws (Section 702 FISA, Executive Order 12,333) don't provide protection comparable to the GDPR. The court established: as long as a cloud provider has technical access to data (e.g., to decrypt it), Standard Contractual Clauses (SCCs) are insufficient.

The Direct Conflict

A US cloud provider that complies with a CLOUD Act order and transmits European customer data to US authorities inevitably violates the GDPR. The company is caught between two mutually exclusive legal regimes:

  • US law: data disclosure is mandatory
  • EU law: data disclosure without an MLAT basis is prohibited

Practically, this means: every US provider is structurally not GDPR-compliant – regardless of how many additional contracts they offer.


The EU-US Data Privacy Framework (DPF): Not a Real Solution

The EU-US Data Privacy Framework, in force since July 2023, was meant to be the Privacy Shield successor. But it only regulates transfer mechanisms for certified US companies – it doesn't prevent US authorities from continuing to access EU data.

What the DPF does:

  • Provides a certification mechanism for US companies
  • Formally facilitates data transfer to the USA
  • Mandates a complaint authority (Data Protection Review Court)

What the DPF does not do:

  • Doesn't change the CLOUD Act
  • Doesn't prevent access via FISA Section 702
  • Doesn't provide effective legal recourse for EU citizens

Schrems III: The Next Wave of Litigation?

The first lawsuit against the DPF came from French MP Philippe Latombe – and failed: on September 3, 2025, the European General Court (Latombe case, T-553/23) dismissed the lawsuit and confirmed the adequacy decision. Max Schrems, who already brought down Privacy Shield (Schrems II) and Safe Harbor (Schrems I), has been critical of the Latombe ruling and is considering his own, broader-scoped lawsuit – as of May 2026, this has not been filed.

Additionally, political developments in the USA – such as the dismissal of Democratic members of the Privacy and Civil Liberties Oversight Board (PCLOB) by the Trump administration – are, according to data protection experts, structurally weakening the foundation of the DPF. Companies relying today on a US provider's DPF certification risk losing their compliance foundation again.


Provider Check: Where Each VPN Service Stands

Cloudflare WARP / Cloudflare Zero Trust

  • HQ: Cloudflare, Inc., San Francisco, California
  • Infrastructure: Own global edge network in over 330 cities across more than 125 countries
  • CLOUD Act: Directly applicable
  • EU options: "Data Localization Suite" for additional fee – doesn't structurally prevent US authority access
  • TLS termination: At Cloudflare edge (plaintext access by Cloudflare)

Cloudflare's Customer Metadata Boundary promises that logs and metadata stay in the EU. But that doesn't change the fact that Cloudflare Inc. is a US company – and thus subject to the CLOUD Act. Which building blocks of Cloudflare One an EU-hosted overlay can replace, and which it cannot, is separated category by category in Cloudflare Zero Trust alternative.

Zscaler ZTNA / Zscaler Internet Access

  • HQ: Zscaler, Inc., San Jose, California
  • Infrastructure: Own Zero Trust Exchange platform with global data centers
  • CLOUD Act: Directly applicable
  • EU data residency: Available at extra cost – doesn't change the US group risk
  • Market position: Leader in enterprise ZTNA segment, but structurally a US provider

Tailscale

  • HQ: Tailscale Inc., Toronto, Canada (Canadian company)
  • Infrastructure: Control plane on AWS (US cloud) in AWS Virtual Private Clouds
  • DERP relay servers: Multiple providers, multiple regions
  • CLOUD Act: Indirectly applicable via AWS – when US authorities demand data from AWS, this also affects Tailscale configurations
  • Data locations per privacy policy: "Canada, Germany, USA, UK, and possibly other jurisdictions"

Tailscale encrypts user traffic end-to-end with WireGuard – Tailscale itself doesn't see the content. But control plane metadata (devices, users, keys) sits on AWS servers subject to the CLOUD Act. With Aperture and the Border0 acquisition, Tailscale is also turning this AWS control plane into a central control point for AI agents and privileged access, which further increases the CLOUD Act exposure, as we show in Tailscale Aperture and the Border0 acquisition: the sovereign NetBird alternative.

Twingate

  • HQ: Twingate Inc., Redwood City, California
  • Infrastructure: Own cloud control plane, connector architecture
  • CLOUD Act: Directly applicable
  • Self-hosting: Not possible – control plane is proprietary and cloud-only
  • Vendor lock-in: High (proprietary platform)

Check Point SASE / Harmony SASE (formerly Perimeter 81)

  • HQ: Tel Aviv (Israel) – Check Point Software Technologies, NASDAQ-listed (CHKP) with significant US business presence (US office Redwood City)
  • Product status: Perimeter 81 was acquired by Check Point in 2023 (closing September 2023, $490M) and progressively integrated into the Check Point portfolio since 2024 (official product name: Check Point SASE / Harmony SASE)
  • CLOUD Act: Applicable via US business presence and NASDAQ listing (personal jurisdiction)
  • EU data residency: On request – doesn't change the US legal framework

NordLayer

  • Operational HQ: Vilnius, Lithuania (Nord Security)
  • Group structure: Complex – the historical parent Tefincom S.A. is based in Panama, Nord Security is incorporated in Amsterdam (Netherlands), and NordLayer (formerly NordVPN Teams) relocated its operational headquarters to the USA in 2020
  • Infrastructure: Own global servers, EU main base
  • CLOUD Act: Not directly applicable to the EU operational HQ – but due to US operational presence and partial US group affiliation, the risk should be classified as 🟡 Medium rather than 🟢 Low
  • GDPR: Fundamentally EU-compatible, but more nuanced in practice
  • Limitation: Proprietary cloud SaaS model, no self-hosting option

NetBird via birdhost

  • HQ Software: NetBird GmbH, Berlin
  • HQ Hosting: merkaio Brands GmbH, Germany (Ruhr region)
  • Infrastructure: German ISO 27001 and BSI C5 certified data centers
  • CLOUD Act: Not applicable
  • Open source: ✓ Hybrid license (BSD-3-Clause for most components, AGPLv3 for server components Management, Signal, Relay – since August 2025)
  • Self-hosting: ✓ Fully possible (all control plane components)

Three Compliance Layers for GDPR VPN

Layer 1: Provider Jurisdiction (Jurisdictional Layer)

The provider must have its headquarters in the EU and have no US parent company. Otherwise, the CLOUD Act applies via the corporate connection. This excludes:

  • US companies directly (Cloudflare, Zscaler, Twingate)
  • US subsidiaries of European groups (if data control lies with the US subsidiary)
  • EU companies with a US parent (e.g., Microsoft Germany → Microsoft Corp.)

Layer 2: Infrastructure (Technical Layer)

The entire infrastructure – control plane, signal server, relay, database – must be in the EU. Important: not via AWS or Azure EU regions, because these hyperscalers are subject to the CLOUD Act. Dedicated German hosters (Hetzner, IONOS Cloud, plusserver, OVH-DE) are safer.

Layer 3: Encryption (Cryptographic Layer)

Even with an EU provider and EU infrastructure, user traffic should be end-to-end encrypted – so that not even the hoster has plaintext access. WireGuard fulfills this natively. For key management, an own key manager under EU control is recommended.

Only when all three layers are fulfilled is a VPN setup legally GDPR-compliant.


NIS2 Tightens the Situation

Since December 6, 2025, the NIS2 Implementation Act has been in force in Germany. § 30 BSIG requires for around 29,500 companies in Germany:

  • State-of-the-art cryptography and encryption (No. 8)
  • Access control and identity management (No. 9)
  • Multi-factor authentication (No. 10)
  • Supply chain security (No. 4)
  • Effectiveness assessment of measures (No. 6)

Especially supply chain security (No. 4) makes US cloud VPNs problematic: a provider legally obligated to hand over EU data to US authorities cannot be reliably integrated into a secure supply chain. NIS2 violations carry fines up to €10M or 2% of revenue for essential entities, or €7M or 1.4% of revenue for important entities – plus personal management liability under § 38 BSIG.


Practical Example: Hidden CLOUD Act Risks

Scenario: SMB Uses Tailscale Business

A German machinery company with 80 employees deploys Tailscale Business – $18/user/month, cloud SaaS, quickly set up. Management thinks: "Tailscale is Canadian, we're safe."

What management overlooked:

  1. Tailscale control plane runs on AWS (US cloud). AWS thus has technical access to all Tailscale metadata.
  2. AWS is subject to the CLOUD Act. An FBI request to AWS reaches Tailscale data – without Tailscale being informed (gag order possible).
  3. Tailscale's privacy policy explicitly names "Canada, Germany, USA, UK" as data locations. The US risk is named directly.

This will surface in a GDPR audit. In the worst case: fine plus reputation damage.

Scenario: SMB Uses NetBird via birdhost

Same company, same requirement – but NetBird via birdhost:

  1. NetBird is open source (hybrid license: BSD-3 / AGPLv3 for server components) – code fully auditable, no hidden data leakage.
  2. birdhost hosts the control plane in a German data center (Hetzner Falkenstein) – ISO 27001 and BSI C5 certified.
  3. Operating company: merkaio Brands GmbH, German company, no US group, no CLOUD Act.
  4. Data Processing Agreement (DPA) directly available in the portal.

GDPR audit: all requirements met. NIS2 § 30 No. 4 (supply chain security): met.


What Defines GDPR-Compliant VPN Hosting

Criterion Requirement
Provider HQ EU, no US parent company
Server location EU data centers with clear data residency
Infrastructure provider EU hoster (no AWS/Azure/GCP EU region)
Data processing Entirely in the EU
Encryption End-to-end, modern protocols (WireGuard, ChaCha20)
DPA Standardized, immediately available
Open source Desirable for auditability
Certifications ISO 27001 (DC operator), BSI C5 for particularly sensitive data

birdhost: Managed NetBird Hosting for GDPR Compliance

Our managed NetBird hosting in Germany fulfills all three layers:

  • Jurisdictional Layer: merkaio Brands GmbH, Germany. No US group. No CLOUD Act risk.
  • Technical Layer: German ISO 27001 and BSI C5 certified data centers. With Germany region selected, no data packet leaves the EU.
  • Cryptographic Layer: NetBird with WireGuard – end-to-end encryption. Not even birdhost itself can decrypt the traffic.

Additionally:

  • DPA immediately available in the merkaio portal
  • 8 regions worldwide – available for global companies, with clear data residency per region
  • Open Source: NetBird is hybrid licensed (BSD-3-Clause for most components, AGPLv3 for management, signal, and relay servers since August 2025) – every line of code auditable
  • Flat-rate pricing: from €99.90/month, no per-user fees

Decision Guide: Which Provider for Which Use Case?

US Cloud VPN (Cloudflare, Zscaler, Twingate, Check Point Harmony SASE)

Acceptable when:

  • You have no personal data in the VPN
  • You are not a NIS2 or KRITIS operator
  • You don't process special categories of data (Art. 9 GDPR)
  • US data access is acceptable for your business model

Tailscale (Canada / AWS)

Acceptable when:

  • You accept the indirect CLOUD Act risk via AWS
  • Tailscale convenience matters more than 100% EU data residency
  • You operate a DPF-certified setup

NetBird via birdhost (Germany)

Recommended when:

  • You need GDPR compliance without compromise
  • You are NIS2-relevant (KRITIS, regulated industries)
  • You have personal data in the VPN (employees, customers, patients, clients)
  • You must structurally ensure data sovereignty
  • You factor in Schrems III as a real risk

Conclusion

The GDPR question for VPNs is no longer a theoretical discussion in 2026. With NIS2 fines up to €10M (essential entities) or €7M (important entities), personal management liability, and over €7.1B in GDPR fines since 2018 – with the highest top-10 fines hitting US groups such as Meta (€1.2B), Amazon (€746M), and TikTok – the compliance question is existential.

US cloud VPNs – no matter how technically sophisticated – remain structurally a risk. The CLOUD Act forces US providers to disclose data, the CJEU has rated US surveillance laws as inadequate, and the EU-US Data Privacy Framework doesn't solve the core problem. Even Tailscale is indirectly affected via AWS infrastructure.

birdhost positions itself clearly: German provider, German data centers, open-source code, no US group risk. For companies with real GDPR requirements, this is the only legally secure choice.

Try it now: merkaio self-service portal7 days free.

Recommended reading: NIS2 and VPN Network Security · VPN for Healthcare and Legal Professionals


Sources

Frequently Asked Questions

Are US cloud VPNs GDPR-compliant?
No, not reliably. US providers are subject to the CLOUD Act, which gives US authorities access to data worldwide – including in EU data centers. This directly conflicts with Article 48 GDPR. The CJEU's Schrems II ruling (2020) determined that US surveillance laws don't provide adequate data protection for EU data. Even the EU-US Data Privacy Framework (DPF) of 2023 doesn't solve this fundamental problem.
Is an EU data center of a US provider sufficient?
No. The CLOUD Act applies regardless of data location. If a US company controls or owns the data, it must be handed over upon US authority request – even if the data sits in Frankfurt. This applies to AWS EU regions, Cloudflare Edge in Europe, and all other US cloud providers.
What about Tailscale? They're Canadian.
Tailscale is a Canadian company, but operates its control plane on AWS infrastructure (US cloud). According to its privacy policy, data is processed in Canada, Germany, USA, and the UK. Despite the Canadian headquarters, there's an indirect connection to US CLOUD Act risk via AWS.
How does a GDPR-compliant VPN work?
The only legally secure solution: self-hosted or managed hosting with an EU provider without US group affiliation. The entire VPN stack – control plane, signal server, relay – must be hosted in the EU by an EU provider without a US parent company. With birdhost: German ISO 27001 and BSI C5 certified data centers, German company (merkaio), no US CLOUD Act risk.
What happens with GDPR violations using US VPNs?
Fines up to €20M or 4% of global annual revenue – whichever is higher. Since 2018, over €7.1B in GDPR fines have been imposed; the majority of top-10 fines hit US giants such as Meta (€1.2B), Amazon (€746M), TikTok (€345M + €530M), and Meta-Instagram (€405M). Plus reputation and customer loss, plus personal management liability under § 38 BSIG for NIS2-relevant companies.
Is EU location enough for compliance?
EU location alone isn't enough. Three factors matter: (1) EU headquarters of the provider (no US parent), (2) EU data centers with clear data residency, (3) no technical possibility for US authority access. Only when all three are met is a VPN service legally GDPR-compliant.
What does the BSI say about US cloud VPNs?
The BSI explicitly recommends European providers with EU data residency for critical infrastructure (KRITIS) operators and NIS2-relevant companies. NIS2 (§ 30 BSIG, in force since December 2025) requires state-of-the-art encryption and supply chain security – neither can be reliably guaranteed with US cloud VPNs.
How is NetBird with birdhost GDPR-compliant?
NetBird is open source under a hybrid license model (BSD-3-Clause for most components, AGPLv3 for management, signal, and relay servers since August 2025) and can be fully self-hosted or operated via birdhost. birdhost hosts the entire NetBird infrastructure in German ISO 27001 and BSI C5 certified data centers. The operating company is merkaio Brands GmbH – a German company without US group affiliation. DPA available in the portal, no CLOUD Act risk.
Timo Wevelsiep

Written by

Timo Wevelsiep

Founder, merkaio

Founder of merkaio. Managed NetBird VPN hosting. Focused on network security, zero-trust architecture and scalable VPN infrastructure.

LinkedIn

Request Managed NetBird

We operate your dedicated NetBird instance including hosting, updates, monitoring and support. Tell us how many users, sites or devices you want to connect. We'll get back to you within 24 hours with a suitable proposal.

Timo Wevelsiep

Your Contact

Timo Wevelsiep

Founder, merkaio

Discuss your project with Timo

By submitting, you agree to our Privacy Policy.