The question comes up in almost every CRM or business-application scoping call: "do our customer records have to be hosted in France, or at least in Europe?". The short answer has two parts. Legally, no: GDPR (the General Data Protection Regulation) imposes no national hosting requirement, and the French SecNumCloud obligation that took effect in 2026 only targets the state. In practice, yes, more and more often: the legal ground under EU-US data transfers eroded in 2026, and hosting with a European-law operator is now the cheapest way to stop depending on that ground at all.

Key takeaways

What the law actually requires, and what it does not

GDPR is a regulation about accountability, not geography. It allows hosting anywhere in the European Union without formality, and outside the EU as long as a valid transfer mechanism exists: an adequacy decision, standard contractual clauses, or binding corporate rules. An SME using an American CRM hosted in Ireland, or an email tool whose servers sit in Frankfurt, is in principle compliant.

The only recent French localization mandate does not concern private companies. Decree no. 2026-272 of April 14, 2026, implementing article 31 of the SREN law, requires French state administrations and their operators to entrust their most sensitive data to offers qualified under SecNumCloud, the security framework of ANSSI, France's national cybersecurity agency. As this analysis of the SecNumCloud scope (in French) sums up, the legal obligation only covers the public sector; for private companies the qualification remains voluntary, even if it is becoming a de facto standard in healthcare, finance and defense.

In other words: if a vendor sells you French hosting as a legal obligation, they are wrong or overstating the case. The real question lies elsewhere.

Why a data center in Paris is not enough

Many executives believe they settle the matter by picking the "Paris region" of their American cloud provider. That is a common reasoning error. The CLOUD Act, passed by the US Congress in 2018, lets American authorities compel a provider subject to US law to hand over data it hosts, wherever the servers physically sit. An AWS, Azure or Google Cloud server in the Paris region therefore remains legally reachable under US law.

What matters is not the data center's address but the law governing the operator who holds the access keys. That is precisely the distinction SecNumCloud draws: it requires protection against "unauthorized access by public authorities of third states", a guarantee that no standard certification such as ISO 27001 covers. For an SME the consequence is easy to state: hosting with a French or European-law operator, free of controlling American ownership, mechanically takes your data out of the CLOUD Act's reach. Hosting with a US hyperscaler in France does not.

Are transfers to the United States still safe in 2026?

They are legal, but their legal basis has never looked more fragile. EU-US personal data transfers rest on the Data Privacy Framework (DPF), the adequacy decision adopted in 2023. That framework survived a first challenge before the EU General Court in September 2025, but history calls for caution: its two predecessors, Safe Harbor and Privacy Shield, were both struck down by the EU Court of Justice, in 2015 and 2020.

The year 2026 added a crack from the other shore. On June 29, 2026, in Trump v. Slaughter, the US Supreme Court endorsed the "unitary executive" theory, which places federal agencies under the president's direct authority. Yet the independence of the FTC (Federal Trade Commission), the regulator tasked with enforcing the DPF on the American side, is mentioned 259 times in the adequacy decision, as this legal analysis of the ruling (in French) details. If the framework's foundation collapses on the American side, the European Commission or the Court of Justice could draw the consequences; privacy lawyers already advise companies to map their data flows to the United States and document European fallback options.

For an SME, the point is not to predict the outcome of the litigation. It is to avoid rebuilding your data architecture at every tremor. A company whose CRM, invoicing and customer files live with European operators simply does not have this problem.

What should you actually check before choosing?

Four criteria are enough to assess a hosting option: the law the operator answers to, the actual location of the servers, the security certifications, and reversibility (can you leave with your data, in what format, how fast). The table below sums up the main families of options for an SME.

OptionSubject to the CLOUD Act?Best forMain limit
US hyperscaler, France region (AWS, Azure, Google Cloud)YesHeavy technical workloads, rich ecosystemLocation does not shield from US law
European host (OVHcloud, Scaleway, Hetzner)NoMost SMEs: websites, CRM, business applicationsSmaller catalog of managed services
SecNumCloud-qualified offer (OVHcloud, Outscale, Scaleway on some ranges)NoHighly sensitive data, regulated sectors, public contractsCost and overhead unnecessary for everyday use
US SaaS (CRM, email, support)YesEveryday tools without sensitive dataDepends on the Data Privacy Framework, weakened in 2026

A word on costs, since that is the expected objection: it no longer really holds. The French cloud market reached €21.4bn in 2025, growing 19% according to IDC France, cited in Silicon's 2026 cloud benchmark (in French), and the European offer has broadened accordingly. At a comparable tier, a server with a European host costs in the same range as, and often less than, its hyperscaler equivalent. The real cost of moving to European hosting is not the infrastructure: it is the migration, which is quoted case by case depending on volume and dependencies.

When European hosting is not the right fight

Honesty requires saying it: not all data deserves this debate. A B2B prospect list with work emails, an internal planning tool, a brochure website: the actual risk there is low, and migrating those tools on principle is budget better spent elsewhere. Likewise, if your team depends on an American SaaS that does its job very well, the right answer is often to keep it knowingly, with up-to-date contractual clauses, rather than rebuild everything.

The reasoning flips as soon as the data becomes sensitive: health, minors, social situations, detailed financial records, or simply a customer file that is the core of your value. There, the law applicable to your host becomes an architecture decision, to be made when the tool is designed, not after. That is the reasoning behind the custom CRM of e-Enfance, the French nonprofit that operates 3018, the national helpline against online abuse of minors: particularly sensitive data, processed in real time across channels, on a platform hosted in France, detailed on the projects page. That level of care is not reserved for large accounts: it simply has to be decided at the right moment.


The question "where does my data live?" is settled by architecture, not by a checkbox in a contract. If you want to know where your own setup stands, the inventory is quick: the list of your tools, the law each one answers to, and the sensitivity of what they hold fits on one page. That is exactly the kind of assessment a 30-minute scoping call can produce, and if a custom CRM hosted in Europe is the right answer, you will know; if your current setup is fine, you will know that too.

Frequently asked questions

Is an SME legally required to host customer data in Europe?

No. GDPR regulates how personal data is processed but imposes no national or EU hosting requirement. France's SecNumCloud obligation, introduced by decree no. 2026-272 of April 14, 2026, only applies to state administrations and their most sensitive data. For a private SME, European hosting is a risk-management choice, not a legal constraint.

Does an AWS or Azure server located in Paris escape the CLOUD Act?

No. The CLOUD Act, a US law passed in 2018, applies to providers subject to US law regardless of where the servers physically sit. An AWS server in the Paris region remains legally reachable by US authorities. What matters is the law the operator answers to, not the address of the data center.

What is SecNumCloud and does an SME need it?

SecNumCloud is the qualification issued by ANSSI, France's cybersecurity agency, certifying that a cloud offer protects data, including against extraterritorial laws. It became mandatory for certain French state data in 2026 but remains voluntary for the private sector. A typical SME does not need it: a European-law host with ISO 27001 certification already covers most of the risk.

Is European hosting more expensive than a US cloud?

Not necessarily. At a comparable tier, European providers charge in the same range as the US hyperscalers, and often less for virtual private servers and dedicated machines. The real cost of switching is the migration itself, not the destination infrastructure; that cost depends on volume and dependencies and is quoted case by case.