Most infrastructure threat models stop at the edge of the box. Patch level, exposed ports, key management, backups. All necessary, and all built on an assumption that quietly goes unexamined: that the machine will still be there tomorrow, and that nobody outside your organisation can reach into
it.
That assumption fails at the legal layer, not the technical one. The question worth asking before you provision anything sensitive is not where the server sits. It is who can compel the company that owns the hardware, under what procedure, and how fast.
The answer depends less on the flag on the provider’s website than most buyers assume.
Three mechanisms that reach across borders
There are three regimes that account for most cross-border demands on hosting providers today, and they work differently enough that conflating them leads to bad decisions.
The US CLOUD Act
Passed in 2018, it establishes that a provider subject to US jurisdiction must produce data in its possession, custody or control regardless of where that data physically lives. A US company storing your data in Frankfurt is still a US company.
The test is control over the data, not the location of the disk. So “our servers are in Europe” is an incomplete answer whenever the entity that actually holds or controls the data is subject to US jurisdiction, which is most obviously the case where a US parent has control over a foreign
subsidiary’s systems. Working out whether that applies to a given provider means reading the corporate structure, not the datacenter page.
The EU e-Evidence Regulation
Regulation (EU) 2023/1543 became applicable on 18 August 2026 across the EU except Denmark, and it is the biggest recent change in this area. It lets a judicial authority in one member state send a European Production Order directly to a provider in another, bypassing the mutual legal assistance
channels that historically took months. The response deadline is ten days, or eight hours in emergencies. A European Preservation Order freezes data for sixty days while the authority obtains what it needs to compel disclosure.
Two details matter for anyone outside the EU who assumes this does not apply to them. First, scope is defined by offering services in the Union rather than by establishment in it, and hosting providers are explicitly named. Second, the companion Directive (EU) 2023/1544 requires in-scope providers
to designate an EU establishment or appoint a legal representative to receive these orders. A non-EU provider selling to EU customers is inside this framework whether or not it has noticed.
Swiss surveillance law
Switzerland sits outside both regimes as a matter of domestic law, and its Federal Act on Data Protection, in force since September 2023, sets a high floor. The more useful detail is in the surveillance statute rather than the data protection one.
The BÜPF and its implementing ordinance divide obligated parties into telecommunications service providers, which carry the heaviest duties including a six month retention obligation, and providers of derived communication services, which carry tiered and lighter ones. The second category is
defined by whether you operate a communication service yourself: email, messaging, VoIP and comparable platforms. Where a general-purpose hosting or VPS provider sits is genuinely contested. Renting infrastructure that a customer configures and controls is not obviously the same thing as running a
communications platform, and if a customer self-hosts their own mail server on a rented machine, the stronger argument is that the customer is the one operating the derived communication service. But the Swiss surveillance service has read the category broadly, and storage and cloud offerings have
been treated as falling inside it. Anyone relying on that distinction should treat it as an argument that has not been fully settled rather than a safe harbour.
That boundary has been under active pressure. A revision opened for consultation in January 2025 proposed expanding obligations for providers of derived communication services, including cloud services, with broader user identification and retention duties. The response was overwhelmingly
negative, and in February 2026 the Federal Department of Justice and Police commissioned an external impact assessment and announced that a redrafted version would go out for a second consultation. The Federal Council also clarified that any decryption obligation would not extend to end-to-end
encrypted messages exchanged between users. The most aggressive version is not proceeding, but a paused proposal is not a withdrawn one, and anyone building on Swiss infrastructure should track where the redraft lands.
Foreign authorities wanting Swiss-held data generally still go through mutual legal assistance, which is slower, reviewable, and refusable on defined grounds. That is the real Swiss advantage, and it is procedural rather than absolute. Anyone selling Switzerland as a place data cannot be compelled
from is selling something that does not exist.
Singapore, briefly
Worth noting for readers in the region. Section 39 of the Criminal Procedure Code lets a police officer or authorised person access and copy data from a computer connected to an arrestable offence, and it is not subject to prior judicial approval. Section 40 extends that to decryption information
and to compelling technical assistance, on the authority of the Public Prosecutor. Data protection law sits alongside these powers rather than limiting them.
The part almost nobody checks: which network is underneath
Here is where country-level analysis breaks down, and it is the most useful thing in this article.
Two servers can sit in the same country, in the same city, sold by the same provider under the same brand, and be handled differently when a demand arrives. One of the variables is the upstream network the service runs on, identified by its autonomous system number.
An example from our own infrastructure, since it is easier to be specific about networks you operate on than ones you do not. Our Finnish capacity currently spans two segments. Services on AS207003 run on our primary Finland network, over a direct-to-datacenter contracted connection. Other
services run on AS24940, where we are a customer of the upstream operator.
The handling differs. US DMCA notices are actioned only on AS24940, because the upstream forwards them under its own compliance obligations with a stated deadline, typically twenty four hours, and does not accept counter-statements. On AS207003, services operate under EU and Finnish law, foreign
takedown demands are not actioned without a Finnish court order or equivalent instrument, and content complaints follow a standard notice and counter-statement process. Expedited live event takedowns exist on the first segment and not on the second. All of this is published in our acceptable use
policy, and which products sit on which network is visible through our looking glass.
Same country. Same company. Same product page. The network a service is provisioned on can materially change how a takedown demand is handled, and it is not the only variable: the contracting entity, the upstream agreement, the applicable law and the nature of the complaint all feed into the
outcome.
This is not unique to us. Any provider that leases or resells upstream capacity inherits some of that upstream’s abuse policy, and most do not disclose which network a given plan lands on. If your threat model includes takedown pressure or process served at the infrastructure layer, the ASN is a
more informative data point than the country, and it takes about ten seconds to look up.
What to check before you provision
A short, practical list.
- Look up the IP in the RIR database. RIPE, ARIN or APNIC will tell you which organisation holds the ASN and the address block. Often it will be a datacenter operator or upstream rather than the brand you paid, which is normal and fine as long as you know it and have priced the
abuse policy in. Do this to us as well. - Read the acceptable use policy per location, not per company. Providers operating across multiple networks should publish different policies for them, because the obligations genuinely differ. A single global AUP spanning several upstreams usually means at least one of them is
not being described accurately. - Ask what is logged and for how long. Not what the marketing page says about privacy. What the panel, the billing system and the hypervisor retain, and for how long. A provider cannot produce what it never collected, and that is the only guarantee in this space with real
structural weight. - Check the corporate structure, not just the datacenter address. Which legal entity holds the customer contract, where it is incorporated, and what it controls. That determines which of the regimes above can reach it directly.
- Test the network before you buy. A looking glass with live diagnostics and downloadable test files lets you verify routing and latency rather than taking a claim on faith. If a provider does not publish one, ask why.
What jurisdiction does not buy you
Jurisdiction is a procedural layer, not a security control, and it fails in predictable ways when treated as one.
It does not protect data your provider can read. It does not survive a compromise of your own credentials. It does not help if your backups sit with a US cloud provider while your production box sits in Zurich, which is a surprisingly common configuration. And it does nothing about the civil side,
where pressure often arrives first and is not addressed by criminal procedure rules at all.
The sensible posture is to treat jurisdiction as one layer among several. Encrypt at rest with keys the provider does not hold. Keep backups under a different operator in a different legal system. Assume any data your host can technically read is data that can eventually be compelled, and design
so that the compellable set is small and boring.
Then choose the jurisdiction, with an accurate picture of what it actually changes. We publish a jurisdiction-by-jurisdiction comparison scoring fourteen countries on retention mandates, surveillance powers and legal
process, which is a reasonable starting point if you are weighing options. For teams that land on Switzerland after reading it, Packetra’s VPS hosting in Switzerland runs on Swiss infrastructure under the framework described above.
The honest summary is that no jurisdiction puts your infrastructure out of reach. Some of them change who has to ask, how long it takes, and whether anybody independent reviews the request first. For most threat models that difference is the whole game, and it is worth understanding properly
rather than buying a flag on a landing page.
Disclosure: the author is the founder of Packetra, a hosting provider operating in Finland and Switzerland.