What Does ‘European Software’ Mean?
EU-based, EU-hosted and GDPR-compliant describe different parts of a software service. Learn what each claim tells a buyer, and what it leaves unanswered.
When we started reviewing companies for Speartip.eu, we expected the country field to be easy.
A company has an address in Berlin. Germany. Done.
Then we added hosting information, and the neat classification started to fall apart. A German company might run its service on an American cloud provider in Frankfurt. A US company might offer an EU data region. A vendor might describe itself as “European”, “EU-hosted” and “GDPR-compliant” on the same page.
All three statements can be true. They still answer different questions.
The wording becomes consequential as soon as two vendors sit on a procurement shortlist. A company address tells you little about data residency. A server in Frankfurt does not settle jurisdiction. And “GDPR-compliant” does not tell you where the data goes.
So we started treating European software as a claim that needed specifics.
The address and the server
Take a hypothetical German SaaS company. It is incorporated in Germany, signs customer contracts through that German entity and employs its team there. On any ordinary reading, this is EU-based software.
Now suppose its production environment runs in an EU region of a US cloud provider.
The company has not stopped being European. Its hosting also has a European location. But these are separate facts, and buyers may care about them for separate reasons.
The European Commission made this distinction unusually clear in its 2025 Cloud Sovereignty Framework. Server location is only one part of its assessment. The framework looks separately at ownership and governance, legal exposure to foreign authorities, control of data, operational independence, the supply chain, the technology stack, and security and compliance.1
That is a useful way to think about software even outside large cloud procurements. “Where is the company?” and “where is the data?” belong on different lines of the questionnaire.
There is a third question too: who can exercise legal authority over the provider?
The US Department of Justice describes the CLOUD Act as applying to providers subject to US jurisdiction and says valid US legal process can reach data in a provider’s custody or control regardless of where that data is stored.2 An American service with an EU region may still be a perfectly sensible choice. The hosting label alone cannot settle the jurisdiction question.
That is the distinction hidden by the phrase EU-hosted software.
GDPR compliance is a different kind of claim
“GDPR-compliant” is often placed beside “EU-hosted”, which makes the two sound more closely connected than they are.
The GDPR itself has a broader territorial scope. It applies to processing in the context of an EU establishment regardless of whether the processing itself takes place in the Union. It can also apply to organisations outside the EU when they offer goods or services to people in the Union or monitor their behaviour there.3
Data transfers outside the European Economic Area have their own rules. The European Data Protection Board notes that personal data may be transferred outside the EEA only under the conditions set out in Chapter V of the GDPR.4
So a service can process data in Europe and still have plenty of GDPR work to do. A service can also process data outside Europe lawfully when the required transfer mechanism and safeguards are in place.
For a buyer, the phrase GDPR-compliant software opens a line of inquiry.
What is the vendor actually claiming? Does it offer a data processing agreement? Which subprocessors are involved? Is the advertised EU region the default, or an option on a particular plan? Do backups remain in the same region? Does support staff outside the EEA have access to customer data? If data leaves the EEA, what transfer mechanism is used?
A green badge is easier to design. Procurement needs the details.
Why we separated the fields on Speartip
While building Speartip, we kept running into versions of this classification problem. The simplest design would have been a European flag and a row of checkmarks underneath it.
We decided against that.
Speartip records the provider’s country separately from hosting and data-residency information. Product profiles can also show whether a DPA is available and whether trust information is vendor-declared or has a stronger review status. The directory itself can be filtered using company and hosting information rather than treating “European” as one catch-all property.5
There is a practical reason for being fussy here. People searching for European software alternatives, or more narrowly for EU-based software, do not all have the same objective.
One buyer wants to contract with an EU company. Another has a policy that certain data must remain in the EEA. A public-sector team may have a much stricter sovereignty requirement. Someone else simply prefers European SaaS and wants to support companies building here.
These are all reasonable preferences. They produce different shortlists.
A directory should make the distinction visible before the buyer has to open six privacy policies to reconstruct it.
Read the claim literally
When a vendor says it is European, start with the narrowest possible interpretation of the statement.
If it says EU-based, look for the legal entity and country of establishment.
If it says EU-hosted, find out which data is stored and processed there, whether that location is optional, and which providers and subprocessors are involved.
If it says GDPR-compliant, look for the documents and operating practices behind the claim. Hosting location may be relevant, but it is only part of the picture.
And if the requirement is data sovereignty, write down what sovereignty means for your organisation before searching for products. The Commission’s framework is a good reminder of how quickly that word expands once you examine it: jurisdiction, control, operations, supply chain and technology can all matter.1
We began Speartip with a fairly simple goal: make European software easier to find. Building the product has made the phrase “European software” seem less simple than it did at the start.
That is probably healthy.
A flag can be a useful filter. The interesting work begins with the questions the flag cannot answer.
Browse European software on Speartip.
Footnotes
-
European Commission, Cloud Sovereignty Framework, version 1.2.1, October 2025. ↩ ↩2
-
U.S. Department of Justice, The Purpose and Impact of the CLOUD Act – FAQs. ↩
-
Regulation (EU) 2016/679, Article 3, Territorial scope. ↩
-
European Data Protection Board, International data transfers. ↩
-
Speartip European software directory and Speartip trust methodology. ↩
