Skip to main content

Choose your country

Article

EU Data Sovereignty and Scam Protection: How F‑Secure Horizon Supports EU‑Based Data Processing

F-Secure

13 min read

Where subscriber data goes, who can access it, and under what legal conditions that access might be compelled: these questions have moved from specialist concern to standard procurement checklist for European digital service providers. The General Data Protection Regulation (GDPR) has been in force since 2018. EU states were required to transpose the Network and Information Security 2 Directive (NIS2) into national law by October 2024. And the landscape for cross-border data transfers involving non-EU jurisdictions has become significantly more complex since the Schrems II ruling in 2020.

For telcos, banks, and insurers offering consumer cyber security services to subscribers in Germany, Austria, France, and the UK, data residency isn’t an abstract compliance question. It shapes which platform partners are viable, which data processing arrangements are defensible, and how the service can be described to subscribers in transparency-sensitive markets.

This article explains why EU data sovereignty matters for consumer security services, what the GDPR and NIS2 frameworks require in practical terms, why cross-border data transfer law creates additional complexity for EU organizations, and how F-Secure Horizon is structured in relation to these considerations.

Does F‑Secure Horizon support EU‑based data processing for consumer security services?

F‑Secure is a European company headquartered in Helsinki, Finland, operating within the EU's legal and regulatory framework. Data processing arrangements, including data residency terms, are set out in the data processing agreement available to partners. Before deploying any subscriber-facing security service, partners should review these terms with their own legal and data protection teams. Contact the F‑Secure partner team to request the data processing agreement and other data protection documentation.

Why data residency matters for European digital service providers

Data residency refers to where data is physically stored and processed. For organizations subject to GDPR, it matters because the regulation imposes strict requirements on transfers of personal data outside the European Economic Area (EEA). Personal data can only be sent to a non-EEA country if that country has been granted an adequacy decision by the European Commission, or if appropriate safeguards such as standard contractual clauses are in place.

For a consumer cyber security service, personal data flows in several directions. Device telemetry, browsing activity flagged as suspicious, identity-related information, and threat encounter data all have the potential to be personal data under GDPR's broad definition. If that data is routed to or processed in a non-EEA jurisdiction without the correct legal basis, the organization responsible faces potential GDPR enforcement action.

Beyond the legal exposure, there is a market reality in Germany and Austria that compliance officers understand well. Subscribers in these markets have consistently higher expectations around data privacy than the European average. The expectation that a security product protects rather than exposes personal data isn’t just a regulatory requirement; it is a commercial condition of acceptance. A security service that can’t answer clearly where subscriber data is held will face trust barriers that no amount of marketing spend can overcome.

What GDPR requires for data transfers outside the EEA

GDPR Chapter V sets out the conditions under which personal data can be transferred to a third country. The three main pathways are an adequacy decision from the European Commission, standard contractual clauses (SCCs), or binding corporate rules for intra-group transfers. In practice, for most commercial relationships involving a non-EU vendor, SCCs are the most common mechanism.

The Schrems II ruling by the Court of Justice of the European Union in July 2020 invalidated the EU‑US Privacy Shield and significantly raised the bar for relying on SCCs with US‑based processors. Following the ruling, organizations must carry out a transfer impact assessment to determine whether the legal framework in the destination country provides an essentially equivalent level of protection to EU law. For US‑based processors, this assessment must take into account the potential reach of US surveillance law, including laws that allow government agencies to compel access to data held by US‑based companies.

This is where the Clarifying Lawful Overseas Use of Data Act (US, 2018), commonly known as the CLOUD Act, becomes relevant for EU organizations evaluating platform partners. The CLOUD Act allows US law enforcement agencies to compel US‑based technology companies to produce data stored on servers anywhere in the world, including in the EU, subject to the terms of the act and any bilateral agreements in place. For EU organizations, this creates a question: if a platform vendor is incorporated in the US, can a US government request compel access to subscriber data held on EU servers?

This question doesn’t have a simple universal answer. The CLOUD Act contains provisions for challenging requests, and bilateral executive agreements between the US and EU member states are under development. But the uncertainty itself is a material factor in vendor selection for compliance-conscious organizations, and it is a question that should be put directly to any platform vendor during procurement.

EU data transfer mechanisms under GDPR Chapter V

Transfer mechanism

How it works and what it requires

Adequacy decision

The European Commission has determined that the destination country provides equivalent data protection. Currently covers countries including the UK (the European Commission renewed the UK's adequacy decisions in December 2025 for a further six years ), Japan, South Korea, and others. The US has a partial adequacy framework under the EU‑US Data Privacy Framework, adopted in 2023 (currently subject to a pending appeal before the Court of Justice of the EU).

Standard contractual clauses (SCCs)

Contractual terms approved by the European Commission that bind the parties to GDPR-equivalent obligations. The most common mechanism for commercial relationships with non-EEA processors. Updated SCCs were issued by the Commission in 2021.

Following Schrems II, organizations relying on SCCs must conduct transfer impact assessments (TIAs) to assess whether the legal environment in the destination country provides essentially equivalent protection. Required for transfers to countries where government access to data is a concern.

Binding corporate rules (BCRs)

Used for intra-group transfers within multinational organizations. Requires approval from a supervisory authority. Less commonly used in commercial vendor relationships.

The CLOUD Act in context: what EU organizations need to understand

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) was signed into US law in 2018. It clarifies that US‑incorporated technology companies are required to preserve and disclose data stored on servers under their control, regardless of where those servers are physically located, when compelled by a valid US legal order.

For EU‑based organizations, the practical concern is this: if a cyber security platform vendor is incorporated in the United States or is a subsidiary of a US‑incorporated parent company, the CLOUD Act may allow US law enforcement to seek access to subscriber data that the EU organization assumed was protected by GDPR. The vendor's response to such a request, and the legal arguments available to challenge it, will depend on the specific corporate structure, the nature of the data, and any applicable bilateral agreements.

The EU‑US Data Privacy Framework, adopted in July 2023, provides some additional protection for data transferred from the EU to the US under the framework, including a redress mechanism for EU individuals. But the Data Privacy Framework applies to data transfers covered by it; it doesn’t neutralize the CLOUD Act's reach over data held by US companies on European servers outside a covered transfer.

The practical implication for procurement is straightforward. EU organizations should ask any platform vendor the following questions: Is the vendor incorporated in the US or is it a subsidiary of a US parent? Has the vendor ever received a CLOUD Act request for subscriber data? What legal mechanisms does the vendor have in place to challenge such requests? And what would the vendor's response process look like if such a request were received?

F‑Secure's position as a European company

F‑Secure Corporation is incorporated and headquartered in Helsinki, Finland. Finland is an EU member state, which means F‑Secure operates within the EU's legal and regulatory framework, is subject to GDPR as a data processor and controller in various contexts and is not a US‑incorporated entity.

This distinction matters for EU‑based partners evaluating data sovereignty risk. A European-incorporated vendor doesn’t carry the same CLOUD Act exposure as a US-incorporated one, because the CLOUD Act’s   jurisdictional reach generally tracks US incorporation, ownership, or control. A Finnish company is not a US person for the purposes of the CLOUD Act.

F‑Secure has operated as a privacy-focused security company for more than 37 years. The company's approach to data handling has been shaped by Finnish and EU law, and its consumer products are designed with data minimization principles consistent with GDPR requirements.

For partners who need to document their data residency and processing arrangements as part of a GDPR compliance program or a NIS2 supply chain security assessment, F‑Secure can provide data processing agreements and documentation that set out the terms of data handling. These agreements are available through the F‑Secure partner team and should be reviewed by the partner's own legal and data protection advisors before the service is deployed.

Data sovereignty checklist for evaluating a cyber security platform partner

Question to ask the vendor

Why it matters

F‑Secure Horizon position

Where is the vendor incorporated?

US‑incorporated vendors may be subject to CLOUD Act requests for data on EU servers.

F‑Secure is incorporated in Finland, an EU member state.

Where is subscriber data processed and stored?

GDPR requires a lawful basis for processing of personal data and transfers of data outside the EEA. EU/EEA processing avoids transfer complexity.

Data processing terms, including residency, are set out in the data processing documentation available to partners.

Is a data processing agreement available?

GDPR Article 28 requires a formal agreement between controller and processor. Without one, the arrangement is non-compliant.

Yes. Available through the F‑Secure partner team on request to cover situations where F‑Secure acts as a processor.

Does the vendor hold ISO/IEC 27001 certification?

An independently verified security management standard, relevant for NIS2 supply chain assessments.

Yes. F‑Secure Horizon is ISO/IEC 27001 certified.

What data does the security product collect?

Data minimization under GDPR means only necessary data should be collected. Over-collection creates compliance risk.

Covered in the F‑Secure Total product documentation.

Structuring a GDPR-compliant consumer security service

For digital service providers deploying a subscriber-facing cyber security product, GDPR compliance involves more than choosing the right platform vendor. The partner organization is typically the data controller for the subscriber relationship, which means it holds responsibility for establishing a lawful basis for processing, providing transparent information to subscribers at sign-up, and maintaining the processes to handle data subject requests.

Before launching a consumer security service, partners should work through the following areas with their data protection team.

  • First, identify the lawful basis for processing subscriber data through the security product. For most commercial services, this will be contract performance or legitimate interests, but this needs to be assessed for the specific context.

  • Second, update subscriber-facing privacy notices to reflect the data flows introduced by the security product.

  • Third, execute the data processing agreement with F‑Secure before subscriber data begins flowing through the platform.

  • Fourth, document the transfer impact assessment if any data processing occurs outside the EEA.

None of this is unusual for organizations already operating under GDPR. Most telcos and financial service providers have data protection programs in place that can accommodate these steps. The key is to treat the security service launch as a new processing activity that requires the standard GDPR documentation review, rather than assuming existing notices and agreements cover it.

For data processing agreement inquiries, contact the F‑Secure partner team:

Talk to the partner teamISO/IEC 27001 certificationSee how F-Secure Horizon worksView pricing

Why the German and Austrian market context makes this particularly relevant

Data privacy isn’t just a compliance consideration in Germany and Austria. It is a cultural expectation embedded in how consumers and regulators approach digital services. Germany's Federal Commissioner for Data Protection and Freedom of Information (Bundesdatenschutzbeauftragter, or BfDI) has been among the most active data protection authorities in Europe, with a track record of enforcement actions and public positions on issues including transatlantic data transfers and cloud provider data residency.

Austrian supervisory authority decisions have similarly shaped how EU privacy law is interpreted in practice, including the landmark ruling in late 2021 that found the use of Google Analytics on Austrian websites to be incompatible with GDPR due to the risk of US intelligence agencies accessing the data under US surveillance laws.

For telcos and insurers serving German and Austrian subscribers, data sovereignty isn’t a procurement preference. It is a condition of market credibility. A security product that can’t demonstrate clear EU‑based processing, or that involves a US-incorporated vendor without clear CLOUD Act safeguards, creates a reputational risk that extends well beyond regulatory enforcement.

F‑Secure's Finnish incorporation, combined with its data processing agreement and ISO/IEC 27001 certification, provides a set of documented, verifiable answers to the questions that German and Austrian compliance teams will ask. That is a more commercially solid foundation than relying on adequacy frameworks that remain subject to legal challenge.

Conclusion

Data sovereignty has become a practical commercial variable for European digital service providers, not just a compliance checkbox. The combination of GDPR's transfer restrictions, the Schrems II ruling's impact on SCCs with US processors, and the CLOUD Act's extraterritorial reach has created a procurement environment where the question of where a vendor is incorporated matters as much as what the product does.

F‑Secure's position as a Finnish, EU‑incorporated company addresses the most significant structural concern in this evaluation. The data processing agreement and documentation, ISO/IEC 27001 certification, and transparent data handling framework provide the documented basis that compliance teams in Germany, Austria, France, and the UK need to proceed with confidence.

Deploying a consumer cyber security service that meets both the commercial expectations of subscribers and the data sovereignty requirements of GDPR is achievable. The precondition is choosing a platform partner whose legal structure and data handling practices are aligned with the EU framework from the start.

Contact the F‑Secure partner team to request the data processing agreement.

Frequently asked questions

Legal disclaimer

This article provides general information about data residency, GDPR, and related regulatory considerations. It is not legal advice. Partners should consult their own legal and data protection teams for guidance on their specific obligations.

About the author

F‑Secure Partner Content Team

Cyber Security Content Specialists, F‑Secure

This content is produced by the F‑Secure Partner Content Team using insights from the F-Secure Digital Trust Report 2026, F‑Secure Global Consumer Market Survey 2026 (n = 10,000, 10 countries), and F‑Secure Horizon partner program data. F‑Secure has more than 37 years of experience in cyber security research and partner services. F‑Secure Horizon is ISO/IEC 27001 certified.

Turn AI-powered scam protection into high-margin revenue

F-Secure Horizon is an effortless, full-service business platform that helps you deliver award-winning cyber security to your customers with zero complexity and maximum impact. Sign up to start reselling F‑Secure Total with a minimum monthly commitment starting from €99.

  • Create, distribute, and manage subscriptions with ease — or automate via API

  • Drive high-margin recurring revenue growth

  • Build customer loyalty through trusted protection

Talk to the F‑Secure Partner team.