← back to home FR

Why European DNS Matters

Where your DNS is hosted determines who can access your data

When you configure a DNS resolver, you’re not just choosing a piece of network infrastructure. You’re choosing a legal jurisdiction. The country where a server is hosted determines which governments can compel data disclosure — and how. This is not a theoretical concern. It affects which DNS providers can actually deliver on their privacy promises.

The CLOUD Act Problem

In 2018, the United States passed the Clarifying Lawful Overseas Use of Data (CLOUD) Act. This law allows US government agencies to compel US-incorporated companies to hand over data stored anywhere in the world — including data stored on servers physically located in Europe.

Cloudflare is a US company. Google is a US company. Cisco/OpenDNS is a US company. NextDNS is a US company. Being incorporated in the US means that a US court order can compel any of these providers to disclose your DNS query data — even if those queries were resolved by a server in Frankfurt or Amsterdam.

This isn’t hypothetical. These companies receive National Security Letters, FISA court orders, and other legal process that may be accompanied by gag orders preventing disclosure. You would never know it happened.

Schrems II and the Collapse of Privacy Shield

In July 2020, the Court of Justice of the European Union invalidated the Privacy Shield framework — the primary mechanism that had allowed EU personal data to be legally transferred to US companies. The court found that US surveillance law, specifically FISA Section 702, did not provide adequate protection for EU residents’ personal data.

The legal landscape hasn’t fundamentally changed since then. Standard Contractual Clauses (SCCs) can be used for some transfers, but they’re not a universal solution — they require case-by-case assessment and provide no protection against intelligence-agency access that the service provider is prohibited from disclosing.

The legal position on EU data at US-incorporated DNS providers remains genuinely uncertain. “Our EU servers are in Europe” is not sufficient if the company itself is US-incorporated.

GDPR as a Meaningful Constraint

The EU General Data Protection Regulation applies to entities established in the EU and to entities that process data of EU residents. An EU-incorporated entity processing EU residents’ DNS data is subject to GDPR in ways a US company is not:

These aren’t just principles — they’re enforceable obligations with consequences. Enforcement is imperfect, but the regulatory framework and the underlying legal culture are meaningfully different from a jurisdiction where “we promise not to look at your data” is the primary protection.

Digital Sovereignty: Why It Matters Beyond Privacy

There’s a strategic dimension to this beyond individual privacy.

DNS is critical internet infrastructure. Every connected device, on every network, relies on DNS for every internet connection it makes. Concentrating this infrastructure in the hands of a small number of US companies creates a strategic dependency that has real consequences.

In a geopolitical dispute, a crisis, or a policy shift, the behavior of US companies providing DNS services to European users is ultimately governed by US law and US political decisions — not European ones. The EU has recognized this as a concern in its digital sovereignty agenda. The same logic applies to individual users making choices about their DNS provider.

Using European DNS infrastructure is a small act with meaningful implications: it keeps your queries within a regulatory framework you have some democratic relationship to, and it doesn’t contribute to concentrating critical internet infrastructure in the US.

Not All European DNS Is Equal

Being incorporated in Europe and running servers in Europe is necessary but not sufficient.

Some EU-incorporated DNS providers still log query data extensively for analytics or to sell to third parties. Some operate under business models that require monetizing user data in some form. “European” on a marketing page doesn’t automatically mean privacy-respecting in practice.

What you’re looking for:

le_dns Infrastructure

All le_dns servers are in the EU, operated by EU-based providers:

le_dns is operated by a French entity. We are subject to French and EU law, not US law. A US court order cannot compel us to disclose data we don’t have — and we design our systems to minimize what we hold.

In practice: we truncate IP addresses to /16 (IPv4) or /48 (IPv6) before any logging. We don’t log which domains you resolve. Operational logs have a 7-day retention. We have no analytics product built on DNS data. We don’t have the data that surveillance law could compel us to produce.

The Honest Trade-offs

US providers like Cloudflare have genuine advantages: global anycast networks with points of presence in 250+ cities, which typically means lower latency than a smaller European-only service. If your priority is pure performance and you’re comfortable with the jurisdictional situation, that’s a legitimate choice.

le_dns currently operates five nodes across France, Germany, and Poland. Coverage will improve over time. For European users, latency differences to nearby European nodes are typically negligible. For users in North America or Asia, this matters more.

What we offer that US providers structurally cannot: genuine EU legal jurisdiction, real data minimization by design, and infrastructure that cannot be compelled to disclose your data by US intelligence law.


Want to learn more about how le_dns is built? See our about page. Ready to configure it? Check our setup guides.