Bitwarden stores data within the EU, but the vendor is based outside the EU and may be covered by third-country legislation (for US companies: the CLOUD Act) regardless of server location. For non-sensitive data this is rarely a problem, but for customer data you should weigh the risk.
EU/EEAPasswords & securityFreemiumEU data storage ✓ISO 27001
Simple and affordable password manager from Nord Security with ISO 27001, SOC 2 Type 2 and EU data storage in AWS data centers for business customers. The catch: closed source and a tangled ownership structure via holding companies that makes the sovereignty picture less clear than the marketing suggests.
EU company with EU data storage via AWS data centers
ISO 27001 certified and SOC 2 Type 2 audited, code audited by Cure53 (2020)
Not open source
Best for: Small businesses that want an easy-to-use EU-based password manager without technical hassle
EU/EEAPasswords & securityFreemiumEU data storage ✓
Open-source password manager from Luxembourg, built for teams, with cloud hosting in Belgium/Germany or sovereign data center in Luxembourg. The catch: the interface is built for IT professionals and feels clumsier than consumer alternatives, and cloud plans require at least 10 users.
Fully open source and auditable encryption
Luxembourg company with data storage in the EU, plus sovereign data center in Luxembourg (Cloud Sovereign)
Less polished interface than consumer products
Best for: IT teams and regulation-heavy operations that require open source and full EU sovereignty
Yes, Bitwarden offers data storage within the EU/EEA.
Is Bitwarden covered by the CLOUD Act?
The vendor is based outside the EU. US companies are covered by the CLOUD Act regardless of server location; see the tool page for details.
What is needed to use Bitwarden in a GDPR-safe way?
Sign a data processing agreement (DPA) if the tool processes personal data on your behalf, minimise the personal data you feed in, and check the vendor's sub-processors. See our DPA guide for the steps.
Our assessment is based on verified data about vendor, storage and certifications (2026). GDPR compliance also depends on how you use the tool. This is guidance, not legal advice. See How we review.