Buffer is controlled from a country outside the EU and lacks confirmed EU data storage: processing effectively takes place in a third country. That makes the tool unsuitable for sensitive personal data without additional safeguards. For non-personal data (drafts, public material) it is usually fine.
Swedish platform for newsletters, marketing automation and SMS with data processing within the EU/EEA and Swedish-language support. The catch: the free plan only holds 250 contacts and the price climbs quickly as the list grows (Professional from 595 SEK/month for 2,500 contacts).
Swedish company (Stockholm, founded 2007), data processed within the EU/EEA according to the DPA
Free entry plan and personal Swedish support via email and phone
Free plan limited to 250 contacts
Best for: Swedish e-commerce companies and SaaS businesses that want email, SMS and automation in one place with data storage within the EU/EEA
No, Buffer has no confirmed EU data storage: data is processed in a third country.
Is Buffer covered by the CLOUD Act?
The vendor is based outside the EU. US companies are covered by the CLOUD Act regardless of server location; see the tool page for details.
What is needed to use Buffer in a GDPR-safe way?
Sign a data processing agreement (DPA) if the tool processes personal data on your behalf, minimise the personal data you feed in, and check the vendor's sub-processors. See our DPA guide for the steps.
Our assessment is based on verified data about vendor, storage and certifications (2026). GDPR compliance also depends on how you use the tool. This is guidance, not legal advice. See How we review.