Google Meet offers EU data storage only on more expensive business plans, but the vendor is based outside the EU and may be covered by third-country legislation (for US companies: the CLOUD Act) regardless of server location. For non-sensitive data this is rarely a problem, but for customer data you should weigh the risk.
Facts that decide
Vendor jurisdiction
Outside EU (Google (Alphabet))
EU data storage
Enterprise/Business plan only
GDPR terms / DPA
Stated to be available, verify in your contract
Certifications
ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 2, BSI C5
Spanish video meeting tool that runs in the browser and can be embedded in your own apps via API; all operations are within the EU. The catch: the strength lies in embedding for developers, less as a standalone meeting service.
Fully EU-based company and infrastructure (Barcelona)
Runs in the browser without installation
Most valuable for those who want to integrate video into their own product
Best for: Companies that want to embed GDPR-safe video meetings into their own website or app.
SwedishVideo meetingsFrom approx 99 SEK/monthEU data storage ✓ISO 27001
Swedish cloud PBX with built-in video meetings, chat and telephony where data is stored in Sweden. The catch: video is part of a larger telephony solution, not a standalone meeting service.
Swedish company, data stored in Swedish data centres
Video meetings in the browser without installation
Video is part of a PBX solution, not a pure meeting tool
Best for: Swedish companies that want to gather telephony, chat and video meetings in a fully Swedish platform.
Only on Enterprise/Business plans. On free and standard plans data is stored outside the EU.
Is Google Meet covered by the CLOUD Act?
The vendor is based outside the EU. US companies are covered by the CLOUD Act regardless of server location; see the tool page for details.
What is needed to use Google Meet in a GDPR-safe way?
Sign a data processing agreement (DPA) if the tool processes personal data on your behalf, minimise the personal data you feed in, and check the vendor's sub-processors. See our DPA guide for the steps.
Our assessment is based on verified data about vendor, storage and certifications (2026). GDPR compliance also depends on how you use the tool. This is guidance, not legal advice. See How we review.