Microsoft Teams stores data within the EU, but the vendor is based outside the EU and may be covered by third-country legislation (for US companies: the CLOUD Act) regardless of server location. For non-sensitive data this is rarely a problem, but for customer data you should weigh the risk.
Facts that decide
Vendor jurisdiction
Outside EU (Microsoft)
EU data storage
Yes
GDPR terms / DPA
Stated to be available, verify in your contract
Certifications
ISO 27001, ISO 27017, ISO 27018, ISO 27701, SOC 2, BSI C5
Swedish team chat with channels, direct messages as well as voice and video calls, running on Webbfabriken's own servers in Stockholm. Drawback: small vendor and a young service without a large ecosystem of integrations.
All data is stored in Stockholm, built and run by a Swedish company
Free for now, with core features such as channels, video and file sharing
Small vendor: long-term future and pricing model unclear (free now, paid tiers may come)
Best for: Small Swedish teams that want all chat data to stay in Sweden without American cloud.
Spanish video meeting tool that runs in the browser and can be embedded in your own apps via API; all operations are within the EU. The catch: the strength lies in embedding for developers, less as a standalone meeting service.
Fully EU-based company and infrastructure (Barcelona)
Runs in the browser without installation
Most valuable for those who want to integrate video into their own product
Best for: Companies that want to embed GDPR-safe video meetings into their own website or app.
Yes, Microsoft Teams offers data storage within the EU/EEA.
Is Microsoft Teams covered by the CLOUD Act?
The vendor is based outside the EU. US companies are covered by the CLOUD Act regardless of server location; see the tool page for details.
What is needed to use Microsoft Teams in a GDPR-safe way?
Sign a data processing agreement (DPA) if the tool processes personal data on your behalf, minimise the personal data you feed in, and check the vendor's sub-processors. See our DPA guide for the steps.
Our assessment is based on verified data about vendor, storage and certifications (2026). GDPR compliance also depends on how you use the tool. This is guidance, not legal advice. See How we review.