For public bodies, universities and NGOs

Self-hosted email marketing for the public sector, universities and NGOs in Europe

European governments are reducing their dependence on US software and cloud providers. Most of that work is about office suites, video calls and hosting. The newsletter tool gets less attention, yet it holds a list of citizens, students, alumni or donors. This page covers what public bodies have actually done, what is still only proposed, and what a newsletter stack you can defend to your data protection officer looks like.

We are not lawyers. This page is informational and is not legal advice. Your data protection officer (DPO), procurement team and legal counsel decide what applies to your organisation.

Who this page is for

Municipalities, regional and national agencies, universities, research institutes and NGOs in Europe that send newsletters or announcements and want the subscriber list on infrastructure they control. It is also for the IT teams who will be asked to run it.

In short

  • • Public bodies in Germany, Denmark, Austria, the Netherlands, France and Switzerland, plus the International Criminal Court and the European Commission, have taken concrete steps away from US vendors or toward European cloud since 2025. Some are full migrations. Many are pilots, framework contracts or partial moves.
  • • The EU-US Data Privacy Framework is valid but under challenge. An appeal is pending at the Court of Justice, and after a US Supreme Court ruling in June 2026, noyb asked the Commission to repeal it.
  • • The Cloud and AI Development Act (CADA), proposed on 3 June 2026, includes a common public procurement framework for cloud. It is a proposal, not law.
  • • A public newsletter stack needs a predictable cost line, EU hosting with an owner you have checked, a way out with your data, and a processor list short enough to document.
  • • Self-hosting can avoid third-country transfers of subscriber data, but only if the server, SMTP provider, backups, analytics, support tooling and error tracking are all with EU processors.

What European public bodies have actually done

Headlines tend to inflate these moves. Here is each one at the size the sources support. None of them is about newsletters. They show which questions your auditors and DPO are now used to asking.

Schleswig-Holstein, Germany

State press release, 4 December 2025

LibreOffice is the binding standard. On nearly 80% of workplaces outside the tax administration, Microsoft Office and Outlook are uninstalled or being uninstalled, and almost 44,000 mailboxes have moved to Open-Xchange. The state says it already saves more than €15 million in licence costs, against a one-off €9 million investment in 2026. Source.

Denmark and Aarhus

June 2025 and the 2026 budget

Denmark’s digital ministry started a pilot in June 2025: a group of staff had Microsoft Office in their case-management system replaced with Collabora, which is based on LibreOffice. The minister called it “a welcome step in the right direction”, not an exit. Aarhus went further. Its 2026 budget agreement sets a target of at least 25% of office suites on open source by 2030, and one department has moved 60 IT systems from Azure to Hetzner at about a third of the cost. Ministry, Aarhus.

Austrian armed forces

Completed September 2025

According to press reports, the Bundesheer moved about 16,000 workstations from Microsoft Office to LibreOffice after several years of planning, and completed the migration in September 2025. The stated motive was sovereignty and keeping sensitive data processed internally, not cost. We found no official press release, so treat these figures as reported. Der Standard, Janes.

The Netherlands

March 2025 to May 2026

On 18 March 2025 the Dutch House of Representatives adopted nine motions on government IT, including one asking for a risk analysis and exit strategy for all cloud services from US tech companies. On 23 April 2026 the central government signed a voluntary framework agreement with STACKIT: data stays in the EEA, and the state can terminate if the supplier comes under non-EEA ownership. It makes STACKIT available; it is not a migration. On 25 May 2026 the government blocked the sale of Solvinity, which hosts services behind DigiD, to US-based Kyndryl under the Telecommunications Undesired Control Act (WOZT). Kyndryl has since dropped the deal. Solvinity is still contesting the ban; on 14 July 2026 a Rotterdam court refused to suspend it. STACKIT, Solvinity.

France

January and April 2026

On 26 January 2026 the minister for the public service announced that Visio, the state’s own videoconferencing tool, will be rolled out to all state services by 2027, replacing Teams, Zoom, Webex and others. It is hosted on Outscale, which is SecNumCloud-qualified. On 23 April 2026 the Health Data Hub announced that Scaleway had been selected after a tender to host the platform in place of Microsoft Azure, with migration planned for late 2026 to early 2027. Visio, Health Data Hub.

Switzerland

November 2025 and September 2026

In a resolution dated 18 November 2025 and published on 24 November 2025, privatim, the association of Swiss cantonal and communal data protection authorities, said public bodies should in most cases not outsource sensitive or secret personal data to international SaaS such as Microsoft 365, unless they encrypt it themselves and the provider has no access to the keys. It is guidance, not a ban, and some cantons still moved to Microsoft 365. On 2 September 2026 the Federal Council was briefed on a feasibility study, and the Federal Chancellery launched a programme for a sovereign open-source office platform: about 3,000 staff are to use it from the end of 2027, in parallel with Microsoft 365. privatim, Federal Chancellery.

International Criminal Court

Reported October 2025

The ICC in The Hague is reported to be replacing Microsoft Office with openDesk, the open-source workplace suite from ZenDiS, developed under Germany’s Federal Interior Ministry. The reports place the move in the context of US sanctions on ICC officials. The Register.

European Commission

Awarded April 2026

The Commission awarded a sovereign cloud tender worth up to €180 million over six years to four providers or consortia: Post Telecom (with CleverCloud and OVHcloud), STACKIT, Scaleway, and Proximus (with S3NS, Clarence and Mistral). Bids were scored against its Cloud Sovereignty Framework. One detail for your own assessments: S3NS is a joint venture of Thales and Google. Commission.

The legal background, as of September 2026

Three things matter for a public body choosing a newsletter tool. One is in force, one is under challenge, and one is only proposed.

US transfers: valid, under challenge

The EU-US Data Privacy Framework was adopted on 10 July 2023. The EU General Court upheld it on 3 September 2025 (T-553/23). The appeal, C-703/25 P, is pending at the Court of Justice.

On 29 June 2026 the US Supreme Court held in Trump v. Slaughter that the removal protection for FTC commissioners is unconstitutional. The next day noyb wrote to the Commission asking it to repeal the DPF, arguing the framework relies on an independent FTC. The EDPB asked the Commission on 31 July 2026 to assess the effect, as reported by IAPP. Other commentators argue the redress mechanism is unaffected.

Separately, the US CLOUD Act (2018) lets US authorities compel US companies to produce data they control, including data stored in the EU.

CADA: proposed, not law

The Commission proposed the Cloud and AI Development Act on 3 June 2026 (COM(2026) 502) as part of its Tech Sovereignty Package. It aims to triple EU data centre capacity in five to seven years and sets out a common framework for public procurement of cloud services.

According to an analysis by Covington, the proposal defines four “Union assurance levels”, with a baseline level covering EU infrastructure and data location for all public-sector cloud use, and a non-price “Union added value” criterion in procurement. The text is at first reading in the European Parliament and will change. It does not order anyone off a US provider.

NIS2: in force, scope varies

Member states had to transpose the NIS2 cybersecurity directive by 17 October 2024. On 28 November 2024 the Commission opened infringement procedures against 23 of them for missing that deadline. Germany’s implementing law took effect on 6 December 2025 with no transition period.

Whether your organisation is in scope depends on your sector, your size and how your member state transposed the directive. Ask your security officer. If you are in scope, a self-hosted newsletter server is one more system in your security programme, not an exception to it.

What a public newsletter stack needs

Whatever tool you pick, these are the questions procurement, the DPO and IT will ask.

A cost line that fits a budget cycle

Most newsletter services charge a monthly or annual fee that rises with the number of contacts. That is a recurring commitment that grows when your list does, and it has to be re-approved every year. A one-time licence is a single purchase. The running costs that remain (a server and sending costs) are small and predictable. Check with procurement which of the two is easier to buy in your organisation. In some it is the subscription.

EU hosting, with an owner you have checked

Data location is only half the question. The other half is who owns the provider. The Dutch STACKIT agreement shows one way to handle it: a right to terminate if the supplier comes under non-EEA ownership. You can ask for the same clause from your own hoster or reseller. The Commission’s award to a consortium including a Thales and Google joint venture shows why you should read past the brand name.

A way out

An exit strategy is what the Dutch parliament asked the government to write for its US cloud services. Apply the same test to your newsletter: can you take the full subscriber list, consent records and history with you, in a format another tool can read, without the vendor’s help? For cloud services generally, the EU Data Act bans switching charges from 12 January 2027.

A processor list you can document

Your DPO decides whether a data protection impact assessment (DPIA) is needed for your newsletter. Either way, you will write down every party that touches subscriber data. With a SaaS tool that is the vendor plus its sub-processors, which can change. With a self-hosted tool it is the list you configure: hoster, SMTP provider, backup storage, and any analytics, error tracking or AI provider you connect.

Where Broadcast fits, and where it does not

Broadcast is email marketing software you install on your own server. It runs as a single Docker image with Postgres, and it sends through the SMTP provider you choose.

Where it fits

  • • Procurement: a Regular License is $250 once for one server. An Extended License is $1,000 for up to 25 servers, which suits a university with several faculties or an umbrella NGO with member organisations. No per-subscriber pricing, and a 30-day money-back guarantee.
  • • Hosting: the database sits on a server you rent from a hoster you choose, in the country you choose.
  • • Exit: your data is in your own Postgres database. You do not need us to get it out.
  • • Data to us: no usage telemetry. The update check can be disabled.
  • • Everyday needs: double opt-in, forms, segmentation, sequences with conditional branching, and an API for transactional email and webhooks.

Where it does not

  • • Broadcast is not open source. If your policy requires open-source software, look at listmonk or Mautic.
  • • Someone has to run the server: updates, backups, monitoring. If nobody in your IT team can take that on, a European SaaS tool is the better choice.
  • • Deliverability is your job: DNS records, domain reputation, bounce handling.
  • • There are no landing pages and no lead scoring.
  • • Your SMTP provider is still a processor. If it has a US parent, the transfer question comes back at that layer.

What self-hosting does not do: it does not replace your records of processing, your privacy notice, your consent handling or your processor agreements with the hoster and SMTP provider. It can avoid third-country transfers of subscriber data if the server, SMTP provider, backups, analytics, support tooling and error tracking are all with EU processors. The picture changes only as far as your whole stack changes.

Frequently asked questions

No. The Cloud and AI Development Act was proposed on 3 June 2026 and is still at first reading in the European Parliament. It includes a common framework for public procurement of cloud services, but it is not law and it does not order anyone off a US provider.
No. Broadcast is commercial software sold under a one-time licence. You run it on your own server and your data stays in your own database. If your policy requires open-source software, listmonk and Mautic are the open-source options we compare it with.
A Regular License covers one server. The Extended License covers up to 25 servers, so each department or faculty can run its own instance with its own list.
Broadcast collects no usage telemetry, and the update check can be disabled. Your emails go out through the SMTP provider you configure, and if you use AI features, the content goes to the AI provider you configure. Those providers are your processors.
No tool does that on its own. Self-hosting can avoid third-country transfers of subscriber data if the server, SMTP provider, backups, analytics, support tooling and error tracking are all with EU processors. You still need records of processing, a privacy notice, consent handling and processor agreements.

A newsletter stack you can explain to your DPO.

Broadcast does not make you automatically compliant. It gives you a simpler infrastructure model: your list, your server, your database, your chosen SMTP provider.

One-time licence. No per-subscriber pricing. No US processor at the application or database layer.