When EU hosting becomes "EU + AWS" overnight: the DeepL case
On 20 May 2026 DeepL's Terms of Service shifted from EU-only processing to a hybrid EU + AWS architecture - with a 30-day opt-out window and a binary accept-or-leave outcome. A quick read on what it means for procurement teams that picked European tooling for jurisdictional reasons.
DeepL’s Terms of Service update took effect yesterday, 20 May 2026. As of that date, customer content data flows through a hybrid DeepL EU + AWS architecture by default, with processing distributed across AWS regions globally. Customers who did not opt out within the 30-day window were automatically transitioned. Customers who objected can only continue using their existing subscription through the end of the current billing period, no later than 31 December 2026.
This is a textbook example of the argument we make in Does EU hosting make your AI sovereign? Not on its own: the geographic location of a server is necessary but not sufficient for sovereignty. The decisive question is who controls the processing decisions and whose laws apply to that controller.
DeepL was founded in Germany. Its European-server architecture was a recognised reason that law firms, pharmaceutical companies, public agencies, and research institutions chose it over US-headquartered competitors. As Xpert.digital noted, AWS retains CLOUD Act exposure regardless of whether the data sits in Frankfurt - so the change is not just operational, it is jurisdictional.
Three points for procurement teams:
- A vendor’s hosting strategy is not a contract guarantee. A 30-day notice can shift the underlying processing geography and sub-processor list. If your data-protection impact assessment was based on “EU-only servers”, it now needs revisiting against the new sub-processor.
- Opt-out windows close quickly. DeepL’s window was 30 days from announcement (14 April 2026) to effect date (20 May 2026). That is faster than most enterprise procurement review cycles.
- The remediation is architectural, not contractual. Once a vendor decides their growth path requires hyperscaler capacity, the only durable answer for organisations that cannot accept third-country jurisdictional exposure is to run inference on infrastructure they control.
For organisations evaluating sovereign alternatives, the pillar resource on EU hosting vs sovereignty covers what European regulators have actually said about this and what the architecture must look like to meet the bar for healthcare, defense, and public-sector work. The short version: if you cannot point to the rack, you cannot point to the controller.
If your team is renegotiating a translation, transcription, or document-processing contract in light of this change, we can help model the on-premise alternative.
Bring the answers to your own environment
If your organization cannot compromise on security, privacy, or compliance, the next step is a conversation about your specific data and constraints - not a generic demo.
Request a sovereignty assessment