Understanding what an Outlook alternative actually needs to do to keep mail in Europe

Switching away from Outlook is not just about the inbox. It is about who can be legally compelled to hand over your mail, and from where. Here is what a real outlook alternative needs to solve, and what it does not.

Binadit Tech Team 7 October 2026 12 min lire
Understanding what an Outlook alternative actually needs to do to keep mail in Europe

What this is about and why it matters now

Outlook is the mail client. Microsoft 365 is the service behind it. For most companies the two have become one thing in daily use: you open Outlook, you see your mail, your calendar, your contacts, and somewhere behind that screen sits a Microsoft data centre. That distinction between client and service is exactly where this article needs to start, because a true outlook alternative is not just a different inbox. It is a different legal relationship with your own data.

Here is the plain version of the problem. Microsoft Corporation is an American company. Google LLC is an American company. Under the US CLOUD Act, enacted on 23 March 2018, a provider under US jurisdiction must hand over data in its possession, custody or control if ordered to by a US court, a warrant or a subpoena, no matter where that data is physically stored. Choosing "EU data region" in Microsoft 365 or Google Workspace changes where the servers sit. It does not change which country's courts can compel disclosure, because the law follows the company, not the server rack.

This is not a flaw in Outlook or Microsoft 365 as products. They are well built, widely supported and familiar to almost every office worker in Europe. The issue is jurisdiction, not quality. An IT manager evaluating an outlook alternative needs to understand that distinction clearly, because it changes what you are actually solving for. You are not looking for a prettier inbox. You are looking for a provider that answers to a different legal system.

We have covered the compliance side of this in more depth in our earlier piece on whether your email is still GDPR compliant next year. This article looks at it from the practical side: how the mechanics of mail, calendar and client actually work, what a genuine European alternative needs to replace, and where the trade-offs are.

How mail, jurisdiction and data residency actually interact

To understand why an outlook alternative needs to be more than a different app icon, it helps to walk through what happens when you send and receive mail, and where the legal exposure actually sits.

When you send an email through Microsoft 365, it typically moves through several Microsoft-controlled systems: the Exchange Online mailbox, spam and malware filtering, journaling and compliance archives, and often a copy in a separate retention or eDiscovery store for legal hold purposes. Each of those systems is a separate place where a copy of your data can exist. Each one is operated by Microsoft Corporation or a subsidiary under its control. The CLOUD Act text is specific here: it applies to data in a provider's "possession, custody, or control", regardless of whether that data sits inside or outside the United States. A European data centre location does not remove Microsoft's custody of the data; it only changes the postal address of the hardware.

GDPR approaches the same problem from the other direction. Chapter V of the regulation (Articles 44 to 50) says personal data may only leave the European Economic Area on the basis of an adequacy decision or safeguards like standard contractual clauses. Article 48 adds something specific and often missed: a foreign court order or government demand does not, by itself, make a transfer lawful. And Article 24 puts the burden of proof on the controller, meaning your company, not the vendor, is the one who has to be able to demonstrate that its data handling is compliant.

These two laws do not quite fit together, and that mismatch has already gone through the courts three times. Safe Harbor, the first EU-US data transfer framework, was struck down by the Court of Justice of the EU in 2015. Its replacement, Privacy Shield, was struck down in July 2020 in the case known as Schrems II, where the Court found that US surveillance law, specifically FISA Section 702, gives EU citizens no effective way to challenge or remedy US government access to their data. The current framework, the EU-US Data Privacy Framework, was adopted by the European Commission on 10 July 2023 and is in force today.

It is also, at the time of writing, under legal challenge again. The EU General Court dismissed a challenge brought by French MP Philippe Latombe on 3 September 2025. He appealed on 31 October 2025, and that appeal is now pending before the Court of Justice of the EU with no judgment yet given. This is not a prediction of what will happen. It is simply the current state of a pattern: three frameworks in a row have ended up in European courts, two of the three have already been struck down, and the third is actively being tested.

There is also a human data point worth knowing, because it answers the question most IT managers actually want answered: can the vendor guarantee this won't happen to us? On 10 June 2025, Anton Carniaux, director of public and legal affairs at Microsoft France, testified under oath before a French Senate inquiry. Asked directly whether he could guarantee that French citizens' data entrusted to Microsoft through the French public purchasing body UGAP would never be handed to the US government without explicit French authorisation, his answer was: "Non, je ne peux pas le garantir", meaning "No, I cannot guarantee that." He added that it had never happened so far. Both halves of that answer matter: no guarantee, and no known incident yet. That is an honest answer from a company executive, not a scandal, and it is worth repeating accurately rather than dramatising it.

Concrete examples: what actually changes when you switch

Let's make this concrete rather than abstract. Say a 40-person architecture firm in Utrecht runs entirely on Microsoft 365: Outlook for mail, OneDrive for files, Teams for meetings, and a shared info@ mailbox that three people monitor. What does a genuine switch away from Outlook actually involve, piece by piece?

  • Mailboxes. Each person's mail, calendar and contacts need somewhere to live that is not US-jurisdiction. The receiving system needs to speak the same protocols your existing tools expect: IMAP and SMTP for mail, CalDAV for calendar, CardDAV for contacts. If the new provider only offers a web app with no protocol support, you have traded one lock-in for another.
  • Shared mailboxes. The info@ mailbox needs permission control so the right three colleagues can read and send from it without needing their own separate login to it.
  • Domain authentication. SPF, DKIM and DMARC records need to be reconfigured for the new mail server so that outgoing mail is not flagged as spam by the people you are writing to.
  • The client. Staff are used to the three-pane Outlook layout: folder list on the left, message list in the middle, reading pane on the right. If the replacement forces everyone into a browser tab, adoption suffers regardless of how sound the backend is.
  • Files. OneDrive files need somewhere to sync to that supports the same "files on demand" behaviour people expect, where a file shows as available without actually occupying local disk space until opened.
  • Meetings. Teams calls need a replacement that guests can join from a browser link without installing software, because you cannot ask every client and supplier to adopt your internal tooling.

Binadit Workspace is built to cover exactly that list, as one product with one login on the customer's own domain, rather than five separate subscriptions bolted together. Mail, calendar and contacts work over IMAP, SMTP, CalDAV, CardDAV and JMAP, so existing mail clients, including our own, keep working. Shared mailboxes like info@ get per-colleague permissions. Domain records (MX, SPF, DKIM, DMARC, autoconfig) are placed automatically through Binadit's own DNS tool. For the client itself, Northmail is Binadit's free mail app for macOS and Windows, built deliberately in the three-pane layout people already know from Outlook, and it can connect to Workspace, on-premises Exchange and Gmail side by side, which matters during a migration when not everyone switches on day one.

On pricing, a 2 GB mailbox with calendar, contacts, webmail, Northmail, Meet and Book included costs €2.95 per month excluding VAT; a 25 GB mailbox is €5.95. A company storage pool for shared drive and office documents starts at €9 per month for 250 GB and includes the online office suite. None of this requires a minimum number of mailboxes or a fixed contract term; the full calculator is at binadit.work.

Trade-offs and design decisions worth knowing before you choose

No honest comparison skips the trade-offs, so here they are plainly.

Feature parity is not total parity, and it should not pretend to be. Binadit Workspace does not include team chat with channels, the kind of thing Microsoft Teams or Slack offer; that is planned but not yet announced, so if real-time threaded chat across the whole company is a daily requirement today, factor that into your timeline. It also does not do telephony, large-audience webinars, or meeting room hardware integration. If your organisation runs 200-person town halls or needs a dial-in PBX, that is outside scope.

Encryption is in transit and at rest, not end to end, for regular mail. That matches how Outlook and Gmail work too: convenient server-side search and webmail access require the server to be able to read the content. The one place Workspace does go further is the Receive tool, the replacement for Cryptshare, where files and filenames are encrypted in the sender's browser before upload, so the server only ever stores ciphertext and the password travels through a separate channel that Binadit itself cannot recover.

Desktop sync coverage is not yet universal. Drive, the file sync layer, has native apps for macOS and Windows today; Linux, iOS and Android apps are in development. If your team is heavily iOS or Android for file access, check the current state before committing a migration date.

There is no AI assistant reading your mailbox on the server. Binadit does not train on customer data and does not run an AI assistant inside the mailbox or documents. The only assistant available is an optional one inside Northmail that runs locally on the user's own computer and sends nothing to a cloud. If your organisation specifically wants a server-side AI summarising every inbox, that is a deliberate gap, not an oversight.

Jurisdiction is the actual design decision underneath all of this. Binadit B.V. is a Dutch company, 100% Dutch-owned, with no foreign parent. Every server runs in the Netherlands, in data centres operated by European companies, and Binadit operates the servers itself rather than reselling a US hyperscaler's EU region. No supplier outside the EU is involved, the customer signs a processing agreement under European law, and because there is no American parent company in the ownership chain, the US CLOUD Act simply does not have a hook to apply through. That is a structural answer, not a policy promise. (Note: the data centres Binadit hosts in are ISO 27001 and NEN 7510 certified facilities; Binadit itself does not hold those certifications as a company.)

Switzerland comes up occasionally in these conversations too, worth a short note: it is not an EU or EEA member, but transfers there are lawful under an existing EU adequacy decision, and a Swiss provider answers to Swiss law rather than EU law. That is a different, narrower kind of sovereignty than a Dutch provider operating fully inside the EU legal system, and worth distinguishing if a supplier brings it up.

When to actually make the switch, and when not to

An outlook alternative is worth evaluating seriously when any of the following is true for your organisation:

  • You handle client data under a contractual or regulatory obligation to keep it inside the EU, not just "an EU region", and you need to be able to demonstrate that under GDPR Article 24 if asked.
  • You are responding to a tender or procurement process, public or private, where data residency and provider jurisdiction are evaluation criteria.
  • Your privacy officer or legal counsel has flagged the Schrems I, Schrems II, and now Latombe pattern as a recurring risk that keeps resurfacing on a multi-year cycle, and wants a structural answer rather than another framework to monitor.
  • You want one login and one invoice for mail, files, documents, meetings and scheduling instead of stitching together Microsoft 365, a separate scheduling tool, and a separate secure file transfer tool.

It is less of a fit, at least for now, if your organisation genuinely depends on deep Teams channel structures across departments, needs enterprise telephony integration, or requires mobile file sync on iOS and Android before the native apps for those platforms ship. In those cases, a phased migration, mail and calendar first, files and meetings second, is usually the more honest plan than an all-at-once cutover. We have written separately about why EU region toggles inside US cloud providers don't actually solve data sovereignty, which is worth reading if your current plan is to simply flip a region setting inside your existing Microsoft 365 or Google Workspace tenant and call it solved.

Further reading and next step

If you want the fuller legal background on the CLOUD Act, GDPR Chapter V, and the Schrems case history before making a decision, start with our article on whether your email is GDPR compliant today and whether it will still be next year, and our comparison of standard contractual clauses against binding corporate rules after Schrems II.

When you are ready to look at what replacing Outlook, Microsoft 365 or Google Workspace actually looks like for your organisation, in terms of mailbox counts, storage, and migration sequencing, Binadit Workspace is built specifically for European companies that want mail, calendar, drive, documents, meetings and scheduling under one login, on servers in the Netherlands, under European law. Ask for a demo and a quote and the same engineer who sets up your environment will walk you through what a migration from Outlook would actually look like for your team.