U.S. passkey providers' security gaps exposed. Developers, learn what it takes to ensure a secure login for your users.
Niclas
Created: February 23, 2023
Updated: August 28, 2026

With the increasing threat of cyber attacks and data breaches, it's vital to ensure that sensitive information is kept safe and secure. This is where passkeys come in, providing an additional layer of protection for online accounts. While there are many ways to host passkey infrastructure, from EU companies perspective EU passkey authentication providers have recently been gaining an edge over US providers. This mainly due to their compliance with the General Data Protection Regulation (GDPR) and their reputation for providing top-notch security and data protection. In this article, we'll dive into why European passkey authentication providers are the way to go, causing less headache if you want to be on the safe side when it comes to data security.
In July 2020, the European Court of Justice issued a landmark ruling, known as the 'Schrems II' judgement, which nullified the Privacy Shield agreement between the US and the EU. The Privacy Shield agreement aimed to provide a framework to ensure that companies transferring personal data from the EU to the US complied with EU data protection requirements, especially the GDPR.
With its nullification, there are increased concerns about the potential for unauthorized access and use of this data by US-based companies, as well as the potential for government surveillance. This has caused widespread anxiety about the protection of personal data in the US, and the implications for EU citizens who entrust their data to US companies.
In addition to the US Foreign Intelligence Surveillance Act (FISA) one of the main reasons for these concerns is the CLOUD Act, which requires US companies to hand over data to the government - even if servers are stationed in Europe. This has led to serious questions about data security and privacy. As a result, it is essential that businesses take proactive measures to ensure that customer data is handled securely and transparently.
So lets break down your options:
You could go with a US passkey authentication provider that also operates in the EU, but with their primary focus not directed to this region. This means that there wont be any motivation for them to comply with GDPR.
High risk of government surveillance of your user's data.
Another option is to choose an American passkey authentication provider that actually caters to the EU market. While these providers might make some efforts to meet GDPR requirements, the risk of potential government surveillance and unauthorized access to your data remains a concern. Even if their servers are located in Europe they can't guarantee that user data is out of reach of US surveillance because they are still legally required to hand it out.
Little improvement to just choosing a standard US provider as in option 1.
Alternatively, you could opt for a European passkey authentication provider. Were getting on the right track, but lets not lose sight of the fact even EU companies often use US infrastructure providers, such as Amazon Web Services (AWS), Google Cloud Platform (GCP) or Microsoft Azure. While it's possible to specify the server location to be in the EU, keep in mind that this still doesn't eliminate the requirement for the US infrastructure provider to hand over data to the government even if data is collected on foreign soil.
That obligation is real, but it is worth asking what it would actually produce. A handover can only surface the personal data the provider holds in the first place. A European vendor that keeps pseudonymous records in a Frankfurt region under a data processing agreement, and never receives an email address at all, is exposed differently from one holding a full identity graph on the same cloud. So option 3 is a trade-off rather than a dead end: you carry the legal exposure but you can shrink what it reaches. Option 5 below removes the exposure at the source, which is the cleaner answer where it is available.
Concerned about data privacy? You may be considering having your engineering team implement and operate passkey authentication themselves. While this may be more secure, it will be a significant undertaking in terms of time and resources. Really, just trust us with this one (¦or check out our article about time and cost involved).
So whats the key to best data privacy for EU companies?
If you want to be on the safe side when it comes to your users data privacy, youll hardly find a way around European passkey authentication providers with servers hosted in Europe. They are mandated to comply with GDPR, ensuring a higher standard of personal data handling, transparency and accountability. You have more control over your data, including the ability to request deletion or access to it, a fundamental right under the GDPR.
Plus, using European passkey authentication providers means that businesses can focus on their operations without worrying about compliance issues. These providers ensure that they meet all necessary requirements and are always up-to-date with any changes in data protection legislation. This gives businesses peace of mind and allows them to concentrate on their core operations.
In conclusion, if you're looking for a passkey authentication provider that puts data privacy and data protection first, European passkey authentication providers are the way to go!
Where a provider runs is one half of that question. The other half is how much personal data it needs before it can do its job at all. Corbado is a German company based in Munich, and managed deployments are operated in Amazon Web Services data centers in Germany, with Frankfurt as the main server location, under ISO 27001 and SOC 2 Type II and with a data processing agreement on request. Corbado Observe is then designed so the second half carries most of the weight.
See User Debugging in Corbado Observe →Sparked your interest? Corbados passkey solution might be a good fit for you and your company. Reach out to us to learn more.
Corbado is the Passkey Intelligence Platform for large-scale CIAM teams running consumer authentication. We help you see what IDP logs and generic analytics tools can't: where passkeys, passwords, OTP, social login and fallback journeys succeed, stall or fail, which devices and browsers create friction, and when an OS update silently breaks login. Two products: Corbado Observe layers process mining and observability across authentication journeys. Corbado Connect adds managed passkeys with analytics built in alongside your IDP. VicRoads runs passkeys for 5M+ users with Corbado (+80% passkey activation). Talk to a Passkey Expert →
Even when US companies locate servers in Europe, the CLOUD Act legally compels them to hand over user data to the US government regardless of where that data is stored. This means EU user data remains reachable by US government surveillance, which does not satisfy GDPR's data protection requirements.
The Schrems II judgment, issued by the European Court of Justice in July 2020, nullified the Privacy Shield agreement that had provided a compliance framework for transferring personal data from the EU to the US. Without it, there is no adequate mechanism ensuring US-based passkey providers meet EU data protection standards, raising serious concerns about unauthorized access and government surveillance.
It depends on how much personal data that provider holds. The CLOUD Act attaches to the infrastructure provider's corporate nationality, so AWS, Google Cloud Platform and Microsoft Azure carry a data-handover obligation in every region they operate, Frankfurt included. What that obligation is worth in practice depends on what there is to hand over: a provider keeping pseudonymous records in an EU region under a data processing agreement sits in a materially different position from one holding a full identity graph on the same cloud. Ask a vendor which personal data ever reaches it, how long each field is kept, which region it sits in, who operates the service and whether export and deletion requests have a documented route. Choosing a European infrastructure provider removes this particular exposure at the source. Holding less personal data reduces what any handover could produce, whoever runs the servers.
EU passkey authentication providers that host their services exclusively with European infrastructure providers offer the strongest data privacy posture for EU users. These providers are mandated to comply with GDPR, ensuring transparency, accountability and user rights such as data access and deletion that US-based or US-infrastructure-dependent providers cannot fully guarantee.
Related Articles
Table of Contents