"Our data is in Frankfurt" is the most common answer to a data residency question, and on its own it does not answer the question.
What the law actually says
The Clarifying Lawful Overseas Use of Data Act, passed in the United States in 2018, settled an argument that had been running through the courts for years: whether a US provider could be compelled to produce data it held on a server outside the United States.
The answer it gave was yes. A provider subject to US jurisdiction must produce data in its possession, custody or control in response to lawful process, and the physical location of the storage is not by itself a defence.
The practical consequence is that the question "where is my data" and the question "who can be ordered to hand it over" have different answers. Choosing a European region changes the first. It does not, by itself, change the second.
Three positions, not two
This is why the directory records CLOUD Act exposure as its own field rather than treating "has European regions" as the whole story. There are three meaningfully different positions, and a fourth for when we have not checked.
A European company with no US parent and no US operations is outside the scope of the act. An order has to go through European legal process, which is the situation most people are actually asking about.
A US operator is within scope regardless of which region you pick. This includes every hyperscaler, and it includes providers whose infrastructure is entirely European if the operating company is American.
A European entity with a US parent sits between the two, and it is the case people most often miss. The subsidiary is European. The corporate group is not. Whether a given order reaches the subsidiary's data depends on facts about control that are specific to the company, which is precisely why it is recorded separately rather than folded into one of the other two.
Why this is a filter and not a category
It would be simpler to split the directory into European and non-European sections. That would also be wrong, for two reasons.
The first is that sovereignty is one axis among several. A team choosing a managed database cares about the query language, the backup story, the regions and the price, and where the operator is domiciled. Splitting the catalogue by one axis makes the others harder to compare, and comparing them is the point.
The second is that the honest answer is often mixed. A provider can be a US operator with excellent European infrastructure, real data residency guarantees and a signed agreement covering processing. Whether that is acceptable depends on what the reader is required to comply with, and that is their judgment to make rather than ours to make for them by hiding the listing.
So it is a filter. Turn it on and the list narrows to European companies. Leave it off and the column still tells you where each one stands.
What to check yourself
Three things, in order.
Who is the contracting entity on the agreement you would sign. Not the brand, the legal entity, which is usually named in the terms and often differs from the name on the website.
Whether that entity has a US parent, and if so, what control the parent has over operations. This is a corporate structure question rather than a technical one.
Whether the provider publishes a data processing agreement and a transparency report, and what the report says about the orders it has received. A provider that publishes nothing is not necessarily worse, but it is harder to evaluate, and that difficulty is itself information.
Every listing in this directory records the first two where they have been verified, and says so plainly where they have not.