Varnish Software has launched a new Europe-hosted Content Delivery Network (CDN) to provide organizations with full control over their digital footprint, ensuring traffic, logs, and metadata are processed strictly within European jurisdiction.
The Swedish high-performance content delivery technology operator created Varnish CDN to address the risk of routing live traffic through providers subject to US jurisdiction, an issue that has grown in importance for European organizations as the GDPR and the NIS2 directive are setting the standard for digital infrastructure.
With most global CDNs subject to the U.S. Cloud Act, this means that even if data is stored in Europe, the metadata and traffic logs generated during delivery can be subject to non-European legal claims.
To prevent exposure of information, Varnish CDN was designed to provide a delivery network operated by a European entity with no U.S. parent company, using nodes situated in major European internet hubs.
"Varnish CDN solves a critical challenge for European tech: securing the digital supply chain without sacrificing performance," said Filip Golonka, senior devops manager at Schibsted. "During the beta [phase], we validated that we could deploy complex logic in seconds, all while ensuring our traffic and logs never left European borders. It is a robust, future-proof solution."
Varnish aims to help regulated industries, in particular, by reducing compliance complexity and transforming sovereignty from a legal hurdle into a competitive advantage.
Its new CDN's security capabilities are delivered through a combination of native edge functionality and tightly integrated partners. The main features include native resilience – built-in DDoS protection, GeoIP blocking, and hotlink protection to ensure service continuity; bot protection – real-time AI mitigation with DataDome against sophisticated scraping, fraud, and automated attacks; and managed WAF – advanced atomicorp rulesets to block application-layer threats, including SQL injection and credential theft.
Gilles Walbrou, CTO of DataDome, said: "Our integration brings AI-powered bot and agent trust management directly to that edge infrastructure, enabling organizations to stop sophisticated automated attacks in real-time, before they ever reach origin servers.
“This combination delivers what European businesses need most: uncompromising security, data sovereignty, and the ultra-low latency that modern user experiences demand."
The wave of increased data protection in the EU intensified at the end of 2025 when tech giants, including Microsoft, committed to AI user data staying in the bloc's borders.
As sovereignty pressures mounted, Microsoft doubled down on its efforts to address growing data sovereignty demands, unveiling a flurry of new cloud capabilities amid increased lawmaker scrutiny.
The hyperscaler revealed that data processed by its AI services will remain within the EU. All customer data, whether at rest or in transit, will be stored and processed exclusively in the EU, unless a customer requests otherwise.
Microsoft’s new data processing rules also apply to its Copilot chatbot service, which is now firmly embedded across a wave of enterprise PCs following the Windows 10 support switch-off as devices move to Windows 11.
In a similar move, November also saw Google open a sovereign cloud hub in Germany in a bid to strengthen digital sovereignty for the continent.
Co-located with Google Cloud’s existing security and privacy engineering hub, the new hub is set to provide a dedicated space for regional partners to engage with Google’s sovereign cloud tools. The offering promised to simplify the complexities of the changing technological and regulatory landscapes.
Comments