In early 2026, France announced that all government departments would discontinue the use of US-based communications platforms like Zoom and Microsoft Teams with the aim of switching to its own, French-built solution by 2027. This forms part of a strategy of the country’s government to stop using foreign-based software providers in order to “guarantee the security and confidentiality of public electronic communications,” according to minister for the civil service and state reform, David Amiel.
However, this is not an issue that is confined to the public sector. With private company communications often comprising business-sensitive information and personal data, you are reliant on the security of the channels through which you transmit them for competitive, operational and compliance reasons.
Foreign-based software vendors are subject to the jurisdiction of their home country’s government, which may not be compatible with maintaining the integrity of your data. To achieve data sovereignty, you need a platform that meets the EU’s high standards for security.
This article provides a practical framework to help you understand the risk exposure of your communications tool.
Key takeaways
- France’s decision to replace Zoom and Microsoft Teams across government departments shows that data sovereignty and secure communications have become strategic priorities across Europe.
- EU regulations, including DORA, NIS2 and the EU Data Act, are increasing pressure on companies to assess the resilience, governance and jurisdictional exposure of their communications platforms.
- GDPR compliance alone does not eliminate risk because US laws can enable foreign access to EU-held data.
- Recent Microsoft Teams updates and vulnerabilities demonstrate how quickly the security profile of mainstream collaboration tools can change.
The regulatory pressure is already here
EU companies have an obligation to maintain secure communications and protect access to the data that they hold. This is evident in the following pieces of legislation:
| Regulation | What it means for communications tools | Potential exposure |
|---|---|---|
|
Financial entities must report major ICT incidents within four hours of classification and demonstrate strong operational resilience across digital systems. Communications platforms used for earnings calls, investor events and internal communications form part of this ICT infrastructure. |
Weak or insecure communications platforms increase the risk of operational disruption. A secure platform reduces this risk and shows the company has measures in place to ensure resilience.
|
|
|
Essential and important entities must assess their ICT supply chain security, including whether technology providers could be exposed to foreign government access demands under laws such as the US CLOUD Act. |
Organisations using non-EU communications providers without assessing sovereignty and supply chain risks may face compliance concerns, even if no breach has occurred. Penalties can reach €10 million or 2% of global annual turnover. |
|
|
Cloud and data service providers operating in the EU must implement safeguards against unlawful access requests from non-EU governments relating to data stored in Europe. |
Companies using platforms without clear protections around foreign access requests may expose sensitive corporate, investor or employee communications to governance and compliance risks. |
Why GDPR compliance is not enough
GDPR compliance is important, but it is not the only consideration regarding the security of your corporate communications. The regulation covers:
-
Ensuring companies process data legally and transparently
-
Organisations can only collect data for specific legitimate purposes and can only collect the minimum amount of data required
-
The data collected must be accurate and up to date
-
The organisation must store the data securely and keep it only for as long as necessary
GDPR does not cover issues such as the ability of US authorities to demand access to the data held by American-owned companies that provide communications tools. Even if the data is physically held on a server in the EU and in accordance with GDPR, the American government can still use the CLOUD Act to compel US-based companies to hand over that data.
Furthermore, Foreign Intelligence Surveillance Act (FISA) Section 702 allows the US intelligence services to collect communications data from US-owned companies without receiving an individual warrant.
This shows that you can be fully GDPR-compliant but your communications can still be exposed to access by foreign authorities and you might not even be notified.
Example: Microsoft Teams security concerns
Many companies still use Microsoft Teams for their communications workflows. However, as well as being under the jurisdiction of CLOUD and FISA which expose you to foreign access to your data, in recent years there have been some other security concerns about the platform. These include:
-
The introduction in January 2026 of security flagging by default. This means that Teams will alert users to malicious URLs within private meetings, which has raised concerns about what data the tool is monitoring and who has access to that data.
-
Teams’ Chat with Anyone feature that allows external contacts to join Teams conversations via email. Files shared in these chats bypass traditional email security filters, creating a new attack surface.
-
Criminals could also now create spoof Teams invitations, meaning that unsuspecting users could visit a malicious site, thinking they were joining a meeting. It is important for your communications tools to have a verifiable workflow for joining events.
With these vulnerabilities appearing within a short timeframe and some companies not even realising the updates were coming, it shows how quickly the risk profile of your tools can change. And with Teams’ jurisdiction being outside of the EU, the consequences could be serious.
The true security of your tool lies in whether the company behind it operates under a legal framework compatible with your organisation’s own compliance obligations.
Free assessment: Is your communications setup a security risk?
Corporate communications feature high-stakes events and require a secure platform that helps you maintain the integrity of the data and information processed and shared. But is your current setup secure or is it exposing you to risk?
This simple, two-minute assessment allows you to find out what your exposure looks like and what you need to do to maintain data sovereignty.
EngageStream: Built for regulated communications
EngageStream from Euronext Corporate Solutions is a communications solution created and hosted in the EU, adhering to privacy and data handling requirements within the union. As an EU business, you can be sure that the platform will maintain compliance with EU laws and keep you compliant and secure in your communications workflows.
EngageStream is:
-
ISO/IEC 27001 certified and GDPR compliant, with EU-hosted infrastructure.
-
Purpose-built for IR events, AGMs, earnings calls and Capital Markets Days.
-
An end-to-end, white-glove solution with full production support, location scouting and speaker training, as well as access to Europe's largest professional studio network.
-
Embedded in the fabric of Europe’s capital markets, as part of the Euronext Corporate Solutions ecosystem. It is not a standalone tool, but rather created by capital markets experts as part of a suite of tools for issuers.
FAQs
Does this affect how we manage on-demand content and replay libraries or only live events?
The same governance, data sovereignty and access control concerns apply to recordings, replay libraries, transcripts and archived communications content as they do to live events.
How do we explain this risk to senior leadership or the board?
Frame it as an operational resilience, governance and reputational risk issue rather than a technical IT discussion, particularly where sensitive investor, employee or market-facing communications are involved.
Does switching to a European platform mean we have to give up tools we already rely on?
Not necessarily, as many organisations continue using general collaboration tools for routine meetings while adopting specialist European platforms for high-stakes and regulated communications.
Conclusion
Recent updates to Microsoft Teams show the ever-changing risks of using consumer tools for high-stakes events. Given your duty to keep information secure and protect your organisation and stakeholders from external data access, it is no longer acceptable to rely on tools built by companies in non-EU countries. The French government has led the way in the public sector, highlighting lessons that the private sector should heed regarding data sovereignty. When choosing a communications platform, look for one built by an EU company in the European Union and which helps you avoid leaks and unauthorised access.
EngageStream
Find out how EngageStream can help you
EngageStream is produced within the European capital markets framework, backed by financial, communications and compliance experts to deliver a full-service package and peace of mind for your corporate communications.
References and further reading
- Manage shareholder communications from home
- Organise a successful earnings call
- Why webcast your CMD?
- Engage shareholders virtually
- How to organise hybrid and virtual AGMs
Related Articles
See all posts