European password managers: Proton Pass, NordPass and more
Which password managers come from Europe or offer EU data storage? A fair comparison of Proton Pass, NordPass, Bitwarden, 1Password, KeePassXC and others.
ReviewsPublished
If you want a password manager with European roots, Proton Pass from Switzerland is the clearest choice, with NordPass from the Lithuania-founded Nord Security group as the second. Bitwarden, 1Password and Keeper are non-European companies that let you store your data in the EU, and KeePassXC avoids the question by keeping everything local. This page explains what “European” can and cannot guarantee and compares the realistic options. For the full field, see our best password managers overview.
What “European” actually means here
Three questions get mixed up, and it helps to separate them:
- Where is the company based? This decides which courts and authorities can compel it to act.
- Where is the encrypted data stored? This decides which data protection rules apply to the servers.
- Can the provider read the vault at all? With a zero-knowledge design, it cannot.
The third point is the one that protects you most. A properly built manager encrypts the vault on your device, so what sits on a server in Zurich, Frankfurt or Virginia is unreadable ciphertext. A European location still adds value: GDPR applies to account data, billing and metadata, and some organisations require EU-based processing. Switzerland is outside the EU but benefits from a European Commission adequacy decision.
The criteria
We use the same criteria on every comparison page: encryption model (zero knowledge), independent audits, passkey support, server location and EU option, recovery, export and switching, price (October 2026, indicative) and platforms. These are editorial assessments from vendor documentation and public information, not lab tests.
Comparison table
| Manager | Company base | EU / European data option | Open source | Audits | Passkeys | Price from (approx.) |
|---|---|---|---|---|---|---|
| Proton Pass | Switzerland | Swiss infrastructure | Clients open source | Cure53 audit published | Yes, also free | Free; paid about 3 EUR per month, billed yearly |
| NordPass | Nord Security, Lithuanian roots | Check privacy policy for processing locations | No | Cure53 (business, 2020), ISO 27001 per vendor | Yes | Roughly 1.40 to 2.60 EUR per month |
| Bitwarden | USA | EU cloud region; self-hosting | Yes | Cure53 and ETH Zurich, SOC 2 | Yes, also free | Free; premium about 1.65 USD per month |
| 1Password | Canada | EU region (1password.eu, billed in EUR) | No | Third-party audits, SOC 2 per vendor | Yes | About 3.65 EUR per month, billed yearly |
| Keeper | USA | EU regions (Ireland, Frankfurt) | No | SOC 2, ISO 27001 per vendor | Yes | About 35 USD per year |
| Dashlane | USA / France | Not a main selling point; see vendor documentation | No | ISO 27001 per vendor | Yes | About 4 to 5 USD per month |
| KeePassXC | Community project | Your own device | Yes | Independent audit 2023, ANSSI certification | Yes, via extension | Free |
Provider by provider
Proton Pass (Switzerland)
Proton Pass is the most European of the mainstream choices. The company is Swiss, the clients are open source, and Proton published an audit by the security firm Cure53. The free plan includes unlimited logins and passkeys plus a handful of hide-my-email aliases; paid plans add the built-in authenticator, vault sharing and unlimited aliases. Weaknesses: the product is younger than rivals, and recovery depends on your Proton account, so set up the recovery phrase or file. Read the Proton Pass review.
NordPass (Lithuania)
NordPass comes from the Nord Security group, which was founded in Lithuania. It uses XChaCha20 encryption, supports passkeys and tends to be inexpensive on long plans. A European origin is a fair point in its favour, though the consumer apps have fewer published independent audits than Bitwarden or Proton. Check the current privacy policy for where processing takes place. See the NordPass review.
Bitwarden (EU region or self-hosted)
Bitwarden is US-based but arguably the best fit for people who want control without leaving the cloud: an EU data region, open-source code, a visible audit trail and the option to run your own server. See the Bitwarden review.
1Password, Keeper and Dashlane
1Password (Canadian) and Keeper (American) let you choose European hosting, which suits companies with data residency rules. Dashlane has French roots with a New York headquarters, so it sits in between. For all three, check where the company, rather than the server, sits legally.
KeePassXC (local)
KeePassXC is a community project with no provider at all. You hold the encrypted file, and you decide how to sync it. Read the KeePassXC review.
Smaller European options
A few smaller European projects exist, such as Passbolt, an open-source tool from Luxembourg aimed mainly at teams. We list only the providers above in our comparison tables, but it is worth looking at Passbolt if you want a self-hostable, team-focused system.
What European law adds in practice
For account data, billing details and some metadata, the General Data Protection Regulation applies to any provider that serves people in the EU, wherever it is based. A European company or an EU data region adds simpler contracts, a clearer supervisory authority and, for some organisations, a hard requirement that data stays in the EU. It does not change the cryptography. If a provider is compelled to hand over data, a zero-knowledge vault still arrives as ciphertext, and the master password stays with you.
There is also a limit to the argument. A manager can be European and still be weak on audits, recovery or export, and a non-European one can be excellent on all three. Treat origin as one criterion among the eight we use, not as a shortcut.
Questions to ask any provider
- Where is the company legally established, and which entity signs the contract?
- Where is encrypted vault data stored, and can you choose the region?
- Which independent audits are public, and how recent are they?
- What does recovery look like if you lose the master password?
- Can you export everything in an open format, and is there a plain-text warning?
- What happens to your data if the company is sold or closes?
Answers to these questions, from the privacy policy and security documentation, tell you more than a country flag does. If you want a broader introduction first, read how a password manager works.
Why encryption still beats geography
Imagine two managers with identical encryption, one in Zurich and one in Virginia. If both are zero knowledge, an attacker or authority who obtains the server data holds only ciphertext, and the only realistic way in is guessing the master password. The same two managers differ greatly if one uses weak key derivation or a short master password. That is why a long, unique master password, two-factor authentication and, ideally, a hardware key for the vault do more for you than any choice of country. Use geography as a tie-breaker, and use the audits and recovery rules to decide the rest.
Who should pick what
- You want a European company and a simple app: Proton Pass, or NordPass if price matters most.
- You need EU data residency but a mature team product: Bitwarden, 1Password or Keeper with an EU region.
- You want no provider at all: KeePassXC, or a self-hosted Bitwarden server.
- You are mainly worried about government access: prioritise zero knowledge, a long master password and a hardware security key for the vault, then jurisdiction.
For a broader view of how European identity and privacy rules fit together, see our piece on EUDI wallet privacy.
Providers in this comparison
Proton Pass
Origin: Switzerland
Visit websiteNordPass
Origin: Nord Security, Lithuania
Visit websiteBitwarden
Origin: USA, EU data region available
Visit website1Password
Origin: Canada
Visit websiteKeeper
Origin: USA
Visit websiteDashlane
Origin: USA / France
Visit websiteKeePassXC
Origin: Open-source community project
Visit website
Frequently asked questions
Is Proton Pass a European password manager?
Yes, Proton is based in Switzerland, and its servers are there too. Switzerland is not an EU member, but the European Commission recognises its data protection as adequate, so personal data can flow to it without extra safeguards.
Does a European provider protect me from US authorities?
It reduces some legal exposure, but the stronger protection is technical. With zero knowledge the provider holds only encrypted data and cannot hand over your passwords, whatever law applies. Metadata such as account details and login times may still be accessible.
Can a US or Canadian manager store my data in the EU?
Several can. Bitwarden offers an EU cloud region and self-hosting, 1Password offers a European account region billed in euros, and Keeper offers hosting in Ireland and Frankfurt. The company still has its headquarters outside the EU.
What is the most European option of all?
Keeping everything on your own devices with KeePassXC, or self-hosting an open-source server, removes the provider from the picture. The price is that you handle sync, backups and recovery yourself.
More in Reviews
1Password review 2026: security, features and price
1Password reviewed: Secret Key security, passkeys, EU account region, recovery rules, export and 2026 prices in euros. Who it suits and the alternatives.
2FAS Authenticator review: open source, no account
Review of 2FAS Auth, the free open-source authenticator from Poland: encrypted backup, export, browser extension, Apple Watch support, limits and who it suits.
Aegis Authenticator review: open-source 2FA for Android
Review of Aegis Authenticator: free GPL v3 2FA app for Android with an encrypted vault, automatic backups, export, audit log, limits and who should use it.
Best authenticator apps in 2026: 2FAS, Aegis, Ente Auth
The best authenticator apps for 2FA codes compared: 2FAS, Aegis and Ente Auth, with encrypted backup, export, open source, platforms and what to avoid.
Best free password managers in 2026: what you really get
Bitwarden, Proton Pass and KeePassXC offer genuinely usable free password managers, while Dashlane and 1Password no longer do. Limits and trade-offs explained.
Best hardware security keys 2026: YubiKey, Nitrokey, Token2
The best hardware security keys of 2026 compared: YubiKey 5, Security Key Series, Nitrokey 3, Token2 and Google Titan on passkeys, NFC, firmware and price.