Best European Alternatives to LastPass

Looking for a European alternative to LastPass? LastPass has suffered multiple security breaches and stores encrypted vaults on US servers.

European password managers offer better security practices with data stored in Europe and some offering self-hosting.

4 Alternatives
100% GDPR Compliant
How we rank these tools — 4-step process
  1. 1
    European ownership, verified

    The company is headquartered and incorporated in the EU, EEA or Switzerland, and processes customer data in Europe. A US parent company disqualifies a tool from this page regardless of where its servers are.

  2. 2
    Category fit and hands-on review

    What the tool actually does, who it suits, and where it falls short — checked against the vendor’s own documentation, changelog and pricing page rather than its marketing copy.

  3. 3
    Compliance and pricing check

    GDPR posture, hosting location and the prices quoted on this page are verified against the vendor’s public pricing before publication, and re-checked when we revisit the category.

  4. 4
    Position on this page

    Placement on this page can be paid, and that can affect which tools appear here and the order they appear in. It never buys a good review: a tool that fails the checks above is not here at any price, and payment does not change the shortcomings we write about. A vendor can ask us to correct a factual error — not to remove a criticism.

Vendors can pay for visibility on this page. It never changes what an entry says about a product, including the criticism, and we earn nothing when you click through to a vendor. Paid placement can affect which tools appear here and the order they appear in. Editorial policy

4 European Alternatives to LastPass

Proton Pass

Encrypted password manager from the Proton team

#1 for replacing LastPass
Switzerland

NordPass

Password manager with zero-knowledge architecture

#2 for replacing LastPass
Panama/EU

Passbolt

Open-source team password manager

#3 for replacing LastPass
Luxembourg

Heylogin

Passwordless authentication for teams

#4 for replacing LastPass
Germany

Key takeaways

  • The vault backups copied in 2022 cannot be recalled, so the only remaining defence on those accounts is the strength of the master password.
  • The encrypted fields held; the website URLs did not, which is why rotating passwords does not close the incident.
  • LastPass now documents PBKDF2-SHA256 at 600,000 iterations, so the widely repeated 100,100 figure describes 2022 and not today.
  • LastPass separated from GoTo in 2024, but LastPass US LP is still in Boston, so the jurisdiction did not change with the ownership.
  • heylogin is the only tool here with nothing to brute-force, because there is no master password in its design.

Why people leave LastPass

Nobody leaves LastPass over a feature. They leave because of one week in December 2022, when the company confirmed that attackers had copied backups of customer vault data from cloud storage after a developer's machine was compromised in August.

It is worth being exact about what that means, because both the panic and the reassurance are usually overstated. The sensitive fields — usernames, passwords, secure notes, form fill — were AES-256 encrypted and stayed that way. What was not encrypted was the metadata around them, including the website URLs, so whoever holds a copy knows every service each customer had an account with.

The structural problem is that the copy is permanent. You can change every password in the vault and you cannot un-copy the file, so the encrypted half is protected for as long as your master password holds out against offline guessing at whatever iteration count your account happened to be on at the time. That is not a risk you manage; it is a risk you either accept or leave behind.

  • A copy of your vault exists and always will This is the difference between the LastPass incident and an ordinary breach. Nothing you do now changes what an attacker already has, and the only variable left is how expensive your master password is to guess. Every alternative on this page is a way of changing that arithmetic: by not storing your vault with a third party at all, or by not having a master password to guess.
  • The URL list was never encrypted LastPass's own notice lists unencrypted fields alongside the encrypted ones, and website URLs are among them. That is a map of where each customer banks, which brokers they use and which internal systems their employer runs, and it is useful to a phishing operation without decrypting anything. Password rotation does nothing about it.
  • American company, no published European region LastPass US LP is in Boston, so the CLOUD Act reaches it regardless of where servers happen to sit. Its own security documentation describes vault data as held on servers in the cloud and names no region, and there is no European residency option advertised on any plan. Where 1Password lets you pick an EU region, here there is nothing to pick. The privacy policy does name LastPass Ireland Limited in Dublin as the controller for customers in the EEA, which settles who you contract with — it is not a place your vault is kept, and the same policy says data is processed in the United States and other countries.
  • The free plan is a single device type The free tier is restricted to one device type: computers or phones, not both. That has been the arrangement for years and it is still on the pricing page today. Proton Pass's free tier covers unlimited devices and heylogin runs a free tier as well, so for a household that never intended to pay, the gap is not subtle.

What you have to replace, not just match

Before shortlisting anything, separate the two problems the 2022 incident left you with, because different tools answer different ones.

The first is custody: your vault was held by a provider, backed up by that provider, and taken from that provider. The second is the master password, which is the single secret standing between a stolen copy and its contents.

Passbolt answers the first by letting you keep the server. heylogin answers the second by removing the master password from the design altogether. Proton Pass and NordPass answer neither structurally and instead offer the ordinary thing — a better-run provider in a better jurisdiction — which for most households is the honest, proportionate choice.

The alternatives compared

European LastPass alternatives, in the order this page ranks them, compared on headquarters, pricing and jurisdiction
PositionToolHeadquartersPricingJurisdiction
#1 Proton Pass Geneva, Switzerland Free tier / from about €1.99/month (Pass Plus) Switzerland (adequacy decision, outside the EEA)
#2 NordPass Vilnius, Lithuania Free tier / from about €1.49/month (Premium) EU (Lithuania)
#3 Passbolt Luxembourg City, Luxembourg Free Community Edition / from about €4/user/month (Pro) EU (Luxembourg)
#4 heylogin Hannover, Germany Free tier / from about €2.50/user/month (Business) EU (Germany)

How each alternative compares to LastPass

#1

Proton Pass

the easiest landing, and the one that fixes the URL problem

Geneva, SwitzerlandFree tier / from about €1.99/month (Pass Plus)#1 in Password Managers

  • Which law reaches it. Switzerland (adequacy decision, outside the EEA). LastPass is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Switzerland, Germany.
  • Source code. Open source, where LastPass is not: you can read what it does rather than take the description on trust.

Best for: Households and small teams replacing a personal LastPass vault

The company is Proton AG, a Geneva business that keeps its servers in Switzerland and Germany, so neither the corporate entity nor the ciphertext sits within reach of a United States order. For a straightforward move off LastPass it is the shortest path: importer, apps everywhere, free tier you can stay on indefinitely and across every device you own.

The interesting part against LastPass specifically is the aliases. The metadata taken in 2022 tied a real email address to a list of services, and that pairing is what makes the leak useful to whoever holds it. Proton Pass generates a unique forwarding address per service in the same step as the password, so the equivalent list would identify nothing beyond the aliases themselves.

It is a 2023 product and does not hide it. Business administration is thin next to LastPass Business, there is no emergency access, and the browser extension still misses fields on complicated sign-in flows. It is also, like LastPass, a hosted service that holds your encrypted vault, so it changes the provider rather than removing one.

What Proton Pass does better than LastPass

  • Swiss company and Swiss or German storage, where LastPass is a Boston entity within CLOUD Act reach
  • A free tier that works across all your devices, not one device type
  • Open source and independently audited clients, where LastPass publishes no source
  • Email aliases, so the service-to-address mapping that leaked in 2022 would not exist to leak
  • No comparable breach history for the vault product

Where Proton Pass is a step down from LastPass

  • Still a hosted vault at a third party, so the custody question is moved rather than answered
  • Enterprise policy and reporting are lighter than LastPass Business
  • No emergency access, which LastPass has offered for years
  • Launched 2023, so autofill on awkward sites is less dependable than LastPass's

Standout against LastPass. It is the only option here that would have made the leaked URL-and-address pairing worthless, because the address in it would have been disposable.

proton.me/pass Visit Proton Pass
#2

NordPass

the cheapest like-for-like move, with one caveat worth reading

Vilnius, LithuaniaFree tier / from about €1.49/month (Premium)#2 in Password Managers

  • Which law reaches it. EU (Lithuania). LastPass is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Europe.
  • Source code. Closed source, as LastPass is.
  • Independently checked. Independently audited, zero-knowledge.

Best for: People who want the same product for less and are not rebuilding their threat model

NordPass is built by Nord Security in Vilnius, so the company is EU-established and processing is intra-EEA with no transfer question to answer. At about €1.49 a month for Premium it is the cheapest paid tier in this comparison, and the apps are the most polished of the four for someone who simply wants what LastPass did without the history.

The one technical departure worth knowing is the cipher. NordPass encrypts with XChaCha20 instead of the AES-256 that LastPass uses, a choice that pays off on handsets with no dedicated AES instructions and whose nonce length removes reuse as a practical worry. Encryption and decryption happen on your device and only ciphertext reaches the servers, which is the same zero-knowledge claim LastPass makes and, in 2022, largely held.

The caveat NordPass states itself is that its infrastructure runs on AWS. That does not undo zero-knowledge — Amazon holds material it cannot read — but if your reason for leaving LastPass was that an American company was holding your vault, you should know the servers are still American-operated even though the company is not. It is also closed source, so the implementation is audited rather than readable.

What NordPass does better than LastPass

  • Lithuanian company under EU jurisdiction, where LastPass US LP answers to United States orders
  • About €1.49 a month for Premium, below LastPass Premium
  • XChaCha20 in place of the AES-256 LastPass uses, which suits phones without AES hardware
  • Independently audited zero-knowledge design with no comparable incident record

Where NordPass is a step down from LastPass

  • Runs on AWS by the company's own account, so the hosting is American even though the company is not
  • Closed source, so the client that handles your key cannot be inspected
  • Team and enterprise features are thinner than LastPass Business
  • Access on multiple devices is a Premium feature, so the free plan is tighter than LastPass's one-device-type tier
  • Changes the provider without changing the structure that failed in 2022

Standout against LastPass. It is the only tool here that is cheaper, tidier and requires no change in how you work — which is exactly why its AWS footnote deserves reading before you decide.

nordpass.com Visit NordPass
#3

Passbolt

the one where there is no provider backup to steal

Luxembourg City, LuxembourgFree Community Edition / from about €4/user/month (Pro)#4 in Password Managers

  • Which law reaches it. EU (Luxembourg). LastPass is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. EU cloud, or self-hosted anywhere.
  • Source code. Open source, where LastPass is not: you can read what it does rather than take the description on trust.

Best for: Organisations whose conclusion from 2022 was that nobody else should hold the vault

Behind Passbolt is a Luxembourg company, Passbolt SA, and its free Community Edition carries an AGPL v3 licence with no cap on seats; you put it on a Linux box of your own, by hand or through the published Docker and Kubernetes recipes. What failed at LastPass was a provider's cloud backup being reached through a compromised provider employee. Remove the provider and that path does not exist.

Sharing works on a stricter model than LastPass folders do. A secret handed to five colleagues is wrapped five times, once against each OpenPGP public key, which means the administrator who granted the access cannot read it and neither can anyone holding the database on your own machine. Around that sit permission roles, folder hierarchies, a log of who did what and an automation API — the accountability half that LastPass leaves to good faith.

It asks more of you in return. GPG keys are an obstacle for non-technical staff, the mobile apps trail the browser extension, individual use is explicitly not the target, and the backups that LastPass was taking for you are now yours to take, test and store. A self-hosted vault nobody backs up is worse than a hosted one that gets breached.

What Passbolt does better than LastPass

  • Self-hosted under AGPL v3, so no third party holds a backup of your vault at all
  • Per-recipient OpenPGP encryption, where LastPass shared folders rely on the provider's access control
  • Published source and published audits, against a closed-source product with a disclosed incident
  • Free with no seat limit on the Community Edition, where LastPass bills per user
  • An activity log and role-based access control that make offboarding a procedure rather than a memory exercise

Where Passbolt is a step down from LastPass

  • Not built for individuals or families, which LastPass handles perfectly well
  • You now own the backups, patching and uptime that LastPass owned for you
  • GPG key handling is a genuine barrier for non-technical users
  • Mobile apps are behind LastPass's on both platforms

Standout against LastPass. It is the only option here that removes the thing that was actually stolen in 2022: a provider's backup of everybody's vault, in one place.

passbolt.com Visit Passbolt
#4

heylogin

the one with no master password to grind against

Hannover, GermanyFree tier / from about €2.50/user/month (Business)#5 in Password Managers

  • Which law reaches it. EU (Germany). LastPass is run from the United States, so the CLOUD Act obliges the provider to hand over data on a valid order regardless of which country the servers are in.
  • Where the data sits. Germany.
  • Source code. Closed source, as LastPass is.
  • Independently checked. End-to-end encrypted.

Best for: Teams whose worry is that the stolen copies will eventually be opened

heylogin GmbH is in Hannover, hosts with EU cloud providers and is ISO 27001 certified. Its design point is the one that matters most to a LastPass refugee: there is no master password. Your smartphone is the key, and a login is approved with a fingerprint, a face or a PIN.

Follow that through against 2022 and the difference is stark. The lasting damage there is that a copied vault can be attacked offline, forever, by guessing one memorised secret. Where no such secret exists, there is nothing to guess — no phrase to phish, no reuse from another service, and no account quietly sitting on parameters chosen years ago.

The failure mode moves rather than vanishing, and heylogin is straightforward about it. The phone becomes critical, so registering a second device is not optional, and the product is closed source, so the encryption must be trusted rather than read. It is also a smaller product than LastPass Business in features and in company size.

What heylogin does better than LastPass

  • No master password exists, so a stolen vault copy has no memorised secret to attack offline
  • Nothing for a phishing page to capture, because there is no master password to type
  • German company with EU hosting, against a Boston entity with no published European region
  • ISO 27001 certified, where LastPass carries a disclosed incident rather than a comparable certificate
  • A free tier to stay on, with business plans from about €2.50 per user per month

Where heylogin is a step down from LastPass

  • Losing the phone is a bigger event than forgetting a LastPass master password would be
  • Closed source, so the implementation cannot be independently read
  • A smaller feature set than LastPass Business, especially on policies and reporting
  • The mobile-first approval flow does not suit people who work from shared or locked-down machines

Standout against LastPass. Of everything listed here it alone retires the 2022 question instead of shrinking it, because no memorised secret stands behind the ciphertext to be guessed at.

heylogin.com Visit heylogin

What actually breaks when you switch

The export is a plain-text CSV and people leave it in Downloads. Put it on an encrypted disk, import it, verify a handful of entries by actually signing in, then delete it and empty the bin. This is the single most common way a careful migration creates a worse exposure than the one it was fleeing.

Shared folders do not come with you. In LastPass they belong to whoever created them, so your own export contains what you own and nothing else. Ask each owner to export separately before anyone cancels, because a departed colleague's shared folder is unrecoverable once the account lapses.

And sequence the master-password reset. Everyone moving needs a new secret on the new manager while the old one still works, and autofill will misbehave for a week on sites where both extensions are installed. Run the two side by side for a fortnight, then remove the LastPass extension deliberately rather than letting people decide individually.

If my vault was copied in 2022, is changing passwords enough?

It protects the accounts themselves and it does not undo the exposure. Rotating every credential means a decrypted copy of the old vault yields dead passwords, which is the main thing, and it is worth doing before anything else.

What rotation cannot touch is the unencrypted metadata. The URL list in that backup still describes which services you hold accounts with, and that remains accurate however many times you change the passwords behind it. Treat targeted phishing that names your actual bank and your actual payroll provider as a live possibility rather than a generic warning.

The other thing rotation cannot fix is the master password, because the copied file is decrypted with a key derived from it. If your master password was short, reused, or set years ago when your account was on a lower iteration count, the sensible reading is that the vault will eventually open, and moving is the only response that matters.

Has LastPass fixed the encryption since then?

It has raised the cost of guessing substantially. LastPass documents PBKDF2-SHA256 with 600,000 iterations for deriving the key from the master password, which is above the current OWASP recommendation and roughly six times the 100,100 it was running when the backups were taken.

That matters for vaults going forward and it does not retroactively protect the copies already in circulation, which were made under the old parameters. This is the part most write-ups get wrong in one direction or the other: the current product is not weakly hashed, and the 2022 copies are not protected by that improvement.

So if you are asking whether LastPass is badly engineered today, the answer is no. If you are asking whether your particular vault is still exposed, the answer depends entirely on what your account looked like in December 2022.

Does any of these stop the same thing happening again?

Only one changes the structure. Passbolt self-hosted means there is no provider holding a backup of your vault, so the specific failure — a third party's cloud storage being read by someone who compromised a third party's engineer — has no equivalent. The failure it substitutes is your own backup hygiene, which is a risk you can at least see.

heylogin changes a different variable. With no master password, a stolen copy of encrypted material has no memorable secret behind it to grind against; the key sits on a phone protected by a fingerprint or face. The trade is that losing the phone matters much more, so a second device is not optional.

Proton Pass and NordPass are conventional zero-knowledge managers hosted by a European company. They are better-run and better-situated than LastPass, and if one of them were breached the same way, you would be in the same position. That is a fair trade for most people; it is not a structural fix and this page will not call it one.

Does leaving cost more than staying?

Usually less. NordPass Premium is about €1.49 a month and Proton Pass Plus about €1.99, both of which undercut LastPass Premium. The free tiers are not equivalent, though: Proton Pass Free covers unlimited devices, while NordPass keeps access on multiple devices for Premium — so of the two it is Proton Pass, not NordPass, that actually removes the restriction you are leaving.

For a business the comparison is closer and turns on what you need. Passbolt Pro is about €4 per user per month with a free Community Edition underneath it, and heylogin Business from about €2.50 per user per month, against LastPass Teams and Business tiers billed annually per seat.

The cost that is real and rarely counted is the master-password reset for everyone. Moving a family or a team means each person creating a new secret and each person's autofill breaking for a week, and that is where these migrations stall rather than in the export file.

Which one to pick

If the vault you held in December 2022 still contains passwords you have not rotated, stop reading comparison pages and rotate them, starting with email. The choice of replacement is the second decision, not the first.

For a household or a small team, Proton Pass is the move: Swiss, open source, a free tier that works on everything you own, and aliases that break the address-to-service link that leaked. NordPass is the cheaper option and just as sensible, provided you have read what it says about running on AWS.

If your conclusion from 2022 was that a provider should not be holding everyone's vault in one place, a self-hosted Passbolt is the one option here that acts on it, and it acts on it properly — provided somebody takes ownership of the backups that become yours.

And if your conclusion was that a memorised master password is the thing that will eventually fail, heylogin removes it instead of hardening it. That is a more radical answer than any iteration count, and for a team it is easier to roll out than it sounds.

Frequently Asked Questions

Proton Pass for a personal or family vault, because the free tier is not device-limited and the email aliases address the half of a credential LastPass never touched. NordPass if you want the cheapest polished consumer option. Passbolt if the lesson you took from 2022 is that no provider should be holding your vault. heylogin if the lesson you took is that the master password is the weak link.

It was serious in a specific way. The sensitive fields in the copied backups were AES-256 encrypted and there is no evidence that encryption failed; the unencrypted metadata, including website URLs, was taken in the clear. So it is not true that passwords were stolen in readable form, and it is true that an attacker holds a permanent copy which only your master password protects and a full list of the services you use.

No, and the figure gets repeated long past its expiry date. LastPass documents PBKDF2-SHA256 with 600,000 iterations today, which is above the OWASP recommendation. The 100,100 figure belongs to the 2022 incident, and matters because it describes the parameters the copied vaults were protected by, not the parameters new ones are.

No. LastPass formally separated from GoTo in 2024 and now operates as an independent company. The point worth noting is that the jurisdiction did not change with the ownership: LastPass US LP remains a United States entity in Boston, so the CLOUD Act applies exactly as it did before.

Nothing published says so. The zero-knowledge documentation describes vault data as held on servers in the cloud without naming a region, no European residency option appears on any plan, and the privacy policy says data is transferred to and processed in the United States and other countries.

LastPass Ireland Limited is named there as the controller for EEA customers, but that is a contracting entity rather than a storage region. That is a plainer position than 1Password, which lets you choose a European region when the account is created.

Free accounts work on one device type only, computers or mobile devices, so a laptop and a phone cannot both be active on the same free account. The pricing page still states it. It is the single most common reason people on the free tier start looking, and it is the difference that Proton Pass and heylogin remove rather than reduce.

The browser extension and the web vault both export to CSV after re-entering the master password. Two warnings: the file is plain text, so it belongs on an encrypted disk and in the bin the moment the import is verified, and shared folders belong to whoever created them, so ask each owner to export their own rather than assuming your export contains them.

Yes, if your vault existed in 2022, and in an order rather than all at once. Email first, because it is the reset path for everything else, then anything with money attached, then anything where the same password was reused. Anything else can be rotated as you encounter it. Doing all six hundred in one evening is how people lock themselves out of something that matters.

Yes, and the 2022 incident is not an argument against the category. The realistic alternative is reused passwords across dozens of services, which fails more often and more quietly than any manager has. What the incident is an argument about is where the vault lives and what protects it, which is why the options on this page split between hosting it yourself and removing the master password.

Who worked on this review

Three people touch every comparison page: one writes it, a second edits it, and a third checks the compliance and pricing claims against the vendor's own documentation.

Daniel Brandt
Written by

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.

Marta Kowalczyk
Edited by

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Ingrid Halvorsen
Fact-checked by

Ingrid Halvorsen

Managing Editor · Oslo, Norway

Runs the review process and decides when a page is ready to publish or needs another pass.

Read our editorial process for how we source, verify and update these pages — and how we keep affiliate income separate from what we recommend.

Explore More European Alternatives

Discover privacy-focused European alternatives to other popular US tech services.

More Password Managers Browse All Categories