How to Tell If Your Web Host Is GDPR-Compliant
A server in Europe does not make your hosting GDPR-compliant by itself. Seven questions and three documents separate hosts that can back the claim from hosts that just put it on the homepage.
- What a server in the Netherlands does solve
- Three documents to ask for
- Email and backups get forgotten
- Seven questions to put to a sales team
"GDPR-compliant hosting" is usually sold as a map. Put the site on a server in Frankfurt or Amsterdam, the pitch goes, and the regulation is taken care of. The regulation says nothing of the sort. The GDPR is barely interested in server coordinates; it regulates processing, and it holds you responsible for every company that processes personal data on your behalf. Your host is the first name on that list.
So the location claim is neither necessary nor sufficient. A host with every rack inside the EU can still be a liability if it can't produce the contracts described below, while a host that runs, say, its status page through a US provider is workable as long as that one transfer has its paperwork.
What a server in the Netherlands does solve#
Moving personal data out of the European Economic Area is perfectly legal under the GDPR, provided each transfer has a documented basis: an adequacy decision for the destination country, Standard Contractual Clauses, or another recognised safeguard. Every border crossing is one more mechanism you have to document and stand behind when a customer or a regulator asks.
Data that never leaves the EEA needs none of that. This is the honest argument for EU hosting: it shortens the list of things you have to prove. A lawful basis for processing and a privacy policy are still yours to sort out; those duties never transfer to the host.
Maxinodes keeps customer sites and databases in data centres in the Netherlands. The sites and their backups stay under EU jurisdiction for their whole life on the platform.
Three documents to ask for#
In GDPR terms you are the data controller and your host is a data processor. Article 28 wants that relationship in a contract, and in practice you should see three things before you pay.
Start with the Data Processing Agreement. The DPA records what the host may do with personal data and the security it owes you, down to what happens to the data when you cancel. No DPA means the host has no legal place in your processing chain, whatever its homepage claims. Ours is a standard document on every plan; read it before you sign up.
Then the sub-processor list. Hosts lean on other companies for things like backup storage and monitoring, and any of those companies may touch personal data. You are entitled to know who they are and where they operate, so the list should be public and reasonably current. Ours is here.
The last piece is a safeguard for anything that does sit outside the EEA. If a sub-processor operates from the US, say, the host should be able to name the mechanism covering the transfer — usually SCCs — without checking with legal first.
While you're at it, spend ten minutes with the host's own privacy policy; it tells you a fair amount about how they'll end up treating your customers' data too.
Email and backups get forgotten#
Mailboxes rarely run on the web server. If your addresses live on Microsoft 365 or Google Workspace (we resell both), keep in mind that EU data residency is available on both platforms but usually has to be selected during setup. Confirm where your mailboxes were provisioned rather than assuming the tenant defaulted to Europe.
Backups are the other blind spot. A nightly copy of your database written to storage on another continent is a transfer in its own right, even while the live site never leaves the Netherlands. The same logic applies to DNS and monitoring. Ask where each piece runs and how long backup copies are retained.
Seven questions to put to a sales team#
These take one email to send, and they sort providers quickly.
- In which country do the servers physically run?
- Where are backups stored, and how long are they retained?
- Do I get a GDPR-compliant DPA on a regular plan, or only after an enterprise upgrade?
- Is the sub-processor list published, and when was it last updated?
- Which sub-processors operate outside the EEA, and under what safeguard?
- If email is part of the package, in which region are the mailboxes provisioned?
- Who do I write to about a data request or an incident, and how quickly do they reply?
A well-run host can answer all seven from memory. Take evasive answers seriously. A provider that cannot say where its backups sit leaves that gap in your records, and it tends to surface when a customer files an access request or a regulator asks about transfers.
Our own answers are in the documents linked above, and support fills in the rest. The managed plans page shows what is handled for you, and anything specific to your setup can go through the contact form.