The sentence this market gets wrong
The claim is almost never written down plainly, which is how it survives. It arrives as an implication: the servers are offshore, the company is offshore, therefore the European rules are somewhere behind you. Read the regulation and the implication collapses in one sentence.
Article 3 sets out who the GDPR applies to and it never once mentions where the hardware is. Paragraph 1 says the regulation applies to processing by a controller or processor established in the Union regardless of whether the processing takes place in the Union or not. Paragraph 2 reaches the other way: a company with no establishment in the Union at all is still covered where it offers goods or services to people in the Union, or monitors their behaviour there.
This is not a disappointment, and it is worth saying why before anything else. The reason to move a server is that a court in one country cannot order a disk in another. That reason is untouched. What travels with the machine is a compliance obligation, not a legal exposure, and the two are confused constantly because both get described with the word “jurisdiction”.
Which of you the regulation is talking to
Two roles, defined in Article 4, separated by a single question: who decided what the data was for.
| The role | Who it is when you rent a server | What it answers for |
|---|---|---|
| Controller, Article 4(7) | You. You chose to collect the data and chose what it is for | Every obligation in the regulation, including the ones you delegate |
| Processor, Article 4(8) | The hosting company. It holds the data because you put it there | Acting only on your instructions, securing what it holds, and Article 28 |
Almost every argument about hosting and the GDPR is really an argument about that table. A provider cannot be compliant on your behalf, because the majority of the duties are the controller’s and cannot be contracted away. What a provider can be is a processor you are able to defend having chosen, which is Article 28 — a document rather than a feeling.
Article 28(3) lists what that contract has to contain and the list is short enough to check against your own. Process only on documented instructions. Bind everyone with access to confidentiality. Take the Article 32 security measures. Add no sub-processor without permission. Help you answer data subjects. Help you with breaches and assessments. Delete or return everything at the end. Give you what you need to verify all of it.
What counts as a transfer
Chapter V — Articles 44 to 49 — governs sending personal data to a third country. A third country means anywhere outside the European Economic Area, which is the twenty-seven member states plus Iceland, Liechtenstein and Norway. The GDPR was taken into the EEA Agreement in 2018, which is why those three are inside the line rather than merely near it.
Article 44 states the principle: a transfer may take place only if the rest of the chapter is satisfied. There are then three routes, in descending order of how easy they are to live with.
| The route | What it requires | Where it applies |
|---|---|---|
| An adequacy decision, Article 45 | Nothing further. The Commission has found the country’s protection essentially equivalent, and the transfer proceeds like a domestic one | A published list of about fifteen countries and territories |
| Appropriate safeguards, Article 46 | A recognised instrument — in practice the standard contractual clauses — plus an assessment of whether the destination undermines it | Everywhere with no adequacy decision |
| A derogation, Article 49 | Explicit consent, or necessity for a contract, and only occasionally | The exception. Not an architecture |
The last row is where improvised compliance usually ends up and it does not hold. Article 49 is written for the occasional and the specific. Hosting a customer database on a server for three years is neither of those things.
The eight regions, sorted by what Chapter V calls them
This is the part a hosting company can answer and a legal blog cannot, because it is a fact about a specific estate rather than a general principle. The eight regions on this network fall into three groups, and the distance between the first group and the last is two documents.
| Region | What Chapter V calls it | What you need |
|---|---|---|
| Reykjavík, Iceland | Inside the EEA | Nothing under Chapter V. An Article 28 processor contract, exactly as for a rack in Frankfurt |
| Amsterdam, Netherlands | EU member state | Nothing under Chapter V |
| Bucharest, Romania | EU member state | Nothing under Chapter V |
| Sofia, Bulgaria | EU member state | Nothing under Chapter V |
| Zurich, Switzerland | Third country with an adequacy decision | Article 45. Record the transfer and add no instrument. Switzerland has held a decision since 2000 and it was renewed in January 2024 |
| Chișinău, Moldova | Third country, no adequacy decision | Article 46. Standard contractual clauses, plus an assessment of the destination |
| Panama City, Panama | Third country, no adequacy decision | Article 46, the same. Panama has its own statute, Law 81 of 2019, but a national statute is not a Commission decision |
| Singapore | Third country, no adequacy decision | Article 46, the same |
Four of the eight are not transfers at all. That is worth more than most of what is published about offshore hosting and compliance, and it is a sentence nobody selling either one has an interest in saying, because it makes the difficult product unnecessary for half the estate.
The half of the question that is not about the rack
Where the disk sits decides whether there is a transfer. Which company you signed with decides who is holding it, and those two come apart more often than they should.
A provider with racks in Frankfurt and a parent company in California is exporting your data whether or not anything crosses a cable, because the processor is subject to a jurisdiction that can reach it. That is not a hypothetical distinction. It is the reason the corporate structure of a host is a data protection fact rather than a trivia question.
The arrangement here is eight jurisdictions and eight separate companies, set out in clause 1 of the terms. A server in Reykjavík is contracted with the Icelandic entity, which is inside the EEA, which is why the first row of the table above says what it says. If you are reading somebody else’s page, that is the question to put to it: not where is the server, but which company is on the invoice and where is that company.
What Article 46 actually asks of you
If you use one of the three third countries, the work is real but it is bounded, and it has not changed much since 2021.
- Write the transfer down. Which categories of personal data, about whom, to which entity, in which country, and in what form it arrives — readable, or encrypted under a key you kept.
- Put the instrument in place. In practice that means the standard contractual clauses the Commission adopted in June 2021, in the module that matches the relationship. Controller to processor is Module Two, which is what renting a server is.
- Assess the destination. Since the Court of Justice decided Schrems II in July 2020, signing the clauses is not the end of it: you have to look at whether the law where the data lands lets a public authority reach it in a way the clauses cannot survive. The European Data Protection Board published the method in 2021 and it runs to six steps.
- Add whatever closes the gap the assessment found, which is the next section, because there is really only one measure that closes it.
- Put a date on it. The assessment is about a country’s law and a country’s law changes without telling you. Once is not compliance; a review interval is.
The measure that actually closes the gap
The supplementary measures the Board describes are mostly disappointing on close reading. Contractual and organisational ones do not stop a state that has the power to compel, and the Board says so plainly. One technical measure survives the analysis, and it is the same one recommended everywhere else on this site for reasons that have nothing to do with the GDPR.
If the data lands encrypted under a key that never leaves your control, the processor holding it cannot produce anything legible to anyone — not to a court, not to you, not to itself. The Board’s recommendations treat strong encryption with a key retained by the exporter as effective for stored data, and treat a processor that needs the data in the clear as a case where no measure is identified. Which is the honest position: you cannot contract your way out of somebody being able to read a disk.
The distinction that matters in practice is between storage and processing. An object store holding encrypted archives is the easy case. A running database on a virtual machine is the hard one, because the key has to be in memory on hardware somebody else can touch. What your provider can still read works through exactly where that line falls, and it does not end with a reassurance.
Article 48, which points the other way
Chapter V contains one article that is rarely quoted in this market and deserves to be. Article 48 says that a judgment of a court, or a decision of an administrative authority, of a third country requiring a controller or processor to disclose personal data may be recognised or enforceable only where it is based on an international agreement — a mutual legal assistance treaty, in practice.
Read as an instruction to a host, that says something specific: an order arriving from a country with no jurisdiction is not, in European law, a reason to hand anything over. A provider that complies with it anyway is not being careful. It is making an unlawful transfer and calling it cooperation.
This estate arrives at the same answer from the other direction, and has since 2019, which is checkable rather than assertable: 164 law-enforcement requests, 31 of which produced something, no gagged order in twenty-nine published quarters, and what was produced was an email address and a ledger of amounts. The law-enforcement guide states the bar in one line: an order from a court with jurisdiction over the entity that was served.
What does not change, wherever the machine is
This is the section that costs a sale, so it is the one worth reading twice. Each of the following is yours as controller, and no hosting decision touches any of them.
| The obligation | What it means on a rented server | Changed by hosting abroad |
|---|---|---|
| A record of processing, Article 30 | A written inventory of what you process, why, for how long, and who receives it | No |
| Security appropriate to the risk, Article 32 | Encryption and pseudonymisation are named in the article itself | No |
| Breach notification, Article 33 | Seventy-two hours to your supervisory authority from the moment you are aware | No |
| A data protection impact assessment, Article 35 | Required where the processing is likely to be high risk | No |
| A representative in the Union, Article 27 | For a controller outside the EU that Article 3(2) still catches | No |
| Answering data subjects, Articles 12 to 22 | Access, rectification, erasure, portability and objection, on a one-month clock | No |
Six rows, one answer. The word keeping this confusing is “jurisdiction”, which is doing two jobs at once: it is the answer to who can compel the disk, and it is the answer to whose rules you follow. Moving a server changes the first and leaves the second precisely where it was.
What a border does change
- Who has to be persuaded. An order has to come from a court with jurisdiction over the company holding the disk, and eight companies in eight countries is eight separate arguments rather than one.
- Whether a notice has any force. A takedown notice is correspondence everywhere; in some places it is correspondence a host is obliged to act on, and offshore means it is not. That is the subject of the DMCA guide.
- What the host can be made to keep. Retention mandates are national. Romania struck its own down twice and nothing replaced it; Moldova and Panama impose none. What a provider cannot be compelled to retain, it cannot be compelled to produce.
- Whether the transfer needs an instrument. Which is this page — and which is a paperwork cost rather than a risk.
What it does not change
- Whether the GDPR applies to you. Article 3, decided by where you are established and whose data you hold.
- Any obligation in the table above. Records, security, breach notification, assessments, data subject rights.
- Your own logs. The machine you rent writes visitors down under your configuration, in your custody, and it is you somebody writes to about it — which is a separate guide because it is a separate problem.
- Whether you can be reached. If you are established in the Union, your supervisory authority has no need to reach the server. It needs to reach you.
An afternoon that settles the question
Nothing below needs a tool you have to buy, and the whole sequence is shorter than the market implies.
- Decide whether you process personal data of people in the Union at all. If the honest answer is no — and for a great many projects it is — everything above is background reading and you are finished.
- Write down which entity you contract with for each region you use, and which country that entity is in. Not the region: the company on the invoice.
- Sort those into the three groups in the table. Inside the EEA, adequate, neither.
- For anything in the third group, put the 2021 clauses in place and write the destination assessment. Two documents, once, per country.
- Look at what actually lands there. If the answer is an encrypted archive whose key is on your own hardware, say so in the assessment, because that is the fact which makes the rest of it straightforward.
- Fold all of it into your Article 30 record, which is the document a supervisory authority asks for first and the one most controllers write last.
- Put a review date on the assessment and leave it where the next person to touch this will find it.
That is the entire exercise, and it does not conflict with anything else on this site — which is the sentence this guide exists to make available. Choosing a jurisdiction that protects your data and following the rules that protect your users are not opposite decisions. They are the same decision read from its two ends.
Questions people actually ask
Does the GDPR still apply if my server is outside the EU?
Yes, if it applied before. Article 3 attaches the regulation to the controller and to the data subjects rather than to the hardware: processing by a controller established in the Union is covered wherever the processing happens, and a controller outside the Union is covered when it offers goods or services to people in the Union or monitors their behaviour. Moving the machine changes who can compel the disk. It does not change who the rules are addressed to.
Is offshore hosting GDPR-compliant?
The question is not quite well formed, because compliance is a property of a controller rather than of a rack. What is true is that hosting outside the European Economic Area is lawful and always has been, on the conditions set out in Chapter V: an adequacy decision, or appropriate safeguards, or a narrow derogation. Four of the eight regions here are inside the EEA and raise no Chapter V question at all.
Is hosting in Iceland a transfer outside the EU?
It is outside the European Union and inside the European Economic Area, and the EEA is the line Chapter V draws. The GDPR was taken into the EEA Agreement in 2018 and Iceland applies it. A transfer to an Icelandic entity is treated like a transfer to a German one, so it needs an Article 28 processor contract and nothing from Chapter V.
Do I need standard contractual clauses with my hosting provider?
Only where the entity you contract with sits in a third country without an adequacy decision. On this estate that means Moldova, Panama and Singapore; it does not mean Iceland, the Netherlands, Romania, Bulgaria or Switzerland. Where they are needed, the instrument is the set the Commission adopted in June 2021, in the controller-to-processor module.
Is Switzerland still adequate for data transfers?
Yes. Switzerland has held an adequacy decision since 2000, and the Commission renewed it in January 2024 along with the other decisions taken under the old directive. A transfer to a Swiss entity proceeds on the decision alone: record it, and add no clauses.
Does encrypting the disk solve the transfer problem?
It closes the gap the assessment is looking for, in the case where the provider genuinely cannot read what it holds. The European Data Protection Board treats strong encryption with a key retained by the exporter as an effective measure for stored data, and treats a processor that needs the data in the clear as a case where no measure works. So an encrypted archive is the easy case and a running database is not, because a live key sits in the memory of a machine somebody else can touch.
Can a foreign court order my host to hand over EU personal data?
It can send the order. Article 48 says a third-country judgment or administrative decision requiring disclosure is recognisable or enforceable in the Union only where it rests on an international agreement, such as a mutual legal assistance treaty. A provider that complies without one is making an unlawful transfer. The published position here is the same answer from the other direction: an order from a court with jurisdiction over the entity served, or nothing.
Does no-KYC hosting conflict with data protection law?
It runs with it rather than against it. Article 5 requires data minimisation — adequate, relevant and limited to what is necessary — and a provider that never collects identity documents is holding none to lose, disclose or have breached. Identity verification duties come from financial regulation and bind payment institutions, not hosting companies. Your own duties as a controller are untouched either way.
Who is the controller and who is the processor on a VPS?
You are the controller and the provider is the processor, in very nearly every case. You decided what the data is for; the provider holds it because you put it there. That stays true on an unmanaged machine where nobody at the provider ever reads anything, which is why the Article 28 contract is required regardless of how little the provider touches.
Do I need a representative in the European Union?
If you have no establishment in the Union but Article 3(2) catches you anyway — you sell to people there, or you monitor them — then Article 27 says yes, in writing, in one of the member states where your data subjects are. The exemptions are narrow: occasional processing, unlikely to be risky, no large-scale special category data. Your hosting choice has no bearing on it in either direction.
Every price on this estate is published in full, in one place. See the whole catalogue

