GDPR · Hosting guide
GDPR-compliant hosting, explained by the processor that signs the agreement.
When a host stores your website, its database and your mailboxes, it processes personal data on your behalf. The GDPR has specific rules for that: a processor agreement, security, breach notification and where the data may go. Here is what they ask of you, a checklist for your website, and exactly what we sign.
General information, not legal advice.
The short version
No host can make your website GDPR-compliant.
Hosting in the EU helps with one part of the GDPR — where the data is and who can reach it — and a good host gives you the contract and the security the law expects of a processor. But the forms on your site, the plugins you install, the analytics and embeds you add, your cookie banner, your privacy statement and the reason you collect data at all are your decisions. As the controller you stay responsible for them, whoever hosts the site.
That is also how our own Data Processing Agreement divides the work: we are the processor for what you host, you are the controller.
What the GDPR asks
Six rules that apply the moment a host holds your data.
Article numbers refer to the General Data Protection Regulation (EU) 2016/679. In the Netherlands it is known as the AVG, and the supervisory authority is the Autoriteit Persoonsgegevens (AP).
Controller and processor
The controller decides why and how personal data is processed — for your website, that is you. The processor processes it on your behalf: your web host. The EDPB stresses that these roles follow from what each party actually does, not from what a contract calls them. And the AP is clear that the controller stays responsible for processing it outsources.
A processor agreement
You may only use a processor that gives sufficient guarantees, and the processing must be governed by a contract — a DPA, or verwerkersovereenkomst — in writing, which may be electronic (Art. 28(9)). The AP points out that without one, both parties are in breach.
Sub-processors
A processor may not bring in another processor without your prior specific or general written authorisation. Under a general authorisation it must tell you about intended changes so you can object, it must pass the same data-protection obligations down, and it remains fully liable to you for the sub-processor.
Security of processing
Controller and processor must both take measures appropriate to the risk, including as appropriate: encryption, ongoing confidentiality, integrity and availability, the ability to restore data in a timely manner after an incident, and a process for regularly testing those measures.
Breach notification
The controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach — unless it is unlikely to result in a risk to people. The processor notifies the controller without undue delay. A high-risk breach must also be communicated to the people affected, and every breach is documented (Art. 33(5)).
Transfers outside the EEA
Personal data may only go to a country outside the EEA under Chapter V: an adequacy decision of the European Commission (Art. 45), appropriate safeguards such as the Commission’s standard contractual clauses (Art. 46(2)(c)), or a narrow derogation (Art. 49). The rules cover onward transfers too.
Art. 28(3)
What a processor agreement must say.
It describes the subject-matter and duration of the processing, its nature and purpose, the type of personal data, the categories of people concerned, and your rights and obligations as controller. Then it binds the processor to eight things.
Reading a host’s DPA, check each of these is actually there — and that it names its sub-processors and where they process.
- Process only on your documented instructions, including on transfers outside the EEA.
- Bind everyone who handles the data to confidentiality.
- Take the security measures Art. 32 requires.
- Follow the sub-processor rules of Art. 28(2) and (4).
- Help you answer requests from data subjects.
- Help you with security, breach notification and impact assessments (Art. 32–36).
- At your choice, delete or return the data when the service ends.
- Give you the information to show compliance, and allow and contribute to audits.
EU servers, EU owner
Why the owner of the host matters, not only the datacentre.
The US CLOUD Act lets US authorities order providers of electronic communication and remote computing services to disclose data in their possession, custody or control, whether that data is stored inside or outside the United States. The EDPB and the EDPS assessed its impact on EU data protection law in a joint response to the European Parliament in 2019.
That is why procurement questionnaires ask not only where the servers are, but who runs them and which companies sit in the chain. It is a question to put to any host — including us. Our answer is in the next section.
Checklist
A GDPR checklist for a small business website.
Fifteen things to check, whoever hosts your site. The first seven are about your host; the rest are about your own website.
- A signed processor agreement with your host. In writing or electronic, covering everything in Art. 28(3). Keep a copy with your records.
- A list of the host’s sub-processors. Who they are, what they do and where they process — and how you are told before one is added or replaced (Art. 28(2)).
- Where the data and the backups live. Ask for the countries of the servers, the backup copies and the mailboxes, not just the marketing region.
- No transfers outside the EEA without a basis. If any provider in the chain is outside the EEA, check the Chapter V basis: adequacy, standard contractual clauses or a derogation (Art. 44–49).
- Who can be compelled to hand data over. Know which companies in the chain fall under non-EU law, such as the US CLOUD Act.
- A breach procedure in the contract. How fast the host tells you about a breach, with what information, and who at your company receives it — you have 72 hours towards the AP (Art. 33).
- Backups, and a restore you have actually tried. Art. 32 asks for the ability to restore data in time after an incident. Know how often backups run, how long they are kept, and restore one once.
- HTTPS on every page. Every form and every login travels encrypted. Certificates should renew automatically.
- Personal logins and two-factor authentication. For the hosting dashboard and your CMS: no shared passwords, a second factor on, and access removed when a staff member or agency leaves.
- Software kept up to date. CMS core, plugins and themes. Delete what you do not use.
- Third-party embeds that leak visitor data. Fonts loaded from Google, analytics, CDN scripts, YouTube embeds and chat widgets all send the visitor’s IP address to someone else. Self-host what you can and load the rest only after consent.
- Contact forms that collect only what you need. Ask for what you need to answer, say so in your privacy statement (Art. 13), and know where the submissions end up — usually in a mailbox.
- Consent before non-essential cookies. According to the AP, functional cookies and limited analytics cookies with little privacy impact need no consent; tracking and most other cookies do (Dutch Telecommunications Act, art. 11.7a).
- Retention you have decided. Form submissions, orders, logs, old mailboxes and old backups: keep personal data no longer than necessary (Art. 5(1)(e)).
- Email hosted under the same rules. Mailboxes are full of personal data. Check that your email provider is covered by a processor agreement and where it stores mail, just as for the website.
More on embeds: Your fonts are snitching on your visitors — what a font request sends, and how to serve fonts yourself.
What we sign
What veldhost does, in the words of our contract.
Everything below is in the published Data Processing Agreement, which is drafted to meet Art. 28(3).
The agreement
The DPA forms part of our Terms and is incorporated into your contract by reference, so it applies from the moment you order. If you need a countersigned copy for your records, email legal@veldhost.eu.
DPA →The roles
For your websites, databases, files, mailboxes, backups and DNS records, you are the controller and veldhost is your processor. For account, billing and support data, veldhost is an independent controller under the Privacy Policy.
DPA §1 →Where the data is
Servers in Germany — Falkenstein and Nuremberg — rented from Hetzner and operated by us. The DPA also permits Hetzner’s Finnish region. We do not intentionally place your content, production compute or backups outside the EU/EEA.
DPA §5 →Sub-processors
A versioned register, currently v1.3. For your content: Hetzner Online GmbH (Germany/Finland) and our own self-hosted mail service on that infrastructure. At least 14 days’ notice before we add or replace one, a right to object, and a right to terminate the affected service if the objection cannot be resolved within 30 days.
Register →A breach
We notify you without undue delay and in any event within 48 hours after becoming aware of a breach affecting your content, with the facts you need for your own Art. 33/34 obligations. As controller, you notify the AP and the people affected where required.
DPA §10 →Security measures
TLS on all customer-facing and management traffic, multi-factor authentication and audit logging for operator access, a separate container per customer, automated security updates, and backups to EU storage — weekly on every plan, daily with the add-on.
DPA §7 →When you leave
Your export stays available for 30 days after the service ends. Backup copies are not erased one by one; they are overwritten as the rotation runs and are gone no later than 35 days after the live data is deleted.
DPA §11 →What we do not claim
We do not hold ISO 27001 certification or a SOC 2 report. The trust centre lists what we have and what we do not, and the security questionnaire is answered in advance.
Trust centre →Trust centre → · Pre-answered security questionnaire → · Privacy Policy →
Questions
GDPR and hosting, answered.
Does EU hosting make my website GDPR-compliant?
No. EU hosting deals with where your data is stored and which laws can reach it, and a processor agreement covers what the host does with it. Your forms, plugins, embeds, cookies, privacy statement and the reasons you collect data remain your responsibility as controller.
Do I need a processor agreement with my web host?
Yes, if the host stores personal data for you — and a website with a contact form, a shop or mailboxes almost always does. Art. 28(3) GDPR requires a contract, in writing or electronic form, and according to the Autoriteit Persoonsgegevens both parties are in breach without one.
Do I have to sign something separately with veldhost?
No. Our Data Processing Agreement is part of the Terms and is incorporated into your contract by reference when you order. If you need a countersigned copy for your records, email legal@veldhost.eu.
Who reports a data breach to the Autoriteit Persoonsgegevens?
You, as the controller: without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk. Your host, as processor, must tell you without undue delay; our DPA commits us to do so within 48 hours of becoming aware of a breach affecting your content.
Where does veldhost store my data?
In Germany, in Falkenstein and Nuremberg, on servers rented from Hetzner and operated by us. Our Data Processing Agreement also permits Hetzner’s Finnish region, which is in the EU as well. Websites, databases, mailboxes and backups stay in the EU/EEA.
Why does the US CLOUD Act come up when choosing a host?
Because it allows US authorities to order providers of electronic communication and remote computing services to disclose data in their possession, custody or control, wherever that data is stored. So buyers ask who owns and operates the host, not only where the servers are. veldhost is a Dutch company; the sub-processor for your content is Hetzner Online GmbH, a German company.
Is veldhost ISO 27001 or SOC 2 certified?
No. We do not hold ISO 27001 certification or a SOC 2 report, and we do not imply otherwise. The trust centre lists the controls in place, what we do not have, and a pre-answered security questionnaire.
Do I need a cookie banner?
It depends on what your site sets. According to the Autoriteit Persoonsgegevens, functional cookies and limited analytics cookies with little privacy impact need no consent, though you must still inform visitors; tracking cookies and most other cookies do need consent.
Sources
- Regulation (EU) 2016/679 (GDPR), EUR-Lex — Art. 4, 5, 13, 28, 32, 33, 34 and 44–49.
- Verwerkersovereenkomst, Autoriteit Persoonsgegevens — the agreement is mandatory and what it contains.
- Verantwoordelijke en verwerker, Autoriteit Persoonsgegevens — the controller stays responsible; who reports a breach.
- This is how you report a data breach, Autoriteit Persoonsgegevens.
- Cookies, Autoriteit Persoonsgegevens — which cookies need consent.
- Guidelines 07/2020 on the concepts of controller and processor, EDPB.
- Guidelines 9/2022 on personal data breach notification, EDPB.
- EDPB-EDPS joint response on the US CLOUD Act (2019), EDPB.
General information, not legal advice. For your own situation, ask a lawyer or your data protection officer.