ngpaas.eu

GDPR-Compliant Cloud Hosting: What Really Matters

GDPR-compliant cloud hosting explained: data processing agreement, data location, transfers outside the EU, security measures and a provider checklist.

EU cloudPublished

Cloud hosting is GDPR-compliant when three conditions are met: the provider processes personal data on your behalf under a data processing agreement, the data is protected by security measures appropriate to the risk, and any transfer of data outside the European Economic Area rests on a valid legal basis. The provider’s marketing label does not decide this. You remain the controller, and you document why your choice is sound.

This page offers orientation for developers and decision-makers. It is not legal advice; involve your data protection officer and, where necessary, legal counsel.

Who is responsible for what

Under the General Data Protection Regulation, the company that decides why and how personal data is processed is the controller. A cloud provider that stores or processes that data on your instructions is a processor. The roles bring different duties:

Role Typical party Key duties
Controller You (the company running the app) Legal basis for processing, choosing a suitable processor, records of processing, data subject rights
Processor Cloud or hosting provider Process only on instructions, security measures, support with data subject requests, notification of breaches
Sub-processor Provider’s own suppliers (data centres, support, CDN) Bound by the same obligations through the processor

The five things that matter

1. A data processing agreement

Article 28 GDPR requires a contract between controller and processor. Most providers offer a standard data processing agreement (DPA) in their customer portal or legal pages. Check that it covers the services you actually use, describes the security measures, lists or links the sub-processors and explains how you are informed about changes.

2. Data location and transfers

Storing data in the EU or EEA avoids most transfer questions. Transfers to third countries are regulated in Chapter V of the GDPR and need a legal basis: an adequacy decision, standard contractual clauses with a transfer impact assessment, or another listed instrument. For the United States, the Commission adopted an adequacy decision for companies certified under the EU-US Data Privacy Framework in July 2023, after the earlier Privacy Shield had been annulled by the Court of Justice in 2020.

A transfer can also happen without data leaving the EU physically, for example when support staff in a third country can access it remotely. Ask the provider where support and operations staff are located.

A provider with its parent company outside the EU may be subject to foreign laws that require disclosure of data, regardless of where it is stored. Whether that is acceptable for your data is part of your risk assessment. We explain the background in sovereign cloud explained.

4. Security measures

Article 32 GDPR asks for technical and organisational measures appropriate to the risk. In cloud setups that typically means:

  • encryption in transit (TLS) and at rest,
  • strict access control with multi-factor authentication and least privilege,
  • logging of administrative access,
  • regular, tested backups,
  • a process for patching and incident handling.

Certifications such as ISO/IEC 27001 or Germany’s BSI C5 can support your assessment, provided their scope covers the services you use.

5. Deletion and exit

The agreement should state how and when data is deleted at the end of the contract and how you can export it beforehand. Portable formats and documented export paths protect you from lock-in as much as from compliance gaps.

Checklist for choosing a provider

  1. Is a data processing agreement available for the services you need?
  2. Can you choose an EU or EEA region for storage and processing, including backups?
  3. Where are support and operations staff located, and who can access customer data?
  4. Is the sub-processor list published, and how are you notified of changes?
  5. Where is the company headquartered, and what is its policy on government requests?
  6. Which certifications exist, and do they cover your services?
  7. Can you manage your own encryption keys?
  8. How are data export and deletion handled at contract end?

European providers often make points 2, 3 and 5 easier to answer. Our overview of European cloud providers and the comparison of STACKIT, IONOS Cloud and OVHcloud show who offers what.

Common misunderstandings

  • “The provider is GDPR-certified.” There is no general GDPR certificate that relieves you of your duties.
  • “EU region means no transfer.” Remote access and sub-processors can still create transfers.
  • “Anonymised logs are fine.” IP addresses and identifiers in logs are often personal data. Check retention periods.
  • “Backups don’t count.” Backup locations must meet the same requirements as primary storage.

Further guidance

The European Data Protection Board publishes guidelines and recommendations, including on supplementary measures for international transfers (EDPB guidelines). National supervisory authorities also publish guidance on cloud use. If you are planning a move, migrating from AWS or Azure to a European cloud covers the practical steps.

Frequently asked questions

Can I use a US cloud provider under the GDPR?

Yes, it is possible. Transfers to US companies certified under the EU-US Data Privacy Framework can rely on the Commission's adequacy decision of July 2023. Otherwise standard contractual clauses plus a transfer impact assessment are needed. Many companies still prefer EU providers to reduce legal uncertainty.

Is hosting in an EU region enough?

It helps, but it is not the whole picture. Check whether support staff or sub-processors outside the EU can access data, and which law the provider is subject to. These factors decide whether a transfer in the GDPR sense still takes place.

What is a data processing agreement?

It is the contract required by Article 28 GDPR between you as controller and the provider as processor. It defines what the provider may do with the data, which security measures apply, how sub-processors are used and what happens at the end of the contract.

Do I need encryption?

The GDPR asks for security appropriate to the risk and names encryption as one possible measure. For most cloud workloads, encryption in transit and at rest is standard practice; holding your own keys adds protection against access by the provider.

More in EU cloud