Cover: The GDPR Hosting Checklist Most Guides Get Wrong
October 6, 2026·7 min read·1,448 words·

The GDPR Hosting Checklist Most Guides Get Wrong

A Stockholm hosting founder explains why GDPR compliance depends on sub-processors and backup policies, not just server location inside Europe.

A support ticket that taught me what GDPR actually means

In 2018, a client asked us to prove a host's backups were "GDPR compliant" before we migrated their site over. I asked what that phrase meant to her. She had no idea. She just knew a checklist somewhere told her to ask.

That ticket stuck with me. It showed how confused people still are about GDPR (the General Data Protection Regulation, the EU law on personal data). Most hosting guides shrink it down to one rule: servers in Europe equals compliant. That rule was wrong when the law started in 2018, and it is still wrong now.

At HostList.io I track more than 30,000 hosting companies, and privacy claims are one of the first things I check. Here is what actually matters when you choose a host, not the checklist version you find everywhere else.

Server location matters, but not for the reason you think

Keeping data inside the EU or EEA (European Economic Area, a wider group of countries with similar data laws) removes one genuine legal headache: the rules around moving data across borders. Since the Schrems II court ruling, sending personal data to the US carries real legal risk, and companies still argue about what paperwork makes that transfer safe.

Location alone does not make a host compliant, though. Picture a server in Frankfurt run by a company with weak access controls, no breach process, no clear rules on logging. That is not "GDPR hosting". It is just a server that happens to sit in Germany.

When you browse our directory, do not stop at the country flag on the homepage. Ask a simpler question: what actually happens to the data once it lands on that server?

  • Where the data physically sits, including backups and disaster recovery copies
  • Who can access it, and whether those staff work inside or outside the EU
  • How long the host keeps it after you cancel your account

Our rankings page lets you filter hosts by data centre country, which saves you reading fifty homepages just to find the basic facts.

Sub-processors: the GDPR loophole most hosts hide

Here is the part almost nobody explains clearly. Your host rarely does everything alone. They use a sub-processor, another company that touches your data on their behalf: email delivery, spam filtering, a CDN (content delivery network, a system that copies your site to servers around the world for speed), or support ticket software.

I have seen hosts market themselves as "EU-based and GDPR-compliant" while routing support tickets through a US customer service tool with weak data protections. The main server sits safely in Amsterdam. Customer data still leaks out through the back door.

Under GDPR, you are the data controller for your site's visitor data. Your host is a processor working for you. Every sub-processor your host uses becomes your responsibility too, because you chose that host in the first place.

What to ask before signing

A host that takes GDPR seriously will publish a sub-processor list without you needing to ask. If they cannot name their spam filter, backup provider, or CDN, that silence tells you everything.

  • Ask for the full sub-processor list, not just the main server location
  • Check whether any sub-processor sits outside the EU or EEA
  • Confirm they will tell you before adding a new sub-processor

If you run WordPress, this matters even more, since plugins often add their own sub-processors behind the scenes. Our best WordPress hosting guide covers which providers actually disclose this properly.

Data Processing Agreements are not optional extras

A DPA (Data Processing Agreement) is a legal contract between you and your host setting out how they handle personal data on your behalf. GDPR requires this document. It is not a nice bonus feature buried in a premium plan.

If a host cannot produce a DPA within a day of asking, be careful. If they hide it behind a sales call, that is a warning sign too. The hosting providers we work with at Seahawk Media typically produce these within hours when asked properly. The template rarely changes from provider to provider, so there is no good reason for delay.

Read the DPA once, even briefly. Look closely at two sections: breach notification timing, and rules around sub-processor changes. Those two sections tell you more about a host's real habits than any marketing page ever will.

If you are shopping specifically for UK-based options, our UK hosting providers page lists which companies handle this paperwork well. Post-Brexit UK data rules mirror GDPR closely, but they are not identical, so check both.

Shared IP blacklisting: the privacy problem nobody talks about

This is my pet issue, so bear with me. Many budget hosts put hundreds of customers on one shared IP address (the numeric address that identifies a server online) to cut costs.

When one customer on that IP sends spam, or gets hacked, the whole IP can land on a spam blacklist. Your emails stop arriving: account confirmations, password resets, and, ironically, your replies to GDPR data requests.

This is not just an email problem. It is a compliance problem. GDPR gives people the right to request their own data, and you must respond within a set time limit. If your infrastructure fails at that exact moment because of a stranger's spam, that is a real business risk, not a small technical inconvenience you can shrug off.

The better hosts we track through HostList.io stopped sharing IPs beyond their smallest starter plans years ago. It costs more to run this way. But overselling shared resources to cut prices always shows up somewhere, usually at the worst possible time.

Backups, logs and the parts nobody reads the fine print on

GDPR does not just cover the live database sitting on your server. It also covers backups, server logs, and even the cached pages a CDN keeps around the world. Most guides skip this part entirely.

Ask how long backups stay around after a customer requests deletion. If your host keeps rolling backups for 90 days "just in case", that data is not actually gone the day you press delete. Neither is your visitor's personal data, even though you told them it was removed.

Server access logs record who requested what page, and when, usually including IP addresses, which count as personal data under GDPR. A host with no log retention policy at all is not being helpful by "keeping everything forever". They are creating a liability that eventually lands on you.

The European Data Protection Board publishes clear guidance on retention periods. Most hosting companies never bother reading it. I have read it. Most hosts have not built their systems around it, and it shows the moment you ask them a direct question.

A practical checklist and what I would actually do in your position

Enough theory. Here is what I tell friends and family when they ask me where to host their small business site. I have watched this space since before GDPR was fashionable, through the thousands of sites we manage, so I keep it simple.

Start with our hosting match tool if you want a shortlist based on your country and needs. Then verify each candidate yourself using the points below. Do not trust a badge on their homepage alone.

  • Confirm the primary data centre location, and ask if backups ever leave that region
  • Request the sub-processor list and the DPA before you pay anything
  • Check if the host offers a dedicated IP address, not just shared hosting by request
  • Look for a named data protection contact, not a generic support inbox
  • Search for any past data breach disclosures, and how the host handled them

If you run a personal blog, your GDPR risk is genuinely low, but these same principles still protect you from vendor lock-in and poor support down the line. If you run an agency, or handle customer data for clients, treat your hosting choice as a legal decision, not a purely technical one.

Do not assume "based in the EU" equals compliant on its own. It is a useful starting filter, not a finish line. The real work is checking sub-processors, checking retention policies, and seeing whether a host treats your DPA request as routine paperwork or as a sales objection to dodge.

My recommendation is simple: ask any host on your shortlist for their DPA and sub-processor list before you sign up, not after. Choose a dedicated IP address over shared hosting if your business handles any customer data at all. And read the official GDPR text yourself once, so no salesperson can bluff you with a term you have never actually seen defined.

HostList on LinkedIn
More independent hosting data

Follow HostList for new rankings, original research, and changes across the hosting industry.

Gautam Khorana
Gautam Khorana
Founder, HostList.io

Over 10,000 websites launched. Thousands of sites under management. Built HostList because the world deserves honest hosting advice.

LinkedIn →

RELATED ARTICLES

.host domains from RadixSponsor.host: a domain that says what you doPremium .host names for hosting companies and infrastructure brands, from the Radix registry.See premium .host
RadixSponsorPremium names that work like prime real estate400,000+ short, memorable premium domains across .tech, .store, .online, .site and more. 20,000+ already sold.See Radix premiums
.tech domains from RadixSponsor.tech: the address for what you buildPremium .tech names like cloud.tech and micro.tech, from Radix. Short, dictionary-word domains for tech brands.See premium .tech
.icu by ShortDotSponsor.icu: the domain that says I see youShort, memorable and cheap to start. From ShortDot, the registry behind .icu, .bond, .cfd, .sbs and .cyou.See .icu domains
ShortDotSponsorShort domains that actually get used.icu, .bond, .cfd, .sbs and .cyou: 3M+ names live across 400+ registrars. Short to type, cheap to start.See ShortDot domains
OpusDNSSponsorWelcome to the future of domainingNo platform fees, no minimum spend, personal support, seamless migration, and a developer-first REST API.Visit OpusDNS
HostPapaSponsorFast, Reliable, & Affordable Web HostingLaunch, grow and manage your website with reliable hosting, easy tools and 24/7 PapaSquad support.See HostPapa
GreenGeeksSponsorEco-Friendly WordPress Hosting DealFast WordPress performance backed by expert 24/7 support, free migration, daily backups and built-in security.See GreenGeeks

Promoted placement. Does not affect HRI, ranking order or eligibility.