Scaleway and sovereignty: location, ownership, and jurisdiction do not say the same thing
Scaleway claims a sovereign French cloud, but sovereignty spans location, ownership, and applicable law — three axes to cross-check before a sensitive project.
Browse our Compliance posts on European hosting.
No results for this search
Scaleway claims a sovereign French cloud, but sovereignty spans location, ownership, and applicable law — three axes to cross-check before a sensitive project.
"Daily backups" without a tested restore is an unverified promise. One timed exercise beats a printed SLA.
An accessible front end can be sabotaged by misconfigured CDN, absurd response times, or a WAF blocking screen readers. Hosting matters — without replacing editorial work.
"Data in Europe" does not answer the Cloud Act — what matters is the contracting entity's nationality and what the contract says when a US authority requests your data.
Infomaniak hosts in Switzerland with a strong GDPR story, but residency does not stop at the Geneva datacenter. Email, CDN, analytics, and backups all need an explicit data map.
"Export on request" in terms means nothing if nobody measured time, format, or egress cost of an outbound migration.
The cookie banner covers your domain — not necessarily the CDN logging IP and URL at the edge before the page reaches your French host.
Education, gaming, youth media: hosting children's data requires technical and contractual measures beyond standard shared hosting.
Keeping data ten years is not enough — legal archiving requires integrity, traceability and durable format — qualities a simple operational backup does not guarantee.
Three acronyms, three levels of requirement. A guide to what your project must actually demand from a host — without paying for a certification you do not need.
Liability caps, indirect damage exclusions, force majeure — in hosting, many clauses fail against an informed B2B client or in court.
A Dutch datacenter reassures on the EU, but access law (AIVD, police) and US ownership links matter as much as the Amsterdam pin on the map.
Host name, address, and contact in legal notices — seemingly simple, often wrong after migration, white-label resale, or subsidiary change.
Switzerland eases transfers through an adequacy decision, but hosting with Infomaniak or Hostpoint does not remove the duty to document every flow outside the EEA.
The BDSG supplements GDPR in Germany with rules on DPOs, fines, and certain processing — useful when reading a Hetzner, IONOS, or Strato contract.
Beyond European GDPR, Italy (Garante) and Spain (AEPD) expect concrete proof: DPA, register, location, and documented subprocessors.
Phishing, malware, or illegal content reports on shared hosting — without a traceable procedure you expose host, publisher, and victims to delay or error.
OVHcloud, Cloud Temple, and Outscale display HDS — on different scopes. Logo without annexed attestation is regulatory risk, not a purchase shortcut.
After a breach or GDPR audit, "we don't know who accessed the server" is an expensive answer. How to structure admin logs on both host and customer side.
GDPR's 72-hour window leaves no time to improvise who calls whom. Without a contractual alert channel with your host, you start late before understanding the incident.
The processing activities register must name the host, what it actually processes, and on what basis — not just copy-pasted "web hosting."
A "validated BCP" PDF does not restart a site. In hosting, continuity is proven by tested RTO, off-zone backups, and escalation roles — not a library of procedures.