Independent comparison · no paid rankings
Home / Blog / Compliance / Hetzner: review the data processing agreement before placing customer data there

Hetzner: review the data processing agreement before placing customer data there

Hetzner's DPA frames GDPR processing, but read it line by line before hosting customer data — sub-processors, German location, and IaaS responsibilities included.

Hébergeurs.eu Editorial Team 4 min read Updated Jul 19, 2026

A B2B SaaS picks Hetzner Cloud for price and German latency. The founder ticks "GDPR OK" on the client questionnaire — then discovers the DPA was never signed, snapshots copy to an external bucket, and the sub-processor register mentions neither Hetzner Online GmbH nor the billed subsidiary.

Hetzner is a solid choice for many European workloads. The trap is not missing contract framework: it is confusing a German host with a closed compliance chain.

What Hetzner's DPA contains — in practice

The data processing agreement defines Hetzner as processor under GDPR: process personal data only on documented instructions, assist the controller, notify breaches, delete or return data at contract end.

Read first:

ClauseWhat it commits toWhat it does not
Purpose & termOrdered cloud servicesYour unlawful or off-purpose use
LocationDE/FI DC per offerYour DIY backups elsewhere
Sub-processorsList or notification mechanismYour own SaaS sub-processors
Security measuresDatacenter & platform scopeYour VM hardening
Audits & assistanceCooperation termsUnlimited free audit
TransfersOutside EEA if statedYour US CDN added later

Request the current version from Hetzner's legal pages or sales — and archive the signature date.

Sub-processors: the chain beyond the server

As controller (or sub-processor), list every sub-processor touching client data — Hetzner included, but also your backup tool, monitoring, CI/CD, support, and transactional email.

Hetzner documents its sub-processors in the DPA or an annex. Your GDPR register must merge both levels: Hetzner's and yours.

Hetzner's DPA does not replace your own DPA with clients if you process their data on their behalf.

IaaS: shared responsibilities

On Hetzner Cloud or a dedicated server, the model is IaaS: you manage the OS, applications, certificates, application firewall (alongside the cloud firewall), and root accounts.

Before placing client data, verify: signed DPA with the correct Hetzner entity; chosen region (DE/FI) documented in the register; encryption at rest and in transit configured by you; backups located and contractually governed; client offboarding deletion procedure tested; breach notification with clear responsibilities within 72 hours.

Our profile marks GDPR and ISO 27001 in the public matrix — a starting point, not a substitute for your analysis.

Common mistakes before client audit

DPA downloaded but never signed or linked to the client contract.

Personal account for B2B SaaS — unclear legal entity.

Object Storage or snapshots without retention policy — excessive retention.

Hetzner support accessing the machine without trace — log admin access.

Forgetting Finland if you chose Helsinki for Nordic latency.

To compare with another German host, see Germany: what the BDSG adds.

The peak: the DPA does not replace your client promise

That is the gap in "compliant host?" questionnaires: compliance cascades.

Decide and move forward without blind spots

Download and sign the DPA this week, then link it to the master agreement with your client. Map production, backups, logs, and support on a single diagram. Update register and privacy policy with the exact Hetzner subsidiary.

Test client data deletion and export on a dummy account. Compare via the compare tool and directory if managed hosting would reduce your ops load. Read the Hetzner profile for product framing, then validate region and offer in the order flow.

Frequently asked questions

Does Hetzner provide a GDPR-compliant DPA?

Yes, for business customers. It covers instructions, security, sub-processors, and transfers — without guaranteeing a misconfigured VPS.

Where is data processed at Hetzner?

Datacenters in Germany and Finland per offer. Your backups or external integrations may change the real map.

What obligations stay with the customer?

Firewall, hardening, access, encryption, backups, patching, and breach notification on the controller side.

Must I inform end customers?

Yes: mention Hetzner in register, privacy policy, and DPA with clients if you process their personal data.


Before answering "yes" to your client's GDPR questionnaire, check: signed DPA, updated register, and a flow map you would defend before a DPO.

See the Hetzner sheet

Independent scores, plans, pros/cons and alternatives to Hetzner.

Open the Hetzner sheet
Blog

Related reading

All articles →