A Barcelona scale-up hosts with a European provider. The group's Italian DPO asks for contratto di sub-fornitura, sede dei datacenter, and lista subprocessori — in vain if the provider only delivers a "GDPR compliant" page.
Italy and Spain apply the same GDPR with active authorities (Garante Privacy, AEPD). Expected proof goes beyond slogans: contractual documentation and technical mapping.
Five minimum documents to require
| Document | Expected content | Audit use |
|---|---|---|
| DPA / AVV / contrato encargo | Purpose, duration, measures, subprocessors | GDPR Art. 28 |
| Registro / registro actividades | Host cited with purpose | Accountability |
| DC location | Italy, Spain, EU — per service | Transfers |
| Lista subcontratistas | Names, countries, role | Chain |
| Attestations | ISO, etc. with scope | Due diligence |
Italy vs Spain specifics (host view)
Italy: strong sensitivity on cookies and marketing (Garante guidelines), frequent DPO on SMBs beyond EU thresholds, contracts often required in Italian for local markets.
Spain: active AEPD on transfers and rights, LSSI attention for electronic communications (distinct from GDPR but linked to hosted site), delegado de protección de datos if thresholds met.
In both cases, language and support matter as much as server response time.
Local vs pan-European hosts
IT/ES actors in the directory (Aruba, SiteGround ES, OVH ES, etc.) or FR/DE/NL clouds: compare the same proof grid, not nationality alone.
Require bilingual or translated DPA if needed, documented EU datacenter for EU client data, notification on new subprocessor, and documented assistance for rights exercise (esercizio diritti / ejercicio de derechos).
The peak: conformità senza documenti non esiste
Decide and move forward without blind spots
Establish an identical proof grid for all candidates before shortlisting. Sign DPA before any production with personal data. Update IT/ES register with host and exact purpose. If ISO is claimed, read attestation scope. Compare via compare tool and read Transfers outside EU if the chain includes third countries.
Frequently asked questions
Is GDPR enough in Italy and Spain?
Yes as EU base; Garante and AEPD require solid documentation beyond the compliance logo.
Which proof to ask the host?
DPA, subprocessors, datacenters, measures, breach procedure, rights assistance, certificates with scope.
Must I use a local IT/ES host?
No if EU safeguards suffice; a local actor sometimes eases contract and support.
Health or public sector hosting?
Additional frameworks — do not confuse with standard web hosting.
Require the cinco documentos before go-live — not after a complaint to the authority.
