Independent comparison · no paid rankings
Home / Blog / Compliance / Italy and Spain: which evidence should a host provide for personal data?

Italy and Spain: which evidence should a host provide for personal data?

Beyond European GDPR, Italy (Garante) and Spain (AEPD) expect concrete proof: DPA, register, location, and documented subprocessors.

Hébergeurs.eu Editorial Team 3 min read Updated Jul 19, 2026

A Barcelona scale-up hosts with a European provider. The group's Italian DPO asks for contratto di sub-fornitura, sede dei datacenter, and lista subprocessori — in vain if the provider only delivers a "GDPR compliant" page.

Italy and Spain apply the same GDPR with active authorities (Garante Privacy, AEPD). Expected proof goes beyond slogans: contractual documentation and technical mapping.

Five minimum documents to require

DocumentExpected contentAudit use
DPA / AVV / contrato encargoPurpose, duration, measures, subprocessorsGDPR Art. 28
Registro / registro actividadesHost cited with purposeAccountability
DC locationItaly, Spain, EU — per serviceTransfers
Lista subcontratistasNames, countries, roleChain
AttestationsISO, etc. with scopeDue diligence

Italy vs Spain specifics (host view)

Italy: strong sensitivity on cookies and marketing (Garante guidelines), frequent DPO on SMBs beyond EU thresholds, contracts often required in Italian for local markets.

Spain: active AEPD on transfers and rights, LSSI attention for electronic communications (distinct from GDPR but linked to hosted site), delegado de protección de datos if thresholds met.

In both cases, language and support matter as much as server response time.

Local vs pan-European hosts

IT/ES actors in the directory (Aruba, SiteGround ES, OVH ES, etc.) or FR/DE/NL clouds: compare the same proof grid, not nationality alone.

Require bilingual or translated DPA if needed, documented EU datacenter for EU client data, notification on new subprocessor, and documented assistance for rights exercise (esercizio diritti / ejercicio de derechos).

The peak: conformità senza documenti non esiste

Decide and move forward without blind spots

Establish an identical proof grid for all candidates before shortlisting. Sign DPA before any production with personal data. Update IT/ES register with host and exact purpose. If ISO is claimed, read attestation scope. Compare via compare tool and read Transfers outside EU if the chain includes third countries.

Frequently asked questions

Is GDPR enough in Italy and Spain?

Yes as EU base; Garante and AEPD require solid documentation beyond the compliance logo.

Which proof to ask the host?

DPA, subprocessors, datacenters, measures, breach procedure, rights assistance, certificates with scope.

Must I use a local IT/ES host?

No if EU safeguards suffice; a local actor sometimes eases contract and support.

Health or public sector hosting?

Additional frameworks — do not confuse with standard web hosting.


Require the cinco documentos before go-live — not after a complaint to the authority.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →