Independent comparison · no paid rankings
Home / Blog / Compliance / GDPR register: documenting the host as a processor

GDPR register: documenting the host as a processor

The processing activities register must name the host, what it actually processes, and on what basis — not just copy-pasted "web hosting."

Hébergeurs.eu Editorial Team 3 min read Updated Jul 19, 2026

CNIL inspection or enterprise client asks for your Article 30 register. Hosting line: "Cloud provider, client data, EU." Insufficient: which provider? Exact data (twelve-month IP logs, encrypted backups where)? Upstream sub-processors (US CDN, India support)?

Register is not formality. It is the map of what the host actually does with your personal data.

Host role: infrastructure processor

You = controller (site content, user database). Host = processor (storage, execution, infra logs) unless it determines purposes (rare).

Document: legal name, DPO or privacy contact, contractual datacenter location.

Register content — useful fields for host

Register fieldHost example
PurposeHosting and site availability
Data categoriesApp files, client DB, access IP logs
Data subjectsVisitors, clients, admins
Recipients / processorOVHcloud SAS — see DPA + sub-processor list
Transfers outside EUNo / yes + safeguards (SCCs)
DurationContract term + log retention (see policy)
Security measuresTransit/at-rest encryption, backups, ISO if relevant

Sub-processors to trace

CDN, transactional email, SaaS monitoring plugged by host or you on same server — each may be sub-processor to list in DPA and register.

Request upstream sub-processor list from host (Article 28.3). Cross-check with processing agreement and transfers outside EU.

In audit, inspector compares register, DPA, and real architecture. A line "OVH Gravelines VPS hosting" with twelve-month log retention and US Cloudflare CDN mention beats generic paragraph — and avoids non-compliance found by documentary gap.

Update register the day you add CDN, monitoring tool, or change region — not the eve of annual audit.

The summit: register reveals DPA gaps

Decide and move forward without blind spots

Inventory personal data on your infrastructure: application, logs, backups. Fill host line with contractual product, region, retention durations. Cross-check DPA and sub-processor list. Update register at every stack or provider change — before DNS cutover, not after. See our compliance guides and directory.

Frequently asked questions

Must the host appear in the register?

Yes once it processes personal data on your behalf — Article 28 processor. Shared or dedicated: same obligation, different scope.

What to write precisely?

Identity, infra purpose, data categories, duration, sub-processors, contractual location — not generic "EU cloud."

Shared vs dedicated?

Same processor logic; specify product and contractual region, not vague label.

Host change?

Controller updates register and DPA before DNS cutover — not in post-migration rush.


An honest register entry on the host forces clarity the "GDPR compliant" quote promised without detailing.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →