CNIL inspection or enterprise client asks for your Article 30 register. Hosting line: "Cloud provider, client data, EU." Insufficient: which provider? Exact data (twelve-month IP logs, encrypted backups where)? Upstream sub-processors (US CDN, India support)?
Register is not formality. It is the map of what the host actually does with your personal data.
Host role: infrastructure processor
You = controller (site content, user database). Host = processor (storage, execution, infra logs) unless it determines purposes (rare).
Document: legal name, DPO or privacy contact, contractual datacenter location.
Register content — useful fields for host
| Register field | Host example |
|---|---|
| Purpose | Hosting and site availability |
| Data categories | App files, client DB, access IP logs |
| Data subjects | Visitors, clients, admins |
| Recipients / processor | OVHcloud SAS — see DPA + sub-processor list |
| Transfers outside EU | No / yes + safeguards (SCCs) |
| Duration | Contract term + log retention (see policy) |
| Security measures | Transit/at-rest encryption, backups, ISO if relevant |
Sub-processors to trace
CDN, transactional email, SaaS monitoring plugged by host or you on same server — each may be sub-processor to list in DPA and register.
Request upstream sub-processor list from host (Article 28.3). Cross-check with processing agreement and transfers outside EU.
In audit, inspector compares register, DPA, and real architecture. A line "OVH Gravelines VPS hosting" with twelve-month log retention and US Cloudflare CDN mention beats generic paragraph — and avoids non-compliance found by documentary gap.
Update register the day you add CDN, monitoring tool, or change region — not the eve of annual audit.
The summit: register reveals DPA gaps
Decide and move forward without blind spots
Inventory personal data on your infrastructure: application, logs, backups. Fill host line with contractual product, region, retention durations. Cross-check DPA and sub-processor list. Update register at every stack or provider change — before DNS cutover, not after. See our compliance guides and directory.
Frequently asked questions
Must the host appear in the register?
Yes once it processes personal data on your behalf — Article 28 processor. Shared or dedicated: same obligation, different scope.
What to write precisely?
Identity, infra purpose, data categories, duration, sub-processors, contractual location — not generic "EU cloud."
Shared vs dedicated?
Same processor logic; specify product and contractual region, not vague label.
Host change?
Controller updates register and DPA before DNS cutover — not in post-migration rush.
An honest register entry on the host forces clarity the "GDPR compliant" quote promised without detailing.
