Independent comparison · no paid rankings
Home / Blog / GDPR: the right questions to ask before signing with a host
Guide

GDPR: the right questions to ask before signing with a host

French datacenter on the slide, subcontractors missing from the contract — before you sign, demand a DPA, real data location, logs and breach procedures. A host due diligence checklist.

5 min read Updated Jul 19, 2026

Picture due diligence for an HR SaaS: the sales deck promises "100% France hosting", the contract is silent on backups, Indian support never appears, and a clause allows transfer "if necessary" to the United States. The DPO blocks the signature — not out of paranoia, but because Art. 28 requires guarantees the PDF does not contain.

Choosing a host under GDPR is not ticking "European Union". It is verifying that processing, subcontracting and incidents are framed before the first euro is charged. The good news: the right questions are the same for a shop, an association or a software vendor. The bad news: few sales teams answer them unprompted.

Contractual questions: the DPA before the badge

The hosting contract (terms) and the Data Processing Agreement (DPA) do not play the same role. Terms mostly protect the provider; the DPA frames what it does with your personal data. Before signing, verify the DPA explicitly states your role as controller and the host's role as processor.

Nine points must appear or be annexed: purpose and duration of processing; nature of data (accounts, IP logs, user content); documented instructions (deletion, export, location); staff confidentiality; list of further processors and change notification; help for the DPO, impact assessments and breach notification within 72 hours; fate of data at contract end (data deletion); and audit or information rights.

Weak answerSolid answer
"We are GDPR compliant"Signed DPA in annex, dated
"Data in Europe"Prod regions, backups and CDN listed
"ISO in progress"Dated, verifiable scope attestation

Technical questions: where data actually goes

Beyond the contract, ask for a simple map: production, backups, logs, support tickets. Are these flows in the same country? Do backup copies leave the EU? For transfers outside the EU, what guarantees apply (standard contractual clauses, adequacy decision) and how is the Cloud Act addressed if a US subcontractor is involved?

Also ask about encryption at rest and in transit, key management, and admin access logs on the host side: who can read what, for how long, with what approval process. In an incident, what timeline and channel for breach notification? Is reversibility documented (export format, deadline, cost)?

Cross-check answers with our real location investigation and directory profiles — two sources that complement sales talk.

Scenarios by project sensitivity

Not every application needs the same rigour. A brochure blog can work with a standard DPA, an EU region and minimised logs. An e-commerce site must frame backups, CDN and, if payment is integrated, PCI compliance on top of GDPR.

For health or sensitive data in France, the HDS framework may apply in addition to GDPR — generic shared hosting without attestation is not enough. Compare frameworks in GDPR, HDS, SecNumCloud — who needs what? before mixing acronyms in one quote paragraph.

Common mistakes before signing

Confusing registrar and host: two providers, sometimes two DPAs. Forgetting a third-party CDN without a chain DPA. Choosing a "free" offer without reading the underlying cloud subcontracting. Failing to update the processing register after signature — internal audit will reveal the gap six months later.

The climax: displayed compliance is not contracted compliance

Ask the questions before the annual commitment. Renegotiating after migration costs more than refusing an incomplete offer.

Decide and move forward without blind spots

Start by downloading the full DPA and terms — not a sales summary. Then map data flows: production, backups, CDN, transactional email. Verify the subcontractor list and any transfers outside the EU. Align your processing register and, if needed, your impact assessment with what the contract actually allows. Finally, compare hosts that document these points via the compare tool and guides — the short list shrinks quickly once the right questions are asked.

Frequently asked questions

Is an EU host automatically GDPR compliant?

No. GDPR requires a documented contractual and technical framework. A datacenter in France guarantees nothing if backups, support or CDN route through countries or providers not covered in the DPA.

Do you need a DPA with the host?

Yes, as soon as the host processes personal data on your behalf — Art. 28. Refusal or an empty template is a red flag. Without a signed DPA, you cannot demonstrate lawful processing.

What should you ask about subcontractors?

An up-to-date list with location and transfer guarantees. Your register and DPA must reflect them. Any chain change must be notified before production use.

Is ISO 27001 enough?

Useful if the certified scope covers your offer. ISO complements GDPR but does not replace the DPA or data-subject rights. Read the attestation before citing it in a meeting.


Before signing with a GDPR host, the right question is not "are you in Europe?" — it is "show me the DPA and the backup path".

Compare European hosts

Filter by compliance, location and use case — then open the sheets to verify the real scope.

Browse the directory
Blog

Related reading

All articles →