Independent comparison · no paid rankings
Home / Blog / GDPR, HDS, SecNumCloud — who needs what?
Compliance

GDPR, HDS, SecNumCloud — who needs what?

Three acronyms, three levels of requirement. A guide to what your project must actually demand from a host — without paying for a certification you do not need.

5 min read Updated Jul 19, 2026

"We want a compliant host." That sentence shows up in almost every RFP. The problem: compliant with what? Sales teams often answer with a cocktail of acronyms — GDPR, HDS, SecNumCloud, ISO 27001 — as if they were interchangeable. They are not.

This guide helps you decide before you compare sheets. For every project, one question matters: what real obligation sits on your data, and what level of proof must you demand from the provider?

The three layers, in one minute

FrameworkWhat it coversWho actually needs it
GDPRPersonal data in EuropeAlmost everyone
HDSPersonal health data (France)Healthcare, care sector, patient-record vendors
SecNumCloudTrusted cloud against extraterritorial lawsGovernment, critical operators, highly sensitive workloads

GDPR is the baseline. It does not "certify" a host: it imposes rules for processing, sub-processing and documentation. A serious European host should provide a clear processor agreement, data location, and a process for individual rights.

HDS is a French sector certification. Without the right certified scope, you cannot lawfully host personal health data. Reading the badge is not enough: you must read the attestation. Our investigation Where is your health data really stored? unpacks that trap.

SecNumCloud, issued by France's ANSSI, mainly answers extraterritorial access risk (Cloud Act and equivalents). Useful for some public or strategic workloads; useless as a substitute for HDS, and often excessive for a classic e-commerce site.

Case 1 — Brochure site, blog, small shop

You collect customer accounts, newsletters, logs. No medical record, no government workload.

What you need: a host that can run GDPR day to day — DPA (processor agreement), data region, listed sub-processors, incident process. Ask for these documents before you sign, not after go-live.

What you do not need: HDS, SecNumCloud. Paying for them "to be safe" raises cost without cutting real risk if your exposure remains that of an ordinary website.

To structure questions before signing, see also GDPR: the right questions before you sign with a host.

Case 2 — Health data

Patient records, teleconsultation, enriched medical calendars, health data warehouses, facility software: as soon as personal health data is hosted, the HDS framework generally applies.

What you need:

  1. A current HDS attestation
  2. A scope that covers your stack (app, database, files, backups, any managed ops)
  3. Explicit location and sub-processing chains

What is not enough: "we are GDPR", "data centre in France", "ISO 27001", or SecNumCloud without HDS on the right product.

Here the decision is no longer "which host has the nicest badge", but "which certified product matches my architecture". Then compare providers in the directory while filtering for health compliance.

Case 3 — Public or highly sensitive workloads

Local government, critical operator, an application exposed to extraterritorial interference, critical industrial secrecy: SecNumCloud can become relevant — sometimes required by the project's framing.

What to verify: which exact service is qualified, reversibility, admin access, sub-processor jurisdictions. A dedicated guide: SecNumCloud: who actually gets a real answer from this qualification?.

If health data is also involved, SecNumCloud does not waive HDS. The two layers stack.

The decision grid

Before you run a price / performance comparison, answer these five questions in writing:

  1. Which data do you process (personal, health, sensitive, anonymised)?
  2. Who is the controller, and who is the processor?
  3. Where must production, backups and logs reside?
  4. Is extraterritorial access a real business risk, or marketing fear?
  5. Do you need managed ops, or only infrastructure?
Dominant answerLevel to require
"Ordinary" personal dataGDPR + contractual proof
Health dataHDS on the exact scope
Public workload / critical foreign accessSecNumCloud (often + GDPR)
Health and high sovereigntyHDS + SecNumCloud, without mixing the evidence

How to read an offer without getting fooled

When a quote lists several labels, demand one line per label:

  • GDPR → processor agreement, sub-processor list, location, log retention
  • HDS → attestation number, date, technical scope, products covered
  • SecNumCloud → framework / level, qualified services, reversibility terms

If sales merges all three into one sentence ("sovereign health-compliant cloud"), ask for the paperwork. Not the slides.

To compare European hosts on these criteria, start with the directory and the guides. And if your core topic is the real location of health data, the investigation health data & HDS is the natural companion to this guide.

Frequently asked questions

Does a brochure website need HDS?

No, unless it processes personal health data. A corporate site, blog or ordinary shop falls under GDPR, not HDS.

Does SecNumCloud replace HDS?

No. SecNumCloud mainly addresses extraterritorial access risk. HDS remains required when you host personal health data in France.

Does GDPR require a French host?

No. It requires guarantees on processing, sub-processing and transfers. A well-documented European host can be enough — if the contract and data flows hold up.

Where should I start if my project is "somewhat sensitive"?

First write down which data you process, for whom, and where it travels. Only then choose the framework: GDPR alone, HDS, SecNumCloud, or a combination.


Next time a quote says "compliant", ask: compliant with which framework, on which scope, with which evidence? If the answer fits in a slogan, it is not an offer yet.

Compare European hosts

Filter by compliance, location and use case — then open the sheets to verify the real scope.

Browse the directory
Blog

Related reading

All articles →