"We want a compliant host." That sentence shows up in almost every RFP. The problem: compliant with what? Sales teams often answer with a cocktail of acronyms — GDPR, HDS, SecNumCloud, ISO 27001 — as if they were interchangeable. They are not.
This guide helps you decide before you compare sheets. For every project, one question matters: what real obligation sits on your data, and what level of proof must you demand from the provider?
The three layers, in one minute
| Framework | What it covers | Who actually needs it |
|---|---|---|
| GDPR | Personal data in Europe | Almost everyone |
| HDS | Personal health data (France) | Healthcare, care sector, patient-record vendors |
| SecNumCloud | Trusted cloud against extraterritorial laws | Government, critical operators, highly sensitive workloads |
GDPR is the baseline. It does not "certify" a host: it imposes rules for processing, sub-processing and documentation. A serious European host should provide a clear processor agreement, data location, and a process for individual rights.
HDS is a French sector certification. Without the right certified scope, you cannot lawfully host personal health data. Reading the badge is not enough: you must read the attestation. Our investigation Where is your health data really stored? unpacks that trap.
SecNumCloud, issued by France's ANSSI, mainly answers extraterritorial access risk (Cloud Act and equivalents). Useful for some public or strategic workloads; useless as a substitute for HDS, and often excessive for a classic e-commerce site.
Case 1 — Brochure site, blog, small shop
You collect customer accounts, newsletters, logs. No medical record, no government workload.
What you need: a host that can run GDPR day to day — DPA (processor agreement), data region, listed sub-processors, incident process. Ask for these documents before you sign, not after go-live.
What you do not need: HDS, SecNumCloud. Paying for them "to be safe" raises cost without cutting real risk if your exposure remains that of an ordinary website.
To structure questions before signing, see also GDPR: the right questions before you sign with a host.
Case 2 — Health data
Patient records, teleconsultation, enriched medical calendars, health data warehouses, facility software: as soon as personal health data is hosted, the HDS framework generally applies.
What you need:
- A current HDS attestation
- A scope that covers your stack (app, database, files, backups, any managed ops)
- Explicit location and sub-processing chains
What is not enough: "we are GDPR", "data centre in France", "ISO 27001", or SecNumCloud without HDS on the right product.
Here the decision is no longer "which host has the nicest badge", but "which certified product matches my architecture". Then compare providers in the directory while filtering for health compliance.
Case 3 — Public or highly sensitive workloads
Local government, critical operator, an application exposed to extraterritorial interference, critical industrial secrecy: SecNumCloud can become relevant — sometimes required by the project's framing.
What to verify: which exact service is qualified, reversibility, admin access, sub-processor jurisdictions. A dedicated guide: SecNumCloud: who actually gets a real answer from this qualification?.
If health data is also involved, SecNumCloud does not waive HDS. The two layers stack.
The decision grid
Before you run a price / performance comparison, answer these five questions in writing:
- Which data do you process (personal, health, sensitive, anonymised)?
- Who is the controller, and who is the processor?
- Where must production, backups and logs reside?
- Is extraterritorial access a real business risk, or marketing fear?
- Do you need managed ops, or only infrastructure?
| Dominant answer | Level to require |
|---|---|
| "Ordinary" personal data | GDPR + contractual proof |
| Health data | HDS on the exact scope |
| Public workload / critical foreign access | SecNumCloud (often + GDPR) |
| Health and high sovereignty | HDS + SecNumCloud, without mixing the evidence |
How to read an offer without getting fooled
When a quote lists several labels, demand one line per label:
- GDPR → processor agreement, sub-processor list, location, log retention
- HDS → attestation number, date, technical scope, products covered
- SecNumCloud → framework / level, qualified services, reversibility terms
If sales merges all three into one sentence ("sovereign health-compliant cloud"), ask for the paperwork. Not the slides.
To compare European hosts on these criteria, start with the directory and the guides. And if your core topic is the real location of health data, the investigation health data & HDS is the natural companion to this guide.
Frequently asked questions
Does a brochure website need HDS?
No, unless it processes personal health data. A corporate site, blog or ordinary shop falls under GDPR, not HDS.
Does SecNumCloud replace HDS?
No. SecNumCloud mainly addresses extraterritorial access risk. HDS remains required when you host personal health data in France.
Does GDPR require a French host?
No. It requires guarantees on processing, sub-processing and transfers. A well-documented European host can be enough — if the contract and data flows hold up.
Where should I start if my project is "somewhat sensitive"?
First write down which data you process, for whom, and where it travels. Only then choose the framework: GDPR alone, HDS, SecNumCloud, or a combination.
Next time a quote says "compliant", ask: compliant with which framework, on which scope, with which evidence? If the answer fits in a slogan, it is not an offer yet.