Independent comparison · no paid rankings
Home / Blog / Compliance / Transfers outside the EU: mapping dependencies behind your hosting

Transfers outside the EU: mapping dependencies behind your hosting

A datacenter in Roubaix does not guarantee zero transfer: US CDN, India support, replicated backup — the flow map is missing on nine contracts out of ten.

Hébergeurs.eu Editorial Team 4 min read Updated Jul 19, 2026

Your impact assessment says "OVH France hosting." The auditor opens HTTP headers: Cloudflare US. Logs go to Datadog US. Support tickets are handled from a tool hosted in Ohio. The register said "EU" — reality is a transatlantic graph nobody had drawn.

Mapping dependencies is not checking a legal box. It is tracing every subprocessor that touches personal data — not just the pin on the datacenter map.

Why server location is not enough

A French host can run your origin in Roubaix while enabling third-party services: CDN, anti-DDoS, monitoring, email, support chat, object backup. Each integration can create a transfer outside the European Union if processing or admin access sits elsewhere. The end client sees only your domain; the DPO must see the full chain.

Many teams discover a US transfer the day the auditor asks for the CDN DPA — not the day hosting was chosen.

Layers to audit behind hosting

LayerExamplesTransfer risk
Edge / CDNCloudflare, FastlyUS entity common
OriginVPS FranceOK if sole link
BackupS3 us-east-1Transfer if personal data
MonitoringDatadog, New RelicUS by default
SupportZendesk, IntercomIf tickets contain PII
EmailSendGrid, MailgunMetadata and content

Five-step method

Start by listing all personal data flows: visitors, customers, administrators. Identify processors and subprocessors per flow, with seat country and processing zone. Verify the GDPR Article 44 mechanism: adequacy decision, standard contractual clauses or binding corporate rules.

Write a TIA for countries without adequacy — the United States remains the most frequent case. Update register, DPA and privacy policy so they reflect the real diagram, not the initial intention.

Schrems II and supplementary measures

Signed SCCs do not close the file if government access remains plausible. The TIA must document encryption, pseudonymisation, minimisation and, where relevant, encryption keys outside the concerned country. Cross-read with Schrems II and hosting and Cloud Act and contract to align contract, architecture and register.

The peak: chosen region is not the data border

Decide and move forward without blind spots

Draw the production, staging and backup graph with actor, country and legal basis on each arrow. Replace US services with European equivalents when possible without breaking the business. Document a TIA for each remaining US flow and update the GDPR register accordingly. Validate the diagram with the technical team before legal review — a register without architecture stays fragile. See our compliance guides and directory to compare hosts that clearly document subprocessors and regions.

Frequently asked questions

France = zero transfer?

No. CDN, support, backup, US parent company or SaaS tools can transfer data even with a French origin. The datacenter is one link only.

How to map?

Draw the full path with actor, country and legal basis on each arrow. Start with production, then backups, logs and support tools.

Do SCCs suffice?

After Schrems II: SCCs plus supplementary measures plus TIA if the country is at risk. Signing without analysis is not enough.

Indispensable US service?

Minimise, encrypt, document a TIA, evaluate an EU alternative and inform data subjects if required. The choice must be dated and owned.


The French datacenter is a node — not the border. Trace the arrows to the end.

HDS & compliance hosts

Filter European hosts by HDS, ISO and data residency.

Browse HDS hosts
Blog

Related reading

All articles →