If you run a UK-based business that handles customer data, your hosting provider is a critical part of your GDPR compliance. Get it wrong, and you could face fines of up to £17.5 million or 4% of global turnover.
This guide covers what UK GDPR means for your hosting choices, and how to evaluate providers.
---
Part 1: The Post-Brexit GDPR Landscape
UK GDPR vs EU GDPR
Since Brexit, the UK has its own version of GDPR — UK GDPR — which is substantially similar to EU GDPR but operates independently.
| Aspect | UK GDPR | EU GDPR |
|---|---|---|
| Regulator | ICO (Information Commissioner's Office) | EDPB (European Data Protection Board) |
| Territorial Scope | Data of UK residents | Data of EU residents |
| Adequacy Decision | UK has EU adequacy decision (until review) | EU adequacy decision for UK (under review) |
| Maximum Fine | £17.5 million or 4% of turnover | €20 million or 4% of turnover |
| Key Principle | Data must not leave UK without safeguards | Data must not leave EU without safeguards |
The Adequacy Decision Risk
The EU's adequacy decision for the UK is currently under review. If revoked, UK-based businesses handling EU customer data would need additional safeguards (Standard Contractual Clauses) — adding complexity and cost.
What this means for your hosting: If you host EU customer data, choosing a UK provider with UK data centres doesn't automatically satisfy EU GDPR. You may need SCCs regardless. But for UK-only customer data, a UK provider keeps everything under UK jurisdiction — the simplest compliance path.
---
Part 2: How Hosting Affects Your GDPR Compliance
Data Processor vs Data Controller
Under UK GDPR: - You (the business) are the Data Controller — you decide what data to collect and why - Your hosting provider is the Data Processor — they process data on your instructions
As data controller, you are legally required to: 1. Choose a processor that provides "sufficient guarantees" to meet GDPR requirements 2. Have a written contract with your processor covering GDPR-mandated terms 3. Conduct due diligence on your processor's security measures 4. Document your processor relationships in your Records of Processing Activities (ROPA)
What Your Hosting Provider Must Provide
| Requirement | What to Look For |
|---|---|
| Data Processing Agreement (DPA) | Written contract with GDPR-mandated terms |
| Security Measures | ISO 27001, SOC 2, or equivalent certification |
| Data Residency | Guarantee that data stays in specified jurisdiction |
| Sub-processors | List of any sub-processors and right to object |
| Breach Notification | Commitment to notify you within 24-72 hours |
| Data Deletion | Process for secure deletion when contract ends |
| Data Portability | Ability to export data in standard formats |
| Audit Rights | Right to inspect or audit their security practices |
---
Part 3: The US CLOUD Act Risk
What Is the CLOUD Act?
The US Clarifying Lawful Overseas Use of Data (CLOUD) Act (2018) allows US law enforcement to request data from US-owned companies regardless of where the data is stored.
This means: If your hosting provider is a US company (even if they have a UK data centre), your data could be accessible to US authorities under US law.
Why This Matters for UK GDPR Compliance
UK GDPR requires that personal data of UK residents has "equivalent protection" when transferred outside the UK. The ICO has expressed concerns about the CLOUD Act's impact on UK data protection.
The practical risk: - Low for most small businesses — US authorities rarely request hosting data - Medium for businesses in regulated sectors (finance, healthcare, legal) - High if you handle politically sensitive data, work with UK government, or operate in sectors where data sovereignty is explicitly required
Providers by Jurisdiction
| Provider Type | Examples | CLOUD Act Exposure | UK GDPR Simplicity |
|---|---|---|---|
| UK-owned, UK-hosted | Hostingowy, UKFast, Krystal | None | ✅ Simplest |
| EU-owned, UK-hosted | Hetzner, OVHcloud | None | ✅ Straightforward |
| US-owned, UK data centre | AWS, Google Cloud, Azure, DigitalOcean, Vultr, Linode | ⚠️ Yes | ⚠️ Requires documentation |
| US-owned, US-hosted | All US providers | 🔴 Yes | 🔴 Complex SCCs needed |
---
Part 4: GDPR Hosting Checklist
Use this checklist when evaluating a hosting provider:
Legal & Compliance
- [ ] Is the provider UK-registered or EU-registered? (Not US-owned?) - [ ] Do they offer a GDPR-compliant Data Processing Agreement (DPA)? - [ ] Are their data centres in the UK or EU? - [ ] Do they list all sub-processors? - [ ] What is their breach notification SLA? - [ ] Do they offer audit rights?Technical Security
- [ ] Encryption at rest (AES-256 or equivalent)? - [ ] Encryption in transit (TLS 1.2+)? - [ ] ISO 27001 or SOC 2 certification? - [ ] Regular security updates and patching? - [ ] DDoS protection? - [ ] Backup and disaster recovery? - [ ] Access controls and logging?Operational
- [ ] UK-based support with UK business hours? - [ ] Clear data deletion process on contract end? - [ ] Data export tools for portability? - [ ] Uptime SLA (99.9%+)? - [ ] Transparent pricing with no hidden fees?---
Part 5: Common GDPR Hosting Questions
"Can I use a US provider if I sign a DPA?"
Yes, but you need additional safeguards. The ICO requires you to assess the transfer risk and document your decision. For US providers, this typically means: 1. Signing Standard Contractual Clauses (SCCs) 2. Conducting a Transfer Impact Assessment (TIA) 3. Documenting supplementary measures (encryption, access controls) 4. Reviewing the provider's data access policies"Does using a UK data centre with a US provider solve the problem?"
Partially. Your data is physically in the UK, but the US-owned provider can still be compelled by US authorities to hand over data under the CLOUD Act. The physical location helps, but doesn't eliminate the US jurisdiction risk."What about EU GDPR if I use a UK provider?"
If you handle EU customer data, you need additional safeguards under EU GDPR. The UK has an EU adequacy decision (currently), but this is under review. If hosting with a UK provider for EU data, you should have SCCs in place as a backup."Do I really need to worry about this as a small business?"
Honestly? For a small SaaS with a handful of customers, the risk is low. But GDPR compliance is about demonstrating good faith efforts. If you can show you chose a UK provider with UK data centres because of data protection concerns, that's a strong compliance signal. If you chose the cheapest US provider without any due diligence, that's a weaker position if the ICO comes calling."Can Hostingowy provide a DPA?"
Yes. All Hostingowy customers are covered by our Data Processing Agreement, which includes: - UK GDPR-mandated terms - Data stays in UK jurisdiction - 24-hour breach notification - Right to audit - 30-day data export on termination - Full list of sub-processors (currently none — we own our hardware)---
Part 6: Quick Decision Guide
| Your Situation | Recommended Hosting Approach |
|---|---|
| Side project, no customer data | Any provider works |
| UK startup with customer PII | UK-owned provider with UK data centre |
| UK business in regulated sector | UK-owned provider, explicit DPA, audit rights |
| UK business with EU customers | UK-owned provider + SCCs for EU data |
| Enterprise with compliance team | Multi-provider strategy with documented due diligence |
---
Summary
GDPR hosting compliance doesn't have to be complicated. The simplest path:
- Choose a UK-owned provider with UK data centres
- Sign a DPA with GDPR-mandated terms
- Document your decision in your ROPA
- Review annually — provider status, adequacy decisions, and your data flows change
For most UK businesses, the combination of a UK-owned provider, UK data centres, and a proper DPA provides the strongest compliance position with the least ongoing overhead.
---
Hostingowy is a UK-owned VPS hosting company with servers in UK data centres. All plans include a GDPR-compliant DPA. Deploy your first VPS in under 60 seconds — no US jurisdiction, no CLOUD Act exposure, just straightforward UK hosting.