EU-Only Hosting: The Test That Punishes Honest Providers
“EU region” and “EU-only” are different products, and most buyers are sold the first while believing they bought the second.
We set out to score providers on the four axes that would make a hosting arrangement genuinely EU-only. The exercise produced a result we didn’t expect, and it says more about the method than about the companies.
The four axes
A server in Frankfurt satisfies one of these. EU-only needs all four.
1. Legal entity domicile. Who you contract with. A US-incorporated provider is subject to US compulsory process regardless of where the disk is — the residency-versus-sovereignty distinction covers why.
2. Data centre location. Where the bytes sit. The only one anybody advertises.
3. Subprocessors. Who else touches the data in the course of delivering the service — fraud screening, identity verification, email delivery, analytics, CDN, backups. This is the axis nobody checks and it’s where “EU-only” usually breaks.
4. Support and operations staff location. Who can read your data while helping you. A ticket that gets escalated to an engineer outside the EU is an access event, whatever the server’s postcode.
What we found
| Provider | Entity | EU data centres | Subprocessors published | Ops location |
|---|---|---|---|---|
| Hetzner | Hetzner Online GmbH (DE, HRB 6089) | Yes — plus US and Finnish | None we could find | Not disclosed |
| IONOS | IONOS SE (.de) / IONOS INC. (.com) | Yes | None we could find | Not disclosed |
| Hostinger | Hostinger International Ltd (Cyprus, EU) | Yes — plus US, Brazil, Singapore, Indonesia | Yes — named, detailed | UK, NL, LT, CY disclosed |
| nazwa.pl | Not established from its pages | Polish | None we could find | Not disclosed |
| dhosting | dhosting.pl Sp. z o.o. (PL, KRS 0000336780) | Polish | None we could find | Not disclosed |
Now look at that table honestly.
The awkward finding
The provider that scores worst on axis 3 is the only one that answered the question.
Hostinger publishes a detailed account of who processes your data, where, and under what legal basis. It names specific subprocessors. It states which of its server locations sit outside the EEA. So it accumulates disclosures that look like failures.
Hetzner, IONOS, nazwa.pl and dhosting appear cleaner — because we found nothing to read. That is not the same as having no subprocessors. Every hosting company uses payment processing, email delivery and fraud screening; the question is only whether you can see the list. Hetzner even has a /legal/subprocessors URL, but it redirects to its general legal notice rather than a list.
So a scoring exercise like this rewards opacity, and any “EU-only hosting” ranking built this way is measuring disclosure practice while claiming to measure data flows. We’re publishing the table because the axes are right, and flagging that the third column is not evidence about the providers — it’s evidence about us.
The correct move is to ask rather than infer. Under GDPR you’re entitled to know who processes your data as a controller engaging a processor. Request the subprocessor list and the data processing agreement in writing before you buy. A provider that won’t supply one has answered the question.
We wrote the eight questions worth sending — and found that three of six providers publish a DPA at a findable URL, that nobody offers an hour-based breach notification SLA because the Regulation doesn’t ask processors for one, and that the meaningful difference is what the breach notice must contain.
What a real answer looks like
Since Hostinger is the one that documents this, its policy is worth reading as a template for what you should be asking everyone else. Four things in it are instructive.
The entity is stated plainly. “Hostinger International Ltd is based in Cyprus, which is a member of EU.” That settles axis 1 — and it’s a detail we’d previously been unable to confirm from its other legal pages.
The processing locations are enumerated: the United Kingdom, Netherlands, Lithuania or Cyprus, “and in other jurisdictions as necessary.”
The non-EU server locations are admitted directly: “Some of our servers are located outside EU or European Economic Area (EEA), such as US, Brazil, Singapore, Indonesia” — with transfers covered by standard contractual clauses under Article 46. Which means picking an EU region is your job, not the default.
And this sentence, which every buyer of “EU-only” hosting should read twice. On data localisation obligations, the policy says it may keep personal information within a jurisdiction’s boundaries where legally obliged — and then:
“You acknowledge that while doing so, we may continue to collect, store and use your Personal Information elsewhere.”
That is an honest statement of how localisation actually works at a global provider: the regulated data stays put, and the operational metadata around it may not. Nobody else in this comparison told us that, which doesn’t mean it isn’t true of them too.
Why strict EU-only is hard with anyone
The named subprocessors in that policy illustrate the general problem. Delivering hosting involves:
- Fraud screening on orders — Hostinger names Ravelin
- Identity verification, in this case processing biometric data during the session — it names iDenfy
- AI and adjacent services — it names nexos.ai and Oxylabs Studio AI
- Advertising and analytics tooling — Facebook and Google are named
Some of those are EU companies and some aren’t, and the point isn’t to indict any of them. It’s that the operational chain behind a €20 server has a dozen participants, and “EU-only” in the strict sense — no non-EU entity touching anything, ever — is close to unachievable with any mainstream provider at consumer prices.
If you genuinely need that, you’re not shopping for a VPS from a price comparison. You’re procuring from a provider that will contract to it, and you should expect to pay several times these rates and to read a lot of paperwork.
The good-enough tier
For everyone else, here’s the honest ladder.
Tier 1 — EU entity, EU region, keys you hold. An EU-incorporated provider, a European data centre you selected deliberately, and encryption at rest with keys outside the provider’s control. That last part does more work than any of the four axes above, because a provider who cannot decrypt your data is in a different position from one holding your plaintext. This is the sensible target for regulated-adjacent work.
Tier 2 — EU region, documented transfers. A non-EU provider’s European region, with the subprocessor list and SCCs on file so your transfer assessment is grounded in something. Fine for the large majority of commercial workloads.
Tier 3 — pick a region and move on. If you handle no special-category data and no regulated data, this is genuinely fine and the rest is procurement theatre.
And confirm which rule binds you before paying a premium. Across four country guides the cited rule repeatedly wasn’t the operative one — British Columbia repealed its residency requirement in 2021, India’s DPDP Act permits transfers absent a notified restriction, and UK adequacy was renewed to 2031. Establish the obligation, then buy for it.
The providers
Hetzner — the strongest answer on the axes that are checkable: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Ansbach registration office HRB 6089, German data centres, no US parent. €19.99 for 4GB on the CPX line plus €0.50/month for an IPv4 address. Two caveats: it also sells US regions in Ashburn and Hillsboro, so choose your location deliberately; and we could not find a published subprocessor list, so ask for one. Its Nuremberg facility answered a German probe in 0.60ms.
IONOS — genuinely European and the best value per core here, around £9 or $11 for four vCores and 4GB. Buy from your local European site, not the .com: the German imprint names IONOS SE and the .com imprint names IONOS INC., which changes axis 1 entirely. Watch the short promotional term. No subprocessor list found.
Hostinger — the cheapest capable option at $11.99 renewal for 4GB, and the most transparent provider in this comparison by a wide margin. Entity confirmed as Hostinger International Ltd in Cyprus. Because it documents its subprocessors and its non-EEA server locations, it looks worse on a naive scorecard and is easier to run a real transfer assessment against. Select an EU region explicitly — its policy is clear that some locations sit outside the EEA.
nazwa.pl — a Polish provider with Polish infrastructure, useful if you want an EU entity outside the German-French duopoly or your users are in Central Europe. We could not establish its legal entity from the pages we read, so treat axis 1 as unverified and ask.
dhosting — the other Polish option, and it does publish its entity: dhosting.pl Sp. z o.o., NIP 7010198361, KRS 0000336780. A Polish limited company on the Polish commercial register, which is exactly the kind of specificity axis 1 needs.
How we checked this
The entity findings come from providers’ own published pages, read on 17–18 August 2026: Hetzner’s legal notice giving Hetzner Online GmbH at Industriestr. 25, 91710 Gunzenhausen with the Ansbach registration office and HRB 6089; IONOS SE on the German imprint and IONOS INC. on the .com imprint; Hostinger’s privacy policy stating that “Hostinger International Ltd is based in Cyprus, which is a member of EU”; and dhosting.pl Sp. z o.o. with NIP 7010198361 and KRS 0000336780 from its own site.
The Hostinger material — the processing locations of the United Kingdom, Netherlands, Lithuania and Cyprus “and in other jurisdictions as necessary”; the statement that some servers sit outside the EU or EEA “such as US, Brazil, Singapore, Indonesia”; the standard contractual clauses under Article 46; the named third parties Ravelin, iDenfy, nexos.ai and Oxylabs Studio AI; and the quoted sentence from its data localisation section — is all from section 11 of its published privacy policy.
The third column is a statement about our search, not about the providers, and we’ve said so in the body because it’s the article’s most important caveat. We looked for subprocessor lists at the conventional URLs and in privacy policies. Not finding one does not mean a provider has no subprocessors — every hosting business has them. Hetzner’s /legal/subprocessors path resolves but redirects to its general legal notice. It’s entirely possible these lists exist in customer-facing data processing agreements we have no access to, which is precisely why the article tells you to request one rather than trusting a table like ours.
Axis 4 is the weakest column here. Only Hostinger disclosed processing locations for staff and affiliates. For the others we found nothing, and we have not contacted any provider’s sales or support to ask — which is the obvious next step and one a buyer can take in a single email. We haven’t done it, so we haven’t scored it.
We are not lawyers and this is not legal advice. The GDPR points — that a controller is entitled to know its processor’s subprocessors, and that transfers outside the EEA need an Article 46 mechanism — are the general shape of the rules, not advice about your obligations.
What we did not do: hold accounts with any of these providers, request a data processing agreement, audit any subprocessor relationship, verify where any support engineer physically sits, or test whether encryption-at-rest arrangements would resist a production order. nazwa.pl’s entity and four of five providers’ subprocessor positions are unresolved rather than clean.
The host links above are affiliate links. The most transparent provider in this comparison scores worst on our own table, and we’ve said that the table is the problem rather than quietly letting it stand — and the highest-value recommendation here, holding your own encryption keys, costs nothing and earns us nothing.
FAQ
What is EU-only hosting?
Hosting where the provider’s legal entity, data centres, subprocessors and operations staff are all within the EU. Most products marketed as EU hosting satisfy only the second of those.
Is an EU data centre enough for GDPR?
For the storage question, often yes. But a US-incorporated provider with an EU data centre remains subject to US compulsory process, and subprocessors or support staff outside the EU are separate access routes that a transfer assessment should address.
How do I find out a host’s subprocessors?
Ask for the subprocessor list and the data processing agreement in writing before buying. As a controller engaging a processor you’re entitled to know. Very few providers publish this openly, so absence from a website tells you little — a refusal to supply it on request tells you a lot.
Which providers are genuinely EU-incorporated?
Of the ones we checked: Hetzner Online GmbH in Germany, IONOS SE if you buy from a European site rather than the .com, Hostinger International Ltd in Cyprus, and dhosting.pl Sp. z o.o. in Poland. We could not establish nazwa.pl’s entity from its published pages.
Does picking an EU region guarantee my data stays in the EU?
No. One provider’s policy states plainly that some of its servers are outside the EEA and that where it does localise data it “may continue to collect, store and use your Personal Information elsewhere.” Choosing the region is a step you have to take deliberately, and it covers the primary data rather than everything.
Is truly EU-only hosting possible?
At consumer VPS prices, rarely in the strict sense — fraud screening, identity verification, email delivery and analytics bring in additional parties. If you need a contractual guarantee, that’s a procurement exercise with a specialist provider, not a price comparison.
What should most companies actually do?
An EU-incorporated provider, an EU region you selected on purpose, and encryption at rest with keys you hold outside the provider’s control. The encryption does more for your exposure than any of the other axes.