Hosting outside the EU: what it means legally

What changes when your website or its data is processed outside the European Union, which transfer mechanisms exist, and how to keep it simple.

4 minread 776words last updated

The short answer

Personal data may be transferred outside the European Union only on a lawful basis for that transfer. There are three families: an adequacy decision, where the Commission has determined that a country or framework provides adequate protection; appropriate safeguards, most commonly the standard contractual clauses combined with a transfer impact assessment and technical measures; and a small set of derogations for specific situations, which are not intended for routine processing. For a small business, the simplest approach is usually to avoid the question by choosing providers that process in the EU, which is now available for hosting, email, CRM, analytics and most other website services. Where a non-EU provider is genuinely needed, document the transfer, the mechanism and the assessment, because that documentation is exactly what a client questionnaire or a supervisory authority asks for. The transfers businesses most often overlook are the indirect ones: a content delivery network’s global locations, a support team accessing systems from abroad, and a backup replicated to another region.

The mechanisms, in plain terms

MechanismWhat it isWhen it fits a small business
Adequacy decisionThe Commission has recognised a country or framework as providing adequate protectionSimplest route where it applies; check the provider’s certification is current
Standard contractual clausesCommission-approved contract terms between exporter and importer, plus an assessment of the destination and supplementary measures where neededCommon with large providers; they supply the clauses, you keep the documentation
Binding corporate rulesApproved internal rules within a corporate groupNot relevant to a small business
DerogationsExplicit consent, contract necessity, legal claims, and others, for occasional situationsNot a basis for routine hosting or analytics
No transferProvider processes only in the EUThe simplest, and the one we recommend by default

Keeping it simple

  1. List where each provider processes data, from their documentation, not from where their head office is.
  2. Prefer EU regions where the provider offers a choice, and select them explicitly rather than by default.
  3. Confirm in writing: the processing agreement, the regional commitment, the sub-processor list.
  4. For non-EU providers, identify the mechanism and obtain the clauses or certification reference.
  5. Write the assessment where standard contractual clauses apply, including your supplementary measures.
  6. Check the indirect transfers: content delivery, support access, backups, monitoring tools.
  7. Record it all in your record of processing, and update at renewal.
  8. Reassess when frameworks or provider arrangements change, which happens.

Why we default to EU processing

Not because non-EU providers are unlawful, but because the compliance overhead is real and recurring: assessments to write, frameworks to monitor, questions to answer in every client questionnaire, and a risk of arrangements changing. EU processing for hosting, email, CRM and analytics is available at no meaningful cost or quality penalty for a typical business website, and it removes the topic from the compliance list entirely. We keep non-EU services for cases where there is no acceptable European alternative, and we document those specifically.

What this means for you

Data leaving the EU needs a lawful transfer mechanism and documentation to match. Prefer providers that process in the EU, select EU regions explicitly, and confirm it in writing. Where a non-EU service is necessary, identify the mechanism, write the assessment, cover the indirect transfers including support access, and record everything. This is general information rather than legal advice; complex transfers deserve a qualified opinion.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

Is it illegal to use an American hosting provider?

No. Transfers to countries outside the EU are permitted with a lawful mechanism. Several major providers operate under an adequacy framework or offer standard contractual clauses together with technical safeguards and EU processing regions. What is not permitted is transferring without any mechanism or assessment. The practical question for a small business is whether you need the complexity, since EU regions are widely available.

Does using a global content delivery network count as a transfer?

Serving cached files from locations worldwide involves processing, and access to logs and support from outside the EU is a transfer. Most major networks address this with contractual mechanisms, regional controls and documentation. Check what your provider offers, choose EU-restricted options where they exist for anything containing personal data, and record the arrangement.

What is the simplest compliant setup?

Choose hosting, email, CRM and analytics providers that process in the EU, confirm it in writing in their documentation or agreement, and note it in your record of processing. That removes the transfer question for the main systems. Where a non-EU tool is genuinely necessary, document the mechanism and the reason rather than adopting it silently.

Sources

  1. European Commission: International dimension of data protection (accessed 2026-09-12)
  2. EUR-Lex: Regulation (EU) 2016/679, Chapter V (accessed 2026-09-14)