Hosting outside the EU: what it means legally
What changes when your website or its data is processed outside the European Union, which transfer mechanisms exist, and how to keep it simple.
The short answer
Personal data may be transferred outside the European Union only on a lawful basis for that transfer. There are three families: an adequacy decision, where the Commission has determined that a country or framework provides adequate protection; appropriate safeguards, most commonly the standard contractual clauses combined with a transfer impact assessment and technical measures; and a small set of derogations for specific situations, which are not intended for routine processing. For a small business, the simplest approach is usually to avoid the question by choosing providers that process in the EU, which is now available for hosting, email, CRM, analytics and most other website services. Where a non-EU provider is genuinely needed, document the transfer, the mechanism and the assessment, because that documentation is exactly what a client questionnaire or a supervisory authority asks for. The transfers businesses most often overlook are the indirect ones: a content delivery network’s global locations, a support team accessing systems from abroad, and a backup replicated to another region.
The mechanisms, in plain terms
| Mechanism | What it is | When it fits a small business |
|---|---|---|
| Adequacy decision | The Commission has recognised a country or framework as providing adequate protection | Simplest route where it applies; check the provider’s certification is current |
| Standard contractual clauses | Commission-approved contract terms between exporter and importer, plus an assessment of the destination and supplementary measures where needed | Common with large providers; they supply the clauses, you keep the documentation |
| Binding corporate rules | Approved internal rules within a corporate group | Not relevant to a small business |
| Derogations | Explicit consent, contract necessity, legal claims, and others, for occasional situations | Not a basis for routine hosting or analytics |
| No transfer | Provider processes only in the EU | The simplest, and the one we recommend by default |
Keeping it simple
- List where each provider processes data, from their documentation, not from where their head office is.
- Prefer EU regions where the provider offers a choice, and select them explicitly rather than by default.
- Confirm in writing: the processing agreement, the regional commitment, the sub-processor list.
- For non-EU providers, identify the mechanism and obtain the clauses or certification reference.
- Write the assessment where standard contractual clauses apply, including your supplementary measures.
- Check the indirect transfers: content delivery, support access, backups, monitoring tools.
- Record it all in your record of processing, and update at renewal.
- Reassess when frameworks or provider arrangements change, which happens.
Why we default to EU processing
Not because non-EU providers are unlawful, but because the compliance overhead is real and recurring: assessments to write, frameworks to monitor, questions to answer in every client questionnaire, and a risk of arrangements changing. EU processing for hosting, email, CRM and analytics is available at no meaningful cost or quality penalty for a typical business website, and it removes the topic from the compliance list entirely. We keep non-EU services for cases where there is no acceptable European alternative, and we document those specifically.
What this means for you
Data leaving the EU needs a lawful transfer mechanism and documentation to match. Prefer providers that process in the EU, select EU regions explicitly, and confirm it in writing. Where a non-EU service is necessary, identify the mechanism, write the assessment, cover the indirect transfers including support access, and record everything. This is general information rather than legal advice; complex transfers deserve a qualified opinion.
Frequently asked questions
Is it illegal to use an American hosting provider?
No. Transfers to countries outside the EU are permitted with a lawful mechanism. Several major providers operate under an adequacy framework or offer standard contractual clauses together with technical safeguards and EU processing regions. What is not permitted is transferring without any mechanism or assessment. The practical question for a small business is whether you need the complexity, since EU regions are widely available.
Does using a global content delivery network count as a transfer?
Serving cached files from locations worldwide involves processing, and access to logs and support from outside the EU is a transfer. Most major networks address this with contractual mechanisms, regional controls and documentation. Check what your provider offers, choose EU-restricted options where they exist for anything containing personal data, and record the arrangement.
What is the simplest compliant setup?
Choose hosting, email, CRM and analytics providers that process in the EU, confirm it in writing in their documentation or agreement, and note it in your record of processing. That removes the transfer question for the main systems. Where a non-EU tool is genuinely necessary, document the mechanism and the reason rather than adopting it silently.
Sources
- European Commission: International dimension of data protection (accessed 2026-09-12)
- EUR-Lex: Regulation (EU) 2016/679, Chapter V (accessed 2026-09-14)