Cookie settings

Decide per category. You can come back here at any time from the footer.

NecessaryAlways on

Signing in, your language and theme, and remembering this very choice. The site does not work without them, so there is nothing to switch off.

Google Analytics, to see which pages get used and where people give up. Off until you turn it on, and the data is never passed on to Google Ads.

Aderlo Cloud
Sign inGet started

GDPR and web hosting for an online store: DPA, server location and backups

Grzegorz Ciupek · Updated 6 October 2026 · 9 min read

A store owner is the controller of customer data and the hosting company is a processor, so a data processing agreement under Article 28 GDPR is required. Data and backups are simplest to keep inside the EU; a transfer outside the EEA needs a basis under Chapter V. At Aderlo Cloud the DPA is part of the terms, sites, databases and backups run on servers in Germany (EU), and we notify the customer of a breach within 48 hours at the latest.

Who is who: controller and processor

The store decides which customer data it collects and why, so it is the controller. The host stores that data on its servers and backs it up on the store’s instructions, so it is a processor. The same hosting company is also the controller of data about its own customers, such as invoicing details.

This article is general information, not legal advice. For a specific store, consult a lawyer or a data protection officer.

What a data processing agreement must contain (Article 28)

  • Processing only on documented instructions from the controller.
  • A confidentiality commitment from everyone with access to the data.
  • The security measures required by Article 32.
  • Rules for engaging sub-processors and notice of changes.
  • Assistance to the controller with data subject rights, breaches and impact assessments.
  • Deletion or return of data when the service ends.
  • Information and audit rights.

Where servers and backups may be

The GDPR does not require data to stay in the store’s own country, but a transfer outside the European Economic Area needs a basis under Chapter V: a Commission adequacy decision (for the US, the EU-US Data Privacy Framework for companies certified under it) or standard contractual clauses. It is simplest when servers and backups are in the EU — then there is no transfer at all. Ask about backups separately; they are sometimes held elsewhere.

Security and breaches

  • Article 32 requires measures appropriate to the risk, including encryption, the ability to restore data promptly after an incident, and regular testing. For a store that means TLS, account isolation, malware protection and backups that can actually be restored.
  • Article 33: the controller notifies the supervisory authority within 72 hours of becoming aware of a breach, and the processor notifies the controller without undue delay. The sooner the host tells the store, the more of those 72 hours remain.

Questions to ask your host

QuestionWhy it mattersAderlo Cloud
Is there a DPA?Required by Article 28yes, part of the terms, in 5 languages — read it
Where are the servers?A transfer outside the EEA needs a legal basisFalkenstein, Germany (EU), Hetzner Online GmbH
Where are the backups?Backups are personal data tooin the EU, on separate hardware (Hetzner Storage Box)
Who are the sub-processors?You need to know who has accesslisted in the DPA; 14 days’ notice of changes, with a right to object
How soon will I hear about a breach?You have 72 hours to reportwithout undue delay, within 48 hours at the latest
What happens to data when I leave?Return or deletionreturned or deleted, as you choose
Can I audit?Article 28(3)(h)yes, with 30 days’ notice
Based on the Aderlo Cloud DPA, version of 1 August 2026.

Store, newsletter and analytics data

  • Orders and customer accounts — the basis is usually performance of a contract (Article 6(1)(b)); keep them as long as tax law requires, not longer.
  • Newsletter — you need consent you can demonstrate; a self-hosted autoresponder (e.g. NetSendo) keeps the list in your own database, in the EU.
  • Analytics and cookies — tools that store information on the visitor’s device generally need consent under the ePrivacy Directive; keep them off until the visitor turns them on.
  • AI agents — limit an agent’s access to customer databases to read-only, or switch it off; on Aderlo Cloud agent access is off by default for every database.
Aderlo Cloud DPA →

Frequently asked questions

Is hosting in Germany GDPR-compliant for a store elsewhere in the EU?
Yes. Germany is in the EU, so storing data on servers there is not a transfer outside the EEA. You still need a DPA with the host.
Do I have to sign a DPA separately?
Not at Aderlo Cloud — the DPA is an annex to the terms and takes effect when the hosting contract is concluded.
Does a store outside the EU have to comply with the GDPR?
Yes, if it offers goods or services to people in the EU or monitors their behaviour (Article 3(2) GDPR).

Sources