A store owner is the controller of customer data and the hosting company is a processor, so a data processing agreement under Article 28 GDPR is required. Data and backups are simplest to keep inside the EU; a transfer outside the EEA needs a basis under Chapter V. At Aderlo Cloud the DPA is part of the terms, sites, databases and backups run on servers in Germany (EU), and we notify the customer of a breach within 48 hours at the latest.
Who is who: controller and processor
The store decides which customer data it collects and why, so it is the controller. The host stores that data on its servers and backs it up on the store’s instructions, so it is a processor. The same hosting company is also the controller of data about its own customers, such as invoicing details.
This article is general information, not legal advice. For a specific store, consult a lawyer or a data protection officer.
What a data processing agreement must contain (Article 28)
- Processing only on documented instructions from the controller.
- A confidentiality commitment from everyone with access to the data.
- The security measures required by Article 32.
- Rules for engaging sub-processors and notice of changes.
- Assistance to the controller with data subject rights, breaches and impact assessments.
- Deletion or return of data when the service ends.
- Information and audit rights.
Where servers and backups may be
The GDPR does not require data to stay in the store’s own country, but a transfer outside the European Economic Area needs a basis under Chapter V: a Commission adequacy decision (for the US, the EU-US Data Privacy Framework for companies certified under it) or standard contractual clauses. It is simplest when servers and backups are in the EU — then there is no transfer at all. Ask about backups separately; they are sometimes held elsewhere.
Security and breaches
- Article 32 requires measures appropriate to the risk, including encryption, the ability to restore data promptly after an incident, and regular testing. For a store that means TLS, account isolation, malware protection and backups that can actually be restored.
- Article 33: the controller notifies the supervisory authority within 72 hours of becoming aware of a breach, and the processor notifies the controller without undue delay. The sooner the host tells the store, the more of those 72 hours remain.
Questions to ask your host
| Question | Why it matters | Aderlo Cloud |
|---|---|---|
| Is there a DPA? | Required by Article 28 | yes, part of the terms, in 5 languages — read it |
| Where are the servers? | A transfer outside the EEA needs a legal basis | Falkenstein, Germany (EU), Hetzner Online GmbH |
| Where are the backups? | Backups are personal data too | in the EU, on separate hardware (Hetzner Storage Box) |
| Who are the sub-processors? | You need to know who has access | listed in the DPA; 14 days’ notice of changes, with a right to object |
| How soon will I hear about a breach? | You have 72 hours to report | without undue delay, within 48 hours at the latest |
| What happens to data when I leave? | Return or deletion | returned or deleted, as you choose |
| Can I audit? | Article 28(3)(h) | yes, with 30 days’ notice |
Store, newsletter and analytics data
- Orders and customer accounts — the basis is usually performance of a contract (Article 6(1)(b)); keep them as long as tax law requires, not longer.
- Newsletter — you need consent you can demonstrate; a self-hosted autoresponder (e.g. NetSendo) keeps the list in your own database, in the EU.
- Analytics and cookies — tools that store information on the visitor’s device generally need consent under the ePrivacy Directive; keep them off until the visitor turns them on.
- AI agents — limit an agent’s access to customer databases to read-only, or switch it off; on Aderlo Cloud agent access is off by default for every database.
Frequently asked questions
- Is hosting in Germany GDPR-compliant for a store elsewhere in the EU?
- Yes. Germany is in the EU, so storing data on servers there is not a transfer outside the EEA. You still need a DPA with the host.
- Do I have to sign a DPA separately?
- Not at Aderlo Cloud — the DPA is an annex to the terms and takes effect when the hosting contract is concluded.
- Does a store outside the EU have to comply with the GDPR?
- Yes, if it offers goods or services to people in the EU or monitors their behaviour (Article 3(2) GDPR).