GDPR and Data Hosting in France: The Obligations You Need to Know

Yes, there are rules to follow. To comply with the GDPR in France, you need to treat hosting as a processor arrangement covered by a written contract. That means a signed Data Processing Agreement, technical measures that meet Article 32 and, wherever possible, hosting in France or the European Union. These basics are non-negotiable, and they come before any talk of certifications or audits.
Key takeaways:
- If you outsource the hosting of personal data, you must have a signed written contract that includes a DPA compliant with Article 28 of the GDPR.
- Hosting in the European Union makes compliance easier. It does not guarantee GDPR compliance on its own if the provider is subject to US law or belongs to a foreign parent company.
- ISO 27001, HDS and SecNumCloud certifications show that a provider takes security seriously. On their own, they don't guarantee compliance or rule out legal risk.
- Focus first on technical security measures such as encryption with proper key management and access logging. They reduce the risks tied to unauthorized access and incidents.
- Check your hosting provider's data location, contracts and security certificates regularly, and document the results through audits. That's how you stay GDPR-compliant over time.
Table of Contents
- GDPR and data hosting in France: who is responsible for what, controller or processor
- The Article 28 DPA: what must your hosting contract include?
- Transfers outside the EU, Schrems II and the CLOUD Act: what actually changes for you
- Encryption, logging, backups: the Article 32 checklist
- What ISO 27001 and SecNumCloud certifications really guarantee
- How can you check that a French hosting provider actually complies with the GDPR?
- Why data sovereignty is becoming a strategic factor
- Infrastructure hosted in France to lighten your compliance workload
- Sources
- Frequently Asked Questions
GDPR and data hosting in France: who is responsible for what, controller or processor
A hosting provider that stores or processes personal data on your behalf is almost always a processor under the GDPR, and your company remains the controller. This distinction has real consequences. It decides who answers for what to the CNIL (France's data protection authority) and to your customers.
According to the official text published on EUR-Lex, EU Regulation 2016/679 sets out three principles to keep in mind whenever you make a hosting decision. The first is lawfulness: you need a clear legal basis for every piece of data you host. The second is data minimization, which means you can't store more data than you need. The third is storage limitation, which requires a defined and documented retention period.
As the controller, your company has several concrete obligations:
- Keep a record of processing activities, including for data hosted by a third party.
- Have a legal basis (contract, legal obligation, legitimate interest or consent) for each category of data.
- Tell data subjects that the processing exists and where their data is hosted.
- Make sure people can exercise their rights of access, rectification and erasure, even when their data passes through an external provider.
The hosting provider, for its part, must follow your written instructions, keep the infrastructure secure and alert you to any incident. The CNIL points out that this division of roles is central to the General Data Protection Regulation, and it penalizes both non-compliant controllers and careless processors. Under the consolidated text of the regulation, the most serious violations can bring fines of up to 4% of worldwide annual turnover or €20 million.
In practice, auditing your hosting provider once when you sign the contract isn't enough. Keep a written record of every exchange about security, every policy update and every renewed certificate. If the CNIL inspects you, that documentation is what separates compliance you can prove from compliance you merely claim.
The Article 28 DPA: what must your hosting contract include?
Under Article 28 of the GDPR, you must sign a written Data Processing Agreement with your hosting provider as soon as it processes personal data on your behalf. Without one, your hosting isn't compliant, however good the infrastructure is.
The parties don't get to decide what goes into this contract. At a minimum, it must specify:
- The nature and purpose of the processing: why the provider processes your data and within what specific scope.
- The types of data and categories of data subjects: customers, employees, prospects or patients, depending on your business.
- The duration of the processing, in line with your retention policy.
- The provider's security obligations, with an explicit reference to Article 32.
- The conditions for using sub-processors, which require your prior written authorization, properly documented.
- The procedure for notifying you of a data breach, with a specific deadline.
- The help the provider will give you in handling data subject rights requests.
- How the data will be returned or destroyed when the contract ends.
Some operational clauses deserve special attention during negotiation. The incident notification deadline, for example, has to be short enough to leave you time to meet your own obligations to the CNIL. The provider's help with data subject rights should come with concrete response times, not just a vague promise of "reasonable cooperation."
Pro tip: Before you sign, always ask for an up-to-date, signed and dated DPA, not a generic template downloaded from a third-party website. An unsigned or undated DPA is worthless in a CNIL inspection, even if its content looks complete.
You should also ask for the named list of your provider's sub-processors, such as the data center operator, the backup provider and the technical support service. Each link in that chain must itself be covered by an Article 28-compliant contract. Otherwise, your own compliance has nothing to stand on.
Transfers outside the EU, Schrems II and the CLOUD Act: what actually changes for you
Hosting your data in France or elsewhere in the European Union makes international transfers far less complicated. As the European Data Protection Board explains, it spares you many of the obligations in Chapter V of the GDPR, including standard contractual clauses and transfer impact assessments. That matters: it's often the difference between a light compliance file and a never-ending legal project.
In 2020, the Court of Justice of the European Union's Schrems II ruling struck down the Privacy Shield and tightened scrutiny of transfers to non-EU countries, especially the United States. Since then, a company whose data is hosted by a provider subject to US law must show that the data stays protected from access requests by foreign authorities, even when the physical server is in Europe.
This is where the US CLOUD Act complicates things. The law lets US authorities demand data from an American company, even when that data is stored on a server in France. Physical location alone doesn't give you legal protection. Whether a provider can be forced to hand over your data depends on its legal structure, not just the address of its data center.
Several extra measures strengthen your position against this risk:
- End-to-end encryption, with keys that you control rather than the provider.
- Strict separation between the company that stores the data and the one that holds the decryption keys.
- A regular legal review of your provider's ownership structure and the jurisdiction it falls under.
- A contract clause requiring the provider to tell you about any access request from a foreign authority.
Hosting 100% in France or 100% in the European Union has a real advantage: it simplifies your record of processing, cuts down on paperwork and reassures customers during a tender. It has one limit, though. A French provider owned by a US group may still be exposed to the CLOUD Act. That's why SecNumCloud qualification is gaining ground: it requires ownership independence, which geography alone can't guarantee.
Encryption, logging, backups: the Article 32 checklist
Article 32 of the GDPR requires "appropriate" technical and organizational measures but doesn't give an exhaustive list. That leaves your company and your hosting provider to show that the level of security truly matches the risk. In practice, four categories of measures come up again and again in audits and in French guidance.

Encryption and key management
Encryption should cover data in transit, using protocols such as TLS, and data at rest on storage disks. Behind this technical point lies an often-overlooked question: who holds the decryption key? If your hosting provider can read your data whenever it likes, encryption at rest loses much of its value when an outside legal demand arrives. Best practice is to rotate keys regularly and, where possible, keep the company that stores the encrypted data separate from the one that holds the keys.
Logging and access management
Tracking access to personal data is a core requirement. You need it to detect an intrusion and to prove afterwards who looked at what, and when. The guidance published on Cyber describes a robust logging architecture: centralized logs, protection against tampering and a retention period suited to investigation needs.
Identity and access management (often called IAM) completes the picture. Always apply the principle of least privilege: every account, whether it belongs to a person or a system, should only access the data it strictly needs. A system administrator, for example, has no reason to open customer files during routine maintenance.
Here's what to check with your hosting provider:
- Multi-factor authentication for all administrative access to servers.
- Separate accounts for each privilege level, with no accounts shared between technicians.
- Access logs kept, and available to consult, for a period set in the contract.
- Immediate removal of access when an employee leaves or a contractor's assignment ends.
Backups and business continuity
A backup that has never been tested is just a promise. Require your hosting provider to run regular, documented restore tests, not just describe a backup policy in a sales brochure. Keeping backups in at least two separate locations protects you against a local disaster such as a fire, a flood or a major hardware failure.
Pro tip: Ask your hosting provider when it last ran a real restore test, not a simulated one. A reliable provider can give you a dated report showing the measured recovery time, known as the RTO. If you can't get a precise answer on this, treat it as a warning sign.
Audits and vulnerability management
Complying with Article 32 is an ongoing process, not something frozen at the moment you sign the contract. A vulnerability management cycle includes regular scanning for weaknesses, applying security patches within a reasonable time and holding regular external audits, ideally once a year. If a provider won't share its audit reports, even as a summary, you won't be able to prove your own compliance during an inspection.
What ISO 27001 and SecNumCloud certifications really guarantee
Certifications such as ISO 27001, ISO 27701, HDS and SecNumCloud show effort and seriousness. They are never enough on their own to make your hosting GDPR-compliant. Information security bodies stress this point: according to a published analysis of security certifications, a certification only proves that a standard was met on a given date, for a specific scope.
A few useful reference points:
- ISO 27001 certifies an information security management system, with organizational and technical controls audited by an independent third party.
- ISO 27701 extends this standard to the management of personal data, which makes it a natural complement to the GDPR.
- HDS (Hébergeur de Données de Santé, France's certification for health data hosting) is mandatory for any organization processing medical data in France, with stricter requirements for traceability and availability.
- SecNumCloud, issued by ANSSI (France's national cybersecurity agency), adds legal and ownership independence requirements. These are especially relevant to the CLOUD Act risk discussed above.
The weakness of these labels is their actual scope. A provider can show an ISO 27001 certification that covers its headquarters while its regional data centers fall outside the audit. Before trusting a logo on a sales website, always ask for the certificate itself, its exact scope, its issue date and its expiry date. A certificate that expired six months ago protects nobody.
How can you check that a French hosting provider actually complies with the GDPR?
Before signing with a hosting provider, or renewing an existing contract, work through a series of document and operational checks. This checklist works for a formal tender as well as a routine update to your record of processing.
- Ask for the signed and dated DPA, with the minimum content described above, not a blank template.
- Check the proof of where your data is stored, ideally through an explicit contract commitment naming the countries where the primary servers and backups are located.
- Check the provider's legal identity using its SIREN number (French company registration number) and ownership structure, so you can assess its exposure to foreign jurisdictions.
- Require up-to-date security certificates (ISO 27001, HDS or SecNumCloud depending on your sector), along with their exact scope.
- Ask for a recent audit report, even a summary, rather than a simple sales claim of compliance.
- Check the data retention policy and make sure it matches the retention periods you have declared.
- Test the incident notification procedure: what is the contractual deadline, which communication channel is used and who is the contact person?
- Check the reversibility clauses: how do you get all of your data back if you switch providers, in what format and how quickly?
Some contract clauses are worth negotiating rather than accepting as they stand. A reliable provider shouldn't push back on the notice period for termination, the customer's exclusive ownership of the data or a commitment never to hand data over to commercial third parties.
Pro tip: Before going live, ask for a real portability test. Export a sample of your data and check that you can use the format you receive without relying on the provider's proprietary tools. It's the best sign of whether a reversibility clause means what it says.
Pay close attention to how data comes in and goes out from the negotiation stage onward, not just when a dispute arises. A provider that clearly documents how it securely destroys data, and issues a certificate of destruction, shows a level of maturity that few providers offer unprompted. Our GDPR cloud checklist goes through each of these checks for French businesses.
Why data sovereignty is becoming a strategic factor
GDPR compliance is no longer just a legal box to tick. It's becoming a selling point. In B2B tenders, where data is stored and documented proof of compliance now rank among the selection criteria, sometimes ahead of price.
There's no single answer when you're balancing sovereignty, cost and innovation. A well-documented French hosting provider can cost more than a general-purpose international offering. In return, it can save you months of legal justification with a demanding customer or during a CNIL inspection. The real question isn't "France or abroad?" but "what evidence can I produce, at any time, to prove I'm compliant?"
Our view, based on reviewing many compliance files: ongoing documentation is worth more than one impressive audit. A DPA signed three years ago and never updated, an expired certificate, a record of processing that has never been reviewed: these oversights carry more weight than a single technical flaw. Schedule annual reviews instead of auditing only when there's a crisis.
— Yundera
Infrastructure hosted in France to lighten your compliance workload
Making GDPR compliance simpler often starts with one straightforward choice. Instead of rebuilding every safeguard yourself on general-purpose infrastructure, use a provider that has already dealt with data location, contracts and data portability. That means fully managed private servers hosted in France, with guaranteed data export at any time, on infrastructure that never collects or sells information about you.

You get access to a wide range of pre-installed open source applications for file storage, photo sharing and website hosting, without negotiating each component with a different vendor. Data sovereignty is at the heart of the approach: your data stays in France, under your control, and you can export it at any time if you decide to switch solutions.
If your company is looking for a managed alternative to general-purpose cloud offerings, without the legal uncertainty covered above, visit the Yundera private servers page to see whether this infrastructure fits your needs. Startups and SMBs that want to keep IT costs down while staying in control of their data will also find useful information on the page for solutions for small businesses.
Sources
To go further on any of these points, keep a few key texts close at hand. Regulation (EU) 2016/679 on EUR-Lex is the founding text for any question of principle. Article 28 on Legifrance sets out the contractual obligations toward a processor. The European Data Protection Board's guide to international transfers covers situations outside the EEA. The CNIL publishes practical guides for the French context, including guidance on data breach notification.
- Legifrance — GDPR Article 28
- EDPB — International transfers and obligations
- EUR-Lex — Regulation (EU) 2016/679 (GDPR)
- CNIL — The General Data Protection Regulation
Frequently Asked Questions
What does Article 32 of the GDPR say about data security?
Article 32 requires technical and organizational measures that are "appropriate" to the risk. It doesn't give an exhaustive list, but these measures usually include encryption, access logging and regularly tested backups.
What does Article 34 of the GDPR say about notifying data subjects?
When a data breach is likely to pose a high risk to people's rights and freedoms, you must inform those people directly, in addition to notifying the CNIL.
What does Article 17 of the GDPR say about the right to erasure?
In certain cases, data subjects have the right to have their personal data erased. Your hosting provider must therefore be able to delete data completely and verifiably, not just deactivate an account.
What does Article 21 of the GDPR say about the right to object?
People can object to the processing of their data, especially for direct marketing. The controller therefore needs a fast process to stop that processing at the hosting provider.
Is a hosting provider based in France automatically GDPR-compliant?
No. Hosting in France makes international transfers simpler, but you still need a signed DPA, technical measures that meet Article 32 and a check of the provider's legal structure against foreign laws such as the CLOUD Act.
What is the difference between HDS and SecNumCloud?
HDS applies specifically to health data hosting providers in France. SecNumCloud, issued by ANSSI, certifies a higher level of security along with legal and ownership independence from non-European jurisdictions.
GDPR and Data Hosting in France: The Obligations You Need to Know