Trusted across 27 EU member statesClient Area
Legal

Our GDPR Commitment

Last updated: 1 January 2026

Why This Page Exists

GDPR compliance was the reason WebHostingEurope was founded, not a checkbox added later. This page explains, in plain terms, what that commitment actually means in practice.

Data Controller vs. Data Processor

For your account and billing information, we act as the data controller. For content you store on our hosting infrastructure — your website, databases and email — we act as a data processor on your behalf, under the terms of our Data Processing Agreement.

Your Data Processing Agreement

Every hosting contract automatically includes a DPA that meets GDPR Article 28 requirements, covering the scope of processing, our security obligations, and your rights as the data controller for your own customers' data. Download it any time from your client area.

Our Sub-processors

We use a small number of sub-processors, each contractually bound to GDPR-equivalent standards:

  • Payment processing — an EU-licensed payment service provider.
  • Transactional email delivery — hosted within the EU.
  • Domain registry services — required by the relevant TLD registry operator.

The current, complete list is available on request from our data protection team.

Data Breach Notification

In the event of a personal data breach, we notify affected customers within 72 hours of becoming aware of it, as required under GDPR Article 33, including what happened, what data was affected, and what we're doing about it.

Your Rights

Access, rectification, erasure, restriction, portability and objection — the full list of GDPR data subject rights, and how to exercise them, is detailed in our Privacy Policy.

Data Protection Officer

Our Data Protection Officer oversees compliance across the organisation and can be reached directly at dpo@webhostingeurope.com for any GDPR-related question or concern.

International Data Transfers

Customer content never leaves our EU data centers. Where a sub-processor operates outside the EU for a specific auxiliary function, transfers are protected by Standard Contractual Clauses approved by the European Commission.

Independent Verification

Our practices are reviewed annually as part of our ISO/IEC 27001 certification audit. Summary audit results are available to customers on request — see our GDPR & Security page for more.