Law & jurisdiction

Does the GDPR apply if I host outside the EU?

Short answer

The GDPR follows the data subject, not the server. If you process personal data of people in the EU, it applies regardless of where the server sits — and hosting outside the EU adds a transfer-mechanism obligation. Offshore hosting does not exempt you from the GDPR; it adds a step to your compliance.

For personal data of EU residents, an international transfer needs a lawful basis: an adequacy decision, standard contractual clauses, or a derogation. Switzerland and Uruguay hold adequacy decisions; Panama and Seychelles do not, so SCCs plus a transfer impact assessment are required.

If you process no personal data of EU residents, none of this applies to you. Many privacy-motivated workloads — a personal VPN, a Tor relay, a private file server — fall entirely outside the regulation.

See also: Offshore hosting · GDPR · Tor