“EU hosting” is one of the easiest claims to make and one of the hardest to verify. A provider can host in an EU data centre, put an EU flag on the pricing page, and still route your data through companies that answer to laws outside the EU. The good news is that you can check this yourself in an afternoon, without a lawyer, using documents the provider is legally required to give you. This is the audit we run on our own supply chain, written out as steps you can follow on any host.
First, separate the hosting path from the peripheral path
Before you list anything, draw one line. On one side is the hosting path: the servers, database, file storage, backups and CDN that actually hold and serve your site’s data. On the other side is the peripheral path: the tools the provider uses to run its business, such as support chat, ticketing, email delivery and payment processing. The two carry very different risk. The hosting path holds your visitors’ personal data in bulk. The peripheral path usually holds your billing contact and support messages, not your visitors’ records.
This line matters because a fair audit judges each side by the right standard. Demanding that a host use zero non-EU tools anywhere in its business is neither realistic nor the point. The standard that actually protects your users is stricter and narrower: the hosting path must be under EU control, and no personal data from your visitors should flow through the peripheral tools into a jurisdiction you were trying to avoid. Hold both sides to that and you are auditing the thing that matters.
Step one: get the sub-processor list
Under the GDPR, a processor that engages other processors has to disclose them. In practice this means every serious host publishes, or will send you, a list of sub-processors: the third parties it relies on to deliver the service. Look for it in the Data Processing Agreement (DPA), in a “sub-processors” page, or ask support directly. If a provider cannot produce this list, that is your answer already. A host that handles personal data for a living and has no documented sub-processor list is not one you can verify.
When you get the list, you are looking for three columns for each entry: the company name, what it does, and where it and its parent are based. A good list gives you all three. If it only gives you logos, push for the legal entity names, because that is what you will use in the next step.
Step two: trace ownership, not just location
For each entry in the hosting path, find the company that ultimately controls it. A brand you recognise may be a subsidiary of a parent on another continent. This is where “EU hosting” quietly breaks: the racks are in Stockholm, but the company operating them is owned by a US corporation, which brings it within reach of US legal orders regardless of where the hardware sits. You can check ownership through the company’s own corporate pages, national business registers, or a plain search for “who owns [company]”. You are answering one question: if a foreign authority served this company with a lawful order, could it be compelled to produce data it holds?
- What is the legal entity name, not just the brand?
- Which company ultimately owns and controls it?
- In which country is that controlling company incorporated?
- Is this entry in the hosting path or the peripheral path?
- If it sits outside the EU, what transfer mechanism is claimed, and does any visitor data actually reach it?
Work down the hosting path first. If every entry there resolves to an EU-controlled company processing data inside the EU, the foundation is sound. Then look at the peripheral path with the narrower test: not “is this tool foreign” but “does any of my visitors’ personal data pass through it”.
Step three: read the transfer language honestly
Where a sub-processor sits outside the EU, the DPA should name the mechanism used to make that transfer lawful, such as Standard Contractual Clauses or the provider’s certification under the EU-US Data Privacy Framework. These mechanisms are real and can be valid, but they are not magic words. After the Schrems II ruling, a transfer to the US is not automatically fine just because a clause is cited. The practical question you are checking is simpler: does any bulk personal data from your site actually cross that border, or is the foreign tool limited to something like your own billing details. A payment processor that touches a card number is a very different exposure from a chat tool that only holds a support thread between you and your provider.
The question is not “does this host use any foreign tool at all”. It is “can anyone outside the EU be compelled to produce my visitors’ data”.
Red flags to watch for
A few answers should make you slow down. If a provider talks only about the physical location of its data centres and goes quiet when you ask who owns the operating company, that gap is usually deliberate. If the sub-processor list is missing, vague or “available on request” but never actually arrives, treat the request as a test the provider failed. And if the marketing page makes a sweeping claim like “no US anything” while the DPA tells a more complicated story, believe the DPA, because it is the legally binding document and the marketing copy is not.
None of these on their own proves bad faith. Plenty of good providers use some non-EU tool in their back office. What matters is whether they will tell you about it plainly and whether visitor data stays out of it. A provider that answers openly, even when the answer is “yes, we use this EU-region tool for that”, is far more trustworthy than one that gives you a flawless slogan and no documents.
Running the audit on Celestio
We hold ourselves to the same test, so here is how we score. In the hosting path, sites run on our own infrastructure in Falkenberg, Sweden, on GleSYS hardware powered by renewable energy, with customer site data processed inside the EU. There is no US cloud in that path by construction. In the peripheral path we are deliberately transparent: our DPA lists the tools we use to run the business, which includes an EU-region collaboration tool and a payment processor for billing. Those touch our operations and your invoice, not your visitors’ records. That is the honest shape of it, and it is exactly the shape our audit is designed to reveal. A provider that hides the peripheral path is a worry. A provider that documents it, and keeps visitor data out of it, is one you can verify.
If you run these three steps on your current host and the answers do not line up, that gap is worth a conversation. Our sovereignty page sets out where our data lives and who controls it, and if you want a second pair of eyes on your own supply chain, our engineers are happy to walk through it with you.
This is practical guidance, not legal advice. For a formal transfer assessment, consult your DPO or legal counsel.
