GDPR-compliant server infrastructure
A GDPR-compliant server infrastructure protects personal data with EU hosting, encryption, access control and documented deletion periods.
Personal data
The GDPR requires appropriate protection for form submissions, customer accounts, orders and IP addresses in log files. Breaches can lead to fines, legal warnings and a loss of trust.
Technical measures
hosting in EU data centres
TLS 1.3 in transit, encryption at rest where necessary
personal accounts, two-factor authentication and logging
encrypted backups with defined retention periods
short log retention and truncated IP addresses
No unnecessary data flows
External fonts, maps or videos often transmit data before consent. We host them locally or load them only after consent.
Forms collect only necessary data and delete submissions after a set period.
Documentation
Every processor requires a data processing agreement. We document the technical and organisational measures in line with ISO 27001 and supply the details for your record of processing activities.
Approach
First, we record where personal data is processed. The measures are agreed with your data protection officer. They do not replace legal advice.