Compliance – GDPR in practice

GDPR-compliant cloud hosting from Germany

A cloud service is not GDPR-compliant by virtue of its server location alone, but through the complete chain: a data processing agreement under Article 28 GDPR, documented technical and organisational measures under Article 32, a transparent chain of sub-processors and a provider governed exclusively by European law. This page shows how centron implements each of these points – with the documents available for download.

The four building blocks of GDPR-compliant hosting

Overview
Building blockLegal basisHow centron implements it
Data processing agreementArt. 28 GDPRStandard DPA for all cloud products, available as a PDF: DPA (EN) · AVV (DE)
Technical and organisational measuresArt. 32 GDPRDocumented TOMs covering physical access, system access, separation, encryption and availability: TOM (EN) · TOM (DE)
Independent auditingArt. 32(1)(d) GDPRISO 27001 based on IT-Grundschutz (BSI-IGZ-0773-2026, valid until 4 July 2029) and an unqualified BSI C5:2020 Type 1 attestation – details in the Trust Center
No third-country transfersChapter V GDPRProcessing exclusively in German data centres; German ownership structure with no parent company in a third country – no reach-through via the US CLOUD Act or FISA 702

Data location per product

All centron products are operated in Germany. The core of the platform is the company’s own data centre in Hallstadt near Bamberg; the information network certified to ISO 27001 based on IT-Grundschutz additionally covers the infrastructure sites in Nuremberg and Frankfurt am Main. No personal customer data is transferred to third countries.

Overview
ProductProcessing
ccloud³ Virtual Machines, Managed Server, Managed KubernetesGermany (Hallstadt near Bamberg)
S3 Object Storage, Volumes Block Storage, cBacks backupsGermany (Hallstadt near Bamberg)
Cloud GPU, Dedicated Server, ColocationGermany (Hallstadt near Bamberg)

Sub-processors, deletion, access requests

  • Sub-processors: The sub-processors used are listed in the DPA; changes are announced in accordance with the procedure agreed there (Art. 28(2) GDPR).
  • Deletion: After the end of the contract, customer data is deleted or returned in accordance with the DPA (Art. 28(3)(g) GDPR). During the term you can delete instances, volumes and buckets yourself at any time via the console.
  • Data subject rights: As a processor, centron supports access and erasure requests (Art. 15, 17 GDPR) on the instructions of the controller; the contact route and deadlines are governed by the DPA, and contact details can be found in the <a href="/rechtliches/datenschutz">privacy policy</a>.
A common misconception

Server location = compliance

An EU data centre operated by a US provider does not solve the underlying problem: US law (CLOUD Act, FISA 702) reaches US companies regardless of where the data is stored – precisely the constellation the ECJ objected to in "Schrems II" (C-311/18). What matters instead, and how to vet providers systematically, is explained in the guide Data sovereignty in the cloud with its 10-point checklist, and in the overview Alternatives to US cloud providers.

Last reviewed: 31 August 2026 · Sources: GDPR Art. 15, 17, 28, 32 and Chapter V; ECJ C-311/18; BSI certificate BSI-IGZ-0773-2026; C5 audit report of 12 June 2026 (Trust Center).

Get started for free

Sign up and receive €200 credit at centron within your first 60 days.

This promotional offer applies to new accounts only. Available exclusively to businesses.