# UK GDPR and Website Hosting

Source: https://dijituldns.co.uk/gdpr-compliant-hosting/
Updated: 2026-10-08

> dijitul provides website hosting that helps UK organisations meet their UK GDPR duties, on dijitul Complete Hosting at £1 a day + VAT. We act as your processor for your site's data, keep the server patched and access-controlled, take daily backups kept for 14 days, and provide a data processing agreement on request. Compliance remains your responsibility as controller.

## Key facts

- UK GDPR and the Data Protection Act 2018 apply to UK websites handling personal data
- The ICO is the UK regulator for data protection
- Your host is normally a processor; you are the controller
- A written processor contract (data processing agreement) is required: available from dijitul on request
- Security measures: patching, firewall, access control, SSL and daily backups kept for 14 days
- Ask us in writing where your website and backups are held

## No host can make you GDPR compliant

Be wary of any host selling 'GDPR compliant hosting' as if it solves everything. Under UK GDPR, the organisation that decides why and how personal data is used is the **controller**. That's you. Your host is usually a **processor**, handling data on your behalf. Hosting matters, but your privacy notice, consent, retention, forms and what you collect matter just as much.

What a good host can do is give you secure infrastructure, a proper contract and honest answers. That's what we offer.

## What UK GDPR expects from hosting

- **A written contract with your processor.** UK GDPR requires one. We provide a data processing agreement (DPA) on request.
- **Appropriate security.** Measures proportionate to the risk, such as patching, encryption in transit and access control.
- **The ability to restore data.** Backups that let you recover from an incident.
- **Knowing where data goes.** If personal data leaves the UK, transfer rules apply. Ask us in writing where your website and backups are held, and we'll confirm.
- **Breach handling.** Controllers must report qualifying personal data breaches to the ICO within 72 hours of becoming aware. Processors must tell controllers without undue delay.

## How dijitul hosting supports you

- **Access control:** each site runs under its own system user, Plesk logins are individual, and staff access is limited to what's needed to support you.
- **Encryption in transit:** [SSL](https://dijituldns.co.uk/ssl-certificates/) on every site, with Cloudflare in Full (strict) mode.
- **Patching and monitoring:** see [website security](https://dijituldns.co.uk/website-security/).
- **Daily backups kept for 14 days** so data can be restored. A fixed 14-day window also helps your retention planning: deleted data drops out of our backups after two weeks. See [website backups](https://dijituldns.co.uk/website-backups/).
- **A UK company** you can contact: DIJITUL LTD, Mansfield, trading since 2006.

## Your side of the job

- Collect only the personal data you need on forms.
- Don't let forms email sensitive details in plain text if you can avoid it. Store them securely or use a dedicated system.
- Delete old form submissions, abandoned accounts and test data on a schedule.
- Keep a privacy notice that lists your processors, including your host.
- Check whether you need to pay the ICO data protection fee. Most organisations that process personal data do, unless exempt.
- Use a cookie banner that gets proper consent for non-essential cookies. Cookie rules come from PECR, and the Data (Use and Access) Act 2025 is changing some of them, so check current ICO guidance.

## Getting started

Order [dijitul Complete Hosting](https://dijituldns.co.uk/complete-hosting/) at [clients.dijitul.uk/order](https://clients.dijitul.uk/order) and ask for our DPA when you do. If you handle special category data, such as health records, talk to us first so we can recommend the right setup. See [hosting for medical practices](https://dijituldns.co.uk/hosting-for-medical-practices/).

## FAQs

### Does my website hosting need to be GDPR compliant?

Your hosting is part of how you process personal data, so UK GDPR requires appropriate security and a written contract with your host as processor. dijitul provides secure managed hosting at £1 a day + VAT and a data processing agreement on request.

### Is my web host a data processor?

Usually yes. If your website stores or handles personal data such as form submissions or customer accounts, your host processes it on your behalf. You are the controller. UK GDPR requires a written contract between you, often called a DPA.

### Does UK GDPR require my website data to be stored in the UK?

No, UK GDPR doesn't require UK storage, but transfers outside the UK must meet transfer rules, such as adequacy regulations or appropriate safeguards. Ask your host where your site and backups are held. dijitul will confirm this in writing.

### Do I need to pay the ICO data protection fee?

Most UK organisations and sole traders that process personal data must pay the ICO data protection fee unless an exemption applies. The ICO has a self-assessment tool on its website to check whether you need to pay.

### Who do I report a website data breach to?

If a personal data breach is likely to risk people's rights and freedoms, the controller must report it to the ICO within 72 hours of becoming aware. Your host, as processor, should tell you promptly. Keep a record of all breaches.

### Can I get a data processing agreement from dijitul?

Yes. dijitul provides a data processing agreement on request for customers on its hosting. Ask when you order, or email info@dijitul.uk.

## Pricing and ordering

dijitul Complete Hosting is £1 a day + VAT (£365 a year + VAT). Order at https://clients.dijitul.uk/order?product=complete-hosting&ref=dijituldns&src=gdpr-compliant-hosting or call 01623 650333.
