UK managed hosting · £1 a day + VAT · old websites welcome01623 650333 · Client login
Order now

Is my web hosting GDPR compliant?

Hosting is not GDPR compliant on its own: you, as controller, must use a host that acts as a processor under a written data processing agreement, keeps data secure and tells you where it is stored. dijitul is a UK company offering managed Complete Hosting at £1 a day + VAT, with daily backups kept for 14 days, updates and security.

Updated 2026-10-08 · by the dijitul hosting team, Mansfield, UK

Key facts

  • In the UK, GDPR applies as the UK GDPR alongside the Data Protection Act 2018.
  • The business that decides why and how personal data is used is the controller.
  • A web host storing that data on the controller's behalf is usually a processor.
  • UK GDPR Article 28 requires a written contract between controller and processor.
  • Controllers must report notifiable personal data breaches to the ICO within 72 hours of becoming aware.
  • This guide is general information, not legal advice; the ICO publishes free guidance for small businesses.

First, who is responsible?

This guide explains the basics in plain English. It is not legal advice. For your own situation, check the ICO's guidance at ico.org.uk or speak to an adviser.

  • You are the controller. If your website collects personal data, such as contact form messages, customer accounts or orders, your business decides why and how that data is used. That makes you the controller, and responsible for compliance.
  • Your host is usually a processor. A web host stores and processes that data on your instructions. That normally makes them a processor.
  • "GDPR compliant hosting" is a shared job. A host can support your compliance, but it cannot make your website compliant for you. Your privacy notice, cookie consent, forms and data retention are still your responsibility.

The data processing agreement (DPA)

UK GDPR Article 28 says a controller must have a written contract with any processor. This is usually called a data processing agreement or data processing terms. It should cover:

  1. What data the host processes and for how long.
  2. That the host only acts on your instructions.
  3. That staff with access are bound by confidentiality.
  4. The security measures in place.
  5. Rules on using sub-processors, such as data centres or backup providers.
  6. Helping you respond to data subject requests and breaches.
  7. Deleting or returning data when the contract ends.

Ask any host, including us, for its data processing terms before you sign up.

Where is the data stored?

Location matters because sending personal data outside the UK is a restricted transfer under UK GDPR.

  • Data stored in the UK has no transfer issue.
  • Data stored in the EEA is generally covered by the UK's adequacy regulations.
  • Data stored elsewhere needs a lawful transfer mechanism, such as adequacy regulations or the UK International Data Transfer Agreement.

Remember the website is not the only place data sits. Ask about backups, email, form submissions and any plugins that send data to third parties. Our guide Does my website need to be hosted in the UK? covers this in more detail.

Security: the part your host really affects

UK GDPR requires "appropriate technical and organisational measures" to keep personal data secure. For a website, that typically means:

  • HTTPS on every page with a valid SSL certificate.
  • Server and software updates applied promptly.
  • Regular backups so data can be restored after an incident.
  • Strong passwords and two-factor login for admin accounts.
  • Monitoring, so problems are spotted quickly.
  • Not keeping personal data longer than you need, for example clearing old form submissions.

If a breach does happen, a controller must report it to the ICO within 72 hours where it is likely to put people at risk. Your host should tell you quickly so you can meet that deadline. See My website has been hacked.

How dijitul helps

dijitul is a UK limited company (DIJITUL LTD) in Mansfield, Nottinghamshire, trading since 2006. Complete Hosting at £1 a day + VAT (£365 a year + VAT) covers the security side your host can influence: managed server updates, security and monitoring, daily backups kept for 14 days, free SSL and Cloudflare DNS. Ask us where your data and backups are stored and for our data processing terms, and we will answer plainly. Read about GDPR compliant hosting or order online.

Frequently asked questions

Is my web host a data processor or a controller?

Usually a processor. If your website collects personal data, your business decides how it is used, so you are the controller. The host stores and processes that data on your behalf, which normally makes it a processor. A host is a controller only for data it uses for its own purposes, such as billing you.

Do I need a data processing agreement with my web host?

Yes, if your website stores or handles personal data. UK GDPR Article 28 requires a written contract between a controller and a processor. Many hosts include data processing terms in their standard terms of service. Ask your host to point you to them and check they cover security, sub-processors and deletion.

Does my website have to be hosted in the UK for GDPR?

No. UK GDPR does not require UK hosting. It controls transfers of personal data outside the UK. Data stored in the UK or the EEA is generally straightforward. Data stored elsewhere needs a lawful transfer mechanism. Check the ICO's guidance on international transfers if your host stores data outside the UK or EEA.

Can a web host make my website GDPR compliant?

Not on its own. A host can provide secure servers, updates, backups, SSL and a data processing agreement. You are still responsible as controller for your privacy notice, cookie consent, lawful basis, data retention and handling requests from individuals. Compliance is shared, and the ICO's small business guidance is a good starting point.

What happens if my hosting has a data breach?

Your host should tell you without undue delay. As controller, you must assess the risk and, where the breach is likely to affect people's rights and freedoms, report it to the ICO within 72 hours of becoming aware. If the risk is high, you may also need to tell the affected people. Keep a record either way.

Can dijitul help with GDPR and hosting?

dijitul can help with the hosting side. Complete Hosting at £1 a day + VAT includes managed updates, security and monitoring, daily backups kept for 14 days, free SSL and Cloudflare DNS from a UK company trading since 2006. Ask us where your data is stored and for our data processing terms. For legal questions, check the ICO's guidance.

Related

Set it up and forget about it

Managed hosting, Plesk, Cloudflare DNS, daily backups and your domain for £1 a day + VAT. We move your site for you.

Call usOrder £1/day