Why the location matters
A server is subject to the laws of the country where it sits. Latency decides where your users are best served; jurisdiction decides which authorities can demand what, and under which safeguards. Here is how our four jurisdictions compare as of September 2026 — a summary, not legal advice.
European Union
Amsterdam, Frankfurt, Helsinki, Bucharest and Stockholm are covered by the GDPR. The EU’s Data Retention Directive was annulled by the Court of Justice in 2014, and later rulings (2016, 2020) held that general and indiscriminate retention of traffic data is incompatible with EU law — in 2020, explicitly including hosting providers.
- Netherlands — no general retention duty since a court set the retention act aside in 2015.
- Romania — the Constitutional Court struck down retention laws in 2009 and 2014.
- Germany — the old retention law has been unenforced since 2017; a bill making internet access providers keep IP assignments for three months is pending.
- Sweden — a narrowed retention duty applies to telephony and internet access providers, not to hosting.
United Kingdom
London operates under the UK GDPR and the Data Protection Act 2018, amended by the Data (Use and Access) Act 2025. The Investigatory Powers Act 2016, amended in 2024, allows retention notices approved by a judicial commissioner, as well as technical capability notices.
United States
New York, Miami and Los Angeles are in a country with no comprehensive federal privacy law. State laws fill part of the gap — California’s CCPA/CPRA is the strictest, and CalECPA requires California state and local agencies to obtain a warrant for electronic communication data. At the federal level, the CLOUD Act requires US providers to disclose data in their possession on a valid order, wherever it is stored.
Singapore
Singapore’s Personal Data Protection Act governs the private sector, with breach notification within three days. Police can obtain computer data with production orders under the Criminal Procedure Code, and require decryption with a Public Prosecutor’s order. Singapore is outside both the EU and the Five Eyes intelligence alliance.
How to choose
- Start with your users — the latency planner shows which sites are close enough.
- Among those, pick the legal framework you are most comfortable with.
- Do not rely on geography alone. Encrypt data at rest and in transit, keep logs minimal, and prefer providers that publish a warrant canary and a transparency report.
Sources
- Court of Justice of the EU, Digital Rights Ireland (C-293/12, 2014), Tele2 Sverige (C-203/15, 2016), La Quadrature du Net (C-511/18, 2020)
