Logo
Company

How we protect your data and what you need to do

September 2, 20269 min read
Hero-Datenschutz-Hetzner-Blog.webp
Back to Overview
If you process personal data, you are responsible for protecting it
Data security in practice: How we protect your data
GDPR: basics and responsibilities
Your responsibilities as a controller
Evidence of information security
US CLOUD Act: Why your provider's jurisdiction matters
Conclusion

In this article

  • If you process personal data, you are responsible for protecting it
  • Data security in practice: How we protect your data
  • GDPR: basics and responsibilities
  • Your responsibilities as a controller
  • Evidence of information security
  • US CLOUD Act: Why your provider's jurisdiction matters
  • Conclusion

In this article

  • If you process personal data, you are responsible for protecting it
  • Data security in practice: How we protect your data
  • GDPR: basics and responsibilities
  • Your responsibilities as a controller
  • Evidence of information security
  • US CLOUD Act: Why your provider's jurisdiction matters
  • Conclusion
TL;DR
Data protection gives you control over your data. In Europe, the General Data Protection Regulation (GDPR) provides the legal framework for this. It defines who may process personal data, under what conditions, and what roles you and we have in this process. To protect personal data, we have implemented technical and organizational measures (TOMs), such as high-security fencing around our data center parks and site-wide video surveillance. These measures are part of our security concept and are embedded in our information security management system (ISMS). We regularly review and further develop our ISMS. Certifications and attestations, such as our ISO/IEC 27001:2022 certification and our BSI C5 Type 2 attestation, confirm its effectiveness. Protecting data requires TOMs at multiple levels. Even though we implement appropriate measures for our infrastructure and services, you as a customer should also take measures to adequately protect your data and the Hetzner products you use.

Would you give just anyone the key to your home? Or your personal password? Probably not. You likely care about keeping your data secure and deciding for yourself who can access it. That is exactly what data protection is about: it sets rules for handling your personal data and helps determine who may access which of your personal data and when.

But data protection is not just about laws and regulations. It also has to work in practice. Whether you are an individual, an association, or a company, anyone who processes personal data is also responsible for protecting it.

In this article, we explain what measures we take at Hetzner to protect this data, the role technical and organizational measures (TOMs) play, and where your responsibilities as a customer begin.

If you process personal data, you are responsible for protecting it

Maybe you run the website for your local bowling club or sell cute cat toys through a small online shop. To make your website or online shop accessible, you might use a Hetzner product, such as one of our web hosting packages, a Cloud Server, or a Dedicated Server.

In many cases, this also involves processing other people’s data. On a club website, for example, this could include members’ contact details. In an online shop, it could include customers’ names and shipping addresses. To protect this data, both we as the hosting provider and you as the customer need to implement appropriate TOMs. But what does that look like in practice? Below, we show you some examples of the measures we take.

Data security in practice: How we protect your data

Data protection goes hand in hand with information and data security. That is why we protect not only personal data, but also the systems and infrastructure we use to process it. In doing so, we also help protect business-critical and other sensitive data. Our measures to prevent unauthorized physical access and ensure the reliable operation of our systems are two examples of how we do this.

Content_Datenschutz_Gebaeude.webp
Content_Datenschutz_Gebaeude.webp

How we prevent unauthorized physical access

High-security fences with anti-climb and anti-dig protection, along with video surveillance, secure our data center parks. So our technical protection of your personal data starts with our physical infrastructure.

How we ensure high availability

We provide the infrastructure that keeps your server running reliably and your data available. This also helps protect your data. To do this, we use several measures:

  • Uninterruptible power supply (UPS): We ensure that your servers have a reliable power supply by using UPS systems and backup generators. If the power fails, the UPS batteries bridge the gap until the regular power supply is restored or, during a longer outage, until the backup generators take over. This allows us to power a data center independently of the public grid for up to three days.
  • Cooling: Servers generate a lot of heat and need cooling to operate reliably. We cool our servers with outside air, which flows to the servers through cold aisles and raised floors
  • Fire protection: Our system includes aspirating smoke detectors, which detect smoke at an early stage and trigger an alarm.
  • Hardware failures: Our technicians are on site around the clock and replace failed components.

Together with our redundant network connectivity, these measures help ensure that your services remain reliably accessible.

We also protect your systems against attacks from the internet. Our DDoS protection runs continuously, detects DDoS attacks at an early stage, and automatically filters malicious traffic before it reaches your systems.

You can find more information about the measures we take in our Hetzner Docs.

GDPR: basics and responsibilities

Protecting personal data is not just our responsibility as the hosting provider. Who is responsible for processing personal data — we at Hetzner or you as the customer — changes depending on the product.

The General Data Protection Regulation (GDPR) has provided the legal framework for this since 2018. It establishes consistent data protection rules for all companies in the EU, as well as companies outside the EU that offer goods or services to people in the European Union.

The GDPR distinguishes between the following role:

  • Data subject
  • Controller
  • Processor

The "data subject" is the person whose personal data is being processed. This could be you, for example, when you create a customer account with us and add your bank details to your account. But it could also be your customer whose contact details you store.

As a hosting provider, we may act as either the "controller" or the "processor" depending on the situation. When you enter into a contract with us, we process your contract and customer data as the "controller". If you use our infrastructure to store or process your content, we act as the "processor". In this case, you are the "controller" for the personal data you store and process on the Hetzner product you use.

Good to know: If you store personal data on a Hetzner product, that data does not belong to us. We do not use it for advertising, sell it, or analyze it for our own purposes. We only access it when necessary to provide our services or when you ask us to do so, for example, as part of a support request.

Your responsibilities as a controller

Legal basis

You may only process personal data if you have a legal basis for doing so. The most important legal ones include:

  • The data subject has given their consent.
  • You need the data to perform a contract.
  • You need to process the data to comply with a legal obligation, such as retaining invoice data.
  • You have a legitimate interest: For example, you write about a public figure on your blog or publish journalistic content.

Keeping your account secure

Anyone who gains access to your Hetzner customer account can also access your products. That is why you should:

  • Use a strong, unique password. It should contain uppercase and lowercase letters, numbers, and special characters, be around 20 characters long, and consist of a random combination of characters – for example, fK7!vQ2#Lm9@xR4$Np8Z
  • Enable two-factor authentication.
  • Carefully manage permissions in your own applications, such as your CMS, online shop, or databasedie Berechtigungen in deinen eigenen Anwendungen (CMS, Shop, Datenbank) gewissenhaft pflegen.

Who is responsible for which security measures?

The product you use determines which security measures you need to implement yourself and which ones we handle. With Dedicated Servers and Cloud Servers, you are responsible for almost all aspects of managing and securing your server. This includes configuring a firewall, regularly updating the operating system, and implementing an appropriate backup strategy.

With Managed products, we take care of tasks related to the operation, maintenance, and security of the systems we manage. However, regardless of the product, you remain responsible for your content and for encrypting your data.

You can find a detailed overview of product-specific responsibilities in our Hetzner Docs.

Choose your hosting provider carefully

Part of your responsibility is choosing a secure hosting provider that complies with the applicable legal requirements. You should therefore check which TOMs a provider has implemented to protect personal data. Certifications, attestations, and other official documentation can help you make an informed choice.

Evidence of information security

Hetzner is one example of a hosting provider that can meet these requirements. We provide various certifications and attestations, including:

ISO/IEC 27001:2022

Our TOMs are part of our overarching security framework. The information security management system (ISMS) also defines processes, responsibilities, and procedures for systematically managing information security risks. It also supports us in meeting data protection requirements.

ISO/IEC 27001:2022 confirms that we systematically organize, manage, review, and continuously improve our information security management. Information security goes beyond the protection of personal data: It covers all information that is relevant to customers, the company, and its systems.

The certified scope covers all hosting services and the data centers of Hetzner Online GmbH at the locations listed in the certificate.

BSI C5 Type 2 Attestation

The C5 criteria catalogue draws on requirements and concepts from ISO/IEC 27001 and supplements them with additional requirements, particularly cloud-specific security requirements and transparency criteria. However, an ISO 27001 certification alone is not equivalent to a C5 attestation.

C5 stands for Cloud Computing Compliance Criteria Catalogue. Published by the German Federal Office for Information Security (BSI), the catalogue defines minimum information security requirements for cloud services. A Type 2 attestation assesses not only whether the specified controls are appropriately designed and implemented, but also whether they operated effectively over a defined audit period.

Hetzner's Type 2 audit in accordance with BSI C5:2020 covered the following products and services during the current audit period: Dedicated Servers, Managed Servers, Cloud Servers (virtual servers), Volumes, Load Balancers, vSwitches and Floating IPs, Storage Boxes, Storage Share and Object Storage, Web Hosting and Domains, as well as Colocation. The audit and the resulting audit opinion apply exclusively to our European locations in Gunzenhausen, Nuremberg, Falkenstein, and Helsinki.

C5 is particularly relevant in regulated sectors such as healthcare. Section 393 of the German Social Code Book V (SGB V) sets specific requirements for the level of security and the corresponding evidence for certain types of processing of healthcare and social service data using cloud computing services.

At Hetzner, the scope covers not only Cloud Servers, but also Dedicated Servers, Managed Servers, Web Hosting and Domains, Storage Share, Storage Box, Object Storage, and Colocation.

You can find more information and evidence relating to our information security in our Hetzner Docs article.

US CLOUD Act: Why your provider's jurisdiction matters

Certifications and audit reports are only part of the overall picture. The provider’s location (and thereore, which laws apply) can also play a role when you choose a hosting provider.

Under certain circumstances, the Clarifying Lawful Overseas Use of Data Act (or CLOUD Act) can require US companies to disclose data to US authorities even if that data is stored outside the United States.

What matters is therefore not only where the data is stored, but also which jurisdiction the provider is subject to. For you, this means that even if you use a European data center operated by a US cloud provider, legal requirements beyond European data protection law may also become relevant. If you want to process personal data in accordance with European data protection standards, you should therefore consider not only where the servers are located, but also which jurisdiction applies to the provider.

Our headquarters are in Gunzenhausen, Germany. We process and store data from our non-cloud products exclusively within the European Union. With our cloud products, you choose the location and therefore the region in which your data is stored (EU or non-EU). Our teams who access your data to provide technical support are all located within the EU.

Conclusion

Data protection is not something that one person or company can achieve alone. It depends on a combination of legal requirements, technical safeguards, and responsible action.

We provide secure infrastructure and regularly have our measures reviewed. Our certifications and attestations provide evidence of this. You as the customer are also responsible for making sure that you process that data you store on our products in a lawful way. You must also implement any relevant security measures. You should therefore be clear about which aspects of your server you are responsible for and take these responsibilities seriously.

Only by working together can we help protect the data of the people who place their trust in us.

self_hosting_stage_teaser_matrix_small.webpself-hosting-CTA-Teaser_big.webp

Sovereignty starts with hosting it yourself.

Minimize risks. Control costs. Maximize data protection.

Learn moreLearn more
Company
Content-profile-Scholz_Alena-Hetzner-Blog Kopie.webp

Alena Scholz

Data Protection Manager, Data Protection

Share article
Logo
Subscribe to our newsletter

Subscribe to our newsletter

Hetzner
  • Company
  • Our Customers
  • Sustainability
  • new
    Blog
  • Career
  • Pressroom
Support
  • Support Center
  • Contact
  • Downloads
  • Hetzner Docs
  • Status
Legal
  • Legal notice
  • Data privacy
  • System policies
  • Terms and conditions
  • Digital Services Act
  • Abuse form

©2026 Hetzner Online GmbH. All Rights Reserved. Prices