Most "EU hosting" is a US company renting rack space in Frankfurt. The server sits in Europe, but the entity that controls it — and therefore your customers' data — answers to a US court order. For a genuinely GDPR-compliant EU VPS, the datacenter location is table stakes; what actually matters is who owns the legal entity, who owns the network, and which jurisdiction can compel disclosure. This is a note from our NOC on how we draw those lines, and why we keep every layer inside the EU rather than borrowing someone else's cloud.
What "GDPR-compliant EU VPS" actually requires
GDPR does not ban international transfers outright, but it makes them expensive to defend. The moment your processor is a US-controlled entity, you inherit the US CLOUD Act — a law that lets US authorities compel a US company to hand over data it holds anywhere in the world, including its Frankfurt region. That is the exposure the Schrems II ruling was built around, and it is why "data stored in the EU" and "data outside US legal reach" are two different claims. A defensible setup needs three things aligned: an EU-established controller/processor, physical storage in EU datacenters, and a transit path that does not silently hairpin through a non-EU network.
NODED.CLOUD is operated by X ZONE IT SRL, a Romanian company — an EU legal entity, billed in EUR, with no US parent to serve. That is the part a datacenter pin on a map can't give you.
The sovereignty wedge: we own the network, not just the server
Here is where most "European sovereign cloud alternative" pitches get thin. They rent compute from a hyperscaler and rent transit from whoever is cheapest, so your packets can leave the EU and come back without you ever seeing it. We don't resell. We run our own AS60982 — our own autonomous system, our own IP space, our own routing policy — across EU datacenters spanning 13 POPs and 15 internet exchanges. When we say data stays in EU infrastructure, we mean the routing is ours to keep it there, not a promise inherited from an upstream we can't audit. You can read the full topology on our network page.
Owning the AS matters for GDPR specifically because it removes a hidden processor from your chain. With a reseller, there is always another company — often US-headquartered — sitting between you and the metal. With us, the entity that provisions the VPS, routes the traffic, and holds the disk is the same EU entity on your invoice.
EU data residency you can point at in a DPA
Data residency is a clause auditors read closely. Our VPS fleet runs in EU datacenters on NVMe storage with 1 Gbps unmetered symmetric connectivity, and the streaming and edge POPs sit in EU cities such as Amsterdam and Frankfurt — the same jurisdictions a German or Dutch controller wants to name in a Data Processing Agreement. For teams whose compliance team specifically asks for gdpr vps netherlands germany coverage, that is deliverable without a caveat about a US control plane.
Because the control plane, the billing entity, and the storage are all EU-side, your Standard Contractual Clauses exercise gets shorter: there is no third-country transfer to paper over, so you are not writing supplementary measures to compensate for one. We built the dedicated GDPR-compliant hosting use case around exactly this chain of custody.
No US CLOUD Act exposure by design
The cleanest way to be outside a law's reach is to not be subject to it. X ZONE IT SRL is Romanian; it holds no US assets a US court can leverage and has no US corporate parent to compel. That is a structural answer to no US CLOUD Act hosting, not a policy toggle in a dashboard that a future acquisition could quietly flip. We are not promising we would refuse a US warrant — we are pointing out that the legal instrument doesn't attach to us in the first place.
Payment is part of the same story. We accept card, SEPA, and BTC, so an EU customer can pay via a SEPA bank transfer without routing personal financial data through a US payment processor, and privacy-sensitive customers can settle in BTC.
Specs, tiers, and what you actually deploy
Sovereignty shouldn't cost a premium. Our hourly VPS line runs six tiers, billed to the second so a short-lived compliance test environment costs cents:
| Tier | RAM | vCPU | NVMe | Price |
|---|---|---|---|---|
| VPS I | 2 GB | 1 | 40 GB | EUR 4/mo (EUR 0.0056/hr) |
| VPS II (popular) | 4 GB | 2 | 80 GB | EUR 6/mo |
| VPS III | 8 GB | 2 | 120 GB | EUR 10/mo |
| VPS IV | 8 GB | 2 | 120 GB | EUR 16/mo |
| VPS V | 16 GB | 4 | 200 GB | EUR 30/mo |
| VPS VI | 32 GB | 6 | 400 GB | EUR 58/mo |
Every tier ships with root SSH, KVM virtualization, IPv4 and IPv6, a choice of 41 OS templates, and a median deploy time of 47 seconds. Backing all of it is free 1 Tbps DDoS mitigation on every product and a 99.9% uptime SLA. Full specs live on the VPS hosting page, and if a compliance workload needs isolated hardware — single-tenant disks, a /29 of IPv4, BGP on our AS — that moves to dedicated servers.
How Noded Can Help
If you are moving a workload off a US-controlled cloud to shrink your GDPR surface, we can stand up an EU VPS on our own AS60982 in under a minute and give your compliance team a clean chain of custody: EU legal entity, EU datacenters, EU-owned routing, SEPA billing. We are happy to walk through your DPA requirements before you migrate — where the data physically sits, which jurisdiction holds it, and how we keep transit inside the EU. Spin up the smallest tier hourly to validate the setup, and scale to dedicated hardware if your data residency clause calls for single-tenant isolation. Start on our GDPR-compliant hosting page.
FAQ
Is a VPS in an EU datacenter automatically GDPR-compliant?
No. Physical location is only one factor. If the provider is a US-controlled company, the US CLOUD Act can compel disclosure of data held in its EU datacenters. Compliance also depends on the operating entity's jurisdiction. NODED is operated by X ZONE IT SRL, an EU (Romanian) entity, with storage in EU datacenters and routing on our own AS60982.
How does NODED avoid US CLOUD Act exposure?
The CLOUD Act attaches to US-established companies. X ZONE IT SRL is a Romanian company with no US parent and no US assets to leverage, so the legal instrument doesn't reach us structurally — it isn't a policy setting that could later change.
Where is my data physically stored?
On NVMe storage in EU datacenters, across a network of 13 POPs and 15 internet exchanges that we operate on our own AS60982. Because we own the routing, EU-resident data stays on EU infrastructure rather than transiting an upstream we can't audit.
Can I pay without using a US payment processor?
Yes. We accept SEPA bank transfer and BTC alongside card, so EU customers can settle in EUR without routing financial data through a US processor.
What does the smallest GDPR-compliant EU VPS cost?
VPS I starts at EUR 4/mo, or EUR 0.0056/hr billed to the second, with 2 GB RAM, 1 vCPU, and 40 GB NVMe. It includes free 1 Tbps DDoS mitigation, root SSH, IPv4 + IPv6, and a 99.9% SLA — enough to validate a compliance setup before scaling up.