Engineering

GDPR in 3 layers

The marketplace principle, not consultant folklore

The GDPR applies where the data subject is, not where the server stands (marketplace principle, Art. 3(2) GDPR). “Everything has to sit on EU servers” is consultant folklore, not a legal basis — following it wholesale means paying for protection applied in the wrong place.

3 layers, 3 answers

  • Layer A — personal end-user data: accounts, payment data, anything directly identifying customers. Here EU hosting is a deliberate, reasoned decision — not always technically required, and in the German market additionally an argument for trust.
  • Layer B — internal operational data without personal reference: no hosting constraint; tools outside the EU are permissible where they are technically superior.
  • Layer C — no personal data held at all: there is simply nothing that would have to sit anywhere.

Why this site is layer C

This site collects no form data, stores no conversations and holds no accounts. Contact runs exclusively through outgoing links that visitors trigger themselves — no form, no pre-filling, no storage. Without data being held, the question of server location answers itself for this site: it is in layer C, not because a provider configured it that way, but because architecturally nothing arises here that would need configuring.

Ask CurtisClose
CurtisLive

You are speaking with an AI system. Its answers are generated automatically.

I am Curtis. Which AI model answers is your decision. With every answer you see what a conversation like this costs.

Curtis is an AI agent. Only the human makes commitments.This chat stores nothing beyond the session; even so, please do not enter personal data here.