MenuClose
Engineering

GDPR in three layers

The marketplace principle, not consultant folklore

The GDPR applies where the data subject is, not where the server stands (marketplace principle, Art. 3(2) GDPR). “Everything has to sit on EU servers” is consultant folklore, not a legal basis — following it wholesale means paying for protection applied in the wrong place.

Three layers, three answers

  • Layer A — personal end-user data: accounts, payment data, anything directly identifying customers. Here EU hosting is a deliberate, reasoned decision — not always technically required, and in the German market additionally an argument for trust.
  • Layer B — internal operational data without personal reference: no hosting constraint; tools outside the EU are permissible where they are technically superior.
  • Layer C — no personal data held at all: there is simply nothing that would have to sit anywhere.

Why this site is layer C

This site collects no form data, stores no conversations and holds no accounts. Contact runs exclusively through outgoing links that visitors trigger themselves — no form, no pre-filling, no storage. Without data being held, the question of server location answers itself for this site: it is in layer C, not because a provider configured it that way, but because architecturally nothing arises here that would need configuring.