Every privacy-focused hosting company says roughly the same thing: pick us, we're in a good jurisdiction. Almost none of them explain what that actually means, or show their work. So we did the work ourselves.
We spent the past several weeks researching data retention law, government access powers, and documented enforcement history across 14 countries where privacy-conscious hosting customers commonly look, including our own two, Finland and Switzerland. We scored each country on six criteria and read the actual legal history behind each score, not just the marketing pages.
Two countries ended up defining the opposite poles of everything we found. Romania's Constitutional Court struck down the country's data retention law twice, in 2009 and again in 2014, and after the second loss, the Romanian government simply stopped trying to pass one. Hong Kong went the other direction entirely: as of March 2026, refusing to give police your device password is now a criminal offense there, a rule that applies even to travelers just passing through the airport.
Here's everything we found, country by country, with sources.
How We Scored This
We scored each of the 14 countries from 0 to 5 on six criteria, for a maximum of 30 points. The question we asked wasn't "does this country have good privacy laws generally," it was narrower and more practical: if you rent server space in this country, what can the government compel your hosting provider to collect, keep, and hand over about you, and what has actually happened in practice?
The six criteria:
- Mandatory data retention. Does the law require providers to keep customer or traffic data, and does that obligation actually reach hosting providers specifically, or only telecom and internet-access companies?
- Legal process for disclosure. Does law enforcement need a court order, or can data be compelled through a lower-threshold administrative request?
- Foreign reach. Intelligence-alliance membership, cross-border legal cooperation obligations, and any law letting the state pull in data from outside its own borders.
- Gag orders and notification. Can a provider be legally barred from telling a customer their data was requested?
- Identity verification requirements. Is there any legal mandate to verify who a hosting customer actually is?
- Practical track record. Documented cases, court rulings, and enforcement history over roughly the past five to eighteen years. Law on paper and law in practice aren't always the same thing, this criterion is where that gap shows up.
One honesty note before the rankings: the gag-order criterion turned out to be far harder to research than the other five. Most countries' data retention laws and court-order requirements are well documented in English-language legal guides, since they come up often. Whether a specific criminal procedure code allows a gag order is a much narrower, more obscure question, and for most of the 14 countries we simply couldn't find reliable public information on it without pulling primary legal text in the country's own language. Where we found solid, direct evidence (Sweden, the United States, Singapore), we scored it. Where we didn't, we left it unscored rather than guess, and the totals below reflect that: a lower total sometimes just means fewer criteria were scoreable, not that the country scored badly on every measure.
The Rankings
Scores are out of a possible 30. The gag-order criterion is unscored for most countries (see the honesty note above), so treat close scores as roughly comparable rather than precisely ranked against each other.
Developing: Canada's "Lawful Access Act"
This one is moving fast enough that it's worth flagging separately from the main rankings. Bill C-22, widely referred to as Canada's Lawful Access Act, passed third reading in the House of Commons on June 18, 2026, after the government used a closure motion to limit debate. The bill authorizes regulations requiring designated "core providers" to collect and retain metadata on all Canadians for up to a year without any individual being under suspicion, and gives the Minister of Public Safety power to extend that same requirement to any electronic service provider, including a hosting company, by ministerial order alone.
It also lowers the evidentiary bar for subscriber-data production orders from "reasonable grounds to believe" to the looser "reasonable grounds to suspect," a standard Canada's own Supreme Court had specifically required be higher in a 2014 privacy ruling.
The bill is not yet law. It now sits with the Senate, which won't take it up until Parliament returns on September 21, 2026. This is the third attempt at similar legislation in Canada in roughly 15 years, the first, in 2012, was withdrawn entirely after public backlash. Whether this one clears the Senate is genuinely an open question as of this writing.
Romania: The Government That Gave Up
This is the cleanest result anywhere in our research, even though it isn't the single highest score, Germany and Switzerland both score a point higher, but each carries a live, unresolved legislative fight attached. Romania's result comes with no such asterisk, which is why the story behind it is worth knowing. Romania transposed the EU's original data retention directive into law in 2008. Its Constitutional Court struck the law down as unconstitutional in 2009. Parliament passed a replacement in 2012, nicknamed the "Big Brother law" by Romanian civil society groups, while the European Commission was simultaneously suing Romania over its earlier non-compliance and threatening a fine of 30,000 euros per day. The Constitutional Court struck that replacement down too, in 2014.
After the second loss, Romania's legislature simply stopped trying. There has been no third attempt. Today, data retention in Romania is evaluated case by case rather than under any blanket statute, and when authorities do seek data, they generally need prior court authorization, with a narrow exception for national security matters. Romania chose losing a legal fight with the EU over compromising on this twice, and never went back for a third round.
Hong Kong: The Opposite Direction
If Romania represents permanent restraint, Hong Kong represents the opposite trend, and a very recent one. In March 2026, Hong Kong changed the implementing rules of its National Security Law so that refusing to hand over a password or provide decryption assistance to police is now a criminal offense. This applies broadly: to residents, to visitors, and to travelers simply transiting through Hong Kong International Airport, regardless of nationality.
Security analysts tracking this describe it as the latest step in a deliberate, ongoing convergence between Hong Kong's legal environment and mainland China's, a trend they've followed since Hong Kong's Article 23 national security legislation passed in 2024. A 2023 memorandum of understanding between Hong Kong's technology regulator and mainland China's Cyberspace Administration, facilitating cross-border data flow within the Greater Bay Area, points the same direction.
Switzerland: Where We Host, and Why the Live Legal Fight There Doesn't Reach Us
Switzerland is one of our two hosting jurisdictions, so we looked at it especially closely, including at a genuinely live political fight happening there right now. Switzerland has permitted six-month data retention for telecommunications providers since 1997. In January 2025, the Swiss Federal Council opened consultation on a significant expansion: requiring "derived communication service" providers, meaning platforms like email, VPN, and messaging services, with as few as 5,000 users to log IP addresses, verify identity at signup, and retain data for six months.
The backlash was immediate. Proton began moving infrastructure out of Switzerland over the legal uncertainty. Threema's CEO stated the company was prepared to launch a popular initiative, Switzerland's direct-democracy mechanism, to block the expansion outright. The Federal Council was forced to pause the proposal and order a full external risk assessment before proceeding further.
Here's the part that matters specifically for a hosting provider like us: the "derived communication service" category this fight is about is defined as providers who operate a communications platform themselves, think Threema, ProtonMail, or a VPN service. It's a different thing entirely from a general-purpose hosting or VPS provider, which rents computing infrastructure that a customer controls and uses however they choose. If one of our customers chose to self-host their own email server on one of our Swiss servers, that customer, not us, would be the one operating a "derived communication service." We're not part of this fight, structurally, regardless of how it resolves. We think that distinction matters, and we haven't seen anyone else explain it clearly.
Finland: Our Other Jurisdiction
Finland's data retention obligation runs through its Electronic Communications Act, and like Switzerland's framework, it's scoped to providers of publicly available electronic communications networks or services, not hosting or VPS providers specifically. As of the most recent count we could confirm, only four companies in Finland have actually been designated as subject to the retention obligation. No hosting-specific identity verification requirement exists under Finnish law either.
Germany: Two Court Wins and One Live Bill
Germany currently has no mandatory telecom data retention in force, one of only three countries out of 18 surveyed in a recent European comparison to say that. That's not an accident. Germany's Constitutional Court struck down the country's first retention law in 2010. In 2023, the Federal Administrative Court struck down its successor too, in a case brought by an internet industry group. Two separate courts, two separate successful challenges.
That said, this is actively in motion. Germany's Federal Cabinet approved a new draft law in April 2026 mandating three-month IP address retention, and as of the most recent reporting we found, it was still working through the Bundestag and Bundesrat, not yet passed. Industry groups have specifically warned it could expand further, including a possible extension to six months and new automated biometric-matching provisions.
The Rest of Europe
Bulgaria has one of the most heavily litigated retention histories anywhere in this research: courts struck down its original law in 2008, again in 2015, the European Court of Human Rights found continuing safeguard gaps in 2022, and the Constitutional Court struck down yet another expansion attempt just weeks before we finished this research. A retention law still exists there today, narrower than its original version, but the pattern of ongoing judicial pushback is genuinely remarkable.
The Netherlands is one of the three countries currently without any telecom retention law in force, after a 2015 court ruling found the previous version excessively broad. Working against that: the Netherlands is a Nine Eyes intelligence-alliance member with documented cable-access infrastructure at one of the largest internet exchange points in the world.
Luxembourg operates under a retention law, in force since 2015, that's narrower than most: access is limited to offenses carrying at least a year's prison sentence, and data must be stored within EU territory.
Norway requires every internet access provider, regardless of size, to log which subscriber held which IP address for 12 months, a broader net than most of its Nordic neighbors, which generally exempt smaller providers. Norway is also a confirmed Nine Eyes intelligence-alliance member, the same tier as the Netherlands. Combined with an under-sourced legal-process criterion we chose to leave unscored rather than guess at, Norway ends up as the lowest-scoring country in our data set, not because its situation is uniquely bad, but because what we could confirm about it painted a consistently weaker picture than most other countries here.
Sweden is one of only two countries in our research where we could confirm all six criteria with direct evidence, rather than leaving any unscored (the other is the United States, below). Its bulk-interception program was the subject of a European Court of Human Rights ruling that found real oversight gaps, and in that same ruling, the court found Sweden's legal requirement to notify surveilled individuals is, in the court's own words, "very limited due to secrecy" and serves no meaningful purpose as a safeguard.
Iceland is worth a special note, because it's a useful lesson in reading marketing claims carefully, and because it turned out to be more complicated than a single number suggests. Some Iceland-based providers advertise "no data retention laws," and for the specific slice of the law that applies to them, that can be technically true. But Iceland's Electronic Communications Act has required telecom providers to retain user data, including browsing history, for six months since 2005. Iceland completely rewrote its telecommunications law in 2022, a clean opportunity to drop the requirement if lawmakers wanted to, and chose to keep it. "We personally aren't classified as an ISP" and "this country has no retention law" are two very different claims, and it's worth knowing which one you're actually being told.
That said, Iceland does genuinely well on a different measure: it isn't a member of the Five Eyes, Nine Eyes, or Fourteen Eyes intelligence alliances, sitting only in a much looser tier of "focused cooperation" limited to cyber-exploitation matters. It's also outside the EU entirely (Iceland is an EEA member, not a full EU member), avoiding the automatic cross-border cooperation obligations that bind EU countries. So the honest picture is mixed: a real retention law that undercuts the "privacy haven" marketing, paired with genuinely low exposure to foreign intelligence-sharing.
The United States, Canada, and Singapore
The United States has no federal mandate requiring ISPs or hosts to retain data, but that's arguably beside the point. The CLOUD Act lets US law enforcement compel any US-based company to hand over data regardless of where in the world that data is physically stored, meaning US incorporation carries legal exposure that follows a company's data globally. Separately, the FBI can issue National Security Letters compelling record disclosure without any court approval at all, bundled with gag orders that courts have repeatedly ruled unconstitutional since 2004, and that the FBI has continued using anyway.
Canada, beyond the Bill C-22 situation detailed above, is a founding member of the Five Eyes intelligence alliance.
Singapore stood out for how little judicial process is actually required: police can search any computer they suspect is connected to a crime without a court order, a 2018 law extended that power to data stored overseas on any computer operating in or from Singapore, and Singapore's Internal Security Act explicitly bars judicial review of national-security detention decisions.
Where Packetra Fits
We built this because we were tired of jurisdiction claims that don't hold up to five minutes of actual research, including, honestly, some of our own competitors' marketing. We host in Finland and Switzerland specifically because both countries' data retention frameworks are scoped to telecommunications and communications-service providers, not general-purpose hosting, and because both have real, functioning legal systems rather than simply looking the other way. That's a different pitch than "nobody can touch you here," and we think it's a more honest one.
If you want to see how we put that into practice, our writeups on why we chose Finland and how Finland and Switzerland compare go into more detail, and our explainer on DMCA takedowns and hosting jurisdiction covers the same due-process question this piece does, from a different angle.
This piece reflects our own research as of July 2026 and isn't legal advice. Laws change, and two of the situations described above, Canada's Bill C-22 and Germany's pending retention bill, were genuinely unresolved as we published this. We'll revisit this piece as those situations develop. If you're making a decision that depends on the current legal status in any of these countries, talk to a lawyer licensed in that jurisdiction.
Shared Hosting
WordPress Hosting
Cloud VPS Hosting
Dedicated Servers