Home
Web Hosting
Domains FAQ
Resources
About Contact Client Portal
Insights ยท ยท 13 min read

Hosting Outside Germany Solves Less Than You Think

ยท 13 min read

Hosting Outside Germany Solves Less Than You Think

Last reviewed: September 2026

We sell hosting in Finland and Switzerland, so the useful thing we can tell a German site owner is where our own product does not help. For most German websites, hosting outside Germany changes less than the marketing around offshore hosting suggests, and understanding exactly why is more valuable than a sales pitch.

Germany is not the United Kingdom and it is not the United States. It has constitutional protection for personal data, a data protection authority in every federal state, and a constitutional court with a long record of striking down surveillance laws. A German reader does not need rescuing from German law. What follows is what Germany already gives you, what is genuinely changing in 2026, where the real exposure usually sits, and the narrow case where moving does make sense.

The short version: moving from Germany to Finland changes little jurisdictionally, because both are EU member states under the same GDPR and the same cross-border evidence framework. Moving to Switzerland puts your provider under a different framework, though it does not move you, since a German business remains subject to the GDPR wherever its server sits. And for most German sites, the bigger data protection exposure is the third-party services running on the page, not the country the server is in.

What Germany already gives you

Constitutional protection for your data
The German constitutional court derived a right to informational self-determination from the Basic Law in its 1983 census judgment, decades before anything comparable existed elsewhere. Personal data protection in Germany is not only a statutory matter, it has constitutional standing.

Courts that strike surveillance laws down
Germany's 2015 data retention regime never survived. The Court of Justice held in September 2022 that rules of that kind were incompatible with EU law, and in August 2023 the Federal Administrative Court ruled the relevant Telecommunications Act provisions unapplicable. The current bill exists because the old one was struck down, and the government's own explanatory memorandum says so.

Regulators that actually enforce
Germany's state data protection authorities are among the most active in Europe, and German courts have produced some of the sharpest decisions on third-country data transfers and embedded third-party services.

GDPR plus the BDSG
The Federal Data Protection Act supplements the GDPR with German-specific rules. You are already operating under one of the more demanding data protection regimes in the world.

What is actually changing in 2026

The IP retention bill, read properly

This is the development driving most of the current anxiety, and most coverage of it is imprecise in both directions. The Federal Ministry of Justice published a draft in December 2025, the cabinet approved it on 22 April 2026, and it had its first Bundestag reading on 24 June 2026 before going to the Committee on Legal Affairs and Consumer Protection, where a public expert hearing is scheduled for 7 October 2026. It is not law yet. Everything below comes from the bill itself, Bundestag printed paper 21/6581.

The bill does three separate things, and conflating them is where the confusion comes from.

1. A three-month retention duty on internet access providers

The new § 177 TKG opens with "whoever provides internet access services". Those providers must store the public IP address assigned to a subscriber, the associated port numbers and further traffic data where needed for attribution, an identifier for the connection and assigned user, and the start and end of the assignment to the second with time zone. Three months. The provision states expressly that communications content, and data about the calling up or use of other telecommunications or digital services, may not be stored on its basis. The explanatory memorandum puts the number of affected companies at around 700.

2. A preservation order reaching far more companies

Separately, the bill creates the Sicherungsanordnung: an order requiring traffic data about a specific person to be preserved before the conditions for actually collecting it are met. Under the new § 176 TKG this binds anyone providing or participating in publicly available telecommunications services, which the memorandum puts at around 3,000 companies. It is case-based rather than blanket, capped at three months and extendable once by a court. It also carries a statutory duty of silence: a provider served with one must say nothing about it to the person concerned or to third parties.

3. A restructuring of what can be demanded from digital services

The bill rewrites the criminal procedure provisions on subscriber, traffic and usage data. Usage data can be obtained from providers of digital services, the category most web hosting falls into, and there is a new power aimed at number-independent interpersonal communications services, meaning email and messengers, to obtain a stored IP address and timestamp for identifying a suspect. The government presents this as tidying up provisions that had become unwieldy rather than expanding them, but it is the reason some coverage says email and messaging services are caught. They are, for these powers, just not for the blanket retention duty.

So the accurate answer for a German site owner is narrower than either the alarmed or the reassuring version. Your web host acquires no duty to retain anything under this bill. Your host is not, however, outside the picture entirely, because powers to obtain data from digital services providers are being restructured in the same act, and if your provider also offers publicly available telecommunications services it can be served with a preservation order it is forbidden to tell you about.

The industry objections are substantive rather than reflexive. The association eco, which backed the successful challenge to the previous regime, warns that the design risks weakening judicial oversight and that linking retained IP data with other sources enables profiling. The government relies on the Court of Justice's April 2024 ruling in Case C-470/21 permitting limited IP retention. Whether this version survives German constitutional scrutiny is genuinely open.

NIS2, which landed late and hit hard

Germany's NIS2 implementation, the NIS2UmsuCG, took effect on 6 December 2025 with no general transition period. More than 30,000 organisations are expected to fall within the expanded regime, against roughly 4,500 before. Organisations already in scope when the law took effect had three months to register with the BSI, while newly qualifying organisations have three months from the point at which they fall within scope. Significant incidents trigger staged reporting within 24 hours, 72 hours and, normally, one month. Management has statutory duties to implement and oversee the required security measures. Serious violations can attract multi-million-euro fines, with higher turnover-based ceilings applying to certain large organisations.

Two things follow for a hosting decision. First, if your business is in scope, that is an obligation on you, not something a hosting location fixes. Second, supply chain security is part of the risk management duty, so if you are in scope you need appropriate contractual arrangements with your host wherever it is. Moving abroad does not remove the duty and does not by itself satisfy it.

Where German exposure usually actually sits

German enforcement and litigation on website data protection has concentrated overwhelmingly on one thing, and it is not where the server is. It is the third-party services embedded in the pages.

Germany produced the ruling that made this concrete: a Munich court held that loading Google Fonts from Google's servers, which transmits the visitor's IP address to a US company without consent, violated the visitor's rights, and a wave of warning letters followed. Similar data protection issues can arise with analytics, embedded maps, hosted video, CAPTCHA services and fonts from any third-party CDN, though the legal basis and the implementation differ from service to service.

A German business can move its server to Switzerland, feel more private, and still send every visitor's IP address to several American companies before the page finishes rendering. If you want the highest-value change available to a German site owner, it is usually removing those calls rather than relocating the server. We covered the detail in what the Google Fonts rulings actually said, running WordPress without Google, and what a CDN sees.

So what does hosting outside Germany actually change?

Move What changes
Germany to Finland Little jurisdictionally. Same GDPR, same EU cross-border evidence framework. What changes is the national law your provider operates under, the price, and the network route.
Germany to Switzerland Your provider operates under Swiss law and Swiss international-assistance procedures rather than EU instruments. Your own obligations as a German business are unchanged.
Germany to a US provider Worse on this axis, not better, regardless of which region you pick. Covered in the CLOUD Act article.

The Finland row surprises people, so it is worth stating plainly. Since 18 August 2026 the EU e-Evidence Regulation has made the route from a German authority to a Finnish provider considerably more direct and standardised than it was before. Finland therefore does not create the kind of separation that moving outside the EU can, even though national Finnish law and its procedural safeguards still matter. Finland has real advantages, including strong constitutional protection for confidential communications and better pricing, but jurisdictional distance from Germany is not the main one. The connection is not incidental either: the German bill's preservation order exists partly because the e-Evidence Regulation requires member states to have such an instrument in national law.

When moving does make sense

You want your hosting provider outside the EU legal framework. Switzerland delivers that distinction: the provider operates under Swiss law rather than EU e-Evidence rules. Be clear about the limit, though. A German business itself remains subject to the GDPR and its other German and EU obligations, so moving the server does not take the customer out of EU law.

You want a hosting service that does not require identity documents at signup. Packetra signup requires an email address rather than an ID document or phone verification. That is a product-policy difference rather than something moving the server itself accomplishes.

You want to pay in cryptocurrency. Rare among mainstream hosts, ordinary among privacy-focused ones.

Your audience is not in Germany. If most of your visitors are in Northern or Eastern Europe, a Helsinki server may simply be closer to them.

And one reason that is not good enough on its own: a general feeling that Germany is becoming more surveilled. The retention bill is real and worth watching, but as drafted the blanket duty reaches internet access providers rather than hosts, and Germany still has stronger structural protections than most of the alternatives people consider.

Do not forget the domain

A .de domain sits with DENIC, a German registry, regardless of where the website behind it is hosted. If jurisdiction is the reason you are moving the server, the domain deserves the same thought, and for many German businesses keeping .de is the right customer-facing choice anyway. The trade-off should be a decision rather than an oversight. We set out how registry jurisdiction works in who can actually take your domain away.

For German customers at Packetra

Prices are shown and billed in euros, so there is no currency friction. Signup takes an email address, with no identity check and no phone verification, and we accept Bitcoin and Monero through a BTCPay Server we run ourselves alongside conventional methods.

On latency, both locations are a short hop from Germany and the difference from a Frankfurt server is small for ordinary websites, but you should measure rather than take our word for it. Our looking glass tests the route from your own connection.

Which location fits depends entirely on what you read above. If you want your provider outside the EU framework, Switzerland. If you want better value inside it, Finland, with the honest caveat that this is a change of provider rather than a change of jurisdiction. The full comparison is in Finland versus Switzerland, and the legal detail in our guides to Finnish hosting law and Swiss data protection law.

Shared and WordPress hosting carry a 30 day money-back guarantee, and our migration guide covers moving an existing site without downtime.

View hosting plans

Research note. The account of the IP retention bill above is taken from the text and explanatory memorandum of Bundestag printed paper 21/6581, not from secondary coverage. Also used: EU regulation, German court decisions cited in that memorandum, industry association statements, and Packetra's own experience operating hosting infrastructure in Finland and Switzerland. Last checked September 2026. The bill is in committee with a public hearing scheduled for 7 October 2026 and may change before it becomes law, if it does. This is general information, not legal advice for your situation.

Frequently asked questions

Does the German IP retention bill apply to my web host?
Not the retention duty. The new § 177 TKG binds providers of internet access services, around 700 companies according to the explanatory memorandum. The bill's separate preservation order reaches providers of publicly available telecommunications services, around 3,000 companies, and the act also restructures the powers to obtain subscriber and usage data from digital services providers. A web host takes on no duty to retain anything, but the bill is not irrelevant to it either.

What exactly would be retained, and for how long?
The public IP address assigned to a subscriber, associated port numbers and further traffic data where needed for attribution, connection and user identifiers, and the start and end times of the assignment. Three months. Communications content and data about the use of other services are expressly excluded.

Is my data safer in Finland than in Germany?
Not in any strong legal sense. Both are EU member states under the GDPR, and since August 2026 both sit within the EU e-Evidence framework. The differences are national law around your provider, price and network route, not the level of data protection.

Is Switzerland actually different?
For your provider, yes. It is outside the EU, applies its own Federal Act on Data Protection, and handles foreign requests through its own international assistance procedures rather than EU instruments. For you as a German business, your GDPR obligations follow you regardless of where the server is.

Do I need to worry about NIS2 when choosing a host?
If your business is in scope, you have obligations regardless of where you host, including supply chain measures that require appropriate arrangements with your provider. Hosting location neither creates nor removes the duty.

What is the most useful privacy change I can make to a German website?
For most sites, removing third-party services that transmit visitor IP addresses to companies outside the EU. That is where German rulings and warning letters have concentrated, and it is usually a bigger real-world change than relocating the server.

Can I keep my .de domain if I host abroad?
Yes. Domain and hosting are separate, and a .de domain works pointed at a server in any country. Just be aware that the domain remains with a German registry, which matters if jurisdiction is your reason for moving.

Need Reliable Hosting?

Privacy-focused, anonymous, and built for people who value their data.